B

Baroness Lloyd of Effra (Lab)

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline. I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report. I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure. The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take. Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that. Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.

More from Baroness Lloyd of Effra (Lab)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.