Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Ravensdale Excerpts
Lord Ravensdale Portrait Lord Ravensdale (CB)
- View Speech - Hansard - -

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis and I support the Bill. Given the threats that we are facing, strengthening the cyber security of the UK is vital. I think that the flexible, risk-based approach taken within the Bill is the right one.

Noble Lords have made many of the broader points already, so I will focus on a few narrower points. My remarks are really centred around the impact on economic growth and the need for proportionate regulation, because this legislation supports growth through, first, increasing our cyber resilience. The noble Baroness, Lady Northover, gave the example of the ÂŁ15 billion cost of cyber attacks in 2024: that is a significant fraction of our GDP, around 0.5%.

I am also glad that the noble Lord, Lord Vaizey, brought up our world-leading cyber industry: the Bill represents a great opportunity for one of our key industries. However, there are threats to that growth agenda within the Bill, particularly through how larger corporates and SMEs will be affected, and we need to tread extremely carefully here. Business already has to deal with much burdensome regulation, as the noble Earl, Lord Effingham, set out. As ever in legislation, we need to think about those unintended consequences. To this end, there are three points I want to make.

Looking at some of the detail of the Bill, my first point is around supply chains. Clause 12 rightly brings in the concept of “critical suppliers” and ensures that supply chains are within the scope of the regulations. However, given the ambiguity of the criteria for designation, there is a risk that a significant number of SMEs could be affected, perhaps unintentionally, by this legislation, so I would be grateful if the Minister would set out what steps the Government are taking to ensure that the “critical supplier” designation is restricted to suppliers posing genuine systemic risks to the UK economy. Terms such as “potential to cause disruption”, which is the wording used in the Bill, are qualitative, and there are no hard quantitative thresholds in the Bill. The risk, of course, is that a significant number of SMEs could be bought within scope, stifling those businesses with unnecessary regulation. We need to ensure that is proportionate.

Secondly, going through the Bill and continuing on this theme, we come to Clause 15, on reporting. To expand on what the Minister set out at the start, Clause 15 expands the definition of “a reportable incident” to include those capable of having

“an adverse effect on … network and information systems”.

The risk is that this could lead to overreporting, as even a minor phishing email could be deemed to be capable of having “an adverse effect”, and then we could perhaps see overreporting overwhelming systems and bringing the risk that genuine threats could get through. So, I would also be grateful if the Minister could tell us how the Government will ensure that the “capable of having an adverse effect” threshold does not lead to overreporting of low-level incidents.

Thirdly, we have heard a lot of talk about AI in this debate, and perhaps a little less about quantum. I want to bring up quantum as a specific aspect, as the noble Lord, Lord Birt, referred to. I appreciate that there is a difficult balance here. This is a framework Bill, and it is perhaps not appropriate to set out specific technologies or technology impacts in it. However, the threat of quantum computers using algorithms like Shor’s algorithm to crack current public key crypto, such as RSA, enabling “harvest now, decrypt later” attacks on sensitive data, is something that will come, sooner or later, and quantum computing is evolving astonishingly quickly. The Parliamentary Office of Science and Technology, POST, where I am vice-chair of the board, has set out around a 10-year timescale for when a quantum computer will be able to break conventional encryption, and that aligns with the National Cyber Security Centre, which has already set out that organisations must complete migration to post-quantum crypto by 2035. I would be grateful for the Minister’s thoughts on how this could perhaps be strengthened within the Bill. For example, could there be something in the statement of strategic priorities in Clause 25 to help to join together the regulators in terms of the focus that is required on quantum cryptography? I would be very grateful for the Minister’s thoughts on that key area too.

In general, as I said, I support the Bill and I look forward to working with the Minister and her team as we move towards Committee.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Ravensdale Excerpts
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - -

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis. I shall speak to Amendment 82.

In our debate on group 3, a lot of good points were made about one specific technology related to cyber: AI. However, as the noble Lord, Lord Birt, said in the debate on the previous group, quantum is the other area that needs attention as a specific technology. When I started here around seven years ago, I never thought that I would one day be talking about quantum mechanics in your Lordships’ House.

I recently heard the story of Heisenberg and his discovery of the uncertainty principle, almost 100 years ago in 1927. He was out in a park late one night, after a long argument with Niels Bohr, and he saw a row of street lights. He saw a person walking in between the street lights late at night. He would see them go past one light—you would be able to observe them—and then they would disappear into the darkness and they would then reappear at the next light. He realised that he could use that analogy for the behaviour of the electron: as it was being measured, it was there as a particle, but, when it was not being measured, it had to be considered probabilistically because you do not know where it is. In the same way, with a quantum computer, the value of the qubit, as it is called, is locked in only when it interacts with a measurement device.

This extraordinary powerful technology is now emerging. As an example, the Willow chip, which has recently been developed by Google, completed a benchmark calculation in five minutes. It would have taken the fastest classical computer in the world 10 septillion years—that is 10 with 24 zeros, I believe—to complete it. According to the Parliamentary Office of Science and Technology and the NCSC, in less than 10 years—perhaps even sooner than that—we could have a cryptographically relevant quantum computer that uses Shor’s algorithm to decrypt all communications that rely on the RSA algorithm on which we have relied for decades for all of our bank transactions, state-level communications and so on. This is an area of technology that is moving extremely quickly, and it is not just one about which we will have to worry at some point in the future. So-called “harvest now, decrypt later” attacks could be used to decrypt sensitive information in the future.

