Science, Innovation and Technology: Ofcom: Crisis Response Protocol
“May I, as ever, thank the Chair of the Select Committee for such a depth of expertise and experience, and in particular for the report that she mentioned, which has formed the basis of a lot of our thinking? There are clear things that we have done in our engagement with Ofcom, such as ensuring we empower users, not least through the commitments made in the “Protecting What Matters” social cohesion strategy, which will follow up on a number of recommendations that the hon. Lady talked about, including empowering users of algorithms. Misinformation is very much under consideration, and I have spoken to Ofcom about categories of harm as part of the crisis playbooks. We will continue to review that.”
Spoke in 69 debatesAsked 116 questions
Business and Trade
Cyber Security and Resilience (Network and Information Systems) Bill: New Clause 2 - Cyber security support service for SMEs
“I start by echoing the thoughts of many Members from across the House, particularly my hon. Friends the Members for Leeds Central and Headingley (Alex Sobel) and for Cowdenbeath and Kirkcaldy (Melanie Ward). I did not know Jo Cox, but I admired her deeply. As we talk about our country’s resilience, her central message—that there is no deeper route to resilience than through the unity of our country and community—is top of our minds for all of us in this House. It is a pleasure to bring this important Bill back to the House this afternoon. The Bill will increase our cyber-defences and resilience, making the UK an even safer place to live and do business. I thank Members on both sides of the Chamber for their valuable contributions to this debate and for the expertise that they have brought throughout the passage of the Bill. I particularly thank them for their recognition of my core belief: that the central question for our national security and resilience is the question of our technological and AI capabilities. We tested the Bill’s measures carefully before introduction, but we have since listened to feedback. There are a small number of minor, technical drafting improvements, which I will briefly go through. Government amendments 16 and 17 ensure that regulators can ask for the information they need to fulfil their obligations under the NIS regulations. This does not give regulators any new powers; it simply confirms that the current reasons for requesting information under the NIS regulations will still apply under the updated regulations. Government amendments 7 and 8 make changes to align with two information-gathering Government amendments—amendments 16 and 17. Government amendment 11 makes consequential changes following an amendment made in Committee. That amendment enables information sharing between NIS regulators and other public authorities for cyber-matters outside the scope of the NIS regulations. Government amendments 14 and 15 clarify the safeguards for information sharing gateways, and amendments 9, 10, 12 and 13 make the necessary changes to ensure that the rest of the clause is consistent with the change made by amendment 14. Government amendments 18 to 26, to clause 57, allow regulators and the Secretary of State to issue notices related to the powers of direction to nominated representatives of regulated entities. I have also tabled Government amendment 27, which corrects minor drafting errors to ensure the Bill works as intended. Members raised a series of questions, and I will address them thematically. First, the question of scope was raised by new clauses 4, 20, 21, 5, 8 and 9. I thank my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, who brings consistent expertise and experience to these questions; the Chair of the Joint Committee on National Security Strategy, my hon. Friend the Member for Warwick and Leamington (Matt Western); and the hon. Members for Harpenden and Berkhamsted (Victoria Collins) and for Brecon, Radnor and Cwm Tawe (David Chadwick), who tabled amendments on the services and scope of the Bill. All organisations, from high street shops to manufacturing giants, should take steps to increase their cyber-security and resilience. The Government and the National Cyber Security Centre are making sure that the right tools are available for every part of the economy. I am sympathetic to their intent, and in particular with my hon. Friend the Member for Middlesbrough South and East Cleveland (Luke Myer) when he talks about the impact of cyber-security incidents on local communities. The Government have committed to reviewing whether new activities need to be brought into the scope of the NIS regulations, but it is essential that any such decision is based on a systematic and specific assessment of carefully considering whether the regulation in these particular parts of statute are the most appropriate response. The NIS regime has been put in place to protect the most essential parts of our economy, often those whose disruption would cause an imminent threat to life. It is focused on a specific set of tests where sectors have little or no alternative service provision in the event of disruption and relates the latest systematic evidence of the threats that each sector faces. In that context, all Government Departments with sectoral responsibility work with their sectors on broader cyber-resilience. The Department for Environment, Food and Rural Affairs does so with food, and the Department for Business and Trade does so with retail, automotive and so on. The NCSC also has strong relationships across sectors, actively working with them to share best practice and incident insights, and to strengthen overall resilience, such as by engaging with the British Retail Consortium following incidents affecting the sector last year. The food sector is unique among other critical sectors because of its high levels of diversity. In the analysis underpinning the judgments made in the Bill, there are approximately 20,000 SME food manufacturers in the UK alone, and many more farms, distribution centres, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull, rather than bringing food in scope of the NIS regime. We have made similar judgments about other sectors on the basis of that systematic analysis, as I have shared in Committee and at other stages of the Bill’s consideration.”