← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Kanishka Narayan

MP for Vale of Glamorgan · Labour · United Kingdom

IN THEIR OWN WORDS

May I, as ever, thank the Chair of the Select Committee for such a depth of expertise and experience, and in particular for the report that she mentioned, which has formed the basis of a lot of our thinking?

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first thank my hon. Friend for championing an incredibly important cause. Content promoting eating disorders is horrific, and I have to be clear that not just at the age of 16, but under the Online Safety Act 2023, platforms must already prevent children under the age of 18 from accessing content about eating disorders or self-harm.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

This Government have led the world in tackling dangerous content online, including in law with illegal content duties that platforms must comply with, with our full backing for Ofcom’s enforcement of them, and by strengthening the law, with cyber-flashing, intimate image abuse and self-harm content all deemed priority offences needing to…

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

Do we want tougher accountability? Absolutely. That is why the codes published mean stronger review mechanisms, a direct line to law enforcement and a clear crisis playbook required of risky platforms. Do we want it to be faster? Absolutely. That is exactly why we have asked Ofcom to expedite those codes in particular.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

Keeping people safe online at moments of real danger is a top priority for this Government. That is why we have asked Ofcom to expedite its work on updates to its codes of practice under the Online Safety Act 2023. All services face strict duties to deal with illegal content.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first pay tribute to the families that I have met who have raised the issue of suicide forums, which the hon. Member rightly raises. I have committed to them in the past that we will continue to press for quicker remedies for them when they suffer the worst tragedies imaginable.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

The complete record

Every one of 602 lines we hold for Kanishka Narayan, in date order, each linked to its source. Free to read, in full, without an account. Page 5 of 13.

