Proceeding contribution from Lord Clement-Jones (Liberal Democrat) in the House of Lords on Tuesday, 1 September 2026. It occurred during Committee proceeding and Debate on bill on Cyber Security and Resilience (Network and Information Systems) Bill.
Cyber Security and Resilience (Network and Information Systems) Bill
My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.
As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.
Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.
4.30 pm
This is reinforced by Amendment 8, also in the name of the noble Baroness, which tackles the arbitrary SME exemption for digital service providers. A micro-entity or 10-person software house might develop and maintain a proprietary algorithmic routing tool or specialised API that underpins an entire national utility network. Under the Bill’s blunt size thresholds, that entity sits completely outside the statutory duties. Amendment 8 would ensure that, where a small provider poses a systemic risk to public safety, national security or essential infrastructure, regulators can bring it into scope.
This scope gap is made even more glaring when we look at the omission, broadly, of local government from this Bill. The newly published “Analogue 72” Green Paper from the Cyber Centre of Excellence highlights that across four annual cycles of external passive scans, including their latest July 2026 data, UK local authorities show rising external vulnerabilities. Councils hold the electoral registers, child safeguarding files and social care records of millions of citizens, yet they remain entirely excluded from direct statutory
duties under this Bill. The Government expect resilience to be delivered from the bottom up but plan entirely from the top down, leaving local government without statutory baseline funding or standards.
Finally, Amendment 14 in my name would provide a vital refinement to the definition of “managed services” in Clause 9. As currently drafted, Clause 9 defines a managed service so broadly that it in effect acts as a legal dragnet, capturing any service provided under contract for ongoing IT management, support, maintenance or other activities. This threatens to pull thousands of small, non-critical IT consultancies, training providers, software licensing agents and basic help desks into heavy NIS registration and turnover-based penalties. My Amendment 14 would establish a clear statutory boundary: if an IT provider does not possess ongoing privileged administrative access to configure, alter or control a customer’s live network, it is excluded from the managed service provider regime. This would protect small businesses and tech companies and include only those that present genuine systemic threats. I urge the Government to accept this balanced package of risk-based, future-proofed definitions.
Secondary information
- Type
- Proceeding contribution
- Reference
- 859 cc12-3GC
- Session
- 2026-27
- Chamber / Committee
- House of Lords Grand Committee
- Subjects
- Software Cybercrime Digital technology Fraud Infrastructure Ministerial powers National security Procurement Regulation Training Small businesses Supply chains Artificial intelligence Cybersecurity Data centres Digital service providers Quantum technology AI Security Institute
- Legislation
- Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 to 2026-27
- Link
- View this Proceeding contribution on hansard.parliament.uk
Librarians' tools
- Timestamp
- 2026-09-02 12:02:10 +0100
- URI
- http://hansard.intranet.data.parliament.uk/Lords/2026-09-01/26090149000005
- In Indexing
- http://indexing.parliament.uk/Content/Edit/1?uri=http://hansard.intranet.data.parliament.uk/Lords/2026-09-01/26090149000005
- In Solr
- https://search.parliament.uk/claw/solr/?id=http://hansard.intranet.data.parliament.uk/Lords/2026-09-01/26090149000005