Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateViscount Camrose
Main Page: Viscount Camrose (Conservative - Life peer)Department Debates - View all Viscount Camrose's debates with the Department for Science, Innovation & Technology
(1 month, 3 weeks ago)
Lords ChamberMy Lords, I am grateful to all noble Lords who have contributed to the debate and, of course, to the Minister for her introduction. It has been a really thoughtful, compelling and persuasive debate. It is clear that, on all sides of the House, there is a shared recognition of the scale of the threat that this legislation seeks to address and the importance of doing so effectively.
As my noble friend Lord Effingham said, we on these Benches support the objectives of the Bill. Indeed, much of what is in it has its origins in work begun by the previous Government, following the 2022 consultation, and we applaud the continuity. We do not intend to try to make the perfect the enemy of the good, although I wholly endorse the cyber insurance argument set out by the noble Baroness, Lady Paul of Shepherd’s Bush, my noble friend Lord Ashcombe and others.
Listening to the debate has only reinforced for me the central question with which we began: where is the strategy? Ministers have described the Bill as one part of a wider programme, yet the national cyber action plan that was promised before the end of last year, and then promised again for this summer, remains unpublished. I observe as an aside that, as with the defence investment plan, we are in danger of creating the perception, which we must avoid, that there is a pattern of delay and avoidance when it comes to defending ourselves. Noble Lords across the House have, in their own ways, returned again and again to that same point.
I started off the debate diligently writing down everybody who called for a change to the scope but that turned out to be everybody, which makes our task today far harder. I absolutely accept that this is a Bill designed to have a narrow scope, but we have no way to understand the broader context in which that narrow scope sits. It is like trying to judge an orchestra but being allowed to hear only the woodwind section.
It is inevitable that we will have questions, concerns and suggestions that go beyond the narrow scope and intent of the Bill. How will SMEs learn to protect themselves better? Many people have raised that. A great many noble Lords—again, almost everybody—mentioned AI, but what response overall is envisaged to the threats of emerging technologies of which as yet we know little, such as new AI models at the frontier, quantum cracking and so on? How will we reduce the number of vacancies for cyber roles? By the way, it is not a new problem, by any means, that there are too many vacancies for cyber roles. We were wrestling with it when we were in government. It is an intractable problem that we need to find better ways to address.
How will we address the growing prevalence and effectiveness of weaponised disinformation that does so much harm to our society every day, right now? More fundamentally, what are our strengths and weaknesses relative to those of our assailants and our allies? Let me express the hope—I will return to this point—that, during the Bill’s passage, and ideally before Committee, we have the national cyber action plan to answer these and no doubt many other questions. This could make the passage of the Bill considerably easier for all of us, in particular for the Minister, and indeed help bring about the wish of my noble friend Lady Neville-Jones that we get through the Bill quickly in order to get these measures on to the statute book as soon as possible.
Even the National Cyber Security Centre itself has publicly called on government to set out a clearer strategic policy agenda. If GCHQ’s own technical authority feels moved to say so, that ought to give the Minister and the Government pause.
In the other place, my honourable friend Dr Ben Spencer made precisely this point, warning that the National Audit Office had found
“inconsistent, and in some cases glacial, progress”,—[Official Report, Commons, 6/1/26; col. 223.]
in cyber resilience, and that the Bill risked becoming “yet another missed opportunity”. My honourable friend Julia Lopez for her part reminded the Commons that, if the pandemic had accelerated the adoption of digital technology, artificial intelligence would embed it further still. Yet, as she noted, and as noble Lords, including my noble friend Lord Arbuthnot, have echoed this evening—in fact, as everybody has said this evening—the Bill is silent on AI. It is silent on the Computer Misuse Act. These omissions go to the heart of whether this legislation will still be fit for purpose in five years’ time, given how disappointingly rarely Parliament revisits this ground.
On the question of regulatory burden, I was also struck by how many noble Lords share our concern for smaller businesses. I hope that the Minister agrees that this is not a party-political point. It was raised by members of the party opposite in the other place too, who rightly noted that SMEs are disproportionately targeted by cyber crime, yet are the least equipped to absorb new compliance obligations. In fact, techUK, as the noble Lord, Lord Clement-Jones, pointed out, has warned that leaving so much of the detail of this regime to secondary legislation, as well as using some of the rather woolly language that was commented on by the noble Lord, Lord Ravensdale, risks creating exactly the kinds of legal uncertainty and cost that fall hardest on smallest firms.
Again, I am trying to make not a political point—we urgently need this Bill—but a practical point. Indeed, my noble friend Lady Harding’s account of attempting to communicate while managing the crisis caused by an attack was absolutely salutary and I hope the Minister will take note of it.
So, as we move towards Committee after the Summer Recess—I think Committee promises to be a very productive activity—I hope the Minister will reflect carefully on the questions raised today and, in her closing, perhaps answer the following questions. First, will the Government commit to a firm date for publishing the strategy within which this legislation is meant to sit? Secondly, how will the effectiveness or otherwise of the Bill’s measures be assessed, and how will that assessment be reported to Parliament—we hope not every five years? Thirdly, what assessment has been made of the cumulative reporting burden facing businesses of all sizes already subject to data protection and sector-specific obligations? Fourthly, what confidence can the Minister offer the House that the 12 regulators tasked with enforcing this regime, which we have heard a great deal about, will have and will continue to have the resources and expertise to do so effectively?
In Committee, we on these Benches will continue to press the Government on precisely these questions because, as with any regulation, it must be built on a foundation of strategic clarity rather than being asked to substitute for it. I look forward to the Minister’s response.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateViscount Camrose
Main Page: Viscount Camrose (Conservative - Life peer)Department Debates - View all Viscount Camrose's debates with the Department for Digital, Culture, Media & Sport
(5 days, 8 hours ago)
Grand CommitteeMy Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.
My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.
That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.
However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.
Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.
I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.
I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.
Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.
In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.
I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.
On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.
On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.
A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.
With that, I beg leave to withdraw—
Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?
My Lords, I shall begin with Amendment 12 in the names of the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron. I completely understand the necessity and urgency of taking action on these things. The noble Lord, Lord Tarassenko, set out the absolute urgency and the growing weight of the problem that we need to solve here. I have my doubts—I am delighted to carry on talking about this—about the significant expansion of and change in the role of AISI to take on these additional responsibilities. Those are practical doubts; I am certainly not disputing the desirability of fixing this problem.
Equally, we have to think practically about how this works alongside the Information Commissioner’s Office and the relative role of each. I thought my noble friend Lord Holmes set it out very well. We are going to need to look carefully at who regulates what—we are going to come to this in the next group—but we need to do so with quite a bit more information about their resources and goals and how we see each regulator taking this forward. I am afraid that there is a very much larger discussion that we will have to take forward on this matter.
Although I understand the desire to maximise the use of AISI in giving it these statutory functions via Amendment 85, we on these Benches are hesitant about consolidating powers in a separate non-governmental body. No matter how effective that body continues to prove to be in its original and existing role, taking power outside Parliament may not be the most effective way to ensure rigour and accountability. The Secretary of State should of course have regard to what AISI says and closely monitor its output, but I am concerned—although willing to be convinced on this—that placing it on a statutory footing risks diverting responsibility away from the Secretary of State. We hold the same position on Amendment 92. Giving AISI standard-setting, inspection and enforcement powers risks creating an unaccountable body with a greatly increased remit out of what is currently a vital and successful research body. I feel that that risk is too great for both sides.
Instead, we would rather see powers vested in the hands of accountable public figures. It is for this reason that we support the principle behind Amendment 84 in the name of the noble Lord, Lord Clement-Jones, which would provide the Secretary of State with the power to shut down AI systems during large-scale emergencies. It would also provide a necessary stopgap in the hands of an accountable Secretary of State while requiring Parliament to be informed of the decision taken. Additionally and importantly, it would not inhibit the growth of safe and responsible AI across the AI sector, which could be an additional worry with the pre-deployment checks in Amendment 85.
Amendment 75 tabled by the noble Baroness, Lady Kidron, would introduce red lines for relevant AI digital services. I confess that I was very impressed when I read the red lines because I thought that she had written them herself, but she gave away—perhaps foolishly—that they came from the brilliant Stuart Russell. Needless to say, the list is entirely sound, at least for today. We agree that AI services should not partake in actions that threaten the safety of individuals, businesses or nations, but our hesitation arises from the fact that, while their logic is clear, the red lines themselves are necessarily speculative at a moment in time, however eminent and wise their creator.
Further, AI models would have to demonstrate that they cannot perform the capabilities listed, so they would essentially be asked to prove a negative. Aside from the fact that this would place an administrative burden on the providers, as we all know, AI models develop in ways that are nearly impossible to predict and quantify. I am unclear how frontier labs would be able to engineer their models so that, for example, they would demonstrably not self-improve so as to pose
“a risk to the authenticity and integrity of the processed data”.
Similarly, I am unsure how the regulators will be expected to quantify these capabilities because, to a large extent, they are a function of not just ability but degree. In theory, the requirement not to support the development of chemical weapons might be violated by a model that simply gives basic chemistry lessons. Would that model be banned or would it be forced not to answer questions about chemistry? I do not want to trivialise this matter by giving too simple an example, but I am trying to convey just how difficult it will be to design the precise scope and extent of the necessary regulations. I worry that they currently seem arbitrary. They would be onerous on firms and regulators and slow down safe and responsible growth where it exists in our domestic AI industry.
I would suggest a different or additional approach, principles based rather than capabilities based. Ensuring, for example, that labs and associated businesses are focused on integrity, prevention, human control, threat minimisation and transparency, rather than attempting to regulate specific examples of AI malpractice, could prove more effective at serving the dual goal of AI growth and AI safety. As I have argued many times, I am afraid, in other Bills and debates, the only way legislation can keep ahead of technology is to pursue principles over rules about specific features.
My Lords, I first congratulate the noble Lord, Lord Birt, on what is a really comprehensive vision expressed in this group of amendments. I speak in strong support of those amendments, on which both he and the noble Lord, Lord Londesborough, have spoken so cogently. Together, they address one of the most glaring defects of the architecture of this Bill: the fragmented, inefficient model of 12 separate sectoral regulators. I think that the noble Baroness, Lady Neville-Jones, asked the right questions about how to co-ordinate and how to be fair, but I am afraid I come to very different answers and to the same conclusion as the noble Lord, Lord Birt. Cyber threats are sector-agnostic. Malicious code and supply chain exploits do not respect the boundary between Ofwat, Ofgem or the CAA. Expecting 12 separate bodies to recruit scarce elite cyber forensic talent is a fantasy that results in weak, uneven enforcement.
Furthermore, multi-sector businesses face duplicative compliance obligations across separate competent authorities in the current scheme. Under Amendments 7, 9 and 11, the noble Lord, Lord Birt, would correctly widen the definition of digital service providers to include the creators, distributors and managers of software and digital platforms. As the Synnovis pathology attack proved so catastrophically to London hospitals, our critical infrastructure is entirely dependent on third party software code. If we do not bring software and platform providers into scope under Clauses 7 and 8, we leave the front door wide open to cyber crime. Amendment 88, in the name of the noble Lord, Lord Birt, which I actually prefer to my own Amendment 87, would replace this maze of regulators with a unified, specialised body, the office for cyber resilience. The OCR would centralise enforcement, establish common auditing baselines and maintain sector-specific expertise under a single roof.
Amendments 76 and 77 would ensure that, when the Secretary of State specifies new essential activities under Part 3, they must act on the expert recommendations of the OCR, targeting any activity whose disruption carries severe economic, societal or national security impacts. I entirely agree with what the noble Lord, Lord Holmes, had to say and think, sadly, that we would all benefit from a bit of musical accompaniment.
This structural foundation would enable a vital reform suggested by the noble Lord, Lord Birt: Amendment 89 would establish a register requiring software and platform providers to certify products as safe by design; and Amendment 91 would introduce annual independent cyber resilience audits modelled on statutory financial audits.
Under Amendment 90, the OCR would work hand in glove with the UK Cyber Security Council to validate and enforce workforce competence standards across all regulated entities. I remind your Lordships that Amendment 99, in the name of my noble friend Lady Northover, has been degrouped but is relevant to the relationship between the potential OCR and the UK Cyber Security Council.
This is a comprehensive but significant group of amendments that hang together extremely well. I urge the Government to look very closely at what could be a really effective scheme of regulation.
My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.
As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.
More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.
I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.
The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.
The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.
Baroness Lloyd of Effra (Lab)
I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.
As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.
I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.
Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.
Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.
On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.
I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateViscount Camrose
Main Page: Viscount Camrose (Conservative - Life peer)Department Debates - View all Viscount Camrose's debates with the Department for Digital, Culture, Media & Sport
(3 days, 8 hours ago)
Grand CommitteeMy Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.
Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.
We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.
Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.
Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.
For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.
I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.
First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.
The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.
These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.
I turn now to the amendments tabled by—
My Lords, I, too, support these customer notification amendments tabled by the noble Baroness, Lady Harding of Winscombe. As I have said, the noble Baroness brings vital lived experience, in more ways than I thought, from the front line of corporate crisis response. When a major cyber breach occurs, vague statutory requirements to notify customers
“as soon as reasonably practicable”
lead to corporate delay. Amendment 58 would replace this with a strict statutory 24-hour notification clock, while Amendment 65 would establish explicit harm triggers and require providers to provide actionable remediation advice to affected customers. Look at what Amendments 60 and 65, in particular, would achieve across Clause 16.
Under Amendment 65, notification would be explicitly triggered whenever an incident causes or threatens severe operational disruption, substantial financial loss or material harm to downstream users. Furthermore, Amendment 71 would place a positive duty on the provider to advise customers on immediate remediation steps that they can take. In the cyber realm, time is the attacker’s greatest ally. If a hospital, bank or small supplier is informed within 24 hours that their cloud or managed service provider has been breached and given technical instructions on how to isolate their systems, they can prevent contagion before it paralyses their operations. We must ensure that customer notification is prompt and meaningful, empowering downstream businesses to isolate compromised systems before contagion spreads, so we very strongly support these amendments.
My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.
Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.
It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.
Baroness Lloyd of Effra (Lab)
I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.
I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.
We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.
I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.
On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.
My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.
Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.
I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.
However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.
We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.
I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.
Baroness Lloyd of Effra (Lab)
I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.
I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.
That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.
I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.
To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.
I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.
Baroness Lloyd of Effra (Lab)
It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.
Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.
Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.
Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.
This brings me on to Amendment 81A—
I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?
Baroness Lloyd of Effra (Lab)
The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.
Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.
I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.
The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.
I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.