  1. Drafting a report of vulnerabilities that cannot be disclosed to Parliament without harming national security would simply duplicate existing assessments, and run the risk of distracting Government from more effective measures to protect from hostile foreign actors. That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber-security risks where it is appropriate to do so, through things such as the National Cyber Security Centre’s annual report and advisories. I therefore kindly ask that the shadow Minister withdraw the new clause. I thank the hon.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  2. As a result, it is unclear what additional support the proposed register would provide to the Secretary of State when, for example, deciding whether to issue a direction to a regulated entity. Additionally, the report required by new clause 3 would effectively be a list of the vulnerabilities of the network and information systems of our essential services, and would therefore be an asset to malicious actors. That would be counterproductive to national security. The new clause would allow the Secretary of State not to publish part or all of the report, if publishing would be contrary to the interests of national security. However, it is unclear how even part of the report could be published without harming national security, given its intended content.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  3. As drafted, the Bill grants the Secretary of State new powers to issue national security directions to regulated entities or regulators where their compromise poses a national security risk. So long as those tests are met, the powers may be used by the Secretary of State irrespective of the actor that is causing the national security incident or threat. New clause 2 would require the creation of a register of foreign states that pose a risk to the UK based on GCHQ advice. I reassure the shadow Minister that regardless of the proposed new clause, any decision to use the powers in this part of the Bill will be informed by expert national security advice from GCHQ.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  4. It is a pleasure to serve with you in the Chair, Ms McVey. I thank the shadow Minister, the hon. Member for Runnymede and Weybridge, for the new clauses in his name, which would require the Secretary of State to create a register of foreign powers that pose a threat to UK cyber-security, to review that register, and to lay a report before Parliament. This is intended to inform the use of powers granted under part 4 of the Bill. I empathise with the shadow Minister’s concerns that hostile foreign actors could target the network and information systems of operators of essential services or critical supplies. That is a clear risk, and one that we are addressing through the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  5. NIS regulators also support organisations to share information with each other in sector-specific groups. However, while I fully endorse the value of those initiatives, I do not believe it is the Government’s role to review how they operate or to mandate how or where they are established. Such centres are meant to be a forum in which organisations can voluntarily engage in the exchange of information. As such, they operate most effectively where the initiative for participation comes from the organisations themselves or from technical authorities such as the NCSC. The Government are, of course, committed to ensuring that the information-sharing provisions within the Bill are effective, and that will be assessed through the formal review of the legislation already required under clause 40.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  6. I thank the shadow Minister for this amendment, which would require the Secretary of State to review how information sharing and analysis centres support the functioning of the NIS regime and what steps the Government can take to improve them. I recognise the intent of this new clause. These centres play a key role in promoting collaboration and co-ordination in the cyber-security space, allowing organisations to share information, intelligence and best practice. In fact, the UK already benefits from a range of such initiatives, many of which are facilitated by the National Cyber Security Centre. In its latest annual report, the NCSC noted that more than 200 companies now meet regularly in trust groups to exchange intelligence and best practice, and to support each other in incident response.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  7. I thank the shadow Minister for moving new clause 5, which seeks to require annual reporting on progress towards meeting the recommendations of the National Audit Office’s report on Government cyber-resilience and meeting the implementation milestones of the Government’s cyber action plan. We recognise the value of accessing the expertise of Parliament to hold the Government accountable for the changes required for our cyber-resilience. That is why, notwithstanding the hon. Member for Spelthorne acknowledging the embarrassment of the Conservative party owning its hypocrisy, this Government have already strongly welcomed the recent reports from the Public Accounts Committee and the National Audit Office on Government cyber-resilience.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  8. My hon. Friend is right. Where the Conservative party did absolutely nothing and continues with its hypocrisy, I am glad to inform hon. Members that this Government have already adopted a duty to provide biannual reporting on progress against the recommendations of these two reports.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  9. I simply repeat my prior sentence: this Government have already adopted a duty to provide biannual reporting on progress against the recommendations of these two reports. In addition, the Government’s cyber action plan was published in January this year. It sets out how the Government will rapidly improve the cyber-security and resilience of public services to deliver a step change in cyber and digital resilience across the public sector. The plan sets out clear accountability structures to ensure that cyber-risks at all levels of Government are actively owned and effectively managed, with those responsible held to account.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  10. The hon. Member makes a very important point. We have heard of two major sources of risk from a cyber point of view: legacy technology and technology debt, and frontier AI attacks. The Government’s cyber action plan is not technology-specific, but both those sources of risk are very much on my mind, and I will make sure they are also on the mind of those implementing the Government’s cyber action plan. I assure Members that we will continue to work with Parliament to support oversight of the plan’s implementation and to explore additional avenues for scrutiny of the Government’s cyber-resilience to guarantee the right level of accountability. I therefore kindly ask the shadow Minister to withdraw his new clause. Question put , That the clause be read a Second time.