Dame Chi Onwurah

Dame Chi Onwurah

Labour — Newcastle upon Tyne Central and West

Speaking in the House of Commons on 16 June 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

It is a pleasure to follow the hon. Member for Harpenden and Berkhamsted (Victoria Collins). I would like to start by making two relevant declarations of interest. I worked for the Office of Communications before entering Parliament and I am currently a fellow of the Institution of Engineering and Technology. Madam Deputy Speaker, you might have heard me mention on occasion that I was an engineer before coming into Parliament. As such, in 2010, I was desperate for issues around technology to come up in Parliament, as it was a subject I actually knew something about, but they rarely did. In the intervening 16 years, however, things have changed, and technology issues such as online safety, wi-fi on trains, sovereign technology and infowars are now raised regularly. I welcome the increasing role of technology in all our constituents’ lives, but this must go hand in hand with rigorous cyber-security to protect against threats from state and non-state actors. As I highlighted in my speech on Second Reading, the UK’s only cross-cutting cyber-security legislation is currently that inherited from the European Union. The previous Conservative Government failed to update these regulations, leaving us working under an outdated framework. I therefore really welcome this Bill, which seeks to expand the scope of existing cyber-security regulations to new sectors, strengthen the role of regulators and grant the Government new powers to respond to the threats posed by cyber-security breaches. We are only as secure as our weakest link, but I am afraid we still have a number of weak links left. Cyber-attacks are having a real financial impact on the UK and are happening at an increasing rate. According to the Institution of Engineering and Technology, cyber-attacks cost UK businesses an estimated £64 billion annually, with £37 billion in direct costs and £26 billion in indirect costs. Last year we also saw the well-documented cyber-attack that hit Marks & Spencer, leaving shoppers unable to buy online from the company for months. The company’s profits were almost wiped out, down from £390 million to £3 million for the first half of 2025. As a Sparks card holder myself, I was unable to use my card for six months and I fear I may have contributed to those figures. This brings me to my first amendment, new clause 20, which seeks to designate retail businesses as an essential activity, bringing them within scope of part 3 of the Bill. Retail is the UK’s largest private sector employer. It holds large amounts of consumer data but often relies on dated IT systems. Yet, as I noted on Second Reading, the existing scope of the Bill would not have prevented or even had an impact on the attacks on Marks & Spencer or Jaguar Land Rover, despite the significant disruption they caused to our constituents and our economic activity. Indeed, in November, the Bank of England cited the cyber-attack on JLR as a factor in its decision to hold interest rates. The Government’s plan to promote the new cyber governance code of practice to improve pre-operative preparedness in sectors such as retail is welcome, but voluntary measures alone will not deliver the consistent adoption of good cyber governance across economically significant sectors such as retail. According to the Government’s figures, only 9,680 Cyber Essentials Plus certificates were issued to small and medium-sized businesses between November 2023 and October 2024. There are an estimated 6 million small and medium-sized enterprises in the UK, so this is not going to address that challenge at the rate at which it needs to be addressed. I welcome the Opposition amendments that would bring retail businesses within the Bill’s scope, but I am concerned that they might be too extensive in bringing small and medium-sized businesses into its remit and placing a disproportionate burden on them. The revenue threshold of £12 billion in my new clause 20 provides the necessary specificity to ensure that only large retail businesses, including Marks & Spencer and Jaguar Land Rover, would fall under the expanded Network and Information Systems Regulations 2018. This would lead to faster incident-reporting responses and customer notification, alongside stronger powers, including those to deal with non-compliance. Turning to my new clause 18, we have already heard that the concentration of the UK’s public sector data within a small number of US-owned providers—Amazon Web Services and Microsoft Azure specifically—presents a structural risk to national resilience. Combined, AWS and Microsoft account for 70% to 80% of the public cloud market, according to the Competition and Markets Authority. Part of the issue is that that figure is an estimate. I have put down a series of written parliamentary questions over the last seven years to find out just how dependent the Government are on AWS and Microsoft. This data is not tracked across Government. Can the Minister say how he intends to assess a threat that the Government are not measuring? As set out in my Committee’s report entitled “Rewiring the state: Delivering digital government”, our national resilience is put at risk by the strategic lock-in that these companies have in many of our public services and Administrations. Major Departments, including His Majesty’s Revenue and Customs and the NHS, are under multi-year agreements that further entrench these cloud infrastructures within the Whitehall ecosystem. Included in my Committee’s report was evidence we heard from the Open Cloud Coalition, who suggested that the Department for Science, Innovation and Technology should consider a period of over-correction, including the mandatory re-competition of high-risk or large-scale contracts, to break cycles of vendor lock-in. The Government are rightly seeking to co-ordinate cloud contracting, but I believe that this should be done in a way that would ensure more, not less, competition. We would like to see the detail of how the all-of-Government cloud contract will prevent vendor lock-in, and I would like the Minister to outline his engagement with the CMA on the contract’s development. Not only does our reliance on these two cloud services raise practical issues—as seen with the AWS outage in October—but there are questions around data protection. Under the Clarifying Lawful Overseas Use of Data Act and the Patriot Act, the US Government can compel US companies, including AWS and Microsoft, to hand over data if held overseas—that is, in the UK. I am aware that the Minister might reference our sovereign hosting capability, Crown Hosting, but it hosts only 4% of Government legacy services. Will he please outline how the Government intend to ensure protection so that the public sector makes better use of the services provided by Crown Hosting? Could he also set out how he will ensure that the Government’s digital transformation ambitions cannot be derailed at any time by decisions based on the narrow interests of a foreign, commercial or state actor? He might choose to argue that this is highly unlikely, but I would point him to the recent decision of the US Government to withdraw foreign nationals’ access to Anthropic’s Fable 5 model. Finally, my new clause 19 calls on the Secretary of State to conduct a review into the risks posed by foreign state ownership or control of providers of cellular internet-of-things modules. I always like to mention that I was the first Member of Parliament to speak about the internet of things, in my debate back in 2011. Having worked in technology as an engineer, the threat posed by cyber-attacks on the internet of things was very real to me from the start of my parliamentary career. Indeed, in 2017 I wrote an article highlighting the threat of cyber-attacks on sex toys, in a vain attempt to raise the profile of the issue.

More from Dame Chi Onwurah

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.

For Dame Chi Onwurah's full parliamentary record including voting history, expenses and all other contributions, see the Dame Chi Onwurah report card.

Partner sites