← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Dr Ben Spencer

MP for Runnymede and Weybridge · Conservative · United Kingdom

IN THEIR OWN WORDS

However, her former partner requested that the DNA sample be taken at Woodlawn medical centre, a location that was not on Cellmark’s approved list of collection sites. Despite that, the testing kit was sent there.

SIR DAVID AMESS SUMMER ADJOURNMENT · 2026-07-16 · READ IN HANSARD

Subsequent investigations by the Department for Work and Pensions and the police confirmed what had happened. An employee of Woodlawn medical centre, Robert Patel, had conspired with Mr Brown and tampered with the DNA testing process. Both Mr Brown and Mr Patel were subsequently convicted and sentenced to prison for fraud.

SIR DAVID AMESS SUMMER ADJOURNMENT · 2026-07-16 · READ IN HANSARD

I would like to raise a deeply troubling case that highlights serious concerns about the integrity of DNA testing within the Child Maintenance Service and questions surrounding the existing safeguards in place to protect families.

SIR DAVID AMESS SUMMER ADJOURNMENT · 2026-07-16 · READ IN HANSARD

Most importantly, what lessons have been learned to ensure that no other parent or child has to endure the same ordeal? People need to have confidence in paternity testing, whether in child maintenance or other forensic uses. The chain of evidence needs to be secure.

SIR DAVID AMESS SUMMER ADJOURNMENT · 2026-07-16 · READ IN HANSARD

The A244 has always had too much traffic and too many heavy goods vehicles on it. It goes through Oxshott in my constituency, and following the roadworks on the M25 and A3, increasing numbers of cars and large vehicles are using it as a shortcut between the A3 and the M25. We need that to stop.

ROAD CONGESTION · 2026-07-16 · READ IN HANSARD

I start by thanking the Chair of the Science, Innovation and Technology Committee and its entire membership for the publication of a very interesting and timely report. Business, academia and the whole tech sector needs clarity, in some ways more than anything else.

SCIENCE, INNOVATION AND TECHNOLOGY COMMITTEE · 2026-07-09 · READ IN HANSARD

The complete record

Every one of 607 lines we hold for Dr Ben Spencer, in date order, each linked to its source. Free to read, in full, without an account. Page 7 of 13.

