L

Lord Clement-Jones (LD)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well. Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described. As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons. We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe. Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale. Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance. Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support. In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans. We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

More from Lord Clement-Jones (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.