Debates between Victoria Collins and Judith Cummins during the 2024 Parliament

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Victoria Collins and Judith Cummins
Victoria Collins Portrait Victoria Collins (Harpenden and Berkhamsted) (LD)
- View Speech - Hansard - -

I beg to move, That the clause be read a Second time.

Judith Cummins Portrait Madam Deputy Speaker
- Hansard - - - Excerpts

With this it will be convenient to discuss the following:

New clause 3—Review of high-risk bodies—

“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies.

(2) A review under this section must assess—

(a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise;

(b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and

(c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities.

(3) In this section—

“relevant body” means—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier,

within the meaning of the NIS Regulations.

“foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest;

“network and information systems” has the meaning given by section 24(1).”.

This new clause would require the Government to review the security risks posed by critical suppliers and essential service providers linked to foreign states and evaluate whether current powers are sufficient to address these threats.

New clause 4—Critical manufacturing and retail sectors

“(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities—

(a) the manufacture of critical transport equipment;

(b) the industrial production and processing of food products; and

(c) the retail sale of food and essential goods via large-scale distribution chains.

(2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors.”.

This new clause would require the Secretary of State to designate the manufacturing of critical transport equipment and retail of food and essential goods (when part of a large-scale distribution chain) as essential activities, bringing them within the scope of Part 3 of the Bill.

New clause 5—Local authorities to be regulated as essential services

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—

“Local Government

Local Government

The Secretary of State for Housing, Communities and Local Government”



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—

“The Local Government Sector

12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector.

(2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register.

(3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records.

(4) In this paragraph “local authority” means—

(a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly;

(b) in Wales, a county council or a county borough council;

(c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994;

(d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.”.

This new clause would bring local authorities within the scope of the NIS Regulations as operators of essential services in relation to their functions managing electoral rolls and social care records. This ensures that public sector bodies holding sensitive data such as electoral rolls and social care records are subject to the same statutory protections as other critical infrastructure.

New clause 6—Computer Misuse Act 1990: security and resilience of network and information systems

“(1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities.

(2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines—

(a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review;

(b) the review’s conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and

(c) the Government’s intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”.

This new clause would require the Secretary of State to review, within 12 months, whether amending the Computer Misuse Act 1990 could improve the resilience of network and information systems, and to report the government’s intentions to Parliament.

New clause 7—Consultation on resourcing of regulatory authorities and regulated persons

“(1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing—

(a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and

(b) whether further government support is needed.

(2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1).”.

This new clause would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations, and whether additional government support is required.

New clause 8—Electoral infrastructure to be regulated as an essential service

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Elections

Electoral infrastructure

The Electoral Commission”



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—

“The electoral infrastructure subsector

12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector.

(2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to—

(a) maintain a register of electors containing more than 50,000 entries;

(b) issue, receive, or process postal ballots for a parliamentary or local government election; or

(c) count or aggregate votes cast in a parliamentary, mayoral or local government election.

(3) In this paragraph—

“parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom;

“network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026.

(4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—

‘(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.’”.

This new clause would designate the administration of elections and maintenance of voter registers as an “essential service” within the meaning of the NIS Regulations.

New clause 9—Political parties to be regulated as an essential service

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Government

Political parties

The Secretary of State for Housing, Communities and Local Government”



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—

“The political parties subsector

12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector.

(2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons.

(3) In this paragraph—

“registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.”.

This new clause would designate political parties as providing essential services for the purposes of cyber security.

New clause 10—Board oversight of security and resilience of network and information systems

“(1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body’s network and information systems.

(2) In exercising oversight, the management body must—

(a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems; and

(b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks.

(3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems.

(4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices.

(5) For the purposes of this section, a relevant body is one which is—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier,

within the meaning of the NIS Regulations.”.

This new clause would require active board oversight of, and accountability for, security and resilience measures, where a relevant body is governed by a board or similar body.

New clause 11—Requirement for regular testing of network and information systems

“(1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services.

(2) Testing undertaken in accordance with this section must—

(a) be proportionate, having regard to the size, nature and risk profile of the business; and

(b) be conducted periodically, at intervals that are appropriate to the risks identified by the body.

(3) A relevant body must document—

(a) the outcomes of testing undertaken in accordance with this section; and

(b) any remedial actions required or taken in response to the testing.

(4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request.

(5) For the purposes of this section, a relevant body is one which is—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier,

within the meaning of the NIS Regulations.”.

