← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Dame Chi Onwurah

MP for Newcastle upon Tyne Central and West · Labour · United Kingdom

IN THEIR OWN WORDS

An extraordinary debate is going on right now inside and outside AI companies about whether the possibility of AI destroying humanity is more or less than 10%. The European Union is moving ahead with a comprehensive AI regulatory framework, but the UK continues to rely on existing regulation.

EU-UK RELATIONSHIP · 2026-09-10 · READ IN HANSARD

The Pope also highlighted how the billions of online digital twins constitute an unprecedented concentration of power in the hands of a small number of men. Among the many consequences of the 40 years of neoliberalism repeatedly called out by the Prime Minister is a libertarian attitude to technology.

PERSONAL DATA (DIGITAL TWINS) · 2026-09-09 · READ IN HANSARD

But this stealth digital twinning violates the integrity, uniqueness and very personhood of our constituents and of all of us. Digital twins can take many forms, from content creation algorithms and deepfakes to chatbots that reflect aspects of our personalities back at us. It is particularly worrying when children are the target.

PERSONAL DATA (DIGITAL TWINS) · 2026-09-09 · READ IN HANSARD

The automated version of our kids will grow with them, using the power of AI to target advertising and products at them, and worse. The Science, Innovation and Technology Committee has heard about some of the tragic consequences of online grooming by algorithms and chatbots—a vulnerable boy persuaded to kill himself; a vulnerable girl fed…

PERSONAL DATA (DIGITAL TWINS) · 2026-09-09 · READ IN HANSARD

In the arts, entertainment and tech industries, many performers are agreeing to the creation and use of digital replicas as part of their work—think of ABBA Voyage. But performers increasingly encounter unauthorised digital replicas of themselves, which pose a threat to their career, livelihood and reputation.

PERSONAL DATA (DIGITAL TWINS) · 2026-09-09 · READ IN HANSARD

Since then, deepfakes have proliferated. The hon. Member for Mid Norfolk (George Freeman) was shown crossing the Floor in Parliament to join Reform, to his constituents’ consternation and his own—it was a fake. Then there were the horrendous photos of naked women and girls that Elon Musk’s AI created on demand.

PERSONAL DATA (DIGITAL TWINS) · 2026-09-09 · READ IN HANSARD

The complete record

Every one of 5,139 lines we hold for Dame Chi Onwurah, in date order, each linked to its source. Free to read, in full, without an account. Page 37 of 103.

  1. In his response, will the Minister give us some idea of why the Secretary of State might need to set out additional specified requirements that are not in the draft of the TSR that he has published? Is the intention of the clause to enable him to set out additional specified requirements, or is it to enable him to highlight particular specified requirements that he does not think the providers are meeting quickly enough? In either case, does that not suggest that there are particular security concerns, either about providers or about the circumstances, that require these specific security measures? To come back to my first point, does that not highlight for those concerns to receive parliamentary scrutiny, with the appropriate clearance, which is to say that of the Intelligence and Security Committee?

