1 Graeme Downie debates involving the Department for Science, Innovation & Technology

I also wish to mention amendment 3, tabled by the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). If a country cannot guarantee a fair trial, how can we think that, for any reason and at any time, we could disclose data that could result in an unfair conviction? That undermines our whole idea, and today of all days I cannot imagine why we would not enact something to protect the rights of our citizens when abroad.
Graeme Downie Portrait Graeme Downie (Dunfermline and Dollar) (Lab)
- View Speech - Hansard - -

I refer Members to my registered interest as parliamentary chair of the Campaign for Secure Technology, which I thank for its work in preparing my two amendments as well as my speech.

I echo the comments of my hon. Friends the Members for Leeds Central and Headingley (Alex Sobel) and for Newcastle upon Tyne Central and West (Dame Chi Onwurah) about the scale of the threat that we face from cyber-attack. We must ensure that we are having that national conversation about the nature of the threats we face, and who those threats come from. In many ways, this country is already in conflict with Russia, and in more than what we could call competition with China—something that the public are not fully aware of. We must do more to ensure that they are fully aware of that threat, and that they hold our feet, and those of the Government, to the fire, and ensure that we are taking the kinds of measures in this Bill, and beyond, that we need to protect our economy, our military and our democracy more widely.

I will limit my remarks to amendments 4 and 5, which I tabled. It is always difficult to speak at this point in a debate, because people with far more experience and knowledge than me have said a lot of the things that I was planning to say, and have done so with far more eloquence and knowledge than I have. Amendments 4 and 5 seek to deal with part of our digital infrastructure that is almost entirely invisible to the public and rarely discussed in Parliament—other than this afternoon—yet is essential to our national security: cellular internet-of-things modules. As my hon. Friend the Member for Warwick and Leamington (Matt Western) described, cellular IOT modules are small electronic components, about the size of a credit card, and they allow a device to connect to the internet over a mobile network. They sit inside everything from smart meters, CCTV cameras and traffic lights to industrial sensors, medical devices and parts of our energy grid. They are the connective tissue of our modern digital economy, and we all rely on them every day. Despite their importance, however, very little is known publicly about what they do and the potential harm that they could cause.

Today, more than 70% of all cellular IOT modules used globally are manufactured in China, and that dominance creates strategic vulnerabilities that the Bill must address. Amendments 4 and 5 would ensure that the Bill covers the risks created by embedded communications components manufactured outside the UK. Amendment 4 would ensure that the Secretary of State can treat the provenance of those components as a cyber-security risk, and amendment 5 would allow Ministers to require operators of critical systems to identify and mitigate those risks. In short, the amendments would give the Government clear authority to act where foreign-made modules create known vulnerabilities.

Why is that necessary? Because the modules present three major security threats. The first is dependency. When one country controls the overwhelming supply of a critical technology, that is by its nature a structural risk. If supply is disrupted, whether for geopolitical leverage or commercial pressure, our energy systems, transport networks and emergency services could be left without essential replacement parts. We have already seen that threat with Huawei and our 5G network—a mistake we must not repeat.

The second reason is disruption—as colleagues have said, that is increasingly referred to as the “kill switch”. Internet-of-things cellular modules contain firmware that can be updated remotely. If a manufacturer is subject to state influence—and in China we know that they are—it could insert a kill switch or back door that allows it to disable devices at scale and at will. It could push out malicious updates, insert malware or remotely disable devices. That could mean vehicles being turned off, cranes and industrial machinery being halted mid-operation, or financial terminals suddenly going offline. We could even see disruption to areas such as NHS refrigeration, affecting drugs and blood supply.

The concern with that type of module is that it might not happen overnight or be something we immediately see. It could be hidden for a number of weeks or months in different technologies and across different parts of our economy, and it would be incredibly difficult—nigh on impossible—to prove exactly what had happened and who had done it, and to tie it to any one state actor with certainty. It is certainly not something that could be done quickly, allowing for a full response. As my hon. Friend the Member for Warwick and Leamington said earlier, there are a number of examples of that from around the world. Perhaps the best known was when Russia invaded Ukraine in 2022 and tried to steal more than two dozen John Deere tractors and ship them to Chechnya. The US company intervened to switch them off. It remotely locked the thieves out of the equipment, rendering the tractors useless. That is the kind of action we could see China take in the event of a future crisis.

