← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Julia Lopez

MP for Hornchurch and Upminster · Conservative · United Kingdom

IN THEIR OWN WORDS

JLR is still recovering from a crippling cyber-attack, of course, and the Minister has talked about the headwinds facing all car manufacturers. They include massive barriers erected by China to sell into its domestic market, while Chinese cars are aggressively sold into our own.

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

Will this Government be similarly tough, or will they continue to pretend that British industry is not having its legs cut off by net zero? The Chancellor talked ploddingly this week about reducing the burdens on business, but the truth is that, through regulation and tax, the unemployment Act and the national insurance hike, Labour has m…

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

We are being asked to applaud the Government’s industrial energy scheme, which does not start until next year, fails to address the underlying problem, and will not bring down prices for the whole economy. How will it position us against the competition?

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

I thank the Minister for his statement. In his final Prime Minister’s questions, Keir Starmer spoke emotionally about how he had saved jobs at Jaguar Land Rover.

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

Let’s take the ZEV mandate, which dictates that the manufacture of petrol and diesel cars will be banned in this country in just over three years’ time, and which is seeing our firms being fined right now for customers not buying electric vehicles that they do not want.

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

What will the Minister do to make sure that his colleagues are not jeopardising JLR jobs with dubious diplomacy, and are any trade measures being considered when it comes to China? Britain is de-industrialising before our eyes. In the west midlands and beyond, there will be pain in every postcode.

JAGUAR LAND ROVER: REDUNDANCIES · 2026-09-09 · READ IN HANSARD

The complete record

Every one of 603 lines we hold for Julia Lopez, in date order, each linked to its source. Free to read, in full, without an account. Page 3 of 13.

  1. It is a pleasure to serve under your chairmanship, Mrs Harris. I congratulate the hon. Member for Montgomeryshire and Glyndŵr (Steve Witherden) on securing this debate and bringing parliamentary attention back to a subject that has not been properly considered for some years: the role of science and discovery centres within our tech and science ecosystem, the pressures they face, and the contribution they continue to make. I enjoyed hearing about the hon. Member’s connection to the Centre for Alternative Technology, which clearly has such personal resonance given his father’s link, as a founding member in the 1970s. I knew the hon. Member was a teacher, but I did not realise he was a drama teacher, which perhaps explains why he is so fantastic at carrying his voice in this Chamber and speaking with such incredible passion.