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  2. Considering specifically the impact of the requirement to remove Huawei at this stage in our 5G roll-out—the economic impact, the cost to the providers and the cost to our economy—we recognise that it is the right thing to do, but we must also recognise the cost of doing it. Back in 2013, the ISC was one of the first parliamentary organisations to raise the issues around Huawei. I truly urge the Minister to accept this constructive amendment to support the appropriate provision of scrutiny. My other point is more about the working of the clause, which gives the Secretary of State the power to make regulations that require providers to take specified security measures. As we know, the telecoms security framework and telecoms security requirement, to which all providers must adhere, will be set out in delegated legislation.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  3. I will not detain the Committee long, given that my right hon. Friend the Member for North Durham made such excellent points. I will add one point of consideration, which again, his modesty may have forbidden him from making. The amendment goes to the heart of our concerns about the scrutiny of the provisions in the Bill. I say again for the record that we support the wide-ranging powers that the Bill gives the Secretary of State, but those powers must come with appropriate scrutiny, not because scrutiny is a “nice to have” or, as my right hon. Friend said, because the ISC needs further work, but because scrutiny of the provisions is essential to the good working of the legislation in practice.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  4. In addition, the Government have not provided a plan for locating and removing Huawei from our networks; instead, they have opted to leave it entirely to private sector providers. That might seem appropriate, but as someone with 20 years’ experience in the telecoms sector, I have to say that it is generally not the case—I am not insulting any individual provider—that providers know exactly where every bit of equipment is located and what level of software or build is associated with the equipment.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  5. The amendment goes to the heart of two of our key themes: the scrutiny of the powers in the Bill and the effectiveness of the accompanying diversification strategy. It is a probing amendment, designed to enable us to understand—or to have the Minister clarify—plans to ensure that network operators carry out a comprehensive audit of hardware that is relevant to the Bill because, for example, it is manufactured by a designated or high-risk vendor. We tabled the amendment for a number of reasons. The first is the Government’s decision, which we welcome, to strip Huawei out of our telecommunications networks. There are questions about where that equipment is located, the level of software provision, and in particular the exact nature of the revision of the equipment within the network.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  6. I beg to move amendment 21, in clause 1, page 3, line 26, at end insert— “(2A) The Secretary of State must make regulations under subsection (1) requiring providers of public electronic communications networks and public electronic communications services to carry out an audit of the goods, services and facilities supplied, provided or made available for the purposes of the provision of their network or service to ascertain whether they present a risk to the security of that network or service.” This amendment is a probing amendment designed to learn how the Government plans to ensure network operators have a comprehensive audit of hardware of interest because, for example, it is manufactured by a designated or high-risk vendor.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  7. Indeed, providers should have this information already, but I know from my own experience and the experience of those who gave evidence, which I will come to in a moment, that this is not always the case because networks are so complex, and because our networks today have built up over decades and decades. There is software running in some of our networks that has been around for 40 or 50 years, as well as copper lines that have been around for even longer. So it is not always the case that this information is known.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  8. I am slightly confused, to be honest, because there was a contradiction there. It is a basic, inherent requirement under the Bill to understand the security implications of a network—the security implications, the security threat and future compromises. It goes to the amendment tabled by my right hon. Friend the Member for North Durham. Given that different components might provide different threats, it is essential to understand the kit that is in the equipment in order to meet the requirements of the security framework. So no, I do not think it is draconian that there should be an audit of the equipment.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  9. A basic and critical requirement for the Bill to be effective is to have a more diversified supply chain. More suppliers go hand in hand with a diversified supply chain, and therefore different types of equipment, of which we will need to keep track.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  10. As always, my hon. Friend makes an excellent point. Indeed, the audit, which I agree is burdensome if the information is not already in the management systems, which it should be, would, I hope, be less burdensome than the potential fines for not meeting the basic requirements of knowing what is in the network and where it is. Also, that challenge has been made more complex by the subcontracting of different parts of the telecoms networks. For example, network providers such as Vodafone or Three have primary vendors—currently Ericsson or Nokia—but there might be subcontractors who provide particular elements of the network and particular management elements. We hope that that will be increasingly the case as we seek to open up the supply chains and make them more diverse.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  11. We want a level playing field, particularly because the 2019 UK Telecoms Supply Chain Review said that there was not an incentive for security in mobile networks. It concluded specifically that there was no incentive for security in mobile networks. Given that conclusion and some of the points provided in the evidence sessions, the Bill does not address incentives to ensure security by design in our mobile networks. It has burdens and fines for not doing that, but it does not have positive incentives.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  12. My right hon. Friend makes an excellent point. As someone who worked for a regulator for six years, I might be expected to agree with my right hon. Friend on the point of regulation; in this context, regulation should not be seen as a burden. As my hon. Friend the Member for City of Chester set out, it should be seen as a carrot—an incentive—to get things right. Imagine we had known and been able to see how Huawei’s presence in BT’s network, over the last 15 years or so, would rise from small beginnings to becoming the principal vendor. That might have rung more alarm bells and been an incentive to have transparency. Regulation is also about levelling the playing field and enabling more effective competition. The better providers will do that, but some providers may not.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  13. I am not sure that it is necessary to have it on the face of the Bill, and it might be that it will be provided for in delegated legislation, but we need a clear and strong strategy for the detection and removal of high-risk components, vendor hardware and software. Otherwise, the Bill will not protect our national security effectively. I hope the Minister will give clarification on that.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  14. 52, Q67.] Ofcom said that it was more or less impossible to meet the requirements set out in the codes of practice for the operators, unless it had a detailed asset register of everything in its system. We will expect to see evidence of that, and we expect that it will be regularly checked, audited and so on. We recognise the potential costs of an audit, particularly for smaller providers, although most of them have newer networks and equipment and should have a lot of this information already available. Ofcom is anticipating that this is something it would need to have access to, yet there is no requirement in the Bill or, as far as I can see, in the delegated legislation that has been published to make that requirement. I have mentioned that this is a probing amendment.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  15. 13-14, Q10.] Dr Bennett said: “I would hope that those at the top level are clear about it, but I would be surprised if there were not occasions when they had used subcontractors to do maintenance and the imperative had been to sort out the fault ASAP. Knowing precisely what components had gone in could be wrong, and that might come up in an audit. I think it becomes more important as you flow down the levels.” –– [ Official Report, Telecommunications (Security) Public Bill Committee, 14 January 2021; c. 49, Q62.] Dr Bennett later said: “I have said that audit is needed of the assets in the network. The costs of being audited and of dealing with audits are very high, and they are costs that small companies may not have the resources to meet.” –– [ Official Report, Telecommunications (Security) Public Bill Committee, 14 January 2021; c.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  16. For example, Andrea Donà said: “It is vital that the secondary legislation that accompanies the Bill clarifies assets in the telecoms network architecture that will be in scope of the security requirement, so that we can work knowing what we have audited, and knowing that the auditors always shared with NCSC. We need a clear understanding between Ofcom and us as providers before the legislation is enforced, so that we understand exactly the boundaries and the scope, and we all work together, having done the audits, to close any vulnerabilities that we might have.” –– [ Official Report, Telecommunications (Security) Public Bill Committee, 14 January 2021; c.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  17. Again, my hon. Friend makes an excellent point with regard to the way in which Huawei grew in the telecoms sector. I do not want to detain the Committee on that history, but Huawei grew by under-cutting existing vendors, building up scale and making its profits by locking in network providers, despite issues with the quality of the equipment, which, as we have discussed, our security services identified. Having visibility of network equipment, as well as the level of concentration of any one provider, will enable us, in part, not to get into such a situation of dependency in future. Again, I would emphasise that this is about incentivising what should happen but is unfortunately not always the case. That is not simply my view or that of the Labour party; it is the view of witnesses who participated in our evidence sessions.

