Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Markham Excerpts
Finally, Amendment 14 in my name would provide a vital refinement to the definition of “managed services” in Clause 9. As currently drafted, Clause 9 defines a managed service so broadly that it in effect acts as a legal dragnet, capturing any service provided under contract for ongoing IT management, support, maintenance or other activities. This threatens to pull thousands of small, non-critical IT consultancies, training providers, software licensing agents and basic help desks into heavy NIS registration and turnover-based penalties. My Amendment 14 would establish a clear statutory boundary: if an IT provider does not possess ongoing privileged administrative access to configure, alter or control a customer’s live network, it is excluded from the managed service provider regime. This would protect small businesses and tech companies and include only those that present genuine systemic threats. I urge the Government to accept this balanced package of risk-based, future-proofed definitions.
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

I add my thanks to the noble Baroness, Lady Kidron, and other noble Lords for trying to make sense of what we all agree is a very difficult area. We are trying to come to a definition of high-risk areas. As we have heard in the examples today, you cannot limit it to size or certain criteria, but we all recognise that you need some sort of risk-based approach for who we really need to be watching out for, for want of a better phrase.

In some ways, I come back to the suggestion from my noble friend Lord Camrose. In its severity scale, the Cyber Monitoring Centre has tried to set up such a mechanism. It looks at having a separate grid system which considers, on the one hand, the financial, pound-note impact and, on the other hand, the impact on members of the population. It is a really difficult exercise to define exactly what should and should not be in it, but in using a scale such as this and asking companies or entities to assess themselves, if they come up with a “0” or “1”, then it is less of a concern and, if they come up with a “3” or “4”, it is more of a concern. I accept that some of them will game it and might not treat it honestly, but a lot of them might not.

To go to my noble friend’s example of that one small data centre, probably only the centre itself knew at that time that it was pivotal to so many other people. The centre having to make an assessment on where it comes on this severity scale, involving at least the executive team, and having a non-executive board asking, “Are you sure you’re only a 1 or 2? Surely, from what you were telling me the other day about everything we look after, it means we should be 3 or 4” is important because we start to get a criterion that we can look at in all this. Trying to define it by ruling in different entities according to size and certain criteria will be well-nigh impossible. So I welcome the Minister’s thoughts on whether we can take a system that seems to be working, to a degree, today and think about it between now and Report stage in terms of whether that is a relevant criterion we could use.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.

Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.

As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.

We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.

Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.

Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.

Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.

In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.

We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, I thank the noble Baroness, Lady Ludford, for introducing this group. I am generally supportive of the principles she is introducing, and I thank all noble Lords who have spoken in this debate. I particularly enjoyed trying to get my head round ten septillion, however many zeros that was, on that computing.

Moving first to our amendments, I hope that there was something constructive in this debate trying to build on a lot of the things that the noble Lord, Lord Birt, said in the previous group around giving people tools for self-help in a lot of this because we know that the Government cannot be expected to cover every aspect. Starting with the amendment in my name and that of my noble friend Lord Camrose, Amendment 92B builds on a similar principle to that underpinning our support for a voluntary referral scheme, that being that businesses and individuals should, where practical, be self-sufficient and self-accountable with regard to cyber security. The more that businesses are responsible for their own security, the less the state has to look over their shoulders: I think that is of benefit to both parties. Requiring a large business to report its own cyber security and resilience plan provides an impetus. The idea is that you want the board to ask the chief executive and the executive team, “What are you doing in this space?” and hold them to account for the shareholders. If the answer to that is a big fat zero, that would clearly be concerning. That act of informal, nudging pressure—call it whatever you want—would be quite a call to action that any self-respecting chief executive and board would take heed of.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I shall speak in support of this group on designated critical suppliers. I support in particular Amendments 15A and 15B, which were tabled by the noble Lord, Lord Arbuthnot of Edrom; I have signed them both. We are also sympathetic in principle to Amendment 16 in the name of the noble Lord, Lord Ravensdale.

