Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Taylor of Warwick
Main Page: Lord Taylor of Warwick (Non-affiliated - Life peer)Department Debates - View all Lord Taylor of Warwick's debates with the Department for Science, Innovation & Technology
(3 weeks, 5 days ago)
Lords ChamberMy Lords, I thank the Minister for introducing this important Bill. Cyber security is clearly vital to the protection and prosperity of our nation. But if we fail to plan, we plan to fail, and this Bill is at the heart of the Government’s cyber security plan.
I was born and raised in a part of the world that many think of as paradise, bliss, utopia. It is called Birmingham, just off the M6 by the gasworks. I can see there is some accord in the Chamber—or maybe it should go to VAR. I was a district councillor in that region. One of the largest employers there is Jaguar Land Rover. This giant motor vehicle manufacturer is the head of a supply chain of over 4,000 companies. JLR was the victim, as we all know, of a cyber attack last year and was bailed out by this Government to the tune of a £1.5 billion loan guarantee. The Government believed they had no choice because if they had let JLR fall, thousands of workers would have lost their jobs. I have some sympathy with that rationale, but it did set a dangerous precedent. It is also worth noting, surely, that the company had not completed taking out an insurance policy against cyber attacks.
So the first point I want to make to the Minister is that there is no mention in the Bill of the role of the insurance industry. Surely the issue of essential and compulsory cyber insurance needs to be looked at; otherwise, we will have another situation where we have to bail out another huge company.
The retail chain Marks & Spencer lost 99% of its profits due to a ransomware attack which disrupted services and stole customer data last year. Harrods and the Co-op also experienced cyber breaches over recent months. Surely, then, there is a glaring weakness in the Bill in that it will have no impact on private companies such as these. Can the Minister explain why the scope of the Bill cannot be extended—not in the future but now—to include large private retailers, at least those over a certain defined size or turnover? I understand there is potential in the Bill for improving things in the future, but why not do it now?
One of the lessons of history is that we must learn lessons from history, and surely a vital lesson is to take into account the changes in the world around us. In the Bill, the Government recognise that the artificial intelligence revolution has increased the need for more effective cyber security. Yet there is still no UK AI regulation, no cyber strategy, no mention at all of quantum computing or encryption. These matters need to be discussed and looked at now, not some time in the future, when you consider how fast AI is progressing.
We also have a cyber security skills shortage, with 49% of UK companies admitting a lack of cyber foundational skills. As well as protecting the nation, in this AI age it is skills that will pay the bills and grow the economy. It is right that the Government have announced initiatives to attempt to fill vacancies in the cyber security industry, but there is no definition in the Bill of what is required to be a “skilled person” in this context. I just ask the question: why not? Why not look at it now?
We are living longer, and the demands on the public sector are growing, but there is a lack of focus in the Bill on the public sector, particularly the risk to NHS data. For example, Synnovis, which has been mentioned, is a company which provides pathology services to the NHS. A couple of years ago, a ransomware attack on Synnovis cost £32.7 million and resulted in delays to more than 11,000 appointments and even, allegedly, one death. Surely all companies, private and public, that hold personal data should demonstrate that they have effective defences against cyber attacks. I have tried to find out whether Synnovis or its suppliers would be covered by the Bill; there is some ambiguity over that, and that ambiguity at this stage is not helpful.
I welcome that the expanded scope of the Bill now includes data centres, managed service providers, electrical load controls and critical suppliers. But the Bill does not go far enough to protect the UK economy. The current structure of the Bill allows the Secretary of State, in principle, to expand the number of sectors in the scope of the regulations. But even to implement secondary legislation will require the Government to meet a number of conditions. The Minister has referred to emergency powers, but that is still a process rather than an event. Surely the principle of the Secretary of State reporting back to Parliament every five years is not good enough in this fast AI world that we are living in.
The Government also need to recognise that many companies operate across borders, including in the EU, where they have to comply with European directives on cyber security that do not apply in the UK. Over- regulation must not stifle innovation. With 12 regulators enforcing this Bill, there is a danger of regulatory duplication. This is especially so for organisations covered by more than one regulator. Where appropriate, the Government should seek to ensure that UK cyber security regulations align across each regulated sector and across borders with other jurisdictions such as the EU. For example, the Government could ensure that all regulators accept common forms of evidence demonstrating compliance.
There needs to be the adoption of a common baseline security standard, alongside ongoing evidence of security requirements across regulated sectors. This should also recognise that different sectors have their own particular needs: farming is different from fashion, which is different from football. The standard could be the National Cyber Security Centre’s cyber assessment framework. An example of co-ordinating regulators already exists in the Digital Regulation Cooperation Forum, which helps deliver a coherent approach to digital regulation.
Some 43% of all UK companies experienced a cyber breach in the past 12 months. The Department for Science, Innovation and Technology reports that cyber attacks cost the UK economy £14.7 billion a year, and the problem is increasing. For 10 years, I had the privilege of being vice-president of the British Board of Film Classification. Hollywood sometimes produces entertaining films that see the future; for example, Steven Spielberg’s movie “A.I.” was made 25 years ago—an incredible thought. There was a consistent theme in many of the more positive films that we regulated, in that good overcame evil. With a stronger version of this Bill, we can defeat the cyber monsters. In the more positive and hopeful movies we regulated, RoboCop prevailed over the Terminator and Luke Skywalker overcame Darth Vader.