My Lords, we are a proudly online nation, embracing interconnectivity in all walks of life. Cloud-based working, the rise of software as a service, the advent of artificial intelligence and more have rocketed the UK forward. They have enabled us to work faster, more efficiently and with more flexibility than ever before.
However, with these advancements come risks. As the technology powering our modern economy has leapt forward, so too have the tools that our adversaries use to extort, disrupt and surveil. Last year, more than 600,000 UK businesses were subject to cyber attacks. This is not only holding businesses back; it is undermining our security. These are criminals and hostile state actors seeking to disrupt the very foundations of our country.
The UK is now the most targeted country in Europe for cyber attacks. It is the duty of this Government to take bold action. We have been clear that all businesses must protect themselves from cyber attacks, but this does not mean regulating every single business. They know their customers and their suppliers, and they are best placed to protect themselves, using the free tools that we have provided.
I commend those who have already signed our Cyber Resilience Pledge, and urge more to do so, committing to take the three simple steps recommended in it: making cyber a board-level responsibility and following the cyber governance code of practice; signing up to the National Cyber Security Centre’s early warning service; and taking a risk-based approach to requiring Cyber Essentials across supply chains. This is our government certification scheme to help organisations improve their cyber resilience. Cyber Essentials works. Organisations with it are 92% less likely to claim on their cyber insurance than those without it. Taking these steps can make a huge difference.
My Lords, I thank the Minister for introducing the Bill before your Lordships’ House this afternoon. His Majesty’s loyal Opposition support the objective which lies behind this legislation. The cyber threat facing the UK is growing incrementally, both in scale and in sophistication. From hostile states to organised crime, from ransomware attacks on our public services to increasingly complex attacks on critical national infrastructure, the need to strengthen our national resilience is indisputable.
Many noble Lords will be familiar with a number of reforms contained within this Bill, predominantly because they originate from the review of the Network and Information Systems Regulations undertaken by the previous Conservative Government following the consultation that was launched in 2022. It should not be a surprise that we welcome measures to improve consistency across the various regulators responsible for enforcing the existing regime. However, support for the objectives of a Bill should never prevent your Lordships’ House from asking whether the legislation is sufficient and proportionate.
Most importantly, noble Lords would be right to constructively challenge whether this legislation forms part of a coherent strategy. That should be a central question. We are being asked to scrutinise and revise one of the fastest-moving areas of public policy without the Government having first published the cyber strategy within which these measures are intended to sit. Ministers have described this Bill as merely one component of a wider programme to strengthen Britain’s cyber resilience, so it is entirely fair and reasonable to ask, “Where exactly is that programme? Where is the strategy? Where is the explanation of how these powers fit within the Government’s broader approach to protecting our digital economy and our critical national infrastructure?”
Only last Thursday, we heard an Oral Question on the impact of AI in vaccine technology. It is obvious to all that AI is, regrettably, also transforming how cyber attacks are conducted, increasing both their scale and their sophistication. Hostile states have become more aggressive. Organised crime has become more capable. The boundary between economic security and national security has become ever more blurred. Yet little of that ever-shifting landscape appears to find expression within the Bill itself. In fact, artificial intelligence does not appear to feature in the legislation. Quantum cracking does not feature. Weaponised disinformation does not feature. The wider question of how government intends to respond to AI-enabled cyber threats remains unanswered. Nor does the Bill address the long-standing concerns surrounding the Computer Misuse Act, despite repeated calls from the industry for reforms that better reflect modern cyber security practice and remove the legal uncertainty facing legitimate cyber security researchers.
My Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough?
I serve on the House of Lords Select Committee on National Resilience—there is at least one other speaker in the debate who also serves on that Select Committee—and I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates “while we lag behind”. He stated that this
“procedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated laws”.—[Official Report, Commons, 6/1/26; col. 179.]
We do indeed have the worst record in Europe for such attacks. I would argue, from submissions we received to our Select Committee, that it makes most sense for us to be aligned with the EU regulations. It has been put to us that this would mean that organisations do not need to answer to two sets of regulations in Europe. It is clear that this would assist us anyway, given that the EU regulations cover a wider range of areas, which it makes little sense to overlook as the Government appear to be doing. As it was put to us by ISC2,
My Lords, the Government’s own cyber survey reports that 43% of UK businesses experienced a cyber attack last year, costing the UK economy an estimated £15 billion. Here are just a few examples of those many attacks: a deepfake video call cost Arup £20 million; Marks & Spencer was attacked in Easter last year, losing an estimated £300 million, with operations fully restored only three months later; and, most impactful of all so far, Jaguar Land Rover suffered an attack, had to halt production for around five weeks, was unable fully to restore its supply chains for four months and lost around £500 million. Moreover, the Government had to step in and guarantee a loan of £1.5 billion to stabilise JLR’s extensive supply chain. Yet our economy is barely touched by the Bill, as the noble Baroness, Lady Northover, just identified.
I think that a lot of people, untutored, have a mental model of a technology platform as something you might offload off the back of an HGV; in reality, any technology platform, even in a medium-sized business, can be a highly complex network composed of hundreds of providers, any component of which can present a vulnerability. Just two examples among very many are the widespread reliance by providers on free-to-use but vulnerable open-source software maintained by volunteers, and the external software providers bolted on to a technology platform offering a myriad of services —for example, payroll, finance, logistics, e-commerce or customer relationship management.
