← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Kanishka Narayan

MP for Vale of Glamorgan · Labour · United Kingdom

IN THEIR OWN WORDS

May I, as ever, thank the Chair of the Select Committee for such a depth of expertise and experience, and in particular for the report that she mentioned, which has formed the basis of a lot of our thinking?

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first thank my hon. Friend for championing an incredibly important cause. Content promoting eating disorders is horrific, and I have to be clear that not just at the age of 16, but under the Online Safety Act 2023, platforms must already prevent children under the age of 18 from accessing content about eating disorders or self-harm.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

This Government have led the world in tackling dangerous content online, including in law with illegal content duties that platforms must comply with, with our full backing for Ofcom’s enforcement of them, and by strengthening the law, with cyber-flashing, intimate image abuse and self-harm content all deemed priority offences needing to…

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

Do we want tougher accountability? Absolutely. That is why the codes published mean stronger review mechanisms, a direct line to law enforcement and a clear crisis playbook required of risky platforms. Do we want it to be faster? Absolutely. That is exactly why we have asked Ofcom to expedite those codes in particular.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

Keeping people safe online at moments of real danger is a top priority for this Government. That is why we have asked Ofcom to expedite its work on updates to its codes of practice under the Online Safety Act 2023. All services face strict duties to deal with illegal content.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first pay tribute to the families that I have met who have raised the issue of suicide forums, which the hon. Member rightly raises. I have committed to them in the past that we will continue to press for quicker remedies for them when they suffer the worst tragedies imaginable.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

The complete record

Every one of 602 lines we hold for Kanishka Narayan, in date order, each linked to its source. Free to read, in full, without an account. Page 6 of 13.

  1. I will simply repeat the point I have made, which is that we are going to act by the summer. We have already sought permissive powers to ensure that the Government are able to act on the outcome of the consultation through rapid legislation. I hope the combination of those two commitments gives the hon. Member some assurance. The engagement and consultation will take place alongside work with counterparts. We will be monitoring developments in Australia on its social media ban for under-16s to share learnings and best practice. We are steadfast in our belief that the right way to deliver the next steps to protect our children online is to be led by the evidence through our short, sharp three-month consultation.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  2. We also recognise the importance of parliamentary scrutiny and the expertise that parliamentarians in both Houses provide, and have already committed that when regulations are brought forward, they will be debated on the Floor of the House and there will be a vote in both Houses, ensuring proper scrutiny. We are clear that the question is not whether we will act, but what type of action we will take. We will ensure that we do so effectively, in lockstep with our children and in the interests of British families.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  3. I thank the hon. Member for that point, and commit to her that we are going to try to do that as soon as possible. She will be aware that the legislative process is already very tight, so I will come back to her and the House with the wording of the motion as soon as possible. Last week, as I have mentioned, the Secretary of State confirmed that we will take new legal powers to allow us to act quickly on the outcomes of the consultation, delivering on our promises to parents. We will make sure that the wording is presented to the House at the earliest opportunity.

