Dame Chi Onwurah
MP for Newcastle upon Tyne Central and West · Labour · United Kingdom
“An extraordinary debate is going on right now inside and outside AI companies about whether the possibility of AI destroying humanity is more or less than 10%. The European Union is moving ahead with a comprehensive AI regulatory framework, but the UK continues to rely on existing regulation.”
“The Pope also highlighted how the billions of online digital twins constitute an unprecedented concentration of power in the hands of a small number of men. Among the many consequences of the 40 years of neoliberalism repeatedly called out by the Prime Minister is a libertarian attitude to technology.”
“But this stealth digital twinning violates the integrity, uniqueness and very personhood of our constituents and of all of us. Digital twins can take many forms, from content creation algorithms and deepfakes to chatbots that reflect aspects of our personalities back at us. It is particularly worrying when children are the target.”
“The automated version of our kids will grow with them, using the power of AI to target advertising and products at them, and worse. The Science, Innovation and Technology Committee has heard about some of the tragic consequences of online grooming by algorithms and chatbots—a vulnerable boy persuaded to kill himself; a vulnerable girl fed…”
“In the arts, entertainment and tech industries, many performers are agreeing to the creation and use of digital replicas as part of their work—think of ABBA Voyage. But performers increasingly encounter unauthorised digital replicas of themselves, which pose a threat to their career, livelihood and reputation.”
“Since then, deepfakes have proliferated. The hon. Member for Mid Norfolk (George Freeman) was shown crossing the Floor in Parliament to join Reform, to his constituents’ consternation and his own—it was a fake. Then there were the horrendous photos of naked women and girls that Elon Musk’s AI created on demand.”
The complete record
Every one of 5,139 lines we hold for Dame Chi Onwurah, in date order, each linked to its source. Free to read, in full, without an account. Page 38 of 103.
“If every aspect of its network is supplied by, let us say, Ericsson, and Ericsson then has supply issues itself or is bought or acquired by another operator from a different country that we might not be so close to, or—I do not mean to imply that this is a possibility—should fail in some way, that network provider no longer has any support for their network and no longer has the ability to maintain it securely. The dependence of our telecoms security on diversifying the supply chain was set out in the 2019 telecoms supply chain report; yet the Bill fails to mention it at all. The objective of the clause is really for Ofcom to assess how successful a network provider is in meeting our nation’s security requirements.”
“The worst-case scenario for creating a risk in this sense is when monopoly meets supply chain—in secure supply chain in this case. Arguably, the reason why SolarWinds was so successful is that it provided the same service to so many different organisations and departments in the United States. Therefore, if you access one—SolarWinds—you access almost all. That is the risk.” –– [ Official Report, Telecommunications (Security) Public Bill Committee, 19 January 2021; c. 87, Q110.] The reason I have highlighted that particular quote—there were a number of quotations supporting the diversification of supply chains—is that it sets out really well what might happen if a network provider has only one possible supplier.”
“As I have said, this is an integral part of the Bill and requires some considerable debate, so it may detain the Committee for some time, but this debate can be continued at a later time if necessary. There is a long list of requirements that Ofcom might place on network providers, but nowhere is there a requirement for those providers to give a report on the diversity of their supply chains, yet the diversity of a network provider’s supply chains is absolutely integral to the security and resilience of that network provider. We heard that very clearly during our evidence sessions. In particular, I asked Dr Drew: “Is it possible for the UK to have secure networks without a diverse supply chain for them?” Her answer was: “That is a great question that comes with a very simple answer: no.”
“The objective of the amendment is to give Ofcom the power to “request a report from a network provider on the diversity of their supply chains for the purpose of assessing whether they are complying with the security duties placed on them by earlier sections of the Act.” As we have heard, clause 6 amends the Communications Act 2003 to insert section 105N, which gives Ofcom powers to assess compliance with the security duties set out in earlier sections, and section 105O, which gives Ofcom the power to impose on providers the duty to do any of a significant list of things, from (a) to (k)—to “carry out specified tests or tests of a specified description…make arrangements of a specified description…direct an authorised person to documents on the premises…” or “assist an authorised person to view information”.”
“I beg to move amendment 13, in clause 6, page 10, line 20, at end insert— “(aa) provide a report on the diversity of their network’s supply chains;” This amendment gives Ofcom the power to request a report from a network provider on the diversity of their supply chains for the purpose of assessing whether they are complying with the security duties placed on them by earlier sections of the Act. It is a great pleasure to speak to this amendment, which goes to the absolute heart of one of our key concerns about the Bill—the lack of any reference to the diversification of our supply chain. That is absolutely critical and should be integral to our national security. Our amendment 13 affects clause 6, which we have already discussed.”