  1. That is a daunting prospect for smaller companies, even taking into account the caveated duty on competent authorities to co-ordinate in the approach to regulation of critical suppliers in the proposed new paragraph 14L of the NIS regulations. Several witnesses in oral evidence, including techUK and ISC2, made strong arguments that SMEs often lack the financial and human resources to develop cyber-security expertise and comply with regulation. Those organisations will need additional time to prepare, and a better indication of the criteria that might be used by regulators to determine which supply chain providers are critical. Industry bodies have called on the Government to ensure meaningful consultation on secondary legislation and guidance, to ensure that the measures are fit for purpose and capable of practical implementation.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  2. It is those vital elements of transparency and engagement, or rather the current lack of them, that are causing high levels of concern among supply chain entities that stand to be brought within scope of regulation when these provisions come into effect. To break that down, preserving agility for the Secretary of State and regulators to respond to emerging risks has been recognised as both a strength and a weakness of the Bill. However, lack of certainty is a particular concern in a context of critical supplier designation, especially as this part of the Bill has the potential to bring in large numbers of small and even microbusinesses within the scope of regulation, potentially by multiple regulators.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  3. The attack caused at least two cases of serious harm to patients and, tragically, one patient’s death was attributed to the long wait for blood test results. Estimated financial losses from the attack exceeded £30 million. The previous Government were conscious of intensifying supply chain risk, and consulted on measures to enable regulators to designate individual suppliers as critical if they provided an IT service on which an OES or RDSP was dependent for the provision of its essential service. The response to that consultation showed overwhelming support for the proposal, but stakeholders argued that the designation process would need to be transparent and based on engagement with industry.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  4. This clause is one of the provisions that has given rise to widespread industry concern regarding its scope and implications. Business supply chains, particularly for large operators of essential services and multinational companies, are becoming ever more complex. The increased digitisation of service provision across the board means that the delivery of essential services can be vulnerable to severe disruption when the systems of critical supply chain entities are interrupted by cyber-attacks. The Government have pointed to the 2024 cyber-attack on Synnovis, a pathology lab provider serving several London hospitals, as an example of the severe consequences that can flow from a cyber-attack on a key supply chain provider. In that case, the suspension of Synnovis services caused disruption to more than 11,000 appointments and operations.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  5. It is not just something as obvious as the tragic situation with blood and pathology testing that causes a hospital to grind to a halt. Indeed, I cannot think of many private sector provisions that would not have a substantial impact on a hospital if they were to be removed; if any other Member can, I will be very happy to stand corrected. However, just skimming through them, I can see that the removal of most of them would cause the hospital to grind to a halt. The idea that the significant impact definition will be a discriminatory factor regarding suppliers just does not work. Someone might say: “Ben, you’re completely wrong. We found some providers.”, but, if that situation arises, how will the arbitration occur in terms of the threshold?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  6. In fact, the most critical people are often the people who might not be the subject of the most focus, such as the cleaners and porters. If the cleaners stop work or do not turn up to work, the hospital grinds to a halt. If taxis are not taking people to and from hospital out of hours, or if the patient transport is not taking people to hospital, out-patient departments grind to a halt. If the locum companies that fill gaps in staff rotas are not available to do that, and there are substantial rota gaps that make the provision of services unsafe, the hospital also grinds to a halt. If it is not possible to get access to critical medicines, if staff cannot maintain the blood gas machine or the blood pressure machine, or if the boiler breaks down, the hospital grinds to a halt.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  7. Going back to my first point, the idea that access to the IT network or system will somehow be discriminatory, or dichotomise between people who are in scope of this measure and people who are not, seems to me complete nonsense. It is difficult to see what organisations, if they provide a service to a modern OES, will be in scope of it. Secondly, there is systemic or significant disruption. I often say that, if someone wanted to cripple a hospital, the best way to do that would be to stop the cleaners cleaning rooms, and to stop the porters pushing people around the hospital to get them to their appointments and moving beds. There is often a focus on doctors and on the rest of the core medical and nursing staff— I myself often focus perhaps a bit too much on doctors—but it really is a whole-team effort.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  8. My hon. Friend has figured out what I am going to say in a moment, when it comes to the scoping of the regulator and that communication process. Such is the depth of the rabbit hole that the provision creates that, even though my hon. Friend’s intervention did not go where I thought she was going, another problem has just come to mind. What happens in the circumstance where a critical supplier that acts as a proxy for multiple critical suppliers? How does designation operate in that fashion? There are suppliers that essentially operate as a marketplace to a certain provision of services. Is it the marketplace that is regulated, or is it each supplier within the marketplace? A locum agency could hypothetically be an umbrella company for multiple different smaller locum agencies, each of which would share the corporate risk as part of that.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  9. What about when we expand it—and this is just for the NHS—to cleaners, porters, locum agencies or medicines provision? Is the provision of services geographically circumscribed or will this be across the country? I am sure that one can find alternative services to provide taxis to St Thomas’ in Birkenhead, but that does not necessarily mean that it is available in a reasonable timeframe or sense, in terms of the designation of supplier.