    SCIENCE AND DISCOVERY CENTRES · 2026-01-14 · READ IN HANSARD

  2. To conclude, the Tech Secretary has said: “We are as determined to ensure women and girls are safe online as we are to ensure they are safe in the real world”, so will she ensure that the Government enforce against themselves for their failure to advance the rape gang inquiry, their failure to stop puberty-blocking trials, their failure to implement guidance on single-sex spaces, and their inability to deport illegal migrants who have committed sex offences? This Government rightly worry about the online sphere, and we support them on that, but there is plenty to be getting on with in the real world.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  3. If we wish to mitigate the risk to children, one simple intervention may help stop them sharing their own image too freely: raising the digital age of consent for social media to 16. The cross-party consensus is growing. The Mayor of Manchester, Andy Burnham, agrees with that idea; does the Secretary of State? She knows that there are geopolitical consequences to her rhetoric. Figures close to President Trump have already threatened sanctions. Has the Secretary of State engaged with the US Government? Has she been advised on the nature of any retaliation, were the UK Government to block X? The US-UK tech deal has already been paused. We need clarity on what else is at stake.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  4. The uncomfortable truth for all of us is that some of this imagery sits in a legal grey area. What Grok has produced at scale in 2026 is a modern-day iteration of an old problem, from crude drawings to photoshop. Grok is not the only tool capable of generating false or offensive imagery, and not all of this content will cross the threshold into illegality. Plenty of it is sick, degrading and morally repugnant but does not cross the criminal threshold. What, then, is the Secretary of State proposing to do about the difficult enforcement choices that a regulator or police force must make? The risk is that, with finite resource, and in a highly politically sensitive environment, regulators could be diverted from pursuing the most abhorrent and dangerous crimes.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  5. Nobody is on their side, but Government have never before proposed blocking TikTok, Google or Facebook wholesale for the frequent and often flagrant misuse of their sites. That would be an extraordinarily serious move against a platform that can be used for good—for uncovering scandals, sparking democratic revolution, and allowing the free exchange of ideas, day to day, including those that we do not like. It is that very power for good that makes Iran’s mullahs reach to block the internet in the face of courageous protesters. This episode poses legitimate questions about who holds power in the internet age. Many worry about the accrued influence of big tech titans—me included—but they worry, too, about the power of Government to divert, hide and duck accountability. They worry about this Government.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  6. Regardless of the law, it is right to expect AI companies to anticipate and prevent misuse of products before their deployment through rigorous red teaming. I accept that for a law to deter, the enforcement threat must be credible, but its use must also be proportionate. Notwithstanding the soft back-pedalling of the Secretary of State today, the Government’s appendage swinging over the weekend was extremely serious. Ministers mooted as an urgent remedy the banning of a site with 21 million monthly users in this country, despite another Minister guffawing that banning X was “conspiracy theory No. 3,627.” Since their invention, the internet and social media have been misused—often criminally—by people traffickers, paedophiles and fraudsters: the gutter dwellers of our society.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  7. Beyond the platform, however, the Internet Watch Foundation has identified cases where perpetrators have used Grok in tandem with other AI tools to generate category A material. As the Chairman of the Culture, Media and Sport Committee, my hon. Friend the Member for Gosport (Dame Caroline Dinenage), has rightly said, such mainstream AI tools must not become an enabling step in the child abuse production pipeline. Law already exists to deal with much of this, including the Protection of Children Act 1978, the Criminal Justice Act 2003, the Sexual Offences Act 2003, the Data (Use and Access) Act 2025—in which the Government voted against tougher amendments tabled by Baroness Owen of Alderley Edge—and the Online Safety Act 2023. Those laws should be enforced. We await Ofcom, the independent regular, setting out its next steps.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  8. I thank the Secretary of State for advance notice of her statement. Last week, public outrage was rightly expressed about the use of artificial intelligence to undress women and children in photographs by X’s AI assistant Grok. The use of AI in that way without consent is wrong. It is disturbing, and in many cases it is illegal. We support Ofcom in taking enforcement action where an AI tool is used to generate illegal content, especially of children. We support the Government’s stance on nudification tools. X itself has warned of consequences for anyone prompting Grok to make illegal content. The tools in question have been put behind a paywall, for the easy identification via name and bank details of anyone misusing them.