    ONLINE HARM: CHILD PROTECTION · 2026-02-24 · READ IN HANSARD

  4. Although stand-alone 5G is already available outside 83% of premises across the UK, I acknowledge that we need to go much further. Operators are starting to align investment and delivery plans with the ambition that the Government have set out. VodafoneThree has committed to investing £11 billion in its 5G network over the 10-year period following completion of its merger; progress against that commitment will be monitored at regular intervals by Ofcom. BT and Virgin Media O2 have set out similarly significant investment plans into their networks, both aligning with the Government’s stand-alone 5G coverage ambition.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  5. Member for North Shropshire is a member of, along with the other Members, published in January a detailed report on this topic. It provided valuable insights and recommendations. It is well understood across the House that access to high-quality, reliable and secure digital connectivity is essential to day-to-day life, with many services now requiring an online presence. It is important not only for consumers, but for the businesses in every sector of the UK economy that depend increasingly on fixed and mobile networks in some way. From taking card payments to managing businesses online, digital connectivity is central. The focus of this debate is on mobile connectivity. The Government have an ambition for all populated areas, including rural communities, to have access to higher quality stand-alone 5G by 2030.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  6. Members for Bromsgrove (Bradley Thomas), for Chester South and Eddisbury (Aphra Brandreth) and for Lewes (James MacCleary) for talking about not only maintaining bucolic beauty but parity and economic opportunity. I thank the Liberal Democrat spokesperson, the hon. Member for Frome and East Somerset (Anna Sabine), who raised a very concerning case about coercive control through the use of connectivity. I encourage her to write to the Department about that, as I would be keen to follow up on that particular issue. The constituency of my hon. Friend the Member for Camborne and Redruth (Perran Moon) has features of rurality and remoteness, and has coastal communities, and from my constituency I personally understand those features too. The all-party parliamentary group on digital communities, which the hon.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  7. First and foremost, can I start by thanking the hon. Member for North Shropshire (Helen Morgan) for securing this debate on mobile connectivity in rural areas? I thank all hon. Members for their insightful contributions. While I am here speaking in place of my noble Friend in the other place, the Minister for Digital Economy, I feel the pain described by many hon. Members personally, as I too represent a rural constituency. In that context, I particularly thank my hon. Friends the Members for Stafford (Leigh Ingham) and for Truro and Falmouth (Jayne Kirkham) and the hon. Members for Berwickshire, Roxburgh and Selkirk (John Lamont) and for Caerfyrddin (Ann Davies) for their representations on behalf of farmers and agricultural communities, whom I know face a particular challenge. I also thank the hon.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  8. On the reporting of mobile coverage, Members across the House are totally right to highlight the issues with its accuracy in some cases. I feel very personally the depth of their frustration; although I cannot condone the semi-kidnapping experience described by the hon. Member for East Grinstead and Uckfield (Mims Davies), she has my particular sympathies for her pre-Valentine’s break-up with Vodafone. Accurate coverage data is essential for consumers: it allows more informed decisions as to which operator provides the best level of service for life, work and travel.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  9. In that spirit, I hope to take her advice and continue the spirit of Labour, not that of the last Conservative Government or of the Liberal Democrats, who were complicit in the auction challenges of that Government. The focus on investment includes implementing the remaining provisions of the Product Security and Telecommunications Infrastructure Act 2022. I can confirm to my hon. Friend that the Government are considering where planning rules could be relaxed to support the deployment of mobile infrastructure. The shadow Minister mentioned the call for evidence, which is due to close on 26 February. In the usual spirit, I can confirm to him that we will make a prompt statement to the House, but I am afraid I cannot give him a specific date on this occasion.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  10. I thank the hon. Member for raising that point. I will come to that question, because I recognise the gap between the aggregate picture and the experience felt on the ground. Let me return to aggregate investment. To ensure that investment delivers coverage improvements for communities right across the UK, including in rural areas, we continue working to identify and address barriers to deployment where it is practical to do so. I may not share the significant expertise and experience of my hon. Friend the Member for Carlisle (Ms Minns) with matters of spectrum, but I certainly share her enthusiasm. When I was an undergraduate student, the global example of the last Labour Government on auction design and the 3G spectrum was very much a part of my curriculum.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  11. One solution for those who do not currently have smart meter wider area network coverage, which the DCC and Government have decided to focus on, involves harnessing customers’ broadband connections to also carry out smart metering communications. We are looking at how we can use modified smart meter communications hubs, as well as additional devices, to plug the gap. That is not to say that we will not continue to focus on how we can ensure mobile connectivity plays its part in that context as well. I am sure you wish for me to come to a prompt conclusion, Madam Deputy Speaker. First and foremost, I thank the hon. Member for North Shropshire, as I do all hon. Members for their contributions. I will continue, with them, to champion mobile connectivity across our rural communities.