House of Commons (26) - Commons Chamber (12) / Westminster Hall (5) / Written Statements (5) / Petitions (2) / Written Corrections (2)
House of Lords (16) - Lords Chamber (13) / Grand Committee (3)
(2 days, 7 hours ago)
Grand Committee(2 days, 7 hours ago)
Grand CommitteeMy Lords, if there is a Division in the Chamber while we are sitting, this Committee will adjourn as soon as the Division Bells are rung and resume after 10 minutes.
(2 days, 7 hours ago)
Grand CommitteeMy Lords, in moving Amendment 17, I will also speak to Amendment 28, which is closely related. Amendment 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. It does not affect the amendment that I think the Government will move immediately afterwards.
As drafted, Clause 15 gives the very strong impression that an incident “capable of having” an adverse effect on security must be reported. If this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident “likely to have” an adverse effect. I think it is a widely held view—it is certainly the case in the industry and a point with which I agree—that “likely to have” would be far too wide a definition and would lead to extensive overreporting and an undue and unnecessary burden on regulators. Looking at the drafting, I asked myself what was the point of the “capable of having” definition in Clause 15.
I shall put forward a hypothesis. It would be very helpful if the Minister could confirm that it is a correct understanding of the existing draft, and that it does not mean that all incidents capable of having an adverse effect on security will need to be reported. Is it right to say that the definition in Clause 15 of what constitutes an “incident” applies across the whole of the regulations, and therefore feeds into security as well as reporting duties? That is to say, firms have a preventive duty to defend against what could be and what could happen, as well as what is likely to happen. That is a preventive duty. Can the Minister confirm that the phrase “capable of having” means that firms should have adequate preventive policies, but it is not—this is where the point comes in—the trigger for an incident to be reported, because in each case this requires it to have affected or be affecting the system?
I am making a distinction between “capable of having”, which applies to a duty to pursue preventive policies, and the trigger of the duty to report, which lies not in the phrase “capable of having” but in “likely to have”. Then there are examples of what I am saying in the regulations, and I can cite them: Regulation 11(3)(a), on page 21 at line 35; Regulation 12A(2)(a), on page 26; and Regulation 14E(2)(a), on page 29 at line 27. If the Minister can confirm that, within existing structures, what I have said is correct—there are no circumstances in which “capable of having” would be the reporting trigger—that would be a very helpful clarification. I will listen closely to the Minister’s reply on this point.
There is a “however”: there is a snag when it comes to the introduction of data centres, and that is the object of my Amendment 28. Data centres sit outside the existing structures that I have just talked about but, as yet in the drafting, there are no reporting trigger regulations for them. It is intended that the data centres should be, in future, big players in the system, so it matters that there is a gap in our information about the circumstances in which they would have a duty to report. It is an odd anomaly. New Regulation 11A(3)—on page 23, from lines 13 and 14 onwards—makes reportable
“an incident which could have had … a significant”
effect, whether or not it had any impact at all or anything was affected. As there is no list of factors for judging what constitutes a significant attack in the Bill, it makes it quite difficult to interpret.
For the operators of essential digital services and managed service providers, such factors are set out expressly in the new regulations in the Bill. However, they are absent for data centres. Why is this the case? What is the rationale for what appears an anomaly? It means that, when reporting an incident, a data centre has to do so when any of the following have had, or were likely to have,
“a significant impact on the operation or security of the network and information systems relied on to provide the data centre service … a significant impact on the continuity of the data centre service … or … any other impact, in the United Kingdom or any part of it, which is significant”.
These are very wide definitions of liability to report, and the discrepancy between them and those applying to other operators seems neither sensible from a security point of view nor fair for different business circumstances, as there will be all sorts of different businesses using data centres.
Although I hope that this will not be the case, I fear that the Government may say that the thresholds and factors for all categories of business will be set out in secondary legislation and subject to consultation. I ask the Minister to think hard about the adequacy of that reply. We are talking here about a penalty-backed duty, which is the core element of the Bill; it is not some minor point. It would seem a poor legislative approach in a foundational Bill for a new regime to fail to define the factors leading to a penalty for a significant segment of providers, when there are indicators in the Bill for other categories of provider. Those other players have different, less demanding and more sensible terms for a trigger for reporting. If data centre regulations need to be different from those for the other players that I have mentioned and the rest of the market, can the Minister explain why? It is the kind of complexity that will give the sectoral approach to regulation a controversial reputation, because it immediately raises the issue of making different rules for people who are apparently, in practice, in the same category. I hope that is not the case and that the issue can be resolved by remedying the drafting.
To sum up, in addition to my request for a clear statement from the Minister about the trigger for a duty to report in existing structures being related to the likelihood of an adverse effect on security and not on capability, I hope she will also take seriously the need to level the playing field for data centres on this issue and remedy what seems an important defect in the drafting of the Bill. I beg to move.
My Lords, I will speak to this core group of amendments on incident reporting, in particular to Amendment 165, standing in my name, while addressing the other amendments in this group. First, Amendment 17, which was very cogently set out by the noble Baroness, Lady Neville-Jones, addresses what has emerged as one of the most contentious technical faultlines, in our view, across Part 2 of this Bill: the statutory threshold that triggers mandatory incident reporting to the designated competent authority, the NCSC. As the Bill is drafted, Clause 15 fundamentally widens the reporting net by redefining a reportable incident to include any event that is merely “capable of having” an adverse effect on the security of network and information systems, as the noble Baroness described.
While one can readily understand the cyber security community’s desire for complete visibility, in practice, the phrase “capable of having” is an operational disaster. In the daily reality of enterprise networking, thousands of automated port scans, routine phishing lures and perimeter firewall probes occur every hour. Almost every single one of these low-level events is technically capable of having an adverse effect, if multiple defensive layers were to fail simultaneously. By forcing businesses to notify regulators under threat of £17 million penalties whenever an event is merely “capable” of causing harm, the Government will unleash an administrative tsunami of defensive reporting.
Rather than enhancing national security, this compliance overload will drown NCSC analysts in background noise, making it far harder to detect sophisticated state-sponsored attacks. Amendment 17, in our view, would resolve this by replacing “capable of having” with the objective standard of “likely to have”. This would restore the established probability threshold used across UK regulatory frameworks, ensuring that mandatory notifications are reserved strictly for genuine material threats where there is a real likelihood of operational compromise.
This issue is compounded by the Government’s own drafting amendments, specifically Amendments 19, 36 and 44, which replicate the ultra-broad definition of compromise throughout parts 2 and 3. By removing “users” from Clause 15 and redefining data compromise to cover any event affecting data stored or processed on a system, the Government are dramatically expanding the notification net to include technical data anomalies that cause zero destruction or loss to actual customers. Combining this sweeping definition of data compromise with the low “capable of having” trigger will hugely affect responsible operators. It will force critical suppliers and small digital providers to spend their limited resources filling in compliance paperwork, rather than actively defending their infrastructure.
We risk creating a reporting system that captures everything and understands nothing. We must have objective reporting thresholds. By accepting the noble Baroness’s Amendment 17, restoring the “likely to have” test, we would ensure that mandatory reporting delivers high-quality actionable threat intelligence, rather than an unmanageable flood of routine notifications.
Under the new reporting regime, hundreds of incidents will be notified to regulators and the NCSC, but at present the Bill lacks any mechanism to ensure that aggregate intelligence is shared with Parliament or industry. Under Amendment 165 in my name, I propose that the Government lay an annual anonymised report before Parliament, detailing incident volumes, sector breakdowns and principal attack vectors. This would provide software developers and CNI operators with the situational awareness needed to harden defences.
My Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.
Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.
We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.
Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.
Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.
For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.
I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.
First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.
The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.
These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.
I turn now to the amendments tabled by—
May I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.
Baroness Lloyd of Effra (Lab)
We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.
I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.
On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.
To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.
There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.
My Lords, I have listened carefully to what the Minister has said. I had hoped that we would get greater clarity; I fear that the fog has increased. I entirely accept the point that companies have a general duty to take as many preventive measures as they can to increase security. That is a different matter, it seems, from what should trigger the reporting duty. Precisely what the Minister has laid out leads to a situation of an overload of reporting of items that do not require that kind of treatment.
I am extremely concerned that the industry fears—and it has a real point—that it will be caused to be active in areas which lead the regulators to be swamped and which reduces the real level of security, because it is doing things that it does not really need to. For those of us who are willing to contemplate a system of regulation that allows for differentiation between sectors—in other words, a sectoral approach—it is the kind of thing that will lead to a terrible muddle. I am unhappy about the response that has been given to that general point. It strengthens the cause of those who say that we should have one general regulator and that it should set the rules.
Secondly, on the question of data centres, I cannot understand that a data centre could alter the rules under which companies, if they happen to be located in a data centre, are operating and doing their business. I fear that this is an issue to which we will have to return on Report, because as things stand we are not heading in the right direction. I beg leave to withdraw the amendment.
My Lords, I rise to introduce a large number of amendments, for which I apologise: Amendments 18 to 23, 25 to 31, 33 to 39, 41 to 47 and 49 and 50.
Full house. Fear not—it is not as complex as it seems. These amendments, which I have introduced, and I am grateful for the support of the noble Baroness, Lady Kidron, and my noble friend Lord Holmes of Richmond, seek to strengthen the staged reporting requirements of the four different groups of entities, so each change must be repeated four times. Because of the way in which the Bill is drafted, I was unable to introduce the change just once; I had to put in each micro phrase, hence so many amendments. The aim is to strengthen the staged reporting requirements for operators of essential services, data centres, relevant digital service providers and relevant managed service providers, so everything is multiplied by four.
The Bill, as it stands, requires only an initial report within 24 hours and a full notification within 72 hours of an incident. My amendments would add two further stages: an intermediate report which is capped at 14 days after the incident has first been notified, or sooner if the relevant regulator requires, and a final report within one month. In all four cases, the reports must be given without undue delay, so that regulated entities cannot use the timeframes as an excuse to delay until the end of the time period.
These amendments are in line with the EU’s NIS2 directive. The reason why I have introduced them, as I said at Second Reading, is that I have lived this. I absolutely understand what the fog feels like. In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report. You start to understand, 72 hours later, quite how awful it could be. That is your second report, where you start to get real data, because your teams have worked all night, usually all around the world, to try to work out where the malign actors have gone. But it is really only after a couple of weeks that you have a proper sense of what has happened.
