B

Baroness Lloyd of Effra (Lab)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

I thank noble Lords for their amendments in this group, which I will endeavour to cover in my response, starting with the lead amendment from the noble Baroness, Lady Ludford. Fraud risks and fraud are indeed important to address. The Bill requires relevant digital service providers to prevent or mitigate risks through an all-hazards approach. We already expect RDSPs to address risks posed by fraud as part of their security duties. The reason why we do not single out risk posed by fraud is that this may not reflect the full range of risks faced. It is important that regulators in their guidance, for example, in respect of the ICO, respond to the risks that their sectors are experiencing, which could include fraud. I heard clearly the facts that the noble Baroness set out, but that will be something that will come in due course. On the important points made by the noble Lord, Lord Ravensdale, on the risks posed by quantum computing, the “all hazards, all threats, all technologies” approach enables a flexible and future-proof regime. It is important that each version of the statement of strategic priorities is not bound by the risks posed by specific technologies because they could become outdated; it cannot necessarily prefigure what will be a particular risk in 10 years’ time. Post-quantum cryptography is incredibly important. The department is working on guidance documents that will support organisations to manage their transition, in line with the NCSC guidance and deadlines. On the question specifically about the next statement of strategic priorities, we will encourage regulators through the statement to understand the evolving threat landscape and adapt their regulatory response accordingly, which could include risks from quantum or fraud, if those are the most pressing ones at that time. On the approach suggested in Amendment 94 by the noble Lord, Lord Clement-Jones, we appreciate good practice standards, and we continue to promote their adoption across the wider economy. However, a more advanced cyber security framework is required to ensure adequate protection and assurance for the services in scope of the Bill. I am confident that the Bill’s outcomes-based approach is the right one. It allows existing good practice to contribute to demonstrations of compliance with existing and future requirements. We will introduce security and resilience requirements in secondary legislation. These requirements will be linked to the security duties and will provide clearer outcomes that organisations in scope must meet. We are engaging with regulators and industry throughout this development, and we intend to consult on these proposals later this year. I turn to the question of how regulated entities demonstrate their compliance with their duties. Amendment 92B seeks to require large businesses in scope to report on their cyber security and resilience plans. Our proposed security and resilience requirements under the Bill will require regulated entities to maintain overarching security policies, implement a continuous risk management framework, maintain incident response and recovery plans, and ensure appropriate board-level oversight of these. This will be supported by guidance from regulators which must be regarded. Entities would be expected to maintain evidence demonstrating compliance with these requirements. The information provided to regulators and the NCSC will enable effective regulatory supervision, which holds organisations to account, and will enhance wider threat and resilience analysis and support. This will feed into government monitoring and evaluation, where public post-implementation reports will provide insights and assess the effectiveness of the regime. I will come on to the timing of those later. The UK’s corporate reporting framework is currently undergoing wider modernisation efforts. Future consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management, so it is best dealt with as part of that work. On funding and information sharing in Amendment 169, ISACs can play an important role; there are many initiatives under way, many of which are supported by the NCSC. They have a voluntary approach which builds trust and brings about positive cultural changes. We believe that there is a real risk that the Government could undermine these benefits and complicate the regulatory landscape by intervening and recasting these initiatives as mechanisms of regulatory oversight and enforcement. However, I agree that more can be done to understand their impact, and how the Government can support them. That is why the Bill’s formal review mechanism was included, which will consider the entirety of the regime’s impact, including for information sharing. Coming back to the question of regulator funding, and to expand a little on the new cost recovery powers to ensure that regulators are able to recover the full costs relating to their NIS duties, this will enable regulators to be autonomously funded and sufficiently resourced to carry out their responsibilities. We will also enable regulators to better focus their resources through establishing a unified set of objectives through the statement of strategic priorities. The current framework therefore already ensures sufficiently and independently funded regulators, without a delayed commencement of the regime. To respond to the question posed earlier by the noble Baroness, Lady Neville-Jones, it is anticipated that fines levied under the regime would go to the Treasury. On the absolute criticality of skills in the sector and Amendments 15, 174C and 174D from the noble Lord, Lord Arbuthnot, and to all those who spoke on skills and cyber capability, the Government absolutely agree that workforce is crucial for effective implementation of the regime. I have previously set out how we intend to introduce security and resilience requirements, which will be consistent with the CAF. We propose that the SRRs will address organisational capability and personnel skills and training, driven from board level. These requirements will be developed in collaboration with industry, experts and regulators and formally consulted on before they are mandated. The SRRs will be supported by regulator guidance, tailored by sector, as well as government implementation guidance for regulators. We do not believe that additional guidance and a separate strategy would be proportionate, and it could be duplicative given the existing guidance published under the Bill. Cyber skills obviously go much broader than the Bill. That is why we are working closely with the UK Cyber Security Council and regulators to encourage cyber training and professional standards. Additionally, we have TechFirst, the Government’s flagship tech skills programme, which goes to the point made by the noble Baroness, Lady Ludford, everywhere from school children through to professionals and the university sector. Briefly, we talked earlier about skilled persons and Amendment 114. I mentioned earlier that a skilled person is a person with expertise. However, we do not think that we should tie the Government’s hands to specific skills requirements, which would reduce the Secretary of State’s flexibility in this space and could impede the regulated entity’s ability to take the necessary action required by the direction. On the question of reporting, we recognise the pace of cyber developments alongside the importance of regular assessments of the regime. We must be as effective as possible and agile in the face of new developments. Amendments 95 and 95A, tabled by the noble Lords, Lord Arbuthnot and Lord Clement-Jones, would reduce the period that the report on the operation of the legislation should be published to every three or even two years. As raised in the other place, the five-year period set out in the Bill is a minimum baseline and the Government will consider more frequent reports if deemed necessary. This framing follows the precedent set by the Telecommunications (Security) Act and the existing NIS regulations. This will provide the Government with the time they need to meaningfully review the cross-sectoral regime, analyse the information received from regulators and understand how it has evolved, and identify what improvements can be made. However, I stress that the Bill will also require the Secretary of State to provide Parliament with an annual report setting out how regulators have sought to achieve their objectives set out in the statement of strategic priorities. This annual report will enable more frequent monitoring of the regime and how it is working in practice by reporting on the regulators who implement it. The first report will be published one year after the publication of the SSP, which is targeting 2027. As a result, we anticipate that the first report would be published under two years after Royal Assent.

More from Baroness Lloyd of Effra (Lab)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.