(2 weeks ago)
Lords ChamberMy Lords, I see that I have gone down on the speakers’ list as “B Ludford—first half”, presumably in the expectation that I will make the second half of my speech later. I am only kidding.
I knew that I would learn a lot in this debate and I have not been disappointed. I am no expert on cyber issues and I am speaking only because, first, it is an interesting as well as vital topic; secondly, because my noble friend Lord Clement-Jones is very persuasive; and, thirdly, because the Bill has prompted me to revisit my memory of being the victim of a cyber attack 13 years ago.
As an MEP I was involved in drafting the general data protection regulation—GDPR. I see the noble Lord, Lord Moraes, nodding in collective memory. I had sought to take a balanced approach, safeguarding personal data while not totally hampering digital services by overloading them with red tape. This middle way did not please a group of extremist hacktivists, who labelled me an agent of big tech and launched a denial of service attack against my MEP website. It was successfully defended by the small firm which hosted my website—and those of some Lib Dem MPs, including a coalition Minister or two—and it kept all the logs for me, as I wanted to notify the police. I could not find anyone in the Met to speak to so, since I was in touch with Europol and its British director at the time, his chief of staff kindly spoke to old Met colleagues and got an inspector to ring me. This chap was not only uninterested but cross that I had got rank pulled on him, and he did not deign to pursue any inquiry.
I relate that anecdote to illustrate, first, that cyber resilience is a whole-of-society concern which needs to bring in all of us non-experts but, secondly, that the exclusion from the Bill of public sector services is a worrying hole. Politicians and political parties as well as the police, local authorities and others are rather key players in the cyber security ecosphere. I hope that we will explore at further stages the Government’s rationale for exclusions.
At Second Reading in the other place, the Minister for Digital Government and Data, Ian Murray, agreed that cyber security
“is very much an economic growth issue … as we can see from the impact it has on our economy”.—[Official Report, Commons, 6/1/26; col. 171.]
Both Mr Murray and his DSIT colleague Kanishka Narayan cited the £15 billion a year cost of cyber attacks to UK businesses. But in response to calls to include sectors such as retail and manufacturing, as well as small and medium-sized companies, Minister Narayan claimed:
“Introducing blanket coverage for whole new sectors would create extensive regulatory burdens for more of our economy, stifling economic growth”.—[Official Report, Commons, 6/1/26; col. 226.]
So, on the one hand, the Government acknowledge the devasting cost to the economy of cyber security breaches of both public and private operators but, on the other hand, say that including them in the Bill would damage the economy. There is absolutely no logic to this.
The sorely needed intent to boost the pipeline of professionals is of course welcome. But another thing the Government could do on training is to protect the practice of ethical hacking, as part of the testing of networks, so that this workforce is as prepared as it possibly can be to combat weaknesses in cyber protection. Is this going to happen via reform and updating of the Computer Misuse Act 1990?
The effort needs to encompass not only professionals but all of us non-techies, even oldies such as me, given that the most common password in this country is apparently “password”. Much lip service is paid to addressing digital exclusion but there are huge numbers of people—a lot, but not all, of them old—who have not received any training and are still left out. How do the Government plan to extend whole-of-society awareness of cyber safety to everyone living in this country and not regard it just as a limited legislative exercise? While doing that, the Government could surely not avoid the issue of cyber-enabled fraud, a multi-billion-pound epidemic in which criminals often compromise individual customers as a route into wider systems. I do not think that is covered at all in the Bill.
The Government’s response to demands for the Bill to place responsibilities on boards and senior executives has been as feeble as their muddle on the economic impact. Minister Narayan told the other place that last year the Government wrote to chief executives “requesting”—requesting—
“that they make cyber-security a board-level responsibility”.—[Official Report, Commons, 6/1/26; col. 228.]
That in my opinion is pathetic. With the consequences of neglect so clear, a request is simply not good enough. The Government should make cyber security a legal requirement on bosses, which would boost accountability. Alongside that, they could slim the Bill’s administrative load by clarifying responsibilities, definitions and thresholds, having a single unified reporting portal rather than 12 regulators, avoiding overreporting, which would simply make the wood invisible for the trees, and including a duty, not just an option, to consult on secondary legislation—among many other streamlining measures.
Leaving the strategic priorities statement to the Government to draw up is a huge chunk of delegation. This Bill is really a bit of a mess: a combination of lots of executive power and lots of amending of the 2018 NIS regulations. It might have been better to write a whole, clean, comprehensive new Bill.
We can no longer channel EU law into our jurisdiction because the European Communities Act was abolished, but, in an era of alignment—indeed, dynamic alignment —the disparities between the Government’s choices in the Bill and the EU’s proposed NIS 3 directive are puzzling, as my noble friend Lady Northover and others pointed out. Both to lighten the regulatory load on UK companies working across Europe and to facilitate co-operation with the EU, it would make sense to have greater similarity between this Bill and the EU’s imminent new directive.
The Bill is much more limited than the draft directive in its sectoral coverage and regulatory design: for instance, keeping different categories of regulated entities when the EU is bringing them all together, and then distinguishing purely between “essential” and “important”. I am all for regulation being proportionate and flexible when that works—I and some other British MEPs sought with some success to bring that into the GDPR—but can the Minister be explicit about why the Government have diverged rather decisively from the EU model, and indeed left so much detail to executive discretion?
When it comes to the desired digital sovereignty, to avoid in future the servitude to US tech and the US Government that the Mythos episode demonstrated, would it not make more sense to work more closely with the EU so that British companies can help contribute to and benefit from a European market in digital commercial opportunities?
I look forward to working with colleagues on these Benches and across the House to improve this rather unambitious Bill.