I recognise that my experience is, obviously, 10 years old, but quite recently I had a long conversation with some of the leaders at Marks & Spencer. The thing that scared me most was that it seemed so similar to my experience 10 years ago and that this basic process is likely to be the same. So we need the requirement to properly update whatever you learn two weeks on, and then a month later the fog starts to clear and you have a proper sense of the real scale of the problem.
The reason why we need to put this in legislation is that, throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo. Your board will be encouraging you not to tell everyone, the public will be telling you not to tell everyone and there is a real risk, unless you are forced to, that you just make it easier for the blackmailers to do their work. My personal experience was of being blackmailed during this process. Obviously, at the time, there were none of these regulations. I can tell your Lordships that there were so many voices saying, “Why don’t you just shut up? You don’t know what’s going on yet. Keep quiet”. Yet if, in the fog, you share this information with regulators and with law enforcement agencies, that is how the law can prevail. It is how regulators can work out what is happening and how they can warn others who might be affected. It is how the law enforcement agencies can do their work to try to find the bad guys.
This really matters if we want the rule of law to exist in the digital world, because the incentives, even for entirely well-meaning and upstanding leaders of corporations—and government departments, dare I say—are to keep quiet. We need to put these reporting requirements in the Bill. All the amendments would do is bring our own legislation in line with the NIS2 framework. To be honest, many of these companies and these incidents are likely to need to be reported in Europe at the same time as they are in the UK. As my noble friend Lady Neville-Jones said, there is a real primacy on keeping things simple. The more we can mirror and have exactly the same reporting requirements, the easier it will be when you are in that terrifying moment when you realise that you have a serious incident. I beg to move.
My Lords, I am very glad to support all the amendments; I will not read them out again. The noble Baroness, Lady Harding, has already convincingly set out the case. I really hope that the Minister recognises that these amendments are born out of lived experience, which is characteristic of this House and very precious when considering how legislation actually impacts in the world at times of crisis.
The amendment specifically calls for staged incident reporting, to create a drumbeat of information and oversight so that damage can be minimised. Cyber attacks move quickly and are extremely confusing for those involved. Staged incident reporting enables regulators to have a more immediate understanding, so that they can offer support, anticipate spread and learn lessons for strengthening guidance in the future.
My Lords, it is a pleasure to support these amendments. I have signed all of them, although in doing so I almost got a serious case of electronic RSI. They have the great good fortune of being clear, precise and aligned with existing regulations in other jurisdictions. As my noble friend Lady Harding has already pointed out, many businesses will have operations in multiple jurisdictions. For something as significant as reporting, why would we not follow NIS2 in this respect?
The clarity of the amendments is their strength, even more so when compared with what is currently in the Bill in this respect. What we are trying to achieve from these changes is clear. The 24-hour initial reporting period makes sense: of course it does. As my noble friend Lady Harding pointed out, what one knows at that point is that something is happening and a report is made. In many ways, that is all that needs to be known and all that needs to be reported.
To have a situation as currently set out in the Bill, 24 then 72, means that in that period so much would need to be known to comply with the provisions set out in the Bill that it is just not realistic. This staged approach is both clear and precise. It enables what the purpose of the Bill is all about, which is to support the individual business or entity that is under attack. Crucially, as other noble Lords have said, it puts the power in the collective. As a consequence of one attack, the collective can benefit if there is a sense of commitment to this reporting schedule. That will come only if it is in this stage 4, as clearly set out by my noble friend Lady Harding.
If we want to enable businesses and other entities to really commit to this process—not just be dragged there by force of statute but have it as a means of business as usual, a real cultural change and a commitment to the positivity of this—it has to work for them. This staged process not only does that but, by aligning with NIS, stops this being yet another burden added to business: added unnecessarily and less effectively than what these amendments propose. I very much look forward to the Minister’s response.
My Lords, good can come out of bad events. The experience, as well as the speech, of my noble friend Lady Harding is one such good aspect. If it combines with bringing us into line with European practice, which so many businesses already have to follow, so much the better. I hope the Minister will be as sympathetic as she possibly can to my noble friend’s amendments.
My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.
In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.
I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.
Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.
As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.
These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.
The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.
That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?
Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.
I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for their amendments in this group. We have spoken previously about the importance of effectiveness, proportionality and clarity. I absolutely hear the experience of the noble Baroness, Lady Harding, in leading a telecommunications company and the experience it had.
We have learned from experiences across all sectors in introducing the new regime that is in the Bill, which puts in, as others have said, a staged approach that includes an early alert to regulators and the NCSC within 24 hours. That will provide awareness and enable the NCSC and regulator to provide early support, as well as potentially understand whether it is impacting multiple regulated entities.
My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.
What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.
Baroness Lloyd of Effra (Lab)
I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.
My Lords, I have listened really carefully to the Minister and thank her for her response, but I feel that we just had a completely black and white no, which is extremely disappointing. We have had something almost worse than a black and white no, because if I heard her correctly—I will need to go back and read it again—I think she has added uncertainty, because suggesting that it is okay because regulators have the ability to ask for extra reporting is a company’s worst nightmare. What you want is really clear black and white guardrails, as we have been trying to introduce in these amendments.
I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face. I would be very keen to understand, as the noble Lord, Lord Clement-Jones, has just said, what consultation has really happened and to have a recognition that you need to consult organisations that have experienced a substantial cyber attack. If an organisation has not, then I am afraid it will want to keep quiet and will not want to report anything. It is easy to ask broad groups of organisations, “Would you like more reporting?” We all know what the answer to that would be. That is an easy consultation.
I would really value more detailed discussions with the Minister and her officials between now and Report, because I feel that we will come back to this, particularly given the support that my amendments have received from across the Committee, for which I am extremely grateful. I beg leave to withdraw the amendment.
Baroness Lloyd of Effra
Baroness Lloyd of Effra
Baroness Lloyd of Effra
I apologise, I stand to speak to a whole other group of amendments that suffer from the same challenge of needing to be repeated four times, which is why I suggested to the clerks that we degroup them, otherwise we would have got into a real muddle.
This group seeks to address the obligation to report incidents to customers, as the Minister referenced in her remarks earlier. Currently, the Bill requires notification only where a customer is,
“likely to be adversely affected”.
The obligation is to explain the nature of the incident and why the customer is affected. My amendments seek to broaden and deepen that duty. Customers must be notified where an incident has caused or has the potential to cause severe operational damage or financial loss, where I hope my drafting has not fallen prey to the issue that my noble friend Lady Neville-Jones, addressed in Amendment 17. If it has done so, we obviously need to address that.
The duty is extended to cover related natural or legal persons who could suffer considerable damage as a result. The regulated entities must also advise customers on what measures to take in response. Probably most importantly in this group of amendments, the entities must keep customers updated until the incident is resolved, whereas at the moment the Bill only requires them to notify customers once and then leave them hanging, waiting to find out what is going on. Together these amendments would ensure that customers are told promptly what to do and are kept informed throughout the incident until it is resolved. They also follow the NIS2 directive in requiring advice on protective measures and go a little further by making it a requirement to communicate to related persons as well.
Sadly, I have personal experience in this, not from my TalkTalk times but much more recently. I suspect anybody who is on a board or who has chaired a business has experienced this. An organisation that I chair is the customer of a managed service provider that recently experienced an incident. It did not tell us. The incident was to do with some of our staff payroll information, so it was sensitive and important. When it did tell us, it then did not keep us informed about what was going on. So I feel that pain.
I know that some noble Lords may have concerns that we do not want to create panic by endless notification. I absolutely agree. Hence my attempt to define this as severe operational damage. I would very much welcome input between now and Report if we can tighten that wording to make sure that this does not represent lots of unnecessary email alerts telling you that a system three stages back in the tech stack might have been affected. But when your customers’ data has been exposed in a cyber attack through a managed service provider, data centre or digital service that you use, it is entirely reasonable that those companies have a requirement to inform and keep you updated during the incident. That is all that these amendments seek to do. I beg to move.
My Lords, for reasons that I do not understand, I do not have my name on these amendments, given all the others from the noble Baroness that I do, but I support them. It is funny, because when I came back from holiday in August, I had no fewer than five emails from companies saying that there had been data breaches in which I was involved, and I had that exact thought—“What now? What do I do? What’s next? How serious?”—and did nothing.
My Lords, I support all these amendments. They bring the customer perspective well into focus, which the Bill is currently chronically insufficient on, in my view. As the noble Baroness, Lady Harding, identified, if these amendments do not quite get to the precision of it, how will the Government bring something forward that will do the trick perfectly? This is a critically significant element which is currently not within the Bill. On an allied point, which has already been nodded to, I ask the Minister, since the Bill’s drafting seems to like “likely to”, and, in earlier additions “capable of”, why would there not be coherence through the Bill as to the type of legal construction that is being used throughout? Surely, that would not only be beneficial and more precise, but it would give greater clarity to all those who have to engage with the issues therein.
My Lords, I, too, support these customer notification amendments tabled by the noble Baroness, Lady Harding of Winscombe. As I have said, the noble Baroness brings vital lived experience, in more ways than I thought, from the front line of corporate crisis response. When a major cyber breach occurs, vague statutory requirements to notify customers
“as soon as reasonably practicable”
lead to corporate delay. Amendment 58 would replace this with a strict statutory 24-hour notification clock, while Amendment 65 would establish explicit harm triggers and require providers to provide actionable remediation advice to affected customers. Look at what Amendments 60 and 65, in particular, would achieve across Clause 16.
Under Amendment 65, notification would be explicitly triggered whenever an incident causes or threatens severe operational disruption, substantial financial loss or material harm to downstream users. Furthermore, Amendment 71 would place a positive duty on the provider to advise customers on immediate remediation steps that they can take. In the cyber realm, time is the attacker’s greatest ally. If a hospital, bank or small supplier is informed within 24 hours that their cloud or managed service provider has been breached and given technical instructions on how to isolate their systems, they can prevent contagion before it paralyses their operations. We must ensure that customer notification is prompt and meaningful, empowering downstream businesses to isolate compromised systems before contagion spreads, so we very strongly support these amendments.
