Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, I thank the noble Baroness, Lady Northover, for bringing forward Amendment 99. Throughout our consideration of the Bill, I have returned several times to the distinction between cyber compliance and cyber capability, and this amendment goes directly to that issue. We can impose ever more duties on businesses, require ever more reports and give regulators even more powers but, ultimately, our cyber resilience depends on having enough people with the skills to prevent attacks, protect people from them and respond when they occur. That is why, like many other noble Lords, I support the principle behind the amendment.

--- Later in debate ---
Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, in addressing the amendment in the name of the noble Lord, Lord Clement-Jones, I may increase his stress levels, unfortunately, as I oppose it. This means, I guess, that I am supporting the Government—that is, unless the Government are going to perform a volte-face in the face of the noble Lord’s strong arguments for a merits-based review of any decision reached by the First-tier Tribunal.

I do so because it brings back memories of when I was the telecommunications Minister and was, therefore, responsible for Ofcom. At the time, all Ofcom decisions were subject to a merits-based review in front of the Competition Appeal Tribunal, which meant that, in effect, every decision it took regarding broadcasters or telecoms companies was reheard at appeal. As noble Lords can imagine, technical decisions on the charges being levied by wholesale carriers—or, in the case of Sky, the charges being levied on other broadcasters to carry, for example, the Premier League—were extremely complex, and Ofcom faced an army of lawyers deployed by those companies.

Without wishing to give away too many confidences—this was 10 years ago, so I do not think it is a matter of national security—Ofcom found itself extremely frustrated by all this. It was costing millions and millions of pounds. It was being used by commercial providers as a delaying tactic, a firepower tactic, almost, in order, understandably, to put off decisions that were not in their commercial favour. I initially resisted Ofcom’s blandishments to say that we should move away from merits-based appeals, partly because I thought that we would just start a whole new process of the courts feeling their way under the new system and would end up with a whole new set of delays as the courts had to make novel decisions under a novel regime.

However—one of the great telecom chief executives, my noble friend Lady Harding, has just walked into the Committee right on cue; I do not think, though, that she ever used her firepower in the cynical way that others did against Ofcom—the changes did go through. As far as I am concerned, although I have not done my homework properly, things have settled down into a straightforward process whereby a regulator makes a decision based on the facts and, if that decision can somehow be seen as unlawful by the company in question, it can be judicially reviewed.

It must be stressed that removing merits-based appeals would not remove the right of appeal. It seems fairly obvious to me that, as in civil and criminal cases, decisions would be arrived at based on the facts. However, if that decision were somehow so outside the normal judicial process of making a decision and so irrational, as it were—which is what judicial review exists to review—then it could be reviewed. That system should be consistent across regulatory appeals. I cannot necessarily comment on the effective points made by the noble Lord, Lord Clement-Jones, about the clandestine nature of some of the findings, but it may well be that, given the issues to do with cyber security, attacks on critical national infrastructure and so on, some elements of cases must be kept confidential. That is a matter for further debate, perhaps, but I would be extremely concerned if we were to go back to merits-based reviews for regulatory appeals.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this important group and all noble Lords for their contributions. Beginning with Amendment 148A, it is reasonable to suggest that there should be a further right to appeal, given that we are talking about potentially large penalties of ÂŁ17 million or 10% of annual turnover. But, like my noble friend Lord Vaizey, I have concerns about whether the Upper Tribunal system can handle such a process. Right now, it has an open case load of over 800,000, which is a 19% year-on-year increase, and disposals have decreased by 4%. As such, I am hesitant to offer my support without being assured that further pressure will not be placed on tribunals and that this is a workable mechanism.

Amendments 174A and 174B, in my name and those of my noble friends Lord Camrose and Lord Holmes of Richmond, would require the Secretary of State to establish a register of foreign powers posing a cyber security risk to this country, and to review and report on the extent of the risk posed by powers on that list. Part 4 gives the Secretary of State significant new powers to intervene where the use of vendors’ goods and services or facilities pose a risk to national security. We support that objective. A power of that kind is only as good as the intelligence that informs it. At present, the Bill is silent on how the Secretary of State is to identify, in a systematic and transparent way, which foreign powers actually present that risk.

Amendment 174A aims to fill that information gap, outlining a thorough set of criteria for inclusion: a state confirmed by GCHQ to have perpetrated or attempted a cyber attack against the UK in the preceding seven years—one directed at an operator of an essential service or a critical supplier and carried out through a state department, agency or affiliate—or a state that GCHQ has separately warned poses a risk to such systems.

The importance of ensuring that we are fully informed of foreign threats can hardly be overstated. Just this year, the NCSC’s chief executive reported that three-quarters of all attacks on our critical national infrastructure over the preceding 12 months were carried out by hostile states, with Russia, China and Iran named specifically. The NCSC’s annual review recorded 204 nationally significant incidents in the year to August 2025—more than double the previous year, with 18 rated highly significant.

