Proceeding contribution from Lord Vaizey of Didcot (Conservative) in the House of Lords on Tuesday, 14 July 2026. It occurred during Debate on bill on Cyber Security and Resilience (Network and Information Systems) Bill.
Cyber Security and Resilience (Network and Information Systems) Bill
My Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister—which is almost as surprising as learning that I was once the Minister of Fashion.
Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area.
As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very
important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate these important issues of the fact that we have world-leading expertise that can contribute to the growth in our economy. When we talk about the defence investment plan, for example, it is important to talk about the huge opportunities we have to create great defence tech companies. Nor should we lose sight of the opportunity to create great British cyber security companies, which goes to the whole debate about potential sovereignty and giving us our own capability.
Let me begin by echoing a number of speeches about how important it is to work in lockstep with our EU partners. It is a piece of irony that this legislation emerges in effect from a European directive that we were beginning to debate when I was the Cyber Security Minister. In fact, the legislation is necessary because we can no longer transpose European legislation directly into British legislation. The noble Baroness, Lady Ludford, mentioned the GDPR, and it is a fact that Brussels can often take the lead in regulation such as this, and that big multinational companies tend to look at the biggest regulatory space in order to adhere to it. So it is important that we are mindful of how Brussels plans to proceed in this area, even if we find areas where we can be more flexible.
People have talked about our bad record in the UK on cyber security on account of cyber security attacks. I suspect that that is because we remain, I think, the most digital nation in the EU, and the English language as well provides us, weirdly, with some kind of vulnerability. But we are at the forefront of cyber security attacks, and it is important that we have the legislation and the bodies capable of responding to them.
Several themes have emerged. When I was the Cyber Security Minister, we began preparations for the National Cyber Security Centre: I thought that was incredibly important. I used to have a mantra that business in particular needed one front door that it could walk through to get the advice and expertise it needed to draw on to protect itself. We have talked constantly in this debate about 12 regulators, and I echo the calls to provide a uniform platform that can read across all the regulators, and they can add on top of that any sector- specific needs they meet.
I also recognise the calls from many noble Lords to say that this is perhaps an artificially constrained Bill, focusing on only a few vital sectors that are important to protect, instead of, as it were, seeing the whole picture and understanding, as many noble Lords have said, that cyber security pervades everywhere. There are so many ways in which we should look to protect ourselves in this age, one of which, of course, is in not losing sight of the hardware. The Minister spoke about software as a service. It is very important to remember that many of our public service providers, for example, still rely on ageing infrastructure, which provides huge vulnerabilities to cyber security attacks. I wonder whether the Government have a strategy to update much of the hardware that is still being used.
I was also interested in the remarks made about how vendors of software should be accountable. That is a very important avenue to explore: perhaps we could introduce kitemarks and audits of software providers to ensure that they are providing cyber-secure software that is as robust as it can be—again, as the noble Baroness said, we can count on the fingers of one hand the main providers of the software that is used in a vast number of businesses—and that they also work with us, as it were, to be on the front line.
It is interesting that this issue has become one of sovereignty. I am fascinated by the debate on the use of Palantir, for example. Personally, I have no problem working with Palantir. I think it provides a vital service, and I hope that the Government will be cautious in listening to the siren calls of people who say “Don’t work with these companies” simply because they disagree with the slightly bizarre views of some of their chief executives. Nevertheless, it perhaps calls for the Government to have a consistent story on this.
One thought that occurred to me during this debate was what has happened to the debate about encryption? This is a dog that no longer seems to be barking. In the last few years, we have had a vigorous debate on potential backdoors to encryption and security services being given, as it were, cyber keys to access encrypted services such as WhatsApp and Signal, and we saw a big pushback from the tech industry on how that would create big cyber vulnerabilities. I wonder whether the Government have come to a settled view on that.
Returning to the theme of the opportunities for the economy, the need to invest in cyber skills in our workforce is absolutely vital. We need to create a cyber workforce and a cyber defence force that work to protect the country, as well as giving companies the kind of skills base they need to make themselves secure. I echo the call from the noble Baroness, Lady Ludford, about boards. I was astonished to read in the House of Lords Library briefing that the number of board members with a responsibility for cyber has apparently fallen. I do not know if that is true, but I wonder whether it is possible to work with business bodies such as the IoD and the CBI to make it a strong corporate governance recommendation that every board should have somebody with a responsibility for cyber.
As I said at the beginning, this is a partnership: it is business, as much as government, that will protect us from cyber. For example, there has been reference to the insurance industry. One of the best ways we can ensure that companies invest in cyber security is to make it mandatory for them to get cyber insurance—which you cannot get unless you put cyber-secure measures in place—and to employ law firms to protect themselves from liability and to put in place important cyber measures.
I have not had a chance to support the noble Lord, Lord Clement-Jones, in his 50-year call for ethical hackers to be allowed to hack. I also echo the earlier call to hear the Minister’s views on the rise of bots and their impact on cyber security.
7.42 pm
Secondary information
- Type
- Proceeding contribution
- Reference
- 858 cc592-4
- Session
- 2026-27
- Chamber / Committee
- House of Lords chamber
- Subjects
- Disclosure of information Cybercrime Fees and charges Electricity Fines Insurance Food supply Ministerial powers National security Public sector Regulation Training Small businesses Retail trade Supply chains Artificial intelligence Cybersecurity Data centres Information sharing Smart devices Digital service providers
- Legislation
- Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 to 2026-27
- Link
- View this Proceeding contribution on hansard.parliament.uk
Librarians' tools
- Timestamp
- 2026-08-26 16:51:12 +0100
- URI
- http://hansard.intranet.data.parliament.uk/Lords/2026-07-14/260714121000022
- In Indexing
- http://indexing.parliament.uk/Content/Edit/1?uri=http://hansard.intranet.data.parliament.uk/Lords/2026-07-14/260714121000022
- In Solr
- https://search.parliament.uk/claw/solr/?id=http://hansard.intranet.data.parliament.uk/Lords/2026-07-14/260714121000022