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  10. For example, if the regulator decided that taxi services are under threat of becoming a critical supplier, then does the taxi service have the ability to deal with someone who has a cardiac arrest, needs oxygen or has a behavioural disturbance? Can it manage people with physical or mental disabilities? What is the scope of that particular service provision? The experts will be the people who commissioned it in the first place; yet on the face of the Bill there is no objective requirement for the regulator to speak to the OES in the first place about how this provision and service was procured. In terms of the service being available—as per the point made by the hon. Member for Harlow about the time to shift through—how will that be evidenced and investigated? What resource is going into this? That is just for a taxi company.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  11. Do we expect the relevant regulator to check what taxi services are available—actually available, rather than some sort of fantasy availability where they are available on paper, but not in reality—in the local ecosystem that could supply to that hospital, which is the operator of essential services? What is the scope of research that the regulator would have to do? What considerations would they need to take regarding how much the taxis cost and how effective they are? What about the procurement decisions and processes that have already been gone through? Most public sector organisations have complex procurement rules when setting up their contracts—and that is before we even begin to consider health and safety concerns that are subject to regulatory provisions.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  12. However, I might also be nervous of being designated as a critical supplier because of the regulatory burden that would impose on me, which would make me potentially less competitive in getting contracts because of the costs that would ensue. There would need to be an arbitration system where a company that is under threat of being designated a critical supplier could have a discussion or debate about whether that designation was relevant or not. I will now move on to the point that the hon. Gentleman made about alternative services. I really have no idea at all how we can expect a regulator to delve into the complexities and the minutiae of what is available in a local economy to provide these services that the OES is receiving.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  13. I thank the hon. Member so much for that intervention about the time it would take to find an alternative supplier, because it will bring me on nicely to my point about alternative suppliers. However, before I move on to that point, the hon. Gentleman made a very good point in his intervention, which I will address. To be subject to these provisions will create a regulatory burden, and therefore a cost burden, for an organisation that is designated to be a national critical supplier. If I was a supplier of services, I would want to have the best provision possible. I would want to be cyber-secure; I would want to have a gold-standard service.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  14. There are all these weird situations that could emerge because of the scope and the looseness of these provisions, with all the consequent harms and problems. I look forward to hearing the Minister’s responses to my points.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  15. I was really struck by the evidence from the NHS on Tuesday, in which our witnesses described data-sharing operations with adult social care, which is of course provided by local authorities. It seems quite perverse, if I may say so, that a GP surgery, which is a private organisation, could be deemed a critical supplier to a hospital in terms of patient information sharing. Quite frankly, I would like the Minister to answer the question specifically: does he envisage primary care GPs being in scope because of data sharing of hospital records with NHS trusts? GPs could fall within scope as critical suppliers, while social care records, which are provided by local authorities, would not.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  16. If an organisation starts supplying to a hospital trust, or to whoever it may be, it might think, “Actually, we’re likely at risk of being designated, so we need to start doing some work and investment, either to challenge that designation or begin doing the preparatory work.” Maybe that is the intention: to effectively regulate the entire sector providing to OESs without actually lifting a finger in terms of regulation through this Bill. If that is the case, I am sort of sad, because I think it is better to be clear-cut about it. I would be grateful if the Minister answered that point directly. Finally, in terms of OESs, we have already mentioned the fact that Government and local authority IT infrastructure and services are among the biggest risks in our system.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  17. I worry that a lot of providers are going to think to themselves, “Why should we provide to an OES when we might be at risk of being designated as a national critical supplier?” Surely that is a concern that will have a chilling effect on organisations supplying to OESs, because of the risk of being found within the scope of this additional regulatory burden. Don’t get me wrong; as I have said, companies should be taking cyber-security seriously, as should everyone. However, not everyone should be subject to the various regulations and data-sharing requirements that this Bill provides for. I suspect that many organisations will be very concerned. If there is a risk of designation as a critical supplier, companies will already be instructing lawyers and other organisations to manage that corporate risk.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  18. I really appreciate my hon. Friend’s intervention. It goes incisively to the heart of the concern about how these provisions are currently drafted. I really struggle to see how an OES that is providing a service to another OES could effectively argue that it is not within the full scope of these regulations. We have a lot of OESs in this country. It may be the Minister’s and the Government’s intention to essentially have a proxy regulatory framework for suppliers to OESs going forward—it is being kept very loose, because there is some flexibility in that, but that in itself will be a problem.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  19. The Minister is, of course, within his rights to snarkily dismiss the questions that I have raised, but I should point out that the stuff that is debated in Parliament, whether in Committee or on the Floor of the Chamber, is relevant when it comes to future legal disputes after a Bill is passed. The questions I have asked about the application of the Bill’s provisions will be important parts of the legal disputes that I expect will arise after its implementation. When people look back through the Minister’s dismissive comments, I hope they have other resources that they can go to for settling legal arguments. However, he may choose to respond fully now, or in writing if he cannot provide me with an answer.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  20. Clauses 13 and 14 give Ofcom and the information commission access to more detailed information about regulated entities and facilitate regulatory oversight of the data centre RDSP and RMSP industries in the UK. Question put and agreed to. Clause 13 accordingly ordered to stand part of the Bill. Clause 14 ordered to stand part of the Bill. Clause 15 Reporting of Incidents by Regulated Persons

