L

Lord Tarassenko (CB)

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I shall speak in support of Amendment 83 in the name of the noble Baroness, Lady Kidron, to which I have added my name. In my speech, I will focus just on the aspects of the digital sovereign strategy that are relevant to the NHS. I speak as someone who held an honorary contract with the Oxford University Hospitals NHS Foundation Trust until November 2025, enabling me to be a co-investigator on research projects involving patient data. Cyber attacks against NHS trusts and their supply chains occur with very high frequency, from regular automated phishing attempts, which are blocked daily, to major incidents causing significant clinical disruption. Health and social care consistently rank among the top sectors reported for cyber incidents and data breaches to the ICO. I am sure that we all remember the WannaCry cyber attack in May 2017, which affected 81 of our 236 NHS trusts at the time, causing nearly 20,000 appointments to be cancelled in a week. Less than two years ago, in November 2024, there was a major cyber attack against the Wirral University Teaching Hospital NHS Foundation Trust, which compromised the trust’s electronic patient record. I know that EPR well as we have the same EPR in Oxford: Cerner Millennium. As a result of the cyber attack, staff in the Wirral hospitals lost all access to patient records, electronic prescribing tools and diagnostic results. All elective surgeries and outpatient appointments across the trust had to be cancelled, and members of the public were told not to use the emergency department at one of the hospitals in the trust. All clinical systems remained completely offline for nine days. I mentioned the EPR Cerner Millennium. Cerner is now part of Oracle Health. Together, Oracle and Epic, both of which are US companies, account for about 40% of hospital EPR contracts in England and Wales. In primary care, EMIS software manages just under 60% of the patient records—the records of 35 to 40 million patients across England and Wales. EMIS was bought by Optum, part of the UnitedHealth Group, in 2023, but, in March this year, the UnitedHealth Group sold Optum to a US private equity firm, TPG, for just under £300 million. I will come back to that briefly later. In 2023, NHS England and the Department of Health and Social Care launched a 2030 cyber security strategy. The noble Lord, Lord Markham, when he was a Health Minister, wrote the foreword—he will remember this, I am sure—to the strategy document. In it, he wrote—we all agree with him, I am sure—that “the cyber security of our health and social care … underwrites patient safety”. The group director for cyber security for the DHSC has recently written to all NHS trust boards informing them that, from this month, September 2026, new cyber policies will be included in the next data security and protection toolkit, covering issues such as multi-factor authentication, high-severity alerts and endpoint detection. There is nothing about AI, which is perhaps the subtitle of this Bill—something that will, I hope, have been removed by Report. Yet we know from Tuesday’s debate and last week’s open letter from 100 companies, including large tech firms, that AI-enabled cyber attacks are about to become more widespread and more sophisticated within months. This prompts three questions. First, are officials from the Minister’s department, which has overall responsibility for cyber security, co-ordinating with the cyber security group in the DHSC—especially with respect to the latest threats from AI agents? Secondly, have the recent reports from the AISI been communicated to the cyber security group in the DHSC, and have their implications for the NHS been discussed with them? I note here that the new Minister for Science and Innovation, Chris McDonald MP, is a Minister in both the DBIST and the DHSC, so I am hopeful that the answer to these two questions might be yes. Thirdly, given the high prevalence of foreign ownership of companies, such as Epic and TPG, that are responsible for managing patient data within the NHS—notwithstanding the single-supplier agreement with Palantir, another US company, for the Federated Data Platform—has the Minister’s department assessed the risk to relevant network and information systems as a result of our technological dependence on these companies? What I have described for the NHS also applies to other sovereign data assets such as those held by the BBC or the Met Office. If the full value to the UK of these sovereign data assets is to be realised as part of the Government’s growth strategy, we need to be optimally protected against cyber attacks, including AI-enabled attacks. For that to happen, we need a coherent digital sovereign strategy across government departments, led by the Minister’s department.

More from Lord Tarassenko (CB)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.