M

Member

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

I should declare at this stage that I chair, sit on the board of and advise a number of start-ups and scale-ups, with staff numbers ranging from 20 to 100. Let me briefly describe the cocktail of cyber risks to which they are exposed. They all have their customer and prospect databases, CRMs, that sit on third-party software platforms, often requiring bespoke programming to fit the needs of each company. These platforms are typically interfaced with other applications and databases—one for marketing, one for sales, one for finance and accounts, one for HR and payroll, and, often, complicated ones for content, production or product. The point I am making is that, even for companies with fewer than 50 staff, there can be a complex web of interdependencies that may involve as many as five to 10 different software or digital service providers. Their networks are therefore very vulnerable to hackers, who have a number of entry points to exploit.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.