L

Lord Vaizey of Didcot (Con)

Speaking in the House of Lords on 7 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I rise early to support the amendment from the noble Baroness, Lady Northover, partly to spare the stress of the noble Lord, Lord Clement-Jones, and also because there is a Liberal Democrat amendment imminent in the Chamber, although we of course will be abstaining—our solidarity with the Liberal Democrats does not extend too far. However, it does extend to this amendment, which ties in well with the noble Baroness’s earlier amendment concerning qualifications. I was fascinated to hear her referring to the Australian cyber service, which I had not heard about before. I would be fascinated to know more and it would be interesting to hear from the Minister what other lessons there may be for us to learn from similar jurisdictions around the globe. I suspect the Canadians, for example, some of our European partners and some of the south-east Asian nations, such as Singapore or South Korea, will probably have very advanced and sophisticated bureaucracies, if I can put it that way, or institutions looking at the cyber threat. Again, I shall address, rather than the technical detail of the noble Baroness’s amendment, the spirit in which it is brought and why it fits so well with her earlier amendment. It is about injecting a sense of urgency into how we raise our game in cyber in terms of our economy. When she mentioned the cyber action toolkit, it took me back to the days when I was one of the Cyber Ministers in the coalition Government. My responsibility was towards small businesses, and we launched endless small business toolkits, mainly because we wanted to say that we had launched a small business toolkit. We certainly never put in place any mechanisms for auditing its impact or success, and I think the constant references to about 7% of SMEs now having cyber policies in place may point to my abject failure in that role, and perhaps that of some of my successors. The more I have listened to this debate, the more it takes me back to my childhood, when we would get leaflets about a possible nuclear conflagration. I know that Ministers and the Government are now telling people to stockpile water and baked beans because of the impact of El Niño, but we know that a cyber attack on the UK would cripple our economy and essential public services, so it is akin, given the geopolitical situation, to a national emergency. The noble Baroness mentioned the views of the Association of British Insurers. Again, that was part of the toolkit. The feeling was that professional services would drive small businesses towards becoming more skilled in assessing their cyber risks, that you could not get insurance, or indeed cyber insurance, unless you had clear policies to deal with cyber attacks. With professional services firms, you could not necessarily get legal liability insurance for a data breach, which is not necessarily going to cripple your business but will affect your customers and therefore leave you open to liability, unless you could demonstrate that you had proper processes in place to protect your data. There is a whole ecosystem, it seems to me, that needs to be brought to bear to support the uptake of cyber skills and cyber audits by small businesses: we cannot be complacent and assume that 7% is an acceptable figure and that it should be allowed to evolve. To a certain extent, the noble Baroness’s amendment is about the after-effects: if you suffer a cyber attack then you should be able to call on skilled people, whom we hope will have achieved the kind of recognised qualifications that the noble Baroness talked about earlier. She compared them to doctors but, when I thought about the amendment, I thought more about plumbers and electricians and the technical qualifications that you need to have to do a technical and difficult job. We also need to look at what happens before. How do we increase the number of small businesses that put in place policies that will protect them from cyber attacks? That involves using the private sector, insurance companies and professional services firms to push forward clear protocols to which small business should be expected to adhere in order to receive the cover that they need to carry on doing business.

More from Lord Vaizey of Didcot (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.