My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.
Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.
It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.
Baroness Lloyd of Effra (Lab)
I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.
I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.
We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.
I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.
On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.
I thank all the noble Lords who, again, have supported my long list of amendments and I thank them for their excellent contributions. It feels as if we made a very small breakthrough, for which I am extremely grateful, and I thank the Minister. I will not delay anyone any longer as we have another group of my amendments to come, but I look forward to some detailed discussions between now and Report to see if we can bring this back in a form that we are all able to support. I beg leave to withdraw the amendment.
I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name.
This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting.
As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant.
The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill.
As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.
My Lords, I support Amendment 72 and I have signed it. I recognise the probing nature of this, but I also recognise the problem it seeks to address. The knowledge that a cyber threat or cyber attack has failed may be incredibly important intelligence because, on the whole, someone trying to create a cyber threat will not retire after the first time that it did not work out; they will try somewhere else, so the intelligence element of this is so crucial.
Some of the people in cyber security talk about seven stages of cyber attack. The first stage is reconnaissance: you are just having a look round and trying to identify vulnerabilities. The second stage is weaponisation: you are developing the means to target that weakness, which can be as simple as an email. It is not until the third stage that the attack begins. But there are still three or four more stages, each of which can provide a barrier and each of which can be the place at which the attack stops. It is not uncommon for attackers to carry out multiple attempts to find or exploit a vulnerability, or indeed to do a small-scale attack in order to then do something larger down the line. In all these cases, there is something absolutely critical for the regulator and possibly the enforcement community to know.
I, too, support the amendment from the noble Baroness, Lady Harding, as I do all the amendments previously discussed. By definition, a near miss means a severe threat narrowly avoided that would have had substantial consequences if it had not been avoided. The interesting thing is that everyone tells me that the near-miss reporting in the aviation industry proved to be massively significant and fundamentally changed the whole approach to air safety, with very beneficial consequences. The case is very sound that it should be applied here.
My Lords, I support this amendment, particularly in terms of its probing nature and what work can potentially be done between Committee and Report in this respect. It is really about the question of mandation. There should not be any question of a voluntary requirement. This is something that is not about the individual organisation, business or entity. It goes broader than that. It is about the community, the greater good and the country. The fact of a near miss says nothing about the severity of intent and the intel that can thus be gleaned to benefit at that point across the sector, the community, the country and beyond. Mandation has to be the standard for this provision.
My Lords, I cannot possibly compete with the Shakespearean seven stages—as opposed to ages—of the noble Baroness, Lady Kidron. We support Amendment 72 in its entirety. Voluntary reporting is the bit of the amendment that we particularly like. Our national security services and sectoral competent authorities desperately need early upstream visibility of emerging threat patterns before a full-blown systemic crisis unfolds. In the cyber domain, the precursors to the catastrophic attack—the subtle network probes, the exploratory reconnaissance and near misses—often appear weeks before a critical system is actually breached.
At present, the Bill creates a bit of an all-or-nothing trap. If any entity experiences a sophisticated near miss that fails to cross the statutory threshold of an active disruptive breach, it has a powerful legal incentive to keep quiet. It fears that, if it approaches a regulator voluntarily, it will expose itself to regulatory scrutiny, compliance investigations and potential enforcement action. In our view, including a dedicated statutory framework into the NIS regulations specifically for the voluntary notification of near misses, sub-threshold anomalies and early-stage cyber threats would be a significant beneficial addition to the Bill. In effect, it would establish a safe harbour for intelligence sharing.
As the recent “Analogue 72” green paper powerfully argued, we must move away from a culture of fear and silence in this area and we must encourage continuous proactive information flows between our critical infrastructure operators and the NCSC. We strongly support this amendment.
My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.
Baroness Lloyd of Effra (Lab)
My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.
I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.
I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.
The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.
Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.
Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.
It was my suggestion to break up these amendments into different groups, otherwise we would have had about 100 amendments in one group. There is an awful lot of overlap in the discussion on this group in particular and Amendment 17 in the name of my noble friend Lady Neville-Jones. Would the Minister commit to having a joint meeting, where we could try to work this through together? I think we share a common goal of wanting to give as much relevant, immediate and up-to-date intelligence to the network as possible, without overwhelming, and recognising that, as the noble Lord, Lord Clement-Jones, said, time is absolutely everything in these cyber attacks. If we could discuss that together rather than separately, that would be extremely valuable.
Baroness Lloyd of Effra (Lab)
That would indeed be very valuable to discuss the questions around definition, scope, coverage, timeliness and impact on potential entities—sorry, I have just expanded our agenda.
I have heard very clearly the willingness to discuss and collaborate from the Minister, which is extremely welcome, as were the contributions from all noble Lords. If the last hour and half has shown anything, it is that there is a genuine cross-Committee desire to work—this is what the House does at its best—to genuinely improve, with a shared goal of a piece of legislation that the country will benefit from if we can get it right. I beg leave to withdraw the amendment.
My Lords, Amendment 73 stands in the names of the noble Lords, Lord Alton of Liverpool and Lord Hunt of Kings Heath, and the noble Baroness, Lady Ludford, and in my name. Unfortunately, the noble Lord, Lord Alton, is unable to be here today, and I am very pleased to move the amendment on his behalf. The principle behind it is very simple, and I am delighted to see that it has cross-party support. I am sure and trust that it will have cross-Committee support as well.
We all recognise that cyber threats do not respect national borders. Effective cyber security therefore requires international co-operation and information sharing. I think that is something that we all believe in. A lot of measures that we have been talking about would actually give teeth and powers to these organisations to make sure this happens. However, the amendment shows when things can go too far and the risks around that. There must surely be limits on where information obtained under UK statutory powers can subsequently be sent and how it can be used.
The Bill will give NIS enforcement authorities the power to share information with overseas authorities. Amendment 73 would prevent such information being shared where the Secretary of State determines that the receiving jurisdiction cannot guarantee the right to a fair trial, or where disclosure could result in actions incompatible with that right. This is not a theoretical concern. We know that authoritarian states increasingly use apparently legitimate law enforcement processes as instruments of transnational repression. China provides perhaps the clearest example. There are well-documented concerns about the independence of its judiciary, particularly in national security cases, and the treatment of dissidents and human rights defenders.
My Lords, having exchanged some gestures with the noble Lord, Lord Hunt, I think it is me next. I am pleased to support this amendment, which I have cosigned, and I very much agree with everything that the noble Lord, Lord Markham, said.
My remarks will principally have China in mind. China is not the only repressive regime, of course, but certain examples come to mind. Take, for example, the political prisoners in Hong Kong, such as Jimmy Lai and Joshua Wong, who was in the news recently when he was outrageously imprisoned, on so-called national security grounds, for democratic expression and protest. There are many other such examples, of course. There are also concerns about electroshock weapons being demonstrated inside the Chinese embassy here, and we recently saw a considerable eight-year sentence under our National Security Act for the manager of the Hong Kong Economic and Trade Office in the UK because of attempts at repression in the UK. So there are problems of justice—or, rather, injustice—in Hong Kong and China, but the tentacles of repression are very much reaching into this country, particularly for the Hong Kong diaspora.
We have seen other examples, such as Interpol red notices being misused, so there is a great concern that requests for digital information sharing that have a nefarious purpose could be made by authoritarian states under the Bill. We have had examples in Hong Kong of residential surveillance and holding individuals incommunicado for up to six months, without access to a lawyer or family, which amount to enforced disappearance and increase the risk of torture. We have the lack of judicial independence, as the noble Lord, Lord Markham, mentioned, which explicitly prevents a fair trial, particularly in so-called national security cases. The treatment of imprisoned activists undermines any semblance of a fair trial. There are concerns about the admission of evidence obtained through torture in Chinese courts, which includes Hong Kong. The situation in prisons is intolerable. I understand that Jimmy Lai is being held in conditions where he is practically boiling in the heat of his cell. Anyway, this gives the Committee an illustration of everything that I think noble Lords are already aware of.
I understand that, under the Extradition Act, co-operation between the UK and Hong Kong authorities is permitted on a case-by-case ad hoc basis; if that is incorrect, I would accept correction. But if, under the Bill, NIS data—including sensitive information such as IP addresses, digital fingerprints and user-level logs from digital service providers—could increase the risk of extradition to a country without a bilateral treaty with the UK then that could trigger special extradition arrangements, bypassing traditional human rights safeguards. We are on a slightly uncertain basis of extradition to Hong Kong, into which the Bill could add another element, so there are no permanent safeguards against extradition to Hong Kong and this data sharing could serve as an intelligence-gathering tool, which facilitates that process by providing the evidence which then justifies the filing of an ad hoc extradition request. So we could increase the likelihood of an ad hoc extradition request, which would make it more difficult for the British authorities.
Of course, we all know that many of the diaspora in the UK are living in fear of their lives—not just fear for their safety but for their lives, with bounties on their heads. We are also aware of all the cyber attacks that we understand are being launched from a Chinese direction. This NIS data could help to identify the architecture of the UK’s critical systems and choke points. It could also assist with the harassment of dissidents and human rights defenders living in the UK.
For all these reasons, I very much support the amendment. As the noble Lord, Lord Markham, said, if the Government believe that there are institutional drafting problems then it is incumbent on them—if they agree with us that there is a danger in this zone of sharing data with a repressive regime, and I cannot see how they would not—to come up with something which fits the existing parameters but prevents opening the door to assisting repression. That would certainly be against any values in this country.
My Lords, I will briefly follow the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, in supporting this amendment. The noble Lord, Lord Alton, who is the architect of the amendment—indeed, of many amendments relating to China and human rights—unfortunately cannot be here, but both the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, explained eloquently why this is important, particularly the focus on China.
Over the years, British Governments of all colours have had a very ambiguous policy towards China. On the one hand, in terms of trade and the economy, it is crucial. On the other, we have to admit that Chinese repression and China’s appalling human rights record mean that the Government need to tread very carefully in their relationships with China.
My interest in this came from the problems, particularly in Xinjiang province, with enforced organ harvesting of dissidents and followers of Falun Gong. When we say “forced organ harvesting”, we essentially mean that prisoners are killed so that their organs may be taken and sold, in essence, on an international market. China makes billions of pounds from this appalling practice.