    SOCIAL MEDIA: NON-CONSENSUAL SEXUAL DEEPFAKES · 2026-01-12 · READ IN HANSARD

  9. This Bill would help mainly after an attack—not before—by mandating reporting, improving intelligence sharing and increasing accountability.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  10. Those measures are intended to modernise our cyber framework and address clear shortcomings identified in reviews of the NIS regime in 2020 and 2022. On paper, that all sounds sensible, but intent alone is not enough, which brings me back to our central concern: whether this law will work in practice in raising the standard of our collective resilience. The uncomfortable truth is that, in some of the most high-profile cases of cyber-attack, the penetration of systems was carried out by attackers using valid credentials. That means systems behaved normally. The breaches looked like legitimate access until it was too late. Human frailties were exploited: help desks were persuaded to reset passwords, and staff and contractors were impersonated.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  11. Last year alone, insurers paid out £197 million to help businesses recover from cyber-incidents. In fact, the collective cyber insurance bill of the FTSE 100 is now larger than the defence research and development budget. The Bill seeks to respond to one aspect of that reality by expanding the scope of regulation. Data centres, managed service providers, load controllers and designated critical suppliers will now fall within its ambit. That is a welcome acknowledgment that digitisation has introduced systemic risks that the original NIS regulations of 2018 did not adequately cover. The Bill also strengthens the powers of regulators, introduces cost recovery mechanisms and tightens incident reporting requirements.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  12. Ultimately, the Government had to step in with a £1.5 billion loan guarantee to prevent wider economic fallout. When we consider the Bill, we must ask whether it would do anything to strengthen our collective resilience. That is one of the tests that this legislation ought to meet, and it is not yet clear that it does. Indeed, the attack on JLR would not have been stopped, as the Minister himself has made clear, because it would not have been in scope. The cyber-threat landscape is evolving at an extraordinary pace. New research shows that cyber-attacks now cost our economy nearly £15 billion every year. High-profile breaches of businesses such as Marks and Spencer and the Co-op have demonstrated how quickly consumer confidence, jobs and supply chains can be put at risk.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  13. Last year, the UK experienced what is widely regarded as our most economically damaging cyber-incident to date when Jaguar Land Rover suffered a major attack. That was not a sophisticated act of cyber-warfare against the state—although such acts are happening with increasing regularity—but was carried out by a band of hackers. The consequences were enormous, however. For five weeks, Jaguar Land Rover was unable to operate its automated manufacturing lines, cyber-related costs mounted to nearly £200 million, and national economic output was visibly affected in that month alone. The real damage did not stop at the factory gates: hundreds of small and medium-sized enterprises in the supply chain—many of them operating on thin margins—were pushed to the brink, workers faced uncertainty and contractors had their work paused.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  14. AI and automation will not only transform productivity but equip hostile states, criminal gangs and opportunists alike with tools capable of eroding our national defences at speed and at scale. It is right that Parliament legislates to raise the collective security bar. We on the Conservative Benches support that principle. However, legislation of this kind does not come around often. Cyber law takes time to develop, and once the Bill passes, it is unlikely that Parliament will return to this territory for some years. That means that we must ask two simple but very serious questions today: will this law work and is it enough? Before we answer those questions, it is worth reminding ourselves of the real-world consequences of failure. Cyber risk is neither abstract nor theoretical.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  15. Happy new year, Mr Speaker, and thank you for putting the heating on. I am grateful to the Minister for setting out the Government’s rationale for this legislation in the Secretary of State’s stead. I do not know why the Minister was demoted either, but I want him to know that we appreciate him. The official Opposition recognise the scale of the cyber-security challenge that the country faces. If the pandemic accelerated the adoption of digital technology at a pace we had never before seen, then the advent of artificial intelligence will embed that technology into our economy in wholly new ways that bring not only opportunity but unprecedented risk.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  16. Whistleblowers have continued to speak out about the vulnerabilities of the system, and there is no sense whatsoever from Government that the dodgy digital identity plan will be paused until such a point when they are confident about cyber-security.