    TELECOMMUNICATIONS (SECURITY) BILL (FIFTH SITTING) · 2021-01-21 · READ IN HANSARD

  18. My right hon. Friend is making some excellent comments. He has raised another issue, which I perhaps did not highlight in my speech, which is that there might be existing equipment that is not necessarily seen as having a security implication but that, as the network evolves, will pose a security threat in the future. I gave an example in the evidence sessions. Say Amazon Web Services was to be bought by a Chinese company. As our networks move the functionality into the software, that will be running in the cloud over the Amazon Web Services infrastructure, which would have a huge potential security impact. An effective audit of where that equipment is now would be critical to knowing the level of that threat.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  19. Part of the challenge is that the operators do not know themselves and, as we have discussed, there are no incentives for them to find out. To give an example, Virgin Media took over from NTL, which I think took over from the 13 different cable providers in the franchises of the ’80s, and the BT mobile network was bought partially from EE—so there are takeovers and acquisitions, and partners may not know, and do not necessarily have an incentive to find out unless we put in a requirement.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  20. I ask him to write to me, if possible, stating which provisions in the requirements set that out. I beg to ask leave to withdraw the amendment. Amendment, by leave, withdrawn. Question proposed, That the clause stand part of the Bill.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  21. It is a pleasure to serve under your chairmanship, Mr McCabe, and I thank the Minister for his comments. I also thank my right hon. Friend the Member for North Durham and my hon. Friend the Member for City of Chester for their comments. This amendment is probing, so we will not push it to a Division. I would like to say two things to the Minister. Although it is true that the providers were confident that they had an asset anywhere their equipment was, other experts who gave testimony in the evidence sessions were not. My experience of networks is that there are multiple systems and this information is not easily accessible or searchable. I am reassured by the Minister saying that his view is that these requirements could not be met without there having been some kind of audit, to have that information ready.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  22. If he cannot do so now, perhaps he will write to me.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  23. As the Minister says, reaching the end of consideration of clause 1 is a landmark. We are cracking on at a slower pace than anticipated, but it is important that we have rehearsed a number of the arguments that you will hear, Mr McCabe, throughout our detailed scrutiny of the Bill. Those arguments relate to our concerns with regard to national security, which Labour prioritises, yet we do not see that priority recognised consistently in the Bill; the effective plan to diversify supply chains on which it depends, but which it does not mention; and the scrutiny of the sweeping powers that the Bill will give to the Secretary of State and Ofcom. Those issues all arise in the clause, although we welcome the Bill and the increased duties. Will the Minister clarify the relationship between proposed new section 105A and proposed new section 105B?