“I thank the Minister for those comments. He says that the provision is already in clause 12. This is obviously down to my lack of studying, and I thought that I had studied every line of the Bill, but where specifically does clause 12 refer to diversification of supply chains?”
“Clause 12 mentions “information concerning future developments of a public electronic communications network or public electronic communications service that could have an impact on the security of the network or service.” I agree that that could be liable to an interpretation that included diversification of the network, but given that the Bill does not anywhere mention diversification of the supply chain as being part of the security of the network, I am afraid I do not feel reassured.”
“I thank the Minister for that, but I am still puzzled as to where clause 12 says that Ofcom will collect data with regard to diversification of the networks. Ofcom is given the power to collect data with regard to the duties under the Bill, but there is not a duty under the Bill to diversify networks. I am trying to speed-read clauses and subsections; perhaps the Minister can direct me to a part of the clause that specifically requires information concerning.”
“We all agree that the Minister is someone whom we like and who has the best intentions. On that basis, and on the basis that we can table further amendments at this stage or on Report if his letter of reassurance should not be sufficiently reassuring, I beg to ask leave to withdraw the amendment. Amendment, by leave, withdrawn. Ordered, That further consideration be now adjourned. — (Maria Caulfield.)”
“It continues: “In summary, the evidence shows an increased risk for Black and South Asian ethnic groups.” How can the Minister correct the record in what is a really important area and a subject of great concern to many black and ethnic minority communities?”
“On a point of order, Madam Deputy Speaker. I wonder whether I might seek your advice. During Women and Equalities questions last week, the Minister for Equalities told me that her first report on the disproportionate impact of covid-19 on ethnic minority groups in October had concluded that there was no evidence suggesting that ethnicity itself is a risk factor. That is not correct and creates a false impression. The detail of workstream 3 of the four workstreams that form “Term of Reference 3” states: “Further data, research and analysis on the above factors is needed to fully understand the disparities from COVID-19 to ethnic minorities.” That is the point that I was making.”
“The Government were reminded again in 2014 when they let our foremost artificial intelligence firm, DeepMind, be acquired prematurely by Google: national security interests outsourced again on account of blind market faith. They were reminded twice this time when they let our world-leading semiconductor firm Arm be taken over first by SoftBank and now by Nvidia. Again, an intelligence expert told our Committee that the UK had limited freedom of choice in this key strategic technology and that the deal undermined our own ability: our national interest outsourced yet again by Ministers prioritising market zeal over British security.”
“We support the Bill, because it is a Bill demanded by Labour. The problems it tackles are ones that have been highlighted by Labour, and the Government’s action, only after years of delay, seems to be a result of being constantly reminded by Labour. Reminded this Government have been, not least by their failures again and again. They were reminded in 2012, when they let the Centre for Integrated Photonics, a prize British research and development centre, be taken over by Huawei, an event that our recent head of the National Cyber Security Centre said we would not want to happen with hindsight: national security outsourced and British interests relinquished to the market.”
“It is a great pleasure, as always, to follow the Chair of the Intelligence and Security Committee, the right hon. Member for New Forest East (Dr Lewis), and I support many of his remarks. Let me start by saying that the Opposition’s approach to this Bill is one of constructive support. That should not surprise the Minister: by the Committee stage we had already tabled nearly 30 targeted amendments and half a dozen new clauses to strengthen protections of our national security, although, regrettably, the Minister did not choose to accept any of them. As the Minister is also responsible for vaccine roll-out, he may have been distracted. I want to thank everybody—all the members of the Committee and the House staff involved in the Committee stage of the Bill—and confirm that we intend to continue that constructive support.”
“Of course, by the time you get to that point, they will have deployed most of their 5G network already, so it feels as though open RAN will be too little too late to have a significant impact on diversifying the 5G networks that we have in this country and that we will have for the next few years.”
“That is why we see people like Vodafone trialling open RAN in those places. Although Mavenir has all the ticks in the boxes, it does not yet have work-through with the operators to deliver something that really works for all of its network. As we have heard from the operators, that is a long, slow process. The operators are rightly risk averse—they do not want to rush out a whole load of equipment and for their networks to fail after a few months, with all the problems that that would have for consumers. So it seems to me that we are still some time away—I think the operators have said five, six or maybe seven years—from any significant deployment of open RAN. That sounds very plausible to me as a strategy for evolving a network.”