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  17. The Association of Digital Verification Professionals called what Labour inherited on digital identity a “world-leading model for data sovereignty that digitised liberty rather than diluted it”. The citizen, not Government, would be in control. This naive Government are crowding out private sector expertise and making everyone have one of these identities by stealth. They have no idea what this system will cost, and they will not be honest about what it will be used for. What of the cyber-security of this system? The system on which this digital identity will be run was breached during red team testing last year. When I asked the Secretary of State if that system has now met the National Cyber Security Centre’s cyber-security standard, no answers came.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  18. The private sector will have noticed that the new obligations in this Bill broadly do not touch the public sector, where cyber-risk remains red-light-flashingly large, notwithstanding the public cyber strategy that was thrown out today in implicit acknowledgment of that gaping hole. Knowing that the public sector holds such enormous cyber-risk, this Labour Government choose not to minimise it, but to create a brand-new one—a hulking great identity system mandated for anyone who wants a job and, we now hear, possibly for new-born babies. It is mandatory identity by stealth, not consent, and with no honesty about it. It is not to be against the ability of people to verify themselves digitally for banking, to access certain online services or to stop fraud to think that Labour’s mandated digital identity plan is a complete rotter.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  19. Cyber-risk requires as much thought about the fundamentals of plumbing as it does about the laws that try to manage how humans use or exploit technology. The UK Government have a vast procurement budget for which our own firms ought to be able to make a successful bid, but UK tech tells me consistently that, for all the talk in the Government’s AI strategy of sovereign tech capability, it has not got a look-in since Labour has been in power. I am concerned that this Bill should not introduce new, burdensome regulation for UK firms in a way that benefits non-UK incumbents with giant compliance teams and legal resources in a way that would exacerbate the risk of vendor lock-in. Let us turn to another risk.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  20. The US-UK tech partnership was the result, with a huge amount of smoke and mirrors deployed over what it actually contained. Whatever substance lay within it, we heard just before Christmas that it had been paused, used as leverage by the US while other trade negotiations were under way. I am not criticising the US Administration for skilfully playing their hand in their national interest; I am asking this Government rapidly to wake up to the reality of a new world in which the post-war settlement is coming to an end—one that has been giving clues to its existence for many years, since long before President Trump came into office. The United States remains a vital ally, but in this new era Britain must be very clear-eyed about risk, the reality of hard power and the need to protect our sovereign interests.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  21. These investments will provide our companies with things that they need, from compute power to increasingly sophisticated AI platforms, but the UK is doing little simultaneously to mitigate our increased technological dependency. When I say “technological”, we need to understand that technology is what we now run our defence systems, factories, energy networks and communications on. Technology is the plumbing of our nation. During September’s much crowed-about state visit by President Trump, this Government were visibly begging for good economic headlines after the humiliating resignations of the Deputy Prime Minister and the ambassador to the US, not to mention the uncontainable mess of the Chancellor’s first Budget and the threat of her second Budget.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  22. I see no evidence from this Government that they are thinking with any clarity about the risks of long-term technological dependency and lock-in—quite the opposite, in fact. Large parts of our economy now depend on secure, high-quality digital infrastructure, and that reliance will only increase as AI advances. Whoever provides that infrastructure will wield huge future leverage. It was that reality that ultimately drove the change of heart over Chinese tech sitting at the core of our 5G telecom networks a few years ago. However, the Government are seemingly betting every chip on US hyper-scalers. They provide our data centres, supply the platforms on which Government Departments are run and, more often than not, are the ones winning all the Government contracts.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  23. Cyber insurance, sector-wide intelligence sharing and collaborative resilience initiatives can all complement regulation. These tools can reduce risk and improve preparedness without adding unnecessary legislative complexity. The review cycle set out in the Bill may be too slow for the threat landscape we face and the pace of technological change. Annual or biannual reviews might allow Parliament to scrutinise effectiveness, respond to emerging threats and ensure that the legislation remains fit for purpose. Let me make some more general points about the Government’s approach to cyber-security and resilience, and issues about the risk of dependence and threat from adversaries.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  24. The Government should also look at how reporting obligations are calibrated. A one-size-fits-all approach might place disproportionate burdens on smaller firms, and it might be better to ensure that reporting thresholds reflect the size, complexity and risk profile of an organisation. Equally, the funding of regulators must be transparent and predictable. There have to be safeguards against regulatory expansion for its own sake and firm assurances that funds raised are reinvested directly into improving national cyber-resilience, not absorbed by administrative overheads. While the Bill rightly prioritises critical national infrastructure, it cannot afford to ignore high-risk sectors that sit beyond its immediate scope. There is also a major role for market-based solutions.