This new clause would require bodies to carry out proportionate, periodic testing of the security and resilience of their network and information systems and provide the results to regulatory bodies upon request.

New clause 12—“Last-resort” powers in respect of data centres and AI models

“(1) Regulations under section 29(1) may confer on the Secretary of State powers (“last-resort powers”) to direct the shutdown of—

(a) data centres, or

(b) AI systems used or deployed by a data centre,

in the event of an AI security or operational emergency.

(2) For the purposes of this section—

“data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act);

“AI system” means a machine-based system that, from the input it receives, can infer how to—

(a) generate predictions, digital content, recommendations, decisions or other similar outputs, or

(b) influence a physical or virtual environment,

with a view to achieving an explicit or implicit objective;

“used or deployed” means made available to—

(a) a substantial number of individuals within the United Kingdom; or

(b) providers and operators of essential services;

“AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that—

(a) there is a security or operational compromise to one or more relevant network and information systems,

(b) this compromise is caused, or contributed to, by the use or operation of an AI system used or deployed by a data centre, whether through autonomous or non-autonomous means; and

(c) this compromise poses a catastrophic risk;

“catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to—

(a) large-scale disruption to critical infrastructure or essential services;

(b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or

(c) severe, large-scale harm to human life;

“data centre operator” means a person who operates a data centre;

(3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must—

(a) lay a report before Parliament setting out the direction and the reasons for it; and

(b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable.

(4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of AI systems, including relating to—

(a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers;

(b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers;

(c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and

(d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including—

(i) incident reporting; and

(ii) implementation of mitigation measures to prevent recurrence.

(5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4).

(6) Regulations relating to last-resort powers may—

(a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed;

(b) include, for the purposes of paragraph (a), powers to—

(i) close premises;

(ii) turn off systems or require that they be turned off;

(iii) take any other action necessary to control the risk arising from an AI security or operational emergency.

(7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must—

(a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and

(b) inform the operator or provider of their right to apply to the High Court for relief.

(8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including—

(a) confirming, varying or cancelling the requirements;

(b) imposing additional requirements;

(c) ordering compensation.

(9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section.

(10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates.

(11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament.

(12) The causes and potential causes of AI security or operational emergencies considered in any report under subsection (11) must include —

(a) adversarial uses of AI systems by state and non-state actors;

(b) the capabilities for cyber-attacks by autonomous AI systems; and

(c) the development of AI systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent AI”.”.

This new clause would enable the Secretary of State to be granted “last-resort powers” to ensure that the government can intervene in case of an emergency caused by AI used or deployed by a data centre which can cause large-scale harm.

New clause 13—Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies

“(1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy (“a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by—

(a) assessing, managing and mitigating risks—

(i) associated with foreign interference,

(ii) arising from reliance on foreign-supplied technologies, and

(b) preventing over-reliance on foreign providers by building domestic capacity.

(2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier, within the meaning of the NIS Regulations.

(3) A Digital Sovereignty Strategy published under this section must—

(a) include risks associated with—

(i) hardware,

(ii) software,

(iii) supply chains, and

(iv) procurement processes;

(b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption;

(c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and

(d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems.”.

This new clause would require the Government to publish a Digital Sovereignty Strategy setting out how it intends to address risks to relevant network and information systems posed by foreign interference and reliance on foreign technologies, including by supporting the use of domestic technologies.

New clause 14—Register of foreign powers for the purposes of Part 4

“(1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom’s critical network and information systems.

(2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups.

(3) Regulations under this section are subject to the affirmative resolution procedure.

(4) In this section, “foreign power” means—

(a) the sovereign or other head of a foreign state in their public capacity;

(b) a foreign government, or part of a foreign government;

(c) an agency or authority of a foreign government, or of part of a foreign government;

(d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or

(e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government—

(i) hold those posts as a result of, or in the course of, their membership of the party, or

(ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”

This new clause would require the Government to maintain a register of state actors posing a threat to UK cyber security for the purposes of exercising the Secretary of State’s powers under Part 4 of the Act, which enable the giving of directions in the interests of national security.

New clause 15—Review of the cyber security risk posed by foreign powers

“(1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers.

(2) A review under this section must identify whether any risk arises from—

(a) activities undertaken outside of the UK, or

(b) foreign owned or controlled infrastructure or locations within the UK.

(3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups.

