L

Lord Birt (CB)

Speaking in the House of Lords on 3 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, these amendments are highly pertinent. We simply must ensure that non-UK providers of services in this sector are firmly and wholly within the scope of the Bill—they are only partly in scope. For noble Lords who were not at Second Reading, I read out a coruscating report by the American Government that damned Microsoft for its poor cyber security. I am sure that it is not true across the whole of Microsoft, but in that particular instance it manifestly was. I observe that our previous debate was absolutely excellent; it uniformly focused on organisations in the UK that are providing services. There was a danger that somebody hearing that debate might think that all those organisations are themselves responsible for breaches. The data on whether breaches chiefly occur through failures in organisations mentions the absence of multifactor authentication or that they are caused by failures in the quality and design of the services that those organisations consume. By the way, the organisations consume literally hundreds and hundreds of services, and the reality is that it is a huge challenge for organisations to ensure that all the services that they buy are secure. We might say that it is a near impossibility. Again, it is absolutely vital that we keep providers firmly within the scope of the Bill—I am not saying that they are not there, but they are certainly not there in their totality—and, dare I say, firmly under regulation.

More from Lord Birt (CB)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.