Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Vaizey of Didcot Excerpts
Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- View Speech - Hansard - -

My Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister—which is almost as surprising as learning that I was once the Minister of Fashion.

Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area.

As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate these important issues of the fact that we have world-leading expertise that can contribute to the growth in our economy. When we talk about the defence investment plan, for example, it is important to talk about the huge opportunities we have to create great defence tech companies. Nor should we lose sight of the opportunity to create great British cyber security companies, which goes to the whole debate about potential sovereignty and giving us our own capability.

Let me begin by echoing a number of speeches about how important it is to work in lockstep with our EU partners. It is a piece of irony that this legislation emerges in effect from a European directive that we were beginning to debate when I was the Cyber Security Minister. In fact, the legislation is necessary because we can no longer transpose European legislation directly into British legislation. The noble Baroness, Lady Ludford, mentioned the GDPR, and it is a fact that Brussels can often take the lead in regulation such as this, and that big multinational companies tend to look at the biggest regulatory space in order to adhere to it. So it is important that we are mindful of how Brussels plans to proceed in this area, even if we find areas where we can be more flexible.

People have talked about our bad record in the UK on cyber security on account of cyber security attacks. I suspect that that is because we remain, I think, the most digital nation in the EU, and the English language as well provides us, weirdly, with some kind of vulnerability. But we are at the forefront of cyber security attacks, and it is important that we have the legislation and the bodies capable of responding to them.

Several themes have emerged. When I was the Cyber Security Minister, we began preparations for the National Cyber Security Centre: I thought that was incredibly important. I used to have a mantra that business in particular needed one front door that it could walk through to get the advice and expertise it needed to draw on to protect itself. We have talked constantly in this debate about 12 regulators, and I echo the calls to provide a uniform platform that can read across all the regulators, and they can add on top of that any sector- specific needs they meet.

I also recognise the calls from many noble Lords to say that this is perhaps an artificially constrained Bill, focusing on only a few vital sectors that are important to protect, instead of, as it were, seeing the whole picture and understanding, as many noble Lords have said, that cyber security pervades everywhere. There are so many ways in which we should look to protect ourselves in this age, one of which, of course, is in not losing sight of the hardware. The Minister spoke about software as a service. It is very important to remember that many of our public service providers, for example, still rely on ageing infrastructure, which provides huge vulnerabilities to cyber security attacks. I wonder whether the Government have a strategy to update much of the hardware that is still being used.

I was also interested in the remarks made about how vendors of software should be accountable. That is a very important avenue to explore: perhaps we could introduce kitemarks and audits of software providers to ensure that they are providing cyber-secure software that is as robust as it can be—again, as the noble Baroness said, we can count on the fingers of one hand the main providers of the software that is used in a vast number of businesses—and that they also work with us, as it were, to be on the front line.

It is interesting that this issue has become one of sovereignty. I am fascinated by the debate on the use of Palantir, for example. Personally, I have no problem working with Palantir. I think it provides a vital service, and I hope that the Government will be cautious in listening to the siren calls of people who say “Don’t work with these companies” simply because they disagree with the slightly bizarre views of some of their chief executives. Nevertheless, it perhaps calls for the Government to have a consistent story on this.

One thought that occurred to me during this debate was what has happened to the debate about encryption? This is a dog that no longer seems to be barking. In the last few years, we have had a vigorous debate on potential backdoors to encryption and security services being given, as it were, cyber keys to access encrypted services such as WhatsApp and Signal, and we saw a big pushback from the tech industry on how that would create big cyber vulnerabilities. I wonder whether the Government have come to a settled view on that.

Returning to the theme of the opportunities for the economy, the need to invest in cyber skills in our workforce is absolutely vital. We need to create a cyber workforce and a cyber defence force that work to protect the country, as well as giving companies the kind of skills base they need to make themselves secure. I echo the call from the noble Baroness, Lady Ludford, about boards. I was astonished to read in the House of Lords Library briefing that the number of board members with a responsibility for cyber has apparently fallen. I do not know if that is true, but I wonder whether it is possible to work with business bodies such as the IoD and the CBI to make it a strong corporate governance recommendation that every board should have somebody with a responsibility for cyber.

As I said at the beginning, this is a partnership: it is business, as much as government, that will protect us from cyber. For example, there has been reference to the insurance industry. One of the best ways we can ensure that companies invest in cyber security is to make it mandatory for them to get cyber insurance—which you cannot get unless you put cyber-secure measures in place—and to employ law firms to protect themselves from liability and to put in place important cyber measures.

I have not had a chance to support the noble Lord, Lord Clement-Jones, in his 50-year call for ethical hackers to be allowed to hack. I also echo the earlier call to hear the Minister’s views on the rise of bots and their impact on cyber security.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - - - Excerpts

My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes.

