Kanishka Narayan MP: speeches
335 published records · newest first.
Speeches
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I thank my hon. Friend for that point. The reality is that neither he nor I am placed to judge exactly where the thresholds should be set on a permanent basis. That is exactly why we have secured the flexibilities that we have in the Bill. Clause 5 brings Crown-operated data centres into scope of the NIS regulations, ensuring that Government data centres meet robust standards comparable to those in the private sector. Bringing Crown data centres within scope closes a critical gap and guarantees that public sector infrastructure is protected against evolving threats. Exemptions will apply only in defined cases in which a data centre service is provided by an intelligence agency or a facility handling highly classified—“Secret” or “Top Secret”—information. These data centre services are already governed separately, and applying the NIS regime could cause conflict. I urge that clause 5 stand part of the Bill. Finally, clause 6, on large load controllers, introduces the essential new service of load control under the energy subsector of the NIS regulations. This will capture organisations—
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I thank the hon. Member for Brecon, Radnor and Cwm Tawe for tabling amendment 25, which would amend the duties for RDSPs in the NIS regulations. I empathise with the source of his concern about fraud; I think many of us in the House know and feel that concern, through either our personal experience or that of our constituents. That said, the security duties within NIS require RDSPs to identify and take steps to manage the full spectrum of risks posed to the security of their systems. They must prevent and mitigate relevant incidents, regardless of what the threats are or where they emanate from. That includes taking an all-hazards risk-based approach. Entities must manage risks to cyber-security, physical security and broader operational resilience. “Security” includes the ability to resist any action that may compromise the availability, authenticity, integrity or confidentiality of those systems, including risks that may arise from fraud. I caution against highlighting only one particular vector of risk in the clause; that is unnecessary and would not reflect the full range of risks each RDSP faces. Further, while the Bill clarifies the high-level duty to manage risks, secondary legislation will give further detail on the security and resilience requirements. Guidance and the code of practice will give further detail still on the types of risks to consider. For that reason, I kindly ask the hon. Gentleman to consider withdrawing the amendment. The shadow Minister asked about the Government’s treatment of fraud, particularly when it has been found on a platform and the authorities have asked that platform to take it down. The Government made a clear commitment in our manifesto to introduce a new fraud strategy, and the Home Office, as the lead Department, has been working at pace to engage deeply in making that an effective reality. Alongside that, in my wider role in online safety, I am conscious that fraud is a fundamental area of content in which platforms have to look at where it crosses the border into illegality, as it may well do in the instance the shadow Minister described. That has been a central focus since the illegal content duties came into play last year. I believe that such instances are well covered by the pieces of legislation that I have just mentioned. The Bill is clearly more focused on critical national infrastructure and its exposure to network and information systems.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Although I will not rule a particular provider in or out of scope, if the provider in question met the threshold for RDSP coverage, it would be covered, but the locus of that coverage would be limited to the provider rather than to the end-customer entity. I hope that clarifies that sufficiently. Let me explain how clause 8 was designed to tackle the risks that Committee members have set out. The clause updates the existing duties for RDSPs in the NIS regulations to ensure that they remain resilient against evolving cyber-threats. It clarifies the requirement for those services, making it clearer that they must secure themselves not just to keep the services they provide running and available but to contribute to wider systems security as a whole.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Loudly and slowly: this will capture organisations remotely managing significant amounts of electrical load via energy-smart appliances, both in a domestic and non-domestic setting. These organisations play an increasingly important role in the management of the electricity system, but are not currently regulated for cyber-security. A cyber-attack could therefore create major disruptions to the national grid, shutting down public services and critical national infrastructure. Capturing load control as an essential service will safeguard the public from these disruptions. It will also reflect the need to bring in new safeguards to manage a more digitalised and dynamic energy landscape in the transition towards net zero.