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  11. I thank the hon. Member for Brecon, Radnor and Cwm Tawe for his new clause, which seeks to require a consultation on the resourcing and capabilities of regulators and regulated entities, assessment on whether additional Government support is needed, and a report on the findings. I reassure the hon. Gentleman that the Bill was developed in close collaboration with regulators and industry to ensure that regulators have the right information and tools to implement it. The Bill already requires the Government to produce two regular reports to monitor the effectiveness of the legislation, and those would naturally include reviews of whether resourcing and capability were impacting on the effectiveness of the regime. The first of those is the annual report on regulator activities in relation to the statement of strategic priorities.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  12. Beyond that, we will continue to engage with regulators as the Bill is implemented, and consider whether any other means of improving regulators’ and regulated entities’ resourcing and capabilities are necessary and proportionate. For those reasons, I ask the hon. Member to withdraw his new clause. Question put , That the clause be read a Second time.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  13. The hon. Member has made that point a couple of times before. I am happy to write to him about the calculations, so that he is able to understand the survey and the significant uplift on which the figures are based. In response to the hon. Member for Brecon, Radnor and Cwm Tawe, given that the two reports can already include the topics addressed by his new clause, adding another report would risk confusing their purposes and increasing administrative burdens on those involved unnecessarily. The Government will not hesitate to adapt our support offering based on the findings of those reports. That will include using our flexible mechanisms—for example, updating our guidance to regulators, the statement of strategic priorities and the code of practice.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  14. I hope that reassures the hon. Member for Henley and Thame that there is already considerable support available for small and medium-sized entities. Considering that, a new dedicated service is unnecessary, and it could divert resources from existing Government and NCSC schemes and impact our efficacy. For those reasons, I hope he will withdraw the new clause. Question put, That the clause be read a Second time.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  15. Improving the cyber-security of our nation’s small and medium-sized businesses is important for the resilience of our wider economy. That is why the Government have developed a wide range of free tools, guidance and training to help those businesses implement cyber-security measures. Such tools include the recently launched cyber action toolkit, which provides small and medium-sized businesses with tailored advice and the offer of free 30-minute consultations with NCSC-certified cyber advisers. Report Fraud, a reporting service for cyber-crime and fraud, runs a 24/7 cyber business incident reporting line, with regional cyber-resilience centres across England and Wales also providing support for small and medium-sized businesses, including incident response and business continuity advice in line with NCSC standards.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  16. New clause 14 would require the Government to establish a dedicated support service for small and medium-sized enterprises that are operators of essential services, relevant digital service providers, relevant managed service providers or critical suppliers. That would include provision of advice, technical assistance and recovery guidance following a cyber-incident. It is worth noting that the Bill exempts small and micro enterprises from the regulations as relevant digital service providers or relevant managed service providers. Although regulators can designate a small or micro entity as a critical supplier, very few are expected to meet the threshold for criticality in practice. Similarly, there are limited examples of small or micro operators of essential services.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  17. In particular, relevant digital service providers are already required to account for testing as part of their overarching security duty. Additionally, all regulators can use their powers to mandate testing by an inspector, or by the regulated entity, to verify compliance or investigate potential failures. I reassure the hon. Member that we are going further. We will be updating and providing more detail on the measures that regulated entities need to take, as well as setting strategic objectives for regulators. As I have said before, our proposals for the security and resilience requirements in secondary legislation will be consistent with the NCSC’s cyber assessment framework, which includes measures on appropriate testing.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  18. It is important that industry is consulted on those measures, that they form part of a holistic package on security and resilience, and that they can be updated flexibly over time. We intend to consult on proposals for security and resilience requirements and wider implementation plans later this year. New clause 17 seeks to require all organisations in scope of the Bill to test the security and resilience of their network and information systems. We agree that proportionate cyber-security testing is critical to identifying and mitigating vulnerabilities in systems and networks. Organisations in scope need to take appropriate and proportionate measures to manage risks to network and information systems on which they rely, and that can include testing of network and information systems.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  19. More recently, the Secretary of State, together with the Chancellor, the Business Secretary, the Security Minister, and leaders of the NCSC and NSA, wrote to the CEOs and chairs of the UK’s leading organisations, asking them to make cyber-risk a board level priority. I agree with the hon. Member that going further on board-level responsibility is necessary. That is why we will introduce security and resilience requirements in secondary legislation, following consultation. We will consult on proposals that are consistent with the NCSC’s cyber assessment framework, as we confirmed in our policy statement last year. The cyber assessment framework includes comprehensive measures on good cyber governance, including clear board level responsibility.