Over the years, the noble Lord, Lord Alton, has chipped away, legislatively, at a number of pieces of legislation to, in essence, preclude British companies from supplying China with goods, medicines or chemicals that could then possibly be used for organ harvesting. There are a number of pieces of legislation where this happens. Obviously, this Bill is different, but I note the argument that the noble Baroness, Lady Ludford, and the noble Lord, Lord Markham, made about why we should have special provisions for fair trials and the release of information to authoritarian countries.
I fully take the point from the noble Baroness, Lady Ludford, who, like the noble Lord, Lord Markham, referred back to the debates in the other place and the difficulty of drafting. I hope that the Government might be prepared to talk, particularly to the noble Lord, Lord Alton, about whether we can find a way forward here.
Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
I thank noble Lords for their amendments. Obviously, we miss the noble Lord, Lord Alton, who spoke to me this morning to emphasise his regret at not being able to be here. I think many noble Lords know the important reason why he cannot be, which he was keen to stress.
I thank all the noble Lords who spoke on this important amendment, which seeks to restrict overseas information sharing where there could be a risk to an individual’s right to a fair trial. I am sympathetic to noble Lords’ concerns. We must be rigorous in protecting fundamental liberties and the rule of law, both nationally and internationally. I understand that DCMS officials—there is a double D in DCMS; the first D is silent, so I hope that noble Lords been advised accordingly—have been working with teams across government to consider these concerns carefully. From this, I am confident that the risks identified by noble Lords are very low.
The information-sharing powers are discretionary. Regulators are under no obligation to share information overseas under the Bill. We work closely with all regulators and know that they are extremely cautious, sharing information internationally only when it is necessary to do so and after considering whether disclosing that information is in line with their public duties, including those under the Human Rights Act. I have listened carefully to the noble Lord, Lord Markham, my noble friend Lord Hunt and the noble Baroness, Lady Ludford, who all have their particular areas of interest and expertise. I will turn to a couple of those points in a minute.
In addition, the Bill adds further explicit safeguards that information must be disclosed only if it is relevant and proportionate. This requires regulators to exercise judgment and limit information only to that which is necessary for the purposes of the sharing. Requiring the Secretary of State to convene panels of experts in order to judge every instance of information sharing internationally would add a significant layer of bureaucracy. Given the very low risk and the safeguards already in place, that would be disproportionate and would slow or even halt legitimate essential international regulatory co-operation.
International collaboration has long been central to the NIS framework, with information-sharing essential to ensuring that tackling cyber threats is a global effort. The Bill ensures that our regime reflects the UK’s post-Brexit position by enabling effective co-operation with trusted international partners including close allies such as the US and Australia.
On the Hong Kong point raised by the noble Baroness, Lady Ludford, there is no uncertainty regarding UK-Hong Kong extradition. The UK suspended the treaty in 2020 and passed legislation to reflect the suspension in UK domestic law in 2025, completing the severing of ties between the Hong Kong and UK extradition systems. I hope that that addresses that point.
I apologise for interrupting the noble Baroness. My understanding was that, although the treaty had been suspended, there could be consideration on a case-by-case, ad hoc basis. Is that wrong? Is there a complete ban on extradition or, notwithstanding the suspension of the treaty, could there still be a case-by-case, ad hoc extradition?
Baroness Ramsey of Wall Heath (Lab)
I thank the noble Baroness. I will write to her on the case-by-case point.
Finally, I know that my noble friend the Minister will be very happy to meet noble Lords again to discuss this further, as she has done quite recently with the noble Lord, Lord Alton.
I thank the Minister for her response and noble Lords for their involvement. As suspected, the Committee is completely united in what we are trying to achieve, and I am pleased to hear that the Minister is sympathetic. I think we all agree that the devil will be in the detail. That is why I am grateful for the offer of a meeting, which I am sure that the noble Lord, Lord Alton, and many of us here will be delighted to take up.
I have a couple of concerns, and we will cover these in the meeting. As the Minister mentioned, there is no obligation for regulators. The question is: why leave it to their discretion? The Minister later said that there was concern about it being overburdensome on the Secretary of State’s officials to have to determine these cases. If it is too much of a burden for a group of experts, surely it is even less likely that regulators in all sorts of different fields are going to try to apply that same knowledge.
The concern about all of this is that, while the intentions are good, unless there are firm constraints in the Bill, it will just be something which, through no malcontent or wrong reason, is overlooked. That is why we feel it is very important that we have something in the Bill to add teeth to this. That is something that we would be delighted to explore further in meetings and on Report but at this point, I beg leave to withdraw the amendment.
My Lords, Amendment 74 is in my name and those of the noble Baronesses, Lady Morgan and Lady Ludford. The noble Baroness, Lady Morgan, is very sorry that she cannot be in the Committee this afternoon but she particularly wanted me to thank the Minister for their helpful meeting last week. This amendment and Amendment 167 in the name of the noble Baroness, Lady Ludford, relate to the governance of regulated bodies that will be caught under this Act. The reason for this legislation is to reflect the rapidly changing cyber environment and to strengthen areas of current vulnerabilities of those organisations providing services critical to societal or economic life.
As we have discussed, regulators will be given powers to designate critical suppliers whose disruption could have a significant impact on essential services. As we have discussed in previous groups, many of us think the Bill does not go far enough in setting out who those critical suppliers are. We are going to see similar amendments in other forthcoming Bills that make provision for senior manager liability when new responsibilities are legislated. This is something that we have been through in other Bills: the only way to change the culture of an organisation is to start at the top.
I am sure that boards will grumble when they accept new duties, but they will keep their regulators happy were they to be in sight of the law. What really makes the difference to successful implementation is knowing that if it can be proven—I shall read out proposed new subsection (1)(b)—that
“the failure was committed with a consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly”,
that individual will be held responsible. I point noble Lords to recent court cases in the area of social media, where disclosure has repeatedly shown that senior executives knew of harm or stood in the way of harm mitigation for years. The idea that this might capture an unwilling or unwitting senior executive is shown clearly not to be the case by what I have just read out.
I understand that the Minister and the noble Baroness, Lady Morgan, also discussed this in the context of financial services and a regime introduced after the 2008 financial crash with the very intention of changing the culture of financial service businesses and focusing senior minds on the damage those businesses can do if they do not meet their responsibilities. A more recent example is the introduction of the consumer duty by the Financial Conduct Authority, which required relevant boards to appoint an individual consumer duty champion, something that the noble Baroness, Lady Morgan, was involved in. I also point to the Building Safety Act that was a response to the Grenfell Tower disaster.
I am hoping that the Government are sympathetic to this amendment, but if they find themselves unable to be sympathetic, I would be interested also to hear the Minister’s thoughts on whether we could require the relevant regulator to introduce a named senior manager regime, which indeed we did in the Online Safety Act.
The final point I make is that the senior manager must be senior. The intention behind the amendment is to change the culture of an organisation to ensure preventive action is taken to avoid penalties. As I said at the outset, culture change starts at the top. The services covered in the Bill are, by definition, considered by Ministers to be critical to national life, which means that the most senior governing body should be discussing them and responsible for them. While day-to-day management may be delegated, overall oversight and responsibility should sit at the top. For that reason, I support—as I know the noble Baroness, Lady Morgan, supports—Amendment 167, tabled by the noble Baroness, Lady Ludford. Her proposed new clause would focus the minds of those at the most senior levels of organisations caught by the Bill, and I really hope that the Government support this ambition. I beg to move.
My Lords, I am pleased to speak to Amendment 167 and grateful for the support from the noble Baroness, Lady Kidron—the support is mutual, as I co-signed her amendment. The two amendments are complementary, because Amendment 74 is about the liability of senior executives while Amendment 167 is about board oversight of an individual executive, responsibility and accountability. I was interested to hear the noble Baroness refer not only to financial and consumer conduct but to building safety as areas where such responsibility exists.
I am simultaneously involved in the Public Office (Accountability) Bill—the Hillsborough law—which will introduce a duty of ethical conduct, candour and transparency on public authorities and public officials. Perhaps what some of these other sectors have in common is that it has been an after-the-event thought that maybe boards and senior executives ought to have some kind of responsibility in this area. If we have had a catastrophe, often with a great deal of harm created—such as Hillsborough—maybe it would be a good idea if the people at the top, who are often extremely highly paid, took some interest in the area, rather than regarding it as some sort of lowly service, rather like cleaning the loos in the HQ building. I know it is now routine to refer to examples such as Jaguar Land Rover and Marks & Spencer, but there have been huge financial effects of cyber attacks. This is not some negligible issue; cyber security ought to be a core responsibility for senior people.
I am sitting close to the noble Baroness, Lady Harding, who today has referred to her own personal experience—we all remember it. I am sure it was painful for her and very public. She has actually been through it, so nobody knows better what it can be like when you have a big cyber data breach or cyber attack. It really is long past due that this ought to be a top responsibility of boards, directors and senior executives. Yet we understand—I think I get this from my noble friend Lord Clement-Jones—that the Government’s own Cyber Security Breaches Survey reveals that board-level ownership of cyber risk in the UK has declined from 38% to 27% over the past three years. It is going precisely in the wrong direction.
I do not think I need to persuade anyone here of how important it is for senior people in an organisation to be aware and carry not only responsibility, awareness and accountability but liability, so that it hits where it hurts if something goes wrong. Personally, it seems pretty much a no-brainer, and I hope the Minister will agree.
My Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.
I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.
My Lord, this Bill is largely directed at a given segment of the corporate sector. That reminds us, however, that there is a very large swathe of the corporate sector that we are not focusing on directly.
However, in the corporate sector generally, the board has to be interested in all risks, not just financial risks, or whether the book market or the wine market is in good shape; it must be able to protect the business and its shareholders. The board has a duty to the shareholders to do that. This is a very good opportunity to try to raise the level of performance in this area. The record is demonstrably not very good. This is an opportunity to help raise the level of performance and make it clear that if you take on a responsibility as a board director, you will have to be able to help conduct the business of that organisation at the highest possible level. I very strongly support Amendment 167.