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  21. RDSPs are already required, under regulation 14 of the NIS regulations 2018, to provide their contact details to the information commission, as their sector regulator. Clause 14(2) amends regulation 14 to require RDSPs to provide more information, including about their directors and the digital services they provide. It would also require the information commission to share a copy of its register of RDSPs with GCHQ. Clause 14(9) requires RMSPs to register with the information commission and to submit the same contact details as RDSPs. RMSPs must nominate a UK representative if they are based outside the UK. The information commission will be required to maintain a register of RMSPs and to share it with GCHQ.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  22. Clause 13 requires in-scope data centre operators to provide certain information to their designated competent authorities, which—subject to Government amendment 11, which we passed earlier—will now be solely Ofcom, and to keep that information up to date. The information includes the data centre operator’s address and the names of directors. It must be provided within three months of the data centre operator’s designation. For data centres that meet the threshold criteria, that would be three months after clause 4 comes into force. Other OESs are not subject to an equivalent requirement to provide information to their sector regulator. That reflects the fact that the Government currently have limited information about the data centre sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  23. I beg to move amendment 1, in clause 15, page 22, line 15, at end insert— “(f) whether the incident involves failure modes not previously observed in the relevant sector materially involving autonomous or adaptive systems based on machine learning, including where the potential impact of such failure modes was mitigated or prevented.”

