Threads / Cyber Security and Resilience Bill / Cyber Security and Resilience (Network and Information Syst…
Parliamentary Debate Published 7 Sep 2026 ↗ View on Parliament

Cyber Security and Resilience (Network and Information Systems) Bill

Committee (3rd Day) 15:45:00 Northern Ireland, Scottish and Welsh l egislative c onsent sought . Relevant documents: 3rd Report from the Constitution Committee and 7th Report from the Delegated Powers Committee Clause 37: Procedure for issue of code of practice Amendment 92C Moved by 92C: Clause 37, page 62, line 24, leave out subsection (7) Member’s explanatory statement This probing amendment would remove the power for the Secretary of State to amend this Act by regulations so as to change the consultation and parliamentary scrutiny requirements applying to a code of practice. It responds to the recommendation of the Delegated Powers and Regulatory Reform Committee in its 7th Report. Lord Clement-Jones (LD): My Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always author

Attachments
▤ Verbatim text from source document

Committee (3rd Day)

15:45:00

Northern Ireland, Scottish and Welsh l egislative c onsent sought . Relevant documents: 3rd Report from the Constitution Committee and 7th Report from the Delegated Powers Committee

Clause 37Procedure for issue of code of practice

Amendment 92C

Moved by

92C: Clause 37, page 62, line 24, leave out subsection (7) Member’s explanatory statement This probing amendment would remove the power for the Secretary of State to amend this Act by regulations so as to change the consultation and parliamentary scrutiny requirements applying to a code of practice. It responds to the recommendation of the Delegated Powers and Regulatory Reform Committee in its 7th Report.

Lord Clement-Jones (LD)My Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always authoritative recommendations of the Delegated Powers and Regulatory Reform Committee in its seventh report of this Session and are strongly supported by the principles laid down by the Select Committee on the Constitution in its third report. Together, these amendments seek to delete two deeply objectionable provisions that represent a classic example of secondary legislation creep—provisions where the Executive are seeking a blank cheque to unilaterally rewrite the rules.

Amendment 92C targets Clause 37 and seeks to leave out subsection (7). Under the Bill as drafted, Clause 37(7) grants the Secretary of State the unilateral power to make regulations to amend the Act to change and potentially dilute the consultation and parliamentary scrutiny requirements that apply to a code of practice. This is a Henry VIII power of quite an extensive kind. In the Government’s original delegated powers memorandum of November 2025, the department, as it then was, argued that this power was necessary to allow flexibility in case a 40-day parliamentary scrutiny period became, in its words, “unfeasible” or

“a detriment to the quality of … a code”. But as the Delegated Powers Committee correctly noted in its seventh report, the rules governing how Parliament scrutinises the Executive must be set by Parliament in primary legislation; they should not be subject to the administrative convenience of a Minister. Allowing a Minister to use secondary legislation to alter or weaken the very procedural safeguards that this House has debated is not constitutionally correct. The committee’s recommendation is clear and unambiguous: subsection (7) must be removed.

That brings me to Amendment 95C, which seeks to leave out Clause 40(5). Clause 40 requires the Secretary of State to lay a report before Parliament on the operation of this cyber security legislation. However, subsection (5) grants the Secretary of State the power to amend this primary legislation via regulations to change the matters to be covered in those same reports. Again, in their original November 2025 memorandum, the Government defended this by claiming that they needed flexibility to ensure that reports could be expanded over time as technology matures.

With the greatest respect, that argument is entirely spurious. If the Government merely wish to report on more things, they are already fully entitled to include voluntary supplementary chapters in their reports. But by granting themselves a statutory power to amend the legal requirements of Clause 40, they are taking the power to delete or dilute the core mandatory reporting obligations that Parliament has put in the Bill. They would, in effect, be legally empowered to write their own report cards, deciding behind closed doors what they must disclose to Parliament and what they can quietly omit, including critical scrutiny over how they have used the vast delegated powers under Clause 29(1).

The Delegated Powers Committee was again clear. This power is inappropriate, lacks coherent justification and should be deleted from the Bill. The Select Committee on the Constitution too, in its third report, expressed serious anxieties about the overall design of the legislation. It warned that this is a framework Bill that relies far too heavily on secondary regulations to establish the actual perimeters of national cyber resilience.

When a Bill already delegates such sweeping unprecedented powers to the Executive, amplified by the amendments to introduce a parallel high-risk vendor framework, laid on 24 August and discussed on the first day of this Committee, it is doubly important that the statutory channels of parliamentary oversight remain supreme. We cannot allow the Government to use secondary regulations to dismantle the guardrails that keep them accountable. I urge the Minister to accept these common-sense, committee-backed corrections and agree to delete Clause 37(7) and Clause 40(5) before Report. I beg to move.

Viscount Camrose (Con)My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.

I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to

“prioritise the content of the code of practice, rather than arbitrary requirements”.

It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.

By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?

It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.

Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.

These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament. On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.

On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.

I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.

Lord Clement-Jones (LD)I thank the Minister for her response, which was the reverse of the usual ministerial response—the sting was not in the tail but at the beginning. The end was much more conciliatory, given that she said the Government will consider taking on board the DPRRC’s recommendations before Report. I very much hope they do. At this stage in Committee, of course, nothing gets decided, but I assure the Minister that, if this continues, and the Government do not respond in some shape or form to both those pretty solid recommendations from the committee, we will bring this back on Report.

When I say that the sting was in the beginning of the response, I mean that it was a bit surprising, given that the Minister has been the chair of the committee and knows the seriousness with which we all take its recommendations. A huge amount of work goes into the detail, and she knows how much store we place on the recommendations. I hope that she will use all her influence to make sure that the Government introduce before Report something along the lines of what I have produced. In the meantime, I beg leave to withdraw Amendment 92C.

16:00:00

Amendment 92C withdrawn.

Clause 37 agreed.

Amendment 93 not moved.

Clauses 38 and 39 agreed.

Amendment 94 not moved.

Clause 40Report on network and information systems legislation

Amendments 95 to 95C not moved.

Clause 40 agreed.

Clause 41 agreed.

Clause 42Consultation and procedure

Amendments 96 to 98 not moved.

Clause 42 agreed.

