Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Neville-Jones
Main Page: Baroness Neville-Jones (Conservative - Life peer)Department Debates - View all Baroness Neville-Jones's debates with the Department for Science, Innovation & Technology
(2 weeks ago)
Lords ChamberMy Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period.
What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves.
One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again.
We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator—there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and willingness to change gear, are things that we will have to come to terms with. When it is the case that we have not got it quite right, we will need to be prepared to say so.
The thrust of the Bill is certainly in the right direction. I will focus on some of the more detailed points in the drafting where I think we need to try to accomplish some improvements. There is quite a lot of looseness in the drafting, which needs tightening up. For example, terms such as “managed service provider” and “critical supplier”, as well as the wide definition of the notion of “incident”, all need greater precision. We need to avoid situations where words such as “incident” become a way in which companies that have no particular involvement get tangled up in regulation. If part of a company provides managed services, we need to know, and the company needs to know, whether the whole company is caught by the Bill or whether it is simply that part that provides managed services.
There is plenty of implementation detail on which we will need to have a closer fix. I am willing to give the Government the power to fill in the detail and update the law through secondary legislation, as it seems to me that we cannot always have primary legislation doing everything. However, we will need a duty to consult written into the Bill for it to be a safe proposition. One thing I would like to ask the Minister is about the timetable for secondary legislation. Will the Government be willing to consult when it comes to putting that through? That will be a very substantial part of the Bill.
I want to make a couple of comments about the effects of the scope of the Bill. First of all, with the exception of service providers, who are classed as “critical suppliers”, and data centres, the Bill, as other people have remarked, is exclusively concerned with the public sector. As the Government Minister and indeed others have pointed out, some of the biggest losses have occurred in the private sector. I do not need to describe these, as they have been described already.
The Government may argue that they properly seek not to regulate the private sector. I certainly have considerable sympathy with that, but it is not satisfactory from the point of view of the taxpayer that the Government had to bail out with public finance Jaguar Land Rover. Under current conditions, I do not think that that breach, which was expensive, is likely to be the last one with sizeable financial effect.
The Government have recognised the problem and are encouraging private sector companies to make a pledge to improve the management of cyber security at board level. I am all in favour of that: improve reporting in the corporate code and increase activity by the audit committee, whose members, if properly equipped with cyber expertise, will make a valuable contribution. That is part of the way that we must move forward. Having said all that, private sector security self-help, while essential, is not sufficient. So what should we do?
The Government correctly tell us that their first duty is the defence and security of the nation. Cyber security strategy—which I know something about, having been involved in it—was founded on the proposition that the protection of the economy involved active partnership between public and private sectors. The NCSC does a vital job in increasing understanding about the threat and giving advice and guidance on countering it, but it could do an even more important and larger job. It was intended at the outset to be more public-facing than is currently the case. It has, to some extent, retreated from its previous public start. I would like to see the NCSC re-emerge from the shadows with more threat analysis, advice and guidance, and its funding increased to do this.
This would be particularly helpful to SMEs. We have all been worried about their access to expertise and considered that the cost to them of security, which is not insignificant, should be somehow alleviated. They are valuable to us. Small companies provide very important parts of larger systems. If the NCSC were to be a much more active security partner to the corporate world, there would be a strong case for financial support from the private sector to it, to make this much more of a joint enterprise.
I urge the Government to put their intelligence capabilities to greater effect in supporting the private sector to raise its level of security. I do not think this is beyond us. We ought to try to do something where there is much closer co-operation between public and private sectors. The banking world, though different, gives us some pointers on the way in which that could be done.
Secondly, within the public sector, the scope of the Bill is puzzlingly selective, as other speakers have touched on. There is palpable anxiety among the general public about the security of One Login and accessing government services safely. This is a moment when the Government could increase confidence. However, not all government services are covered. To take an example, DWP has in its possession detailed personal—not to say intimate—information about its clients and beneficiaries. Surely it should be a candidate for coverage, but it is not. What are the criteria that govern whether a public sector service is covered or not? On the face of it, I do not think selectivity looks wise. The Government have chosen—
Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
I gently remind the noble Baroness that there is an eight minute advisory Back-Bench speaking time.
I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators.
My last thought is that we need to ensure that another definitional issue in the Bill, the level of security
“appropriate to the risk posed”,
is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.