L

Lord Ravensdale (CB)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I will speak briefly to my Amendment 16. In my view, the central problem is that, if I am small or medium-sized firm, I cannot currently tell with any confidence whether I am within the scope of the Bill as a critical supplier. Small and medium-sized enterprises are the lifeblood of our economy, and we need to approach with caution any ambiguity around their inclusion in the Bill. I took note of what the Minister said at Second Reading, when she said that: “They can be regulated if they are designated as critical suppliers, for which there will be a high bar for designation”.—[Official Report, 14/7/26; col. 622.] That was helpful, but what exactly is that high bar? To give noble Lords an example of regulation legislation that is not defined, I come back to one noble Lords are likely to be familiar with: the infamous IR35. With that, the uncertainty and costs of getting it wrong were high in the regulation, so firms applied a blanket under which everyone they engaged with had to be inside IR35 and had to be treated as an employee. IR35 addressed a real problem, but the test was judgment-heavy and getting it wrong was expensive. That was why many organisations stopped making case-by-case decisions and applied a blanket policy, which meant that far more were caught by the regulation than was intended. I remember many years ago, as an engineer, spending a lot of time trying to fill in IR35 determinations and not doing engineering, which was a frustration at the time. It led to many issues with finding the right new skilled resource that we required to undertake the work. I am sure that the Minister will say that the criteria will be set out in secondary legislation, but there will be a long period of uncertainty, and the IR35 example helps illustrate the risks. I took a look at the impact assessment and some of the costs were laid out. For example, if a firm is within the scope of this legislation, it is looking at physical security costs of perhaps £114,000 and cyber security spending—potentially of £190,000 a year. The impact assessment could not say how many SMEs may be designated within this legislation. All of that uncertainty is a cost, because it means that, if firms are uncertain about whether they are going to included, they may delay investment. In fact, they may overprepare; they may take on additional costs, which has wider implications to the UK economy, or they may walk away from public services. They will not want to go for these contracts because of the risk they may fall under this legislation, and that could potentially cause the same grit in the wheel of the economy that was seen in IR35. There is a case here for providing in the Bill at least some additional definition on what a critical supplier is; that is what my amendment intends to do.

More from Lord Ravensdale (CB)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.