Amendment 99

Moved by

99: After Clause 42, insert the following new Clause— “Cyber security competence: functions of the UK Cyber Security Council(1) The UK Cyber Security Council is to exercise the functions described in subsection (2) and is accountable to the Secretary of State for the exercise of those functions.(2) The functions are—(a) to validate and accredit professional qualifications, standards and titles for cyber security professionals employed by regulated persons,(b) to monitor the supply of, and demand for, qualified cyber security professionals across the sectors regulated under this Act and the NIS Regulations, and(c) to audit whether, and to what extent, regulated persons employ or have access to appropriately certified cyber security professionals.(3) For the purposes of this section, “regulated person” has the same meaning as in Chapter 3 (see section 30).(4) A regulatory authority (as defined in section 24) must have regard to the information and standards provided by the Council under this section when exercising its functions.(5) The Secretary of State must by regulations made by statutory instrument make further provision about the exercise of the Council’s functions under this section, including provision about its accountability for the exercise of the functions described in subsection (2).(6) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament.”Member’s explanatory statement This new clause would give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a “competence mandate” for the regime.

Baroness Northover (LD)My Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.

Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area. This amendment is seeking to move things forward. The proposed new clause would

“give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a ‘competence mandate’ for the regime”.

I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.

The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.

The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a “skilled person” in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.

Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.

Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct. Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.

Lord Clement-Jones (LD)My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.

I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.

Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?

Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.

I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.

Lord Vaizey of Didcot (Con)My Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.

I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.

The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.

Baroness Neville-Jones (Con)My Lords, I very much hope that the Government will accept the amendment in the name of the noble Baroness, Lady Northover. It strikes me as a practical and important contribution to the Bill.

In addition to the points that have already been made by noble colleagues, there is one more thought to be added: one of the weaknesses of the present marketplace in which these skills are operating is the cost and affordability of advice and help for SMEs on security issues. It is costly—security does not come cheap. Many of these small businesses that nevertheless provide sophisticated services are up against it when it comes to making an adequate profit to stay in business. Therefore, a source of guidance and help, of the kind that is being suggested by this structure, would make a real contribution to not only the viability of these small firms but the general security of cyber security services.

We should never forget that these SMEs feed into the bigger ones. Often, it is an outlying service being provided to a bigger provider that is the cause of a fault or of an essential service proving insecure. Helping SMEs in this way would not only make them more secure but make the market generally more secure. This is a very important and helpful amendment, which I hope the Government will accept.

Lord Markham (Con)My Lords, I thank the noble Baroness, Lady Northover, for bringing forward Amendment 99. Throughout our consideration of the Bill, I have returned several times to the distinction between cyber compliance and cyber capability, and this amendment goes directly to that issue. We can impose ever more duties on businesses, require ever more reports and give regulators even more powers but, ultimately, our cyber resilience depends on having enough people with the skills to prevent attacks, protect people from them and respond when they occur. That is why, like many other noble Lords, I support the principle behind the amendment.

16:15:00

Indeed, the previous Government supported the establishment and development of the UK Cyber Security Council precisely because we recognised the need to professionalise the cyber workforce, establish recognised standards and qualifications, and build the skills base we need.

However, I sound one note of cautionwe must not replace one form of box-ticking with another. A certificate can be good evidence of capability, but it is not the capability itself. There are highly experienced cyber professionals who may not hold a particular qualification. Ultimately, what matters is whether an organisation has the people, skills and necessary capability to protect its systems—not whether it can tick a box saying that somebody has the right certificate.

I support the noble Baroness’s objectives around professional standards, particularly monitoring the supply and demand for cyber skills. I am a little more cautious about giving the council an additional audit role that could overlap with the responsibilities of existing regulators. But there is a more fundamental question here for the Government. The Bill substantially increases both the number of organisations subject to cyber regulation and the duties placed on them. Have the Government assessed how many additional skilled cyber professionals will be required to deliver all this? If we create more cyber obligations without ensuring that we have people capable of delivering them, we will have increased compliance without necessarily increasing our resilience.

If the Government do not believe that the UK Cyber Security Council should have the role proposed by Amendment 99, perhaps the Minister can tell us who is responsible for assessing the capability gap and what the Government intend to do about it.

The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab): My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baroness’s amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.

I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UK’s accredited cyber professionals. It establishes pathways for cyber professionals—experienced and new entrants—to have an easier route into quality cyber roles.

We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the council’s independence, and that could affect its relationship with the sector.

That is a separate point from the importance of the need to professionalise the cyber sector and the Government’s strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.

Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Government’s TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and master’s students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.

On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UK’s cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.

Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government C yber A ction P lan . The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Bill’s powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSC’s cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.

To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baroness’s subsequent amendment, to discuss further support that we can provide to those SMEs.

We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.

Baroness Northover (LD)I thank the Minister for her thoughtful reply and I thank other noble Lords for their support here. Clearly, we are all seeking to move in the same direction. There is a challenge and risks here that are incredibly important. Whether this is the right way forward, we will have to see.

I am very grateful to those organisations that fed into our Select Committee, which led me to table this amendment. This is an area that we will need to return to before Report, to look carefully at whether the drivers that the Minister has mentioned are sufficient. But at this stage, I beg leave to withdraw the amendment.

Amendment 99 withdrawn.

Amendment 100

Moved by

100: After Clause 42, insert the following new Clause— “National cyber security support service for small and medium-sized enterprises (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a national cyber security support and incident response service for relevant small and medium-sized enterprises (SMEs), for the purpose of improving the security and resilience of their network and information systems.(2) The service established under this section must—(a) be free at the point of use, and(b) provide, in particular following a cyber incident affecting a relevant SME—(i) advice and technical assistance,(ii) incident response support, and(iii) guidance on recovery and remediation.(3) For the purposes of this section, a relevant SME is a small or medium-sized enterprise which is—(a) an operator of an essential service,(b) a relevant digital service provider,(c) a relevant managed service provider, or(d) a critical supplier,within the meaning of the NIS Regulations.(4) In establishing and operating the service the Secretary of State must have regard to comparable national cyber security support services operated in other jurisdictions.” Member's explanatory statement This new clause would require the Secretary of State to establish a national, free-at-the-point-of-use cyber security support and incident response service for relevant SMEs, modelled on comparable overseas services such as the small-business support provided by the Australian Cyber Security Centre.