There is a possible vulnerability in every part of this complex network of providers, with many doors to pry open. Once one door is opened by a bad actor—a fraudster, a foreign power, a hacktivist or a ransom gang—there is the potential to explore and disable much or all of the system. Entry can be through a clever phishing email, perhaps AI-personalised with stolen data, or through application, network and infrastructure vendors failing to close down vulnerabilities immediately they are identified.
My Lords, what a pleasure it is to follow such an interesting and constructive speech. I hope the noble Lord will take full part in Committee on the Bill. I declare my interest as chairman of the advisory panel of the technology company Thales UK. I thank the Minister for the briefing that she gave noble Lords a couple of months back, which was extremely helpful.
The best legislation has a permeating principle that helps to explain the purpose of the new law and inspire obedience to and observance of the new law. The Joint Committee on the National Security Strategy held an evidence session yesterday on deterrence in an age of Russian aggression, in which one of the witnesses told us that the key thing that should be included in the Bill is that it should hold vendors of software accountable for the reliability and security of their product. That follows on from what the noble Lord, Lord Birt, just said. That, after all, is what we do with cars. When Ciaran Martin was the head of the NCSC, that was one of his overall aims.
However, that is not what this Bill does—it does not have a permeating principle. It is a bit of a muddle. Winston Churchill might have said that this pudding has no theme. My noble friend Lord Effingham asked about strategy, and he was absolutely right to do so.
The Bill draws in some sectors but not others, without any clear explanation of the difference between those that it includes and those that it excludes. In another place, the shadow Secretary of State for Science, Innovation and Technology, Julia Lopez, said that she supported the Bill but feared it might not work in practice. I too support the Bill but fear it might not work in principle.
We live in an age when everything is connected to everything else. Drawing dividing lines between, for example, the private sector, some of which is included and some of which is excluded, and the public sector, which is excluded, is perilous and leads to incomprehension of the law.
My Lords, the Government’s whole-of-society approach to national security rightly recognises that resilience is not delivered by the state alone; it is delivered through partnership between government, regulators, industry, communities and, crucially, the private sector. Cyber resilience is no exception. It requires every bit of the infrastructure to play its part: those who defend networks, those who regulate standards and those who help organisations recover when incidents occur.
I welcome the Bill and I note the broad support it has received from across the resilience sector as a good start. The Bill makes important progress in strengthening incident reporting, modernising the NIS framework and placing greater obligations on essential service providers, digital services and critical suppliers. I particularly welcome the inclusion of managed service providers within the regulatory regime. As other noble Lords have mentioned, more and more organisations rely on MSPs to help them keep pace with the changing nature of the threat and the ever-expanding tools required to remain secure. Without them, many businesses and parts of our critical national infrastructure would struggle to access the expertise they need to keep themselves safe. At the same time, MSPs can present a potential vulnerability because of the privileged access that they often hold to clients’ infrastructure. The Bill is right to recognise this, and I am pleased to see them brought into scope.
In welcoming the Bill, I must also point to what I think is a significant omission, on which I will focus my remarks. There is no mention of the insurance sector, nor any real mention of the part that the private sector can play. I raise this not as a criticism, because there is ample opportunity to put this right and to enhance the Bill’s ambition. The Bill already expands incident reporting and increases the volume and quality of cyber incident data available to regulators and public authorities. That is an excellent step forward, but if the purpose of the Bill is to improve our understanding of cyber risk and strengthen resilience across the economy then it is worth asking whether we should enable structured, anonymised incident data to be shared with the insurance sector and others who can use it.
My Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period.
What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves.
One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again.
We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator—there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and willingness to change gear, are things that we will have to come to terms with. When it is the case that we have not got it quite right, we will need to be prepared to say so.
The thrust of the Bill is certainly in the right direction. I will focus on some of the more detailed points in the drafting where I think we need to try to accomplish some improvements. There is quite a lot of looseness in the drafting, which needs tightening up. For example, terms such as “managed service provider” and “critical supplier”, as well as the wide definition of the notion of “incident”, all need greater precision. We need to avoid situations where words such as “incident” become a way in which companies that have no particular involvement get tangled up in regulation. If part of a company provides managed services, we need to know, and the company needs to know, whether the whole company is caught by the Bill or whether it is simply that part that provides managed services.
I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators.
My last thought is that we need to ensure that another definitional issue in the Bill, the level of security
“appropriate to the risk posed”,
is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.
My Lords, this is proving a fascinating and valuable debate, recognising the Bill’s many strengths, what could be tweaked, and what perhaps is missing as we look ahead. To begin with the strengths, we heard from the noble Earl, Lord Effingham, that the Bill builds on the work of the previous Government and commands cross-party support. We have just heard from the noble Baroness, Lady Neville-Jones, that national security is the first obligation of government. This is unarguably an important step in protecting the nation against cyber criminals, hacktivists and hostile states. It will quite simply make the UK a better place to live, work and do business in.
We have heard already from the noble Lord, Lord Birt, about the economic impact of cyber attacks and from my noble friend the Minister about the 11,000 NHS appointments that are lost to cyber attacks. It therefore seems very timely that we have this Bill, which will cover more essential services, improve regulatory effectiveness, and speed up responses to cyber threats. It is clearly desirable that we have a stronger board level responsibility around cyber. It must be right that data centres are now included in the Bill, helping maintain the UK’s position as a global destination for secure data hosting and for innovation. The focus on high-impact firms means that small companies will not be unduly burdened.
As my noble friend the Minister made clear, this is part of a wider national security effort that includes a cyber action plan for the public sector, a forthcoming cyber action plan for business, the Cyber Essentials certification scheme, and free cyber security support from the NCSC. All these measures will help contribute to our cyber security. The 24-hour incident reporting system will mean that regulated entities have to notify customers impacted by incidents. The tougher penalties for breaches will modernise enforcement and, I hope, improve the uptake of cyber insurance in the way that my noble friend Lady Paul has indicated is so vital. We have to hope that, together, this will mean that cutting corners will no longer be cheaper than doing the right thing. Nevertheless, given the speed at which new cyber threats are emerging, the Bill tries to strike a reasonable balance between maintaining parliamentary oversight and ensuring that the Government can act quickly, as required.
20 of 63 shown
However, where the risks are so great that public safety, the economy or our national security is threatened, it is right that we regulate. The Network and Information Systems—NIS—Regulations 2018 are the UK’s only cross-sector cyber legislation. They apply to operators of essential services in the energy, health, transport, drinking water and digital infrastructure sectors, as well as some digital service providers. The NIS regulations are designed to protect the security and resilience of our most essential services, to keep lights on, to ensure that taps keep running and to protect our NHS. We regulate only where we must, which is why the scope of the NIS regulations is precise. They are a targeted security intervention and the best tool in our arsenal to protect our most essential services. However, the regulations have fallen out of date. If we do not act, the essential services on which we all depend will remain under threat.
That is why we have introduced the Bill. The Cyber Security and Resilience (Network and Information Systems) Bill is a vital opportunity to improve the UK’s defences. In fact, it is the first Bill in British history to have “cyber” in its title. It will update the NIS regulations for the modern age and ensure that the Government can maintain their effectiveness and respond to imminent national security threats.
The objectives behind the Bill are threefold. First, it will safeguard the services on which our people rely most, making our essential and digital services more secure. Secondly, it will deliver a step change in our national security, improving our defences against the cyber attacks that threaten this country. Thirdly, it will better protect our economy. The UK will be a safer and more attractive place for businesses to establish themselves, thrive and grow.
The Bill will achieve these objectives through proportionate and timely measures, which I will speak to in turn. First, the Bill brings more sectors into scope of the NIS regulations. As our economy becomes more interconnected, so do the routes that cyber criminals exploit. For example, data centres in the UK have become critical to nearly all our economic activity and public services. From NHS patient records to financial systems, these vast digital depots are a key part of the modern world. That is why data centres meeting the Bill’s thresholds will be regulated as essential services, ensuring that they take steps to secure their networks.
The Bill also brings large load controllers under regulation. These are organisations that manage significant electricity flows to or from smart appliances. They must be safeguarded to secure our electrical grid and protect consumers using such appliances.
We are also bringing large and medium managed service providers—MSPs—into scope of the NIS regulations. These are organisations offering ongoing services, such as remote IT support or cyber security threat management, to customers. MSPs have deep access into their customers’ systems. As more and more organisations rely on them, MSPs become an increasingly attractive entry point for disruption.
Noble Lords will remember last April’s cyber attack on M&S. It involved a managed service provider being socially engineered, with attackers being able to gain access and compromise systems. We need to close this gap. But these regulations must be proportionate and targeted. Large and medium MSPs comprise fewer than one in 10 of the MSPs active in the UK but account for around 97.6% of the UK’s MSP revenue, so small and micro MSPs will be exempt from this measure. By targeting regulation where the risk and reach are greatest, we will protect almost all MSP customers without burdening small businesses.
In limited circumstances, small and micro-businesses supply critical goods or services to the essential and digital services on which we rely. The Bill therefore enables businesses, including smaller companies, supplying critical goods or services to be designated as “critical suppliers”. This is designed to combat the cyber risks stemming from increasingly complex supply chains.
Members may be aware of the 2024 attack on Synnovis, a pathology provider to some NHS trusts. Criminals thousands of miles away deployed ransomware and made Synnovis’s files unusable, delaying 11,000 appointments. This demonstrates the ripple effect that a compromised supply chain can have on the services at the ends. Duties that critical suppliers will be subject to will be set out in secondary legislation.
I turn to our 12 NIS regulators, whose sectoral expertise is critical to protecting our essential and digital services. These regulators are often operating with one hand tied behind their backs. They do not have the information, resources or levers necessary to properly fulfil their duties. For instance, organisations need only tell their regulator about an incident once it has already caused significant disruption. Under the Bill, they will have to report more types of breaches, to their regulator and the NCSC, within 24 hours and provide a full report within 72 hours. This includes incidents such as pre-positioning and ransomware, where an incident may not cause immediate damage but poses a real threat to the UK economy or society.
This will not only enable the NCSC to support those affected more quickly and warn others but allow the Government to better understand the threat landscape. Furthermore, the Bill requires digital and managed service providers and data centres to inform their customers about reportable incidents that are likely to adversely affect them. This way, customers can take appropriate steps to protect themselves.
However, effective reporting must be matched by consistency. Our 12 regulators cover all NIS sectors and the UK’s four nations. We must utilise their sectoral expertise but ensure that the rules are applied consistently. We cannot allow any sector to become an easy target. This Bill enables government to designate a single set of strategic priorities, as well as objectives tied to them, that regulators must seek to achieve. This will complement the security and resilience requirements, to come in secondary legislation, setting clear, consistent expectations and putting good practice on a firmer footing.
The Secretary of State will be required to consult the regulators on a draft of the statement before designating it. In addition, the Bill gives regulators new powers to recover their full regulatory costs from the organisations that they oversee. This includes enforcement costs, ensuring that this is not conducted to the detriment of a regulator’s books. Regulators must consult on how these fees will be calculated and publish a yearly statement to show how these funds were used.
The Bill also raises the maximum penalty enforceable for regulatory breaches while simplifying the penalty bands for easier, more consistent application. Regulators must consider all circumstances of a case before setting a penalty. This is not designed to punish companies but to incentivise their compliance. The ideal scenario is no penalties at all.
We are also fixing legacy issues concerning information sharing, so regulators can better understand what can and cannot be shared and with whom. All information shared must meet a specified purpose or require permission to be shared and be relevant and proportionate to the purpose for which it is shared. This Bill unties our regulators’ hands, giving them the information, resources and powers that they need to hold the line. That is what effective regulation should look like.
Finally, the Bill contains some important measures to enable future resilience, ensuring that the NIS regulations remain effective into the future. This Bill introduces a targeted, essential set of delegated powers to enable the NIS regulations to keep pace with the ever-changing cyber landscape. These include powers by which the Government can bring new services or sectors into scope of the regulations, so long as they meet the Bill’s strict criteria, or make regulations to further mitigate the risks from security and operational compromises. In the majority of cases, these delegated powers will be subject to consultation and the affirmative procedure will apply. Today’s threats were unimaginable in 2018, so we must not legislate as though today’s threats will stand still. These are carefully targeted, and it would be remiss not to take this opportunity to provide for careful, proportionate delegated powers. In almost all cases of these powers, the Government must consult on any changes. Parliament will still have the final say over legislation made under these powers. Our delegated powers memorandum contains greater detail.
In exceptional cases, even secondary legislation is too slow. Right now, if our intelligence community becomes aware of a NIS incident that threatens our national security, the Government have no emergency power within the NIS regulations to protect our people. This Bill provides powers for the Secretary of State to direct regulators and regulated entities where national security is threatened. This could entail instructing a sector to follow new guidance in response to a crisis or requiring an organisation to take technical steps to remove an intruder from a network. These are essential last-resort levers. The Bill has strong safeguards to ensure that they are used accordingly and only where strictly necessary for national security.
This Bill is about protecting the foundations of a modern economy. Growth cannot flourish where essential services are vulnerable, where businesses are exposed to disruption and where hostile actors can exploit weaknesses. We are not choosing between security and growth; we are recognising that one depends on the other. This will help secure the services that our people rely on, give businesses the confidence to invest and grow and strengthen our national security in an increasingly dangerous world. I beg to move.
Legislation in this field is unlikely to come before Parliament every year. That places a particular responsibility on noble Lords now to ensure that what is enacted today remains relevant, as much as it realistically can be, tomorrow.
The Government have shown an enthusiasm for regulation across a number of sectors. Sometimes regulation is necessary; sometimes it is unavoidable; but good regulation should always be proportionate. This is especially true when it comes to firms that are already navigating an increasingly complex regulatory environment and face ever more costly obligations under the Government’s direct and indirect taxing of small businesses. The Bill introduces new obligations, new reporting requirements and new compliance duties for organisations operating in sectors that are undoubtedly important to our national resilience.
It may be the case that some of this regulation is justified. However, it also raises many questions for the Opposition, the most pressing of which is: what assessment have the Government made of the cumulative regulatory burden these measures will impose on businesses? Many organisations are already subject to reporting requirements under data protection legislation, sector-specific regulation and forthcoming proposals concerning ransomware reporting. If these various obligations are not properly aligned, businesses risk finding themselves complying with multiple reporting regimes for what is in reality the same cyber incident. This would not strengthen resilience but rather create additional bureaucracy during a time of crisis.
Nowhere is this of greater concern than for small and medium-sized enterprises. Large multinational organisations generally possess dedicated legal and compliance teams and cyber specialists capable of navigating increasingly complex regulatory requirements. Smaller businesses simply do not have the resources to do that, and often these businesses are the very scale-ups and high-growth companies upon which our future economic prosperity and unicorn status depends.
Everyone wants economic growth—none more so than His Majesty’s loyal Opposition—but if the Government want growth, they must ensure that cyber regulation does not become yet another barrier to enterprise and innovation. Will the Minister therefore confirm to your Lordships’ House that the overwhelming majority of SMEs will remain outside the scope of these new regulatory requirements? By what benchmark will an SME be defined in the legislation? Will the Minister please explain what support, alongside the new obligations, the Government intend to provide for those smaller organisations that may ultimately fall within the regime? Resilience cannot simply be legislated into existence; it requires expertise and resources.
The Bill grants significant new responsibilities to regulators operating across a wide range of sectors. For these provisions to operate successfully, the legislation assumes that such regulators possess both operational capacity and the expertise necessary to exercise those responsibilities effectively. Will the Minister outline how these assumptions have been stress-tested?
Finally, the Bill confers important national security powers on the Secretary of State. Although these powers may well prove necessary, they also reinforce the importance of transparency. The exercise of national security powers should be informed by clear principles and robust accountability, particularly where they concern hostile foreign actors seeking to undermine our critical infrastructure. Will the Minister inform the House what mechanisms are going to be in place to ensure such accountability?
His Majesty’s loyal Opposition do not dispute that the cyber threat facing our country is real; nor do we dispute that the Network and Information Systems Regulations require updating. Indeed, much of the work underpinning this Bill was initiated by the previous Conservative Government. But surely we need a strategic framework instead of having to ask: why these sectors, why these thresholds and why these powers, and how does this legislation fit alongside artificial intelligence, ransomware policy, national resilience and wider cyber reform? These are not unreasonable questions. They are precisely the questions that a responsible analysis of a slew of updated proposals require, and we ask the Government to provide the strategic context which accompanies the Bill before us.
“the government may have missed an opportunity to have the same taxonomy of CNI across jurisdictions. For example, the EU’s NIS2 directive on cybersecurity includes manufacturing, public administration and food production … These sectors are critical for the UK’s national and economic resilience. Under the proposed regime manufacturers operating across the UK and the EU, when victim of a cybersecurity incident in the UK, will be mandated to report”
this to EU authorities but not to the UK.
One of the submissions notes that the Bill is narrow in scope:
“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms, including its new Cyber Governance Code of Practice”—
although we have seen that yet. The submission argues:
“Without stronger incentives, measurement and accountability, there is a risk that this … will not deliver consistent or meaningful improvements”.
It warns:
“This creates a disconnect between the regulated NIS economy and the wider, unregulated economy, despite risks flowing directly between them”.
We know the wide, deep and prolonged effect of cyber attacks on M&S, JLR and Synnovis, yet JLR and M&S will be out of the scope of the Bill, as the Commons Minister himself noted. Surely, we need to take a whole-of-economy approach. We should surely include the public sector, and economically significant sectors such as retail and manufacturing.
In evidence to our Select Committee, UK Defence First also argued that the potential loss of control of satellite communications is a “severe” national risk and that the Bill should
“explicitly treat space assets as critical national infrastructure”.
Could the Minister comment?
DSIT has estimated that significant cyber attacks on businesses cost the UK almost £15 billion in 2024. The National Cyber Security Centre reported that nationally significant cyber incidents had more than doubled in a year. As ISC2 says:
“It is no longer a question of if an organisation will be attacked, but when”.
ISACA, a global professional association focused on this area, emphasises:
“Digital service providers, particularly cloud infrastructure, also represent a growing concentration of systemic risk. The financial sector is increasingly reliant on a small number of cloud providers, creating potential single points of failure across critical services. For example, evidence presented to the Treasury Committee highlighted that 73% of UK cloud services are provided by just three providers”.
ISACA also warns:
“Cyber risk is inherently systemic, meaning disruption is rarely confined to a single organisation or sector, but is increasingly transmitted through supply chains, shared infrastructure and third-party dependencies”,
which the Minister made reference to. According to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain.
In addition, it is reported that many SMEs may perceive that they are too small to be a target, yet government research has found that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for small businesses, a cyber incident can be existential: roughly 60% of SMEs that fall victim to a cyber attack go out of business in six months. It is all very well, as the noble Earl just indicated, being outside regulation here if our SMEs simply go to the wall as a result of inadequate preparation and protection.
Evidence to our Select Committee suggests that skills shortages are a key challenge for companies, especially SMEs and those in the public sector. Is that why the Government have not included them here? That leaves our economy wide open; that is surely not the right answer. Cyber education, training, apprenticeships and investment in skills must accompany regulatory reforms, and the regulators themselves will need to be properly resourced so that they can deal with their new responsibilities. We know that public bodies have often found themselves dependent on ageing digital systems, with the risks from that.
We also need to recognise the need for the highest level of leadership in this area in companies and other organisations. It cannot simply be left to IT departments: cyber security must now be a major consideration at board level. We also need leadership from the Government, working with allies on intelligence sharing, common standards, co-ordinated responses to hostile activity, and co-operation on investigation. We know we face increasing attacks from rogue states: it is spoken of now as being low-level warfare, and we have seen the effect in many other countries as democracies are under attack.
In conclusion, although we welcome the Bill, we are seriously concerned about its limitations. A start would be to align with the EU, which already recognises that a whole-of-economy approach is the right one. I look forward to the Minister’s response.
Here is a frightening example: a Chinese entity was able to penetrate a large number of services provided by Microsoft to the US Government. As a result, the mailboxes of the Secretary of Commerce and the US ambassador to China, among many, were read. In a coruscating report, the Cyber Safety Review Board, the US government agency that investigated the breach, concluded that
“Microsoft’s security culture was inadequate”
and that the incident resulted from
“the cascade of Microsoft’s avoidable errors”.
We need to act now, to protect our wider economy as well as our public sector institutions.
I am not a technologist, but for three decades I have had to deal constantly with digital technologies and technologists from a position of authority in many large organisations in the public and private sectors, at national, European and global level. I have discussed the Bill extensively with technology and cyber experts who I know and respect, and it has become perfectly clear to me that the Bill as constructed does not begin to match the threats that we in the UK face, which will only grow.
For instance, AI will increasingly empower malign reconnaissance, enabling attacks that probe, diagnose and bypass defences. At some point, quantum computing, with its awesome power, will fatally undermine our current approach to encryption. This is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.
I conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience—OCR—to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use. For clarity, the OCR should also regulate the national infrastructure providers.
First, I propose that the OCR should regulate platform and software providers to ensure that they sell and vouchsafe secure products up front and update them immediately when vulnerabilities become apparent. That does not happen at the moment. The Office for Product Safety and Standards does that in the UK for consumer goods and the Vehicle Certification Agency does it for cars. Why should there not be protection for our vital technology?
Secondly, companies and institutions of a significant size are currently required under statute to face an annual external audit, the purpose of which is to maintain high standards in financial reporting and corporate governance, under a code set by the FRC—Financial Reporting Council. We should extend the remit of that audit, under the auspices of the OCR, to report on the audited organisations’ and their suppliers’ management of cyber security and thus bring company boards clearly into play.
Thirdly and finally, we need to professionalise the skills of the cyber and IT community, which are highly variable. Every profession of which I am aware that can have a significantly adverse impact on individuals or society faces a hierarchy of qualification before a professional can operate at different levels—whether physician, lawyer, chartered accountant, architect or airline pilot.
How far across the economy would the OCR’s remit reach? It would extend precisely to the same extent as the obligation to have a statutory audit; that is, to companies with an annual turnover of about £15 million that have in excess of 50 employees. I have a perhaps surprising statistic for the noble Earl, Lord Effingham: that would mean only 2% of UK companies. But those companies represent around 70% to 80% of the UK economy.
To conclude, we simply must be bolder. We must take the opportunity that the Bill presents better to enable every kind of organisation in the UK to withstand the ever-growing and deeply disruptive threat of cyber attack.
That set of unclear distinctions also ignores the effect of cascade. During lockdown, a health crisis turned into an education crisis, with exam results becoming an unexpected casualty of Covid. When everything is dependent on computers, and the public sector is dependent on the private sector, and vice versa, it is unwise for new legislation to specify rigid demarcations.
Those taking part in this debate have received many useful briefing notes, from the Association of British Insurers, correctly drawing attention to the great value in behavioural terms of insurance, which can have a real impact on resilience of all types as well as cyber resilience; from the News Media Association, about the real danger posed by bots, which now form 50% of all internet traffic, which is accelerating fast; and from Zurich, correctly identifying the huge role played by SMEs in the cyber security sector yet worrying about the ability of SMEs to bear the demands of regulation, not least in reporting incidents within 72 hours; and many more.
I know that the Government are committed to reforming the Computer Misuse Act in the coming national security Bill, as the noble Lord, Lord Clement-Jones, has been demanding for many a year now. CyberUp’s long-running campaign on this is far too long-running. While I am talking about cyber security professionals—because that is the point of amending the Computer Misuse Act: to give them proper protection—I cite the very helpful briefing from ISC2. It says that the Bill will dramatically increase the demand for cyber security professionals even though there is currently a significant shortage of them.
As I understand it, the number of cyber security positions in government that are currently vacant stands at 50% of the total. That is horrifying. Some 58% of UK organisations have a critical or significant skills need and 87% of teams have experienced at least one consequence due to skills needs. The members of ISC2 have said that the biggest impediment to them complying with cyber legislation and regulation is a shortage of skills, so what does this legislation do to increase those skills? Could we look at defining the meaning of a “skilled person” in the Bill?
The shortage of such skills is likely to be exacerbated by there being 12 different regulators—here again I rather echo what the noble Lord, Lord Birt, said. There is going to be a risk of duplication of regulation, even potentially of contradictory regulation. What is an organisation meant to do if one regulator requires that it does one thing but another regulator requires that it does not? Will the Government ensure that regulators adopt common forms of evidence for demonstrating compliance and common cyber security standards? How does the legislation take into account the fact that many organisations will be subject to foreign legislation as well? I agree, as on many other things, with what the noble Baroness, Lady Northover, said about encouraging alignment with the European Union. How are we learning from overseas experience?
This is a well-meaning but muddled attempt to deal with an exceptionally fast-moving, difficult problem. Governments always find it hard to keep up with the pace of technology, so is it right that we should re-examine this Bill only every five years? The Secretary of State should have to report to Parliament earlier than every five years. I know I sound a bit miserable, but I support the Bill. I really do. It could be better, and we will have a lot of work to do in Committee.
The purpose of this data is to provide a clear picture of the threat, so it is important that we share it as widely as possible with those who can help protect us. I ask the Minister to consider this. It would be an extension to the Bill, not a departure from it. It would build on the reporting architecture that the Bill already creates, and it would do so in a way that supports the Government’s whole-of-society approach to resilience. The principle is simple: better data enables better modelling; better modelling enables better pricing and strengthens resilience; and better pricing increases access to cyber insurance and strengthens resilience across the entire economy.
Cyber insurance is already an important part of keeping businesses safe. We know that it enables us to transfer financial risk so that it is shared between businesses in the private sector rather than being borne by the taxpayer. I am sure we all agree that cyber incidents and the cost of recovery should, in most cases, fall on the organisations affected.
As noble Lords know, insurance remains one of the most effective and economically efficient ways of achieving this, but it does not just pay out after an incident; it changes our behaviour before one. To secure affordable premiums, organisations are required to adopt practical cyber hygiene measures, such as multifactor authentication, timely patching, network segmentation and robust incident planning. These requirements are not set in stone but change as the threat involves. Beyond legislation which will mandate a change in behaviour, there are very few other ways to incentivise the scale and pace of the behavioural change required to improve our resilience than insurance. We have locks on our doors, safety features in our cars and sprinklers in our buildings because insurance encouraged and rewarded these measures. It has the potential to play the same role in cyber resilience.
It is worth noting that Cyber Essentials, which the Minister mentioned in her opening remarks, is believed to be held by just 1% of businesses. Although the growth rate is increasing, it would take decades to get to the point where Cyber Essentials is going to provide us with the level of resilience that we need, so we need to do something different and we need to incentivise things differently.
As we also know, cyber insurance helps mitigate the moral hazard where organisations underinvest in security because they assume government or someone else will bear the consequences. The risk to our economy makes this unsustainable. Independent analysis commissioned by the Department for Science, Innovation and Technology, which sponsors this Bill, shows that cyber attacks impose almost £15 billion of economic harm on the United Kingdom every year. That is equivalent to one month’s NHS expenditure, almost the entire annual policing budget, 30 new hospitals or more than three decades of universal breakfast clubs for every primary school child. It is enough to wipe out an entire year’s profit for vast numbers of British businesses.
Yet only a small proportion of that national cyber risk is insured. Based on the department’s modelling data, together with that of the Association of British Insurers and Lloyd’s of London, it is estimated that the UK cyber insurance market currently covers approximately £700 billion of annual losses. In other words, less than 5% of the economic harm caused by cyber incidents is insured. Therefore, more than £14 billion of losses fall directly on businesses, public services and, in some circumstances, the taxpayer. We all know that Marks & Spencer had cyber insurance and reportedly made a claim of around £100 million following its cyber incident last year, whereas Jaguar Land Rover did not have any cyber insurance and, in the end, the Government had to step in and provide a loan. As the frequency and severity of cyber events increases, it is in our interest to increase insurance take-up.
The Bill strengthens reporting obligations. Named suppliers will be required to report significant incidents within 24 hours and to report fully within 72 hours. The Bill expands the definition of a reportable incident to include pre-positioning attacks, significant near misses and incidents likely to have societal impacts even where disruption has not occurred. It must be permissible for regulators to share this information across public authorities and with insurance companies to create a more coherent national understanding of cyber risk. If we accept that it is possible to share in some circumstances, it must be possible for us to consider that it could be shared in others.
Lloyd’s of London, the ABI and brokers including Marsh, Aon and Willis Towers Watson have warned that scarcity of reliable data is one of the principal constraints on market and product development, so why would we not want to facilitate improvement in cover? Market analysis suggests that there is potential for the global cyber insurance market to expand annually by 25%. If the UK were to capture even a modest share of that growth, our domestic cyber insurance market could expand from its current value of around £700 million to well over £2 billion in a few years. This would lead to more highly skilled jobs in London and would maintain London’s position as the world’s leading centre for specialist insurance.
The Bill sets us in the right direction, but we have an opportunity to ensure that insurance is properly recognised as part of the resilience community. I believe that enabling structured, timely, anonymised data to be shared with insurers would be a modest extension to the Bill but would have the capacity to deliver enormous change to the cyber resilience of our country. I hope that the Government will consider this as the Bill progresses through the House.
There is plenty of implementation detail on which we will need to have a closer fix. I am willing to give the Government the power to fill in the detail and update the law through secondary legislation, as it seems to me that we cannot always have primary legislation doing everything. However, we will need a duty to consult written into the Bill for it to be a safe proposition. One thing I would like to ask the Minister is about the timetable for secondary legislation. Will the Government be willing to consult when it comes to putting that through? That will be a very substantial part of the Bill.
I want to make a couple of comments about the effects of the scope of the Bill. First of all, with the exception of service providers, who are classed as “critical suppliers”, and data centres, the Bill, as other people have remarked, is exclusively concerned with the public sector. As the Government Minister and indeed others have pointed out, some of the biggest losses have occurred in the private sector. I do not need to describe these, as they have been described already.
The Government may argue that they properly seek not to regulate the private sector. I certainly have considerable sympathy with that, but it is not satisfactory from the point of view of the taxpayer that the Government had to bail out with public finance Jaguar Land Rover. Under current conditions, I do not think that that breach, which was expensive, is likely to be the last one with sizeable financial effect.
The Government have recognised the problem and are encouraging private sector companies to make a pledge to improve the management of cyber security at board level. I am all in favour of that: improve reporting in the corporate code and increase activity by the audit committee, whose members, if properly equipped with cyber expertise, will make a valuable contribution. That is part of the way that we must move forward. Having said all that, private sector security self-help, while essential, is not sufficient. So what should we do?
The Government correctly tell us that their first duty is the defence and security of the nation. Cyber security strategy—which I know something about, having been involved in it—was founded on the proposition that the protection of the economy involved active partnership between public and private sectors. The NCSC does a vital job in increasing understanding about the threat and giving advice and guidance on countering it, but it could do an even more important and larger job. It was intended at the outset to be more public-facing than is currently the case. It has, to some extent, retreated from its previous public start. I would like to see the NCSC re-emerge from the shadows with more threat analysis, advice and guidance, and its funding increased to do this.
This would be particularly helpful to SMEs. We have all been worried about their access to expertise and considered that the cost to them of security, which is not insignificant, should be somehow alleviated. They are valuable to us. Small companies provide very important parts of larger systems. If the NCSC were to be a much more active security partner to the corporate world, there would be a strong case for financial support from the private sector to it, to make this much more of a joint enterprise.
I urge the Government to put their intelligence capabilities to greater effect in supporting the private sector to raise its level of security. I do not think this is beyond us. We ought to try to do something where there is much closer co-operation between public and private sectors. The banking world, though different, gives us some pointers on the way in which that could be done.
Secondly, within the public sector, the scope of the Bill is puzzlingly selective, as other speakers have touched on. There is palpable anxiety among the general public about the security of One Login and accessing government services safely. This is a moment when the Government could increase confidence. However, not all government services are covered. To take an example, DWP has in its possession detailed personal—not to say intimate—information about its clients and beneficiaries. Surely it should be a candidate for coverage, but it is not. What are the criteria that govern whether a public sector service is covered or not? On the face of it, I do not think selectivity looks wise. The Government have chosen—
I turn to the question of tweaks. Many of them have been touched on so I will not dwell further on them. We heard from the noble Lord, Lord Arbuthnot, about the importance of the workforce and the increasing demand for cyber security skills. Will the proposed codes of practice include a framework for workforce development and training?
The second tweak, as many noble Lords have touched on, is to the Bill’s scope. I have some sympathy with the noble Baroness, Lady Northover, about the case for closer alignment with EU regulations when we have British companies operating and complying with EU legislation in the areas that are covered. I also think that a broader scope would drive the sort of behavioural change that my noble friend Lady Paul cited. I note that the Minister already said that secondary legislation is available to expand the scope. I look forward to her comments on why we do not have a broader scope now, given the groundswell already in this debate, perhaps to include public administration, in particular local government, given the scale and sensitivity of data and the essential nature of public services.
The third tweak is something else that has been widely noted already: the risks associated with having 12 regulators. I appreciate that the Government’s intent is minimising regulatory upheaval. There is a balance to be struck. The noble Lord, Lord Birt, approached the issue of risk from the desire and need to ensure expertise. I will look at it through the lens of the risk of duplication. At lunchtime today, I spoke at a NED event hosted by a US law firm that counts among its clients a major cloud provider, insurance companies, professional services firms and a board effectiveness practice that works with both public and private sector organisations. The strong consensus in the room was that a common cyber security standard across all regulators, upon which appropriate sector-specific requirements could be layered, merits consideration. This approach is in the spirit of the Government’s amendments, tabled in the other place, to streamline reporting and avoid unnecessary complexity. I hope that issue is given further consideration.
In my few remaining minutes, I will touch on what is not in the Bill. As others have noted, technology is advancing faster than government frameworks can keep pace with it. The Bill was published last year, just as it became clear that AI was tipping the advantage to attackers. Attackers need to succeed only once, while defenders potentially need to patch millions of users. There is currently no technology to automate patching at the pace required. The Bill needs to say more on the role of integrating AI tools into cyber defences. The Bill arguably has an AI-shaped hole in it, although I am encouraged that the incoming Prime Minister has signalled a fresh look at AI regulation. Even Sam Altman, faced with a capricious President, has come round, writing in the FT that
“citizens and their elected representatives must make the rules”.
We have also seen the Five Eyes intelligence partnership warning in a very rare joint communiqué last month that the West’s adversaries were within months of developing cyber attacks that could overwhelm the defences of Governments and companies and noting that frontier AI models will fundamentally transform cyber capabilities. All this is now with us, so raising our defensive capability in the face of this rising AI functionality will be essential. Our spy chiefs are asking western companies to use AI models to strengthen their defences.
I fully appreciate that the Government are completely across this threat landscape. The question is: how do we collectively legislate or regulate in such a threat landscape? Some suggestions that we can consider in Committee are, first, that advanced AI providers could perhaps be designated as covered entities under the Bill. Secondly, since the impact of AI in the cyber field is increasingly systemic rather than sector specific, perhaps we need common AI cyber security guidance supporting all regulators in this fast-moving landscape as they then layer on the needs of their sector. Thirdly, perhaps there should be an AI field in the mandatory incident reporting regime. Finally, we should perhaps think about an AI oversight framework giving the NCSC more teeth and the AISI a more co-ordinating role.
In conclusion, as widely recognised, the Bill will support our economy and our people and make the country safer. It is part of a package. It is a crucial building block rather than the final destination. I strongly commend it to the Chamber.