(2 weeks, 1 day ago)
Lords Chamber
The Earl of Effingham (Con)
My Lords, I thank the Minister for introducing the Bill before your Lordships’ House this afternoon. His Majesty’s loyal Opposition support the objective which lies behind this legislation. The cyber threat facing the UK is growing incrementally, both in scale and in sophistication. From hostile states to organised crime, from ransomware attacks on our public services to increasingly complex attacks on critical national infrastructure, the need to strengthen our national resilience is indisputable.
Many noble Lords will be familiar with a number of reforms contained within this Bill, predominantly because they originate from the review of the Network and Information Systems Regulations undertaken by the previous Conservative Government following the consultation that was launched in 2022. It should not be a surprise that we welcome measures to improve consistency across the various regulators responsible for enforcing the existing regime. However, support for the objectives of a Bill should never prevent your Lordships’ House from asking whether the legislation is sufficient and proportionate.
Most importantly, noble Lords would be right to constructively challenge whether this legislation forms part of a coherent strategy. That should be a central question. We are being asked to scrutinise and revise one of the fastest-moving areas of public policy without the Government having first published the cyber strategy within which these measures are intended to sit. Ministers have described this Bill as merely one component of a wider programme to strengthen Britain’s cyber resilience, so it is entirely fair and reasonable to ask, “Where exactly is that programme? Where is the strategy? Where is the explanation of how these powers fit within the Government’s broader approach to protecting our digital economy and our critical national infrastructure?”
Only last Thursday, we heard an Oral Question on the impact of AI in vaccine technology. It is obvious to all that AI is, regrettably, also transforming how cyber attacks are conducted, increasing both their scale and their sophistication. Hostile states have become more aggressive. Organised crime has become more capable. The boundary between economic security and national security has become ever more blurred. Yet little of that ever-shifting landscape appears to find expression within the Bill itself. In fact, artificial intelligence does not appear to feature in the legislation. Quantum cracking does not feature. Weaponised disinformation does not feature. The wider question of how government intends to respond to AI-enabled cyber threats remains unanswered. Nor does the Bill address the long-standing concerns surrounding the Computer Misuse Act, despite repeated calls from the industry for reforms that better reflect modern cyber security practice and remove the legal uncertainty facing legitimate cyber security researchers.
Legislation in this field is unlikely to come before Parliament every year. That places a particular responsibility on noble Lords now to ensure that what is enacted today remains relevant, as much as it realistically can be, tomorrow.
The Government have shown an enthusiasm for regulation across a number of sectors. Sometimes regulation is necessary; sometimes it is unavoidable; but good regulation should always be proportionate. This is especially true when it comes to firms that are already navigating an increasingly complex regulatory environment and face ever more costly obligations under the Government’s direct and indirect taxing of small businesses. The Bill introduces new obligations, new reporting requirements and new compliance duties for organisations operating in sectors that are undoubtedly important to our national resilience.
It may be the case that some of this regulation is justified. However, it also raises many questions for the Opposition, the most pressing of which is: what assessment have the Government made of the cumulative regulatory burden these measures will impose on businesses? Many organisations are already subject to reporting requirements under data protection legislation, sector-specific regulation and forthcoming proposals concerning ransomware reporting. If these various obligations are not properly aligned, businesses risk finding themselves complying with multiple reporting regimes for what is in reality the same cyber incident. This would not strengthen resilience but rather create additional bureaucracy during a time of crisis.
Nowhere is this of greater concern than for small and medium-sized enterprises. Large multinational organisations generally possess dedicated legal and compliance teams and cyber specialists capable of navigating increasingly complex regulatory requirements. Smaller businesses simply do not have the resources to do that, and often these businesses are the very scale-ups and high-growth companies upon which our future economic prosperity and unicorn status depends.
Everyone wants economic growth—none more so than His Majesty’s loyal Opposition—but if the Government want growth, they must ensure that cyber regulation does not become yet another barrier to enterprise and innovation. Will the Minister therefore confirm to your Lordships’ House that the overwhelming majority of SMEs will remain outside the scope of these new regulatory requirements? By what benchmark will an SME be defined in the legislation? Will the Minister please explain what support, alongside the new obligations, the Government intend to provide for those smaller organisations that may ultimately fall within the regime? Resilience cannot simply be legislated into existence; it requires expertise and resources.
The Bill grants significant new responsibilities to regulators operating across a wide range of sectors. For these provisions to operate successfully, the legislation assumes that such regulators possess both operational capacity and the expertise necessary to exercise those responsibilities effectively. Will the Minister outline how these assumptions have been stress-tested?
Finally, the Bill confers important national security powers on the Secretary of State. Although these powers may well prove necessary, they also reinforce the importance of transparency. The exercise of national security powers should be informed by clear principles and robust accountability, particularly where they concern hostile foreign actors seeking to undermine our critical infrastructure. Will the Minister inform the House what mechanisms are going to be in place to ensure such accountability?
His Majesty’s loyal Opposition do not dispute that the cyber threat facing our country is real; nor do we dispute that the Network and Information Systems Regulations require updating. Indeed, much of the work underpinning this Bill was initiated by the previous Conservative Government. But surely we need a strategic framework instead of having to ask: why these sectors, why these thresholds and why these powers, and how does this legislation fit alongside artificial intelligence, ransomware policy, national resilience and wider cyber reform? These are not unreasonable questions. They are precisely the questions that a responsible analysis of a slew of updated proposals require, and we ask the Government to provide the strategic context which accompanies the Bill before us.