(1 week, 4 days ago)
Grand CommitteeMy Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.
There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.
Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.
I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.
I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.
I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.
The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.
My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.
I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.
It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.
Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.
During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.
Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—
(2 weeks, 1 day ago)
Grand CommitteeI, too, support the amendment from the noble Baroness, Lady Harding, as I do all the amendments previously discussed. By definition, a near miss means a severe threat narrowly avoided that would have had substantial consequences if it had not been avoided. The interesting thing is that everyone tells me that the near-miss reporting in the aviation industry proved to be massively significant and fundamentally changed the whole approach to air safety, with very beneficial consequences. The case is very sound that it should be applied here.
My Lords, I support this amendment, particularly in terms of its probing nature and what work can potentially be done between Committee and Report in this respect. It is really about the question of mandation. There should not be any question of a voluntary requirement. This is something that is not about the individual organisation, business or entity. It goes broader than that. It is about the community, the greater good and the country. The fact of a near miss says nothing about the severity of intent and the intel that can thus be gleaned to benefit at that point across the sector, the community, the country and beyond. Mandation has to be the standard for this provision.
My Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.
I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.
My Lord, this Bill is largely directed at a given segment of the corporate sector. That reminds us, however, that there is a very large swathe of the corporate sector that we are not focusing on directly.
However, in the corporate sector generally, the board has to be interested in all risks, not just financial risks, or whether the book market or the wine market is in good shape; it must be able to protect the business and its shareholders. The board has a duty to the shareholders to do that. This is a very good opportunity to try to raise the level of performance in this area. The record is demonstrably not very good. This is an opportunity to help raise the level of performance and make it clear that if you take on a responsibility as a board director, you will have to be able to help conduct the business of that organisation at the highest possible level. I very strongly support Amendment 167.
Let me just say, very briefly, that, as I made clear earlier in the week, the scope of the Bill is far too narrow. I suggested and will continue to suggest that we have to extend the definition of essential services. I remind all noble Lords, despite all the things we have been talking about this afternoon, that the organisations in the framing of the Bill, as drafted, are our national infrastructure sectors, not the great width of the economy or the public sector. In my amendments, I have suggested that we should have a definition of essential services that covers the economy—JLA and Marks & Spencer are not covered in the Bill—and society in general. We have just heard an excellent account of why education has to be included, as does defence and security. I do not think that we should be picking and mixing and putting a small number of sectors in the Bill. We need a conceptual approach to what we bring into the orbit of the Bill and we need a process in the Bill to ensure that that happens.
Baroness Lloyd of Effra (Lab)
I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.
I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.
Can I ask the Minister to comment on another point that the noble Lord, Lord Clement-Jones, raised? Why should this not apply to the higher reaches of government? I ask the Minister specifically: what is her view of 607,000 records being stolen, just weeks ago, from the Department for Education?
Baroness Lloyd of Effra (Lab)
I absolutely intend to talk about the public sector. Given the numerous sectors that have been raised, I also want to respond individually on each sector. I absolutely agree that all sectors need to improve their cyber resilience; it is not the case for only those in the regulatory perimeter. It is also not the only way to improve; we should improve things right now. There is funding, and there are activities going on in all of these sectors that we might talk about—sometimes with public funding, sometimes with public advice and sometimes through industry groups.
I have spoken a little already about the cyber resilience pledge, which over 100 companies have now signed. It sets out the absolute best practice and what actions to take, including making cyber a board-level responsibility, following the Cyber Governance Code of Practice, signing up to the early warning service and taking a risk-based approach to requiring cyber essentials across supply chains.
In the retail sector, the DBIST industry-led Retail Sector Council is working with experts and business representatives to consider cyber security.
In respect of the space sector, it is absolutely critical; I could not agree more on the importance of PNT and satcoms, which underpin a huge amount of UK economic activity. The UK Space Agency is already strengthening cyber resilience in practice through the development of a space cyber assurance framework for the space sector, intending to help operators understand and demonstrate cyber resilience in a proportionate and practical way.
