1-17 of 17 results for house:"House of Lords"
Librarians' tools
- Search time
- 0.443 seconds
- Solr query time
- 0.006 seconds
- Search query
- house:"House of Lords"
- We searched for
- legislature_ses:25277
Type
House
Session
Year
Department
Member
Primary member
More
Answering member
Legislative stage
Legislation
Subject
More
Publisher
To ask His Majesty's Government what assessment they have made of the impact of retrospective settlement changes proposed in their ‘Earned Settlement’ consultation on the UK's national resilience, specifically regarding the retention of cyber security and data science personnel in critical national infrastructure sectors.
To ask His Majesty's Government what assessment they have made of the impact of retrospective settlement changes proposed in their ‘Earned Settlement’ consultation on the UK's national resilience, specifically regarding the retention of cyber security and data science personnel in critical national infrastructure sectors.
The earned settlement model, proposed in ‘A Fairer Pathway to Settlement’, is currently subject to a public consultation, running until 12 February 2026.
The consultation seeks views on whether there should be transitional arrangements for those already on a pathway to settlement, in order to ease the impact of changes for particular groups or preserve already afforded permissions by the previous system. No transitional arrangements have been decided upon yet.
Details of the earned settlement model, including any transitional arrangements for those already in the UK, will be finalised following that consultation. The final model will also be subject to economic and equality impact assessments, which we have committed to publish in due course.
To ask His Majesty’s Government what assessment they have made of the implications of the closure of Heathrow airport following an electricity substation fire for the resilience of the electricity grid and the security of such substations.
To ask His Majesty’s Government what assessment they have made of the implications of the closure of Heathrow airport following an electricity substation fire for the resilience of the electricity grid and the security of such substations.
My Lords, I extend my sympathies to all those affected by what happened at Heathrow. I also wish to praise the efforts of all the people who worked so hard to get Heathrow up and running again. The Government work continuously with industry, regulators and other stakeholders to improve and maintain the resilience and security of energy infrastructure and to minimise the risk of unplanned outages. Alongside Ofgem, my right honourable friend the Secretary of State commissioned the National Energy System Operator to carry out a review to investigate the power disruption to Heathrow. Once we have all the information, we will be best placed to understand any wider lessons to be learned on energy resilience and security for critical national infrastructure.
My Lords, I am grateful to my noble friend for that reply, and I share his comments about the work put in to restore supplies. Some 30 years ago, the IRA had a credible and viable plan to bomb a whole series of substations around London to deprive London of electric power. It was thwarted only through the efforts of MI5 and the Metropolitan Police. Although it now appears that the fire was nothing to do with malicious action, it has demonstrated how significant substations are. What steps are being taken to ensure that substations around the country are properly secure against malicious actors?
My Lords, I am grateful to my noble friend for that reply, and I share his comments about the work put in to restore supplies. Some 30 years ago, the IRA had a credible and viable plan to bomb a whole series of substations around London to deprive London of electric power. It was thwarted only through the efforts of MI5 and the Metropolitan Police. Although it now appears that the fire was nothing to do with malicious action, it has demonstrated how significant substations are. What steps are being taken to ensure that substations around the country are properly secure against malicious actors?
My Lords, I thank my noble friend for his work, particularly the work of the National Preparedness Commission. The matter he raises is very important. The Government take the protection of energy infrastructure seriously. We continually work with industry and the regulators to ensure that proportionate security measures are in place at key sites. In relation to what happened, the cause of the fire is still under investigation, and that is why we need to ask NESO to investigate the situation thoroughly. If there are lessons to be learned more generally relating to the issue my noble friend has raised, of course we will take them very seriously.
To ask His Majesty's Government, following the data breach experienced by Southern Water as a result of a cyber-attack, what assessment they have made of the adequacy of existing cyber security regulations for UK critical infrastructure.
To ask His Majesty's Government, following the data breach experienced by Southern Water as a result of a cyber-attack, what assessment they have made of the adequacy of existing cyber security regulations for UK critical infrastructure.
The National Cyber Strategy 2022 set outcomes for critical national infrastructure (CNI) (in the private and public sector) to better understand & manage cyber risk and minimise the impact of cyber incidents when they occur. In addition, at CyberUK 2023, the Deputy Prime Minister announced specific and ambitious cyber resilience targets for all CNI sectors (public and private sector) to meet by 2025.
