Cyber Security and Resilience (Network and Information Systems) Bill
House of Lords · Lords Chamber · 14 Jul 2026 · 38 speeches · Official Report
Second Reading
Moved by
That the Bill be now read a second time. Northern Ireland, Scottish and Welsh l egislative c onsent sought . Relevant document: 3rd Report from the Constitution Committee
My Lords, we are a proudly online nation, embracing interconnectivity in all walks of life. Cloud-based working, the rise of software as a service, the advent of artificial intelligence and more have rocketed the UK forward. They have enabled us to work faster, more efficiently and with more flexibility than ever before. However, with these advancements come risks. As the technology powering our modern economy has leapt forward, so too have the tools that our adversaries use to extort, disrupt and surveil. Last year, more than 600,000 UK businesses were subject to cyber attacks. This is not only holding businesses back; it is undermining our security. These are criminals and hostile state actors seeking to disrupt the very foundations of our country. The UK is now the most targeted country in Europe for cyber attacks. It is the duty of this Government to take bold action. We have been clear that all businesses must protect themselves from cyber attacks, but this does not mean regulating every single business. They know their customers and their suppliers, and they are best placed to protect themselves, using the free tools that we have provided. I commend those who have already signed our Cyber Resilience Pledge, and urge more to do so, committing to take the three simple steps recommended in it: making cyber a board-level responsibility and following the cyber governance code of practice; signing up to the National Cyber Security Centre’s early warning service; and taking a...
My Lords, I thank the Minister for introducing the Bill before your Lordships’ House this afternoon. His Majesty’s loyal Opposition support the objective which lies behind this legislation. The cyber threat facing the UK is growing incrementally, both in scale and in sophistication. From hostile states to organised crime, from ransomware attacks on our public services to increasingly complex attacks on critical national infrastructure, the need to strengthen our national resilience is indisputable. Many noble Lords will be familiar with a number of reforms contained within this Bill, predominantly because they originate from the review of the Network and Information Systems Regulations undertaken by the previous Conservative Government following the consultation that was launched in 2022. It should not be a surprise that we welcome measures to improve consistency across the various regulators responsible for enforcing the existing regime. However, support for the objectives of a Bill should never prevent your Lordships’ House from asking whether the legislation is sufficient and proportionate. Most importantly, noble Lords would be right to constructively challenge whether this legislation forms part of a coherent strategy. That should be a central question. We are being asked to scrutinise and revise one of the fastest-moving areas of public policy without the Government having first published the cyber strategy within which these measures are intended to sit. Ministers...
My Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough? I serve on the House of Lords Select Committee on National Resilience-there is at least one other speaker in the debate who also serves on that Select Committee-and I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates “while we lag behind”. He stated that this “procedural quirk has left...
My Lords, the Government’s own cyber survey reports that 43% of UK businesses experienced a cyber attack last year, costing the UK economy an estimated £15 billion. Here are just a few examples of those many attacks: a deepfake video call cost Arup £20 million; Marks & Spencer was attacked in Easter last year, losing an estimated £300 million, with operations fully restored only three months later; and, most impactful of all so far, Jaguar Land Rover suffered an attack, had to halt production for around five weeks, was unable fully to restore its supply chains for four months and lost around £500 million. Moreover, the Government had to step in and guarantee a loan of £1.5 billion to stabilise JLR’s extensive supply chain. Yet our economy is barely touched by the Bill, as the noble Baroness, Lady Northover, just identified. I think that a lot of people, untutored, have a mental model of a technology platform as something you might offload off the back of an HGV; in reality, any technology platform, even in a medium-sized business, can be a highly complex network composed of hundreds of providers, any component of which can present a vulnerability. Just two examples among very many are the widespread reliance by providers on free-to-use but vulnerable open-source software maintained by volunteers, and the external software providers bolted on to a technology platform offering a myriad of services -for example, payroll, finance, logistics, e-commerce or customer relationship...
My Lords, what a pleasure it is to follow such an interesting and constructive speech. I hope the noble Lord will take full part in Committee on the Bill. I declare my interest as chairman of the advisory panel of the technology company Thales UK. I thank the Minister for the briefing that she gave noble Lords a couple of months back, which was extremely helpful. The best legislation has a permeating principle that helps to explain the purpose of the new law and inspire obedience to and observance of the new law. The Joint Committee on the National Security Strategy held an evidence session yesterday on deterrence in an age of Russian aggression, in which one of the witnesses told us that the key thing that should be included in the Bill is that it should hold vendors of software accountable for the reliability and security of their product. That follows on from what the noble Lord, Lord Birt, just said. That, after all, is what we do with cars. When Ciaran Martin was the head of the NCSC, that was one of his overall aims. However, that is not what this Bill does-it does not have a permeating principle. It is a bit of a muddle. Winston Churchill might have said that this pudding has no theme. My noble friend Lord Effingham asked about strategy, and he was absolutely right to do so. The Bill draws in some sectors but not others, without any clear explanation of the difference between those that it includes and those that it excludes. In another place, the shadow Secretary of...