(4) Within three months of each review under subsection (1), the Secretary of State must—

(a) lay before Parliament a report containing the findings and conclusions of the review; and

(b) where information is not included in a report on the grounds of being prejudicial to the UK’s national security, send such information to the Intelligence and Security Committee of Parliament.”

This new clause would require the Government to report on the risk to relevant network and information systems posed by specified foreign powers, considering whether such risks arise from extra-territorial activities and/or UK infrastructure or premises owned or controlled by foreign powers.

New clause 16—Digital Sovereignty Strategy (relevant network and information systems)

“(1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems.

(2) The Strategy must—

(a) set out the Government’s assessment of the risks to relevant network and information systems arising from or related to—

(i) dependence on hardware, software, or digital services that may be subject to foreign interference;

(ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers;

(iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities;

(b) technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems;

(c) set out the Government’s approach to mitigating the risks identified under subsection (2); and

(d) include an assessment of—

(i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems;

(ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems;

(iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems;

(iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems;

(v) options for international collaboration in the production of open source components used in relevant network and information systems;

(vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems.

(3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security.

(4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen.

(5) In this section—

“relevant network and information system” means a network and information system belonging to—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier,

within the meaning of the Network and Information Systems Regulations 2018;

“digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend;

“open source” has the meaning given to it in the definition published by the Open Source Initiative.”

New clause 18—Review of the number of bodies providing cloud computing services

“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services.

(2) For the purposes of this section, “cloud computing services” has the meaning given in paragraph 1 of the NIS Regulations.”

This new clause would require the Government to review the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services.

New clause 19—Review of risks posed by foreign state ownership or control of providers of cellular Internet of Things modules

“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by foreign state ownership or control of providers of cellular Internet of Things modules.

(2) For the purposes of this section–

“cellular Internet of Things modules” means devices that communicate over public mobile networks for the purposes of enabling autonomous machine to machine communication;”.

This new clause would require the Government to review the risks posed to relevant network and information systems by providers of cellular Internet of Things modules owned or controlled by foreign states.

New clause 20—Specification of retail commerce as an essential activity

“(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify as an essential activity retail commerce carried out by companies with an annual turnover in excess of £12 billion.

(2) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector.”

This new clause would require the Secretary of State to designate retail commerce carried out by companies with an annual turnover in excess of £12 billion as an essential activity, bringing it within the scope of Part 3 of the Bill.

New clause 21—Food supply chain to be regulated as an essential service

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

“Food supply

Food supply chain

The Secretary of State for Environment, Food and Rural Affairs (United Kingdom)”



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—

“The food supply chain subsector

12 — (1) This paragraph describes the threshold requirements which apply to essential services in the food supply chain subsector.

(2) For the essential service of the food supply chain in the United Kingdom the threshold requirement is that the person is in the food supply chain and does not qualify as small or a micro-entity (or is excluded) within the meaning of Part 15 of the Companies Act 2006.

(3) For the purposes of this paragraph—

(a) a “food supply chain” is a supply chain for providing individuals with items of food or drink for personal consumption, where the items consist of or include, or have been produced to any extent using—

(i) anything grown or otherwise produced in carrying on agriculture, or

(ii) anything taken, grown or otherwise produced in carrying on fishing or aquaculture;

(b) a person is “in” a food supply chain if that person is a producer or an intermediary in a food supply chain.

(4) In paragraph (3)(b)—

(a) “producer” means a person who is carrying on agriculture, fishing or aquaculture;

(b) “intermediary” means a person in the food supply chain between a producer and the individuals referred to in paragraph (3)(a).

(5) In this paragraph—

“agriculture” includes any growing of plants, and any keeping of animals, for the production of food or drink;

“aquaculture” means the breeding, rearing, growing or cultivation of—

(a) any fish or other aquatic animal,

(b) seaweed or any other aquatic plant, or

(c) any other aquatic organism.

“plants” includes fungi.

(6) In regulation 8A of the NIS Regulations (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—

‘(c) provides an essential service of a kind referred to in paragraph 12 of Schedule 2 (food supply chain sector) within the United Kingdom.’”

This new clause would designate those in the food supply chain that rely on network and information systems as “operators of essential services” within the meaning of the Network and Information Systems Regulations 2018, thereby placing them under duties to manage risks to those systems and to provide notification regarding any incidents that have an impact on the food supply chain.

Amendment 1, in clause 8, page 7, line 36, at end insert—

“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,””.

This amendment would explicitly include fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.

