Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Arbuthnot of Edrom Excerpts
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- View Speech - Hansard - -

My Lords, what a pleasure it is to follow such an interesting and constructive speech. I hope the noble Lord will take full part in Committee on the Bill. I declare my interest as chairman of the advisory panel of the technology company Thales UK. I thank the Minister for the briefing that she gave noble Lords a couple of months back, which was extremely helpful.

The best legislation has a permeating principle that helps to explain the purpose of the new law and inspire obedience to and observance of the new law. The Joint Committee on the National Security Strategy held an evidence session yesterday on deterrence in an age of Russian aggression, in which one of the witnesses told us that the key thing that should be included in the Bill is that it should hold vendors of software accountable for the reliability and security of their product. That follows on from what the noble Lord, Lord Birt, just said. That, after all, is what we do with cars. When Ciaran Martin was the head of the NCSC, that was one of his overall aims.

However, that is not what this Bill does—it does not have a permeating principle. It is a bit of a muddle. Winston Churchill might have said that this pudding has no theme. My noble friend Lord Effingham asked about strategy, and he was absolutely right to do so.

The Bill draws in some sectors but not others, without any clear explanation of the difference between those that it includes and those that it excludes. In another place, the shadow Secretary of State for Science, Innovation and Technology, Julia Lopez, said that she supported the Bill but feared it might not work in practice. I too support the Bill but fear it might not work in principle.

We live in an age when everything is connected to everything else. Drawing dividing lines between, for example, the private sector, some of which is included and some of which is excluded, and the public sector, which is excluded, is perilous and leads to incomprehension of the law.

That set of unclear distinctions also ignores the effect of cascade. During lockdown, a health crisis turned into an education crisis, with exam results becoming an unexpected casualty of Covid. When everything is dependent on computers, and the public sector is dependent on the private sector, and vice versa, it is unwise for new legislation to specify rigid demarcations.

Those taking part in this debate have received many useful briefing notes, from the Association of British Insurers, correctly drawing attention to the great value in behavioural terms of insurance, which can have a real impact on resilience of all types as well as cyber resilience; from the News Media Association, about the real danger posed by bots, which now form 50% of all internet traffic, which is accelerating fast; and from Zurich, correctly identifying the huge role played by SMEs in the cyber security sector yet worrying about the ability of SMEs to bear the demands of regulation, not least in reporting incidents within 72 hours; and many more.

I know that the Government are committed to reforming the Computer Misuse Act in the coming national security Bill, as the noble Lord, Lord Clement-Jones, has been demanding for many a year now. CyberUp’s long-running campaign on this is far too long-running. While I am talking about cyber security professionals—because that is the point of amending the Computer Misuse Act: to give them proper protection—I cite the very helpful briefing from ISC2. It says that the Bill will dramatically increase the demand for cyber security professionals even though there is currently a significant shortage of them.

As I understand it, the number of cyber security positions in government that are currently vacant stands at 50% of the total. That is horrifying. Some 58% of UK organisations have a critical or significant skills need and 87% of teams have experienced at least one consequence due to skills needs. The members of ISC2 have said that the biggest impediment to them complying with cyber legislation and regulation is a shortage of skills, so what does this legislation do to increase those skills? Could we look at defining the meaning of a “skilled person” in the Bill?

The shortage of such skills is likely to be exacerbated by there being 12 different regulators—here again I rather echo what the noble Lord, Lord Birt, said. There is going to be a risk of duplication of regulation, even potentially of contradictory regulation. What is an organisation meant to do if one regulator requires that it does one thing but another regulator requires that it does not? Will the Government ensure that regulators adopt common forms of evidence for demonstrating compliance and common cyber security standards? How does the legislation take into account the fact that many organisations will be subject to foreign legislation as well? I agree, as on many other things, with what the noble Baroness, Lady Northover, said about encouraging alignment with the European Union. How are we learning from overseas experience?

This is a well-meaning but muddled attempt to deal with an exceptionally fast-moving, difficult problem. Governments always find it hard to keep up with the pace of technology, so is it right that we should re-examine this Bill only every five years? The Secretary of State should have to report to Parliament earlier than every five years. I know I sound a bit miserable, but I support the Bill. I really do. It could be better, and we will have a lot of work to do in Committee.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Arbuthnot of Edrom Excerpts
Moved by
15A: Clause 12, page 10, leave out lines 27 and 28 and insert—
“(a) P supplies goods or services, whether directly or through one or more intermediaries, on which an OES for which the authority is the designated competent authority materially depends for the provision of an essential service,”Member's explanatory statement
This amendment would allow regulators to address material dependencies beyond immediate contractual suppliers, while ensuring that the statutory review tests whether supply-chain risks outside the regulatory perimeter are undermining resilience and does so at a frequency that reflects technological and threat-related change.
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - -

My Lords, I apologise for having spent less time in Committee than I would have liked, but I have been speaking on the Public Office (Accountability) Bill. I am grateful to those noble Lords who I suspect have been speaking to amendments on my behalf.