“I am sure Mavenir is correct that it can sell equipment that can do 2G, 3G, 4G and 5G, but that is not sufficient for an existing operator. If an operator wants to put this equipment into its network, it needs to work with its network diagnostic systems; it needs to handle all of the various features that it might deliver to customers, businesses or whatever, or that it might use for optimising its network or the various software systems that it has. It has built these up over 20 or 30 years, so adding in the equipment is a lot more than simply ticking the box and saying that it can transmit 2G or 3G. That takes quite some time, particularly with the more complex base stations that we find in city centres. The ones in rural areas are typically much simpler and less problematic if they go wrong.”
“Q It is a pleasure to serve under your chairmanship again, Mr Hollobone, and thanks very much to the witnesses for joining us this morning. I should declare that William and I worked at side-by-side desks at Ofcom for some years, so I am well aware of his expertise in this area. I have a couple of questions, starting with you, William. We heard from Mavenir on Thursday that open RAN could provide 2G, 3G, 4G and 5G networks now, but the operators were not looking to purchase networks from it. What is your view on the accuracy of that statement and the maturity of open RAN? What challenges does that pose with regard to the diversification strategy set out by the diversification taskforce? Professor Webb: Thank you, Chi.”
“They can make that choice and that will pull through the decisions to them, rather than the Government trying to decide on their behalf what the best technology for them to use might be.”
“Q What would your recommendations be in terms of an effective diversification strategy? Where is the capability strong? Professor Webb: If I wanted to diversify, I would instruct the telecoms operators to diversify. I would not try and pull the levers one step removed. I would say to the telecoms operators, either with a carrot or a stick, “You must diversify. If you have x number of vendors in your network, I will give you £x million as a carrot.” The stick might be some kind of licence condition that said, “In order to meet your licence, you have to have at least x number of vendors in your network.” That seems to me to be the way to pull through, and then the operators can decide whether they want ORAN, something like NEC or Samsung or someone like that.”
“Of course, the foreign investment security strategies are all part of this as well, but you make a key point. If Amazon Web Services was sold to a frenemy country, that would potentially introduce the same kind of, at least theoretical, security risks that we have been troubled by over Huawei and 5G. It is also the case that consolidation of infrastructure providers, like the cloud providers, is a security risk, because they become too big to fail. There was a brief outage of Google just before Christmas, and people just cannot work. When Cloudflare or Dyn go down, they introduce massive outages, particularly at a point where we are all so reliant on technology to do our work. These are security risks, and that highlights the need for a flexible approach. You have to be looking across all sectors.”
“One of my reflections on open RAN is that, although, of course, I am excited at the idea of open, interoperable standards, which would prevent vendor blocking, most of my experience has been in the internet environment rather than the mobile environment, and we are replete with open, interoperable standards, but we have a major competition problem. That in itself is not going to be enough of a lever to secure diversification. On the point about acquisitions, particularly where you have cutting-edge technologies coming through, this country is really good at R&D—we have wonderful universities full of very brainy people who are creating things—but there does not seem to be the follow-through to create world-beating companies that can compete across the world stage. Why is that? It is because they either get sold to the US or to China.”
“Ciaran Martin spoke eloquently yesterday about the need for flexibility in what critical national infrastructure is. The last year has shown us that what is critical very much depends on what you are going through at the time. Healthcare systems probably would not have been top of the list two years ago, but now they are. The SolarWinds attack shows that the identity of the vendor is not always the key risk point. SolarWinds is a very trusted vendor from a like-minded, close ally country, and yet it turns out to be a critical single point of failure across key, very sensitive Government Departments, both in the US and the UK. Thank you for talking about consolidation across cloud services, Chi.”
“Q Emily, what other security threats are not fully addressed by the Bill? How can we ensure that our networks are resilient to future security threats? I am thinking of the consolidation in cloud services, for example. As we move to more software-based networks, more and more of the value is in the cloud services. Say, for example, Amazon Web Services was bought by a Chinese company. Would you consider that a threat to the security of our networks? Emily Taylor: Thank you very much for those questions. As a general point about the cyber-security of critical national infrastructure, I feel a little like we have been fetishising 5G and a single company for the last two years, perhaps at the expense of a more holistic awareness of systemic cyber-security risks.”