Amendment 28, in clause 10, page 9, line 33, at end insert—

“(2A) The measures taken by an RMSP under paragraph (1) must ensure that the number of customers to whom the RMSP provides services does not exceed the critical risk threshold.

(2B) In paragraph (2A), the “critical risk threshold” is the number of customers within a sector or subsector where an incident affecting the provision of services to those customers by the RMSP would result in disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom.

(2C) Paragraph (2D) applies where the number of customers to whom an RMSP provides services exceeds the critical risk threshold by virtue of contracts entered into before the coming into force of section 10 of the Cyber Security and Resilience (Network and Information Systems) Act 2026.

(2D) The RMSP must take steps to reduce the number of customers to below the critical risk threshold, including exercising any right to terminate a contract or vary the terms of a contract.”

This amendment would place a duty on relevant managed service providers (“RMSPs”) to ensure that they do not provide services to manage the technology systems for a number of customers that exceeds a critical risk threshold, such that an incident affecting those services would be likely to result in significant disruption in the United Kingdom. This would prevent an RMSP managing the technology systems for a whole sector or subsector. Provision is also made for a situation where an RMSP is in breach of the critical risk threshold because of contracts entered into before the enactment of the Bill.

Government amendments 7 to 11.

Amendment 6, in clause 18, page 40, line 12, at end insert—

“(8A) Where the CSIRT receives notification of an incident under regulation 11, 11A, 12A or 14E which it considers to materially involve autonomous or adaptive systems based on machine learning, the CSIRT must share relevant technical information with the relevant body within 72 hours.

(8B) For the purposes of this regulation, a “relevant body” means the AI Security Institute or any successor or replacement body designated by the Secretary of State.”.

This amendment would require incident data relating to AI systems in critical national infrastructure to be sent to the body designated by the Government as responsible for AI safety and security.

Government amendments 12 to 14.

Amendment 3, in clause 18, page 41, line 15, at end insert—

“Exemption from disclosure: right to a fair trial

(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that—

(a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or

(b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial.

(2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of—

(a) subject matter experts, and

(b) competent civil society groups.

(3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months.”

This amendment would prevent the sharing of information with overseas authorities for the purpose of prosecuting crimes not committed in the UK if the Secretary of State determines that the receiving country is one in which the right to a fair trial cannot be guaranteed.

Government amendments 15 to 17.

Amendment 4, in clause 29, page 54, line 9, at end insert

“, including the risks arising from the use of embedded communications components manufactured outside the UK;”.

This amendment would make explicit that regulations could concern the risks arising from the use of embedded components within the systems (such as cellular internet of things modules).

Amendment 2, in clause 40, page 63, line 7, leave out “5” and insert “3”.

This amendment would increase the frequency of the reports that must be published under Clause 40, from every five years to every three years.

Amendment 5, in clause 43, page 66, line 18, at end insert—

“(i) a requirement relating to embedded communications components manufactured outside the UK.”

This amendment would provide an additional requirement that may be imposed on a regulated person, in relation to an embedded communications component manufactured outside the UK.

Government amendments 18 to 27.

--- Later in debate ---
Victoria Collins Portrait Victoria Collins
- Hansard - -

I thank the hon. Member for his intervention. I absolutely agree. Across the United Kingdom, including in Northern Ireland, there are incredible British tech firms. Many of them have said to me that their services are being procured by other Governments in Europe and around the world, yet they find their own British Government not using them or getting the value out of that British technology here by developing skills and jobs.

The Liberal Democrats welcome the Government’s hardware strategy, announced last week, which at least acknowledges the importance of British procurement, but acknowledgment is not a strategy. New clause 13, which I am pleased to say has drawn support from across the House, would make it one. In an increasingly unstable world, the case for British digital resilience, British technology and British sovereign capability has never been stronger. I therefore urge hon. Members to vote for the new clause.

Cyber-security is no longer a technical matter confined to server rooms and IT departments. It is a question of national resilience, economic strength and democratic integrity. The Bill before us takes important steps, but important steps are not enough in today’s digital age. With these amendments, we have the opportunity to close the gaps, broaden the protections and build a framework that is genuinely fit for the digital age.

Judith Cummins Portrait Madam Deputy Speaker (Judith Cummins)
- Hansard - - - Excerpts

I call the Chair of the Select Committee on Science, Innovation and Technology.