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  20. I thank the hon. Member for Brecon, Radnor and Cwm Tawe for his new clauses. I will speak first to new clause 16, which seeks to require boards or equivalent management bodies of operators of essential services, relevant digital service providers, relevant managed service providers and critical suppliers to take specific measures to oversee the security and resilience of their network and information systems. Board-level engagement is a necessary part of proactively and effectively managing cyber-risks. That is why we published the cyber governance code of practice last spring, as part of a wider package of action to support boards in more effectively governing digital risks to enhance their organisation’s cyber-resilience.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  21. The Government Digital Service is already working on a secure by design standard. We want to make sure that it is as robust as possible, and extend it across not just the public sector but parts of the private sector. I will make sure that security by design remains at the heart of the Government’s cyber action plan, as well as that of the private sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  22. Overall, any approach to going further on proportionate and regular testing must be developed alongside the full set of security and resilience requirements, and co-ordinated and communicated with a wider package of implementing measures. That will allow the impact of options to be assessed, and provide the industry with clarity on the overall approach, including how the components fit together. The shadow Minister asked about the consideration of NIS2 requirements. We have looked at NIS2 provisions, and variability in member states’ implementation of it, as part of a wider set of considerations on which we will be consulting regarding secondary legislation on governance. My hon. Friend the Member for Milton Keynes Central made an incredibly important point about security by design, which I very much take into account.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  23. I thank the hon. Member for his point. I am also aware that the National Cyber Security Centre’s cyber assessment framework has very specific measures on appropriate testing as well. It already exists, and we want to make sure that it is an important part of specific security and resilience requirements in secondary legislation. It is crucial that industry is consulted on the nature of any requirements related to testing. As mentioned, we intend to consult on the proposals later in the year. We will also issue a statement of strategic priorities for regulators, and will explore whether that is an appropriate vehicle for driving consistency in the behaviours of regulators in respect of their approach to testing for their sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  24. My hon. Friend has extensive expertise, from which I benefit extensively. I will be keen to make sure that the Government Digital Service does so too. In the light of those commitments, I kindly ask the hon. Member for Brecon, Radnor and Cwm Tawe not to press the new clauses.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  25. The Government are already conducting a review of the Computer Misuse Act, and we have made significant progress in developing a proposal for a limited defence to the offence provided for in section 1 of the Computer Misuse Act.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  26. It will provide an update as soon as the proposals are finalised. However, limiting a defence to only the sectors covered by the NIS regime would be impractical. Any package of workable defence would need to be broad enough to apply economy-wide. New clause 19 raises the introduction of a statutory defence to the Computer Misuse Act. I acknowledge the strong sentiment regarding reform of the CMA. There is no doubt that UK cyber-security professionals play a significant role in maintaining the country’s overall security and resilience. Supporting them is vital. I agree with the principle behind the new clause: that a defence to section 1 of the Computer Misuse Act could strengthen the resilience of network and information systems by allowing researchers to spot and share vulnerabilities.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  27. I thank hon. Members for their new clauses; I recognise the strong feeling and thoughtful contributions about reforming the Computer Misuse Act. I speak first to new clause 18, which seeks to place a duty on the Secretary of State to review whether amendments to the Computer Misuse Act could support the security and resilience of network and information systems used for carrying out essential activities. I assure the hon. Member for Runnymede and Weybridge that the Government remain committed to ensuring that the Act remains up to date and effective. The Home Office is already conducting a review of the Computer Misuse Act, and is developing proposals that arise from its findings. That includes careful consideration of proposals to introduce a statutory defence that would allow researchers to spot and share vulnerabilities.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  28. My hon. Friend is absolutely right to recognise the shared sense on the principle of reforming the Computer Misuse Act. Although I am not in a position to give him a specific timeline, I absolutely take into account his recognition that the work needs to proceed at pace. Having held an industry engagement recently on specific proposals, with more than 75 attendees from a range of cyber-security organisations, the Home Office is now reviewing specific feedback as a particular proposal. The question is not whether we will reform the Computer Misuse Act, but simply how.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  29. Sure. I would not wish to define it technically, but my understanding is that it is research aimed at ethical hacking. It is effectively trying to find vulnerabilities through simulated attack systems, which can broaden our understanding of risks and vulnerabilities and allow us to mitigate them accordingly. I return to new clause 19. Limiting a defence to just the sectors covered by the NIS regime would be impractical; any proposal for a workable defence needs to be broad enough to apply across the economy. That is why we are making sure that, through the Home Office, we are working as promptly as possible to ensure a proposal that is strong in its safeguards to prevent misuse. Engagement, including with the cyber-security industry, is already under way to refine our approach.