(4Â weeks, 1Â day ago)
Grand CommitteeMy Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.
I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.