UK Biobank Data

Debate between Victoria Collins and Judith Cummins
Thursday 23rd April 2026

(3 months, 3 weeks ago)

Commons Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Judith Cummins Portrait Madam Deputy Speaker
- Hansard - - - Excerpts

I call the Liberal Democrat spokesperson.

Victoria Collins Portrait Victoria Collins (Harpenden and Berkhamsted) (LD)
- View Speech - Hansard - -

I, too, thank the Minister for advance sight of his statement, and I join the Government in thanking the volunteers who have given researchers access to deeply personal medical records. A very close family member of mine has recently taken the decision to share medical data—although not with UK Biobank—in order to advance such research. It is not an easy decision, but this is such an important cause. Without the many people who have handed over their data, many of the transformational medical breakthroughs of recent years would not have been possible. That is precisely why what has happened is so serious.

This is not the first leak from UK Biobank. In March, The Guardian reported that sensitive medical data donated in good faith had been posted online without the consent of donors, and records have now been put up for sale on a Chinese e-commerce site. This is a profound betrayal of the people who trusted this institution with some of the most intimate details of their lives. UK Biobank has sought reassurances that no names, contact details, NHS numbers or phone numbers were leaked. That is reassuring, but the dismissal of privacy concerns shows a shocking lack of understanding of how easily individuals can be identified, especially in today’s world of artificial intelligence and social media. I urge the Government to hold UK Biobank accountable, and to ensure that protocols are followed and that confidential patient data is not shared online.

Although we are pleased to see a quick and full response from the UK Government in this instance, volunteers need more. Will the Secretary of State require UK Biobank to provide a full, step-by-step breakdown of how it will reform its data privacy once and for all? We need not just guidance or reassurance, but binding commitments that this will not happen again, and that includes some of the technical elements. We cannot just rely on people’s commitment not to download something; the technical barriers should be there. Will the Government ensure that any new guidance strikes the right balance between enabling vital research and guaranteeing watertight protections for patient data? Such data is vital for research, which is so important for the future.

Finally, has UK Biobank even offered an apology to its volunteers? We cannot find one, so we are calling on UK Biobank to issue a full apology without delay. People gave their data to save lives, and they at least deserve accountability.

Online Harm: Child Protection

Debate between Victoria Collins and Judith Cummins
Tuesday 24th February 2026

(5 months, 3 weeks ago)

Commons Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Victoria Collins Portrait Victoria Collins
- Hansard - -

Absolutely. YouTube is everywhere. It is embedded in almost every website that has videos.

The hon. Member for Aberdeen North (Kirsty Blackman) asked about AI chatbots. In the proposals we put forward in the Lords, the user-to-user services are the AI chatbots. We have highlighted for a long time that potential harms from AI chatbots are not covered. That is absolutely the case, but Ofcom has clarified that AI chatbots are the user-to-user service. The harms, such as AI psychosis, which my hon. Friend the Member for Winchester (Dr Chambers) alluded to, are not covered. That is why the harms-based approach we are putting forward is so important.

As my hon. Friend the Member for Twickenham (Munira Wilson) said when she opened the debate, the Liberal Democrats have been leading the work on online safety in this Parliament. We were the first party to push a vote on banning addictive algorithms. We have called for health warnings and a doomscroll cap. Today, we are calling for a vote on the age for social media and online harms. We are calling for a ban on harmful social media based on a film-style age rating. That harms-based approach holds tech companies to account, sets a pioneering approach to online standards and prepares for the future of AI chatbots and games like Roblox, which has already arrived.

In the offline world, anyone buying a toy for young children at this point would expect age ratings so that they know it is appropriate and safe, and films have had age ratings for over 100 years, yet we have not had that in the online world. The harms-based approach is backed by 42 charities and experts who work to protect children, stop violence against women and girls and make the internet a safer place.

We are also calling for a reset, because enough is enough. That includes a minimum age of 16 for social media and real accountability for tech companies with film-style age ratings. We need to make sure that we get the best out of the internet for young people and protect them from harms.

For me, it comes back to James, his friends and the young women and children I have spoken to around my constituency. We do not have time to waste—that is why we are pushing for these Bills. We are calling for action, and I call on MPs across the House to put children before politics, exactly as we did in the Lords. The amendment in the Lords could mean a blanket ban. We were uncomfortable with that approach—we much prefer ours—but we knew that the future of children came first. We must help the next generation to get the best of the online world—including those young people who have spoken out and shared their concerns and horror stories—and protect them from the worst of it.

