Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Londesborough Excerpts
Lord Londesborough Portrait Lord Londesborough (CB)
- View Speech - Hansard - -

My Lords, it is getting late, and I am told that we are now competing with the Spain v France World Cup semi-final—the winner may well face England in the final—so I will try to be brief. I speak not as a cyber expert or technologist but as a former CEO of a tech-enabled mid-sized business. I want to bring some ground-level perspectives of these oft-mentioned SMEs, one of which I currently chair.

I welcome the Bill, but like many others, I have some concerns over its scope, its impact on those apparently outside the scope but who sit within critical infrastructure supply chains, the challenges of a horizontal piece of legislation being layered over multiple sectors and their regulators, and why, as so many people have asked, there is no specific strategy for AI. All of that has been covered, and I will not repeat those points. However, I want to question why central government and local authorities will remain out of scope. The National Audit Office’s report last year found serious slow-to-fix security flaws across 58 of the 72 government systems that were reviewed. The public sector badly needs binding legal requirements, not just a voluntary action plan.

As we have heard, the UK is already the most targeted country in Europe for cyber attacks, with more than 40% of UK businesses experiencing such attacks at a cost put at almost £15 billion annually. But those numbers are almost certainly an underestimate not just because they apply to 2024 but because a whole range of cyber incidents go unreported and therefore unmeasured, especially in the world of SMEs. In fact, 96% of UK businesses that suffered a cyber attack were SMEs, not because they are targeted but because they are easier to breach. If you factored in all the incidents and took into account all the costs, including the distraction from core business, the real cost this year might well be closer to £30 billion—roughly 1% of our GDP.

Let us face it: when this Bill is enacted, it will already be out of date. That is not an argument for delay, but it is an argument for shaping legislation to allow changes and add-ons down the line as the threats change without going through the long and arduous processes of legislating through both Houses of Parliament. I suggest that we are pragmatic and that we balance the need for parliamentary scrutiny and consultation with speed and agility.

I am going to finish by focusing on the mid-market and small businesses. The Bill tells us that high impact suppliers of any size could be designated as critical suppliers. That has raised quite a few question marks. Two-thirds of medium-sized UK businesses reported a cyber breach last year alone, yet only 15% of those businesses had formally reviewed the cyber risks that their immediate suppliers posed to them. This Bill will make mid-market players take compliance, incident reporting, risk assessments and audits more seriously. Those should no longer be seen as the sole responsibility of the IT department or the CTO but become a board- level issue that CEOs need to engage with. Currently, only 27% of UK businesses have board-level cyber accountability. That needs to change.

It is confession time. I was once one of those mid-market CEOs who took too little interest at board level in the risks to our company’s infrastructure and systems, delegating them to mid-management and our offshore partners and nearly paying the price when our online platform, which contained all our customer data and 20 years of content, came under attack and was very nearly successfully hacked. Lessons were quickly learned. Will the Minister say how the Government plan to address and resource the information, communication and training challenge that this Bill will present to mid-market players?

I raise the same question for those SMEs that will get dragged into supply chain compliance issues, whatever their size, but without the specialist resources needed. In the other place, the Liberal Democrats proposed what I thought was a very sensible amendment for the establishment of a cyber security support service to help SMEs comply with their regulatory duties. This was dismissed by the Minister, who said that very few SMEs would be in scope, but nobody has put a number to this and I think this misses the point. I fear that the Government underestimate this challenge, both for mid-market and small players.

If this information, resource, communication and education piece is not properly addressed, we will not just lose links in the supplier chain but reduce the level of competition. This will be bad for business and economic growth and, indeed, for trade with our European neighbours, who are way ahead of us in this area.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Londesborough Excerpts
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships.

The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now.

Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change.

Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope.

There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success.

We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions.

My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it.

Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope.

Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question.

The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States.

Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better.

We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require.

Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope.

The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.

Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - -

My Lords, I shall speak to Amendments 7, 9, 11, 76, 77 and 88 to 91 in the name of my noble friend Lord Birt, each of which I have added my name to, and to Amendment 87 in the name of the noble Lord, Lord Clement-Jones.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Londesborough Excerpts
Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, I rise early to support the amendment from the noble Baroness, Lady Northover, partly to spare the stress of the noble Lord, Lord Clement-Jones, and also because there is a Liberal Democrat amendment imminent in the Chamber, although we of course will be abstaining—our solidarity with the Liberal Democrats does not extend too far.

However, it does extend to this amendment, which ties in well with the noble Baroness’s earlier amendment concerning qualifications. I was fascinated to hear her referring to the Australian cyber service, which I had not heard about before. I would be fascinated to know more and it would be interesting to hear from the Minister what other lessons there may be for us to learn from similar jurisdictions around the globe. I suspect the Canadians, for example, some of our European partners and some of the south-east Asian nations, such as Singapore or South Korea, will probably have very advanced and sophisticated bureaucracies, if I can put it that way, or institutions looking at the cyber threat.

Again, I shall address, rather than the technical detail of the noble Baroness’s amendment, the spirit in which it is brought and why it fits so well with her earlier amendment. It is about injecting a sense of urgency into how we raise our game in cyber in terms of our economy. When she mentioned the cyber action toolkit, it took me back to the days when I was one of the Cyber Ministers in the coalition Government. My responsibility was towards small businesses, and we launched endless small business toolkits, mainly because we wanted to say that we had launched a small business toolkit. We certainly never put in place any mechanisms for auditing its impact or success, and I think the constant references to about 7% of SMEs now having cyber policies in place may point to my abject failure in that role, and perhaps that of some of my successors.

The more I have listened to this debate, the more it takes me back to my childhood, when we would get leaflets about a possible nuclear conflagration. I know that Ministers and the Government are now telling people to stockpile water and baked beans because of the impact of El Niño, but we know that a cyber attack on the UK would cripple our economy and essential public services, so it is akin, given the geopolitical situation, to a national emergency.

The noble Baroness mentioned the views of the Association of British Insurers. Again, that was part of the toolkit. The feeling was that professional services would drive small businesses towards becoming more skilled in assessing their cyber risks, that you could not get insurance, or indeed cyber insurance, unless you had clear policies to deal with cyber attacks. With professional services firms, you could not necessarily get legal liability insurance for a data breach, which is not necessarily going to cripple your business but will affect your customers and therefore leave you open to liability, unless you could demonstrate that you had proper processes in place to protect your data. There is a whole ecosystem, it seems to me, that needs to be brought to bear to support the uptake of cyber skills and cyber audits by small businesses: we cannot be complacent and assume that 7% is an acceptable figure and that it should be allowed to evolve.

To a certain extent, the noble Baroness’s amendment is about the after-effects: if you suffer a cyber attack then you should be able to call on skilled people, whom we hope will have achieved the kind of recognised qualifications that the noble Baroness talked about earlier. She compared them to doctors but, when I thought about the amendment, I thought more about plumbers and electricians and the technical qualifications that you need to have to do a technical and difficult job.

We also need to look at what happens before. How do we increase the number of small businesses that put in place policies that will protect them from cyber attacks? That involves using the private sector, insurance companies and professional services firms to push forward clear protocols to which small business should be expected to adhere in order to receive the cover that they need to carry on doing business.

Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - -

My Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.

There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.

Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.

I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.

I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.

The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.