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  30. I thank the shadow Minister for his recognition of our shared approach on this question. Reform of the Computer Misuse Act is led by the Home Office. I have given my personal commitment to ensuring that reform, but I will also write to him and members of the Committee with as much detail as possible on the timeline to ensure that we are moving fast on it. In that spirit, I thank hon. Members for their work on this question of the amendment to the Computer Misuse Act and use this opportunity to thank you, Ms McVey, the entire Committee staff and hon. Members for their expertise and perhaps for their sense of fun as well. I thank all staff members, in particular the Bill team in the Department, which has been fabulous throughout the entire process.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  31. This Government have already set out a way forward that considers those vital issues in a responsible way, and allows for swift action in response. That is how we will give children the childhood that they deserve and prepare them for the future.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  32. It is still not available to Members across the House, yet they are asking the House to hand them control of business to complete all stages of the Bill within a day. That is no way to make complex changes to the law in this area. This is not just a procedural outrage; more than that I am sorry to see the Liberal Democrats join the Conservative party yet again in their usual coalition of putting political desperation on this question ahead of the interests of British children and families. I urge the Liberal Democrats to forget this approach, and to take part in the Government’s consultation, which is a true attempt at engaging across parties and across the country, so that we find the right solution for children and parents.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  33. It is a pleasure to respond to this debate, not least to further my education in my personal passion area of parliamentary procedure. Let me begin by responding to the motion, and then I will turn to the substance of the debate. The hon. Member for Twickenham (Munira Wilson) will accept that no Government could accept a motion such as that proposed by the Liberal Democrats. The motion goes against the Standing Orders of the House, which state that the Government as elected by the people control the Order Paper, apart from specific exemptions such as Opposition days. The motion would give the Liberal Democrats free rein to schedule the business on 9 March. Today they introduced a Bill.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  34. The Government are seeing both urgency and responsibility in the correspondence that we are receiving and the consultation we are engaging with, not the desperate lurch to a specific answer that the Liberal Democrats are exemplifying in this instance. I want to take this opportunity to set out our approach.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  35. I take the hon. Member’s point about wanting to work together. The Government are committed to doing exactly that. It is not a question of whether we act, but how we implement specific changes to secure our children’s future. I encourage her and the entire Liberal Democrat party to engage with the consultation.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  36. However, we have also been clear that in order to harness the potential benefits, parents need to have confidence that their children can benefit from the opportunities that the online world offers, ensuring that technology enriches, not harms, children’s lives. Most children report benefits from being online, such as interacting with their peers, finding useful information or learning a new skill. But we also know that there are concerns about children’s online experience. This Government have always been clear that the protection of children online is our top priority. The Online Safety Act 2023 introduced one of the most robust systems globally for protecting children from harm online.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  37. I will make a little progress having already given way twice to Liberal Democrat Members in short succession. To be clear, it is crucial that we allow for a short, sharp consultation to allow the different parts of the debate to be heard, including crucially the voices of children themselves, who are too often under-represented in the debate. This is a complex area and it is vital that we get it right. We have already announced that we will act both with speed and appropriate scrutiny to legislate based on the outcome of the consultation. Last month, the Secretary of State set out to the House that technology has huge potential for good: to create goods, to drive growth, to transform our public services and so much more.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  38. I commend my hon. Friend on her consistent commitment to evidence-based policy making in this place, and beyond it too. I commit to her that both the Born in Bradford study, which she mentioned, and wider research will be in the front of the Government’s mind.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  39. We will be very glad to come to the House as soon as the consultation is launched. It will be very soon indeed. As we have said, Members will expect not just a consultation— [ Interruption. ] I have not committed to debate the consultation today, prior to having published it. Perhaps the Liberal Democrats will take a lesson from that and follow appropriate procedure in this place. The illegal content and child safety duties came into effect last year. Those duties represent a major milestone in protecting children from illegal and harmful content online, as well as helping them to have age-appropriate online experiences.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  40. I can confirm to the hon. Member that the Government have committed to act robustly by the summer, which is about as short and sharp as a consultation can get. Instead of procrastinating on this question, I encourage her to engage intensively with the process of consultation and the national conversation. I mentioned illegal content duties, as well as child safety duties. Under those duties, services must now conduct highly effective age assurance, precisely addressing the point raised by the hon. Member for Upper Bann (Carla Lockhart), to prevent children in the UK from encountering pornography, as well as content that encourages, promotes or provides instructions for self-harm, suicide or eating disorders. Platforms are also now legally required to put in place measures to protect children from other types of harmful content.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  41. We share the concern of many parents about the wider impact of social media and technology on children’s wellbeing. The rapid growth of grassroots campaigns such as Smartphone Free Childhood highlights how concerned parents are about the pull of these technologies and what it means for their children. That includes the potential impacts on mental health, sleep and self-esteem. We have set out our commitment to supporting parents and children with these issues. We want to find solutions that genuinely support the wellbeing of our children and to give parents the help that they need as they guide children through online spaces safely.