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  24. Clause 2 accordingly ordered to stand part of the Bill.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  25. We are cracking on: clause 2 is taking but a few minutes. The Opposition recognise the critical importance of our network providers taking responsibility for the security of their networks, and that there can never be a zero-risk network. Given that network communications are ever present in almost every aspect of our life and of our nation’s economy and security, it is right and appropriate that the Bill should put requirements in place, both on the operators and in response to specific security compromises. I should like to have better understood how we would expect network operators to respond to a compromise such as the SolarWinds one, for example, but I expect that the clause will at least place the right duties on network operators, and I am content that it should stand part of the Bill. Question put and agreed to.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  26. 89, Q113.] In introducing the code of practice, it is essential to ensure that security input and expertise. I do not see why the Minister would object to including such a requirement in the Bill. Unfortunately, we are not always as joined up as we would like to be. There are numerous examples of issues that could have been prevented, had agencies of Government done what might have been expected of them and talked to teach other. As the Bill involves network operations and deep technical and security issues, a requirement to consult the NCSC is particularly important, and that is what the amendment would achieve.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  27. The Bill looks at many issues to ensure the security of our networks from supply chains to requirements on network providers as well as raising technical issues, and Ofcom will need to do a lot specifically, so it is important to have a specific reference to the security function of the National Cyber Security Centre. It came across clearly in the evidence sessions that Ofcom will not be making national security judgments. Lindsey Fussell said: “It is important to say that, across the scope of the whole Bill, it is not Ofcom’s role to make national security judgments. That is really important. Clearly, that is the Government’s and the Secretary of State’s role, taking advice from the NCSC and the intelligence agencies.”—[ Official Report, Telecommunications (Security) Public Bill Committee, 19 January 2021; c.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  28. I rise to support my right hon. Friend’s excellent comments and to add a couple of points on amendment 10, which would require the Secretary of State to consult the National Cyber Security Centre before issuing a code of practice about security matters. My right hon. Friend spoke ably about the amendment’s intent to ensure security input on national security measures. That sounds basic, so I hope the Minister will explain why he feels it is unnecessary to make that explicit in the Bill. My right hon. Friend suggested that perhaps it should go without saying, but as we heard in the evidence sessions and have already discussed, the evolving security landscape and the change that the Bill represents, through the new powers for the Secretary of State and Ofcom, make it particularly important to set that out expressly.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  29. I thank the Minister for his response to the amendments. He is focusing on the fact that it is possible for information to be shared, but it is not required. I understand that the Bill as drafted, and preceding best practice, means that it is possible for information to be shared. My concern is that it is not required.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  30. Clause 4 Informing others of security compromises Question proposed, That the clause stand part of the Bill.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  31. At the same time, it is important to have a proportional burden on new entrants as we indeed hope to diversify the supply chain. I understand, although perhaps the Minister can clarify the point, that the codes of practice will not refer to the diversification of the supply chain, despite the fact that having a secure network—we shall debate this in more detail—is dependent on having a diverse supply chain. I have made the point a number of times, and will make it repeatedly, that the lack of linkage between the diversification strategy, implementation and the security of our networks is an ongoing cause for concern. However, having made those comments, I do not object to the clause. Question put and agreed to . Clause 3 accordingly ordered to stand part of the Bill.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  32. I will not detain the Committee very long either, as we agree about the importance of codes of practice. I will not say that I am entirely reassured to hear of the statement being issued by Ofcom and the NCSC on how they will work together, but I certainly think that it is a positive development, and I hope we will be able to see it before the Bill progresses to the House. On the codes of practice, as my right hon. Friend the Member for North Durham set out, it is important that the sector should understand the standard to which it will be held. I have some concerns about the tiering system, because, as was made clear by a number of witnesses during the evidence sittings, all networks are joined up and we are only as secure as the weakest link.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  33. I thank the Minister, as always, for graciously giving way. I will make this point later, but I want to give the Minister the opportunity to consider how the requirement for Ofcom to notify users might work with the Information Commissioner’s requirement on data controllers to also notify users when there is a data hack.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  34. Is my right hon. Friend aware that the hack used by the young person had been around for longer than that young person had been alive? That is an indication of the low level of security TalkTalk had in their network; they had not been able to address a known hack that had existed for at least 16 years. The Bill aims, in part, to address that and the consequences of that lack of security for our constituents.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  35. If that is clearly set out in the Bill, I am unable to find it. Presumably, such data sharing will still have to conform with the requirements of our data protection legislation. Will it also reflect international data-sharing gateways for criminal prosecution purposes? Those are just some general comments. We welcome the clause.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  36. There is some indication of the range of actors that the providers and Ofcom must inform, but I do not feel that there is an understanding of the level of information that will be shared with different actors. For example, if the public are to be informed of a security breach, compared with the requirement from the Information Commissioner’s Office, which, as I said, actually goes far enough, what level of information might be shared with other actors, such as other networks? My right hon. Friend talked about who else might be informed. It is also clear that the sharing of information will probably need to evolve over time, as the nature of compromises and their potential reach changes. I wonder how these requirements might be adapted to reflect that. I will just say a little about the sharing of information with overseas regulators.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  37. We are cracking on at such a pace that I lost my place somewhat. I had forgotten that we are now discussing clause 4. My apologies, Mr McCabe. My right hon. Friend the Member for North Durham has already addressed some of the points that I wanted to make, but let me say that we welcome the duty being placed on providers to report security incidents. I have long campaigned, in relation to cases such as the TalkTalk incident, to make that duty clearer and more comprehensive regarding the information that needs to be shared with users and those who are affected, and for them to have some kind of right of redress, which is effectively part of the Bill. I welcome the requirement in clause 4 to inform others of security compromises, but will the Minister provide more clarity?