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  25. Without mechanisms to ensure senior accountability, fines risk becoming little more than a cost of doing business. Directors remain insulated while operational teams are left to carry the can. National cyber-resilience depends not just on systems and software, but on leadership, culture and accountability at the very top. For those reasons, ahead of Committee consideration, we on the Opposition Benches are examining how the legislation can be strengthened, while continuing to support its core objectives. In the meantime, regulators must be properly equipped with the right powers, resources and clarity from Parliament on the intent of the law. Sanctions must be applied swiftly and consistently, and guidance must be clear, so that enforcement is credible and deterrence is real.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  26. Without simplification and proportionality, the administrative load could be significant, once again diverting attention and resource from the very cyber-threat management that the Bill seeks to improve. We need to avoid this legislation becoming a “something must be done” Bill that totally misses the mark. The Bill also fails to grapple properly with the human factor in cyber-security, which has already been talked about by the hon. Member for Harlow (Chris Vince). Technology alone does not keep organisations safe; governance matters. Yet board-level ownership of cyber-risk is moving in the wrong direction. Only 27% of businesses now have a board member explicitly responsible for cyber-security, down from 38% just three years ago.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  27. The companies that thrive in this kind of environment are those with big compliance and legal departments. That concentrates risk and makes our tech economy less diverse, with serious implications that I shall come on to. There may be reporting challenges too. A two-stage reporting process within 24 and 72 hours may be achievable for large, well-resourced organisations with in-house cyber teams, but for smaller operators it risks creating a compliance culture focused on speed, not substance. There is also the danger of duplication. Many organisations already face overlapping reporting obligations under UK GDPR, sectoral rules and existing legislation.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  28. We also have concerns about the Bill’s cost recovery model. Funding regulators through levies on the organisations that they oversee risks unintended consequences in terms of improving our resilience. For large firms, the cost burden may be manageable, but for smaller enterprises it amounts to an additional operational tax that could divert scarce capital away from cyber-defence, staff training and innovation. There is also a structural risk here. Regulators that are reliant on fee income might face incentives to expand scope and complexity unnecessarily, creating bureaucratic drag that crowds out voluntary, market-led initiatives, which often raise standards more effectively than prescriptive regulation. More generally, I worry that this Bill will play into tech monopolies.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  29. The Bill expands regulatory powers and increases the scale of potential fines, but the evidence from the existing regime does not suggest definitively that fines and new regulations deliver us greater cyber-resilience. Under the current NIS regulations, enforcement has been slow, inconsistent and often toothless. Very few significant penalties have been issued. Where they have been issued, the delay between incident and sanction has sometimes stretched beyond two years. That delay matters, because it actively undermines deterrence and disconnects accountability from operational reality. Simply widening the scope of regulation without ensuring that regulators are properly resourced, empowered and required to act quickly risks creating obligations that exist on paper but lack any real-world bite.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  30. Absolutely. The hon. Gentleman is correct: this is fundamentally about culture—that is the point that I am making. We can pass as many regulations as we like, but a lot of the holes in our cyber-security systems come down to human frailties. That means this challenge is not just about new laws but about changing a number of things to make us more resilient. It is right not to dictate technical standards in primary law that will soon be outdated in the fast-moving world of technology, so the question is whether this law has the right mix of carrot and stick to make affected firms act in a way that raises the security bar—there are several areas where we fear it may not. First, there is potentially an enforcement paradox.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  31. The hon. Gentleman is wilfully misinterpreting what I am saying. There is not an issue with having systems tested; there is an issue with the fact that the system test failed. There is no evidence that the Government have therefore acted to deal with those systemic failures.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  32. An approach to cyber-resilience that looks only at introducing new regulations and compliance burdens without thinking through risks such as a mandated identity scheme, dependence on non-sovereign suppliers, the malign intent of other nations, and a failure to build up our own workforce and skills is one that will fail.