“Here in Cambridge there is a plethora of wonderful consultancies and start-up companies. In my experience, the biggest problem is actually finance. To try to raise the finance to get a start-up company off the ground, particularly one that sells to operators who have huge purchasing power and tend to squeeze all their vendors—quite naturally—is very difficult in the UK. It is much easier in the US. Addressing the ability to provide finance for those kinds of entities and, to Emily’s point, allowing them to exist for many years rather than to be bought as part of that financial process would help more than anything else, for the UK to grow its own major players in this space.”
“Q I see that William wants to come in. I just want to say that we have also been told that there was a major difference between fixed and mobile architecture when it came to security issues. You seem to be saying that there may be differences, but there are security issues within fixed networks as well as within our mobile networks. Emily Taylor: Generally, our standard of security across the board is not as high as it should be. Professor Webb: I realise that Chi had also asked me how the UK can strengthen its ability to provide diversified supply chains, and I did not address that. I want to pick up on something Emily said as well. I think she is absolutely right—the UK has a great number of really excellent engineers, both in universities and in leading consultancy-type organisations.”
“We should be making it as hard as possible to gain access; we should be making sure that there is as much oversight and understanding as is possible of where our supply chains go, the standards that they should meet, and whether those standards are being met, and I think this Bill goes some way towards that. I would argue that it needs to be continually updated, checked and maintained. This is not a one-off: times change, and the internet changes faster. Those would pretty much be my recommendations.”
“Those are my biggest queries about the ability of this Bill to be as forward-looking as we would like it to be. Finally, with regard to SolarWinds, I think this Bill is aptly timed in a way, given the context of this particular threat. SolarWinds was a perfect example of a supply chain security risk, and a vector of attack that went through a diverse supply chain to meet what should have been some of the most secure systems that the United States had. Telecoms will, as I have already said, be the backbone of all the UK’s future advancements of technology in all the things we are seeking to develop within our borders. The hardest thing to do as an attacker is to gain access.”
“I would argue that a lot of the technological standard-setting that you see take place in the ITU and elsewhere is essentially that taking place, as is the use of social media platforms to harvest data, which is then used to aid in the censorship of domestic content within China. With regard to evolving threats and the Bill specifically, I think that the Bill goes a very long way towards pre-emptively meeting threats that are likely to come in the future. My biggest issue echoes what I caught of the previous witness statements: the fact that it is a matter of capacity for the institutions that are given this responsibility—that is, Ofcom—and the ability to change their culture to actively engage within that framework and take action to ensure these standards are met and kept to.”
“I am a great believer that technology and values and norms of behaviour are implicitly connected: you cannot separate them. It should be explicitly understood that it is an implicit truth. I believe—and I have stated this before to some of your colleagues and civil servants in various Departments—that the CCP has realised that the great firewall of China, which tries to police content within China, has holes in it and is not going to last, or was not going to last, given the direction that the internet, freedom of communication and transfer of information is going. The next logical step, and what I believe is happening, is that if you cannot control the internet within the great firewall, it is better to be able to shape the internet everywhere, both outside and inside it.”
“Q Thank you for providing your expertise, Dr Drew. We heard from one of our previous witnesses that the security aspects here might be part of, if you like, a battle for the heart of the internet when it comes to embedding values into the standards that drive it. You seem to be saying that that is a part of China’s requirements to monitor and surveil its domestic population, so I wondered what your thoughts were on that expressly. Also, you have great experience in evolving security threats. In your view, does the Bill address major telecommunications threats to national security—future and evolving threats? For example, do you think this Bill would have helped to mitigate the impact of the recent SolarWinds Orion network monitoring hack, which was also mentioned by a previous witness? Dr Drew: I will start with the question of values.”
“On having providers be more proactively involved, I think it would make complete sense for these actors to be made to inform Ofcom, or whichever regulator is chosen, of significant changes to their supply chains. It would be akin to having a black box where we go, “Okay, this black box must output something secure, but we don’t need to know how it gets there.” I think we should know, as much as is possible, who is involved in the supply chains to reach our eventual telecoms network.”
“If you look at the membership and those who take part in ITU standard setting committees and groups, you will see a predominance of not only state representation from China, but also representation of Chinese companies. I think it needs to be made clear to our providers the benefits to them of being able to set standards; I believe this has been overlooked. The easiest way to do that is to simply look at some of the technical standards that have been set or lobbied for in this group by companies such as Huawei and ZTE, which are essentially entrenching their technical standards into a global standards body—that obviously gives them an advantage in producing that output. I think our companies could benefit in exactly the same way, and they would certainly benefit from taking part.”