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  38. The Minister is being incredibly generous with his time. To clarify what we are hoping to receive, as he has indicated, we would not want the ICO to be sending out notifications to 2 million people who had been affected by a hack, and Ofcom to be doing that as well. We would expect there to be co-ordination in that regard, and we would just like to see that set out.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  39. We have also already mentioned the shift that we are seeing on the importance of software and software configuration and services in controlling the network. Requiring providers to notify Ofcom of planned or actual changes to the network would make that evolution more easily visible and therefore provide Ofcom with greater visibility of how all our networks are evolving and what new threats may arise as a consequence.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  40. I admired Ofcom during my time there because it was set up to be a forward-looking regulator. To achieve that aim, when it comes to the sweeping new requirements around security that are placed on it under the Bill, it needs to be able to see what changes are happening and are likely to influence future evolving threats. To do that effectively, amendment 11 requires the network providers to notify Ofcom of planned or actual changes. It is worth remembering that—I made this point earlier—if BT had been required to notify Ofcom or another body of changes to its network as Huawei moved to a greater and more dominant position in its network, that might have rung alarm bells more generally.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  41. I rise simply to support the excellent speech made by my hon. Friend the Member for City of Chester. I thank him for his very kind words. In the amendment, he makes an important contribution in ensuring that Ofcom knows what it needs to know and in putting the onus more firmly on the network providers. I simply ask the Minister to respond to the points that my hon. Friend made in his concluding remarks about being forward-looking. A challenge for us as a nation in securing our networks during such fast-paced technological change is looking backwards to the problems we have had rather than forwards to the evolving and new threats. During the evidence sessions, we were accused of fetishising 5G as if that was the only security challenge, because of the visible problem with Huawei, and that we were not looking more broadly.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  42. I thank the Minister for giving way; in doing so, he shortens what I will say later. I think the Minister is saying that Ofcom has the power to require information, which is true, but the amendment is about providers proactively giving that information. Ofcom cannot request information about a change to the networks that it does not know is happening. I am hoping that perhaps what the Minister is implying is that he would expect Ofcom regularly to review what was changing in the networks and therefore make those requests for further information. Could he clarify that point?