We on these Benches fully support the principle of regulating managed service providers and designated critical suppliers. Because MSPs and key vendors act as trusted bridges into multiple enterprise networks, a single compromised supplier can trigger a systemic, cross-sector shutdown; we saw this in the Collins Aerospace attack, which halted airport check-in systems across Europe. However, we must ensure that our regulatory net is both deep enough to capture hidden systemic risks and precise enough to avoid catching non-critical small businesses.

In our view, Amendments 15A and 15B in the name of the noble Lord, Lord Arbuthnot, achieve the necessary depth. They would empower regulators under Clause 12 to designate critical suppliers that supply essential services or managed service providers through one or more intermediaries. In modern digital architectures, systemic single points of failure often sit at tier 2 or tier 3 in the supply chain. If an essential service materially depends on a sub-tier vendor, regulators must not be blinded by the absence of a direct contract. By pairing Amendments 15A and 15B with Amendment 16 in the name of the noble Lord, Lord Ravensdale, we could ensure that deep supply chain risks are policed, while protecting small innovators from bureaucratic overreach.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Markham Excerpts
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.

In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.

I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.

Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group. We have spoken previously about the importance of effectiveness, proportionality and clarity. I absolutely hear the experience of the noble Baroness, Lady Harding, in leading a telecommunications company and the experience it had.

We have learned from experiences across all sectors in introducing the new regime that is in the Bill, which puts in, as others have said, a staged approach that includes an early alert to regulators and the NCSC within 24 hours. That will provide awareness and enable the NCSC and regulator to provide early support, as well as potentially understand whether it is impacting multiple regulated entities.

--- Later in debate ---
Moved by
73: Clause 18, page 41, line 7, at end insert—
“Exemption from disclosure: right to a fair trial(1) Nothing in paragraphs (1)(d) to (f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that—(a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or(b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial.(2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of—(a) subject matter experts, and(b) competent civil society groups.(3) Every 12 months the Secretary of State must publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) in the previous 12 months.(4) The first report under paragraph (3) must be published and laid within 12 months of the day on which the Cyber Security and Resilience (Network and Information Systems) Act 2026 is passed.”
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, Amendment 73 stands in the names of the noble Lords, Lord Alton of Liverpool and Lord Hunt of Kings Heath, and the noble Baroness, Lady Ludford, and in my name. Unfortunately, the noble Lord, Lord Alton, is unable to be here today, and I am very pleased to move the amendment on his behalf. The principle behind it is very simple, and I am delighted to see that it has cross-party support. I am sure and trust that it will have cross-Committee support as well.

We all recognise that cyber threats do not respect national borders. Effective cyber security therefore requires international co-operation and information sharing. I think that is something that we all believe in. A lot of measures that we have been talking about would actually give teeth and powers to these organisations to make sure this happens. However, the amendment shows when things can go too far and the risks around that. There must surely be limits on where information obtained under UK statutory powers can subsequently be sent and how it can be used.

The Bill will give NIS enforcement authorities the power to share information with overseas authorities. Amendment 73 would prevent such information being shared where the Secretary of State determines that the receiving jurisdiction cannot guarantee the right to a fair trial, or where disclosure could result in actions incompatible with that right. This is not a theoretical concern. We know that authoritarian states increasingly use apparently legitimate law enforcement processes as instruments of transnational repression. China provides perhaps the clearest example. There are well-documented concerns about the independence of its judiciary, particularly in national security cases, and the treatment of dissidents and human rights defenders.

--- Later in debate ---
Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness. I will write to her on the case-by-case point.

Finally, I know that my noble friend the Minister will be very happy to meet noble Lords again to discuss this further, as she has done quite recently with the noble Lord, Lord Alton.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

I thank the Minister for her response and noble Lords for their involvement. As suspected, the Committee is completely united in what we are trying to achieve, and I am pleased to hear that the Minister is sympathetic. I think we all agree that the devil will be in the detail. That is why I am grateful for the offer of a meeting, which I am sure that the noble Lord, Lord Alton, and many of us here will be delighted to take up.

