Contribution
My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baroness’s amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.
I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UK’s accredited cyber professionals. It establishes pathways for cyber professionals—experienced and new entrants—to have an easier route into quality cyber roles.
We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the council’s independence, and that could affect its relationship with the sector.
That is a separate point from the importance of the need to professionalise the cyber sector and the Government’s strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.
Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Government’s TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and master’s students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.
On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UK’s cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.
Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government Cyber Action Plan. The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Bill’s powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSC’s cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.
To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baroness’s subsequent amendment, to discuss further support that we can provide to those SMEs.
We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.