Baroness Paul of Shepherd's Bush debates involving the Department for Science, Innovation & Technology during the 2024 Parliament

Baroness Paul of Shepherd's Bush Portrait Baroness Paul of Shepherd’s Bush (Lab)
- View Speech - Hansard - -

My Lords, the Government’s whole-of-society approach to national security rightly recognises that resilience is not delivered by the state alone; it is delivered through partnership between government, regulators, industry, communities and, crucially, the private sector. Cyber resilience is no exception. It requires every bit of the infrastructure to play its part: those who defend networks, those who regulate standards and those who help organisations recover when incidents occur.

I welcome the Bill and I note the broad support it has received from across the resilience sector as a good start. The Bill makes important progress in strengthening incident reporting, modernising the NIS framework and placing greater obligations on essential service providers, digital services and critical suppliers. I particularly welcome the inclusion of managed service providers within the regulatory regime. As other noble Lords have mentioned, more and more organisations rely on MSPs to help them keep pace with the changing nature of the threat and the ever-expanding tools required to remain secure. Without them, many businesses and parts of our critical national infrastructure would struggle to access the expertise they need to keep themselves safe. At the same time, MSPs can present a potential vulnerability because of the privileged access that they often hold to clients’ infrastructure. The Bill is right to recognise this, and I am pleased to see them brought into scope.

In welcoming the Bill, I must also point to what I think is a significant omission, on which I will focus my remarks. There is no mention of the insurance sector, nor any real mention of the part that the private sector can play. I raise this not as a criticism, because there is ample opportunity to put this right and to enhance the Bill’s ambition. The Bill already expands incident reporting and increases the volume and quality of cyber incident data available to regulators and public authorities. That is an excellent step forward, but if the purpose of the Bill is to improve our understanding of cyber risk and strengthen resilience across the economy then it is worth asking whether we should enable structured, anonymised incident data to be shared with the insurance sector and others who can use it.

The purpose of this data is to provide a clear picture of the threat, so it is important that we share it as widely as possible with those who can help protect us. I ask the Minister to consider this. It would be an extension to the Bill, not a departure from it. It would build on the reporting architecture that the Bill already creates, and it would do so in a way that supports the Government’s whole-of-society approach to resilience. The principle is simple: better data enables better modelling; better modelling enables better pricing and strengthens resilience; and better pricing increases access to cyber insurance and strengthens resilience across the entire economy.

Cyber insurance is already an important part of keeping businesses safe. We know that it enables us to transfer financial risk so that it is shared between businesses in the private sector rather than being borne by the taxpayer. I am sure we all agree that cyber incidents and the cost of recovery should, in most cases, fall on the organisations affected.

As noble Lords know, insurance remains one of the most effective and economically efficient ways of achieving this, but it does not just pay out after an incident; it changes our behaviour before one. To secure affordable premiums, organisations are required to adopt practical cyber hygiene measures, such as multifactor authentication, timely patching, network segmentation and robust incident planning. These requirements are not set in stone but change as the threat involves. Beyond legislation which will mandate a change in behaviour, there are very few other ways to incentivise the scale and pace of the behavioural change required to improve our resilience than insurance. We have locks on our doors, safety features in our cars and sprinklers in our buildings because insurance encouraged and rewarded these measures. It has the potential to play the same role in cyber resilience.

It is worth noting that Cyber Essentials, which the Minister mentioned in her opening remarks, is believed to be held by just 1% of businesses. Although the growth rate is increasing, it would take decades to get to the point where Cyber Essentials is going to provide us with the level of resilience that we need, so we need to do something different and we need to incentivise things differently.

As we also know, cyber insurance helps mitigate the moral hazard where organisations underinvest in security because they assume government or someone else will bear the consequences. The risk to our economy makes this unsustainable. Independent analysis commissioned by the Department for Science, Innovation and Technology, which sponsors this Bill, shows that cyber attacks impose almost £15 billion of economic harm on the United Kingdom every year. That is equivalent to one month’s NHS expenditure, almost the entire annual policing budget, 30 new hospitals or more than three decades of universal breakfast clubs for every primary school child. It is enough to wipe out an entire year’s profit for vast numbers of British businesses.

Yet only a small proportion of that national cyber risk is insured. Based on the department’s modelling data, together with that of the Association of British Insurers and Lloyd’s of London, it is estimated that the UK cyber insurance market currently covers approximately £700 billion of annual losses. In other words, less than 5% of the economic harm caused by cyber incidents is insured. Therefore, more than £14 billion of losses fall directly on businesses, public services and, in some circumstances, the taxpayer. We all know that Marks & Spencer had cyber insurance and reportedly made a claim of around £100 million following its cyber incident last year, whereas Jaguar Land Rover did not have any cyber insurance and, in the end, the Government had to step in and provide a loan. As the frequency and severity of cyber events increases, it is in our interest to increase insurance take-up.

The Bill strengthens reporting obligations. Named suppliers will be required to report significant incidents within 24 hours and to report fully within 72 hours. The Bill expands the definition of a reportable incident to include pre-positioning attacks, significant near misses and incidents likely to have societal impacts even where disruption has not occurred. It must be permissible for regulators to share this information across public authorities and with insurance companies to create a more coherent national understanding of cyber risk. If we accept that it is possible to share in some circumstances, it must be possible for us to consider that it could be shared in others.

Lloyd’s of London, the ABI and brokers including Marsh, Aon and Willis Towers Watson have warned that scarcity of reliable data is one of the principal constraints on market and product development, so why would we not want to facilitate improvement in cover? Market analysis suggests that there is potential for the global cyber insurance market to expand annually by 25%. If the UK were to capture even a modest share of that growth, our domestic cyber insurance market could expand from its current value of around £700 million to well over £2 billion in a few years. This would lead to more highly skilled jobs in London and would maintain London’s position as the world’s leading centre for specialist insurance.

The Bill sets us in the right direction, but we have an opportunity to ensure that insurance is properly recognised as part of the resilience community. I believe that enabling structured, timely, anonymised data to be shared with insurers would be a modest extension to the Bill but would have the capacity to deliver enormous change to the cyber resilience of our country. I hope that the Government will consider this as the Bill progresses through the House.