Baroness Northover (LD)My Lords, this amendment again comes out of the evidence submitted to our National Resilience Select Committee.

It has been reported that many SMEs think that they are too small to be a target. However, as was reported at Second Reading, government research shows that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for many small businesses, a cyber incident can be existential and that roughly 60% of SMEs that fall victim to a cyber attack go out of business within six months.

In this amendment, I therefore seek to address the position of SMEs. Coming from the insurance sector, the Association of British Insurers feels that the Bill is narrow in scope and that

“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms”,

including their new Cyber Governance Code of Practice . It feels that, without stronger incentives, measurement and accountability, there is a risk that it will not deliver consistent improvements. That is obviously concerning a number of people.

There are warnings—we know this—that cyber risk is inherently systemic. Disruption is rarely confined to a single organisation or sector but is increasingly transmitted through supply chains. As I mentioned in the previous group, according to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risks presented by the wider supply chain, so how do we bring in greater protection in a way that, as the noble Baroness, Lady Neville-Jones, and the noble Lord, Lord Vaizey, have just mentioned, does not overwhelm SMEs?

This proposed new clause would require the Secretary of State to establish a national, free-at-point-of-use cyber security support incident response service for relevant SMEs, modelled on comparable overseas services, such as the small business support provided by the Australian Cyber Security Centre.

The ABI notes that the Bill rightly focuses on building resilience in our critical national infrastructure and that more must therefore be done to address the cyber resilience of SMEs. Not surprisingly, it is concerned about cyber insurance. It points out that the take-up of cyber insurance among UK SMEs is very low—somewhere between 10% and 40%—and argues that cyber insurance can help prevent and alleviate the impact of cyber attacks for SMEs. But, obviously, there is a cost to that. As cyber risks continue to grow, SMEs are typically more vulnerable and less well placed than larger businesses to respond to cyber threats due to overstretched resources, including IT and potential security and skills gaps.

We have to be careful to make sure that reporting is not too onerous for SMEs. It is suggested, for example, that maybe their reporting timelines should be not as short as those for bigger companies, and that there should be better clarification of what is an actual or suspected cyber incident, so that things which are not as significant do not, as it were, clog up the system. However, I think everybody agrees that we need to make sure that SMEs are better supported.

I welcome the fact that the Government have set up some support in this area. There is a cyber action toolkit, which was launched in March 2026 and includes a helpline, and a cyber adviser scheme, which offers a free 30-minute session. There is also a small business guide for response and recovery. But when you look at what they are suggesting, they are pushing companies towards the commercial market, so there is going to be a cost to that, and, down the line, towards fraud analysis and law enforcement. We know how challenging that is in so many areas, so it does not necessarily seem the most helpful or robust system.

The reason I mention the Australian cyber resilience service and have looked at what it does is that it goes further than we are now going, and I hope the Government will give thought to extending this in the way that the Australian system does. There is free, tailored, person-to-person support with two functions: helping small businesses assess and build resilience and helping them to recover after an incident, such as account compromise, phishing or ransomware, with case management and device remediation. It is much more supportive than what we currently have in the United Kingdom.

Clearly, much more needs to be done to ensure that SMEs are aware of the risks and do not simply wait until they have been hit, but also that they are actively assisted. That is important for them, but also for the wider economy, given how interlinked we all are. This is clearly an evolving area and I look forward to hearing what the Minister has to say about how we can move this forward, given how significant it is. I beg to move.

16:30:00

Lord Vaizey of Didcot (Con)My Lords, I rise early to support the amendment from the noble Baroness, Lady Northover, partly to spare the stress of the noble Lord, Lord Clement-Jones, and also because there is a Liberal Democrat amendment imminent in the Chamber, although we of course will be abstaining—our solidarity with the Liberal Democrats does not extend too far.

However, it does extend to this amendment, which ties in well with the noble Baroness’s earlier amendment concerning qualifications. I was fascinated to hear her referring to the Australian cyber service, which I had not heard about before. I would be fascinated to know more and it would be interesting to hear from the Minister what other lessons there may be for us to learn from similar jurisdictions around the globe. I suspect the Canadians, for example, some of our European partners and some of the south-east Asian nations, such as Singapore or South Korea, will probably have very advanced and sophisticated bureaucracies, if I can put it that way, or institutions looking at the cyber threat.

Again, I shall address, rather than the technical detail of the noble Baroness’s amendment, the spirit in which it is brought and why it fits so well with her earlier amendment. It is about injecting a sense of urgency into how we raise our game in cyber in terms of our economy. When she mentioned the cyber action toolkit, it took me back to the days when I was one of the Cyber Ministers in the coalition Government. My responsibility was towards small businesses, and we launched endless small business toolkits, mainly because we wanted to say that we had launched a small business toolkit. We certainly never put in place any mechanisms for auditing its impact or success, and I think the constant references to about 7% of SMEs now having cyber policies in place may point to my abject failure in that role, and perhaps that of some of my successors.

The more I have listened to this debate, the more it takes me back to my childhood, when we would get leaflets about a possible nuclear conflagration. I know that Ministers and the Government are now telling people to stockpile water and baked beans because of the impact of El Niño, but we know that a cyber attack on the UK would cripple our economy and essential public services, so it is akin, given the geopolitical situation, to a national emergency.

The noble Baroness mentioned the views of the Association of British Insurers. Again, that was part of the toolkit. The feeling was that professional services would drive small businesses towards becoming more skilled in assessing their cyber risks, that you could not get insurance, or indeed cyber insurance, unless you had clear policies to deal with cyber attacks. With professional services firms, you could not necessarily get legal liability insurance for a data breach, which is not necessarily going to cripple your business but will affect your customers and therefore leave you open to liability, unless you could demonstrate that you had proper processes in place to protect your data. There is a whole ecosystem, it seems to me, that needs to be brought to bear to support the uptake of cyber skills and cyber audits by small businesses: we cannot be complacent and assume that 7% is an acceptable figure and that it should be allowed to evolve.

To a certain extent, the noble Baroness’s amendment is about the after-effectsif you suffer a cyber attack then you should be able to call on skilled people, whom we hope will have achieved the kind of recognised qualifications that the noble Baroness talked about earlier. She compared them to doctors but, when I thought about the amendment, I thought more about plumbers and electricians and the technical qualifications that you need to have to do a technical and difficult job.

We also need to look at what happens before. How do we increase the number of small businesses that put in place policies that will protect them from cyber attacks? That involves using the private sector, insurance companies and professional services firms to push forward clear protocols to which small business should be expected to adhere in order to receive the cover that they need to carry on doing business.

Lord Londesborough (CB)My Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.

There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.

Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.

I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.

Lord Birt (CB)I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.

I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.

The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.

Lord Clement-Jones (LD)My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.

I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.

It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.

Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.

During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.

Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—

16:46:00

Sitting suspended for a Division in the House.

16:57:00

Lord Clement-Jones (LD)To continue, if the state is going to impose heavy, legally binding supply chain security duties on small businesses, backed by turnover-based fines, the state has a moral and strategic obligation to provide the operational tools needed to meet those standards. By establishing a free, Australian-style digital safety net under Amendment 100, we would turn the Bill from a purely punitive compliance exercise into a genuine co-operative national partnership for cyber resilience, and I urge the Minister to accept this vital common-sense amendment.

Viscount Camrose (Con)My Lords, I thank the noble Baroness, Lady Northover, for her amendment and, needless to say, I support the intention behind it. It is clearly right that, having placed several new duties on businesses and their vendors, the Government consider how to ensure that they are able to carry them out. This is particularly the case for SMEs, which are often far less resilient, less well-resourced and more vulnerable to cyber attacks than their larger counterparts. But, when thinking through this idea, I was trying to come up with some sort of framework to estimate the costs of such a provision, and I just could not arrive at a satisfactory estimate, except that they would be very considerable, particularly given the urgency, complexity and difficulty of incident response.

As I think the noble Lord, Lord Clement-Jones, and others mentioned, providing advice on a government website is cheap and useful, but providing urgent incident response is far from cheap. That begs the question: would it be funded by the companies benefiting from this directly or the taxpayer? I am not sure that either is wholly satisfactory. The actual costs of running such a programme will depend largely on how it would operate and the terms of service it would offer. I am very grateful to the noble Baroness, Lady Northover, for pointing to the Australian example; I confess that I was unaware of it before and would be interested to know what service it provides and to what level. It is incredibly hard to estimate how it will operate and what terms of service it will offer. The rate of cyber attacks is non-linear, the scale, nature and complexity of each attack will vary significantly and the number of staff needed or resources available for a response at any one time would necessarily be volatile and unpredictable.

17:00:00

I also worry that a free service provided in this way might be a disincentive for SMEs and other firms to protect themselves properly, so I am guided towards what I hope would be the same outcome, but with a slightly different entry point. As we have heard from a number of speakers throughout Second Reading and Committee, we need to look at measures to promote the cyber insurance market. Indeed, the noble Baroness is right to say that the uptake of cyber insurance by SMEs is far too low, but I feel that it would make more sense to try to raise the uptake of cyber insurance, particularly by SMEs. That would, I suggest, be far more efficient, sustainable and flexible in ensuring the resilience and protection of smaller businesses. We could, for instance, think about reducing the premium tax on cyber insurers in order to promote the growth of their services, or otherwise subsidise the uptake of cyber insurance for the companies that we want to see take it up.

The best protection against a cyber attack is the behaviour of firms and their staff, and the best way to drive safe behaviour is through insurance. The collective cost of insurance is certainly no greater than that of a national cyber response service, and that cost is absorbed by those who benefit the most directly. All that said, I look forward to the Minister’s response.

Baroness Lloyd of Effra (Lab)My Lords, I thank the noble Baroness for her amendment and for linking the issue of cyber security with wider questions on national resilience; she is absolutely right to situate it in that space. I also thank her for introducing the topic of the right amount of cyber security support for the SMEs regulated under the Bill; indeed, the discussion has led to SMEs that are not regulated under the Bill.

We know that SMEs require dedicated cyber security support. That is why there are a wide range of free tools, guidance and training to help SMEs implement cyber security measures. These resources are available to any business, not just those regulated under the regime. As the noble Lord, Lord Vaizey, mentioned, this includes the Cyber Action Toolkit, designed to scale nationally to empower millions of small organisations through tailored cyber security advice with NCSC-certified cyber advisers. A number of noble Lords referenced the importance of Cyber Essentials, as well as insurance and incident response. If an SME with a turnover of less than £20 million has Cyber Essentials, it also has cyber insurance cover of up to £25,000. That incentive is intended to link the process of getting Cyber Essentials with the benefits of insurance. Likewise, SMEs get cyber incident support 24/7 with Cyber Essentials.

The noble Lords, Lord Vaizey, Lord Londesborough and Lord Birt, talked about the “push”. We are indeed encouraging, perhaps not pushing, the private sector to engage its supply chain through the cyber pledge, which is for entities outside the regulated scope. That is one of the key elements of the cyber pledge. Likewise, under the GCAP, the Government’s cyber action plan, Cyber Essentials, or equivalent, are needed for government procurements using official data. These are the mechanisms by which we are encouraging large organisations to look at their supply chains—on the point that the noble Lord, Lord Clement-Jones, made about the interconnectedness of all our organisations today—and encouraging the uptake of Cyber Essentials with these very tangible benefits.

I was asked a very fair question about the best way to provide cyber support to organisations. I heard at least one noble Lord say that SMEs do not like different provision. I think that many SMEs prefer—or, if asked, would request—local trusted advisers, which is exactly what the regional cyber resilience centres offer. They offer free support to SMEs across England and Wales, covering a wide range of services, such as incident response, a business continuity service and support with Cyber Essentials and security training.

The noble Lord, Lord Londesborough, made a point about a central, monolithic model compared with these local or regional models. There is a lot of merit in a regional model that has some common standards but is located much nearer to the SMEs that it serves. I reiterate that small and micro-organisations are exempt from being regulated as relevant digital service providers or relevant managed service providers. They can be regulated only if they are operators of essential services or designated as a critical supplier, for which there is a high bar. On the picture raised by the noble Lord, Lord Clement-Jones, we do not think that a huge number of small enterprises will be in scope of this legislation. All small businesses will benefit from the current provision, but they would not necessarily benefit from the model proposed by the amendment.

The amendment would also require the Secretary of State to have regard to international regimes. We are indeed aware of such schemes, such as the Australian Small Business Cyber Resilience Service. Many of the offerings that that service provides, such as tailored support and practical incident recovery support, already exist in the UK, as I have set out. We learn from international best practice, but we also tailor it to our local economy and the threats we see, to best support and meet the needs of UK businesses and interact with UK regulations.

I hope that I have set out that guidance for small and medium-sized organisations is already available through existing UK support. We are doing more to look at supply chains through discussions with large firms, through the GCAP and through this Bill. We think that a new dedicated service could divert resources from these existing services and potentially impact on their efficacy. On the central point that the noble Baroness started with, we absolutely agree with the importance of providing support to small and medium-sized enterprises under the Bill, ensuring that they have everything they need to be resilient and respond to incidents.

Baroness Northover (LD)I thank the Minister, and I thank noble Lords for their support. This is clearly an area where we agree that there is a problem; we are very vulnerable in the United Kingdom. What we have in place is clearly not working sufficiently well if 60% of SMEs that are hit by cyber attacks go under. That is the context in which we ought to look at proposals that might seek to address that. We clearly need to take SMEs forward in a way that does not overburden them.

I hear the point about extending insurance cover. We can indeed take more than one track, but there is a cost to not supporting SMEs. If they are going to go under, that will be an economic cost to the country and, if we do not support them, they are likely to be hit by cyber attacks, taking them and others under anyway, with that effect upon our economy. Clearly, the Government agree—hence putting in place the measures that the Minister has outlined.

I am suggesting, from the evidence we have received, that this needs to go further and faster. We can discuss exactly how, but it is clear that this is an escalating problem and that we need to do more to tackle it. That is on the basis, in particular, of the concerns expressed to the National Resilience Committee on which I serve and which, as I say, gave me the idea of putting this amendment forward. I think that we will need to return to this, because it is a major problem, but, in the meantime, I beg leave to withdraw the amendment.

Amendment 100 withdrawn.

Amendments 101 to 105 not moved.

Clause 43Directions to regulated persons

Amendments 106 to 117 not moved.

Clause 43 agreed.

Clause 44Compliance with directions under section 43 to take priority

Amendments 118 to 126 not moved.

Clause 44 agreed.

Amendment 127 not moved.

Clause 45Monitoring by regulatory authorities

Amendments 128 and 129 not moved.

Clause 45 agreed.

Clause 46 agreed.

Clause 47Inspections

Amendments 130 to 139 not moved.

Clause 47 agreed.

Clause 48Notification of contravention

Amendments 140 and 141 not moved.

Clause 48 agreed.

Clause 49Penalty amounts

Amendments 142 to 147 not moved.

Clause 49 agreed.

Clauses 50 and 51 agreed.

Clause 52Enforcement of non-disclosure requirements

Amendment 148 not moved

Clause 52 agreed.

Amendment 148A

Moved by

148A: After Clause 52, insert the following new Clause— “Appeals against decisions under section 50(1) A person may appeal to the Upper Tribunal against—(a) a confirmation decision given to the person under section 50;(b) a decision under section 50 to require the person to pay a penalty;(c) the amount of a penalty which the person is required to pay under section 50.(2) An appeal under this section must be brought before the end of the period of 28 days beginning with the day on which notice of the decision appealed against was given to the person, or within such longer period as the Upper Tribunal may allow.(3) The Upper Tribunal must determine an appeal under this section on the merits and by reference to the matters before it, and not by applying the principles that would be applied by a court on an application for judicial review.(4) On an appeal under this section the Upper Tribunal may—(a) confirm, vary or cancel the decision appealed against,(b) substitute for that decision any decision that the Secretary of State could have made, or(c) remit the matter to the Secretary of State with such directions as the Upper Tribunal considers appropriate.(5) Where an appeal is brought under subsection (1)(b) or (c), the requirement to pay the penalty is suspended until the appeal is determined, withdrawn or abandoned.(6) Tribunal Procedure Rules must make provision, for the purposes of proceedings under this section, about—(a) securing that information is not disclosed where disclosure would be contrary to the interests of national security,(b) the holding of proceedings, or of parts of proceedings, in the absence of a party or a party’s legal representative, and(c) the appointment of a person to represent the interests of a party in proceedings, or parts of proceedings, from which that party and that party’s legal representative are excluded.(7) Nothing in this section affects any right to apply for judicial review.”Member’s explanatory statement This new clause would provide a right of appeal to the Upper Tribunal, on the merits, against a confirmation decision or a financial penalty imposed under section 50, with provision for the protection of national security material. It implements the recommendation of the Constitution Committee in its 3rd Report.

Lord Clement-Jones (LD)My Lords, Amendment 148A stands in my name on the Marshalled List. This amendment would address a profound, structural and deeply disturbing gap in the judicial oversight and democratic accountability of the Bill. It represents a direct implementation of the authoritative recommendation of the Select Committee on the Constitution, in its third report of this Session. Under Clause 50, the Secretary of State, acting as the direct enforcement authority for national security directions, is empowered to issue a unilateral confirmation decision that potentially imposes hugely significant financial penalties on non-compliant organisations. Under Clause 49, these penalties can reach a peak of up to £17 million or 10% of global turnover for commercial undertakings. Even for non-undertakings—such as our cash-strapped NHS trusts, local government authorities, or educational bodies—the penalty can be a crushing £17 million, with daily ongoing fines of up to £100,000 per day. Yet, under the Bill as currently drafted, the Government expect us to accept that the only avenue of legal recourse for an affected organisation to challenge these business-destroying fines is judicial review in the High Court.

17:15:00

The Government’s own Explanatory Notes lay this bare, stating in paragraph 314 that:

“A penalty decision may only be appealed by judicial review heard in the High Court”.

