L

Lord Birt (CB)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships. The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now. Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change. Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope. There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success. We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions. My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it. Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope. Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question. The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States. Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better. We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require. Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope. The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.

More from Lord Birt (CB)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.