The UKSA also supports the provision of threat briefings and is working with industry on the potential development of a space information-sharing analysis centre. This would improve the flow of threat information, warnings and good practice between government and industry, and support links to international networks, such as the US-led global Space ISAC model. That would help operators to understand emerging threats and to act quickly.
My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.
I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.
It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.
My Lords, these amendments are highly pertinent. We simply must ensure that non-UK providers of services in this sector are firmly and wholly within the scope of the Bill—they are only partly in scope. For noble Lords who were not at Second Reading, I read out a coruscating report by the American Government that damned Microsoft for its poor cyber security. I am sure that it is not true across the whole of Microsoft, but in that particular instance it manifestly was.
I observe that our previous debate was absolutely excellent; it uniformly focused on organisations in the UK that are providing services. There was a danger that somebody hearing that debate might think that all those organisations are themselves responsible for breaches. The data on whether breaches chiefly occur through failures in organisations mentions the absence of multifactor authentication or that they are caused by failures in the quality and design of the services that those organisations consume. By the way, the organisations consume literally hundreds and hundreds of services, and the reality is that it is a huge challenge for organisations to ensure that all the services that they buy are secure. We might say that it is a near impossibility. Again, it is absolutely vital that we keep providers firmly within the scope of the Bill—I am not saying that they are not there, but they are certainly not there in their totality—and, dare I say, firmly under regulation.
Before the Minister sits down, I ask her to reflect, at the end of our second day in Committee, that the noble Viscount, Lord Camrose, has mentioned more than once that he would like to see a national cyber security strategy, but is not the takeaway from these two days that we are all very clear on the challenges facing the UK? There is a great deal of uniformity across the Room, as well as in the quality of the Minister’s answers, but does the Bill not need to deal with all the issues that have surfaced and been addressed? Frankly, it does not do that at the moment. If the Bill passes in its less ambitious form, how long will it be before we get another Bill to address the strategies? If we have to wait that long, how much more damage is going to be done to our economy and our society in the meantime?
Baroness Lloyd of Effra (Lab)
Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.
(2 weeks, 3 days ago)
Grand CommitteeMy Lords, I think that this is profoundly unsatisfactory. It is not good parliamentary procedure to table so many amendments radically different from anything that we have seen before, which I, for one, have seen only at the last minute, so to speak—I have read them, but I will not claim to have studied them. I do not altogether know what I think, but I readily accept that the noble Lord, Lord Clement-Jones, has had a chance to scrutinise them in a lot more detail than I have.
I do not have anything substantial to say, but I would like to ask the Minister a question. Manifestly, there is a national security risk, which we would all recognise, and we all recognise that something needs to be done about it. But, if this is a national security issue, perhaps the Minister could explain to us why it cannot be dealt with under existing national security procedures. I have had time to go on to the GCHQ website, where one finds an impressive and considered approach to handling different security issues of this kind called the “equities process”—I did not know about it until the weekend, but it is impressive to read. I just do not understand why you would lodge such a set of issues with DCMS rather than the Cabinet Office. DCMS seems to me completely the wrong home for identifying, weighing and working out what to do about things that have such profound ramifications. Perhaps the Minister could explain to us why existing procedures, which are well tested and, by and large, involve GCHQ with a lot of consent in other areas of government activity, cannot be applied here with the same sensitivity that GCHQ has shown on other occasions. We cannot have a meaningful discussion about this today, but I think that the Minister has to think about how we can have a meaningful discussion before we reach the next stage of the Bill.
My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.