Over the past year, the Cabinet Office has been progressing foundational work to support the creation of common but flexible resilience standards across CNI and do more on the assurance of CNI, including cyber assurance preparedness, by 2030. This includes work to evaluate the impact and effectiveness of all regulation that applies to CNI, including (but not limited to) NIS regulations, and to bring more private sector businesses working in CNI within the scope of cyber resilience regulations.
The Government is also committed to ensuring cyber security in the public sector, which is why GovAssure was launched in April 2023. Under GovAssure, government organisations regularly review the effectiveness of their cyber defences against common cyber vulnerabilities and attack methods. We are currently evaluating the first year’s assessments. GovAssure will enable government organisations to accurately assess their levels of cyber resilience across their critical services, highlight priority areas for improvement and provide the Government with a strategic view of cyber capability, risk and resilience across the sector.
To ask Her Majesty's Government what assessment they have made of the role of privileged access management in protecting the cyber security of (1) government departments, and (2) critical national infrastructure.
To ask Her Majesty's Government what assessment they have made of the role of privileged access management in protecting the cyber security of (1) government departments, and (2) critical national infrastructure.
Government departments and Critical National Infrastructure organisations are responsible for managing their own cyber risk effectively.
The high level of importance of privileged access management in cyber security is recognised by the National Cyber Security Centre (NCSC), which is the UK’s national technical authority for cyber security.
For Government, it is documented in the minimum cyber security standard in items 5 and 7. For Critical National Infrastructure (CNI) it is documented in NCSC’s Network and Information Systems guidance in section B2, and there are specific assessment criteria laid out in section B2.c of the Cyber Assessment Framework for use by cyber security regulators.
For wider industry sectors and Small and Medium Enterprises, best practice is contained in the NCSC Board Kit and 10 Steps to Cyber Security.
The Cabinet Office does not require central Government Departments to report all cyber incidents involving the misuse of privileged access credentials and so does not hold this information centrally.
However, The minimum cyber security standard outlines the communications required by a department when there is a security incident that impacts on sensitive information or key operational services. Therefore departments will only be expected to inform the Cabinet Office of an incident involving the misuse of privileged access credentials that met these criteria.
I declare an interest as a member of the Joint Committee. Further to the noble Baroness’s question, in the event of the noble and learned Lord, Lord Mackay of Clashfern, being unsuccessful and our leaving the European Union next year, will we continue to abide by the EU network and information systems directive? If so, how will we continue to make sure that it is kept in line with the situation in Europe? Will we be part of the intelligence system associated with it?
I declare an interest as a member of the Joint Committee. Further to the noble Baroness’s question, in the event of the noble and learned Lord, Lord Mackay of Clashfern, being unsuccessful and our leaving the European Union next year, will we continue to abide by the EU network and information systems directive? If so, how will we continue to make sure that it is kept in line with the situation in Europe? Will we be part of the intelligence system associated with it?
The answer to the first question is yes. We implemented the NIS directive in May this year, one of the first countries so to do. We will continue to honour the directive after 29 March next year. On the broader question about the future relationship, I can only refer the noble Lord to what I said a few moments ago about the Government’s intention to maintain broad co-operation and that it is in the EU’s interests as much as ours that that should continue.
My Lords, the noble Lord has given a very interesting answer, but he did not address the central question that my noble friend asked: what did Ministers do in response to those red/amber ratings in this case?
My Lords, the noble Lord has given a very interesting answer, but he did not address the central question that my noble friend asked: what did Ministers do in response to those red/amber ratings in this case?
As I said in my initial reply, the reviews are primarily aimed at the project leaders. They give them advice on how to identify risks and take mitigating action to ensure that those risks are circumvented to ensure that the project hits the relevant milestones. There might be occasions when Ministers have to intervene, for example, if some legislative change is needed or if fresh estimates and more money are required from the Treasury, but for the most part the reviews are aimed not at Ministers but at departmental leaders. As someone who has been a Minister, if I was in charge of a project that had a red tag attached to it by the IPA, I would take a very close interest in its progress and make sure that it was delivered.
To ask Her Majesty’s Government what proportion of the United Kingdom’s critical national infrastructure is owned by foreign-owned companies; and what assessment they have made of the benefits and disbenefits of that level of ownership.
To ask Her Majesty’s Government what proportion of the United Kingdom’s critical national infrastructure is owned by foreign-owned companies; and what assessment they have made of the benefits and disbenefits of that level of ownership.