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Clause 4 of the Bill amends the NIS regulations by creating a new regulated sector, data infrastructure, and designating the Secretary of State for Science, Innovation and Technology and Ofcom as joint regulators. We have received clear feedback from the data infrastructure sector expressing concerns that a dual regulator model could create unnecessary complexity and limit accountability. Amendments 11 and 12 will remove the Secretary of State for Science, Innovation and Technology as a regulator, leaving Ofcom as the sole regulator, which will streamline the regulatory model for data infrastructure and resolve the concerns raised by stakeholders. Ofcom already has proven regulatory expertise and is well placed to oversee the new data infrastructure sector effectively. By adopting a single regulator for data infrastructure, the amendments will reduce administrative burden, simplify engagement, and strengthen accountability. This will ensure a clearer, more effective regulatory framework for this rapidly growing sector. Clause 4 brings qualifying data centre services into the scope of the NIS regulations, recognising both their vital role in underpinning our economy and public services, and that disruption to them can significantly impact productivity, service delivery, and revenue.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
On that important point, which the hon. Member for Bognor Regis and Littlehampton also raised, the changes to the definition came about in part through extensive engagement, and in particular by ensuring that the attributes of “elastic” and “scalable” were treated individually rather than jointly and that “shareable”—the ability to have multi-tenants and therefore be a genuine cloud computing service for multiple clients—was considered in scope. As I mentioned to the hon. Member for Bognor Regis and Littlehampton, it is important that we keep this under review, and part of the reason for the secondary powers in the Bill is to make sure it remains both specific, giving clarity and certainty, and flexible at the same time.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I might just make a slight bit of progress. As I mentioned in a previous session, the programme reached 415,000 students, and it has now been evolved into the wider TechFirst scheme as well. The shadow Minister, as well as the hon. Member for Bromsgrove, made a very important point about resilience in particular and sovereign capability. Particularly for those reasons, I am really proud of two things. One is that the Bill includes suppliers that may not be resident in the UK but provide essential services in the UK. This is a critical means through which we can secure our capabilities here. The second, which is close to my particular interests in the data centre and compute world, is that, through our initiatives on sovereign AI, and having launched a very innovative advance market commitment in the chips part of the stack, which ends up crowding in wider demand—not least through companies such as Nscale, a fundamental part of our AI growth zone in the north-east—this Government are finally rectifying the errors and omissions of the last Government, in making sure that Britain does not do what it did in the last commercial cloud context, but instead, in this AI compute world, has some actual chips on the table. Thirdly, I will not try to settle the thrilling debate between the shadow Minister and my hon. Friend the Member for Lichfield on the philosophy of regulation. I will simply make the humble suggestion that in this context we have arrived at, not a full-fat compendium, as the shadow Minister described it, but a very targeted Bill, which has been the result of extensive industry engagement—indeed, some of it was carried out by the prior Government—that aligned on the sectors in question and the inclusion of critical suppliers in scope. On the shadow Minister’s question about the thresholds and definitional specificity of large load controllers in the Bill, I will of course remain very open to ensuring that the secondary powers, which are intended precisely to enable us to move flexibly as the clean power industry moves, give us the flexibility to move with it. At the same time, the threshold of 300 MW reflected the point at which a large load controller could pose an unacceptable risk to the electricity system and our CNI. This threshold was set very clearly in partnership with technical experts, including the National Energy System Operator. Of course, as the market grows, the potential for cyber-incidents will grow, and we will keep that under close review.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I beg to move amendment 11, in clause 4, page 3, line 5, column 3, leave out from beginning to “the” in line 6. This amendment and Amendment 12 would remove the Secretary of State for Science, Innovation and Technology as a joint regulator for the data infrastructure subsector, leaving the Office of Communications acting as the sole regulator for that subsector.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I beg to move amendment 13, in clause 7, page 7, line 7, leave out paragraph (b) and insert— “(b) a pool of computing resources is ‘scalable’ if the resources are flexibly allocated by the provider of the service, irrespective of the geographical location of the resources, in order to handle fluctuations in demand; (c) a pool of computing resources is ‘elastic’ if the resources are provided and released according to demand, in order to rapidly increase and decrease available resources depending on workload; (d) computing resources are ‘shareable’ if— (i) multiple users share a common access to the service, which is provided from the same electronic equipment, and (ii) processing is carried out separately for each user.” This amendment would refine and make further provision about certain aspects of the definition of “ cloud computing service ” .