Baroness Lloyd of Effra (Lab)
I am very happy to look at the points that noble Lords have raised in the course of this discussion. I believe that elements such as the consultation and the process of scrutiny are well thought out. I believe that in terms of the elements of subsequent parliamentary scrutiny—the reports that will be made both on the application or when the direction is affected—this is very much in keeping with other national security legislation which has been agreed by this and previous Governments. Many of these elements are very akin to processes that are operational in other areas of government. However, I am very happy to look at, and indeed will look at, all the points that noble Lords have raised. We will discuss them in subsequent meetings, and we will revert to them on Report.
Can the Minister explain why GCHQ is not the right home to exercise these powers? I am sure we will all agree that national security is a significant issue, but it is being lodged in departments that have no prior experience of it. What is wrong with existing GCHQ procedures, which are respected and trusted?
Baroness Lloyd of Effra (Lab)
I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.
My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships.
The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now.
Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change.
Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope.
There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success.
We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions.
My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it.
Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope.
Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question.
The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States.
Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better.
We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require.
Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope.
The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.
My Lords, I shall speak to Amendments 7, 9, 11, 76, 77 and 88 to 91 in the name of my noble friend Lord Birt, each of which I have added my name to, and to Amendment 87 in the name of the noble Lord, Lord Clement-Jones.
Baroness Lloyd of Effra (Lab)
The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.
My Lords, I confess to a real disappointment listening to the Minister’s response. We have sat here all afternoon and heard many strong contributions on many matters, but so far, the Government do not appear to have moved an inch on any of them.
I have a few quick points. The Minister just referred to the regulators. There are 12 regulators of 12 sectors, which is a tiny fraction of the economy. We have had this very profound discussion about AI today. Is she really asking us to believe that Ofwat is capable of mastering the complexity and continuing challenge that AI poses? To me, the answer is all too obvious.
Secondly, I say to the noble Baroness, Lady Neville-Jones, in particular, that I have sat on many boards over recent decades at different levels in the UK, in Europe and globally. An awful lot of expertise comes to the table, but it is absolutely out of the question that every board in the land will have a real cyber expert on it—hence the notion. A financial audit is a really powerful thing these days. It gets into the bowels of a company, and if anything is going wrong anywhere then it will find out about it. That is why I propose that we have a cyber resilience audit—not for every company in the land but for those that fall under the heading of essential services.
Finally, we are at war, and I completely agree with the noble Lord, Lord Londesborough, that the scale of the damage to our economy is almost certainly vastly underestimated. The framework imposed in this Bill is for fighting a war, but we see around the world at the moment that—guess what—wars change. Different weapons are used and different tactics come up. It is as if we have split the MoD and said that the Army will be with DCMS, the Navy will be with another department and the Air Force with another. The idea that you cannot have effective co-ordination within government and outside government honestly does not carry any weight. I beg leave to withdraw my amendment.
(2 months, 2 weeks ago)
Lords ChamberOne of the real strengths of the BBC is that it is such a trusted source of news, and that is behind a lot of the issues within this. On the ongoing discussions with the FCDO, I am happy to meet the noble Baroness to discuss that. As she is aware, another Minister in the department deals with this. The Secretary of State has referred to the BBC’s overseas coverage as
“a light on the hill”,—[Official Report, Commons, 16/4/26; col. 992.]
and somewhere that people go to, so we do recognise the real importance of the World Service.
My Lords, I too welcome the Green Paper because, frankly, Rome is burning. Two of the UK’s greatest, most respected and historic achievements are threatened by the globalisation of media—a lively, challenging and diverse press, which we have had for centuries, and an unmatched tradition of public service broadcasting, encompassed by Channel 4 and ITV, as well as the BBC, which we have had for almost a century. For over a century, through those means, we have created a very effective national debating chamber and brilliantly captured our national culture, talent and capability. Does the Minister accept that radical measures will be needed to arrest these trends?
The Government are fully behind the BBC, both at the present time and as a future source of trusted news and content. Through the charter review process, a lot of these conversations are happening and we are looking in particular at how we can ensure that the funding model is sustainable while being fair and affordable for households. We are clear that,, if we can get sustainable funding and make sure that we get the prominence regime on the internet as well as on television screens, then we should go a long way to ensuring a strong future for our press and media. I would probably draw back a little from saying Rome is burning. There is so much good practice out there that we should celebrate, but I appreciate that we need to see the warning signs of what might come down the road, which is where the paper comes from.