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  42. That will also be designated as a priority offence under the Online Safety Act, and it complements the existing criminal offence of sharing or threatening to share a deepfake intimate image without consent. Alongside that, it was announced that we will legislate to criminalise nudification tools to make it illegal for companies to supply tools to be used as generators of non-consensual intimate images. Last week, we went further still and announced that we will introduce a legal duty requiring tech companies to remove non-consensual intimate images within 48 hours of them being reported. These measures will provide real protection for women and girls online. However, we recognise the strength of feeling up and down the country and right across this House—not least in this debate.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  43. That means that platforms must take proactive steps to stop users seeing this content in the first place. If it does appear, platforms must minimise the time that it is online. As well as that, both intimate image abuse and cyber-flashing are now priority offences under the Online Safety Act. Last month, my right hon. Friend the Secretary of State stood in this Chamber and made it clear that the creation of non-consensual deepfakes on X is shocking, despicable and abhorrent. She confirmed that we would expedite legislation to criminalise the creation of non-consensual intimate images, and I am pleased to confirm to the House that that came into effect earlier this month.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  44. I can confirm to the House that just yesterday, Ofcom announced that it has fined a porn company £1.35 million for failing to introduce proper age verification on its websites—the largest fine levied so far under the Act. I welcome this strong action to protect children online. We have always been clear that while the Online Safety Act provides the foundations, there is more to do to ensure that children live enriching online lives. Like all regulatory regimes, it must remain agile. That is all the more critical given that we are dealing with fast-moving technology. That is why this Government have already taken a number of decisive steps to build on these protections. The first act of my right hon. Friend the Secretary of State was to make online content that promotes self-harm and suicide a priority offence under the Online Safety Act.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  45. Both of my hon. Friend’s points—on the scope of how we look at particular platforms and at their functionalities—are not just considered by the consultation, but deeply important. I engaged with the Australian Minister on this issue just last week, trying to understand their experiences of this and the uncertainty of getting those two things right. That is exactly why the consultation has been an appropriate approach in this context. Where services fail to comply with their duties in the Act, Ofcom’s enforcement powers include fines of up to £18 million or 10% of qualifying worldwide revenue. Ofcom has indicated that it has issued financial penalties to six companies under the Online Safety Act amounting to more than £3 million.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  46. This will include gathering views and evidence on options such as restricting access to addictive functionalities and understanding what we can do better to support parents in navigating their children’s digital lives. We will also explore whether we should raise the digital age of consent, to give parents more control over how their children’s data is used, and how existing laws on age verification could be better enforced.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  47. That is why the consultation approach is the responsible path forward for looking at these issues, considering in a swift and evidence-based way the full range of implications and the most effective way of protecting children and enhancing their lives online. We will consult with parents, the organisations representing children and bereaved families, tech companies and—crucially—children and young people themselves. None of that would be allowed under the motion we are considering today. This consultation, backed by the national conversation, will identify the next steps in our plan to boost and protect children’s wellbeing online. The consultation will include exploring the option of banning social media for children below a certain age, as well as a range of other measures.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  48. That is why the Government announced last month that we will be launching our short, sharp consultation and national conversation on further measures. We recognise that while some people support age restrictions on social media for children, there are diverse views on both the “what” and the “how”. Prominent voices in this debate, including the Molly Rose Foundation and the National Society for the Prevention of Cruelty to Children, are concerned that blunt age limits might not be the right approach and risk doing more harm than good. Even among those who support age limits, there are differing views on how to apply them, including which services restrictions should apply to. Those views are worthy of consideration, but we need to consider them properly and responsibly—we owe that to our children.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  49. I totally agree with the hon. Member’s call for urgency. I assure her that first, the Government will act by the summer in robustly responding to the consultation. Secondly, we have been focused on getting the consultation right, and not just for the wider public; we are ensuring that it is designed for young people’s engagement, which requires particular design features. Thirdly, we are not waiting for the launch of the consultation to have the national conversation. I have been in schools and met parents, as have the Secretary of State and Ministers from across Government, so the conversation has very much started, and I am sure that the consultation is also imminent. While there is consensus that problems remain, there is not yet consensus on the best way to address them.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  50. I am happy to repeat to the hon. Member this Government’s commitment, which is that we will act by the summer. That is about as short and sharp as a consultation period gets. The Online Safety Act took seven years; we are simply asking for one quarter to make sure that young people, parents and families across the country are properly heard from.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD