B

Baroness Lloyd of Effra (Lab)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator. As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors. I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime. Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure. Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach. On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure. I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

More from Baroness Lloyd of Effra (Lab)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.