Baroness Wheatcroft
Main Page: Baroness Wheatcroft (Crossbench - Life peer)Department Debates - View all Baroness Wheatcroft's debates with the Home Office
(1 day, 20 hours ago)
Lords ChamberMy Lords, the noble Lord made a couple of interesting points, which are crucial, and I will try to address them. Cybersecurity of the UK is a key priority for this Government. It is crucial to protect public services, the public, our way of life and a successful, growing economy. We have been taking significant action to help protect business from cyber- attacks.
We are also providing businesses with the tools, advice and support to protect themselves from cyberthreats, including the Cyber Governance Code of Practice, which shows boards and directors how to effectively manage the digital risk to their organisation. The highly effective cyber essentials scheme prevents common attacks and reduces the likelihood of a cyber insurance claim by 92%. Before I was invited to be a part of the Government, when I ran my businesses I ensured that they all had a cyber essentials certificate. That is the basic requirement that you need to have. At the same time, businesses need to protect themselves by having sufficient cybersecurity insurance. There are a wide range of tools and support from the National Cyber Security Centre including training for boards and staff and an early warning system to get notified about cyberthreats to networks.
When parliamentary time allows, this Government will introduce the cybersecurity and resilience Bill to raise cybersecurity standards in critical and essential services such as energy, water and the NHS.
My Lords, does the Minister have any information about how many companies are paying ransom demands? To what extent do the Government deal with insurance companies, advising them whether to pay ransoms or not pay them?
I thank the noble Baroness for that. I am sure that most noble Lords will appreciate that it would not be appropriate for me to comment on any ongoing incidents. However, the Computer Misuse Act continues to enable the prosecution of those who have undertaken unauthorised access to computer systems for a range of malicious reasons including crime and espionage. The Government are in the process of reviewing the Act and the Home Office will provide an update on further proposals once they are finalised. In recent years, the Government’s policy has focused on supporting the insurance industry, to strengthen and grow the commercial cyber insurance market. Pool Reassurance, or Pool Re, was created to ensure the effective functioning of the UK’s terrorism insurance market. The Government do not have any plans to extend Pool Re’s remit to include further cyber-related risks.