Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Londesborough
Main Page: Lord Londesborough (Crossbench - Life peer)Department Debates - View all Lord Londesborough's debates with the Department for Science, Innovation & Technology
(3 weeks ago)
Lords ChamberMy Lords, it is getting late, and I am told that we are now competing with the Spain v France World Cup semi-final—the winner may well face England in the final—so I will try to be brief. I speak not as a cyber expert or technologist but as a former CEO of a tech-enabled mid-sized business. I want to bring some ground-level perspectives of these oft-mentioned SMEs, one of which I currently chair.
I welcome the Bill, but like many others, I have some concerns over its scope, its impact on those apparently outside the scope but who sit within critical infrastructure supply chains, the challenges of a horizontal piece of legislation being layered over multiple sectors and their regulators, and why, as so many people have asked, there is no specific strategy for AI. All of that has been covered, and I will not repeat those points. However, I want to question why central government and local authorities will remain out of scope. The National Audit Office’s report last year found serious slow-to-fix security flaws across 58 of the 72 government systems that were reviewed. The public sector badly needs binding legal requirements, not just a voluntary action plan.
As we have heard, the UK is already the most targeted country in Europe for cyber attacks, with more than 40% of UK businesses experiencing such attacks at a cost put at almost £15 billion annually. But those numbers are almost certainly an underestimate not just because they apply to 2024 but because a whole range of cyber incidents go unreported and therefore unmeasured, especially in the world of SMEs. In fact, 96% of UK businesses that suffered a cyber attack were SMEs, not because they are targeted but because they are easier to breach. If you factored in all the incidents and took into account all the costs, including the distraction from core business, the real cost this year might well be closer to £30 billion—roughly 1% of our GDP.
Let us face it: when this Bill is enacted, it will already be out of date. That is not an argument for delay, but it is an argument for shaping legislation to allow changes and add-ons down the line as the threats change without going through the long and arduous processes of legislating through both Houses of Parliament. I suggest that we are pragmatic and that we balance the need for parliamentary scrutiny and consultation with speed and agility.
I am going to finish by focusing on the mid-market and small businesses. The Bill tells us that high impact suppliers of any size could be designated as critical suppliers. That has raised quite a few question marks. Two-thirds of medium-sized UK businesses reported a cyber breach last year alone, yet only 15% of those businesses had formally reviewed the cyber risks that their immediate suppliers posed to them. This Bill will make mid-market players take compliance, incident reporting, risk assessments and audits more seriously. Those should no longer be seen as the sole responsibility of the IT department or the CTO but become a board- level issue that CEOs need to engage with. Currently, only 27% of UK businesses have board-level cyber accountability. That needs to change.
It is confession time. I was once one of those mid-market CEOs who took too little interest at board level in the risks to our company’s infrastructure and systems, delegating them to mid-management and our offshore partners and nearly paying the price when our online platform, which contained all our customer data and 20 years of content, came under attack and was very nearly successfully hacked. Lessons were quickly learned. Will the Minister say how the Government plan to address and resource the information, communication and training challenge that this Bill will present to mid-market players?
I raise the same question for those SMEs that will get dragged into supply chain compliance issues, whatever their size, but without the specialist resources needed. In the other place, the Liberal Democrats proposed what I thought was a very sensible amendment for the establishment of a cyber security support service to help SMEs comply with their regulatory duties. This was dismissed by the Minister, who said that very few SMEs would be in scope, but nobody has put a number to this and I think this misses the point. I fear that the Government underestimate this challenge, both for mid-market and small players.
If this information, resource, communication and education piece is not properly addressed, we will not just lose links in the supplier chain but reduce the level of competition. This will be bad for business and economic growth and, indeed, for trade with our European neighbours, who are way ahead of us in this area.