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  33. At the same time as risking technological lock-in by friendly allies, we are creating new vulnerabilities for adversaries to attack. Just before Christmas, UK intelligence agencies warned about increasing, large-scale cyber-espionage from China, targeting commercial and political information. We discovered from Ministers that the Foreign Office itself was the subject of a major cyber-attack in October, which officials believe was carried out by Chinese hackers, and this came in the midst of a major row between the Government and the Crown Prosecution Service about the prosecution of spies operating here in Parliament. We will be looking closely at this legislation to identify where the Government should be addressing this cyber-reality with much greater force.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  34. The whistleblowers continue to raise serious concerns about the structures upon which the Government’s digital identity platform will be built. The hon. Member looks absolutely outraged that I might suggest there are some concerns about the cyber-security risk of a national, mandated digital identity platform. I find it extraordinary that he suggests that I am expressing concerns that a system might be tested. Of course every system must be robustly tested—that is not the point I am trying to make, and the hon. Member is being wilfully ludicrous in suggesting otherwise. This Prime Minister cannot run an economy, keep promises or control his Back Benchers, or his Front Benchers, so how on earth does anybody think he can run a secure digital identity system?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  35. As my right hon. Friend is aware, local government is outside of the scope of the Bill, but it is a very juicy target—much of the public sector remains a very juicy target. In acknowledgment of that, the Government whipped out a strategy very quickly this morning that is meant to give us assurances about the public sector’s cyber-resilience. I am not sure that that strategy will provide much reassurance, which is why it is important to understand that this Bill can only be one part of a much wider arsenal to tighten gaps where they exist, in both the private and public sectors.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  36. Cyber-security is no longer a niche compliance exercise; it is about protecting the fundamental economic and defence interests of our nation.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  37. With the private sector taking the lion’s share of the load while gaping holes remain in public sector cyber-defences, the Bill begs obvious questions about the confidence that citizens should have in flagship Government projects such as the Prime Minister’s mandatory digital identity system. As it stands, the Bill would not have prevented high-profile cyber-shutdowns such as Jaguar Land Rover’s, it does little to address the chronic vulnerabilities in the public sector, and it certainly will not make Labour’s dodgy ID database any more secure. That is why, as the Bill progresses through Parliament, we will be pressing this Government to ensure that it delivers genuine security, proper accountability and raised cyber-defences across the board, while taking them to task on major mistakes such as mandatory ID.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  38. A Government who are trying to close down gaps in one place while wilfully opening up huge new risks in a different corner are being negligent in their approach. Furthermore, if this legislation is to command confidence, it must be practical, proportionate and genuinely effective. Without meaningful improvements, the Bill risks placing new burdens on business while delivering only marginal gains for our national resilience. Cyber-security is a shared responsibility between Government, regulators, industry and the public, but leadership must come from the top, and that is where this Bill currently falls short.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  39. My concern is that this Government are not taking seriously enough the various defence and security challenges that this House faces; they are prioritising spending on welfare payments, union payments and all manner of other things. It is one thing to get a strategy out of the door; it is another to put in place the measures that will implement that strategy. Basically, all we have seen over the past 18 months is strategy documents, without a great deal of delivery. That is one of the reasons why the Government are so rapidly losing public confidence. In conclusion, we support this cyber Bill in principle—the threat is real and growing, and it demands action. However, it is only a tool, not a cure-all.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  40. I welcome the strategy, but I have not yet had a chance to have a good look at it, because the Government always seem to publish these sorts of documents right at the last minute. The only way to get any information out of this Government is to apply some pressure in this House, and then, remarkably, things come flying out of the cupboard. I will be very interested to see what the strategy looks like and whether it is up to the challenge we now face. The problems and risks of cyber have increased markedly since we were in Government because of the advent of AI technology—that technology is changing the picture very rapidly, just as the defence picture is changing very rapidly.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL · 2026-01-06 · READ IN HANSARD