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
In the course of engaging with firms we have considered what the timeline for reporting ought to be. It is critical that the initial notification requirement, which is a much lower requirement than the full notification requirement, at least gives the NCSC and other enforcement authorities the ability to counter national security and wider-impact risks. I believe that specification to be proportionate in the Bill, but it is of course a matter for implementation that we will keep a close eye on. An attack on a data centre can have significant impacts beyond the facility itself. As data centres underpin digital services across multiple sectors, disruption or compromise can cascade through essential services, businesses and public services. Incidents may also pose national security and economic risks, given the concentration of sensitive and critical data. Bringing qualifying data centre services into scope of the NIS framework helps ensure these risks are managed proportionately and incidents are reported promptly. As per Government amendments 11 and 12, we propose that Ofcom is the regulator. Medium and large third party data centres and very large enterprise centres will be required to manage risks and report to Ofcom. Their thresholds have been carefully calibrated to capture data centres whose disruption could have the greatest impact, while avoiding unnecessary burdens on smaller operators. This will strengthen the cyber-security and resilience of data centres, align with international regulations, and introduce structured oversight, notification, and incident reporting to strengthen national security and economic stability.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
With your permission, Mr Stringer, I will restrict my comments to clauses in question—in particular, clauses 5 and 6—and the relevant Government amendments. The shadow Minister has auditioned for roles at the Department for Business and Trade in talking about the philosophy of regulation, at the Department of Health and Social Care in talking about his medical background, and at the Treasury in talking about taxation. I will try to restrict myself to none of those and simply speak to the clauses and address three points in response to his comments. The first relates to the skills and resourcing of our regulators. On that, I welcome the shadow Minister’s prior engagement with me directly and his questions now. The last Government completely gutted our regulators. Having done so, they achieved neither growth nor regulatory quality, which Opposition Members now talk about. As a consequence, it falls to us to make sure that our regulators are fit for purpose and resourced in the way they need to be. This Bill gives them the powers to secure initial and full notifications in a timely way, the powers to share information in an appropriate way and, fundamentally, the ability of cost recovery, to resource themselves in an appropriate way. Alongside that, our wider initiatives on skills in the cyber-sector and technology more broadly are fundamental to achieving our aspirations, not least through the CyberFirst programme, which I mentioned in a witness session.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I welcome some of the Opposition spokesperson’s comments. Let me briefly address his questions about definitions and public sector inclusion. It is customary for the Opposition to oppose for the sake of opposition, at times, and I am afraid that this is one of those times; I have so far set out only two clauses, which are effectively an index to the Bill. Notwithstanding that, I will address his two particular points. I was delighted that in our evidence sessions we heard from witness after witness who appreciated the flexibility of the Bill. For the Government to prescribe activities or incident thresholds in the finest detail in primary legislation is not how businesses, Government and regulators ought to engage. I hope that the Opposition will come to appreciate that in due course. On critical suppliers, which no doubt we will come on to, I thought that in response to Opposition comments at our second sitting, I set out a very clear, precise set of tests. I found no opposition to that claim, but I look forward to hearing any original thoughts on that question. On incident reporting, I was delighted that there was a witness who noticed that the extension of the definition of incident reporting, to include incidents capable of having an impact, was appropriate and exactly in the right place. On the question about the public sector’s inclusion, we are here not to prescribe and wait for a law to tell us what we ought to do in the public sector, but instead to move fast and fix things. In that spirit, the Bill focuses on essential services. Question put and agreed to. Clause 1 accordingly ordered to stand part of the Bill. Clause 2 ordered to stand part of the Bill. Clause 3 Identification of Operators of Essential Services Question proposed , That the clause stand part of the Bill.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I am happy to write to the shadow Minister on that point. My understanding is that a Crown data centre will be in scope if it is providing, as in that particular example, to both the public and the private sector, but I am happy to write to him to clarify that point. The load control market is growing exponentially and we need to make it cyber-secure. For that reason, I propose that clause 6 stands part of the Bill. Amendment 11 agreed to. Amendment made : 12, in clause 4, page 3, line 7, leave out “(acting jointly)”.— (Kanishka Narayan.) See the explanatory statement for Amendment 11. Clause 4, as amended, ordered to stand part of the Bill. Clauses 5 and 6 ordered to stand part of the Bill. Clause 7 Digital services
- 4 Feb 2026 · Protecting Young People Online · Hansard source
More
I thank the hon. Lady for raising that important point. I have engaged deeply and frequently with the Molly Rose Foundation on this issue and wider concerns. We continue to ensure that the monitoring and evaluation of the Online Safety Act’s implementation is in progress—I am engaging regularly on that, and I am happy to continue the conversation.
- 4 Feb 2026 · Protecting Young People Online · Hansard source
More
With the groundbreaking steps in the Online Safety Act 2023, we are protecting children from illegal and harmful content online. The Secretary of State’s first step was to ensure that self-harm and suicide content were made priority offences. We have legislated to criminalise both the depiction of strangulation in pornography and the creation of non-consensual intimate images, making them priority offences. We have now launched a short, sharp consultation to protect children’s experiences online. Under this Government, children’s wellbeing is put right at the heart of our decisions.