Baroness Paul of Shepherd's Bush
My Lords, the Government’s whole-of-society approach to national security rightly recognises that resilience is not delivered by the state alone; it is delivered through partnership between government, regulators, industry, communities and, crucially, the private sector. Cyber resilience is no exception. It requires every bit of the infrastructure to play its part: those who defend networks, those who regulate standards and those who help organisations recover when incidents occur. I welcome the Bill and I note the broad support it has received from across the resilience sector as a good start. The Bill makes important progress in strengthening incident reporting, modernising the NIS framework and placing greater obligations on essential service providers, digital services and critical suppliers. I particularly welcome the inclusion of managed service providers within the regulatory regime. As other noble Lords have mentioned, more and more organisations rely on MSPs to help them keep pace with the changing nature of the threat and the ever-expanding tools required to remain secure. Without them, many businesses and parts of our critical national infrastructure would struggle to access the expertise they need to keep themselves safe. At the same time, MSPs can present a potential vulnerability because of the privileged access that they often hold to clients’ infrastructure. The Bill is right to recognise this, and I am pleased to see them brought into scope. In welcoming the...
My Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period. What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves. One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again. We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator-there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and...
I gently remind the noble Baroness that there is an eight minute advisory Back-Bench speaking time.
I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators. My last thought is that we need to ensure that another definitional issue in the Bill, the level of security “appropriate to the risk posed”, is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.
Baroness Alexander of Cleveden
My Lords, this is proving a fascinating and valuable debate, recognising the Bill’s many strengths, what could be tweaked, and what perhaps is missing as we look ahead. To begin with the strengths, we heard from the noble Earl, Lord Effingham, that the Bill builds on the work of the previous Government and commands cross-party support. We have just heard from the noble Baroness, Lady Neville-Jones, that national security is the first obligation of government. This is unarguably an important step in protecting the nation against cyber criminals, hacktivists and hostile states. It will quite simply make the UK a better place to live, work and do business in. We have heard already from the noble Lord, Lord Birt, about the economic impact of cyber attacks and from my noble friend the Minister about the 11,000 NHS appointments that are lost to cyber attacks. It therefore seems very timely that we have this Bill, which will cover more essential services, improve regulatory effectiveness, and speed up responses to cyber threats. It is clearly desirable that we have a stronger board level responsibility around cyber. It must be right that data centres are now included in the Bill, helping maintain the UK’s position as a global destination for secure data hosting and for innovation. The focus on high-impact firms means that small companies will not be unduly burdened. As my noble friend the Minister made clear, this is part of a wider national security effort that includes a cyber...
My Lords, there is a risk of agreement breaking out at this juncture. I too very much welcome the cyber security Bill and agree with others who have raised the omissions. There is nothing for the private sector and nothing on local authorities. It focuses on the size of service provider rather than risk and, in doing so, fails to learn from the battles during the Online Safety Act which established beyond doubt that the size of the company does not equate to the risk it poses in any system. There is also no mandate for executive responsibilities, as in NIS2 in Europe. All these things feel like critical omissions but, above all, there is nothing on AI, as we have just heard. That is where I will focus my remarks. In February, Darktrace, a cyber security firm based in Cambridge, surveyed cyber security professionals; 73% of them reported that AI-powered threats are already significantly impacting their organisations. Nine out of 10 said they needed major upgrades to their defences. Only weeks ago, the US Government instructed Anthropic to withdraw two frontier models, going from zero regulation of AI to a 100% ban within 90 minutes. This was on the understanding that it posed a national security threat, with capabilities that experts anticipate will be mirrored by other frontier models, including Chinese ones, within months. It seems extraordinarily ill advised, therefore, that AI is not front and centre of the Bill. Clearly, this is a decision rather than an omission so,...
