L

Lord Holmes of Richmond (Con)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, it is a pleasure to speak to this group of amendments; I was certainly delighted to sign those in the name of the noble Lord, Lord Birt. Before turning to the specific subject matter, I say that the point he raised about JLR is germane to our broader discussions this afternoon and goes to the heart of the sense of coherence, or lack thereof, in certain key elements of the Bill. JLR suffered a serious cyber attack yet it currently would not fall within one of the sectors covered by the Bill. Was that attack significant at a level that should be of concern to the Bill? To look at its economic impact—the definition of which my noble friend Lord Camrose has identified as being somewhat broad, to paraphrase what he said—the JLR attack impacted that quarter’s GDP numbers, thus raising the eyebrows of the markets, the ratings agencies and all international economic observers. I would suggest that the impact was more than material and certainly significant, yet it would fall outside the sectors in the Bill as currently drafted. That goes to the point at the heart of the need for an OCR or an entity that would perform that function or role. Much of the discussion so far on this group is understandably echoic of the discussion we are having around the need for AI to be taken on by some regulator. As we are discussing the need for AI regulation and legislation, it seems only fair for me to give a nod to the AI authority in my AI regulation Private Member’s Bill—it comes with music every time I announce it, this time from a phone going off; that is multimedia. The reality is, if the choice of the Government, be it for AI or for cyber, is not to have a single centralised regulator, then the consequences are clear and profound. In no sense is there any chance of clarity, consistency and coherence for businesses and sectors right across our economy and society. When you come to cyber, you should not have to consider whether it is or is not in a sector within the Bill. Is that specific regulator in that sector tooled up or do they have any experience, knowledge or ability to lead when it comes to all the challenges of cyber? Let us take one obvious example, just for the case of efficiency, effectiveness and economic good management. Say that there is a search out, a recruitment, for a particular cyber professional and it turns out that Ofgem and the FCA are both in the final throes of getting that person. The FCA ends up getting that cyber professional; that is good for the FCA and good for financial services, but less good for Ofgem. How is that in any sense good for the broader economy and society, the UK as a whole, when it comes to protection from and an effective coherent approach to the cyber risks and how we guard against them? The case for a unifying regulator when it comes to cyber is equal to that for AI. It would enable clarity, consistency and coherence of approach and would be that centre of expertise. There would be horizontal impact across all sectors and it would be delivered effectively and efficiently. That cannot simply be the case just for individual regulators; no matter how well intended or up for it they may be, they simply could not deliver that. Even if one sector did, another sector would not, which would mean that, just by dint of where your business or you as an individual happen to come across a cyber challenge, it would be the luck of the draw as to whichever regulator or professionals were in that field. The case for an individual, central, clear and coherent cyber regulator is clear. I hope that the Minister agrees and I look forward to her response.

More from Lord Holmes of Richmond (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.