Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Birt
Main Page: Lord Birt (Crossbench - Life peer)Department Debates - View all Lord Birt's debates with the Department for Science, Innovation & Technology
(2 weeks, 2 days ago)
Lords ChamberMy Lords, the Government’s own cyber survey reports that 43% of UK businesses experienced a cyber attack last year, costing the UK economy an estimated £15 billion. Here are just a few examples of those many attacks: a deepfake video call cost Arup £20 million; Marks & Spencer was attacked in Easter last year, losing an estimated £300 million, with operations fully restored only three months later; and, most impactful of all so far, Jaguar Land Rover suffered an attack, had to halt production for around five weeks, was unable fully to restore its supply chains for four months and lost around £500 million. Moreover, the Government had to step in and guarantee a loan of £1.5 billion to stabilise JLR’s extensive supply chain. Yet our economy is barely touched by the Bill, as the noble Baroness, Lady Northover, just identified.
I think that a lot of people, untutored, have a mental model of a technology platform as something you might offload off the back of an HGV; in reality, any technology platform, even in a medium-sized business, can be a highly complex network composed of hundreds of providers, any component of which can present a vulnerability. Just two examples among very many are the widespread reliance by providers on free-to-use but vulnerable open-source software maintained by volunteers, and the external software providers bolted on to a technology platform offering a myriad of services —for example, payroll, finance, logistics, e-commerce or customer relationship management.
There is a possible vulnerability in every part of this complex network of providers, with many doors to pry open. Once one door is opened by a bad actor—a fraudster, a foreign power, a hacktivist or a ransom gang—there is the potential to explore and disable much or all of the system. Entry can be through a clever phishing email, perhaps AI-personalised with stolen data, or through application, network and infrastructure vendors failing to close down vulnerabilities immediately they are identified.
Here is a frightening example: a Chinese entity was able to penetrate a large number of services provided by Microsoft to the US Government. As a result, the mailboxes of the Secretary of Commerce and the US ambassador to China, among many, were read. In a coruscating report, the Cyber Safety Review Board, the US government agency that investigated the breach, concluded that
“Microsoft’s security culture was inadequate”
and that the incident resulted from
“the cascade of Microsoft’s avoidable errors”.
We need to act now, to protect our wider economy as well as our public sector institutions.
I am not a technologist, but for three decades I have had to deal constantly with digital technologies and technologists from a position of authority in many large organisations in the public and private sectors, at national, European and global level. I have discussed the Bill extensively with technology and cyber experts who I know and respect, and it has become perfectly clear to me that the Bill as constructed does not begin to match the threats that we in the UK face, which will only grow.
For instance, AI will increasingly empower malign reconnaissance, enabling attacks that probe, diagnose and bypass defences. At some point, quantum computing, with its awesome power, will fatally undermine our current approach to encryption. This is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.
I conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience—OCR—to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use. For clarity, the OCR should also regulate the national infrastructure providers.
First, I propose that the OCR should regulate platform and software providers to ensure that they sell and vouchsafe secure products up front and update them immediately when vulnerabilities become apparent. That does not happen at the moment. The Office for Product Safety and Standards does that in the UK for consumer goods and the Vehicle Certification Agency does it for cars. Why should there not be protection for our vital technology?
Secondly, companies and institutions of a significant size are currently required under statute to face an annual external audit, the purpose of which is to maintain high standards in financial reporting and corporate governance, under a code set by the FRC—Financial Reporting Council. We should extend the remit of that audit, under the auspices of the OCR, to report on the audited organisations’ and their suppliers’ management of cyber security and thus bring company boards clearly into play.
Thirdly and finally, we need to professionalise the skills of the cyber and IT community, which are highly variable. Every profession of which I am aware that can have a significantly adverse impact on individuals or society faces a hierarchy of qualification before a professional can operate at different levels—whether physician, lawyer, chartered accountant, architect or airline pilot.
How far across the economy would the OCR’s remit reach? It would extend precisely to the same extent as the obligation to have a statutory audit; that is, to companies with an annual turnover of about £15 million that have in excess of 50 employees. I have a perhaps surprising statistic for the noble Earl, Lord Effingham: that would mean only 2% of UK companies. But those companies represent around 70% to 80% of the UK economy.
To conclude, we simply must be bolder. We must take the opportunity that the Bill presents better to enable every kind of organisation in the UK to withstand the ever-growing and deeply disruptive threat of cyber attack.