Business and Trade
Support for hospitality businesses
“As the director of the National Cyber Security Centre has said, “Every organisation delivering the UK’s critical services…relies on uninterrupted digital operations. Disruptions to those operations isn’t simply an IT issue; it’s a…national resilience issue”. The Liberal Democrats wholeheartedly support that point, and it is why we welcome the measures introduced by this Bill, which strengthen existing cyber protections to enhance national security. However, as the Liberal Democrats have made clear throughout the Bill’s stages so far, there are many missed opportunities to truly future-proof our country’s cyber-security to protect our democracy, economy and national security. I will speak to the Liberal Democrat amendments to the Bill, which we think would achieve that. First, on the scope of the Bill, last year we saw the costliest cyber-incident in UK history. The financial damage caused by the attack on Jaguar Land Rover is estimated to have cost between £1.6 billion and £2.1 billion—a cost shared between JLR directly and its supply chain. In the public sector, cyber-attacks are causing eye-watering costs too—just look at Redcar’s cyber-attack, which cost them a staggering £10.4 million. Despite that, the Bill takes no consideration of the significant economic cost of such cyber-attacks, excluding retail and manufacturing industries as well as local government from the scope of the Bill. New clauses 4 and 5 address a crucial gap. New clause 4 would bring the manufacturing of critical transport equipment and the retail of food and essential goods, where they form part of a large-scale distribution chain, within the scope of essential categories under the Bill. That means that companies such as Jaguar Land Rover would finally receive the protections that their strategic importance demands and protect their supply chains too. New clause 5 extends that same recognition to local authorities, whose digital infrastructure underpins the delivery of services that millions of people depend on. The Government’s own industrial strategy recognises that sustainable and secure growth requires strong levels of cyber-resilience across the economy, but their own cyber Bill does not live up to this. If a cyber-attack brought JLR’s production lines to a halt or crippled the digital infrastructure of a council, the damage to our economy and people’s daily lives would be enormous. Those are not the only issues within the scope of the Bill. Safeguarding our democratic processes must be treated as a national security priority, and here, too, the Bill falls short. At a time when foreign interference in our elections is not a hypothetical but a documented and growing threat, the Government have chosen not to act. New clauses 8 and 9 would begin to change that. New clause 8 would designate the administration of elections and voter registers as essential services within the meaning of the network and information systems regulations—a straightforward recognition that the machinery of our democracy is as critical as any power grid or hospital network. New clause 9 would designate political parties as essential services for the purposes of cyber-security, extending meaningful protection to the organisations through which the British people exercise their democratic voice. I understand that the Bill is not a silver bullet for cyber-security, but these amendments make the modest, targeted and entirely reasonable ask that vehicle manufacturing, food retail supply chains, local authorities, our elections and our political parties are brought within scope. In turning to online-generated fraud and scams, we can see the impact of a lack of action to secure online and cyber-spaces. Fraud makes up 44% of all UK crime, and online technologies—especially artificial intelligence—are supercharging that. According to reporting in The Times a few weeks ago, research by Lloyds bank found that Meta’s social media sites are a starting point for 76% of purchase scams in the UK, with the value of losses to UK customers estimated at around £66 million in the last year alone. Not only does the Government’s fraud strategy completely overlook the role of social media giants and big tech in the proliferation of online scams, but the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is especially striking when we consider that the Government’s official statistics on cyber-security breaches show that phishing attacks—scams—remain the most prevalent type of breach or attack by far in the UK. Amendment 1 would change that. It would amend clause 8 to add “risks arising from fraud” explicitly to the list of security threats facing relevant digital services so that those threats can be identified and managed. That is also why the Liberal Democrats are calling for social media giants to be financially liable for scams originating on their platforms and for an online crime agency to tackle these issues and standardise AI labelling. We must not forget that these threats do not fall solely on large institutions and critical infrastructure. Small and medium-sized enterprises are on the frontline of cyber-crime; they are disproportionately targeted and too often without the resources or expertise to defend themselves. Many of the businesses caught up in the supply chains of our critical industries and exposed to the fraud and cyber-risks that I have described are SMEs, yet there are no provisions in the Bill to help potentially under-resourced SMEs cope with the increasing threat of cyber-attacks. New clause 2 would require the establishment of dedicated cyber-security support services for those businesses. For the Liberal Democrats, backing British small businesses means ensuring that they are not left to face those threats alone. The Liberal Democrats have also tabled a series of further measures that would make the legislation fit for purpose over the long term. A law is only as good as its enforcement, which is why we are pressing for board-level accountability for cyber-resilience under new clause 10, regular proportionate testing of systems under new clause 11 and more frequent Government reporting every three years—rather than every five years—under amendment 2. Last week, at London Tech Week, as I was surrounded by experts across the industry, one thing became clear. We think that technology is moving quickly now, but with the growth and development of AI this is the slowest we will ever see change happen. That is why we need the framework to evolve, which means reviewing the security risks posed by foreign-linked critical suppliers, which new clause 3 would do, modernising the outdated Computer Misuse Act 1990, which new clause 6 would do, and assessing whether regulators have the resources they actually need to do their job, which new clause 7 would do. Those are not radical tasks; they are basic conditions for a cyber-security regime that works today and will continue to work in the future. If there is one matter that cuts to the heart of what the Bill should be about, and asks the fundamental question about Britain’s place in a contested digital world, it is digital sovereignty. All the protections we have discussed for our industries, our democracy and our small businesses will mean little if we do not first answer who controls the digital infrastructure on which all of them depend, and question whether, at every level of the stack, we have critical control over that. That is echoed loudly by the industry itself. A study by Civo, a UK sovereign cloud provider, found that 83% of IT decision makers in this country worry about the impact of geopolitical developments on their data sovereignty. When we look at the numbers, it is not hard to see why. About 55% of central Government organisations report that over 60% of their estate is on the cloud, and the vast majority of that is with just two providers, both of which are American. We have handed the keys to significant parts of our national digital infrastructure to foreign corporations, subject to foreign laws and exposed to foreign decisions entirely outside our control. That includes our public services. The Liberal Democrats are alarmed at the NHS’s growing reliance on complex, opaque digital systems set up by Palantir. With Palantir’s background in security and surveillance, that marks a divergence from the traditional relationship between the NHS and firms with specialised medical knowledge. The procurement process for the federated data platform, which was awarded to Palantir in 2023, is worryingly opaque. We are pleased that the Science, Innovation and Technology Committee has called on the Government to exercise the break clause in that contract. We call on the Government to use the break clause and provide a clear timeline for Palantir’s removal from the NHS. Even Karp and Zamiska—from Palantir—said: “The limits of soft power, of soaring rhetoric alone, have been exposed. The ability of free and democratic societies to prevail requires something more than moral appeal. It requires hard power, and hard power in this century will be built on software.” Let us now look at Anthropic. Last week, it launched its new AI model, Claude Fable 5. Almost as soon as it was launched, the US Government intervened and shut it down for foreign nationals both inside and outside the country. Let me put that more clearly: Anthropic closed access to its tools under the direction of the US Government. This is a wake-up call. Our reliance on the technology that fuels our economy and underpins our services shows that we desperately need a sovereign digital strategy. Fable 5 may have been a feature for only about a day, but imagine if it had been powering processes and public services when it was suddenly cut off by the US Government. Crucially, this is about backing British tech as well as working internationally. Collaborative sovereignty would make us stronger partners globally. That is why we have tabled new clause 13—I urge the House to vote for it—which would require the Government to establish a digital sovereignty strategy that sets out clearly how Ministers will assess, manage and mitigate risks to the security and resilience of our critical systems and place British tech procurement at its centre.”