Contribution
My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.
That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.
However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.
Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.
I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.
I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.
Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.