  41. Ministers are making very big claims about the pharmaceuticals deal with America, to make up for the billions lost in life sciences investment under Labour. Life sciences firms are telling me that unless the Government reveal what is actually in the deal, those claims are completely hollow. Can the Secretary of State reveal—she could not tell us this two weeks ago—how much the deal is costing the NHS and when she will publish the full legal text, so that we know the details of what the most favoured nation mitigations actually are?

    TOPICAL QUESTIONS · 2025-12-17 · READ IN HANSARD

  42. If we are making Christmas jokes, I think this deal is all tinsel and no tree. The problem is that Labour trumpets about these deals and is then completely sketchy about what has actually been agreed—just like the US-UK tech deal: we now find out from President Trump that he has put that deal on ice. Can the Secretary of State confirm that, despite all the golden carriage action in September and the Prime Minister honking on about his negotiating skills, the Prime Minister has actually nailed down none of the key details on pharma, no zero-tariff pact on steel and no deal on tech?

    TOPICAL QUESTIONS · 2025-12-17 · READ IN HANSARD

  43. It is a pleasure to serve under your chairmanship, Sir John, not least because it means that you cannot speak. I think you would happily take up a good hour of the debate talking about the perils and ills of the internet, and how it needs to be shut down, so that is probably for the best.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  44. I have some sympathy with those concerns, because the Act is large and very complex; although it is proving effective in protecting children in many ways, the implementation undoubtedly comes with challenges, whether that is VPN usage or the inadvertent capturing of no to low-risk sites in compliance duties.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  45. I congratulate the hon. Member for Sunderland Central (Lewis Atkinson) on introducing the debate. He made a particularly excellent contribution to last week’s petition debate on mandatory digital identification; although his party’s leadership may not have thanked him, I am sure his constituents did. He is right that the internet allows unprecedented connection, which is for good, but also for ill. Our job is to balance that inherent tension, while recognising that sometimes there is no balance to be found and that we have to make a choice when it comes to children being served a toxic online diet of extreme content. When we were in government, that choice was the Online Safety Act, about which thousands of petitioners have raised concerns, believing that its breadth and scope are having too restrictive an effect.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  46. I hope that we look back at the time before the Online Safety Act and wonder how we ever allowed children to be exposed to the unbridled internet culture that has hitherto been the norm. To return to the opening remarks of the hon. Member for Sunderland Central, the internet has led to the creation of new bonds and a huge multiplication of opportunity, but simultaneously the opportunity for harm. Sometimes we need to make a choice, and while the Online Safety Act is undoubtedly imperfect, the imperative to protect children will always take precedence. If social media platforms are held to greater account, so be it.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  47. Members have described today, the Online Safety Act is a necessary first step, but it is only the beginning of a much longer fight to protect childhood. We have to create the space for childhood and adolescence away from screens, with all the richness and stimulation that the real world can bring. Parents ultimately can never cease their vigilance. The internet cannot be made wholly safe, and we cannot be naive about that. Ultimately, parents have to remain the ultimate backstop to make sure that their children are safe online—but they need help. It is our role as legislators to provide some of those tools and that assistance to help children through their childhoods.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  48. They did a huge amount of work before the July phase of Ofcom’s introduction of age verification, and they are worried that they will need to make a further step change for regulatory compliance, given the burden that will place on them. Regulation has to remain proportionate, targeting high-risk sites and services without undermining innovation or our competitive position in tech. We also need to examine, as has been discussed many times today, the emerging technologies such as generative AI and chatbots —as was suggested by the hon. Member for Dewsbury and Batley (Iqbal Mohamed) and the hon. Member for Worcester. The legal position under the OSA is not yet entirely clear, but children are increasingly exposed to AI-generated content, and we need to know if the Act is flexible enough to deal with innovations of that kind. As hon.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  49. I would welcome the Minister telling us whether the Government are examining the measures that have been discussed today, including whether GDPR protections on the processing of children’s data might be raised from age 13 to 16. Age-gating also needs attention. Reports of VPN use suggest that children have been circumventing protections, and we must consider whether age-gating should be applied more comprehensively, including to VPN use or via app stores or at device level to close those loopholes. Adults also need to be assured of the privacy preserving nature of the age verification tools that they are using. There are concerns about the volume of sensitive data being collected. As I have described, we also need to ensure that low-risk tech firms are not being disproportionately burdened.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD

  50. Member who has recently been to a school in their constituency will have heard about the challenges to the learning environment, the challenges of the social interactions between children, and the challenges that parents are facing at home, which go way beyond the issue of illegal content. We have also heard other concerns. I liked the way the hon. Member for Worcester (Tom Collins) described it as “a veritable chemistry lab of…psychoactive substances”. He also made some interesting observations about safety and how, as a democracy, we must think very carefully about broader harms. The Act will be statutorily reviewed next year.

    ONLINE SAFETY ACT 2023: REPEAL · 2025-12-15 · READ IN HANSARD