My Lords, I also support Amendments 74 and 167. My experience is that boards that tell you that their cyber security is really good are the ones you should be most worried about. Boards that are really worried about it and can tell you where they think they are exposed might be in a slightly better place. There are too many organisations that will tell you that they are fine. Boards that are not doing what is set out in Amendment 167 are in trouble. It is entirely appropriate, and I fully support that amendment.
On Amendment 74, I would just like to draw a thread between the financial services senior management regime, what we have learned in the Online Safety Act and Tuesday’s debate about whether frontier AI models are included in the scope of the Bill. We have learned from the financial services senior management regime that when you make individual human beings accountable, they change. There is no doubt that the senior management regime in financial services has served to move the dial on the culture in financial services, and all previous attempts have failed.
Through the Online Safety Act, we have learned that various companies—not ones regulated by this Bill—have not taken seriously fines from Ofcom and simply refused to obey. We are living through an era when the tech sector wants to believe that it is exceptional and that laws from individual countries do not apply to it. It is therefore very important that we put into the Bill liability for senior executives, precisely because of what we have learned: in a sector that is doing it, you get culture change. In other digital legislation, where we do not have this, regulators’ decisions have actively been flouted. This is even more important if the Minister were to accept the amendments we debated on Tuesday—the noble Lord, Lord Tarassenko, has arrived just in time—because I firmly believe that the single most important part of regulating AI is holding the creators of the model accountable for their actions. Given that the biggest cyber security threats we face are the actions of agentic AI, I want to be able to build the framework that enables us to hold the managers and leaders developing those models, who currently say that this has nothing to do with them, accountable for their actions. I may be stretching it a bit, but I hope that Amendment 74 would be the beginnings of a framework that would enable us to hold senior tech titans to account.
My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.
Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.
Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.
My Lords, this has been a really useful debate, particularly because it has distilled all the considerable board experience—and, indeed, board training experience—around this Committee. I very much hope that the Minister listened to it with interest.
Amendment 74 in the name of the noble Baroness, Lady Morgan, moved by the noble Baroness, Lady Kidron, would align the UK with the EU’s NIS2 framework. It would introduce personal civil liability for senior executives who deliberately or carelessly neglect cyber duties. My noble friend Lady Ludford’s Amendment 167 would mandate board-level oversight and technical training. In our view, to build national resilience, cyber security must become a fiduciary director’s personal responsibility. As the noble Baroness, my noble friend and the noble Lord, Lord Arbuthnot, have said, this change is long overdue and would be additional to other existing sectors. We need to learn from experience in the way mentioned by the noble Baroness, Lady Harding; I very much hope that we will do so in the course of the Bill.
Together, these two amendments target arguably the single greatest cultural—the noble Baroness, Lady Kidron, rightly emphasised “culture”—and behavioural failure in UK cyber security today: the persistent treatment of cyber security by company boards as a delegated technical IT issue rather than a core personal and fiduciary leadership responsibility. The Government’s approach to corporate cyber governance has been almost entirely passive to date, I am afraid. Ministers have relied on voluntary guidance, such as the Cyber Governance Code of Practice, hoping that boards would voluntarily prioritise digital resilience.
The proof of this policy failure is undeniable. My noble friend quoted the Cyber Security Breaches Survey, which showed that board-level ownership of cyber risk has declined over the past three years. Of course, if boards neglect cyber security, that carries massive public costs, as seen in the recent major supply chain disruptions where, although company directors face strict personal legal liabilities under company law for signing off on financial accounts, they are permitted to treat systemic cyber vulnerabilities—vulnerabilities that can wipe hundreds of millions of pounds from the economy and paralyse critical national supply chains—with complete personal legal impunity.
My noble friend also reminded us of the catastrophic real-world cost of this boardroom neglect in the automotive sector, where a supply chain breach at Jaguar Land Rover cost an estimated £500 million, halted production lines for four months and forced the Government to step in with a £1.5 billion loan guarantee. We have seen the same in retail, also mentioned by my noble friend: the cyber attack on Marks & Spencer cost £300 million and contributed to a 99% collapse in pre-tax profits.
Amendment 74 would provide the direct legislative teeth that the Bill is missing by introducing personal civil liability for senior executives. It would amend the NIS regulations to establish that, where a regulated entity fails to comply with core risk management duties, and that failure was committed with the consent, connivance or deliberate or careless neglect of a senior executive, the regulator may impose a personal civil penalty.
My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.
Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.
I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.
However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.
We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.
I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.
Baroness Lloyd of Effra (Lab)
I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.
I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.
That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.
I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.
To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.
I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.
My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.
Baroness Lloyd of Effra (Lab)
We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.
I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?
Baroness Lloyd of Effra (Lab)
Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.
The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.
Baroness Lloyd of Effra (Lab)
I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.
The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.
The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.
My Lords, this is a group of rather wide scope. I am kicking off. I will also speak to Amendment 168 in my name so as not to speak twice. It is on an entirely different subject from Amendment 79, so we will probably have quite a long debate on this group.
Amendment 79 is about including political parties in this Bill. My honourable friend Victoria Collins MP made the same case in the other place, tabling a proposed new clause to designate political parties as carrying out essential activities. We have discussed, over several days, how cyber security is not just a technical matter confined to server rooms and IT departments; it is a matter of national resilience, economic strength, the functioning of society and, I argue, democratic integrity. On this last count, the Bill is silent.
I remind the Committee that, between August 2021 and October 2022, as we later learned, hostile actors sat undetected inside the systems of the Electoral Commission and exfiltrated copies of the electoral registers—an intrusion the Government attributed to a China state-affiliated actor. There was apparently reconnaissance against the email accounts of parliamentarians who had spoken out against China. So we are hearing of more and more denial-of-service attacks and other incidents affecting critical national infrastructure, which may have some knock-on effect on our democratic structures. Think about what political parties hold: membership lists, canvassing databases covering millions of electors, data on political opinion and special category data of the most sensitive kind—perhaps precisely the material valuable for espionage, transnational repression and targeted disinformation in a campaign period.
Let us think about the kind of defences that are protecting this information. Those of us who have experience of local party activity know that we are normally talking about a small office with a handful of staff and many volunteers, not massive enterprises—and they themselves have been the subject of cyber attacks. We perhaps have quite a weak link at the heart of our democracy.
The National Cyber Security Centre has defending democracy guidance, but this is voluntary, done on an opt-in basis and unenforced; there is no duty to report an incident, no assessment framework, no designated regulator and no floor beneath which a party cannot fall. So there is weakness around the cyber security of political parties and of electoral infrastructure. I am sure that the Minister will tell me that parties are not infrastructure—indeed they are not—but the Bill encompasses data centres and managed service providers on the basis that disruption there would significantly affect the day-to-day functioning of society. If the compromise of a major party’s voter database in the final week of a general election would not meet that test, I struggle to think what would.
Nothing in this amendment invites the Government into the internal affairs of parties; it asks only that the organisations through which the British people exercise their democratic voice are held to a basic standard of resilience. Democracy is essential infrastructure. It is a privilege that we must defend with the utmost priority, and the Bill should reflect that.
I will cover another, completely different matter in my Amendment 168. This amendment was prompted because, probably like others here, in July I had several notifications from either a charity, an arts organisation or an academic organisation—I cannot remember; I think I had four or five altogether—warning me of a data breach. This was a named company—I think it has been in the public domain—called Beacon. It experienced a cyber security incident involving unauthorised access to its systems. I understand it stores data on the membership and customers of a lot of organisations—about 1,000, I read.
This is a probing amendment because I am asking the Government where organisations like this sit. They are variously described as a customer relationship management service provider or a software as a service relationship provider. I do not think they fall into RMSP or RDSP; they are not cloud computing, they are not an online marketplace or search engine and so on. Maybe, arguably, they are a managed service or IT management, support, maintenance or monitoring. I do not know what the precise relationship is between the organisation and the Beacon customer relationship management service provider. I do not really understand it, and the point of the amendment is to find out whether the Government know where it sits in the sphere of cyber and data services. They will often have lots of personal data, including date of birth, contact data, records of donations and memberships, and the booking of events. There is quite a lot where you could profile somebody and find out a lot about them, so it is quite risky to have all of that in unauthorised hands.
I think these breaches triggered reporting duties to the Information Commissioner under the GDPR, but, as far as I know, I do not think that a comparable incident would trigger this Bill’s incident reporting duties. I do not know where these organisations fit, so can the Minister tell me where they live in the ecosystem and what could or should be done to try to increase their support for the organisations that they work for? I beg to move.
My Lords, I wish to speak to Amendment 81A in my name. I was glad to add my name to Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron. I am sorry that I was unable to speak to them on Tuesday due to some caring responsibilities.
Amendment 81A is all about education. Our British educational institutions sit at the heart of our communities. They are key to developing our children and young people, and helping them grow, supporting them through the most important developments of their lives. This year, the UK was ranked as having the third best public education system in the world, something that we should be so proud of but which we must safeguard. We have seen our education system change rapidly in the past decade. We now have exam results revealed via an app. We have homework set through online portals. I receive it weekly for both of my children. Increasingly, vast amounts of student data is being stored online, including around attainment. If our young people are to be properly supported, that must extend beyond the classroom to the network and information systems now essential to their education—a point only reinforced as universities and colleges continue to further embrace online learning.
Exam results determine a young person’s future opportunities. We all remember just a couple of weeks ago the pictures, the interviews of the young people and the elation of many 16 and 18 year-olds as they received and revealed their GCSE and A-level results. We owe it to the next generation to do everything we can to give them the best possible chances—to protect the integrity of the system that determines their future and to prevent the chaos that could follow if, for example, university place allocation, clearing or accommodation processes could not proceed. Anyone who might have friends or family whose 18 year-olds are currently going through that process knows it is frenetic enough at this time—scrambling to get a place for young people who might not have made their grades, changing universities, changing courses, trying to get a university spot or university accommodation.
We have already seen what chaos looks like on a small scale. Noble Lords perhaps will recall students who sat their A-level physics paper with Cambridge International who had their results voided after just one paper was leaked online, with a substitute mark calculated from other components. That was just one paper from one exam board, and it was still enough to undermine confidence in the results for every student affected. We need to look no further than the terrible experience recently in India where the National Testing Agency’s medical entrance exam results were withdrawn after a paper was leaked. It triggered mass protests and, tragically, at least 21 reported suicides among students who had sat the exam. If a single compromised paper can cause that level of devastation, we cannot afford to leave our education system exposed to a compromise on a grand scale.
