Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Graeme Downie Portrait Graeme Downie
- Hansard - - - Excerpts

As ever, my hon. Friend is correct. How many of us have had some bit of technology break because the firmware is no longer allowed to be updated, meaning that something no longer works, it is no longer supported and it breaks down immediately?

To add to that, by its nature, something that is not regularly updated becomes more vulnerable to attack by hackers. They may not be state sponsored, but they may take advantage of a weaker part of a technology. That was pointed out to me on a recent visit to Taiwan. Its semiconductor industry is incredibly strong, but it builds the more high-tech elements of semiconductors. I was told that it would not bother to commit to manufacturing other types of technology because they were too cheap and simple to make and could be mass produced. On that note, I refer to my entry in the Register of Members’ Financial Interests about the trip to Taiwan. I did not intend to raise it during my speech, but there was an opportunity to do so.

The third element of risk is data extraction, as was mentioned by the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). Under the Chinese national intelligence law, companies and organisations are legally required to assist state intelligence agencies and to hand over data upon request, creating a systemic risk in the UK that any data accessible through a cellular internet-of-things module could ultimately be accessible to the Chinese state.

Modern vehicles, especially electric and autonomous vehicles, are effectively computers on wheels, continuously collecting data on drivers, surroundings and infrastructure. The US Select Committee on China recently warned that Chinese EVs are “rolling data collection devices” and argued that restricting Chinese-made components is a national security imperative. The US Department of Commerce has now moved to limit the deployment of software and communications equipment sourced from adversary Governments in connected vehicles. Those who are worried about China’s reaction to such measures should be aware that it has already taken precisely these steps against the west. Tesla cars have been banned not just from entering Chinese defence, bases but from various Government agencies and authorities.

In the meeting mentioned by my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), I was concerned that there was a suggestion by one of the officials that there was no need to concern ourselves about the threat of Chinese internet-of-things modules because the threat was merely “theoretical”. As I and others have shown today, these examples are not just theoretical. Frankly, most threats are theoretical until they are not theoretical. This is happening now across critical sectors and national infrastructure. Other countries, such as the US, Australia and those in the EU, are all moving to toughen up their legislation specifically on cellular internet-of-things modules, and I believe that the UK must take action as well.

My amendments would ensure that the Bill explicitly covers these risks and gives Ministers the clarity and authority to act when necessary. If this Bill is to truly strengthen the UK’s cyber-resilience, it must not leave one of the most serious threats to our modern and increasingly digital world outside its scope. I ask the Government to work with me to address the threat of cellular IOT modules.

Melanie Ward Portrait Melanie Ward (Cowdenbeath and Kirkcaldy) (Lab)
- View Speech - Hansard - -

Madam Deputy Speaker, I hope you will not mind if I take a moment to reflect on the fact that today is the 10th anniversary of the murder of our dear friend Jo Cox. I was lucky to serve alongside Jo on the board of the Labour Women’s Network and we had done similar kinds of work previously. I often sit here in the Chamber and look at Jo’s shield and wonder what she would have made of the state of our politics, our country and our world today. I think about how much better we would be if she was still here to contribute. Jo’s most famous words matter so much today—that we

“have far more in common than that which divides us.”—[Official Report, 03 June 2015; Vol. 596, c. 674-65.]

As my hon. Friend the Member for Midlothian (Kirsty McNeill) said today, holding on to Jo’s words and keeping her spirit going matter always, but they matter even more when it is difficult to do that. I hope that Jo’s family and friends, and those closest to her, know how much she is missed and that we strive to carry her light forward with us.

--- Later in debate ---
Helen Maguire Portrait Helen Maguire (Epsom and Ewell) (LD)
- Hansard - - - Excerpts

In my view, this Bill does not explicitly reference misinformation or disinformation threats. I have just met with the Council for Countering Online Disinformation, and in that meeting I learned that X’s algorithm amplified misinformation and disinformation online about the riots that took place in Epsom. Does the hon. Member agree that it is really important that we add strong safeguards against misinformation and disinformation into the Bill?

Melanie Ward Portrait Melanie Ward
- Hansard - -

I certainly agree. Misinformation and disinformation are a huge challenge to our democracy and our country. We know that many enemy nations, such as Russia and Iran, are seeking to exploit loopholes, and I believe the Government have to take further action on that, for sure.

We should not wait to find out whether AI has the potential to damage our critical national infrastructure; we know that in some cases it does, and we should be prepared for it. “Catastrophic risk” includes harm to critical infrastructure, national security or a severe, large-scale harm to human life. Governments should have the power to prevent those risks from coming to pass. It is our No. 1 duty to keep our citizens safe. In a speech in April, the Secretary of State argued in favour of greater AI sovereignty in the UK, and kill switches would provide exactly that—sovereign control over the most dangerous risks posed by artificial intelligence.

New clause 12 includes proportionality and accountability, and the costs of implementing kill switches on data centres would be minimal, particularly in comparison with the financial losses associated with major cyber-attacks; we have heard more about that from many of my hon. Friends in this debate. It would ensure that there is parliamentary reporting within seven days of any direction from the Secretary of State and a debate in this House at the earliest opportunity. Any operator served with direction would have an immediate right to receive a High Court review.

We are elected to this House first and foremost to keep our nation safe. AI developers are moving at a pace far, far faster than Governments, and they are racing towards superintelligence. It is crucial that if—or, more likely, when—that is achieved, we have the right safeguards in place to avoid catastrophic outcomes. That is a crucial part of our national resilience and an issue that I and others who are present today continue to speak about, because it badly needs more attention.

New clause 12 does not seek to stymie the development of AI systems that could bring radical benefits to our society. Instead, it provides the Government with a suitable mechanism to stay ahead and in control of real threats to our critical national infrastructure. That is why I support the new clause and hope that the Government will do the same. If not, I ask the Minister to set out how the Government plan to ensure that we have these powers, which are so clearly needed.

Chris Vince Portrait Chris Vince (Harlow) (Lab/Co-op)
- View Speech - Hansard - - - Excerpts

I thank all my hon. Friends and all hon. Members who have contributed to what has been a really good and well-meaning debate. People will be relieved to know that I intend to keep my contribution fairly brief. I say to the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith) that I do not pretend to be an expert when it comes to cyber-security and resilience, although other Members across the House would say that that has never stopped me talking before.

It was a pleasure to be on the Bill Committee for this legislation; in part, I think that was because of the very constructive nature of conversations in Committee. As the shadow Minister in particular will know, I sat very passively throughout Committee and said very little, which is common for me. This is a really important piece of legislation. As Members across the House have rightly said, it is the first duty of any Government to protect their citizens. There are obviously huge benefits as we move forward into a more technologically advanced world, but there are also real challenges, and as a country we need to be ready for them.

It was also a pleasure in Committee to have the opportunity to mention my father-in-law, Professor Robin Bloomfield—not least because I need all the brownie points that I can get—who is a professor of cyber-security at City St George’s, University of London. Let me also reference the fact that I have a data centre in my constituency, the Kao data centre; it is named after Charlie Kao, who, along with George Hockham, created the fibre-optic cable in Harlow. It is fair to say that I have some skin in the game in terms of the importance of this legislation.

When I looked through the list of amendments, the first thing I thought was, “The Liberal Democrats have been busying themselves.” I say genuinely to them that I welcome conversations about the need to protect local government and electoral services. Although I do not think that necessarily has to be covered in this legislation, I hope the Minister has listened to the comments made by the Liberal Democrats. We can absolutely come back to that conversation in this House, because it is hugely important that our democratic services in particular are not eroded by bad state actors, as has been discussed previously.