To deny a merits-based right of appeal against a £17 million penalty is a severe and indefensible departure from our constitutional principles and the basic tenets of natural justice. As the Constitution Committee firmly pointed out, judicial review is entirely inadequate for penalties of this magnitude. Judicial review, by its very nature, is restricted to examining matters of legality, rationality and procedural propriety. The High Court cannot stand in the shoes of the decision-maker. It cannot ask the fundamental question: “Did this business actually commit the breach?” It cannot ask: “Is the calculation of this penalty fair on the facts?” or, “Is a multi-million-pound fine truly proportionate to the actual national security risk presented?”

Under the current drafting, the Secretary of State acts as investigator, prosecutor, judge, jury and executioner. The executive branch determines that a breach has occurred, rejects the organisation’s representations, issues the confirmation decision and demands a £17 million payment—with the High Court legally barred from reviewing the actual merits of that determination. This constitutional danger is compounded by the extraordinary veil of secrecy being thrown over these proceedings. Under Clause 50, in subsections (9) and (10), the Secretary of State can legally impose a strict non-disclosure requirement, prohibiting an organisation from even disclosing the existence or contents of a confirmation decision. A breach of this gagging order carries its own eye-watering penalty of up to £10 million, or £50,000 per day, under Clause 52. We are therefore contemplating a terrifying scenario whereby a British business can be fined £17 million in complete statutory secrecy, under a shadow regulatory regime operating entirely in the dark, with absolutely no right to have the merits of that devastating decision reviewed by an independent court of law.

My Amendment 148A would resolve this unacceptable scenario by establishing a clear statutory right of appeal to the Upper Tribunal. Why have I chosen the Upper Tribunal? First, it is a senior court of record, equivalent in status to the High Court, possessing specialised technical and legal expertise. Secondly, and most crucially, the Upper Tribunal already possesses established, highly robust tribunal procedure rules that are specifically designed to handle closed-material proceedings, special advocates and classified national security material. This amendment explicitly provides, in proposed new subsection (6), that rules must be made to secure that sensitive information is protected and not disclosed contrary to the interests of national security, including holding hearings in the absence of a party when absolutely necessary. We do not need to compromise our national security to guarantee a fair trial. The judicial machinery to balance these two imperatives is already built, tested and fully operational.

Furthermore, this amendment would introduce a vital safeguard in proposed new subsection (5). It would mandate that, when an appeal is brought, the requirement to pay the multi-million-pound penalty is suspended until the independent tribunal has made its determination. Under the Government’s original punitive design, a business would be forced to pay a £17 million fine immediately while pursuing a restricted judicial review, which would bankrupt it before it even got a day in court.

We cannot allow a “compliance first, justice second” culture to take root. If we are to grant the Executive these sweeping, unprecedented powers, we must match them with equivalent modern and constitutionally sound safeguards. We must ensure that the citizen and the business are protected by a full, merits-based process, as recommended by our own Constitution Committee. I urge the Minister to accept this vital constitutional correction, and I beg to move.

Lord Vaizey of Didcot (Con)My Lords, in addressing the amendment in the name of the noble Lord, Lord Clement-Jones, I may increase his stress levels, unfortunately, as I oppose it. This means, I guess, that I am supporting the Government—that is, unless the Government are going to perform a volte-face in the face of the noble Lord’s strong arguments for a merits-based review of any decision reached by the First-tier Tribunal.

I do so because it brings back memories of when I was the telecommunications Minister and was, therefore, responsible for Ofcom. At the time, all Ofcom decisions were subject to a merits-based review in front of the Competition Appeal Tribunal, which meant that, in effect, every decision it took regarding broadcasters or telecoms companies was reheard at appeal. As noble Lords can imagine, technical decisions on the charges being levied by wholesale carriers—or, in the case of Sky, the charges being levied on other broadcasters to carry, for example, the Premier League—were extremely complex, and Ofcom faced an army of lawyers deployed by those companies.

Without wishing to give away too many confidences—this was 10 years ago, so I do not think it is a matter of national security—Ofcom found itself extremely frustrated by all this. It was costing millions and millions of pounds. It was being used by commercial providers as a delaying tactic, a firepower tactic, almost, in order, understandably, to put off decisions that were not in their commercial favour. I initially resisted Ofcom’s blandishments to say that we should move away from merits-based appeals, partly because I thought that we would just start a whole new process of the courts feeling their way under the new system and would end up with a whole new set of delays as the courts had to make novel decisions under a novel regime.

However—one of the great telecom chief executives, my noble friend Lady Harding, has just walked into the Committee right on cue; I do not think, though, that she ever used her firepower in the cynical way that others did against Ofcom—the changes did go through. As far as I am concerned, although I have not done my homework properly, things have settled down into a straightforward process whereby a regulator makes a decision based on the facts and, if that decision can somehow be seen as unlawful by the company in question, it can be judicially reviewed.

It must be stressed that removing merits-based appeals would not remove the right of appeal. It seems fairly obvious to me that, as in civil and criminal cases, decisions would be arrived at based on the facts. However, if that decision were somehow so outside the normal judicial process of making a decision and so irrational, as it were—which is what judicial review exists to review—then it could be reviewed. That system should be consistent across regulatory appeals. I cannot necessarily comment on the effective points made by the noble Lord, Lord Clement-Jones, about the clandestine nature of some of the findings, but it may well be that, given the issues to do with cyber security, attacks on critical national infrastructure and so on, some elements of cases must be kept confidential. That is a matter for further debate, perhaps, but I would be extremely concerned if we were to go back to merits-based reviews for regulatory appeals.

Lord Markham (Con)My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this important group and all noble Lords for their contributions. Beginning with Amendment 148A, it is reasonable to suggest that there should be a further right to appeal, given that we are talking about potentially large penalties of £17 million or 10% of annual turnover. But, like my noble friend Lord Vaizey, I have concerns about whether the Upper Tribunal system can handle such a process. Right now, it has an open case load of over 800,000, which is a 19% year-on-year increase, and disposals have decreased by 4%. As such, I am hesitant to offer my support without being assured that further pressure will not be placed on tribunals and that this is a workable mechanism.