Amendment 81A would establish that the education sector is an essential activity by requiring the Secretary of State to make regulations under Part 3 of the Bill. This would bring within scope any institution that provides primary, secondary, further or higher educational and vocational training. It includes exam boards involved in setting, marking or awarding and grades, higher education admission bodies, and any body that is essential to the provision of primary or secondary education that holds substantial volume of student or staff data. The obligations would require that education bodies take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems. The bodies must: take appropriate and proportionate measures to prevent and minimise the impact of cyber incidents, with a view to ensuring continuity of service; have regard to the state of the threat; ensure that they have a high level of security appropriate to the risk; and have regard to any relevant guidance issued by their regulator.
Let me just say, very briefly, that, as I made clear earlier in the week, the scope of the Bill is far too narrow. I suggested and will continue to suggest that we have to extend the definition of essential services. I remind all noble Lords, despite all the things we have been talking about this afternoon, that the organisations in the framing of the Bill, as drafted, are our national infrastructure sectors, not the great width of the economy or the public sector. In my amendments, I have suggested that we should have a definition of essential services that covers the economy—JLA and Marks & Spencer are not covered in the Bill—and society in general. We have just heard an excellent account of why education has to be included, as does defence and security. I do not think that we should be picking and mixing and putting a small number of sectors in the Bill. We need a conceptual approach to what we bring into the orbit of the Bill and we need a process in the Bill to ensure that that happens.
My Lords, just quickly, I will back up the noble Baroness, Lady Ludford, on Amendment 168. I, like many other noble Lords, have been involved with a variety of charities that were impacted by the cyber security breach at Beacon CRM, which has about 1,500 charities that store an enormous amount of personal data. I looked at its website, and perhaps this will emphasise to the Minister the problem that we face. This is what this website, which had a major security breach in the past, says about its security:
“The secure choice for security-conscious charities. Beacon has all of the security certifications and features that you should expect from your CRM, and we’re adding more all the time”.
It says that it is ISO 27001:2022 certified and Cyber Essentials Plus certified and that
“Cyber Essentials Plus is the highest level of certification in the UK government’s Cyber Essentials scheme, and includes a technical audit of the Beacon team’s endpoint devices”.
It says that it has “World-class infrastructure” and that it is “A UK-based system”. If I was a potential customer of Beacon reading all that, I would feel a very false sense of security about the level of knowledge and defence that its systems have. That is clearly not the case. There is a clear, major mismatch between the degree of confidence that organisations such as Beacon have in their own cyber security and the reality of how feeble and weak they actually are. Before this happens again and again, it would be helpful to look at this more closely and see whether we need to do more.
My Lords, the noble Lord, Lord Birt, was right to remind us that we perhaps need something rather more generic and comprehensive when we are assessing whether a particular sector should be brought into the Bill, but that does not mean that we should not use this group of amendments to illustrate that the Bill at the moment is not nearly comprehensive enough in the way it is structured and the sectors that it contains.
The Bill remains stubbornly wedded to what we might call the traditional 2018 five utilities model: water, energy, transport, health and core telecoms. But we have moved on from that world. Today, systemic digital risk does not respect what might be called 20th century arbitrary utility boundaries for critical national infrastructure. An adversary seeking to disrupt our society or blackmail the UK does not need to compromise a power station; it can strike our democratic institutions, food distribution networks, university research labs, orbital satellites or software supply chains.
Amendment 79, tabled by my noble friend Lady Ludford, designates services supporting registered political parties as essential activities. Hostile state actors, from Russian GRU units to Chinese state-sponsored espionage networks, are actively targeting our political parties. As my honourable friend and my noble friend have argued strongly, political parties are a vital part of our constitutional machinery, yet they operate on shoestring budgets with high staff turnovers, heavily reliant on consumer-grade IT and voluntary workers, while holding vast tranches of confidential voter files, donor databases and what we might call strategic policy intelligence. If a hostile power exfiltrates or manipulates a major political party’s systems, the threat is not just a commercial data breach but the subversion of our electoral integrity and democratic sovereignty. To leave our political parties outside statutory NCSC cyber standards is an indefensible democratic blind spot that Amendment 79 would decisively rectify.
Amendment 80, tabled by my noble friend Lady Northover, who sadly cannot be present, addresses the fact that the Bill remains frozen in that 2018 world. It will bring critical manufacturing, industrial food production and large-scale food distribution networks under statutory cyber resilience duties. Our contemporary manufacturing and retail logistics networks are no longer purely mechanical operations; they are vast, hyper-automated cyber-physical systems. They run on automated warehouse robotics, internet-connected telemetry and algorithmic just-in-time delivery pipelines.
Consider the manufacturing of critical transport equipment. When Jaguar Land Rover suffered a catastrophic supply chain cyber breach, the damage was not confined to a single company balance sheet. Production lines were frozen for four months, hundreds of component manufacturers were dragged to the brink of collapse and the economic fallout cost between £1.6 billion and £2.1 billion, making it the costliest cyber attack in British history and forcing the state to step in with loan guarantees. In an economy that depends to a large extent on vehicle transport and haulage equipment, leaving critical automotive and transport manufacturing outside statutory NIS protections is an invitation to systemic economic blackmail.
Even more acute is the vulnerability of our food supply. Modern food processing and supermarket distribution operate with less than 48 hours of inventory buffer. When Marks & Spencer was hit by a major ransomware incident, it cost £300 million to remediate and wiped 99% from its statutory pre-tax profits. As I said earlier, if a hostile state or sophisticated ransomware syndicate executes a co-ordinated attack against the central routeing software of two major distribution operators, supermarket shelves across our cities would begin emptying within two days.
Amendment 80 provides a clear, proportionate statutory safeguard. It includes an explicit turnover threshold of £12 million, ensuring that local bakeries, independent farmers and small shops face zero regulatory burden. It targets solely the industrial food processors and large-scale distributors whose distribution would threaten the daily functioning of society. In doing so, it aligns the UK with the EU’s NIS2 directive, which has already brought food production, processing and critical manufacturing under statutory cyber obligations. Our European neighbours recognise that you cannot have national resilience if your food supply can be halted by a single malicious click, so why are this Government leaving Britain’s food supply chain completely exposed?
That brings me to Amendment 81, also in the name of my noble friend Lady Northover, which designates the space and satellite sector as an essential activity under Part 3. The omission of the space sector from primary cyber security legislation in 2026 is nothing short of extraordinary. The space sector is formally identified in the Government’s own industrial strategy as a core national growth driver. Yet the Bill treats orbital infrastructure as if it were entirely invisible. Our entire critical national infrastructure, from financial transaction timestamps across the City of London and automated container port logistics, to emergency blue-light dispatch, cellular networks and high-voltage grid synchronisation, relies absolutely on satellite positioning, navigation and timing—PNT.
Ground-truth economic studies demonstrate that a five-day blackout of satellite positioning systems would inflict a staggering £5.2 billion direct loss on the UK economy. Furthermore, the UK possesses world-leading capability in earth observation and small satellite manufacturing, with sovereign launch facilities advancing at SaxaVord. But satellites, ground uplink stations and space telemetry are dual-use systems. As the House of Lords special inquiry committee on space, which I sat on, has heard throughout its evidence sessions, satellite communications and orbital command links are under relentless, daily cyber probing, jamming and spoofing by hostile state adversaries. An exploit deployed against the satellite operator’s ground command software can sever communications, blind environmental monitoring or hijack commercial orbital satellites.
Amendment 81 would rectify this strategic blind spot. It would place a statutory requirement on the Secretary of State, within six months, to make regulations bringing the space sector into scope as an essential activity. It specifically covers the operation of space objects and launch facilities, satellite communications, earth observation and critical PNT services, while requiring the Government to designate an appropriate regulatory authority such as the CAA or Ofcom to supervise compliance.
Before moving on to my own amendments, I welcome Amendment 81A, moved by the noble Baroness, Lady Berger, covering the education sector. Our world-class universities are the engines of the UK science and technology prowess, holding billions of pounds of cutting-edge IP, defence research and quantum computing prototypes. They are under relentless cyber espionage assault from foreign adversaries, while centralised bodies such as UCAS and qualification boards, as the noble Baroness said, hold sensitive data on millions of young people. Bringing education into scope under Part 3 is an urgent national security necessity.
I have tabled new amendments—Amendments 81B, 81C and 81D—which address the single most gaping, indefensible and dangerous structural failure of the Bill: the complete and absolute exclusion of central government, public authorities, local councils and our core democratic electoral infrastructure from the scope of our national cyber security perimeters. How can we claim to be building a genuinely cyber resilient nation when the public administration itself is left out entirely in the cold? I wish I had more time to expand on those three amendments, but I will content myself with hoping that the Minister will have considered those amendments and will come back with a positive response. Of course, we strongly look forward to an answer to my noble friend Lord Russell of Liverpool’s questions on Amendment 168.
My Lords, we have heard very compelling cases from all noble Lords who have spoken on this group about why a particular sector should be included. I will not go through the list—it was gone through very well by the noble Lord, Lord Clement-Jones, a moment ago—but I think we can all agree that each one was a compelling case. That probably illustrates the wider problem, because we are almost getting into a game of cyber whack-a-mole here, where we can see them popping up left, right and centre. So our approach, with Amendments 92 and 92A in my name and those of my noble friends Lord Camrose and Lord Holmes, is to try to take a more strategic view, very much reflecting some of the views that the noble Lord, Lord Birt, was mentioning earlier as well. They ask the Government to assess strategically important entities outside the current NIS regime and consider whether they should be brought into scope where a cyber attack would have a sufficiently serious impact on the economy or the day-to-day functioning of society.
We are not asking for another long list of businesses to be regulated, because we need to be careful about the regulatory burdens that we are putting on people. Instead, Amendment 92A proposes a risk-based test and asks these questions: what would actually happen if this organisation went down? Would essential services stop? Would very important supply chains fail? Would significant parts of the economy cease to function? If the answer to those is yes, surely the Government should at least assess whether that organisation belongs within our national cyber security perimeter. This also illustrates why we need to see the national cyber action plan. It was promised this summer; we are now in September and, considering that this is very pertinent to everything we are talking about in Committee, I ask the Minister when we will see the plan.