I have a couple of concerns, and we will cover these in the meeting. As the Minister mentioned, there is no obligation for regulators. The question is: why leave it to their discretion? The Minister later said that there was concern about it being overburdensome on the Secretary of State’s officials to have to determine these cases. If it is too much of a burden for a group of experts, surely it is even less likely that regulators in all sorts of different fields are going to try to apply that same knowledge.

The concern about all of this is that, while the intentions are good, unless there are firm constraints in the Bill, it will just be something which, through no malcontent or wrong reason, is overlooked. That is why we feel it is very important that we have something in the Bill to add teeth to this. That is something that we would be delighted to explore further in meetings and on Report but at this point, I beg leave to withdraw the amendment.

Amendment 73 withdrawn.
--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, we have heard very compelling cases from all noble Lords who have spoken on this group about why a particular sector should be included. I will not go through the list—it was gone through very well by the noble Lord, Lord Clement-Jones, a moment ago—but I think we can all agree that each one was a compelling case. That probably illustrates the wider problem, because we are almost getting into a game of cyber whack-a-mole here, where we can see them popping up left, right and centre. So our approach, with Amendments 92 and 92A in my name and those of my noble friends Lord Camrose and Lord Holmes, is to try to take a more strategic view, very much reflecting some of the views that the noble Lord, Lord Birt, was mentioning earlier as well. They ask the Government to assess strategically important entities outside the current NIS regime and consider whether they should be brought into scope where a cyber attack would have a sufficiently serious impact on the economy or the day-to-day functioning of society.

We are not asking for another long list of businesses to be regulated, because we need to be careful about the regulatory burdens that we are putting on people. Instead, Amendment 92A proposes a risk-based test and asks these questions: what would actually happen if this organisation went down? Would essential services stop? Would very important supply chains fail? Would significant parts of the economy cease to function? If the answer to those is yes, surely the Government should at least assess whether that organisation belongs within our national cyber security perimeter. This also illustrates why we need to see the national cyber action plan. It was promised this summer; we are now in September and, considering that this is very pertinent to everything we are talking about in Committee, I ask the Minister when we will see the plan.

I will highlight one further issue, which the noble Baroness, Lady Berger, illustrated very well, in the area of the data held in certain organisations, particularly in education. We all know that the reason that a lot of these organisations are attractive targets is not because of the essential services they often carry out but because they carry enormous quantities of valuable and sensitive data. Again, this was very much my experience with the attack on Synnovis when I was Health Minister. It caused massive disruption for operations and diagnostic services in London, but the question was: why was that organisation holding so much information in the first place? It had names and addresses of people going back 20 years, their test results and their full medical records, and it did not need any of it at all. It could all have been anonymised, and it definitely did not need to hold it for 20 years.

To me, the question we really need to answer—this speaks to an amendment we will be talking about later—is: what data do all these public bodies really need to hold? Of course, if the data is not there in the first place to be stolen, or if it is not interesting or valuable, then that is the best line of defence, because there is no reason for there to be a cyber attack on it. As I say, we will talk further on that on Amendment 174E, but the principle is directly relevant to what we are talking about here.

Before I come to the end, I have a special request from my colleague here, who I think knows a thing or two. I am told on good authority that the last government AI regulation White Paper has a lot of relevance and synergies here, so I would request the Minister to look at that between now and Report to see where, as I say, there are synergies and learnings from it.

In summary, first, we should systematically identify the organisations whose compromise would cause the greatest damage, as per our Amendment 92A, and, secondly, we should reduce both their vulnerability and attractiveness as targets, including by reducing the data prize available to the attacker, as per our Amendment 174E, which we will come to later on. That, to me, is genuine cyber resilience: not merely making the safe harder to crack but, wherever possible, ensuring that there is nothing valuable inside the safe to steal.

I hope the Minister will respond both on the important sectors raised by noble Lords and to the central question behind Amendment 92A: what systematic test are the Government applying to determine which strategically important organisations should fall within the NIS regime, and will that regulatory perimeter keep pace as technology and the threats change?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.