Julia Lopez

Julia Lopez

Conservative — Hornchurch and Upminster

Speaking in the House of Commons on 6 January 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

Happy new year, Mr Speaker, and thank you for putting the heating on. I am grateful to the Minister for setting out the Government’s rationale for this legislation in the Secretary of State’s stead. I do not know why the Minister was demoted either, but I want him to know that we appreciate him. The official Opposition recognise the scale of the cyber-security challenge that the country faces. If the pandemic accelerated the adoption of digital technology at a pace we had never before seen, then the advent of artificial intelligence will embed that technology into our economy in wholly new ways that bring not only opportunity but unprecedented risk. AI and automation will not only transform productivity but equip hostile states, criminal gangs and opportunists alike with tools capable of eroding our national defences at speed and at scale. It is right that Parliament legislates to raise the collective security bar. We on the Conservative Benches support that principle. However, legislation of this kind does not come around often. Cyber law takes time to develop, and once the Bill passes, it is unlikely that Parliament will return to this territory for some years. That means that we must ask two simple but very serious questions today: will this law work and is it enough? Before we answer those questions, it is worth reminding ourselves of the real-world consequences of failure. Cyber risk is neither abstract nor theoretical. Last year, the UK experienced what is widely regarded as our most economically damaging cyber-incident to date when Jaguar Land Rover suffered a major attack. That was not a sophisticated act of cyber-warfare against the state—although such acts are happening with increasing regularity—but was carried out by a band of hackers. The consequences were enormous, however. For five weeks, Jaguar Land Rover was unable to operate its automated manufacturing lines, cyber-related costs mounted to nearly £200 million, and national economic output was visibly affected in that month alone. The real damage did not stop at the factory gates: hundreds of small and medium-sized enterprises in the supply chain—many of them operating on thin margins—were pushed to the brink, workers faced uncertainty and contractors had their work paused. Ultimately, the Government had to step in with a £1.5 billion loan guarantee to prevent wider economic fallout. When we consider the Bill, we must ask whether it would do anything to strengthen our collective resilience. That is one of the tests that this legislation ought to meet, and it is not yet clear that it does. Indeed, the attack on JLR would not have been stopped, as the Minister himself has made clear, because it would not have been in scope. The cyber-threat landscape is evolving at an extraordinary pace. New research shows that cyber-attacks now cost our economy nearly £15 billion every year. High-profile breaches of businesses such as Marks and Spencer and the Co-op have demonstrated how quickly consumer confidence, jobs and supply chains can be put at risk. Last year alone, insurers paid out £197 million to help businesses recover from cyber-incidents. In fact, the collective cyber insurance bill of the FTSE 100 is now larger than the defence research and development budget. The Bill seeks to respond to one aspect of that reality by expanding the scope of regulation. Data centres, managed service providers, load controllers and designated critical suppliers will now fall within its ambit. That is a welcome acknowledgment that digitisation has introduced systemic risks that the original NIS regulations of 2018 did not adequately cover. The Bill also strengthens the powers of regulators, introduces cost recovery mechanisms and tightens incident reporting requirements. Those measures are intended to modernise our cyber framework and address clear shortcomings identified in reviews of the NIS regime in 2020 and 2022. On paper, that all sounds sensible, but intent alone is not enough, which brings me back to our central concern: whether this law will work in practice in raising the standard of our collective resilience. The uncomfortable truth is that, in some of the most high-profile cases of cyber-attack, the penetration of systems was carried out by attackers using valid credentials. That means systems behaved normally. The breaches looked like legitimate access until it was too late. Human frailties were exploited: help desks were persuaded to reset passwords, and staff and contractors were impersonated. This Bill would help mainly after an attack—not before—by mandating reporting, improving intelligence sharing and increasing accountability.

More from Julia Lopez

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.

For Julia Lopez's full parliamentary record including voting history, expenses and all other contributions, see the Julia Lopez report card.