“Q Thank you very much for that. The Bill does not create any incentives for network operators to diversify their supply chain, or place any requirements on them to make notifications of changes to their supply chains or their networks that could have security implications. There is no proactive requirement on network operators to do that, or to actively participate in standards development—and we have heard about the importance of standards development and the huge presence of China in that space. Do you have any thoughts about how we could address those incentives, and also the power of standards development? Dr Drew: The two essentially go together.”
“I do not think there is a significant technical difference to mean that the goals and direction of this Bill could not, and perhaps should not, be applied to others.”
“It is likely that fixed networks will move towards the concept of computing on the edge, and this is indeed already happening in some senses. As for the actual efforts to control security risk, I do not see any major differences between telecommunications suppliers and fixed network suppliers. There is the same potential risk. You mentioned the SolarWinds hack earlier. That was a fixed network supplier in a way—it was not telecommunications—but there was the same risk involved and the same means of access, through a diversified chain with limited oversight at Government level, because it is a private sector actor with limited responsibilities. That is as true in that case as it would be for a fixed network with Cisco, and as it would be with a telecoms provider by ZTE, Huawei, Ericsson or any other.”
“Dr Drew: As to the second question first, I believe that security should be a component here. In fact, I believe it fits with what Ofcom is likely to be responsible for, and with the Online Harms White Paper as well. Security is fundamentally and inexorably linked with technology, culture and communications in the modern sense, so I believe that it would be important for that to be included as a key provision for DCMS. With regard to the differences between fixed networks and 5G and the implications of this Bill, in the efficacy of its methodology towards the other, there are technical differences in how 5G operates right now and how we perceive the next generation of telecommunications to operate, but those differences will change over time, I believe. They will become less distinct.”
“Q We have talked a lot about 5G—indeed, we have been accused of fetishising 5G. The Government are currently consulting on security issues and fixed networks. Do you see major architectural differences or market differences in the security threats for fixed networks? Are they similar, and should a similar approach be taken to the removal of high-risk vendors? With regards to Ofcom, its principal duties are set out in the Communications Act 2003—I know this very well, having worked for it. They are “to further the interests of citizens in relation to communications matters; and to further the interests of consumers in relevant markets, where appropriate by promoting competition.” Do you think there is an argument to add a further security duty, if that is going to take such a large portion of Ofcom’s capacity?”
“If you have only a single supplier, all it takes is that supplier to be compromised for your whole network to be compromised. As I said earlier, with any form of cyber-attack, the access is always the hardest part if you are the attacker, so if you have an easy target or if the target is just one point, they can throw all their resources at it and it is easier. I would argue that diversification is one of the most basic and probably most effective means of limiting the damage that could be caused in any attack against one of those vectors.”
“Q I have just one quick follow-up question. Thank you very much for your evidence. The Bill separates out the diversification strategy, and in fact it does not refer to the diversification strategy. Is it possible for the UK to have secure networks without a diverse supply chain for them? Dr Drew: That is a great question that comes with a very simple answer: no. The worst-case scenario for creating a risk in this sense is when monopoly meets supply chain—in secure supply chain in this case. Arguably, the reason why SolarWinds was so successful is that it provided the same service to so many different organisations and departments in the United States. Therefore, if you access one—SolarWinds—you access almost all. That is the risk. The same is true in this sense if you transfer these issues to telecommunications or fixed networks.”
“That programme yields an advance look for colleagues about threats and opportunities that are coming towards us into the markets, so that we can build the skills and consider the implications well in advance of their actually impacting on those networks.”
“Simon Saunders: Could I also add that, in respect of our role in emerging technologies, we are not only awaiting others to tell us which emerging technologies to pay attention to? We have our own independent programme of monitoring and horizon scanning for technologies that could appear and have an impact on the networks and the sectors that we regulate. Clearly, the implications are not only about security. They cover a wider range of issues of performance and costs and flexibility and so on. We actively monitor across these sectors for those technologies. I mentioned earlier that we recently published something about technologies heading for the future generations of mobile. That also covers fixed networks, the advent of quantum technologies and distributed software technologies in networks, and so on.”