Baroness Bennett of Manor Castle
My Lords, it is a great pleasure to follow the noble Baroness, Lady Kidron. I will come back to her points about digital sovereignty. I also thank the Minister for introducing this Bill. I have been reflecting back. I am approaching my eighth year in your Lordships’ House, and we have come a long way. About seven years ago, I was standing behind the Bar and a Member of your Lordships’ House who shall remain nameless sidled up to me and said: “They’re talking about catfishing. I gather that doesn’t mean being beside a river with a rod”. I said, “No, you’re right. Well done, well worked out”. We have come a long way. But, of course, the world has changed an enormous amount in those eight years and the message from all corners of your Lordships’ House today is that the Government are not keeping up. Your Lordships’ House will have to do its best to keep up for them and push the Government in those ways. In her introduction, the Minister talked about data centres being a key part of the modern world. Their security is very reliant on water and energy supplies, just as all our security is being impacted by their consumption of those supplies. Something we have not really talked about yet, but need to think about a lot, is that we tend to think about these information systems and networks as being up in the cloud, but of course they are very much physically down to earth and dependent on all our natural physical systems. That cannot be forgotten. I will focus mostly on two areas...
My Lords, the Bill sits squarely within the wider national security and preparedness agenda to which this House has repeatedly returned in recent months since the publication of the strategic defence review. We have spoken often about the interlocking nature of modern threats: geopolitical instability, climate shocks, pressure on critical infra- structure and the growing complexity of our digital systems. The Bill is therefore not a narrow technical measure; it is a national security Bill, and it deserves to be treated as such. Every essential service in the United Kingdom, whether that be our energy grids, water systems, transport networks, hospitals or financial services, now depends on digital infrastructure. The boundary between physical and digital security has dissolved. A cyber attack on a hospital is not an IT problem; it is a threat to life. A breach in a water company’s control systems is not a data incident; it is a public health emergency. A compromise in a major data centre or managed service provider can cascade and cause chaos across the economy in minutes. In recent years, we have seen how ransomware attacks have disrupted patient care or student learning, how supply-chain vulnerabilities have exposed critical national infrastructure, and how hostile actors-some criminal, some state-linked-have sought to test the resilience of our systems to destruction. The economic costs run into billions. The strategic cost is greater still: weakened confidence, reduced...
My Lords, I see that I have gone down on the speakers’ list as “B Ludford-first half”, presumably in the expectation that I will make the second half of my speech later. I am only kidding. I knew that I would learn a lot in this debate and I have not been disappointed. I am no expert on cyber issues and I am speaking only because, first, it is an interesting as well as vital topic; secondly, because my noble friend Lord Clement-Jones is very persuasive; and, thirdly, because the Bill has prompted me to revisit my memory of being the victim of a cyber attack 13 years ago. As an MEP I was involved in drafting the general data protection regulation-GDPR. I see the noble Lord, Lord Moraes, nodding in collective memory. I had sought to take a balanced approach, safeguarding personal data while not totally hampering digital services by overloading them with red tape. This middle way did not please a group of extremist hacktivists, who labelled me an agent of big tech and launched a denial of service attack against my MEP website. It was successfully defended by the small firm which hosted my website-and those of some Lib Dem MPs, including a coalition Minister or two-and it kept all the logs for me, as I wanted to notify the police. I could not find anyone in the Met to speak to so, since I was in touch with Europol and its British director at the time, his chief of staff kindly spoke to old Met colleagues and got an inspector to ring me. This chap was not only uninterested but...
My Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister-which is almost as surprising as learning that I was once the Minister of Fashion. Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area. As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate...
My Lords, too often we hear in the news that our local hospital cannot access patient records, or that the transport network in our cities has stalled, or, as I experienced last year, that the power has gone on and off for over a month as the local electricity grid is affected by cyber attacks. A decade ago, some of this would have sounded like the plot of a Hollywood movie. Today, it is a weekly briefing on the desk of our cyber security data centres. Our world has fundamentally changed. We are no longer just fighting off rogue teenagers or opportunistic hackers looking for a quick payout. The UK is currently navigating a highly sophisticated and aggressive digital battlefield. Malign actors are often directed, tolerated or unleashed by hostile nation states such as Russia, Iran and China, which are actively infiltrating key UK assets. They are mapping our infrastructure, stealing government credentials and probing our defences. That is why I welcome the introduction of the cyber security and resilience Bill. It is a critical and long-overdue overhaul of our national baseline defence. It marks the moment that the UK stops playing catch-up with hostile states and starts to dictate the terms of its own digital safety. To understand why the Bill matters, we have to look at how our digital ecosystem functions. Hostile actors do not just knock on the front door; they look for the weakest link in the supply chain. Look at what happened in September 2025, with the devastating...
