L

Lord Markham (Con)

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them. These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen. The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach. That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else? Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve. I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

More from Lord Markham (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.