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  43. The impression that I have given my hon. Friend about the telecoms sector being tight-knit is absolutely right. One concern that that brings is that there will therefore be conflicts of interest. Ofcom, as a public servant with the status of a quango, has rules and regulations for declaring interests that mean previous conflicts of interest will not weigh into its work. The concern that I have articulated to my hon. Friend in the past is that that would not apply to “other persons”, so broadly defined.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  44. My right hon. Friend the Member for North Durham raised the Test and Trace programme. I do not want to dwell on that, as it is not within the scope of the Bill, but it is important to understand the extent to which the programme has been used as a vehicle to privatise parts of the NHS by building up private sector skills as opposed to public sector skills. There must be some concern that the huge new powers for and requirements on Ofcom might effectively be used to privatise some of its duties.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  45. That likely cost is within scope of any programme that is to be carried out by bringing in large private sector organisations. I hope the Minister will reassure us that he is taking these considerations into account. Finally—I think we will discuss this point in more detail—this is a huge additional requirement on Ofcom. In the evidence session, Ofcom said that it thought it would need to hire 50 or 60 people to address the requirements of the Bill. There is always going to be an inclination to reduce internal resources, especially if they are in short supply, such as those to do with network engineering resources and the current skill set. So it is really important that the Bill should have a better definition than it currently does of who may carry out the work.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  46. It is also the case that, unfortunately, as a regulator, one can be subject to regulatory capture by those who are regulated. The large operators often have tens or, in some cases, hundreds of lawyers and public affairs spokespeople. However, the smaller operators, unfortunately, cannot afford to dedicate so much time and resource to engaging with the regulator. It is critical that this huge increase in new powers and work for Ofcom is carried out in the right way. As my hon. Friend said, the £50,000 figure has not been calculated on the basis of the likely costs to Ofcom, because the impact assessment does not indicate what they could be. However, it is merely the cost of five consultants at £1,000 a day for 10 days. We know that hundreds of consultants have been hired as part of the Test and Trace programme at those sorts of prices.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  47. Again, I rise mainly to support the excellent contributions made by my hon. Friend the Member for City of Chester in moving this amendment. I will raise a couple of points from my experience in this area. As I said to my hon. Friend, having worked in telecoms for 20 years, when I joined Ofcom in 2004, I had worked with, or worked with someone who had worked with, just about every operator and network provider in the business. Those personal relationships can be helpful in ensuring quick, effective collaboration, but they can also bring about conflicts of interest. Ofcom, as a public body, has processes and procedures to address those conflicts of interest. However, the Bill makes no provision for that to be applied to whoever is “another person”.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  48. I am somewhat concerned at the implication of what the Minister says. We cannot put a price on national security, and Ofcom has a role. In an evidence session, Ofcom’s representatives said that although its role excludes any question of its making security decisions, it would ensure compliance, yet now the Minister seems to be saying that Ofcom will not have the skills to ensure compliance. I agree that there are specialised skills. Penetration testing, for example, is a specialised skill, but I would argue that it is a skill that Ofcom should take on as part of this new remit. I say again to the Minister that the skills needed to ensure compliance should be within Ofcom’s remit, or should be better defined.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  49. Actually, the amendment would not limit Ofcom’s discretion to bring in additional resources or skills. It would limit Ofcom’s discretion to Government agencies or organisations within the public sector, which, on matters of national security, we should be able to do.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD

  50. My argument is that it is not possible to do that without understanding the diversity of that network provider’s supply chain; yet the clause as it stands makes no reference to that.

    TELECOMMUNICATIONS (SECURITY) BILL (SIXTH SITTING) · 2021-01-21 · READ IN HANSARD