Music Streaming: Label-led Principles

Debate between Victoria Collins and Judith Cummins
Tuesday 22nd July 2025

(1 year ago)

Commons Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Judith Cummins Portrait Madam Deputy Speaker
- Hansard - - - Excerpts

I call the Liberal Democrat spokesperson.

Victoria Collins Portrait Victoria Collins (Harpenden and Berkhamsted) (LD)
- View Speech - Hansard - -

Britain’s musicians have long been our most beloved cultural treasures. In the crowded field of excellence in our creative sectors, our musicians are some of our proudest exports. They are part of a £124 billion industry that drives our economy, so support for our legacy and session musicians is completely overdue and very welcome. The musicians covered include the Devines in Berkhamsted, upcoming artists like Myles Smith, and national treasures like Elton John—I agree that Adele is one of our national treasures—and, as was mentioned, all those around them: songwriters, producers, and those who support them.

Technological change means that online streaming now constitutes the vast bulk of music consumption, and 120,000 new tracks a day are uploaded to music platforms. This often leaves a hole in musicians’ income, so it is absolutely right that the Government are taking this issue seriously. We simply need to get this right, so I ask the Minister to clarify for the House how much confidence we can really have that the principles he is spelling out will finally lead to a more equitable distribution of streaming revenue. Ultimately, this is a label-led, voluntary framework; where is the independent oversight? Crucially, what guarantees are there of consistency or enforcement across the industry?

We have raised this issue many times in the past, but it remains true that if we are serious about protecting artists’ right to remuneration, we need to ensure that copyright, which has underpinned success for decades, works in our digitally evolving world. Musicians and creatives face an AI tsunami, which could pose a threat to their livelihoods; we need to tackle it seriously. I conclude by asking the Minister once more to consider swifter action from the Government on copyright and data mining, in order to support our musicians and creatives, as well as innovation across the UK.

SEND Funding

Debate between Victoria Collins and Judith Cummins
Thursday 12th June 2025

(1 year, 2 months ago)

Commons Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Victoria Collins Portrait Victoria Collins (Harpenden and Berkhamsted) (LD)
- View Speech - Hansard - -

I congratulate the right hon. Member for Beverley and Holderness (Graham Stuart) on securing this vital debate. I would like to start with the words of Berkhamsted student Hermione:

“I believe, without a doubt, that the school system needs to change. But more than anything, it needs to change for SEN students—because right now, it is failing them…The system broke me down completely. Instead of supporting me, the system left me feeling isolated and overwhelmed.”

Last week, I met Hermione at Egerton-Rothesay school in Berkhamsted. She has complex needs, and has found solace in her new school after years of struggling. That is why, for her English oral exam, she was compelled to write a piece called “The school system needs to change: especially for SEN students”. She happened to send it to her headmaster on the day I visited. It is an eloquent piece about her experience, and I wish I had time to share it in its entirety. She concludes by saying:

“I know I’m lucky to have the support I do, but it’s still not enough. The system needs to change—not just for me, but for all the students still being let down, and for the future of education itself.”

She calls for improved teacher training, for a more flexible curriculum and assessments, for schools to listen to SEND students and for properly funded and staffed support. I would like to tell Hermione that Parliament is listening, and this debate will dive into why that proper funding is so vital and how it can be improved.

The Government must heed the call of parents and children to tackle this issue head on. The Public Accounts Committee reported in January that despite the 58% increase in the Department for Education’s high needs funding over the past decade, it has not kept pace with demand. The current funding model, which sees top-up funding for students requiring more than £6,000 a year of additional SEND support, has not been updated, even given the changes in real-term value. That is crippling local schools and authorities, with 38 unitary and county authorities having racked up debts exceeding £2 billion this year alone. That has resulted in high-needs spending being consistently higher than available funding by between £200 million and £800 million a year between 2018 and 2022.

Hertfordshire was given the worst rating for SEND provision under the previous Conservative Administration. The funding formula under the Conservatives meant that children in Hertfordshire have been burdened with the third-lowest per capita funding for high needs funding and far less than just next door in Buckinghamshire. A three-year-old in Hertfordshire with SEND needs would have to finish all their formal education before they would get equal funding to a similar child in Buckinghamshire. The new Government must stop this postcode lottery, as eloquently put forward by the right hon. Member for Beverley and Holderness (Graham Stuart), and ensure that those previously left behind get the support they need.