I will highlight one further issue, which the noble Baroness, Lady Berger, illustrated very well, in the area of the data held in certain organisations, particularly in education. We all know that the reason that a lot of these organisations are attractive targets is not because of the essential services they often carry out but because they carry enormous quantities of valuable and sensitive data. Again, this was very much my experience with the attack on Synnovis when I was Health Minister. It caused massive disruption for operations and diagnostic services in London, but the question was: why was that organisation holding so much information in the first place? It had names and addresses of people going back 20 years, their test results and their full medical records, and it did not need any of it at all. It could all have been anonymised, and it definitely did not need to hold it for 20 years.
To me, the question we really need to answer—this speaks to an amendment we will be talking about later—is: what data do all these public bodies really need to hold? Of course, if the data is not there in the first place to be stolen, or if it is not interesting or valuable, then that is the best line of defence, because there is no reason for there to be a cyber attack on it. As I say, we will talk further on that on Amendment 174E, but the principle is directly relevant to what we are talking about here.
Before I come to the end, I have a special request from my colleague here, who I think knows a thing or two. I am told on good authority that the last government AI regulation White Paper has a lot of relevance and synergies here, so I would request the Minister to look at that between now and Report to see where, as I say, there are synergies and learnings from it.
In summary, first, we should systematically identify the organisations whose compromise would cause the greatest damage, as per our Amendment 92A, and, secondly, we should reduce both their vulnerability and attractiveness as targets, including by reducing the data prize available to the attacker, as per our Amendment 174E, which we will come to later on. That, to me, is genuine cyber resilience: not merely making the safe harder to crack but, wherever possible, ensuring that there is nothing valuable inside the safe to steal.
I hope the Minister will respond both on the important sectors raised by noble Lords and to the central question behind Amendment 92A: what systematic test are the Government applying to determine which strategically important organisations should fall within the NIS regime, and will that regulatory perimeter keep pace as technology and the threats change?
Baroness Lloyd of Effra (Lab)
My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.
As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.
I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.
The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.
I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?
For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.
Baroness Lloyd of Effra (Lab)
I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.
But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?
Baroness Lloyd of Effra (Lab)
I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.
In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.
My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—
Baroness Lloyd of Effra (Lab)
I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.
I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.
Can I ask the Minister to comment on another point that the noble Lord, Lord Clement-Jones, raised? Why should this not apply to the higher reaches of government? I ask the Minister specifically: what is her view of 607,000 records being stolen, just weeks ago, from the Department for Education?
Baroness Lloyd of Effra (Lab)
I absolutely intend to talk about the public sector. Given the numerous sectors that have been raised, I also want to respond individually on each sector. I absolutely agree that all sectors need to improve their cyber resilience; it is not the case for only those in the regulatory perimeter. It is also not the only way to improve; we should improve things right now. There is funding, and there are activities going on in all of these sectors that we might talk about—sometimes with public funding, sometimes with public advice and sometimes through industry groups.
I have spoken a little already about the cyber resilience pledge, which over 100 companies have now signed. It sets out the absolute best practice and what actions to take, including making cyber a board-level responsibility, following the Cyber Governance Code of Practice, signing up to the early warning service and taking a risk-based approach to requiring cyber essentials across supply chains.
In the retail sector, the DBIST industry-led Retail Sector Council is working with experts and business representatives to consider cyber security.
In respect of the space sector, it is absolutely critical; I could not agree more on the importance of PNT and satcoms, which underpin a huge amount of UK economic activity. The UK Space Agency is already strengthening cyber resilience in practice through the development of a space cyber assurance framework for the space sector, intending to help operators understand and demonstrate cyber resilience in a proportionate and practical way.
The UKSA also supports the provision of threat briefings and is working with industry on the potential development of a space information-sharing analysis centre. This would improve the flow of threat information, warnings and good practice between government and industry, and support links to international networks, such as the US-led global Space ISAC model. That would help operators to understand emerging threats and to act quickly.
My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.
Baroness Lloyd of Effra (Lab)
It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.
Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.
Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.
Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.
This brings me on to Amendment 81A—
I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?
Baroness Lloyd of Effra (Lab)
The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.
Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.
I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.
The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.
I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.
The Minister pointed to three examples of where education is considering issues around cyber security, specifically in schools and only 80% of colleges. One of the concerns I outlined in my contribution was around the examining bodies for both our secondary schools and universities. There was no mention of universities. Can I understand a bit more about how they are currently being considered, if they are not going to be included within the scope of this Bill?
Baroness Lloyd of Effra (Lab)
The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.
More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.
Can I ask a couple of questions and make one comment? The more we hear about the conversation that is taking place on the Bill, the more anomalous the factors that have been chosen or included in the scheme become. Let me give the example of space. Plenty of us now receive our internet connection via satellite. It is inevitably an intimate part of the networking system of cyber security. What we appear to be told is that some parts of the telecoms and internet world are going to be governed by the Bill, but other parts, which are equally integrated and important, are going to be covered separately by a special different arrangement—they are not included. For example, as I understand what the Minister said about space, it is not going to be included in this Bill. With the greatest possible respect to the Minister, it does not make sense.
My question is: in the period ahead of us, could the Government have another look at the whole question of the scope of the Bill? This seems to be one of the problems that lies between us. As a result, Members are now trying to shove into the Bill all sorts of things on the grounds that they are essential services—some of which clearly need to be there, but for others it is arguable that they do not.
I heard what the Minister said about the action plan. I have read the action plan, and it is a good plan, but it lays a heavy responsibility on a department that no longer exists—DSIT. The function is set out so well and is important to keeping government departments up to the mark, which is going to be done separately. Where is that responsibility now going to sit? It will require a very considerable degree of expertise on the part of those conducting this system of keeping people up to the mark. How is that going to be done?
It seems to me that local government requires something of the same. Government is a whole thing. It is not that some things can be done in central government without regard to their implementation by local government or vice versa. Are the Government going to extend the system that is being mapped out in the action plan for government to local government as well, in order to get the same standard of performance and integrity of systems?
Baroness Lloyd of Effra (Lab)
Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.
The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.
On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.
My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.
The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.
I cannot possibly reply on any matters other than political parties. I am left unpersuaded that political parties are sufficiently supported and protected. Maybe bigger parties are not run on a shoestring as much as some of us. I am not talking about national level, but at the local level it could be justified to see some beefing up of the obligations and the support required.
Political parties come in for a lot of flak. They are always getting bashed around—“Who wants parties?”—but, actually, we would not have democracy in most cases without it being channelled through political parties, so they are an obvious target for any malefactor who wants to get at our democracy. It is really unsatisfactory not to give further support to political parties. Perhaps between now and Report we could reflect more on that.
On CRMs, the noble Lord, Lord Russell, prompted me to look at the website of the company Beacon—it is out there, so I am not giving away any secrets. It claims that 1,500 charities, NGOs and other organisations were affected. One was the English National Ballet, which I got a notification from. It manages an awful lot of personal data that has been subject to a cyber security incident. That happened in July, and I tabled this amendment in July, so I would welcome something from the Minister and her team to get a little more of a steer about where an organisation such as that stands in relation to this Bill and whether it should be encompassed to some extent within it.
From this company’s website, you would not know that anything had happened. Maybe that is par for the course. It lists all these security credentials and so on, saying how wonderful it is—I am sure it is, and I do not wish to impugn it—but the fact is that it has had a major cyber security incident affecting apparently maybe 1,500 organisations and the personal data of millions and millions of people in this country. Yet I did not feel we got much back from the Minister, so perhaps we can think more about that between now and Report. I beg to leave to withdraw Amendment 79.
My Lords, Amendment 83, in my name and those of the noble Baroness, Lady Ludford, and the noble Lords, Lord Holmes and Lord Tarassenko, would require the Secretary of State to publish and maintain a digital sovereignty strategy. Before the Recess, many of us participated in a debate on digital sovereignty, and the level of agreement across the Chamber was absolutely overwhelming about the importance of UK national sovereignty and the current threats to it from our current arrangements with the tech sector, particularly US-based behemoths. The same sentiment is articulated by Amendment 166 in the name of noble Baroness, Lady Ludford, and it is a sentiment shared in the other place, where Conservatives, Liberal Democrats and Greens all tabled similar Motions.
During the debate, I identified four areas in which the UK has surrendered its leverage to make its own decisions. We surrendered our political leverage by deferring to the power of US tech; we surrendered our economic leverage by placing UK businesses at a structural disadvantage and entering into expansive and extractive contracts; we surrendered our technological capability as we failed to invest in UK capacity and businesses; and we ensured our strategic vulnerability by depending on foreign companies for key infrastructure. Together, these weaken our economy, our security, our safety and, above all, our autonomy: the ability to choose. I doubt that any single government strategy put us in this position, but it reveals a lack of strategy that we find ourselves here.
Amendment 83 would set out a requirement for the Secretary of State to establish a digital sovereignty strategy. Proposed new subsection (2)(a) would require an assessment of the risks to networks and information systems from
“dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, extra-territorial legal requirements that may be imposed on non-domiciled suppliers”—
such as cloud providers through the US CLOUD Act—
“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”,
the use of
“UK datasets without license or permission”
and vulnerabilities to valuable data assets that belong to the British public, including those related to the NHS, BBC, and Met Office. The rest of proposed new subsection (2) sets out further requirements to assess the risk of
“technological developments, market concentration or strategic dependencies”
and give consideration to vital elements of sovereignty, including open source technology and assets, talent procurement, capital markets and international collaboration with mid-sized partners whom we retain leverage with.
Finally, proposed new subsections (3) and (4) call for the development of a dashboard enabling the measurement of digital sovereignty. I am working with computer scientists at the British Computing Society who are developing a prototype for this and I urge the Government to look at this work and consider developing it, for their own procurement purposes and to provide it as a tool for the wider business community.
I set that out in some detail because I rather suspect that, if we had a proper strategy across the nation, we would not have had the conversation that we just had in our debate on the previous grouping. Sovereignty is now firmly on the agenda. This is partly due to the export ban on Anthropic and Claude Fable 5 introduced by President Trump in June, but stories highlighting our sovereign vulnerability across the digital stack predate that event and have continued since.
