Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateViscount Camrose
Main Page: Viscount Camrose (Conservative - Life peer)Department Debates - View all Viscount Camrose's debates with the Department for Science, Innovation & Technology
(3 weeks, 2 days ago)
Lords ChamberMy Lords, I am grateful to all noble Lords who have contributed to the debate and, of course, to the Minister for her introduction. It has been a really thoughtful, compelling and persuasive debate. It is clear that, on all sides of the House, there is a shared recognition of the scale of the threat that this legislation seeks to address and the importance of doing so effectively.
As my noble friend Lord Effingham said, we on these Benches support the objectives of the Bill. Indeed, much of what is in it has its origins in work begun by the previous Government, following the 2022 consultation, and we applaud the continuity. We do not intend to try to make the perfect the enemy of the good, although I wholly endorse the cyber insurance argument set out by the noble Baroness, Lady Paul of Shepherd’s Bush, my noble friend Lord Ashcombe and others.
Listening to the debate has only reinforced for me the central question with which we began: where is the strategy? Ministers have described the Bill as one part of a wider programme, yet the national cyber action plan that was promised before the end of last year, and then promised again for this summer, remains unpublished. I observe as an aside that, as with the defence investment plan, we are in danger of creating the perception, which we must avoid, that there is a pattern of delay and avoidance when it comes to defending ourselves. Noble Lords across the House have, in their own ways, returned again and again to that same point.
I started off the debate diligently writing down everybody who called for a change to the scope but that turned out to be everybody, which makes our task today far harder. I absolutely accept that this is a Bill designed to have a narrow scope, but we have no way to understand the broader context in which that narrow scope sits. It is like trying to judge an orchestra but being allowed to hear only the woodwind section.
It is inevitable that we will have questions, concerns and suggestions that go beyond the narrow scope and intent of the Bill. How will SMEs learn to protect themselves better? Many people have raised that. A great many noble Lords—again, almost everybody—mentioned AI, but what response overall is envisaged to the threats of emerging technologies of which as yet we know little, such as new AI models at the frontier, quantum cracking and so on? How will we reduce the number of vacancies for cyber roles? By the way, it is not a new problem, by any means, that there are too many vacancies for cyber roles. We were wrestling with it when we were in government. It is an intractable problem that we need to find better ways to address.
How will we address the growing prevalence and effectiveness of weaponised disinformation that does so much harm to our society every day, right now? More fundamentally, what are our strengths and weaknesses relative to those of our assailants and our allies? Let me express the hope—I will return to this point—that, during the Bill’s passage, and ideally before Committee, we have the national cyber action plan to answer these and no doubt many other questions. This could make the passage of the Bill considerably easier for all of us, in particular for the Minister, and indeed help bring about the wish of my noble friend Lady Neville-Jones that we get through the Bill quickly in order to get these measures on to the statute book as soon as possible.
Even the National Cyber Security Centre itself has publicly called on government to set out a clearer strategic policy agenda. If GCHQ’s own technical authority feels moved to say so, that ought to give the Minister and the Government pause.
In the other place, my honourable friend Dr Ben Spencer made precisely this point, warning that the National Audit Office had found
“inconsistent, and in some cases glacial, progress”,—[Official Report, Commons, 6/1/26; col. 223.]
in cyber resilience, and that the Bill risked becoming “yet another missed opportunity”. My honourable friend Julia Lopez for her part reminded the Commons that, if the pandemic had accelerated the adoption of digital technology, artificial intelligence would embed it further still. Yet, as she noted, and as noble Lords, including my noble friend Lord Arbuthnot, have echoed this evening—in fact, as everybody has said this evening—the Bill is silent on AI. It is silent on the Computer Misuse Act. These omissions go to the heart of whether this legislation will still be fit for purpose in five years’ time, given how disappointingly rarely Parliament revisits this ground.
On the question of regulatory burden, I was also struck by how many noble Lords share our concern for smaller businesses. I hope that the Minister agrees that this is not a party-political point. It was raised by members of the party opposite in the other place too, who rightly noted that SMEs are disproportionately targeted by cyber crime, yet are the least equipped to absorb new compliance obligations. In fact, techUK, as the noble Lord, Lord Clement-Jones, pointed out, has warned that leaving so much of the detail of this regime to secondary legislation, as well as using some of the rather woolly language that was commented on by the noble Lord, Lord Ravensdale, risks creating exactly the kinds of legal uncertainty and cost that fall hardest on smallest firms.
Again, I am trying to make not a political point—we urgently need this Bill—but a practical point. Indeed, my noble friend Lady Harding’s account of attempting to communicate while managing the crisis caused by an attack was absolutely salutary and I hope the Minister will take note of it.
So, as we move towards Committee after the Summer Recess—I think Committee promises to be a very productive activity—I hope the Minister will reflect carefully on the questions raised today and, in her closing, perhaps answer the following questions. First, will the Government commit to a firm date for publishing the strategy within which this legislation is meant to sit? Secondly, how will the effectiveness or otherwise of the Bill’s measures be assessed, and how will that assessment be reported to Parliament—we hope not every five years? Thirdly, what assessment has been made of the cumulative reporting burden facing businesses of all sizes already subject to data protection and sector-specific obligations? Fourthly, what confidence can the Minister offer the House that the 12 regulators tasked with enforcing this regime, which we have heard a great deal about, will have and will continue to have the resources and expertise to do so effectively?
In Committee, we on these Benches will continue to press the Government on precisely these questions because, as with any regulation, it must be built on a foundation of strategic clarity rather than being asked to substitute for it. I look forward to the Minister’s response.