(10 months ago)
Lords ChamberThe department has reviewed all appointments processes to ensure that this issue does not arise again. We will work with the Cabinet Office and the commissioner, as per the recommendation in the report. On what success looks like for the Independent Football Regulator, I know that the IFR under David Kogan will protect clubs, empower fans and keep clubs at the heart of their communities, which is exactly where they belong.
My Lords, whatever the imperfections —and there manifestly were some—identified by the commission in the selection process, Mr Kogan did not apply but was invited to apply for the regulator post when it was first advertised, as the noble Lord, Lord Parkinson, just reminded us, under the previous Conservative Government. Does the Minister agree that whether Mr Kogan had been appointed under a Conservative or a Labour Government, it would have been solely because of his unique ability and expertise, which are widely admired right across football?
There is no doubt in my mind, and I know in the minds of noble Lords from across your Lordships’ House, that David Kogan is supremely qualified for the role to which he has now been appointed. As the noble Lord highlights, he was approached under the previous Government for this role and is eminently qualified for the job.
(10 months ago)
Lords ChamberWe will hear from the Labour Benches next, then the Cross Benches.
I am not sure I have anything other than “yes” to say in response to my noble friend. I love the BBC; we want it to be the best it can be. That is everything, as the noble Lord on the Benches opposite said, from coverage of key national moments such as Remembrance Sunday and ceremonial events to general news content and programmes such as “The Traitors”, which three generations of my family enjoyed thoroughly.
My Lords, I welcome the extremely constructive tone from all three Front Benches about the BBC and will make three points. First, the BBC, as some have said already, has been in the making for well over a century—an achievement unmatched in any other country in the world. It is a crucible for our best writers, funniest humourists, scientists, naturalists and historians—for every aspect of our culture. It is the BBC of “Strictly”, “Last Night of the Proms”, “Farming Today” and “The Archers”. Secondly, in my experience, everyone working at the BBC, from the director-general to front-line journalists, works with honest integrity and is utterly dedicated to public service. Thirdly, as with all organisations, mistakes are made. They are mostly innocent, but some are not. Some are the result of inexperience, some are the result of local management laxity and on occasions, including in my 13 years, some are the result of a wider cultural malaise. The critiques of some of the BBC’s journalism by Mr Prescott and others on all sides of the political spectrum need to be calmly considered and, where necessary, addressed. I have no doubts that, under current leadership at the BBC, they will be.
I agree with much of what the noble Lord said, although I am not clear what the question was. I can affirm that I agree whole- heartedly with the noble Lord that we have world-class programme-making and journalism at the BBC. This does not take away from the fact that the BBC also has work to do on some of the issues. We are also confident that the chair of the board is dealing with these issues. I know that the content of the letter to the chair of the Commons Culture, Media and Sport Committee outlines some of these issues and that it will hold the BBC to account. The Secretary of State is also speaking regularly to the chair of the board and is confident that he is taking this situation extremely seriously, exploring all the relevant issues and taking the necessary action to ensure we can continue to have the gold-standard journalism that everyone in your Lordships’ House would expect.
(1 year ago)
Lords ChamberAlongside millions across the country, I was really proud to watch the Lionesses’ victory this summer, and I hope this continues to grow the game and inspire girls across the country. Karen Carney OBE led an independent review of domestic women’s football, published in July 2023. We agree with the recommendation that the women’s game should be given the opportunity to self-regulate, rather than moving immediately to independent statutory regulation. Should it be appropriate to do so in the future, we could include the women’s game. On Sheffield Wednesday and Morecambe, it is precisely because of such situations that we took decisive action to introduce the Football Governance Act.