Amendments 15A and 15B are about the designation of critical suppliers. New Regulation 14H says:

“A designated competent authority may designate a person … under this regulation if P supplies goods or services directly to an OES for which the authority is the designated competent authority”.


The Bill expands this regime to cover additional organisations and creates a new framework for designated critical supplies. That is good, and it recognises that essential services depend on organisations that go far beyond the direct infrastructure of the critical organisation itself; everything is dependent on everything else. However, the critical supplier test is focused on suppliers providing goods or services directly to a regulated organisation. That ignores the concept of a supply chain with several tiers of suppliers. These amendments are intended to address that. Therefore, I beg to move.

Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, I will speak briefly to my Amendment 16. In my view, the central problem is that, if I am small or medium-sized firm, I cannot currently tell with any confidence whether I am within the scope of the Bill as a critical supplier. Small and medium-sized enterprises are the lifeblood of our economy, and we need to approach with caution any ambiguity around their inclusion in the Bill. I took note of what the Minister said at Second Reading, when she said that:

“They can be regulated if they are designated as critical suppliers, for which there will be a high bar for designation”.—[Official Report, 14/7/26; col. 622.]


That was helpful, but what exactly is that high bar?

To give noble Lords an example of regulation legislation that is not defined, I come back to one noble Lords are likely to be familiar with: the infamous IR35. With that, the uncertainty and costs of getting it wrong were high in the regulation, so firms applied a blanket under which everyone they engaged with had to be inside IR35 and had to be treated as an employee. IR35 addressed a real problem, but the test was judgment-heavy and getting it wrong was expensive. That was why many organisations stopped making case-by-case decisions and applied a blanket policy, which meant that far more were caught by the regulation than was intended. I remember many years ago, as an engineer, spending a lot of time trying to fill in IR35 determinations and not doing engineering, which was a frustration at the time. It led to many issues with finding the right new skilled resource that we required to undertake the work.

I am sure that the Minister will say that the criteria will be set out in secondary legislation, but there will be a long period of uncertainty, and the IR35 example helps illustrate the risks. I took a look at the impact assessment and some of the costs were laid out. For example, if a firm is within the scope of this legislation, it is looking at physical security costs of perhaps £114,000 and cyber security spending—potentially of £190,000 a year. The impact assessment could not say how many SMEs may be designated within this legislation. All of that uncertainty is a cost, because it means that, if firms are uncertain about whether they are going to included, they may delay investment. In fact, they may overprepare; they may take on additional costs, which has wider implications to the UK economy, or they may walk away from public services. They will not want to go for these contracts because of the risk they may fall under this legislation, and that could potentially cause the same grit in the wheel of the economy that was seen in IR35. There is a case here for providing in the Bill at least some additional definition on what a critical supplier is; that is what my amendment intends to do.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - -

My Lords, I listened carefully to what the Minister said. She made some very reasonable points and she may even be right, but I will need to take it away and think about it. In the meantime, I beg leave to withdraw my amendment.

Amendment 15A withdrawn.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Arbuthnot of Edrom Excerpts
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, it is a pleasure to support these amendments. I have signed all of them, although in doing so I almost got a serious case of electronic RSI. They have the great good fortune of being clear, precise and aligned with existing regulations in other jurisdictions. As my noble friend Lady Harding has already pointed out, many businesses will have operations in multiple jurisdictions. For something as significant as reporting, why would we not follow NIS2 in this respect?

The clarity of the amendments is their strength, even more so when compared with what is currently in the Bill in this respect. What we are trying to achieve from these changes is clear. The 24-hour initial reporting period makes sense: of course it does. As my noble friend Lady Harding pointed out, what one knows at that point is that something is happening and a report is made. In many ways, that is all that needs to be known and all that needs to be reported.

To have a situation as currently set out in the Bill, 24 then 72, means that in that period so much would need to be known to comply with the provisions set out in the Bill that it is just not realistic. This staged approach is both clear and precise. It enables what the purpose of the Bill is all about, which is to support the individual business or entity that is under attack. Crucially, as other noble Lords have said, it puts the power in the collective. As a consequence of one attack, the collective can benefit if there is a sense of commitment to this reporting schedule. That will come only if it is in this stage 4, as clearly set out by my noble friend Lady Harding.

If we want to enable businesses and other entities to really commit to this process—not just be dragged there by force of statute but have it as a means of business as usual, a real cultural change and a commitment to the positivity of this—it has to work for them. This staged process not only does that but, by aligning with NIS, stops this being yet another burden added to business: added unnecessarily and less effectively than what these amendments propose. I very much look forward to the Minister’s response.

Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - -

My Lords, good can come out of bad events. The experience, as well as the speech, of my noble friend Lady Harding is one such good aspect. If it combines with bringing us into line with European practice, which so many businesses already have to follow, so much the better. I hope the Minister will be as sympathetic as she possibly can to my noble friend’s amendments.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.

In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.

I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.

Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.

--- Later in debate ---
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - -

My Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.

I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.

I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.