I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

To Ministers, indeed—to my noble friend himself. In those days, the National Cyber Security Centre did not exist—I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped.

That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not think that that has changed. I think that unless we make it mandatory to report, people will not do it.

I was surprised at the time, in 2015, that had Sainsbury’s or Tesco been hacked, I would not have had to tell anybody—I had just come from Sainsbury’s in my previous job. It is really depressing, 11 years later, to see that retail is still excluded. I cannot quite understand why water is “essential” but food is not. I think that Covid taught us that our food retail supply chain is an essential service, and those who work in it are essential workers.

Managed service providers are in, but generative AI is out. Only a decade ago, that might have been OK, but it is not now. In the other place, the Minister said there are powers in the Bill so that we can get it right in the future. Well, we need to get it right now, and we also need the powers to try to keep up. I am not against giving Ministers the power to keep this live, but that is not an excuse for not being up to date today. As other noble Lords have said, it looks, sadly, as though the EU has got this more right than we have. We should be humble enough to admit that, rather than be afraid and insist on doing the wrong thing.

The other area I have some lived experience in, which, again, has been mentioned by other noble Lords, is the challenge of 12 NIS regulators and the lack of join-up. When the TalkTalk hack happened, we immediately stood up a series of workstreams—the obvious things such as trying to work out what had happened. That is the biggest problem with a cyber attack—you genuinely do not know whether you have been attacked by a nation state or kids in a bedroom. You somehow hope it might be the former, but more often than not it turns out to be the latter. So you have to know what has happened and you have to start communicating before you know what has happened. That is two workstreams. You have to work out how to get your systems back up again. That is another workstream. Even 11 years ago, without any of these additional regulators, we had to have a “communicating with regulators” workstream.

Now, spare a thought for the poor managed service providers. They are companies that serve transport, telecoms, energy and the NHS. I think they might have a full house. If you were a managed service provider that was the victim of an attack, you would probably have to deal with all 12 regulators. Those of us who have been here for a while know that if you give 12 different public sector bodies the ability to define terms, they will define them in 12 different ways and have 12 different forms. That will stop you, in the first day or the first week of a cyber attack, doing the things that you should be doing to try to protect your customers. As an expert through lived experience, I plead with the Minister: join-up is essential. It should not be optional. We all know it is hard to do. If you do not sort it out in the Bill, it will not happen. Please do not make that join-up a forum.

I can take myself back to October 2015 and imagine having to communicate with—as much as I love it—the DCRF. If we had had to convene a meeting of 12 regulators in the heat of the crisis to work out what to do, that would not have helped anybody. So we need either a single regulator, as the noble Lord, Lord Birt, so eloquently set out, or a lead regulator, as I know the Government are looking at in a number of other areas, to try to reduce the burden of regulation. I very much support what my noble friend Lord Effingham said: regulation does look like it is necessary here but we need to be careful that we are not just layering burden upon burden, and doing it 12 times most definitely is.

I feel I have said nothing original at all but have said it possibly from a unique perspective. I am rare among former chief executives who have experienced a cyber attack in that I am willing to talk about it, which is exactly why this legislation is important. But I very much hope that, as with so many tech issues, the Minister will hear that we agree more than we disagree and that we could work together to improve the Bill, as this House is often quite good at doing.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Vaizey of Didcot Excerpts
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.

I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.

Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?

Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.

I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - -

My Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.

I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.

The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

My Lords, I very much hope that the Government will accept the amendment in the name of the noble Baroness, Lady Northover. It strikes me as a practical and important contribution to the Bill.

In addition to the points that have already been made by noble colleagues, there is one more thought to be added: one of the weaknesses of the present marketplace in which these skills are operating is the cost and affordability of advice and help for SMEs on security issues. It is costly—security does not come cheap. Many of these small businesses that nevertheless provide sophisticated services are up against it when it comes to making an adequate profit to stay in business. Therefore, a source of guidance and help, of the kind that is being suggested by this structure, would make a real contribution to not only the viability of these small firms but the general security of cyber security services.

We should never forget that these SMEs feed into the bigger ones. Often, it is an outlying service being provided to a bigger provider that is the cause of a fault or of an essential service proving insecure. Helping SMEs in this way would not only make them more secure but make the market generally more secure. This is a very important and helpful amendment, which I hope the Government will accept.

--- Later in debate ---
Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - -

My Lords, I rise early to support the amendment from the noble Baroness, Lady Northover, partly to spare the stress of the noble Lord, Lord Clement-Jones, and also because there is a Liberal Democrat amendment imminent in the Chamber, although we of course will be abstaining—our solidarity with the Liberal Democrats does not extend too far.