“As we collect that information with operators, we will discuss with them in advance what type of information they want to see on a routine basis, sharing that and clearly taking guidance from them as necessary if they think there are national security issues that we need to be aware of. I mentioned earlier about having security clearance in place. To expand on that answer, we have a small number of STRAP-cleared staff in Ofcom, and we will expand that if need be. Those relationships with the NCSC are already in place and will be productive. I should say also that if the NCSC identifies new threats, or if we identify new threats, I think the legislation is flexible and it is right to be so, in that the code of practice can be updated to reflect that.”
“So this is absolutely—the legislation in fact specifically says so—about future technology as well as about existing networks. It is critical, I think, that we and the operators go on this journey together in terms of promoting that security by design, in everything that is done. Picking up your question specifically in relation to assets, I think it is more or less impossible to meet the requirements set out in the covid practice for the operators unless they have a detailed asset register of everything that is in their system. We would expect to see evidence of that, and that it is regularly checked, audited and so on. That would be an expectation for us. On the relationship with the NCSC, as I say, we have specific provisions in place that enable us to share information with the NCSC.”
“Would Ofcom be informed of that change in its network? How would that pass to the National Cyber Security Centre—or would it not? Without that kind of duty in place, is there a risk of what you do becoming a meaningless tick-box exercise and, particularly, of its not addressing future and emerging security threats? That is my first question. Lindsey Fussell: The point that you raise about this needing not to be a tick-box exercise is absolutely vital. I think actually what we are talking about in this legislation is changing culture—crucially among operators but also in terms of giving the regulator new responsibilities and changing the culture that we have, and the responsibilities and the range of the role we take on in relation to this.”
“So how are you going to ensure that compliance without taking decisions on security? You seem to suggest that it is just going to be a set of protocols, if you like, from the National Cyber Security Centre, and you are just going to look at ticking the boxes to see that they are met; but in practice that cannot be the case. It is far more complex than that, particularly with regard to emerging technologies. Another issue is that the Bill puts all the requirement to ensure compliance on Ofcom, in terms of Ofcom seeking information, Ofcom requiring information, Ofcom setting out notices to inspect, and so on. For example, let us say that one of our network operators—I shall not name one—decides to buy all its cloud or virtualisation equipment from a Chinese manufacturer that is not designated a high-risk manufacturer.”
“Q Thank you very much for sharing your expertise with us. As a previous employee of Ofcom, for six years, I am, not surprisingly, perhaps, a huge admirer of your work, and, to reflect what was implied by the hon. Member for Hyndburn, I think that Parliament will always benefit from increased telecoms expertise here. I want, with permission, to ask a question about three areas: security, assets and costs, and duties. I share some of the scepticism of my right hon. Friend the Member for North Durham about the statement that Ofcom will not be making decisions on national security. You will clearly have duties with regard to national security and one of the key duties is to ensure compliance of our entire network—all our networks—with national security requirements.”
“Lindsey Fussell: We would, as I say, expect providers to keep detailed records of the components that they use in their networks. I would expect that that is the type of information that, if a significant new vendor is brought into the market, the NCSC might well be interested in. It is worth saying that, while we do not have any direct regulatory powers over the vendors themselves, under these arrangements operators are required to assess the maturity of the vendors and suppliers they use, and the NCSC has issued guidance to them to enable them to assess that maturity. If the question is: if we see a brand new supplier starting to appear, is that the kind of information that we would expect operators to provide to us and for us then to share it with the NCSC? The answer to that question would be yes.”
“Q How can you make that assessment without taking decisions about national security? If you are relying, as you seem to be saying, on the National Cyber Security Centre to make those decisions for you, how are you, or they, accountable to Parliament for that? There is a basic issue here, in that you feel that you are not responsible for national security. However, we do not see how that responsibility for national security is made accountable if you do not have any responsibility for it but you have responsibility for compliance. You have not answered my question as to how a change in the networks would be made known to you or the National Cyber Security Centre when there is no requirement for that at the moment, as far as I can see.”
“If we have learned anything from this most recent period, it is how important connectivity is to everybody’s daily life. Of course, that comes across in pricing and support for more vulnerable consumers, and all those other things that we have responsibility for in telecoms. Actually, promoting secure networks is absolutely in the interests of consumers and citizens as well, not just because of the really damaging consequences of cyber-attacks, but because, ultimately, if we are able to have better networks, that should enable greater economic innovation through 5G use cases and things like that, for example. I think in promoting the interests of citizens and consumers, telecoms security is clearly part of that.”