For illustration, the cyber attack that last month shut down a British power plant is reported to have been committed by Iran-backed hackers. Over the course of the last Parliament and this one, China has targeted Parliament and compromised the Electoral Commission; Russia’s FSB has targeted British parliamentarians and successfully stolen and leaked politically sensitive documents; and Iranian state actors have targeted British politicians, Governments and defence with sustained cyber espionage campaigns.

We are seeing a surge in cyber attacks driven largely by foreign threats. If the Government are serious about security and resilience, tackling foreign interference must be a priority. As a start, a published criteria-based register would bring much-needed transparency and rigour to the process. Amendment 174B seeks to achieve such transparency. It would require the Secretary of State, for each foreign power added to the register, to conduct a review of the extent and nature of the risk that that power poses. It also includes a built-in safeguard for the Government: where the Secretary of State considers that laying their report would be contrary to national security interests, they may instead make a Statement to Parliament confirming that the review has taken place and explaining that it cannot be published. It attempts to strike a balance between accountability and the sensitivities that intelligence assessment of this kind will naturally carry.

I anticipate that the Minister may say that such a register already exists in substance within government and that formalising and publishing it risks informing those very powers of the extent of our knowledge. I gently observe that the amendment does not require publication of intelligence sources, substance or methods—only the fact of designation against published criteria and a review to assess the risk. Given the scale of the threat that the NCSC describes and, given the very significant powers that this part confers on the Secretary of State, I believe that Parliament is entitled to ask that those powers rest on a clear, evidenced and reviewable basis. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, starting with Amendment 148A, from the noble Lord, Lord Clement-Jones, which indeed is in line with the recommendation from the Constitution Committee, which I thank for its report and its detailed scrutiny of this legislation.

As the noble Lord points out, Part 4 enables the Secretary of State to issue penalties for regulated entities that do not comply with directions. The High Court will have jurisdiction to review the lawfulness of a particular penalty issued under Part 4. The noble Lord, Lord Vaizey, referred to precedent and consistency. Our assessment is that the High Court is the appropriate route for hearing sensitive national security cases, consistent with the approach that previous Governments have taken to national security legislation. The Telecommunications (Security) Act, the National Security and Investment Act, and the Procurement Act, key pieces of national security legislation, all follow this approach. That is the reason we have adopted it here.

To the point around parliamentary scrutiny of directions, the Government’s default position is that copies of directions will be laid in Parliament, to enable all parliamentarians to scrutinise the Government’s use of these powers. I am of course preparing a formal response to the Constitution Committee, which will be sent in due course.

--- Later in debate ---
Moved by
174E: After Clause 58, insert the following new Clause—
“Increasing resilience by reducing data retention(1) The Secretary of State must, within one month of the day on which this Act is passed, open a consultation on the potential impact of minimising data collection and increasing data anonymisation on the resilience to cyber attack of relevant public bodies. (2) In this section, “relevant public bodies” are public bodies that are operators of essential services or digital service providers under the NIS Regulations or this Act.”
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

Amendment 174E in my name and those of my noble friends Lord Camrose and Lord Holmes builds on the point I made in the debate last Thursday that the best defence in cyber is, of course, not to present an attractive target in the first place.

I go back to my experience of the Synnovis hack when I was Health Minister. The reality was that it did not need to hold any of the detail or data that it had in the first place. When you are doing a diagnostic test of someone, you do not need to know their name; there can be a serial number that can be matched up later. Not only did Synnovis have names, it had whole medical records going back years and years, and there was no deletion policy either. The whole reason that it was an attractive target was its very sloppy standards in the data it held and its retention policy.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have nothing further to add what I have said in previous sittings.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

Nice try. I will get the final word then. First, I thank the noble Lord, Lord Clement-Jones, for his strong support. Honey pot is a very descriptive and apt term for it. I thank the Minister for her comments and will definitely take up her offer of a meeting. I must admit that the responses she gave were almost exactly the responses that the NHS gave to me on all this, so she is absolutely right: everything is being kept under GDPR. Data security and how that is held were mentioned quite a few times, but I did not hear anything about data minimisation and why we are collecting or keeping it in the first place. That is a gap in all of this because, as I said, a lot of this data does not need to be held or gathered in that way. It is just basic discipline. I would very much like to take up that offer on how we can do that, because—perhaps the Minister can look at this ahead of our meeting—I do not think this issue is addressed anywhere in the Bill.

I do get the last word. I thank everyone who has taken part in this. There have been a number of important issues raised. I really appreciate the willingness of the Minister to engage, and I know there are a number of follow-up meetings that I think we will all want, because there is a lot that we need to work on between now and Report to make sure that the Bill really gives us the sort of protection we would all hope to have. I beg leave to withdraw my amendment.

Amendment 174E withdrawn.