However, it does extend to this amendment, which ties in well with the noble Baroness’s earlier amendment concerning qualifications. I was fascinated to hear her referring to the Australian cyber service, which I had not heard about before. I would be fascinated to know more and it would be interesting to hear from the Minister what other lessons there may be for us to learn from similar jurisdictions around the globe. I suspect the Canadians, for example, some of our European partners and some of the south-east Asian nations, such as Singapore or South Korea, will probably have very advanced and sophisticated bureaucracies, if I can put it that way, or institutions looking at the cyber threat.

Again, I shall address, rather than the technical detail of the noble Baroness’s amendment, the spirit in which it is brought and why it fits so well with her earlier amendment. It is about injecting a sense of urgency into how we raise our game in cyber in terms of our economy. When she mentioned the cyber action toolkit, it took me back to the days when I was one of the Cyber Ministers in the coalition Government. My responsibility was towards small businesses, and we launched endless small business toolkits, mainly because we wanted to say that we had launched a small business toolkit. We certainly never put in place any mechanisms for auditing its impact or success, and I think the constant references to about 7% of SMEs now having cyber policies in place may point to my abject failure in that role, and perhaps that of some of my successors.

The more I have listened to this debate, the more it takes me back to my childhood, when we would get leaflets about a possible nuclear conflagration. I know that Ministers and the Government are now telling people to stockpile water and baked beans because of the impact of El Niño, but we know that a cyber attack on the UK would cripple our economy and essential public services, so it is akin, given the geopolitical situation, to a national emergency.

The noble Baroness mentioned the views of the Association of British Insurers. Again, that was part of the toolkit. The feeling was that professional services would drive small businesses towards becoming more skilled in assessing their cyber risks, that you could not get insurance, or indeed cyber insurance, unless you had clear policies to deal with cyber attacks. With professional services firms, you could not necessarily get legal liability insurance for a data breach, which is not necessarily going to cripple your business but will affect your customers and therefore leave you open to liability, unless you could demonstrate that you had proper processes in place to protect your data. There is a whole ecosystem, it seems to me, that needs to be brought to bear to support the uptake of cyber skills and cyber audits by small businesses: we cannot be complacent and assume that 7% is an acceptable figure and that it should be allowed to evolve.

To a certain extent, the noble Baroness’s amendment is about the after-effects: if you suffer a cyber attack then you should be able to call on skilled people, whom we hope will have achieved the kind of recognised qualifications that the noble Baroness talked about earlier. She compared them to doctors but, when I thought about the amendment, I thought more about plumbers and electricians and the technical qualifications that you need to have to do a technical and difficult job.

We also need to look at what happens before. How do we increase the number of small businesses that put in place policies that will protect them from cyber attacks? That involves using the private sector, insurance companies and professional services firms to push forward clear protocols to which small business should be expected to adhere in order to receive the cover that they need to carry on doing business.

Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - - - Excerpts

My Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.

There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.

Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.

I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.

--- Later in debate ---
We cannot allow a “compliance first, justice second” culture to take root. If we are to grant the Executive these sweeping, unprecedented powers, we must match them with equivalent modern and constitutionally sound safeguards. We must ensure that the citizen and the business are protected by a full, merits-based process, as recommended by our own Constitution Committee. I urge the Minister to accept this vital constitutional correction, and I beg to move.
Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - -

My Lords, in addressing the amendment in the name of the noble Lord, Lord Clement-Jones, I may increase his stress levels, unfortunately, as I oppose it. This means, I guess, that I am supporting the Government—that is, unless the Government are going to perform a volte-face in the face of the noble Lord’s strong arguments for a merits-based review of any decision reached by the First-tier Tribunal.

I do so because it brings back memories of when I was the telecommunications Minister and was, therefore, responsible for Ofcom. At the time, all Ofcom decisions were subject to a merits-based review in front of the Competition Appeal Tribunal, which meant that, in effect, every decision it took regarding broadcasters or telecoms companies was reheard at appeal. As noble Lords can imagine, technical decisions on the charges being levied by wholesale carriers—or, in the case of Sky, the charges being levied on other broadcasters to carry, for example, the Premier League—were extremely complex, and Ofcom faced an army of lawyers deployed by those companies.

Without wishing to give away too many confidences—this was 10 years ago, so I do not think it is a matter of national security—Ofcom found itself extremely frustrated by all this. It was costing millions and millions of pounds. It was being used by commercial providers as a delaying tactic, a firepower tactic, almost, in order, understandably, to put off decisions that were not in their commercial favour. I initially resisted Ofcom’s blandishments to say that we should move away from merits-based appeals, partly because I thought that we would just start a whole new process of the courts feeling their way under the new system and would end up with a whole new set of delays as the courts had to make novel decisions under a novel regime.