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  24. That would have pros and cons, and I remain agnostic on that, but, speaking for His Majesty’s Opposition, I would like to know the Minister’s plans for the AI landscape and whether, in the upcoming King’s Speech, there is an idea of revisiting an AI Bill, which might make such amendments obsolete.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  25. I understand that the use of deepfakes, bots and so on is an emerging risk as a method of cyber-attack. There are broader issues with regard to transparency when bots on the internet and social media networks can get into various IT systems and accounts, and effectively pretend to be somebody else to get around the cyber-security system. As with all things, we do not know what we do not know. I understand that the amendments were tabled to increase reporting requirements and give us more evidence of the scope of the problem and the threat posed. I will be grateful if the Minister gives his sense of how much of a problem this is, particularly with regard to whether reporting requirements are necessary. I believe that the Government’s original plan was to introduce an AI Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  26. I do not know if we have a sense of scope regarding how much this is a problem specifically in the UK, whether for the individual businesses or organisations that will be regulated under the Bill. I understand, as I interpret them, that the point of the amendments is to get a dataset on where AI or automated decision making has been used to pose a particular cyber-security risk. The amendments also speak to a more general point. There has been a lot of debate in this place over the years about what we as a country, and equivalent democracies, are doing on the regulation of AI and large language models, building on the Bletchley conferences, innovative work and what guardrails we need to think about in terms of imposing LLMs and AI in the UK, and how we approach AI being used by hostile state actors, such as through bot accounts.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  27. Broadly speaking, the amendments would ensure that as part of the reporting requirements under these clauses, there is an ability to measure whether adaptive AI or large language models have been responsible for a cyber-security breach or an incident within the systems themselves. That derives from what we see happening more generally in the cyber-security sector. We heard evidence that, online, people can essentially purchase a cyber-security hack suite of software. It is possible to pay for people to do hacking and one can get training in it. A lot of hacking and cyber-security breaches are now expanding because of large language models and the use of AI to probe systems.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  28. I will speak to the amendments tabled by the hon. Member for Dewsbury and Batley (Iqbal Mohamed), but wait for the next group to speak to clauses 15 and 16 and the amendments to them in the name of the official Opposition. From the outset, it is important for me to say that while I have spoken to the hon. Member more generally and responded to a debate he secured on AI, I have not spoken to him specifically regarding these amendments and their precise purpose. However, given his concerns about the AI sector and his background, we can see where he is going with them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  29. I beg to ask leave to withdraw the amendment. Amendment, by leave, withdrawn. Ordered, That further consideration be now adjourned. — (Taiwo Owatemi.)

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  30. The public support a ban on social media for the under-16s, Conservative Members support a ban on social media for the under-16s, and Labour Members support a ban on social media for the under-16s. The Secretary of State has said many fine words about her concerns for children’s safety online, but what we now need is action. Will she take the opportunity to make clear her position: does she, or does she not, support a ban on social media for the under-16s?

