Contribution
My Lords, while the Government Benches may criticise the role of successive Governments in preventing cyberattacks, we must not lose sight of where the true blame lies. The primary responsibility for this deeply troubling incident rests with the malicious individuals who orchestrated it.
This was not merely a digital intrusion; it was a direct assault on some of the most vulnerable members of our society. The data accessed is, in many cases, highly sensitive—it includes medical and other personal records—and the scale and nature of the information compromised over a period, apparently, from 2010, may mark this as one of the more serious data breaches that the Government have suffered in recent years.
Given the gravity of the situation, will the Minister confirm how many individuals have been affected? How are the Government supporting the individuals whose data has been exposed? Is he able to confirm the possible motive and identity of the attackers? Has there, for example, been any form of ransom demand from those who perpetrated this act? We welcome the involvement of the National Crime Agency and the National Cyber Security Centre. Their expertise will be essential. Clearly, it is imperative that those responsible for this breach are held to account and brought to justice.
Significant concerns remain regarding the Government’s handling of this matter. I therefore seek clarity from the Minister on a number of issues. Why were Parliament and the public not informed immediately when the breach was discovered on 23 April? We now understand that the data access may include information dating back to 2010, as I said before, and that over 2 million records may have been compromised. The delay of almost a month before this was made public may have prevented individuals taking timely steps to protect themselves from potential risks. Was there a failure to properly appreciate the seriousness of this breach?
Further, can the Minister update the House on the status of the operational systems that are vital for processing legal aid and payments to legal professionals? If these systems are not fully restored, how can we expect to return to full functionality? It may seem odd to talk about payment of legal aid to lawyers but, of course, those working in the fields of criminal law and family law, which are severely underfunded in many respects, will find the cash flow from the legal fund vital to their continuing activities. It is therefore important that that issue should also be addressed.
We heard in the other place that the Government believe that the incident has been contained. How did the Government arrive at that conclusion, and could the Minister explain to the House what is meant by “contained”? Will he confirm whether the Ministry of Justice has conducted or intends to conduct a comprehensive risk assessment of its wider digital infrastructure? Will similar assessments be made in other departments to safeguard against future vulnerabilities?
I also ask the Minister to ensure that Parliament receives regular and transparent updates as the investigation progresses. It is critical that we and members of the public should be informed clearly and promptly about the consequences of this breach and how it is being addressed. The breach itself represents a significant failure in the protection of our justice system’s digital infrastructure. That is liable to undermine public trust and raises serious concerns about data security and transparency, so I ask the Government to respond with urgency and openness to this issue.
Finally, I will raise a question about the devolved Administrations. For example, Scotland has its own legal aid structure, as, I believe, Northern Ireland does also, but those structures in turn depend on data from the United Kingdom—for example, access to social security data. Have they been impacted by this event? If so, what liaison has there been with the devolved Administrations to try to minimise the difficulties that they may have been caused by this data breach? I am obliged.