However—one of the great telecom chief executives, my noble friend Lady Harding, has just walked into the Committee right on cue; I do not think, though, that she ever used her firepower in the cynical way that others did against Ofcom—the changes did go through. As far as I am concerned, although I have not done my homework properly, things have settled down into a straightforward process whereby a regulator makes a decision based on the facts and, if that decision can somehow be seen as unlawful by the company in question, it can be judicially reviewed.

It must be stressed that removing merits-based appeals would not remove the right of appeal. It seems fairly obvious to me that, as in civil and criminal cases, decisions would be arrived at based on the facts. However, if that decision were somehow so outside the normal judicial process of making a decision and so irrational, as it were—which is what judicial review exists to review—then it could be reviewed. That system should be consistent across regulatory appeals. I cannot necessarily comment on the effective points made by the noble Lord, Lord Clement-Jones, about the clandestine nature of some of the findings, but it may well be that, given the issues to do with cyber security, attacks on critical national infrastructure and so on, some elements of cases must be kept confidential. That is a matter for further debate, perhaps, but I would be extremely concerned if we were to go back to merits-based reviews for regulatory appeals.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this important group and all noble Lords for their contributions. Beginning with Amendment 148A, it is reasonable to suggest that there should be a further right to appeal, given that we are talking about potentially large penalties of ÂŁ17 million or 10% of annual turnover. But, like my noble friend Lord Vaizey, I have concerns about whether the Upper Tribunal system can handle such a process. Right now, it has an open case load of over 800,000, which is a 19% year-on-year increase, and disposals have decreased by 4%. As such, I am hesitant to offer my support without being assured that further pressure will not be placed on tribunals and that this is a workable mechanism.

Amendments 174A and 174B, in my name and those of my noble friends Lord Camrose and Lord Holmes of Richmond, would require the Secretary of State to establish a register of foreign powers posing a cyber security risk to this country, and to review and report on the extent of the risk posed by powers on that list. Part 4 gives the Secretary of State significant new powers to intervene where the use of vendors’ goods and services or facilities pose a risk to national security. We support that objective. A power of that kind is only as good as the intelligence that informs it. At present, the Bill is silent on how the Secretary of State is to identify, in a systematic and transparent way, which foreign powers actually present that risk.

Amendment 174A aims to fill that information gap, outlining a thorough set of criteria for inclusion: a state confirmed by GCHQ to have perpetrated or attempted a cyber attack against the UK in the preceding seven years—one directed at an operator of an essential service or a critical supplier and carried out through a state department, agency or affiliate—or a state that GCHQ has separately warned poses a risk to such systems.

The importance of ensuring that we are fully informed of foreign threats can hardly be overstated. Just this year, the NCSC’s chief executive reported that three-quarters of all attacks on our critical national infrastructure over the preceding 12 months were carried out by hostile states, with Russia, China and Iran named specifically. The NCSC’s annual review recorded 204 nationally significant incidents in the year to August 2025—more than double the previous year, with 18 rated highly significant.

For illustration, the cyber attack that last month shut down a British power plant is reported to have been committed by Iran-backed hackers. Over the course of the last Parliament and this one, China has targeted Parliament and compromised the Electoral Commission; Russia’s FSB has targeted British parliamentarians and successfully stolen and leaked politically sensitive documents; and Iranian state actors have targeted British politicians, Governments and defence with sustained cyber espionage campaigns.

We are seeing a surge in cyber attacks driven largely by foreign threats. If the Government are serious about security and resilience, tackling foreign interference must be a priority. As a start, a published criteria-based register would bring much-needed transparency and rigour to the process. Amendment 174B seeks to achieve such transparency. It would require the Secretary of State, for each foreign power added to the register, to conduct a review of the extent and nature of the risk that that power poses. It also includes a built-in safeguard for the Government: where the Secretary of State considers that laying their report would be contrary to national security interests, they may instead make a Statement to Parliament confirming that the review has taken place and explaining that it cannot be published. It attempts to strike a balance between accountability and the sensitivities that intelligence assessment of this kind will naturally carry.

I anticipate that the Minister may say that such a register already exists in substance within government and that formalising and publishing it risks informing those very powers of the extent of our knowledge. I gently observe that the amendment does not require publication of intelligence sources, substance or methods—only the fact of designation against published criteria and a review to assess the risk. Given the scale of the threat that the NCSC describes and, given the very significant powers that this part confers on the Secretary of State, I believe that Parliament is entitled to ask that those powers rest on a clear, evidenced and reviewable basis. I look forward to the Minister’s response.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act.

This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them.

The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator.

I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation.

Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act.

During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege.

There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems.

Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security.

Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate ÂŁ2.5 billion in additional revenue for the UK economy.

We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can?

When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - -

My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.

The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.