Amendments 174A and 174B, in my name and those of my noble friends Lord Camrose and Lord Holmes of Richmond, would require the Secretary of State to establish a register of foreign powers posing a cyber security risk to this country, and to review and report on the extent of the risk posed by powers on that list. Part 4 gives the Secretary of State significant new powers to intervene where the use of vendors’ goods and services or facilities pose a risk to national security. We support that objective. A power of that kind is only as good as the intelligence that informs it. At present, the Bill is silent on how the Secretary of State is to identify, in a systematic and transparent way, which foreign powers actually present that risk. Amendment 174A aims to fill that information gap, outlining a thorough set of criteria for inclusion: a state confirmed by GCHQ to have perpetrated or attempted a cyber attack against the UK in the preceding seven years—one directed at an operator of an essential service or a critical supplier and carried out through a state department, agency or affiliate—or a state that GCHQ has separately warned poses a risk to such systems.

The importance of ensuring that we are fully informed of foreign threats can hardly be overstated. Just this year, the NCSC’s chief executive reported that three-quarters of all attacks on our critical national infrastructure over the preceding 12 months were carried out by hostile states, with Russia, China and Iran named specifically. The NCSC’s annual review recorded 204 nationally significant incidents in the year to August 2025—more than double the previous year, with 18 rated highly significant.

For illustration, the cyber attack that last month shut down a British power plant is reported to have been committed by Iran-backed hackers. Over the course of the last Parliament and this one, China has targeted Parliament and compromised the Electoral Commission; Russia’s FSB has targeted British parliamentarians and successfully stolen and leaked politically sensitive documents; and Iranian state actors have targeted British politicians, Governments and defence with sustained cyber espionage campaigns.

We are seeing a surge in cyber attacks driven largely by foreign threats. If the Government are serious about security and resilience, tackling foreign interference must be a priority. As a start, a published criteria-based register would bring much-needed transparency and rigour to the process. Amendment 174B seeks to achieve such transparency. It would require the Secretary of State, for each foreign power added to the register, to conduct a review of the extent and nature of the risk that that power poses. It also includes a built-in safeguard for the Government: where the Secretary of State considers that laying their report would be contrary to national security interests, they may instead make a Statement to Parliament confirming that the review has taken place and explaining that it cannot be published. It attempts to strike a balance between accountability and the sensitivities that intelligence assessment of this kind will naturally carry.

I anticipate that the Minister may say that such a register already exists in substance within government and that formalising and publishing it risks informing those very powers of the extent of our knowledge. I gently observe that the amendment does not require publication of intelligence sources, substance or methods—only the fact of designation against published criteria and a review to assess the risk. Given the scale of the threat that the NCSC describes and, given the very significant powers that this part confers on the Secretary of State, I believe that Parliament is entitled to ask that those powers rest on a clear, evidenced and reviewable basis. I look forward to the Minister’s response.

Baroness Lloyd of Effra (Lab)I thank noble Lords for their amendments, starting with Amendment 148A, from the noble Lord, Lord Clement-Jones, which indeed is in line with the recommendation from the Constitution Committee, which I thank for its report and its detailed scrutiny of this legislation.

As the noble Lord points out, Part 4 enables the Secretary of State to issue penalties for regulated entities that do not comply with directions. The High Court will have jurisdiction to review the lawfulness of a particular penalty issued under Part 4. The noble Lord, Lord Vaizey, referred to precedent and consistency. Our assessment is that the High Court is the appropriate route for hearing sensitive national security cases, consistent with the approach that previous Governments have taken to national security legislation. The Telecommunications (Security) Act, the National Security and Investment Act, and the Procurement Act, key pieces of national security legislation, all follow this approach. That is the reason we have adopted it here.

To the point around parliamentary scrutiny of directions, the Government’s default position is that copies of directions will be laid in Parliament, to enable all parliamentarians to scrutinise the Government’s use of these powers. I am of course preparing a formal response to the Constitution Committee, which will be sent in due course.

17:31:00

Sitting suspended for a Division in the House.

17:42:00

Baroness Lloyd of Effra (Lab)I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.

The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.

Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.

That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.

I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.

Lord Clement-Jones (LD)I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.

However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.

Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.

Amendment 148A withdrawn.

Clause 53 agreed.

Clause 54Review, variation and revocation of directions

Amendments 149 and 150 not moved.

Clause 54 agreed.

Amendments 151 and 152 not moved.

The Deputy Chairman of Committees (Baroness Scott of Needham Market) (LD)I cannot call Amendment 153 as it is an amendment to Amendment 152. Clause 55: Laying before Parliament

Amendment 154 not moved.

Clause 55 agreed.

Clauses 56 and 57 agreed.

Clause 58Interpretation of Part 4

Amendments 155 to 163 not moved.

Clause 58 agreed.

Amendment 164

Moved by

164: After Clause 58, insert the following new Clause— “Computer Misuse Act 1990: statutory defence for cyber security activities(1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.(2) The review under subsection (1) must consider, in particular—(a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith,(b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and(c) the approaches taken in other jurisdictions.(3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out—(a) the findings and conclusions of the review, and(b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”Member’s explanatory statement This new clause seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence under section 1 of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.

Lord Clement-Jones (LD)My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act.

This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them.

The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator.

I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation.

Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act.

During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege.

There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems.

Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security.

Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate £2.5 billion in additional revenue for the UK economy.

We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can?

When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.

Lord Vaizey of Didcot (Con)My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.

The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.

18:00:00

We all know what the Minister is going to tell usthat this is the wrong Bill for such an amendment and that there is a Home Office review. I hope that we will hold her to account for a date and timeline for when this review might come out, and some semblance of co-ordination between government bodies on all the legislation and regulations that need to be brought together and updated to provide us with a framework that supports the work that needs to be done to protect our digital infrastructure, as well as an explanation of why there has been such a delay from the Home Office on such an urgent piece of legislation.

Baroness Neville-Jones (Con)My Lords, the campaign to reform the Computer Misuse Act is at least 10 years old, not just five. We—including me—have been working to try to get the provision that is contained in the amendment before us from the noble Lord, Lord Clement-Jones. I endorse every single word that he said; he put the case precisely as it needed to be set out. It is absolutely anomalous that we still have this legislation on the statute book, and we need an update to it.