My Lords, although detailed ownership figures are not held, much of the UK’s infrastructure is foreign owned. More broadly, as a nation the UK has a pipeline of more than £310 billion of potential infrastructure projects over the next five to 10 years. Investment will need to come from a variety of sources, foreign as well as domestic. The UK welcomes all investors, irrespective of nationality, particularly those bringing additional capital into the UK, provided that they meet our corporate governance standards and do not represent an unacceptable national security risk.
My Lords, I note that the Minister does not know what proportion of our national infrastructure is owned by foreign interests, but he does acknowledge that most of it is. Our ports are owned by Dubai, the BT network is controlled by the Chinese and London’s electricity is supplied by the French. Does he not think that it is about time that the Government started to take our national sovereignty, and our freedom of manoeuvre, seriously?
My Lords, I note that the Minister does not know what proportion of our national infrastructure is owned by foreign interests, but he does acknowledge that most of it is. Our ports are owned by Dubai, the BT network is controlled by the Chinese and London’s electricity is supplied by the French. Does he not think that it is about time that the Government started to take our national sovereignty, and our freedom of manoeuvre, seriously?
There are several points there. To say that the BT network is controlled by the Chinese is, to say the least, a considerable exaggeration. The issue of the dependence on the supply of equipment from China is a rather different one, and that, as noble Lords will know, is the subject of a recent ISC report. British sovereignty has traditionally and in recent years been debated much more in terms of threat to English common law, and the existential threat which Brussels and the European courts are thought to provide to Britain, than in terms of the threat from foreign investment. I should welcome the noble Lord banging on about one rather than the other—it would make a nice change.
Lords question for short debate on what assessment they have made of the findings and recommendations of the report of the London Finance Commission Raising the Capital.
Lords question for short debate on what assessment they have made of the findings and recommendations of the report of the London Finance Commission Raising the Capital.
Further to the Written Answer by the Baroness Scotland of Asthal on 18 July (WA 188), which Ministers are responsible for information security in each government department; and which Minister has overall responsibility for information security in the critical national infrastructure.
Further to the Written Answer by the Baroness Scotland of Asthal on 18 July (WA 188), which Ministers are responsible for information security in each government department; and which Minister has overall responsibility for information security in the critical national infrastructure.
Further to the Written Answer by the Baroness Scotland of Asthal on 18 July (WA 188), what progress is being made in preparing a national incident plan to respond in the event of an electronic attack on the critical national infrastructure.
Further to the Written Answer by the Baroness Scotland of Asthal on 18 July (WA 188), what progress is being made in preparing a national incident plan to respond in the event of an electronic attack on the critical national infrastructure.
Who are the Ministers responsible for information security in each government department; and which Minister has overall responsibility for information security in the critical national infrastructure; and
Who are the Ministers responsible for information security in each government department; and which Minister has overall responsibility for information security in the critical national infrastructure; and
What progress is being made in preparing a national incident plan to respond in the event of an electronic attack on the critical national infrastructure.
What progress is being made in preparing a national incident plan to respond in the event of an electronic attack on the critical national infrastructure.
Whether they will seek information from the United States Government on the lessons learned by the three-day exercise code-named ““Silent Horizon””; and what plans they have to mount a similar exercise to test the ability of government and industry to respond to escalating Internet disruptions.
Whether they will seek information from the United States Government on the lessons learned by the three-day exercise code-named ““Silent Horizon””; and what plans they have to mount a similar exercise to test the ability of government and industry to respond to escalating Internet disruptions.
Lords debate on unstarred question on whether Her Majesty's Government are satisfied with the ability of the national infrastructure to withstand cyber-attack.
Lords debate on unstarred question on whether Her Majesty's Government are satisfied with the ability of the national infrastructure to withstand cyber-attack.
Which public sector organisations and which private sector companies the National Infrastructure Co-ordination Centre (NISCC) regards as comprising the United Kingdom Critical National Infrastructure; and how many computers and communications systems the NISCC regards as comprising the Infrastructure; and what is their response and that of the National Infrastructure Co-ordination...
Which public sector organisations and which private sector companies the National Infrastructure Co-ordination Centre (NISCC) regards as comprising the United Kingdom Critical National Infrastructure; and how many computers and communications systems the NISCC regards as comprising the Infrastructure; and what is their response and that of the National Infrastructure Co-ordination...