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  12. Friend the Member for Carlisle, raised the point on 2G and 3G switch-off, though the expectation is that operators will provide broadly equivalent levels of coverage after switching off 2G, I have heard his concerns and will make sure that both the Minister and, as a consequence, the regulator are focused on the complete delivery of that aspiration. Finally, I am conscious that the hon. Member for Berwickshire, Roxburgh and Selkirk also asked about smart meters, as did the hon. Member for East Grinstead and Uckfield. The Data Communications Company is obligated, under the conditions of its licence, to provide smart meter network coverage to at least 99.25% of premises across Great Britain.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  13. Friend the Member for Camborne and Redruth, I know that he is a strong cross-Government champion for Cornwall on all matters and I will continue to make sure that we play our part in supporting the strength of his advocacy. To the hon. Member for Caerfyrddin, there are three Home Office masts in her patch and two are already activated as part of the shared rural network. I will be happy to engage with her through correspondence on her particular concerns about those masts, should she wish to raise that. To the hon. Member for Berwickshire, Roxburgh and Selkirk who, with my hon.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  14. I will make sure that the points raised today are represented as part of Ofcom’s considerations, and in particular I will be sure to convey the concerns of my hon. Friend the Member for Carlisle around possible ways of ensuring duration of support as backstops. We will ensure that the guidance for public telecommunications providers reflects evolving technologies and emerging threats, taking into account input from industry and expert advice from the National Cyber Security Centre. Before I finish, I will address specific points raised by Members. To the hon. Member for East Grinstead and Uckfield, I would be happy to make sure that the Minister for Digital Economy meets her as part of her recurring surgeries. To my hon.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  15. Those developments have the potential to increase the resilience of our services and provide a back-up for crucial ones should territorial networks face disruption. Having coverage alone is clearly not important enough by itself. As Members have raised very clearly, there needs to be confidence that mobile networks will be available in the most difficult of times and that they are secure against threats. Though the Telecommunications (Security) Act 2021 introduced a world-leading regime for the protection and security of such contexts, I know that there is more work to do. In particular, I appreciate the points made right across the House on the resilience of mobile services to power cuts. We welcome that Ofcom is completing a detailed regulatory review on that question.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  16. The shared rural network has helped to deliver 4G mobile coverage to 96% of the UK land mass from at least one operator and to 81% from all four. The publicly funded elements of the shared rural network will continue to deliver improved coverage up to January 2027, with over 100 masts already delivering new coverage across the UK. Where there is no mobile coverage, we are starting to see some positive developments in the satellite direct-to-device market. To the point made by the hon. Member for Caerfyrddin, I also share her enthusiasm and hope for cost reductions as we have greater competition in that market. The UK is taking a pioneering step in enabling direct-to-device connectivity, moving ahead of European counterparts to unlock connectivity as well as growth across remote parts of the UK.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  17. Through the call for evidence, we are looking to gather views on the quality of mobile service and level of coverage required to harness the full benefits of stand-alone 5G, as well as where our ambitions on stand-alone 5G should go further still. As Members will be aware, as part of our work with industry, the Chancellor and the Secretary of State chaired a roundtable yesterday with CEOs of major UK telecoms firms to discuss investment challenges, as well as agreeing to a telecoms consumer charter, which looks to strengthen transparency to empower consumers, as well as to improve support for those struggling to pay. On the provision of reliable 4G connectivity, I know it is essential to many. At the spending review in 2025, the Government committed to continuing to deliver 4G coverage in areas with little or no coverage.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  18. The Government recognise that the investment climate has been difficult for the mobile sector over recent years. We are committed to working with industry to support its investment in our networks. That is why we are undertaking a mobile market review to understand the factors impacting the sector’s ability to invest, and I know that the recent digital communities APPG report calls for an independent review of the digital connectivity landscape. The mobile market review and the accompanying call for evidence, launched on Tuesday, will enable the Government to consider what we can do to support the sector too.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  19. I confirm to the hon. Member that there is no sense of judgment on the Government Benches on the conduct of her cause. The Government continue to work with Ofcom to improve the accuracy of reported mobile coverage, building on the launch of its Map Your Mobile tool in June last year. I am glad that hon. Members recognise that that is reflected in the draft statement of strategic priorities for telecoms, spectrum and post, which the Government laid before Parliament yesterday. It will remain a firm priority for the Government, and I will make sure to represent to my noble Friend the Minister for Digital Economy the concerns that have been raised today. More accurate coverage data also allows us to understand coverage gaps. Addressing these gaps requires investment by the mobile network operators.