My Lords, I declare my interest as a chief engineer working for AtkinsRéalis and I support the Bill. Given the threats that we are facing, strengthening the cyber security of the UK is vital. I think that the flexible, risk-based approach taken within the Bill is the right one. Noble Lords have made many of the broader points already, so I will focus on a few narrower points. My remarks are really centred around the impact on economic growth and the need for proportionate regulation, because this legislation supports growth through, first, increasing our cyber resilience. The noble Baroness, Lady Northover, gave the example of the £15 billion cost of cyber attacks in 2024: that is a significant fraction of our GDP, around 0.5%. I am also glad that the noble Lord, Lord Vaizey, brought up our world-leading cyber industry: the Bill represents a great opportunity for one of our key industries. However, there are threats to that growth agenda within the Bill, particularly through how larger corporates and SMEs will be affected, and we need to tread extremely carefully here. Business already has to deal with much burdensome regulation, as the noble Earl, Lord Effingham, set out. As ever in legislation, we need to think about those unintended consequences. To this end, there are three points I want to make. Looking at some of the detail of the Bill, my first point is around supply chains. Clause 12 rightly brings in the concept of “critical suppliers” and ensures that supply chains...
My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes. I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.
To Ministers.
To Ministers, indeed-to my noble friend himself. In those days, the National Cyber Security Centre did not exist-I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped. That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not...
My Lords, I thank the Minister for introducing this important Bill. Cyber security is clearly vital to the protection and prosperity of our nation. But if we fail to plan, we plan to fail, and this Bill is at the heart of the Government’s cyber security plan. I was born and raised in a part of the world that many think of as paradise, bliss, utopia. It is called Birmingham, just off the M6 by the gasworks. I can see there is some accord in the Chamber-or maybe it should go to VAR. I was a district councillor in that region. One of the largest employers there is Jaguar Land Rover. This giant motor vehicle manufacturer is the head of a supply chain of over 4,000 companies. JLR was the victim, as we all know, of a cyber attack last year and was bailed out by this Government to the tune of a £1.5 billion loan guarantee. The Government believed they had no choice because if they had let JLR fall, thousands of workers would have lost their jobs. I have some sympathy with that rationale, but it did set a dangerous precedent. It is also worth noting, surely, that the company had not completed taking out an insurance policy against cyber attacks. So the first point I want to make to the Minister is that there is no mention in the Bill of the role of the insurance industry. Surely the issue of essential and compulsory cyber insurance needs to be looked at; otherwise, we will have another situation where we have to bail out another huge company. The retail chain Marks & Spencer lost...
My Lords, I strongly welcome the intention of the Bill to strengthen the United Kingdom’s defences by updating our cyber security legislation as it applies to critical national infrastructure. That is good and overdue. As my noble friend Lady Gill pointed to, there is barely a week, if not a day, that passes without a significant business, hospital, local authority or supplier to government reporting a serious cyber incident. Every part of our infrastructure is vulnerable, and a legislative update to reflect that reality is one that this House should have absolutely no hesitation in supporting. Noble Lords have already raised concerns about a number of things relating to what is or is not in the Bill, and things that perhaps need to be tweaked-how we should consider the economic impact of cyber attacks, as well as issues around insurance, reporting, workforce development and training, making AISI a statutory body and the lack of joined-up work across 12 different regulators. These are all concerns that I share. I want to use the time I have available to add some details on the significant gap that has already been shared by others: the Bill currently makes no provision at all for artificial intelligence or, connected to that, for cyber sovereignty. This is not a hypothetical concern. Our allies have already grasped that, if their critical systems, their public services and their citizens’ data will depend increasingly on AI, relying entirely on foreign-built, foreign-hosted...
My Lords, I, too, welcome much of the Bill. It could not be more important in a world in which warfare is not just physical but digital. It is essential as part of our national security that our Government step in to protect us from such attacks. Most noble Lords, I think, welcome the list of bodies to be regulated in Part 2. I am very glad that data centres, large load controllers and specified management services have been brought within the scope of the Bill. After all, the Government celebrated the huge investments of AWS and DC01UK in data centres. It is important that they are now covered by the Bill as an essential part of our national security. There has obviously been an attempt to future-proof the Bill against the fast-changing world of tech. At the beginning of Part 3, Clause 24 gives the Secretary of State enormous and flexible powers to designate what is essential activity for the economy of the United Kingdom and the day-to-day functioning of society. This flexibility is then reinforced in Clause 43 in Part 4, which gives powers to issue directions to regulated persons and to decide what should be reported and to whom it should be reported. My fear is that the Bill does not go far enough to address the present threats, let alone the future ones. Noble Lord after noble Lord has raised concerns about the failure to mention AI in the Bill at all. I, too, was at the terrifying meeting mentioned by my noble friend Lady Kidron, which was held earlier this month, by...