Closer to home, my hon. Friend the Member for Warwick and Leamington mentioned that Norway tested two of its Chinese-designed electric buses, one manufactured in the Netherlands and one built in China, to discover exactly the same kill switch technology.

Jim Allister Portrait Jim Allister (North Antrim) (TUV)
- Hansard - - - Excerpts

Does the hon. Member agree that, given that Transport for London now has 500 Chinese buses ordered and on the streets of London, there is a glaring opportunity for huge embarrassment to this nation if those kill switches were ever used on the buses in our capital city?

Graeme Downie Portrait Graeme Downie
- Hansard - -

That proves why we need more awareness of the threat that we face. It is not necessarily a case of banning certain components or technologies, but we must be more aware and ensure that the Government have the powers they need to respond where possible.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

My hon. Friend is right to say in his eloquent speech that raising awareness and having a debate about this issue is important, but the problems may not necessarily be the result of hostile actors. If the providers of the modules were to stop providing software updates, the modules would be more likely to fail and then become the subject of hostile attacks. So not only could the technology be killed by a hostile actor, but an increased dependency on software updates puts us at risk.

Graeme Downie Portrait Graeme Downie
- Hansard - -

As ever, my hon. Friend is correct. How many of us have had some bit of technology break because the firmware is no longer allowed to be updated, meaning that something no longer works, it is no longer supported and it breaks down immediately?

To add to that, by its nature, something that is not regularly updated becomes more vulnerable to attack by hackers. They may not be state sponsored, but they may take advantage of a weaker part of a technology. That was pointed out to me on a recent visit to Taiwan. Its semiconductor industry is incredibly strong, but it builds the more high-tech elements of semiconductors. I was told that it would not bother to commit to manufacturing other types of technology because they were too cheap and simple to make and could be mass produced. On that note, I refer to my entry in the Register of Members’ Financial Interests about the trip to Taiwan. I did not intend to raise it during my speech, but there was an opportunity to do so.

The third element of risk is data extraction, as was mentioned by the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). Under the Chinese national intelligence law, companies and organisations are legally required to assist state intelligence agencies and to hand over data upon request, creating a systemic risk in the UK that any data accessible through a cellular internet-of-things module could ultimately be accessible to the Chinese state.

Modern vehicles, especially electric and autonomous vehicles, are effectively computers on wheels, continuously collecting data on drivers, surroundings and infrastructure. The US Select Committee on China recently warned that Chinese EVs are “rolling data collection devices” and argued that restricting Chinese-made components is a national security imperative. The US Department of Commerce has now moved to limit the deployment of software and communications equipment sourced from adversary Governments in connected vehicles. Those who are worried about China’s reaction to such measures should be aware that it has already taken precisely these steps against the west. Tesla cars have been banned not just from entering Chinese defence, bases but from various Government agencies and authorities.

In the meeting mentioned by my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), I was concerned that there was a suggestion by one of the officials that there was no need to concern ourselves about the threat of Chinese internet-of-things modules because the threat was merely “theoretical”. As I and others have shown today, these examples are not just theoretical. Frankly, most threats are theoretical until they are not theoretical. This is happening now across critical sectors and national infrastructure. Other countries, such as the US, Australia and those in the EU, are all moving to toughen up their legislation specifically on cellular internet-of-things modules, and I believe that the UK must take action as well.

My amendments would ensure that the Bill explicitly covers these risks and gives Ministers the clarity and authority to act when necessary. If this Bill is to truly strengthen the UK’s cyber-resilience, it must not leave one of the most serious threats to our modern and increasingly digital world outside its scope. I ask the Government to work with me to address the threat of cellular IOT modules.

Melanie Ward Portrait Melanie Ward (Cowdenbeath and Kirkcaldy) (Lab)
- View Speech - Hansard - - - Excerpts

Madam Deputy Speaker, I hope you will not mind if I take a moment to reflect on the fact that today is the 10th anniversary of the murder of our dear friend Jo Cox. I was lucky to serve alongside Jo on the board of the Labour Women’s Network and we had done similar kinds of work previously. I often sit here in the Chamber and look at Jo’s shield and wonder what she would have made of the state of our politics, our country and our world today. I think about how much better we would be if she was still here to contribute. Jo’s most famous words matter so much today—that we

“have far more in common than that which divides us.”—[Official Report, 03 June 2015; Vol. 596, c. 674-65.]

As my hon. Friend the Member for Midlothian (Kirsty McNeill) said today, holding on to Jo’s words and keeping her spirit going matter always, but they matter even more when it is difficult to do that. I hope that Jo’s family and friends, and those closest to her, know how much she is missed and that we strive to carry her light forward with us.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

It is rare for me to have a point of divergence with the Chair of the Select Committee, given her experience and expertise. However, on that question I am absolutely not saying that Government support is limited only to the certain number of sectors covered by the Bill. There are a range of other ways in which the Government act to support sectors outside of the scope of the Bill. That is the right thing to do.

The scope of this Bill—the only Bill horizontally applicable to large parts of the economy—is systematically and specifically set to sectors that are significant as essential services, sectors where there is the risk of significant disruption and threat to life, and sectors where alternative supply is limited. For those reasons, we have excluded retail. Consideration of the scale of the business is not currently in that rubric, because there are also businesses that are small in scale but very material in life-threatening impact. I hope that is a satisfactory answer.

I thank my hon. Friends the Members for Dunfermline and Dollar (Graeme Downie) and for Newcastle upon Tyne Central and West for their amendments relating to the risks posed by communications modules made or controlled from outside the UK. Although I am sympathetic to their concerns, the Bill’s approach is intentionally technology and incident-agnostic. Instead of reacting to individual components in isolation, we focus on structural checkpoints and systematic dependencies in this context.

There are a range of other levers—investment screening through the National Security and Investment Act 2021; telecoms and cyber data security requirements to protect data and networks; supply chain measures, such as those in the Procurement Act 2023; diversification requirements to reduce dependency and build resilience—all of which are important to respond to the deeply significant concerns raised.

Graeme Downie Portrait Graeme Downie
- Hansard - -

Will the Minister give way on that point?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will make some further progress.

I thank my hon. Friend the Member for Leeds Central and Headingley for his amendment relating to AI emergencies. I recognise his concerns, as well as those of my hon. Friend the Member for Cowdenbeath and Kirkcaldy. Technology is evolving rapidly, and Government must be equipped to respond. That is why the Bill grants the Secretary of State the power to direct regulated entities if the compromise of their network and information system, or the threat of it, gives rise to a national security risk. This could, for instance, require an entity to cease using and isolate an AI model.

These powers are a backstop to an effective cyber-security regime, enabling Government to act swiftly in the face of unexpected national security threats. They are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability. While I share my hon. Friends’ concerns, I encourage them to work with the Government on a systematic range of ways in which we can mitigate the risks they have rightly highlighted.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I would be delighted to.

Graeme Downie Portrait Graeme Downie
- Hansard - -

I would be more than happy to work with the Government on something that will provide specific protections against cellular internet-of-things modules. What assessment has he made of the specific threat of internet-of-things modules, and what protections are there against that in the legislation?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Given the specificity of his question, I will suggest that I come back to my hon. Friend. The broad thrust is that through our investment control legislation and procurement legislation, there are a series of responsibilities on Departments to look at it. [Interruption.] Given your encouragement, Madam Deputy Speaker, I shall move on.

Finally, I will respond to the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), who raised a very important point. The most important thing to say is that I share his diagnosis, although for reasons mostly of technical drafting, I disagree with his prescription—I hope he will take that in the spirit in which it is intended. His amendment risks creating undue uncertainty in law for many other areas where we do not have an explicit requirement. While I share his diagnosis and his objective, I hope that we can work together to consider how best to give it effect, including through the Foreign, Commonwealth and Development Office’s overseas security and justice mechanisms for information sharing.

I thank all hon. Members for their consideration.