That brings me to the amendment. It is quite a simple, straightforward one, which goes forward from the discussions on how, given the changing nature of these technologies, it is perhaps not appropriate to have specific technologies and timelines in the Bill. However, as the Minister has already brought out, the statement of strategic priorities is a powerful tool to ensure national join-up, including across those regulators within the remit of the Bill.

We have 12 regulators and each one could approach quantum crypto—so-called post-quantum cryptography—differently. There will be huge benefits in really ensuring that regulators work from the same national signal rather than inventing their own PQC expectations individually. That would also allow them, if it can be brought out in the statement of strategic priorities, to plan their inspections, guidance, skills and capacity around the NCSC timelines, which is a plan ranging from 2028 discovery and initial plan through to 2035 when post-quantum crypto implementation is completed. That will also help with all those newly in-scope firms that will be coming within the remits of this legislation, giving the regulators a legitimate basis to raise post-quantum crypto with those new organisations early on.

I read back the Minister’s remarks at Second Reading, when she said that quantum crypto

“would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face”.—[Official Report, 14/7/26; col. 622.]

I believe that this amendment would help strengthen and deliver exactly that. With that, I look forward to hearing from the Minister on her thoughts about this approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.

Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.

As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.

We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.

Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.

Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.

Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.

In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.

We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

--- Later in debate ---
I thank noble Lords for their amendments, which touch on many aspects of implementation of the regime.
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - -

My Lords, can I clarify the Minister’s response to my amendment? She stated that the statement of strategic priorities should not refer to specific technologies, implying that it is difficult to change. The reasoning behind my amendment was precisely because the statement of strategic priorities is a more flexible instrument than having these targets in the Bill. I think there is no question of the threats posed by quantum cryptography and the need for better join-up. Can the Minister clarify her comments on the statement of strategic priorities?

--- Later in debate ---
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, I apologise for having spent less time in Committee than I would have liked, but I have been speaking on the Public Office (Accountability) Bill. I am grateful to those noble Lords who I suspect have been speaking to amendments on my behalf.

Amendments 15A and 15B are about the designation of critical suppliers. New Regulation 14H says:

“A designated competent authority may designate a person … under this regulation if P supplies goods or services directly to an OES for which the authority is the designated competent authority”.


The Bill expands this regime to cover additional organisations and creates a new framework for designated critical supplies. That is good, and it recognises that essential services depend on organisations that go far beyond the direct infrastructure of the critical organisation itself; everything is dependent on everything else. However, the critical supplier test is focused on suppliers providing goods or services directly to a regulated organisation. That ignores the concept of a supply chain with several tiers of suppliers. These amendments are intended to address that. Therefore, I beg to move.

Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - -

My Lords, I will speak briefly to my Amendment 16. In my view, the central problem is that, if I am small or medium-sized firm, I cannot currently tell with any confidence whether I am within the scope of the Bill as a critical supplier. Small and medium-sized enterprises are the lifeblood of our economy, and we need to approach with caution any ambiguity around their inclusion in the Bill. I took note of what the Minister said at Second Reading, when she said that:

“They can be regulated if they are designated as critical suppliers, for which there will be a high bar for designation”.—[Official Report, 14/7/26; col. 622.]


That was helpful, but what exactly is that high bar?

To give noble Lords an example of regulation legislation that is not defined, I come back to one noble Lords are likely to be familiar with: the infamous IR35. With that, the uncertainty and costs of getting it wrong were high in the regulation, so firms applied a blanket under which everyone they engaged with had to be inside IR35 and had to be treated as an employee. IR35 addressed a real problem, but the test was judgment-heavy and getting it wrong was expensive. That was why many organisations stopped making case-by-case decisions and applied a blanket policy, which meant that far more were caught by the regulation than was intended. I remember many years ago, as an engineer, spending a lot of time trying to fill in IR35 determinations and not doing engineering, which was a frustration at the time. It led to many issues with finding the right new skilled resource that we required to undertake the work.

I am sure that the Minister will say that the criteria will be set out in secondary legislation, but there will be a long period of uncertainty, and the IR35 example helps illustrate the risks. I took a look at the impact assessment and some of the costs were laid out. For example, if a firm is within the scope of this legislation, it is looking at physical security costs of perhaps £114,000 and cyber security spending—potentially of £190,000 a year. The impact assessment could not say how many SMEs may be designated within this legislation. All of that uncertainty is a cost, because it means that, if firms are uncertain about whether they are going to included, they may delay investment. In fact, they may overprepare; they may take on additional costs, which has wider implications to the UK economy, or they may walk away from public services. They will not want to go for these contracts because of the risk they may fall under this legislation, and that could potentially cause the same grit in the wheel of the economy that was seen in IR35. There is a case here for providing in the Bill at least some additional definition on what a critical supplier is; that is what my amendment intends to do.