My Lords, the nomination of David Kogan as the new football regulator has been widely welcomed in football and beyond—his capability and deep knowledge of the game are well recognised. Mr Kogan’s appointment was first announced in April, but four months later he is yet to be confirmed. The uncertainty affecting Morecambe FC and Sheffield Wednesday over the summer, to which the noble Lord, Lord Bassam, just referred, amply underlines why the sooner we have a football regulator up and running, with a chair, a board and an executive, the better. When does the Minister think this will all happen?
I was delighted to see David Kogan endorsed as the Government’s preferred candidate for chair of the regulator. David was subject to a pre-appointment hearing with the CMS Select Committee on 7 May, giving Members of Parliament an opportunity to scrutinise this important appointment before it is made. The committee endorsed David’s appointment, noting his extensive football and media experience. As noble Lords will be aware, the Commissioner for Public Appointments is conducting an inquiry into the process and DCMS is co-operating fully. No conclusion has been reached at this stage and it would not be appropriate for me to comment further.
(2 years, 6 months ago)
Lords ChamberOfcom, not the Government, regulates the provision of news, whatever channel people receive it on. The BBC receives some £3.8 billion in licence fee income; that income allows it to provide its important and impartial news, both at home and around the world.
My Lords, this is indeed a troubling and concerning matter. Does the Minister think there is a case for moving the licence fee to a monthly payment, paid by standing order, in line with other broadcast subscriptions? At the moment, that would mean a payment of £13 per month.
The Simple Payment Plan does help people pay the television licence fee at present. As I say, we are looking at all the ways in which the BBC might receive its funding in the future, taking into account the declining number of people paying for a licence, but looking at all options to make sure that it has the revenue it needs to continue doing the work for which it is much admired.
(2 years, 6 months ago)
Lords ChamberMy Lords, I will start by saying that I think the arguments of the noble Lord, Lord Forsyth, are absolutely unanswerable. This Bill includes some welcome measures in support of our public service broadcasters, particularly on prominence, but I intend today to identify the issues that the Bill should address but does not.
One hundred years ago, both main parties had the wisdom, in contrast to their US counterparts, to create a single, publicly funded public service broadcaster, the BBC. In the 1920s, a Conservative Government even had the wisdom to deny Winston Churchill his wish to take over the BBC during the General Strike, thus cementing its independence ever since. When ITV was launched in 1955, with Churchill now Prime Minister, it was of course commercially funded, but very heavily regulated, with substantial public service obligations. Ten years later, I joined the creative hothouse of Granada TV as a graduate trainee, and a few years later, LWT.
In subsequent decades, ITV would give the BBC a real run for its money: in current affairs, the investigative “World in Action” and “This Week”, both in peak time; an authentic northern voice with “Coronation Street”; “Brideshead Revisited”; the anthropological masterpiece “Disappearing World”; “Spitting Image”; and the first ever recording in the Cavern of an unknown Liverpool group. One of the greatest of ITV’s achievements—indeed of all global culture—was Melvyn Bragg’s painstaking chronicle, over three decades, of the world’s most renowned artists: Bergman, Sondheim, McCartney, Satyajit Ray, Walton, Lean, Callas, and many more.
ITV spent as much money on its local programmes as it did on its network. At LWT, the “London Programme” employed a young Peter Mandelson before his change of career, and was as well resourced as a network current affairs programme, famously rooting out corruption in the Met. ITV made Britain’s first programmes for ethnic minorities, with two young novice producers: one Trevor Phillips, the other Samir Shah. Whatever happened to them? ITV raised the BBC’s game too, forcing the somewhat highbrow broadcaster of the 1950s to embrace and brilliantly develop popular entertainment and drama programmes of quality: “Morecambe and Wise”, “The Two Ronnies” and “All Creatures Great and Small”.
