B

Baroness Ludford (LD)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I apologise for not having been much around earlier, but I am also involved in the Hillsborough Bill in the Chamber. Amendment 10 stands in my name and that of my noble friend Lord Clement-Jones. It would insert just five words into Regulation 12 of the 2018 regulations so that the risks which a relevant digital service provider must identify and manage explicitly include risks arising from fraud. The amendment might create no new duty if the duty is already encompassed in Clause 8, but it settles a question that the Bill currently leaves open. When an online marketplace, search engine or cloud provider—or a software or digital platform, under Amendment 7 from the noble Lord, Lord Birt—sits down with its regulator and asks which risks it is expected to manage, is fraud definitely on the list? At present, nobody can say so with confidence, and the answer matters a great deal because of who Clause 8 applies to. Relevant digital service providers are online marketplaces, search engines, cloud computing services and, possibly, digital and software platforms. These are not incidental to fraud in this country. They are increasingly where it begins. We can see the impact of a lack of action to secure online and cyber spaces. Fraud makes up 44% of all UK crime, and online technologies, especially artificial intelligence, are supercharging that, with a big increase in online-generated fraud and scams. Research by Lloyds Bank found that Meta’s social media sites are a starting point for 76%—three-quarters—of purchase scams in the UK, with the value of losses to UK customers estimated at £66 million in the last year alone. The Government’s fraud strategy does not really focus on the role of social media giants and big tech in the proliferation of online scams, and now the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is very striking when we consider that the Government’s official statistics on cyber security breaches show that phishing attacks—scams—remain by far the most prevalent type of breach or attack in the UK. The evidence of the impact of fraudulent online activity is not contested and is a huge concern for consumers. UK Finance’s annual fraud report, published in June, records that criminals stole nearly £1.3 billion through payment fraud in 2025, a rise of 4% on the previous year and the second consecutive year of growth. There were more than 4 million confirmed cases in 2025: that is eight people defrauded every minute. Authorised push payment losses rose 19% to £576 million, and around two-thirds of that fraud originated online. Investment fraud was up by 40%. UK Finance describes fraud as a “national security threat” and I think it is right. The Government’s cyber security breaches survey published in April found phishing to be by far the most prevalent form of breach or attack, experienced by almost four in 10 businesses and rated the most disruptive by seven in 10 of those affected. Among businesses breached, more than half experienced only phishing. Fraud is not parallel to the cyber security threat. For most organisations, fraud is the cyber threat picture. I anticipate the Minister will tell me that fraud is handled elsewhere: in the Online Safety Act, the reimbursement rules and the fraud strategy. However, I make two points. First, none of those regimes places a security and resilience duty on cloud providers or marketplaces in respect of the systems on which essential activities depend. Secondly, a regulatory architecture in which every regulator assumes that fraud is everybody else’s business is precisely how a gap of this size opens up in the first place. This amendment was raised in the other place by my honourable friend Victoria Collins MP. The ministerial answer was, in essence, that the words were unnecessary. I would rather have them explicitly in the Bill rather than rely on inference. If the Minister cannot accept the amendment, I ask for two assurances: that the guidance the Information Commissioner must issue under paragraph (4)(a) of Regulation 3 will address fraud risk explicitly, and that the statement of strategic priorities under Clause 25 will name fraud among the risks to which regulators must have regard. I shall turn to just one other theme in this group; my noble friend Lord Clement-Jones will sweep up at the end in his winding-up speech. I wish to speak to Amendment 15 on workforce competence and skills, as well as on the issues raised in Amendments 174C and 174D, which also refer to cyber security capability. We are all concerned about the shortage of cyber skills and competencies in the workforce, but one place where that has to start is with young people in schools and colleges. I sought to table an amendment calling for the Government to publish a strategy on improving the cyber security awareness and resilience of children and young people through education. Sadly, the PBO ruled it out of scope, but I hope that we might have that issue in mind. If we are going to get the increase in workforce skills and competence on cyber security that we vitally need, we need also to have an eye on developing those skills in our young people, who spend so much of their lives online. I beg to move.

More from Baroness Ludford (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.