- 4 Feb 2026 · Protecting Young People Online · Hansard source
More
We are looking very closely at that. Of course, under the Online Safety Act, platforms already have a responsibility to make sure that young people are not able to access harmful content. In relation to wider access methods—whether virtual private networks or others—we are looking very closely at patterns of behaviour. So far, we have been pretty successful; after an initial spike in the use of some of those platforms, we have seen a levelling-off, which I very much hope continues. We will continue to monitor the situation.
- 4 Feb 2026 · Protecting Young People Online · Hansard source
More
I first pay tribute to my hon. Friend for the depth and breadth of her advocacy for the people of Derby. I can confirm that I would be delighted to ensure that we continue the conversation with young people. I was at a school last week, and I will be in a school this week. I commit to the House that the Secretary of State and I will continue to put young people at the heart of all our decisions.
- 4 Feb 2026 · Protecting Young People Online · Hansard source
More
My hon. Friend is absolutely right: regulation is one part of this issue, but we are also focused on the fundamental aspects of media literacy and education. We are engaging very closely with the Department for Education on a media literacy aspect of the national curriculum to ensure that our young people can spot misinformation and disinformation, and that they are prepared to make the most of online experiences.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q One of the things that we have heard over the course of the day is that the Bill is just one of a range of different ways in which public authorities engage with companies on cyber-security and resilience. I am interested in hearing about the impact the Police CyberAlarm programme has had on the cyber-security and resilience of organisations. What would you like to see going forward? DCS Andrew Gould: I love the fact that you have heard of it. One of the things that we struggle with is promoting a lot of these initiatives. Successive Governments actually deserve a lot of credit for the range of services that are provided. We aspire to be a global cyber-power, and in many ways we are. When you look at the range of services, tools, advice and guidance that organisations or the public can get, there is quite a positive story to tell there. I think we struggle to bring that into one single narrative and promote it, which is a real challenge. People just do not know that those services are there. For those who are not familiar with Police CyberAlarm, it is a Home Office-funded policing tool focused on small and medium-sized organisations that probably do not have the skills or understanding to protect themselves as effectively. They can download that piece of software, and it will sit on their external networks and monitor for attacks. For the first time, it helps us in policing to build a domestic threat picture for small and medium-sized organisations, because everybody has a different piece of the puzzle. GCHQ has great insight into what is coming into the UK infrastructure, but it obviously cannot monitor domestically. Big organisations that provide cyber-security services and monitoring know what is impacting their clients or their organisation, but not everybody else. At policing, we get what is reported, which is a tiny piece of the puzzle. So everyone has a different bit of the jigsaw, and none of it fits together, and, even if it did, there would still be gaps. For SMEs, that is a particular gap. For us, we get the threat intelligence to drive our operational activity, which has been quite successful for us. The benefit for member organisations—we are up to about 12,000 organisations at the moment, which are mostly schools, because we know that they are the most vulnerable to attack for a variety of reasons—is that, having the free tool available, it can do the monthly vulnerability scans and assessments. So they are getting a report from the police that tells them what they need to fix and what they need to patch. We do not publicly offer a lifetime monitoring service, because we would not want the liability and responsibility, and we do not have the infrastructure to run that scale of security operation centre. But, in effect, that is actually what we have been doing for a long time—maybe not 24/7, but most of the time—because we have been able to identify precursor activity to ransomware attacks on schools or other organisations, and have been able to step in and prevent it from happening. There have been instances where officers have literally got in cars and gone on a blue light to organisations to say, “You need to shut some stuff off now, because you are about to lose control of your whole organisation.” To that extent, it has been really impactful, but the challenge for us is how to scale. How do you scale so that people understand that it is there? How do you make it easier for organisations to install? That is one of the things that we are working on at the moment, so that everybody can benefit from the scans and the threat reporting, and we can benefit from a bigger understanding of what is going on. The flip side of the SME offer from our point of view is our cyber-resilience centres. By working with some of the top student talent in the country, we can scale to offer our member organisations across the country the latest advice and guidance, help them understand what the NCSC advice and guidance is, and then help them to get the right level of security policies, patch their systems and all that kind of thing. It helps them to take the first steps on their cyber-resilience journey, and hopefully be more mature consumers of cyber-security industry services going forward. We are helping to create a market for growth, but also helping those organisations to understand their specific vulnerabilities and improve from a very base level.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q Thank you very much to both of you for your insights today. The question on my mind is related, in part, to the point that Jen raised. There are a range of levers at the Government’s disposal in thinking about and acting on cyber-security. I am interested in your thoughts on which parts of the economy ought to be in the scope of regulation and legislative measures, and where effective measures that sit outside of regulation and legislation—guidance being one from a range of non-regulatory measures—would be better suited. Jen Ellis: Again, that is a hugely complex question to cover in a short amount of the time. One of the challenges that we face in UK is that we are a 99% small and mediums economy. It is hard to think about how to place more burdens on small and medium businesses, what they can reasonably get done and what resources are available. That said, that is the problem that we have to deal with; we have to figure out how to make progress. There is also a challenge here, in that we tend to focus a lot on the behaviour of the victim. It is understandable why—that is the side that we can control—but we are missing the middle piece. There are the bad guys, who we cannot control but who we can try to prosecute and bring to task; and there are the victims, who we can control, and we focus a lot on that—CSRB focuses on that side. Then there is the middle ground of enablers. They are not intending to be enablers, but they are the people who are creating the platforms, mediums and technology. I am not sure that we are where we could be in thinking about how to set a baseline for them. We have a lot of voluntary codes, which is fantastic—that is a really good starting point—but it is about the value of the voluntary and how much it requires behavioural change. What you see is that the organisations that are already doing well and taking security seriously are following the voluntary codes because they were already investing, but there is a really long tail of organisations that are not. Any policy approach, legislation or otherwise, comes down to the fact that you can build the best thing in the world, but you need a plan for adoption or the engagement piece—what it looks like to go into communities and see how people are wrestling with this stuff and the challenges that are blocking adoption. You also need to think about how to address and remove those challenges, and, where necessary, how to ensure appropriate enforcement, accountability and transparency. That is critical, and I am not sure that we see a huge amount of that at the moment. That is an area where there is potential for growth. With CSRB, the piece around enforcement is going to be critical, and not just for the covered entities. We are also giving new authorities to the regulators, so what are we doing to say to them, “We expect you to use them, to be accountable for using them and to demonstrate that your sector is improving”? There needs to be stronger conversations about what it looks like to not meet the requirements. We should be looking more broadly, beyond just telling small companies to do more. If we are going to tell small companies to do more, how do we make it something that they can prioritise, care about and take seriously, in the same way that health and safety is taken seriously? David Cook: To achieve the outcome in question, which is about the practicalities of a supply chain where smaller entities are relying on it, I can see the benefit of bringing those small entities in scope, but there could be something rather more forthright in the legislation on how the supply chain is dealt with on a contractual basis. In reality, we see that when a smaller entity tries to contract with a much larger entity—an IT outsourced provider, for example—it may find pushback if the contractual terms that it asks for would help it but are not required under legislation. Where an organisation can rely on the GDPR, which has very specific requirements as to what contracts should contain, or the Digital Operational Resilience Act, which is a European financial services law and is very prescriptive as to what a contract must contain, any kind of entity doing deals and entering into a contract cannot really push back, because the requirements are set out in stone. The Bill does not have a similar requirement as to what a contract with providers might look like. Pushing that requirement into the negotiation between, for example, a massive global IT outsourced provider and a much smaller entity means either that we will see piecemeal clauses that do not always achieve the outcomes you are after, or that we will not see those clauses in place at all because of the commercial reality. Having a similarly prescriptive set of requirements for what that contract would contain means that anybody negotiating could point to the law and say, “We have to have this in place, and there’s no wriggle room.” That would achieve the outcome you are after: those small entities would all have identical contracts, at least as a baseline.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q Thank you all very much for making time. I have an implementation-focused question, perhaps directed at Stuart, but open to all. In practice, it would be helpful to understand how frequent is the case that a single company might provide multiple of the possible services in scope: MSP services, cloud hosting, data centre support and cyber-security services. What ability might we have to identify parts of an organisation that are in scope for particular bits and those that are not? Stuart McKean: You are going to hear the word “complex” a lot in this session. It is hugely complex. I would almost say that everyone likes to dabble. Everyone has little bits of expertise. Certain companies might be cloud-focused, or focused on toolsets; there are a whole range of skillsets. Of course, the larger organisations have multiple teams, multiple scopes and much more credibility in operating in different areas. As that flows down the supply chain, in many cases it becomes more difficult to really unpick the supply chain. For example, if I am a managed service provider delivering a cloud service from a US hyperscaler, who is responsible? Am I, as the managed service provider, ultimately on the hook, even though I might be using a US-based hyperscaler? That is not just to pick on the hyperscalers, by the way—it could be a US software-based system or a set of tools that I am using. There are a whole range of parts that need to become clearer, because otherwise the managed service community will be saying, “Well, is that my responsibility? Do I have to deliver that?”. You are then into the legislation side with procurement, because procurement will flow down. Although I might not be in scope directly as a small business, the reality is that the primes and Government Departments that are funding work will flow those requirements down on to the smaller MSPs. Although we might not be in scope directly, when it comes to implementing and meeting the legislation, we will have to follow those rules.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q One of the themes already emerging in the conversation and in the wider public debate is that, on one line of thought, the right framework is that the law should focus on outcomes, principles and responsibilities, and then delegate specificity to both agile definition over time and specific expertise in sectors. An alternative view says that in looseness there is uncertainty, and we in Parliament should prescribe activity and impact thresholds and what companies should be doing. I am interested in areas across the board where you think prescription is a helpful way to go, as well as in your general experience of the core way and framework through which we have regulated a number of these activities, which is to rely on the agility and expertise in particular sectors, rather than the prescription of activity in primary legislation. Chris Anley: By our calculation, as you say, the number of organisations that fall under the scope of the Bill in terms of the Government’s impact assessment is 0.1% of the private sector, which is one one-hundredth of the tip of the iceberg. We are going to have to adopt a whole-of-economy approach if we are going to secure the UK—we have already talked about the public sector issues. On the Bill itself, we have three main comments. First, the secondary legislation forms the bulk of the technical measures, so we are calling for early consultation on that. Secondly, the Bill imposes additional reporting obligations, adding to an already complicated situation for reporting cyber-incidents in the UK. The reporting obligations trigger at a time of great complexity for an organisation, so we are calling for a single point of contact for reporting all cyber-security incidents in the UK and a single timeline. That may sound like a big ask—an impossible dream. Australia has already done it, and the EU is in the process of doing it in its digital omnibus streamlining package. Finally, in terms of cyber professionals, the passage of a cyber-security Bill through Parliament is a golden opportunity to address the serious problems with the Computer Misuse Act 1990. Cyber professionals who are defending the UK cannot currently do so without risking criminal prosecution. We cannot carry out basic identification and verification actions without potentially committing the offence of unauthorised access to computer material, because a ransomware gang, for example, is unlikely to give us authorisation to identify the command and control system they are using to attack the UK. We support the CyberUp campaign, which is proposing an amendment to the Computer Misuse Act to provide a statutory defence, resting on four strong safeguarding principles. We believe that that would help to protect our defenders while maintaining the integrity of the law. Based on the campaign’s research into the size of the cyber-security industry in the UK, the amendment would not only help to prevent incidents and mitigate incidents in progress, but add 9,500 highly skilled jobs and over £2.5 billion in revenue to the UK economy. Other nations are already benefiting from this type of safeguard, including our oldest ally, Portugal, which has implemented them in its recent amendments to NIS2, which is the exact legislative equivalent of the process we are in today. In summary, please help us to defend the UK by protecting our defenders. Dr Ian Levy: To follow up on what Chris says, we strongly agree on early consultation on the technical detail of the secondary legislation. Somebody said in the previous session that, in security, the devil is always in the detail. Well-meaning text can be massively misinterpreted. We need to be very careful about that, so wide, early consultation is key. On incident reporting, I will make two points. Chris made the point that when you are being asked to report, you are at your most desperate, because you have just found out that you have been attacked and you do not know what is going to happen. A lot of legislation accidentally ignores the victim. When we set up the NCSC, one of the primary things was that we were there to support the victims. I urge you not to lose sight of that. Absolutely, go after and find the culprits later, but in the moment, the victims are absolutely key to this. The second part of that, about a single reporting timeline and a single reporting route, is that it is not just good for the victims but the only way that we generate strategic intelligence. That is one of the things that is missing in the UK—and has been for decades. We have five, six or seven different reporting portals that all characterise things differently and take different types of information, and bringing them together to have a single picture about the actual threat to the UK is incredibly difficult. A single reporting forum could fix that. Ben Lyons: I might distinguish between what organisations need to do and whether organisations are in scope. In terms of what they need to do, the outcomes-based approach is sensible. If you think about when the Johnson Government were consulting on the measures that would go on to form this Bill, that was a time when ChatGPT had not been invented and the geopolitical environment was very different. The world is moving fast, and I think that the cyber assessment framework is a good starting place for what a code of practice could look like, because it is already understood by industry and is outcomes-driven. I agree with the previous comments about incident reporting. I think that there is a lot of merit in the suggestion around a shared portal so that it is easier to report incidents in that moment of dealing with a cyber-attack. Within the regime as envisaged, probably the most important bit with reference to reporting is about improving that early clarity and visibility for the NCSC so that they can help. That is probably where I would place the emphasis, more than on regulators having that information within 24 hours. In that context, an approach that recognises best efforts in that first 24 hours but is focused on tackling the problem will be important for dealing with the issue. On the supply chain, I would say—and we have heard about this before—that there could be more clarity there in terms of who would be in scope for designated suppliers. Thinking a bit around both systemic dependency and the potential for wider disruption would be important factors to give it more clarity. Matt Houlihan: To round off the responses, on the question about finding the balance between specificity and agility, the Bill does a reasonable job at that. We can totally see the need to keep some of the doors open, because not only is the nature of the threat changing rapidly but the nature of technology—and of our capabilities to defend—is changing as well. We have already talked about AI, and we have lots of quantum research taking place as well that will have a big bearing on cyber-security. It is right that the Bill has some agility in it, but it is clear from the responses today that there is a need to tighten it up in certain places. We talked about incident reporting, and having a simpler, more co-ordinated system for regulated entities to work with so that that reporting process is easier. The definition of “incident” itself needs to be looked at, we believe. The idea of an instance not only having, but being capable of having, an adverse effect on information systems opens the door very widely to lots of potential incidents that may need to be reported on. Having a tighter definition there would be very useful. To touch on the point about Secretary of State powers, we feel that the door is a little bit too wide. If you look at legislation such as Australia’s cyber-security legislation from 2018, the Security of Critical Infrastructure Act, that also has some good Secretary of State powers, but there are lots of guardrails contained in it that make it clear that it is a power of last resort, where the entity is unwilling or unable to carry out the remedial action itself. There are also other guardrails contained in that legislation. We urge the Committee and the Government to look at that Act and take inspiration from it to think about where those guardrails could be worked into the UK law.
- 27 Jan 2026 · Rural Broadband: Installation · Hansard source
More
I am happy to give way briefly.
- 27 Jan 2026 · Rural Broadband: Installation · Hansard source
More
I know my hon. Friend is a deeply committed champion for his constituency, so I would be very happy to meet him—both on my own and with my colleague, the Minister for Digital Economy—to look at the issues in his constituency. We are making good progress on delivering these contracts. We have already celebrated the completion of the first three Project Gigabit contracts in Northumberland, Teesdale and north Dorset, which marks an important milestone in our programme. These early completions show that the programme is working, and rural communities are beginning to see the benefits of this investment. The majority of premises receiving Government funding for broadband upgrades continue to be rural. Between April 2024 and March 2025, 89% of the premises benefiting from our interventions in this sector were in rural areas, including proud farming communities. We remain absolutely committed to ensuring that these communities receive the gigabit-capable connectivity they need and deeply deserve. I also recognise, with honesty, that there have been delays to subsidised roll-out across Devon and Somerset in particular, as a result of premises being descoped from contracts under the earlier superfast broadband programme, including in the constituency of the hon. Member for Bridgwater. When suppliers encounter financial, operational or technical challenges, I know that rural communities feel the impact the most, and as a proud representative of rural communities in south Wales, I feel it, too. I want to reassure hon. Members that we are closely engaging with Connecting Devon and Somerset, and with suppliers, to establish a clear path forward. Following the announcement in 2025, descoped premises, particularly in the constituency of the hon. Member for Bridgwater, were made available for suppliers to bring forward proposals under the gigabit broadband voucher scheme. Several suppliers expressed interest, and I am pleased to say that approximately 3,000 premises are now included in approved voucher projects. Around 8,500 descoped premises remain without confirmed commercial or subsidised plans. However, these premises are now being considered for inclusion in the Project Gigabit contract with Openreach. We expect to finalise the amended scope of that contract in the spring. The hon. Member feels that work is urgent, and I do, too. Approximately 3,100 premises in the hon. Gentleman’s Bridgwater constituency are currently included in the Project Gigabit contract delivered by Openreach, and my hope is that this intervention will deliver gigabit-capable connections to homes and businesses across the constituency, such as those in Nether Stowey, North Petherton and Westonzoyland. Although 3,400 premises in Bridgwater were descoped from the previous superfast broadband contracts, almost half of those premises have since been connected through a supplier’s commercial roll-out, without the need for public subsidy. The remainder are included within the scope of the current contract change discussions we are undertaking with Openreach. A healthy, competitive broadband market is fundamental to achieving our national gigabit ambition. Commercial delivery has been and will remain the backbone of the UK’s digital transformation. The majority of gigabit-capable connections have been delivered entirely through private investment. The Government’s role is to create the right environment for such investment to continue at pace. That is why we continue to work in close partnership with both industry and Ofcom to support the roll-out of fibre networks across the UK, including in the most rural and hard-to-reach areas. Our approach is designed to complement commercial build, not to replace it, ensuring that public funding is targeted only where the market cannot deliver on its own. In July last year, we published a consultation on our draft statement of strategic priorities to Ofcom, setting out the Government’s view on the importance of promoting competition and maintaining a stable regulatory environment that gives investors confidence. A predictable and proportionate regulatory framework is essential for suppliers to continue investing billions in our fibre networks. Ensuring that regulation is not lifted prematurely is central to protecting our consumers, which is why competition must be properly established before we can relax regulatory safeguards. That is the approach needed to deliver long-term benefits. I know there has been a question about where the Government are in this process. Our draft statement set out our position on infrastructure sharing, which has become one of the sector’s most important enablers of competition. In particular, Ofcom’s physical infrastructure access product has allowed over 100 alternative networks to roll out fibre using Openreach’s ducts and poles, lowering barriers to entry and helping to accelerate competition. We have asked Ofcom to provide greater transparency on how PIA pricing is calculated and set, because transparency is the underpinning driver of confidence for investors. We are reviewing responses to the consultation on our draft statement of strategic priorities, and we will set out the Government’s conclusions in due course. I of course note the hon. Member’s comments, and we are all hoping for pace as well as rigour in the response to the consultation.
- 27 Jan 2026 · Rural Broadband: Installation · Hansard source
More
Openreach has not made that representation to me. The Government are squarely focused on reaching the 99% target, and we are doing all we can to make sure that all providers are in a place to do so. I am happy to engage with Openreach if it wants to make a representation to me. To ensure that the commercial market can continue to deliver as fast as possible, the Government remain committed to removing deployment barriers. Whether that is done by reforming wayleave processes, improving access to land and multi-dwelling units, enhancing the co-ordination of street works or accelerating planning decisions, every barrier we remove helps the industry to build networks faster and more efficiently. Even with the scale of commercial investment and the ambition of Project Gigabit, the expectation is that some remote premises will remain too expensive to reach with gigabit-capable fibre in the immediate term. We are therefore continuing to consider what more we can do to enable high-quality alternatives for those in the “very hard to reach” category. The satellite market is developing at pace. We expect to see more competition in that market imminently, with rapidly improving terminal equipment, higher speeds and falling costs for end users. We continue to monitor and support the development of that market, recognising its role in connecting the most remote communities. I am conscious of the points made on mobile connectivity, not least those made by the hon. Member for Winchester (Dr Chambers). With increasing 5G coverage from mobile network operators, fixed wireless access is becoming an increasingly viable connectivity option. Ofcom estimates that fixed wireless access delivered over mobile networks is already available to 96% of UK premises, with wireless internet service providers offering fixed wireless access to around 8% of premises. I thank the hon. Member for Bridgwater for securing this important debate, and I thank all Members who have contributed. In response to the hon. Member for Chester South and Eddisbury (Aphra Brandreth), I want to flag that, since Building Digital UK and Freedom Fibre mutually agreed to terminate the Project Gigabit contract for Cheshire, we have launched a new procurement for Cheshire. We expect it to be in place by the spring, and we will be sure to let her know of its progress. Let me be clear that, although challenges remain, the Government are acting. We are committed to working at pace with suppliers, local authorities, communities and devolved Governments to ensure that progress continues. Rural communities must not and will not be left behind as we work towards our goal of 99% gigabit coverage. Given that the hon. Member for Bridgwater brought up wider support for rural communities, I put on record that this Government are squarely on the side of rural communities across the UK, which were abandoned by the previous Government on trade negotiations and farming funding and were not given appropriate representation. Question put and agreed to.
Published records only — not a full account of an MP’s work. How we work →