My Lords, it is a pleasure to take part in this Second Reading debate and to follow my friend, the noble Viscount, Lord Colville of Culross. Though he, by his own words, repeated some of the earlier points, he was the first speaker to say “lacunae”, for which I am particularly grateful; it sounds like a technology company. I declare my technology interests as set out in the register, as advisor variously to the Crown Estate and to Simmons & Simmons LLP. As has been noted, this Bill is significant by having “cyber” in the title. This is long overdue, much needed and critical, as the Minister said, taking a cross-sector approach to cyber. Yet the first interesting point is that the Bill does not do that. Most notably, it is extraordinary that neither food nor space are included in the Bill. Similarly, it is said to take a cross-economy approach, yet it does not. However, it is worth mentioning the two sides of that economic coin and the huge economic growth potential from our cyber industries. I echo all the points that have been made about the need for skills and education, and to enable the cyber sector to grow and deliver that economic benefit. Reporting has been mentioned widely throughout the debate. It is unfortunate if one finds themselves in a situation such as that of my noble friend Lady Harding, with multiple agencies to have to report to. Surely it would make sense to have a single reporting point for the speed, efficiency and effectiveness of that reporting...
My Lords, it is a pleasure to follow the noble Lord, Lord Holmes. The noble Baroness, Lady Harding, has inspired me, as I am so low down the list-nearly at the end-not to do that thing of saying, “Everything has already been said, but not yet by everyone”, which I was thinking of while she was speaking. I will not do that; I am going to dump my very boring speech, inspired by the noble Baroness, Lady Ludford, who reminded me of what we used to do for a living. This contextualises exactly what the Government are trying to do. My noble friend the Minister has a very tough job-I will explain a little why I think it is so difficult-but it is a job that we said we would do. We wanted to update the NIS regulation in 2018 and, as the noble Baroness, Lady Neville-Jones, said, to move fast and have some urgency. I know why she said that: I will come on to what the intelligence services are dealing with every single day, with hacking and what the Russians are doing. She knows that, as that is part of her DNA. We have to move fast, and we have to do something. That is exactly what the Government are doing. I want to try to contextualise what they are doing, why this is a national priority and how we can be as constructive as we can in building cyber security and cyber resilience. A number of noble Lords, including the noble Baroness, Lady Harding, mentioned the EU network and information systems directive, which is very much the context of what we are doing. The noble Baroness, Lady...
My Lords, it is getting late, and I am told that we are now competing with the Spain v France World Cup semi-final-the winner may well face England in the final-so I will try to be brief. I speak not as a cyber expert or technologist but as a former CEO of a tech-enabled mid-sized business. I want to bring some ground-level perspectives of these oft-mentioned SMEs, one of which I currently chair. I welcome the Bill, but like many others, I have some concerns over its scope, its impact on those apparently outside the scope but who sit within critical infrastructure supply chains, the challenges of a horizontal piece of legislation being layered over multiple sectors and their regulators, and why, as so many people have asked, there is no specific strategy for AI. All of that has been covered, and I will not repeat those points. However, I want to question why central government and local authorities will remain out of scope. The National Audit Office’s report last year found serious slow-to-fix security flaws across 58 of the 72 government systems that were reviewed. The public sector badly needs binding legal requirements, not just a voluntary action plan. As we have heard, the UK is already the most targeted country in Europe for cyber attacks, with more than 40% of UK businesses experiencing such attacks at a cost put at almost £15 billion annually. But those numbers are almost certainly an underestimate not just because they apply to 2024 but because a whole range of...
