Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Arbuthnot of Edrom
Main Page: Lord Arbuthnot of Edrom (Conservative - Life peer)Department Debates - View all Lord Arbuthnot of Edrom's debates with the Department for Science, Innovation & Technology
(2 weeks, 1 day ago)
Lords ChamberMy Lords, what a pleasure it is to follow such an interesting and constructive speech. I hope the noble Lord will take full part in Committee on the Bill. I declare my interest as chairman of the advisory panel of the technology company Thales UK. I thank the Minister for the briefing that she gave noble Lords a couple of months back, which was extremely helpful.
The best legislation has a permeating principle that helps to explain the purpose of the new law and inspire obedience to and observance of the new law. The Joint Committee on the National Security Strategy held an evidence session yesterday on deterrence in an age of Russian aggression, in which one of the witnesses told us that the key thing that should be included in the Bill is that it should hold vendors of software accountable for the reliability and security of their product. That follows on from what the noble Lord, Lord Birt, just said. That, after all, is what we do with cars. When Ciaran Martin was the head of the NCSC, that was one of his overall aims.
However, that is not what this Bill does—it does not have a permeating principle. It is a bit of a muddle. Winston Churchill might have said that this pudding has no theme. My noble friend Lord Effingham asked about strategy, and he was absolutely right to do so.
The Bill draws in some sectors but not others, without any clear explanation of the difference between those that it includes and those that it excludes. In another place, the shadow Secretary of State for Science, Innovation and Technology, Julia Lopez, said that she supported the Bill but feared it might not work in practice. I too support the Bill but fear it might not work in principle.
We live in an age when everything is connected to everything else. Drawing dividing lines between, for example, the private sector, some of which is included and some of which is excluded, and the public sector, which is excluded, is perilous and leads to incomprehension of the law.
That set of unclear distinctions also ignores the effect of cascade. During lockdown, a health crisis turned into an education crisis, with exam results becoming an unexpected casualty of Covid. When everything is dependent on computers, and the public sector is dependent on the private sector, and vice versa, it is unwise for new legislation to specify rigid demarcations.
Those taking part in this debate have received many useful briefing notes, from the Association of British Insurers, correctly drawing attention to the great value in behavioural terms of insurance, which can have a real impact on resilience of all types as well as cyber resilience; from the News Media Association, about the real danger posed by bots, which now form 50% of all internet traffic, which is accelerating fast; and from Zurich, correctly identifying the huge role played by SMEs in the cyber security sector yet worrying about the ability of SMEs to bear the demands of regulation, not least in reporting incidents within 72 hours; and many more.
I know that the Government are committed to reforming the Computer Misuse Act in the coming national security Bill, as the noble Lord, Lord Clement-Jones, has been demanding for many a year now. CyberUp’s long-running campaign on this is far too long-running. While I am talking about cyber security professionals—because that is the point of amending the Computer Misuse Act: to give them proper protection—I cite the very helpful briefing from ISC2. It says that the Bill will dramatically increase the demand for cyber security professionals even though there is currently a significant shortage of them.
As I understand it, the number of cyber security positions in government that are currently vacant stands at 50% of the total. That is horrifying. Some 58% of UK organisations have a critical or significant skills need and 87% of teams have experienced at least one consequence due to skills needs. The members of ISC2 have said that the biggest impediment to them complying with cyber legislation and regulation is a shortage of skills, so what does this legislation do to increase those skills? Could we look at defining the meaning of a “skilled person” in the Bill?
The shortage of such skills is likely to be exacerbated by there being 12 different regulators—here again I rather echo what the noble Lord, Lord Birt, said. There is going to be a risk of duplication of regulation, even potentially of contradictory regulation. What is an organisation meant to do if one regulator requires that it does one thing but another regulator requires that it does not? Will the Government ensure that regulators adopt common forms of evidence for demonstrating compliance and common cyber security standards? How does the legislation take into account the fact that many organisations will be subject to foreign legislation as well? I agree, as on many other things, with what the noble Baroness, Lady Northover, said about encouraging alignment with the European Union. How are we learning from overseas experience?
This is a well-meaning but muddled attempt to deal with an exceptionally fast-moving, difficult problem. Governments always find it hard to keep up with the pace of technology, so is it right that we should re-examine this Bill only every five years? The Secretary of State should have to report to Parliament earlier than every five years. I know I sound a bit miserable, but I support the Bill. I really do. It could be better, and we will have a lot of work to do in Committee.