Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always authoritative recommendations of the Delegated Powers and Regulatory Reform Committee in its seventh report of this Session and are strongly supported by the principles laid down by the Select Committee on the Constitution in its third report. Together, these amendments seek to delete two deeply objectionable provisions that represent a classic example of secondary legislation creep—provisions where the Executive are seeking a blank cheque to unilaterally rewrite the rules.

Amendment 92C targets Clause 37 and seeks to leave out subsection (7). Under the Bill as drafted, Clause 37(7) grants the Secretary of State the unilateral power to make regulations to amend the Act to change and potentially dilute the consultation and parliamentary scrutiny requirements that apply to a code of practice. This is a Henry VIII power of quite an extensive kind. In the Government’s original delegated powers memorandum of November 2025, the department, as it then was, argued that this power was necessary to allow flexibility in case a 40-day parliamentary scrutiny period became, in its words, “unfeasible” or

“a detriment to the quality of … a code”.

But as the Delegated Powers Committee correctly noted in its seventh report, the rules governing how Parliament scrutinises the Executive must be set by Parliament in primary legislation; they should not be subject to the administrative convenience of a Minister. Allowing a Minister to use secondary legislation to alter or weaken the very procedural safeguards that this House has debated is not constitutionally correct. The committee’s recommendation is clear and unambiguous: subsection (7) must be removed.

That brings me to Amendment 95C, which seeks to leave out Clause 40(5). Clause 40 requires the Secretary of State to lay a report before Parliament on the operation of this cyber security legislation. However, subsection (5) grants the Secretary of State the power to amend this primary legislation via regulations to change the matters to be covered in those same reports. Again, in their original November 2025 memorandum, the Government defended this by claiming that they needed flexibility to ensure that reports could be expanded over time as technology matures.

With the greatest respect, that argument is entirely spurious. If the Government merely wish to report on more things, they are already fully entitled to include voluntary supplementary chapters in their reports. But by granting themselves a statutory power to amend the legal requirements of Clause 40, they are taking the power to delete or dilute the core mandatory reporting obligations that Parliament has put in the Bill. They would, in effect, be legally empowered to write their own report cards, deciding behind closed doors what they must disclose to Parliament and what they can quietly omit, including critical scrutiny over how they have used the vast delegated powers under Clause 29(1).

The Delegated Powers Committee was again clear. This power is inappropriate, lacks coherent justification and should be deleted from the Bill. The Select Committee on the Constitution too, in its third report, expressed serious anxieties about the overall design of the legislation. It warned that this is a framework Bill that relies far too heavily on secondary regulations to establish the actual perimeters of national cyber resilience.

When a Bill already delegates such sweeping unprecedented powers to the Executive, amplified by the amendments to introduce a parallel high-risk vendor framework, laid on 24 August and discussed on the first day of this Committee, it is doubly important that the statutory channels of parliamentary oversight remain supreme. We cannot allow the Government to use secondary regulations to dismantle the guardrails that keep them accountable. I urge the Minister to accept these common-sense, committee-backed corrections and agree to delete Clause 37(7) and Clause 40(5) before Report. I beg to move.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.

I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to

“prioritise the content of the code of practice, rather than arbitrary requirements”.

It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.

By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?

It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - - - Excerpts

I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.

These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament.

On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.

On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.

I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

To continue, if the state is going to impose heavy, legally binding supply chain security duties on small businesses, backed by turnover-based fines, the state has a moral and strategic obligation to provide the operational tools needed to meet those standards. By establishing a free, Australian-style digital safety net under Amendment 100, we would turn the Bill from a purely punitive compliance exercise into a genuine co-operative national partnership for cyber resilience, and I urge the Minister to accept this vital common-sense amendment.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Baroness, Lady Northover, for her amendment and, needless to say, I support the intention behind it. It is clearly right that, having placed several new duties on businesses and their vendors, the Government consider how to ensure that they are able to carry them out. This is particularly the case for SMEs, which are often far less resilient, less well-resourced and more vulnerable to cyber attacks than their larger counterparts. But, when thinking through this idea, I was trying to come up with some sort of framework to estimate the costs of such a provision, and I just could not arrive at a satisfactory estimate, except that they would be very considerable, particularly given the urgency, complexity and difficulty of incident response.

As I think the noble Lord, Lord Clement-Jones, and others mentioned, providing advice on a government website is cheap and useful, but providing urgent incident response is far from cheap. That begs the question: would it be funded by the companies benefiting from this directly or the taxpayer? I am not sure that either is wholly satisfactory. The actual costs of running such a programme will depend largely on how it would operate and the terms of service it would offer. I am very grateful to the noble Baroness, Lady Northover, for pointing to the Australian example; I confess that I was unaware of it before and would be interested to know what service it provides and to what level. It is incredibly hard to estimate how it will operate and what terms of service it will offer. The rate of cyber attacks is non-linear, the scale, nature and complexity of each attack will vary significantly and the number of staff needed or resources available for a response at any one time would necessarily be volatile and unpredictable.

--- Later in debate ---
Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

My Lords, one of the advantages of being in this Committee Room for these debates in Committee is that I can use Claude—I hope that is allowed—to answer the question of what the cyber security community thinks about the Computer Misuse Act. The answer comes back in bold. I will read just the paragraph in bold: “The UK cyber security community’s view is that the Computer Misuse Act 1990 is dangerously out of date and reform efforts so far do not go far enough”. I rest my case.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems.

Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.

The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.

I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

In the spirit of her final remarks on the Bill overall, is the Minister able to give any update as to when the national cyber action plan might emerge?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have nothing further to add what I have said in previous sittings.