    TEENAGERS’ USE OF SOCIAL MEDIA · 2026-02-04 · READ IN HANSARD

  31. I can see the benefits of having an agile, flexible system, but organisations—especially global ones, which are the sort within the scope of this Bill—need time to prepare, recruit people, get the skillset in place, and understand where they need to get to. That fixed future point needs to be defined.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  32. NIS2 gives certainty and definition, by way of the legislation itself and then the implementing legislation, which means that organisations have had a run-up at the issue and a wholesale governance programme, which takes a number of years, but they know where they are headed, because it is a fixed point in the distance, on the horizon. The Bill we are talking about today has the same framework as a base. The plan then is that secondary legislation can be used in a much more agile way to introduce changes quickly, in the light of the moving parts within the geopolitical ecosystem outside the walls. For global organisations with governance that spans jurisdictions, a lack of certainty is unhelpful. Understanding where they need to get to often requires a multi-year programme of reform.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  33. Including those might be one way to go about it, but it is worth noting that it would not simply solve the problem because the problem is complex and multi-faceted, and this is just one piece of legislation. David Cook: With respect to NIS2, that is an example of a whole suite of laws that have come in across the European Union—the Digital Decade law; I think there is something like 10 or 15 of these new laws. They do all sorts of different things, and NIS2 sits within that. NIS2 is the reform of the NIS directive, which is the current state of play in UK law.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  34. Jen Ellis: There is a thing that you always hear people say in the cyber-security industry which is, “There are no silver bullets”. There is no quick fix or one easy thing, and that definitely applies when looking at policy as well. I cannot give you a nice, easy, pat answer to how we solve the problem of attacks like the ones we saw last year. What I can say is that, looking at the Cyber Security and Resilience Bill specifically, I think it could include companies above a certain size or impact to the UK economy. The Bill currently goes sector by sector— which makes lots of sense, to focus on essential services—but I think we could say there is another bucket where organisations beyond a certain level of impact on the economy would also be covered. That could be something like the FTSE350.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  35. Q Thank you, Jen and David, for coming to give evidence to us morning. Two questions. First, one to you, Jen. Lots of UK corporations have been the subject of recent major cyber-attacks, such as Jaguar Land Rover and M&S. Under the Bill as drafted, these remain outside the scope of the regulation. In your view, what is the best way to mitigate the risk to the economy, jobs and supply chains of further cyber-attacks of that scale to these important out-of-scope businesses? Secondly, and linked to that: Mr Cook, what lessons have you learnt from assisting clients with the implementation of NIS2—the second network and information systems directive—on the need for certainty in legislation? What do you think will be the most challenging areas of business to implement this Bill?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  36. We think that the upcoming national cyber action plan can further encourage the uptake of such schemes and frameworks. Most importantly, we call upon Government to focus on skills development as a non-legislative measure, because ultimately that will be the key enabler of success, whether it is for organisations that are within or outside the scope of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  37. On your question about sectoral scope, our central message is that we welcome the introduction of the Bill and we believe that it will go a long way towards improving the cyber-resilience of UK plc. Yes, there are certain sectors that are outside the scope of the Bill, and we believe that there are a number of non-legislative measures that could be used to enhance the cyber-security of other industries and parts of the sector. In particular, the forthcoming national cyber action plan should be used as a delivery vehicle for improving the resilience of UK plc as a whole. On the previous panel, I think Jen mentioned that there are voluntary codes of practice. As an organisation, we have piloted the code of practice for cyber governance, and we have signed up to the ambassadors scheme for the code of practice for secure software development.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  38. Q Thank you for giving evidence this morning. The Bill would not have prevented recent attacks on high-profile parts of UK industry such as Co-op, Marks and Sparks, and Jaguar Land Rover. What more do you think can be done to mitigate the risk to jobs, supply chains and the UK economy from further large-scale cyber-attacks against out-of-scope companies? My second question is a bit more technical. Do you consider that the definition in the Bill of a managed service provider is sufficiently clear and certain for businesses to understand whether they are in scope or out of scope of the Bill? Dr Sanjana Mehta: I appear before the Committee today on behalf of ISC2, which is the world’s largest not-for-profit membership association for cyber-security professionals. We have 265,000 members around the world and 10,000-plus members in the UK.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  39. Leaving all the detail to secondary legislation is what makes it slightly difficult to examine what is on the face of the Bill, so making sure that everything is consulted on in a mandatory and meaningful way will be important.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  40. Q The issues about complexity and how loosely the Bill is drafted have come up quite a few times, and you have given good evidence regarding your concerns. What cost to business do you anticipate if the Bill stays so loose, with so much left to secondary legislation? Jill Broom: There is probably a broader point around legal certainty, which is not given on the face of the Bill. Some of our members have highlighted language that could create some pretty significant legal jeopardy for regulated entities. The Bill needs to go a bit further. It could and should do more to provide some legal certainty, because the cost to companies could be quite significant. To the point on consistency across regulators and things like that, we need more frameworks around how that is going to work.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  41. It is sensible not to talk about AI in depth on the face of the Bill, but through mechanisms such as the code of practice, it will be possible for expectations to evolve over time as the threat and the technology mature.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  42. Last month, the chief executive officer of Anthropic, which is one of the main frontier AI labs, warned that he sees AI-led cyber-attacks as potentially being the main way in which cyber-attacks are conducted in the future. At the level of the enterprise, you have a challenge of how you secure the enterprise, in terms of not only developing and deploying AI, but visibility of AI used in an organisation. We are certainly seeing AI transform how cyber-security vendors and organisations manage the threat: they have greater visibility, can detect threats more quickly and the like. On how the Bill responds to that, one positive in its approach is that it is setting out an agile, outcomes-based approach that means that the regulatory regime can be capable of evolving as the threat evolves.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  43. You can think about it at three levels: first, the way in which attackers are using AI to mount cyber-attacks; secondly, the need to secure AI systems and AI within companies and organisations; and thirdly, the question of how AI is changing cyber-security on the defensive side. In brief, we see significant use of AI by attackers. Today, we are releasing the results of a survey in which 73% of surveyed security professionals say that AI-powered threats are having a significant impact on their organisation. These are things like phishing, reconnaissance, and lowering the barriers to being able to launch attacks and review more targets more effectively.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  44. How can Government Departments be overseen and held to account in a way that will deliver meaningful improvements in cyber-resilience? Finally, Ian from Amazon, a core feature of your business model is extensive exposure to supply chain partners. Do you think that the designation of critical suppliers by regulators under the Bill is the correct approach? What further consultation is needed to make sure that that is proportionate, prioritises the most critical suppliers and, crucially, gives a degree of certainty, whether legal or financial? Ben Lyons: AI is significantly changing cyber-security.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  45. Q Thank you for coming to speak to us this morning. I have a different question for each of you, so I will rattle them off and ask you to go through them. Starting with Ben from Darktrace, how are developing and emerging technologies such as AI and post-quantum crypto changing the nature of cyber-security threats? Do you think the Bill responds adequately to that changing threat landscape? Moving on to Matt from Cisco, what further guidance and consultation from the Government and the Information Commissioner is needed for MSPs to comply effectively with their obligations under the Bill? Chris from NCC Group, the National Audit Office report last year highlighted lots of serious deficiencies in Government cyber-resilience. Do you think the cyber action plan goes far enough?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  46. On enforcement, in seven years we have used all the enforcement regimes available to us, including penalties, and we will continue to do so. We absolutely welcome the changes in the Bill to simplify the levels and to bring them up, similar to the sectorial powers that we have today.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  47. Ian Hulme: On incident reporting, the thresholds in the existing regulations mean that levels are very low. Certainly, the reports we see from relevant digital service providers don’t meet those thresholds. I anticipate that we will see more incidents reported to us. With our enhanced regulatory powers and the expanded scope of organisations we will be responsible for, I anticipate that our oversight will deepen and we will have more ability to undertake enforcement activity. Certainly from our perspective, we welcome the enhanced reporting requirements. Stuart Okin: To pick up on the incident side of things, I agree with Ian. The thresholds will change. With the new legislation, any type of incident that could potentially cause an issue will obviously be reported, whereas that does not happen today under the NIS requirements.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  48. I have done a number of visits, for example, to hear at first hand from industry representatives about their concerns and how they want to work with us. We are also focusing on skills and recruitment. We already have substantial cyber-security responsibilities in the communications infrastructure sector. We are building on the credibility of the team, but we are focused on making sure we continue to invest in them. About 60% of the team already come from the private sector. We want that to continue going forward, but we are not naive to how challenging it is to recruit in the cyber-security sector. For example, we are working with colleagues from the National Cyber Security Centre, and looking at universities it is accrediting, to see how we can recruit directly using those kinds of opportunities.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  49. How will your respective approaches to regulation change as a result of this Bill, to ensure that it is implemented and that cyber-resilience is improved across the sectors you are responsible for regulating? Natalie Black : I will kick off. We have some additional responsibilities, building on the NIS requirements, but the data centre aspect of the Bill is quite a substantial increase in responsibilities for us. It is worth emphasising that we see that as a natural evolution of our responsibilities in the sector. Communications infrastructure is evolving incredibly quickly, as you will be well aware, and data centres are the next big focus. In terms of preparations, we are spending this time getting to know the sector and making sure we have the right relationships in place, so that we do not have a standing start.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  50. Q 38 Thank you for giving your time this afternoon. I have a couple of questions, which I will deal with in one go. The first is for Natalie. Ofcom’s role in cyber-security regulations will be expanded significantly under the Bill. What preparation has Ofcom undertaken to ensure it has sufficient capacity for effective oversight and, where necessary, enforcement in relation to its new regulatory obligations? My second question is jointly for Ian and Stuart, from the ICO and Ofgem. Some industry stakeholders have expressed concern about low levels of incident reporting and enforcement under the NIS1—network and information systems—regs.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD