Contributions
353 recent contributions in Hansard
HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)I am grateful to my hon. Friend the Member for Harlow for his affirmation of that important point of parliamentary scrutiny. As I mentioned, the report in question will set out…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)The hon. Member raises a very important point. We want Parliament to play an important role in the scrutiny of the overarching regime as a whole, but particularly in the operation…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)I thank the hon. Member for her point. Perhaps I can give a flavour of the objectives I might expect in a statement and assure her of the independence of sector regulators.…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)Clause 25 introduces a power for the Secretary of State to designate a statement of strategic priorities for the implementation of the NIS regulations. The NIS regulations are…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)I will start by addressing the questions raised by hon. Members, including the hon. Member for Spelthorne, who concluded by setting out a general philosophy of how we thought…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 24 defines key terms for this part of the Bill, and in doing so introduces two delegated powers. Those powers enable the Government to bring new sectors into the scope of…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 23, through schedule 2, introduces a number of minor and consequential amendments to the NIS regulations, necessitated by the more substantive changes introduced by the…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 22 sets out, through schedule 1, consequential changes to the regulations in relation to enforcement and appeals. That is to ensure that the regulations work effectively in…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)The shadow Minister makes a really important point: cyber-security must be taken seriously at the highest level—at board level. It is part of the cyber assessment framework, which…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I can see the shadow Minister’s hypothetical point, but I assure him that if there is some universal, consistent practice on the part of an MSP to avoid liability, where liability…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I thank the hon. Member on both fronts. On the penalty bands, clearly defined parameters are set out in the Bill, and my hope is that that increases the effectiveness, the clarity…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 21 reforms the enforcement regime for the NIS regulations. It seeks to ensure that providers of the UK’s most essential services are complying with their obligations under…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I thank the hon. Member for asking and repeating the question. The purposes of the provisions on information requirements are focused on ensuring that regulators can conduct their…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I would not want to imply that every organisation has a business continuity plan, but the simple point is that the framework for assessing critical third-party suppliers is…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Although I will not specify prescriptively what the activity and flow ought to be, I can share from my experience that many large-scale businesses—and indeed many medium and…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Just so that I am clear, not least for future records, I think the case described is one where the client is not in the Bill’s scope but is provided to by an MSP that is in the…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)I will take each of those three questions in order. The hon. Member for Bromsgrove raised a very important point—shared, I think, in sentiment across the House—about ensuring that…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 20 introduces important updates to the information-gathering powers that regulators have under the NIS regime. It ensures that regulators are able to collect any…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)As I have mentioned to the shadow Minister, the Minister for Digital Economy, the Secretary of State and I have engaged with a number of the regulators in scope here. Both those…10 Feb 2026HANSARDCyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)Clause 19 sets out that regulators must provide guidance on specific issues, including security requirements and incident reporting notifications. Guidance already plays an…10 Feb 2026