B

Baroness Harding of Winscombe (Con)

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name. This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting. As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant. The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill. As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.

More from Baroness Harding of Winscombe (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.