B

Baroness Northover (LD)

Speaking in the House of Lords on 7 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, this amendment again comes out of the evidence submitted to our National Resilience Select Committee. It has been reported that many SMEs think that they are too small to be a target. However, as was reported at Second Reading, government research shows that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for many small businesses, a cyber incident can be existential and that roughly 60% of SMEs that fall victim to a cyber attack go out of business within six months. In this amendment, I therefore seek to address the position of SMEs. Coming from the insurance sector, the Association of British Insurers feels that the Bill is narrow in scope and that “large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms”, including their new Cyber Governance Code of Practice. It feels that, without stronger incentives, measurement and accountability, there is a risk that it will not deliver consistent improvements. That is obviously concerning a number of people. There are warnings—we know this—that cyber risk is inherently systemic. Disruption is rarely confined to a single organisation or sector but is increasingly transmitted through supply chains. As I mentioned in the previous group, according to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risks presented by the wider supply chain, so how do we bring in greater protection in a way that, as the noble Baroness, Lady Neville-Jones, and the noble Lord, Lord Vaizey, have just mentioned, does not overwhelm SMEs? This proposed new clause would require the Secretary of State to establish a national, free-at-point-of-use cyber security support incident response service for relevant SMEs, modelled on comparable overseas services, such as the small business support provided by the Australian Cyber Security Centre. The ABI notes that the Bill rightly focuses on building resilience in our critical national infrastructure and that more must therefore be done to address the cyber resilience of SMEs. Not surprisingly, it is concerned about cyber insurance. It points out that the take-up of cyber insurance among UK SMEs is very low—somewhere between 10% and 40%—and argues that cyber insurance can help prevent and alleviate the impact of cyber attacks for SMEs. But, obviously, there is a cost to that. As cyber risks continue to grow, SMEs are typically more vulnerable and less well placed than larger businesses to respond to cyber threats due to overstretched resources, including IT and potential security and skills gaps. We have to be careful to make sure that reporting is not too onerous for SMEs. It is suggested, for example, that maybe their reporting timelines should be not as short as those for bigger companies, and that there should be better clarification of what is an actual or suspected cyber incident, so that things which are not as significant do not, as it were, clog up the system. However, I think everybody agrees that we need to make sure that SMEs are better supported. I welcome the fact that the Government have set up some support in this area. There is a cyber action toolkit, which was launched in March 2026 and includes a helpline, and a cyber adviser scheme, which offers a free 30-minute session. There is also a small business guide for response and recovery. But when you look at what they are suggesting, they are pushing companies towards the commercial market, so there is going to be a cost to that, and, down the line, towards fraud analysis and law enforcement. We know how challenging that is in so many areas, so it does not necessarily seem the most helpful or robust system. The reason I mention the Australian cyber resilience service and have looked at what it does is that it goes further than we are now going, and I hope the Government will give thought to extending this in the way that the Australian system does. There is free, tailored, person-to-person support with two functions: helping small businesses assess and build resilience and helping them to recover after an incident, such as account compromise, phishing or ransomware, with case management and device remediation. It is much more supportive than what we currently have in the United Kingdom. Clearly, much more needs to be done to ensure that SMEs are aware of the risks and do not simply wait until they have been hit, but also that they are actively assisted. That is important for them, but also for the wider economy, given how interlinked we all are. This is clearly an evolving area and I look forward to hearing what the Minister has to say about how we can move this forward, given how significant it is. I beg to move.

More from Baroness Northover (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.