We need to put our researchers, and those who help to protect us and keep us safe, in a safe position themselves, which they are not at the moment. They are subject to potential criminal prosecution, which is stupid and a great disincentive to doing what needs to be done. I very much hope that the Minister will be persuaded to take this opportunity—not to reject it—to put a clause, even if it needs modification to a form that the Government approve of, in this legislation.

Baroness Harding of Winscombe (Con)My Lords, I will speak briefly in support of the amendment from the noble Lord, Lord Clement-Jones, which he so comprehensively set out. I did not mention this at Second Reading because I thought it was so self-evidently sensible that this needed to be fixed. I should know better, having been in this place for a decade, than to assume that something will happen just because it is self-evidently sensible.

The last three days in Committee have been rather depressing—my noble friend Lord Vaizey is lucky he was not here last week, although he managed to give an excellent speech that suggested he had at least been following us in Hansard or on TV—because it has been so clear that the most important issues are not being addressed in the Bill. This seems like something simple to fix. There are much bigger issues, such as the complete gaping hole of the absence of AI and the huge complexity of all the different regimes that the noble Lord, Lord Birt, set out. I am of the view that you cannot wait for the perfect, and there is a real risk that we are letting perfect be the enemy of the good. This is a straightforward and sensible proposal that I think the Government previously agreed with, but it was just not the right time. Surely, now is the time for us to do things rather than keep kicking the can down the road.

Lord Tarassenko (CB)My Lords, one of the advantages of being in this Committee Room for these debates in Committee is that I can use Claude—I hope that is allowed—to answer the question of what the cyber security community thinks about the Computer Misuse Act. The answer comes back in bold. I will read just the paragraph in bold: “The UK cyber security community’s view is that the Computer Misuse Act 1990 is dangerously out of date and reform efforts so far do not go far enough”. I rest my case.

Viscount Camrose (Con)My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems. Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.

The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.

I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.

Baroness Lloyd of Effra (Lab)I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

Lord Clement-Jones (LD)I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.

I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.

I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.

Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.

Amendment 164 withdrawn.

Amendments 165 to 174D not moved.

Amendment 174E

Moved by

174E: After Clause 58, insert the following new Clause— “Increasing resilience by reducing data retention(1) The Secretary of State must, within one month of the day on which this Act is passed, open a consultation on the potential impact of minimising data collection and increasing data anonymisation on the resilience to cyber attack of relevant public bodies. (2) In this section, “relevant public bodies” are public bodies that are operators of essential services or digital service providers under the NIS Regulations or this Act.”

Lord Markham (Con)Amendment 174E in my name and those of my noble friends Lord Camrose and Lord Holmes builds on the point I made in the debate last Thursday that the best defence in cyber is, of course, not to present an attractive target in the first place.

I go back to my experience of the Synnovis hack when I was Health Minister. The reality was that it did not need to hold any of the detail or data that it had in the first place. When you are doing a diagnostic test of someone, you do not need to know their name; there can be a serial number that can be matched up later. Not only did Synnovis have names, it had whole medical records going back years and years, and there was no deletion policy either. The whole reason that it was an attractive target was its very sloppy standards in the data it held and its retention policy.

18:15:00

I must admit that, when I challenged the NHS on that, there really was not much appetite to address it at all. It probably would say that it was meeting all the GDPR requirements and that people consented to their data being shared—I am sure that absolutely was the case. But when you are presented with a diagnostic test that says you consent to your data being shared, you think it is being shared for a good reason; the reality there was that it did not need to be shared at all. The real-life consequence of all that was that it made Synnovis a target for an attack—the data did not need to be there—and that thousands upon thousands of operations had to be cancelled, as the NHS in London had to go back to a paper-and-pen-based system. It had real-life consequences.

What I am suggesting here is a very modest amendment. I have put that attack on the radar as just one example; I am sure we could all come up with a lot more public service examples. To be honest, as I say, my experience at the time was that, unfortunately, the NHS had very little interest in trying to tackle this issue.

The amendment proposes a requirement for the Secretary of State to consult on achieving the minimisation of identifiable data, while looking at deletion and at what needs to be kept. It is seen as constructive. Again, if there are other suggestions, I am happy to talk about the best ways of going about this, but I very much hope that all noble Lords will see that it is a sensible and pragmatic approach to try to deal with a problem. It would remove a lot of the juicy targets—for want of better words—from a potential attack vector in the first place. I beg to move.

Lord Clement-Jones (LD)My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface. The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?

The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.

Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.

Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.

Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.

While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.

Baroness Lloyd of Effra (Lab)I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security.

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on. I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Viscount Camrose (Con)In the spirit of her final remarks on the Bill overall, is the Minister able to give any update as to when the national cyber action plan might emerge?

Baroness Lloyd of Effra (Lab)I have nothing further to add what I have said in previous sittings.

Lord Markham (Con)Nice try. I will get the final word then. First, I thank the noble Lord, Lord Clement-Jones, for his strong support. Honey pot is a very descriptive and apt term for it. I thank the Minister for her comments and will definitely take up her offer of a meeting. I must admit that the responses she gave were almost exactly the responses that the NHS gave to me on all this, so she is absolutely right: everything is being kept under GDPR. Data security and how that is held were mentioned quite a few times, but I did not hear anything about data minimisation and why we are collecting or keeping it in the first place. That is a gap in all of this because, as I said, a lot of this data does not need to be held or gathered in that way. It is just basic discipline. I would very much like to take up that offer on how we can do that, because—perhaps the Minister can look at this ahead of our meeting—I do not think this issue is addressed anywhere in the Bill.

I do get the last word. I thank everyone who has taken part in this. There have been a number of important issues raised. I really appreciate the willingness of the Minister to engage, and I know there are a number of follow-up meetings that I think we will all want, because there is a lot that we need to work on between now and Report to make sure that the Bill really gives us the sort of protection we would all hope to have. I beg leave to withdraw my amendment.

Amendment 174E withdrawn.

Clause 59 agreed.

Clause 60Commencement

Amendment 175 not moved.

Clause 60 agreed.

Clause 61 agreed.

Bill reported with amendments.

Committee adjourned at 6.28 pm.