Dependency is not built overnight. It is the result of a systemic and concerted effort by entrenched big tech companies across many years to make themselves indispensable to the UK state, businesses and society, and of successive UK Governments failing to invest in our businesses, communities and people and choosing always to buy oven-ready tech, irrespective of the economic, societal and individual costs.
Just as dependence is not built overnight, neither can sovereignty be reclaimed overnight; nor is it a zero-sum game in which every part of the stack can or should be replaced. None the less, to restore any independence at all, we require an equally systematic and concerted approach to build where we can, to buy only products and services that adhere to our laws, to recognise our unique skills and assets, and to work co-operatively with other like-minded countries. That begins with a strategy that establishes a clear route for government and is fed into experts, free from lobbying and scrutinised by Parliament—which is the very purpose of the amendment in front of us. I beg to move.
My Lords, I shall speak to my Amendment 166. It offers an alternative route to the same destination, although the amendment in the name of the noble Baroness, Lady Kidron, is probably superior because it is fuller and more comprehensive; I readily concede that. Her amendment would add an important element—a digital sovereignty dashboard prepared by the Office for National Statistics, the Competition and Markets Authority, the National Cyber Security Centre and the AI Security Institute—so that we can measure whether anything is changing. The cross-party agreement on this matter, which the noble Baroness referenced, is important and might help persuade the Minister of the force of the argument.
The Competition and Markets Authority puts Amazon Web Services and Microsoft together at between 70% and 80% of the UK’s public cloud market. That is not only a duopoly but a digital sovereignty issue. In its report Rewiring the State, which was published in June, the Science, Innovation and Technology Committee in the other place found that major departments, including HMRC and the NHS, were locked into multiyear agreements that further entrench those dependencies. The National Audit Office has found no shared strategic approach across government towards the handful of very large suppliers that now dominate these markets and are, to a large extent, American. Research done by the British cloud provider Civo found that 83% of UK IT leaders believe that geopolitics threatens their ability to control their data, while only 35% know precisely where that data resides.
I have a history, as a Member of the European Parliament, of being involved in all the arguments about transatlantic data transfer and what happens to the data when it is in the US; this was all in the wake of the war on terror, Guantanamo and so on. We are back in that territory, I guess. It is not just about the economic side of non-national control; it is also about your vulnerability to decisions—including, sometimes, decisions that you do not like—about what happens to the data.
Lord Tarassenko (CB)
My Lords, I shall speak in support of Amendment 83 in the name of the noble Baroness, Lady Kidron, to which I have added my name. In my speech, I will focus just on the aspects of the digital sovereign strategy that are relevant to the NHS. I speak as someone who held an honorary contract with the Oxford University Hospitals NHS Foundation Trust until November 2025, enabling me to be a co-investigator on research projects involving patient data.
Cyber attacks against NHS trusts and their supply chains occur with very high frequency, from regular automated phishing attempts, which are blocked daily, to major incidents causing significant clinical disruption. Health and social care consistently rank among the top sectors reported for cyber incidents and data breaches to the ICO. I am sure that we all remember the WannaCry cyber attack in May 2017, which affected 81 of our 236 NHS trusts at the time, causing nearly 20,000 appointments to be cancelled in a week.
Less than two years ago, in November 2024, there was a major cyber attack against the Wirral University Teaching Hospital NHS Foundation Trust, which compromised the trust’s electronic patient record. I know that EPR well as we have the same EPR in Oxford: Cerner Millennium. As a result of the cyber attack, staff in the Wirral hospitals lost all access to patient records, electronic prescribing tools and diagnostic results. All elective surgeries and outpatient appointments across the trust had to be cancelled, and members of the public were told not to use the emergency department at one of the hospitals in the trust. All clinical systems remained completely offline for nine days.
I mentioned the EPR Cerner Millennium. Cerner is now part of Oracle Health. Together, Oracle and Epic, both of which are US companies, account for about 40% of hospital EPR contracts in England and Wales. In primary care, EMIS software manages just under 60% of the patient records—the records of 35 to 40 million patients across England and Wales. EMIS was bought by Optum, part of the UnitedHealth Group, in 2023, but, in March this year, the UnitedHealth Group sold Optum to a US private equity firm, TPG, for just under £300 million. I will come back to that briefly later.
In 2023, NHS England and the Department of Health and Social Care launched a 2030 cyber security strategy. The noble Lord, Lord Markham, when he was a Health Minister, wrote the foreword—he will remember this, I am sure—to the strategy document. In it, he wrote—we all agree with him, I am sure—that
“the cyber security of our health and social care … underwrites patient safety”.
The group director for cyber security for the DHSC has recently written to all NHS trust boards informing them that, from this month, September 2026, new cyber policies will be included in the next data security and protection toolkit, covering issues such as multi-factor authentication, high-severity alerts and endpoint detection. There is nothing about AI, which is perhaps the subtitle of this Bill—something that will, I hope, have been removed by Report. Yet we know from Tuesday’s debate and last week’s open letter from 100 companies, including large tech firms, that AI-enabled cyber attacks are about to become more widespread and more sophisticated within months.
This prompts three questions. First, are officials from the Minister’s department, which has overall responsibility for cyber security, co-ordinating with the cyber security group in the DHSC—especially with respect to the latest threats from AI agents?
Secondly, have the recent reports from the AISI been communicated to the cyber security group in the DHSC, and have their implications for the NHS been discussed with them? I note here that the new Minister for Science and Innovation, Chris McDonald MP, is a Minister in both the DBIST and the DHSC, so I am hopeful that the answer to these two questions might be yes.
Thirdly, given the high prevalence of foreign ownership of companies, such as Epic and TPG, that are responsible for managing patient data within the NHS—notwithstanding the single-supplier agreement with Palantir, another US company, for the Federated Data Platform—has the Minister’s department assessed the risk to relevant network and information systems as a result of our technological dependence on these companies?
What I have described for the NHS also applies to other sovereign data assets such as those held by the BBC or the Met Office. If the full value to the UK of these sovereign data assets is to be realised as part of the Government’s growth strategy, we need to be optimally protected against cyber attacks, including AI-enabled attacks. For that to happen, we need a coherent digital sovereign strategy across government departments, led by the Minister’s department.
My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.
I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.
It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.
My Lords, these amendments are highly pertinent. We simply must ensure that non-UK providers of services in this sector are firmly and wholly within the scope of the Bill—they are only partly in scope. For noble Lords who were not at Second Reading, I read out a coruscating report by the American Government that damned Microsoft for its poor cyber security. I am sure that it is not true across the whole of Microsoft, but in that particular instance it manifestly was.
I observe that our previous debate was absolutely excellent; it uniformly focused on organisations in the UK that are providing services. There was a danger that somebody hearing that debate might think that all those organisations are themselves responsible for breaches. The data on whether breaches chiefly occur through failures in organisations mentions the absence of multifactor authentication or that they are caused by failures in the quality and design of the services that those organisations consume. By the way, the organisations consume literally hundreds and hundreds of services, and the reality is that it is a huge challenge for organisations to ensure that all the services that they buy are secure. We might say that it is a near impossibility. Again, it is absolutely vital that we keep providers firmly within the scope of the Bill—I am not saying that they are not there, but they are certainly not there in their totality—and, dare I say, firmly under regulation.
My Lords, I support the principles behind these amendments. A point was raised by the noble Baroness, Lady Ludford, and I wish to make the point in a different way. Many reasons have been shared during this debate, which I share. The noble Baroness, Lady Ludford, referred to the questions asked by Chi Onwurah MP in the other place. It is interesting because I submitted a very similar Question just before the end of the summer in July. I asked:
“what proportion of the computing and cloud services used by government departments are provided by suppliers that are … headquartered outside the UK, or … subject to the jurisdiction of a government outside the UK”.
I asked that specifically in the wake of recent events and the debate we had in July.
The Answer came back on Tuesday. I accept that the Question asked by Chi Onwurah MP was specifically about AWS, but I was asking about all services hosted outside the UK. The Answer was:
“This information is not held centrally. Individual government departments are responsible for managing their own commercial arrangements for computing and cloud services and would need to confirm the proportion of services provided by suppliers headquartered outside the UK”.
The Government do not know how much they are collectively relying on other countries for our key government digital infrastructure. Our Government’s critical systems, public services and citizens’ data are increasingly reliant on foreign-hosted clouds and data centres. While the Answer refers to “commercial arrangements”, I think it is about much more than that. This is a question of our national security and resilience. I believe we urgently need a digital sovereignty strategy to ensure that we know the answers to these questions, that we can act on them and that we can prevent any future challenges happening to ensure that we are as resilient as we should be.
My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.
I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.
Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.
Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.
My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.
Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.
In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.
My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.
However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.
We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.
Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.
For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.
On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.
My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.
Baroness Lloyd of Effra (Lab)
It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.
On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.
For clarification, that is on the spend, but my question is specifically about where the cloud services are hosted and/or whether they are under the jurisdictions of Governments beyond the UK. It was not just about what money is being spent; it was about who is responsible for it and where it is located.
Baroness Lloyd of Effra (Lab)
That is well noted.
For all digital services, as many noble Lords have pointed out, government departments are required to carry out robust security and resilience assessments in their procurement to ensure that the actions of foreign states or hostile actors cannot disrupt the delivery of public services. In June, the Cabinet Office published procurement policy note 025, Protecting the UK’s National Security through Public Procurement, and AI will be one of four key sectors recognised as critical for national security, with new guidance for departments prioritising contracts for British business where necessary to protect our national security.
Before the Minister sits down, I ask her to reflect, at the end of our second day in Committee, that the noble Viscount, Lord Camrose, has mentioned more than once that he would like to see a national cyber security strategy, but is not the takeaway from these two days that we are all very clear on the challenges facing the UK? There is a great deal of uniformity across the Room, as well as in the quality of the Minister’s answers, but does the Bill not need to deal with all the issues that have surfaced and been addressed? Frankly, it does not do that at the moment. If the Bill passes in its less ambitious form, how long will it be before we get another Bill to address the strategies? If we have to wait that long, how much more damage is going to be done to our economy and our society in the meantime?
Baroness Lloyd of Effra (Lab)
Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.
My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:
“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.
I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.
The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.
The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.
I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.
This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.