(2 weeks, 1 day ago)
Lords ChamberMy Lords, my noble friend Lady Harding talked about speaking half way down the list, and the noble Lord, Lord Moraes, of being nearly at the end of the list. I am last, as your Lordships will be glad to hear.
I must declare my interest as an employee of Marsh Risk, an insurance brokerage company with a large cyber practice. Like many other noble Lords, I welcome the Government’s ambition to strengthen the UK’s cyber defences and, in doing so, to protect the continuity of the essential services on which the public depend.
The Bill’s direction of travel is right: widening the scope of the existing regulatory framework to reflect modern supply chains, strengthening oversight and improving the flow of information to regulators and the National Cyber Security Centre so that we can build a clearer national picture of threats and vulnerabilities. However, I will press the Minister on two areas where the Bill, as drafted, risks leaving practical gaps: first, the role of cyber insurance in building national resilience; and secondly, whether the proposed incident reporting timelines will, in practice, help resilience or inadvertently hinder it.
On insurance, my argument is straightforward. Regulation, technical standards and guidance are essential, but they are not, on their own, a resilience strategy. Resilience also means the ability to recover quickly: to fund remediation, to access specialist incident response capability at speed, and to keep vital services running while systems are rebuilt. My noble friend Lord Arbuthnot referred to cyber insurance. On its own it is not a silver bullet, but it is one of the few tools that can mobilise financial and operational support within hours. Time is of the essence to limit further damage, as we have seen in a number of recent incidents.
The noble Baroness, Lady Paul, discussed how insurance can incentivise behaviour. I very much agree with that and a lot of what she said. I will take the process a little further. In the cyber insurance market, the best policies do more than pay claims. They typically provide 24/7 emergency hotlines, pre-vetted panels of incident response firms, forensic expertise, legal and communications support, extortion specialists and business interruption expertise, all of which can be decisive in reducing harm, shortening outages and supporting faster restoration of services. Some insurers even pay loss or claims expenses directly to the party owed—for example, breach counsel and forensic vendors—saving their clients from having to pay large incident response costs out of pocket. For many small and medium-sized organisations, it is often the only affordable way to access that depth of capability. This support can potentially prevent the Government having to step in, as they had to offer to do in the Jaguar Land Rover incident.
Yet cyber insurance can play that stabilising role only if organisations are encouraged to take it up as part of a wider risk management approach. Indeed, my noble friend Lord Vaizey talked about it being mandatory. At the very least, we need to create greater awareness of the benefits that cyber insurance can bring to businesses. Personally, I tend to prefer a carrot rather than a stick approach.
My first question to the Minister is: what incentives are the Government considering to encourage greater uptake of cyber insurance, particularly among smaller operators and critical suppliers who may sit outside the largest corporate balance sheets but whose disruption can cascade through supply chains? Has she considered introducing a moratorium on insurance premium tax of, say, three years for companies that take out cyber policies for the first time, as a way to incentivise uptake? Incentives are not just about premiums. They are also about information and confidence, ensuring that organisations understand what insurance does and does not cover, encouraging consistent baseline controls so that insurers can price risk responsibly, and supporting appropriate data sharing so that lessons from incidents can improve both national defences and underwriting insight. In short, the objective should be a virtuous circle: better cyber security, greater insurability, more uptake and stronger national resilience.
I turn to incident reporting, as discussed by the noble Lord, Lord Ravensdale, and my noble friend Lord Holmes. The policy intent to ensure that regulators and the NCSC receive timely warning of significant events is understandable. Many noble Lords have mentioned this in principle. But in a major cyber incident, the earliest hours and days are dominated by triage, containing the threat, protecting services, preserving evidence and restoring critical functionality. Those involved in the response work around the clock to keep the businesses running. In that context, the requirement for rapid reporting can create real operational tension.
As I understand it, the approach envisages a two-stage process: an initial notification shortly after the organisation becomes aware of a significant incident, followed by a fuller report within a tight timeframe. My concern is not with the concept of early warning; rather, it is that the requirement to produce a comprehensive report within 72 hours risks driving premature, incomplete or speculative reporting, and it can pull scarce technical leadership away from response and recovery at precisely the moment it is most needed.
That is why I intend to table an amendment to adjust the reporting time so that the full report is due within 30 days, with an expectation that the affected entity provides an initial notification promptly and submits updates as material facts become clear. This would preserve the Government’s need for awareness and situational insight, but it would also recognise the practical realities of incident response. Organisations often cannot state with confidence the root cause, scope of compromise or data impact within 72 hours, particularly where third-party suppliers and complex networks are involved. Can the Minister confirm whether the Government have considered an approach of this kind—one that distinguishes clearly between early warning and a detailed, evidence-based report? Requiring a detailed report too early can reduce the quality of the information that authorities receive, increase the risk of later correction, meaning rework and additional expense for all concerned, and potentially undermine trust and transparency.
I support the Bill’s overall aims, but if we are serious about resilience we must think not only about prevention but about recovery and continuity. Cyber insurance, properly understood and appropriately incentivised, can be one of the mechanisms that turns a cyber event from a national disruption into a managed incident. Finally, on reporting, we should insist on a regime that delivers timely awareness without undermining operational response.