Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport
She asked the Minister to say how he intended to assess a threat that the Government were not measuring. I confess that I have not recorded the answer from the Minister but, even if I cannot get an answer on that particular second-hand question now, we on these Benches share, along with the noble Baroness, Lady Kidron, the deep concern at our vulnerability to external shocks. We need a bit of reassurance that the Government are thinking about how we can better protect ourselves against all these external events. On Amendments 83 or 166, it would be good to hear a positive response from the Minister.
Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

My Lords, I shall speak in support of Amendment 83 in the name of the noble Baroness, Lady Kidron, to which I have added my name. In my speech, I will focus just on the aspects of the digital sovereign strategy that are relevant to the NHS. I speak as someone who held an honorary contract with the Oxford University Hospitals NHS Foundation Trust until November 2025, enabling me to be a co-investigator on research projects involving patient data.

Cyber attacks against NHS trusts and their supply chains occur with very high frequency, from regular automated phishing attempts, which are blocked daily, to major incidents causing significant clinical disruption. Health and social care consistently rank among the top sectors reported for cyber incidents and data breaches to the ICO. I am sure that we all remember the WannaCry cyber attack in May 2017, which affected 81 of our 236 NHS trusts at the time, causing nearly 20,000 appointments to be cancelled in a week.

Less than two years ago, in November 2024, there was a major cyber attack against the Wirral University Teaching Hospital NHS Foundation Trust, which compromised the trust’s electronic patient record. I know that EPR well as we have the same EPR in Oxford: Cerner Millennium. As a result of the cyber attack, staff in the Wirral hospitals lost all access to patient records, electronic prescribing tools and diagnostic results. All elective surgeries and outpatient appointments across the trust had to be cancelled, and members of the public were told not to use the emergency department at one of the hospitals in the trust. All clinical systems remained completely offline for nine days.

I mentioned the EPR Cerner Millennium. Cerner is now part of Oracle Health. Together, Oracle and Epic, both of which are US companies, account for about 40% of hospital EPR contracts in England and Wales. In primary care, EMIS software manages just under 60% of the patient records—the records of 35 to 40 million patients across England and Wales. EMIS was bought by Optum, part of the UnitedHealth Group, in 2023, but, in March this year, the UnitedHealth Group sold Optum to a US private equity firm, TPG, for just under £300 million. I will come back to that briefly later.

In 2023, NHS England and the Department of Health and Social Care launched a 2030 cyber security strategy. The noble Lord, Lord Markham, when he was a Health Minister, wrote the foreword—he will remember this, I am sure—to the strategy document. In it, he wrote—we all agree with him, I am sure—that

“the cyber security of our health and social care … underwrites patient safety”.

The group director for cyber security for the DHSC has recently written to all NHS trust boards informing them that, from this month, September 2026, new cyber policies will be included in the next data security and protection toolkit, covering issues such as multi-factor authentication, high-severity alerts and endpoint detection. There is nothing about AI, which is perhaps the subtitle of this Bill—something that will, I hope, have been removed by Report. Yet we know from Tuesday’s debate and last week’s open letter from 100 companies, including large tech firms, that AI-enabled cyber attacks are about to become more widespread and more sophisticated within months.

This prompts three questions. First, are officials from the Minister’s department, which has overall responsibility for cyber security, co-ordinating with the cyber security group in the DHSC—especially with respect to the latest threats from AI agents?

Secondly, have the recent reports from the AISI been communicated to the cyber security group in the DHSC, and have their implications for the NHS been discussed with them? I note here that the new Minister for Science and Innovation, Chris McDonald MP, is a Minister in both the DBIST and the DHSC, so I am hopeful that the answer to these two questions might be yes.

Thirdly, given the high prevalence of foreign ownership of companies, such as Epic and TPG, that are responsible for managing patient data within the NHS—notwithstanding the single-supplier agreement with Palantir, another US company, for the Federated Data Platform—has the Minister’s department assessed the risk to relevant network and information systems as a result of our technological dependence on these companies?

What I have described for the NHS also applies to other sovereign data assets such as those held by the BBC or the Met Office. If the full value to the UK of these sovereign data assets is to be realised as part of the Government’s growth strategy, we need to be optimally protected against cyber attacks, including AI-enabled attacks. For that to happen, we need a coherent digital sovereign strategy across government departments, led by the Minister’s department.

Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.

I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.

It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.