Kyle’s family in Markyate told me that the system treated them not as kids with hopes and dreams, but as just another name on a piece of paper. Jess in Tring made the difficult decision to remove their six-year-old from school to home-educate and told me that seeing their five-year-old struggling was “heartbreaking”. Those are not isolated cases; they reflect the story across constituencies up and down the country, the real consequences of underfunding and the postcode lottery of unfair distribution.

The Liberal Democrats have a clear plan to fix this broken system. We call on the Government: to establish a national SEND body to end this postcode lottery and to fully fund costs above £25,000 per annum, ensuring that children with complex needs receive the tailored support they require; to increase funding for local authorities to reduce the financial burden on schools after the Conservatives left local councils underfunded; to extend the profit cap from children’s social care to SEND; to provide cash towards the cost of EHCPs to tackle the disincentives creating this adversarial system; and, to reform that broken national funding formula.

This crisis cannot go on. Every child, no matter their needs, deserves the opportunity to succeed with the right support in place. The Government must urgently clarify their reform plans. SEND families deserve certainty, not to be drip-fed information about their children’s future. As Hermione says:

“To anyone who thinks, ‘The system works fine as it is’—fine for who? If it doesn’t work for all, then it doesn’t truly work.”

Judith Cummins Portrait Madam Deputy Speaker (Judith Cummins)
- Hansard - - - Excerpts

I call the shadow Minister.

Dementia Care

Debate between Victoria Collins and Judith Cummins
Tuesday 3rd June 2025

(1 year, 2 months ago)

Commons Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Victoria Collins Portrait Victoria Collins (Harpenden and Berkhamsted) (LD)
- View Speech - Hansard - -

I start by thanking my hon. Friend the Member for South Devon (Caroline Voaden) for securing this debate. I also thank the many Members from all parts of the House who have shared passionate stories, either of their own or of constituents. Far too many people across the UK are living with dementia, a cruel and progressive condition that robs them of their memory, speech and independence. For every person with dementia, there is often a family doing everything they can behind closed doors to hold things together. I have heard from so many, and one of them is my constituent, Claire.

Claire describes her mother, Christine, as a vibrant and sociable woman. She was a devoted mother, a church flower arranger and a proud Harpenden resident of nearly 40 years. However, in her early 60s, Christine started showing signs of confusion, withdrawal and mood swings. Her family noticed something was off, but like so many others, they did not assume it was dementia. Even medical professionals overlooked these signs. Christine’s story took a devastating turn in 2018, just four weeks after her daughter Claire had given birth to twins.

At what should have been a joyful and tender time in their family’s life, Christine suffered a cardiac arrest. That moment plunged her into mid-stage vascular dementia, a terminal diagnosis with no treatment or cure. After Christine’s diagnosis, the family was visited by a nurse once and then told they were being discharged. They received no care plan nor long-term guidance. From then on, care fell entirely to the family. Claire’s dad, a retired engineer, became a full-time carer overnight. He learned to administer insulin and to manage medicine, and he joined online courses alongside his daughter.

Support for the family came when Dementia UK got involved in March 2020, and that was great, but unfortunately it was too late to change the trajectory and was tragically interrupted by the pandemic. Admiral nurses, who provide expert guidance for families such as Claire’s, could have made all the difference, but demand continues to outstrip supply.

Through it all, Claire created something positive. She saw at first hand the extraordinary power music had to reach her mum, even in the late stages of her dementia, so she set up Sing from the Heart, a community singalong in care settings and online for people with dementia. It was a real pleasure to visit them in the Willow Court care home and to hear Claire play along and the residents enjoying it. It is now a lasting tribute to her mother, who passed away in April last year, aged 73.

Alongside Sing from the Heart in Harpenden and Berkhamsted, we also have the memory café at Harpenden Trust and Open Door. There are so many volunteers, as mentioned today, working to give that care in the community. Everyone with dementia deserves high-quality care whenever they need it. The Liberal Democrats want everyone to be able to live independently and with dignity, and to receive any care they need in their home whenever possible. That is why we have routinely called on the Government to act now. Their decision to quietly drop cross-party talks on social care and push the delivery of the Casey commission’s recommendations to almost a decade away will leave many with dementia, and their families, paying the price. Do the Government accept that dementia care is in crisis, and will they now commit to better funding, so that families in this country do not go through the same hardships of receiving care as Claire and Christine?

Judith Cummins Portrait Madam Deputy Speaker (Judith Cummins)
- Hansard - - - Excerpts

I now ask Members to keep their comments to no more than four minutes.