Contribution
I very much welcome the opportunity to speak on Second Reading. The Bill addresses one of the most defining national security challenges of our age and we have heard many valuable contributions from right hon. and hon. Members across the House.
Before entering Parliament, I spent several years working to protect our country from cyber-risks. My background in software engineering gave me a rare view under the bonnet of the systems that now underpin almost every aspect of our daily lives. I saw first-hand how our digital infrastructure works and just how vulnerable much of it remains. I really loved that work, and I am proud to say that as a country we are genuine world leaders, but I would be dishonest if I said that it did not leave me deeply worried at times. That is not because of any single threat or actor, but because of the sheer scale, complexity and relentlessness of the cyber-risks we face. Those risks are only accelerating with advances in artificial intelligence, automation and the advent of quantum computing. Those technologies will, as we have heard today, revolutionise our lives in ways that we are only just beginning to understand. We must adapt alongside them if we are to remain a serious technological and economic power.
Our lives are now dependent on digital systems at every level. From water treatment plants and electricity networks, to transport, financial markets, healthcare and the wider economy, it is fair to say that we are no longer merely supported by digital infrastructure, but built upon it. And when those systems fail, the consequences are not abstract. They are immediate, they are human and they can be devastating.
We have already seen that reality play out in this country. If we cast our minds back to May 2017, the WannaCry ransomware attack tore through the national health service. Tens of thousands of computers were infected, and staff were locked out of patient records, diagnostic systems and telephony. Ambulances were diverted, and thousands of appointments and operations were cancelled, including urgent cancer referrals. The estimated cost to the NHS was £92 million, but the human cost—the stress, disruption and loss of confidence—cannot be measured in pounds and pence. The crucial point, which we have heard made in contributions today, is that while the attack was not targeted at the NHS, it was particularly vulnerable, because it was reliant on outdated and unpatched systems, and on the fragmented digital assets it owned. It was a warning shot that should never be forgotten.
More recently, the private sector has faced similarly sobering lessons. Capita was recently fined £14 million following a cyber-attack that compromised the data of more than 6 million people. British Airways and Marriott International suffered major breaches affecting hundreds of thousands of customers, resulting in substantial penalties and lasting reputational damage. These are not small firms, but sophisticated organisations with scale, expertise and resources, yet still they were exposed. That is why the Bill matters and why I want to work constructively with the Government to ensure that we get it right first time.
Crucially, we must build the ability to adapt and update the framework as technology and threats continue to evolve, while—I refer to the point made by my right hon. Friend the Member for Hertsmere (Sir Oliver Dowden)—not making that burdensome on businesses and organisations.
As the UK’s first piece of legislation to include the words “Cyber Security” in its title, the Bill represents an important step forward. It modernises the network and information systems framework; brings new sectors into scope, including data centres, managed service providers and critical suppliers; strengthens incident reporting requirements; enhances enforcement powers; and allows Government to act decisively—I hope—where national security is at risk. I welcome those objectives and, in particular, the recognition that managed service providers and supply chains are now critical attack vectors. That is absolutely correct. Cyber-threats do not respect organisational boundaries, and our regulatory framework must reflect that reality.
However, the Bill must not be treated as some sort of elixir. Cyber-security is not solved by regulation alone. The Bill strengthens protections for critical national infrastructure but leaves significant questions unanswered—questions that we must address if we are serious about national resilience. One of the most pressing concerns raised by industry is the growing complexity of incident reporting. Organisations already face overlapping obligations under data protection law, sector-specific regulation and, soon, economy-wide ransomware reporting requirements. Add to that multiple voluntary reporting channels, and the landscape becomes fragmented and very confusing. Having been a small business owner, I know that, when dealing with marketing, advertising and payments to staff, having extra layers of complexity, with reporting added on, is a difficult position to be in.
The first hours of a cyber-incident are chaotic: systems are down, decisions are time-critical and staff are under immense pressure. Forcing organisations to navigate multiple reporting regimes in that moment risks distracting them from the most important task, which, as we all know, is containing the attack and restoring services. A unified reporting framework with a single point of contact and aligned timelines would reduce burdens on businesses, while improving the quality of information available to Government. The Bill should move us closer to that outcome, not further away from it. I look forward to working with the Government at the next stage of the Bill to ensure that happens.
We must be honest about the limits of sector-based regulation—the Minister referred to this in his opening remarks. The Bill focuses, rightly, on critical national infrastructure, but many of the most damaging attacks in recent years have occurred outside its scope. Manufacturing, retail and consumer services have been heavily targeted. The attack on Jaguar Land Rover, which many right hon. and hon. Members have referred to today, is estimated to have caused up to £2 billion in economic damage across the company and its supply chain. That is a stark example.
I want to put on the record my deep concern about the precedent being set: the British taxpayer is effectively being required to act as insurer of last resort for major companies that have failed to adequately defend themselves. For large firms that are critical to our economy, the expectation that the public will step in cannot become the norm. Responsibility must sit squarely with the boards and executives to invest properly in cyber-security resilience or face the consequences. I am glad to see that the Government have taken the initial steps to have that conversation with industry.
At the same time, small and medium-sized enterprises, which make up the vast majority of our economy, are particularly exposed. They often lack the skills, budgets and capacity to implement proportionate cyber-defences, yet they sit deep within critical supply chains. A single weak link can have cascading consequences far beyond the organisation directly attacked. If cyber-security is economic security—I think we all agree that it is—we need a whole-of-economy approach. That means combining regulation with incentives, and support and standards that uplift resilience across UK plc, not just at the very top. That should include stronger, secure-by-design requirements for technology products, embedded through procurement and standards, and practical, accessible support for smaller businesses, potentially including consideration of a national first responder model to help small firms recover quickly from cyber-attacks.
We must also address the skills challenge head-on, as cyber skills shortages are already undermining resilience and compliance. If we are to give them more investigatory powers, the regulators themselves will need additional technical and enforcement capacity to deliver the expanded responsibilities set out in the Bill. That capacity cannot be assumed; it must be planned for, funded and developed far in advance.
Finally, I want to raise the issue of cyber-crime law. The Computer Misuse Act 1990 dates from a time when fewer than 1% of the population had access to the internet. Its blanket prohibition on unauthorised access fails to distinguish between malicious attackers and legitimate cyber-security professionals acting in the public interest. That matters: vulnerability research and threat intelligence are essential to defending our systems, yet many professionals in the industry operate in a legal grey area when carrying out work that ultimately strengthens our national security. Updating that framework, including by introducing protections for reasonable research, would modernise the law without weakening it.
In conclusion, the Bill is an important foundation. It strengthens protections for critical services and sends a clear signal that cyber-security is a core responsibility of the modern state. However, legislation alone will not deliver that resilience; it requires co-ordination, clarity, capability and sustained investment, as well as an honest understanding of where the Bill must be strengthened as it moves through Parliament.
Cyber-threats do not stand still, and neither can we. I support the direction of travel set out in the Bill and urge the Government to engage constructively as it progresses so that we can deliver a framework that provides real, lasting protections for our country, our economy and the British citizens.