Channel 4 was launched in 1982, when Mrs Thatcher was Prime Minister. Again, it was a deeply wise decision by government not to have an ITV2, pressed at the time, but rather, another publicly owned public service broadcaster, mandated to innovate and break the mould. And it did: “Gogglebox”, “Big Brother”, “Saturday Live”, “Dispatches”.
Of course, we had and have the contemporary BBC itself: the BBC of John Ware’s revelatory “Panorama” last week on Hamas; the BBC of unsurpassed coverage of the Coronation; the BBC of “Dad’s Army”, “Absolutely Fabulous”, “The Office”, “Fawlty Towers”, and “Fleabag”; the BBC of “Gardeners’ World” and “Countryfile”; of “Horizon”; of the Proms and “The Archers”; of the whole life’s work of David Attenborough.
No other country in the world comes even close to matching the dazzling success of British public service broadcasting. Though a BBC executive at the time, I attended—to criticism—Sky’s opening night in 1990. I unequivocally welcome the streamers for the explosion of riches they bring, but they are an expansion of choice and are not, and never will be, a substitute for what 100 years of UK PSB has brought us—for the PSBs, unlike the streamers, are rooted in British culture, identity, creativity, expression, experience and values.
It is horrific to apprehend that these very same PSBs are facing an existential threat. ITV has seen its share price fall by almost 80% since 2015, and—forgive me—is a shadow of its former self. Channel 4’s revenues fell by 20% in real terms in the decade following 2010. Since the pandemic, it has seen an uplift, but it is currently signalling stormy seas ahead.
The BBC is a prime victim of the culture wars, the governing party over the past 14 years wholly lacking the wisdom of its predecessors. From 2007 to 2022, BBC licence revenues declined by around 27% in real terms, yet in the same period the BBC has been handed further responsibilities which were previously funded by government. In 2014, it was required to fund most of the World Service from the licence fee; from 2018, some over-75s licences; and, since 2022, the whole cost of S4C. In all, these cuts and obligations add up to a 33% drop in real terms of the funding for core BBC programming. Unavoidably, the BBC is pulling back in every area of programming, and for me that is a personal tragedy.
Yet, in spite of these reverses, 96% of the population still consumes the BBC every month. On average, UK adults consume BBC services for around 17 hours per week, more than Netflix, Disney and Prime combined. Moreover, licence payers do so for a bargain £13 per month versus the Netflix subscription of £18 per month and the mighty £105 paid by a football fanatic such as me who wants to be able to watch any Premier League match across the three services that now carry Premier League games live. My football obsession now costs me six times as much as I pay each month to consume the BBC.
In conclusion, I look not just to the Minister, who is young and, I think, probably redeemable, but to other Front Benches and to all sides of this House, and I issue a challenge: whatever form a new Government take after our imminent general election, one of our national priorities simply must be to identify how we can ride to the rescue of one of our most precious and hard-won achievements of the past 100 years: British public service broadcasting.
(2 years, 8 months ago)
Lords ChamberThat is fitting for a Question begun by the noble Lord, Lord Morse. The noble Lord, Lord Bassam, is right. So many of the world’s democracies go to the polls this year, and this is an issue which will face broadcasters, but the BBC particularly, both at home and through the World Service, does a brilliant job at making sure that the claims of politicians—wherever they are in the world, whatever party they come from—are rightly scrutinised and that people are informed so that they can make decisions about the societies and countries in which they live.
It is right against the backdrop of an ever-more complex digital universe to review the funding model for the BBC, as the Government intend. However, will one or more of the panel of experts to be appointed to advise the Government be an expert in the evolution of the BBC, with an understanding that its emergence as one of the most renowned institutions in the whole world, noted for its values, its creativity, and its devotion to public purposes, is inextricably bound up in the fact that for 100 years it has been publicly funded?
We will ensure that the expert panel helps to inform our thinking in the round, looking at both the things that have made the BBC so successful over the last century and the challenges ahead. We have also already been consulting the BBC itself as part of the process.