Contributions
235 recent contributions in Hansard
HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)I thank the Minister for his patience. He mentions a specific example of where he will ensure that the NCSC is resourced up. Do we have specific examples that have happened…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)Could the Minister repeat that?10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)We heard from the Information Systems Audit and Control Association that codes work best when they reflect operational reality. Given their evidential status, can the Minister…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)These procedures are standard, but the powers they apply to are significant. Where regulations under part 3 would materially expand duties or bring new actors into scope, have the…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)As the Association of British Insurers has highlighted in its written evidence, the way cost recovery operates will shape behaviour on the ground. Can the Minister reassure the…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I want to use new clause 1 as a lens to view a wider question that sits underneath clause 24, rather than as a verdict on the clause itself. That question is how we decide, in a…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)Having worked in business, I know that the words we use to ensure that the capabilities are there are easy to say but not always easy to deliver. How will the Minister ensure that…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)New clauses 6 and 7 sit together and are linked by the same practical concern regarding clarity and workability when an incident is unfolding. I will start with new clause 6.…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)As the Minister is saying, clause 28 is meant to help Parliament understand how regulators are responding to the statement of strategic priorities. Can he say a little about how…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Third sitting)Clause 4 relies heavily on capacity as the trigger for regulation. I understand why that is attractive: it is measurable. But capacity is not the same as criticality, and a…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Third sitting)My hon. Friend is making a very good point, which also applies to improving board awareness and ensuring that the enforcement of the regulations incentivises boards to take the…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Third sitting)Clause 7 is definition-heavy, and rightly so; these terms decide who is regulated and who is not. My only observation is that cloud models are, as the Minister knows, evolving…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)Bringing MSPs into scope is the right direction of travel, and MSPs sit at points of concentrated risk, but they are not all the same and the real risk is not size alone but the…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Third sitting)Does my hon. Friend agree that, although we support the intent behind the Bill, clause 2 does a lot of framing work but does not necessarily consider the extensive perimeter that…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)I think my hon. Friend is about to reference the commercial impacts on MSPs. We have already referenced the fact that they are of many different sizes. One of the concerns the…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)On my hon. Friend’s point about the lack of clarity in the Bill, there is a real possibility that firms will find that an MSP has one view of an issue while their client has…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)The clause merits close scrutiny, because it is the point in the Bill where risk is supposed to be addressed beyond the individual operator and into the supply chain. In plain…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)The clause is drafted broadly, which is understandable, but in practice many of the supply chains, as my hon. Friend has ably demonstrated, involve several layers of providers and…05 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (First sitting)Q Returning to the supply chain risks, I want to ask you about the difference between OT—operational technology—and IT, and whether there is sufficient detail in the Bill to…03 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (First sitting)I am so sorry. Could you possibly speak into the microphone? I cannot hear you. Stuart McKean: Sorry. I was saying that the cyber-criminal does not care about lines, geographies…03 Feb 2026