My Lords, my noble friend Lady Harding talked about speaking half way down the list, and the noble Lord, Lord Moraes, of being nearly at the end of the list. I am last, as your Lordships will be glad to hear. I must declare my interest as an employee of Marsh Risk, an insurance brokerage company with a large cyber practice. Like many other noble Lords, I welcome the Government’s ambition to strengthen the UK’s cyber defences and, in doing so, to protect the continuity of the essential services on which the public depend. The Bill’s direction of travel is right: widening the scope of the existing regulatory framework to reflect modern supply chains, strengthening oversight and improving the flow of information to regulators and the National Cyber Security Centre so that we can build a clearer national picture of threats and vulnerabilities. However, I will press the Minister on two areas where the Bill, as drafted, risks leaving practical gaps: first, the role of cyber insurance in building national resilience; and secondly, whether the proposed incident reporting timelines will, in practice, help resilience or inadvertently hinder it. On insurance, my argument is straightforward. Regulation, technical standards and guidance are essential, but they are not, on their own, a resilience strategy. Resilience also means the ability to recover quickly: to fund remediation, to access specialist incident response capability at speed, and to keep vital services running while systems...
My Lords, first, I declare an interest as an adviser to DLA Piper on AI policy and regulation. I should also say that we as a law firm were subject to a ransomware attack by NotPetya back in 2017. It was not a pleasant experience. I thank the Minister for her introduction and earlier engagement on the Bill and thank all noble Lords who spoke today in such an expert fashion. On these Benches, like many other noble Lords, we support the fundamental objectives of this legislation to modernise our outdated cyber security framework. But what has been remarkable today is the consensus across the Benches that the Bill is not nearly ambitious enough. Indeed, as my noble friends Lady Northover and Lady Ludford, the noble Lord, Lord Vaizey, and the noble Baronesses, Lady Neville-Jones and Lady Harding, have said, this could be a missed opportunity to align much more closely with the EU framework. I would prefer not to be jumping off a cliff, with or without wings, with all due deference to the noble Lord, Lord Moraes, and I do not think that we are really living up to the motto of the city of Newcastle either. As the noble Lord, Lord Arbuthnot, said: where are the principles? The noble Earl, Lord Effingham, said: where is the strategy? The noble Baroness, Lady Kidron, asked where the plan of action was. There is quite a bit missing from the Bill, and I shall take noble Lords through some of those areas. As many noble Lords have illustrated, the threat landscape has deteriorated...
My Lords, I am grateful to all noble Lords who have contributed to the debate and, of course, to the Minister for her introduction. It has been a really thoughtful, compelling and persuasive debate. It is clear that, on all sides of the House, there is a shared recognition of the scale of the threat that this legislation seeks to address and the importance of doing so effectively. As my noble friend Lord Effingham said, we on these Benches support the objectives of the Bill. Indeed, much of what is in it has its origins in work begun by the previous Government, following the 2022 consultation, and we applaud the continuity. We do not intend to try to make the perfect the enemy of the good, although I wholly endorse the cyber insurance argument set out by the noble Baroness, Lady Paul of Shepherd’s Bush, my noble friend Lord Ashcombe and others. Listening to the debate has only reinforced for me the central question with which we began: where is the strategy? Ministers have described the Bill as one part of a wider programme, yet the national cyber action plan that was promised before the end of last year, and then promised again for this summer, remains unpublished. I observe as an aside that, as with the defence investment plan, we are in danger of creating the perception, which we must avoid, that there is a pattern of delay and avoidance when it comes to defending ourselves. Noble Lords across the House have, in their own ways, returned again and again to that same point....
I thank noble Lords for their insightful and wide-ranging content, and I am pleased to hear the broad support for the Bill. I also thank the Minister in the other place and the parliamentarians who engaged with your Lordships and others ahead of the Bill’s introduction. The dialogue has been shaped by pragmatism and a genuine interest in protecting our people and businesses. Should I not be able to respond in the allocated time to all the very many specific points that were raised today, I will make sure that I review Hansard carefully and reply to noble Lords accordingly, placing copies in the Library. The noble Viscount, Lord Camrose, raised an excellent point about the scope of the Bill and the many other government actions and activities to equip our businesses to tackle cyber threats. I agree that the national cyber action plan is the right place to set out exactly how this is all put together, but today I cannot provide noble Lords a date for the publication of the national cyber action plan. As other noble Lords did, I started writing down the names of all the noble Lords who raised the question of scope-and I too decided that it was probably better to say “everybody”. This is a very pertinent question. Cyber security and resilience are a shared responsibility. The Government and the NCSC provide a range of tools for all parts of the economy, and it is for all organisations to make use of those to enhance their protections. We have invited all businesses, charities...
Bill read a second time.
Commitment and Order of Consideration Motion
Moved by
That the bill be committed to a Grand Committee, and that it be an instruction to the Grand Committee that they consider the bill in the following order: Clauses 1 to 22, Schedule 1, Clause 23, Schedule 2, Clauses 24 to 61, Title.
Motion agreed.