Contribution
I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.
In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.
However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.
The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.
On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.
On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.
Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,
“balancing, flexibility, security or stability of the electricity system”.
The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.
Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.