    RURAL MOBILE CONNECTIVITY · 2026-02-12 · READ IN HANSARD

  20. These are organisations that, if compromised, could leave their customers’ systems, data or services exposed or inaccessible. In such circumstances, it is vital that their customers are notified, so that they can take whatever steps they need to in order to mitigate those risks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  21. Clause 16 sets out requirements for managed service providers, relevant digital service providers, and operators of data centres to inform customers who are likely to have been adversely affected by a reportable incident. Under the current regulations, there is no requirement for any regulated entity to inform its customers if it has been impacted by a reportable incident. That may have made sense when the NIS regulations were more heavily focused on operators of essential services and the primary concern was service disruption, but it would be an inexcusable omission now that the Bill is expanding to include managed service providers and operators of data centres, in addition to the digital service providers already in scope.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  22. It also sets out what those organisations can do with the information they receive, including how the information can be shared to manage the wider impacts of an incident or prevent future incidents. Finally, the clause introduces faster reporting, so that the NCSC and regulators are informed within 24 hours of entities becoming aware that a reportable incident is taking place. The 24-hour notification will be light touch, but will enable the NCSC and regulators to offer faster support to minimise the negative impacts of the incident. Fuller details will need to be reported within 72 hours of the entity becoming aware that a reportable incident is happening. The changes will protect the UK’s essential services, ensuring that the NCSC and regulators are able to provide the best support that they can.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  23. Taken together, it means that only meaningful incidents are reported. Over-reporting has been a concern raised by hon. Members throughout the Bill’s progress, so I stress this point: things such as unsuccessful phishing emails will clearly not be reportable, as they would not be likely to have a significant impact. Given our economy’s systemic dependence on data centre facilities, for that sector alone we will also ensure that Ofcom and the NCSC receive reports on a wider range of potential incidents and near misses. That ensures that not only immediate disruptions but incidents posing future risks are reported. Clause 15 also streamlines the reporting process for all NIS sectors. It ensures that incident notifications and reports go to the NCSC at the same time as the regulator.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  24. The focus is now on incidents that have successfully affected the security or operation of an organisation’s network and are likely to have a significant UK impact, which will ensure that regulators and the National Cyber Security Centre are fully aware of the range of cyber-threats affecting the UK’s essential services. The Bill sets out the factors that should be considered when assessing whether an incident has had, or is likely to have, a significant impact in the UK—including, crucially, whether the confidentiality, authenticity, integrity and availability of data has been compromised. The Government will provide further clarity in secondary legislation, setting out thresholds for each sector for when an incident is considered to have had, or be likely to have, a significant impact. That will be consulted on before it is introduced.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  25. To take two examples: a ransomware attack where confidential data has been exfiltrated from an organisation without an immediate impact on service would not be reportable; nor would a pre-positioning attack, where a hostile actor has hacked into a network and is in a position to cause significant disruption down the line, such as to the provision of drinking water. That cannot be right, and does not reflect the cyber-threats that critical services face. To ensure such incidents are caught, the clause sets a new, wider definition of incidents that must be reported.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  26. I will begin by discussing clauses 15 and 16. Clause 15 updates the incident reporting provisions in the Network and Information Systems Regulations 2018. Under the current regulations, organisations are required to report incidents only once they have had a significant impact on service continuity. It is widely recognised that this is too narrow, and results in a range of concerning incidents going unreported and a distorted picture of how secure and resilient the UK’s essential services actually are.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  27. These new requirements will support the overall resilience of the UK’s essential services and economy, which depend so heavily on these services, and reduce the overall impact of disruptive cyber-attacks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  28. I hope that exactly those principles are embodied in the guidance that regulators share about notification requirements. Customers being notified is all the more important given that in many cases, those customers will themselves be operators of essential services and other critical national infrastructure. The Bill therefore places new transparency requirements on managed service providers, relevant digital service providers and operators of data centres. Similar requirements were introduced under the NIS2 regulations in the European Union. Clause 16 requires those regulated entities to take steps to establish which of their customers, if any, are likely to be adversely affected by a reported incident. It then sets out the information that the entity must share with those identified customers.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  29. I thank the hon. Member for those two thoughtful points. On the first, in terms of retrospective regulatory action on the adequacy of notification, I expect that the regulators will set out—in their guidance and by working closely with the entities in scope—their expectations about the nature and timeliness of the notification. That will be one input into a regulator’s broader assessment of entities’ compliance with the regime. I expect that timely notification will be assessed on an ongoing basis by the regulator, but I would not expect it to be an exclusive or primary aspect. On the question of customer notifications being proportionate, I share the hon. Member’s concern about ensuring that it is timely and efficient and at the same time meaningful for the relevant customers.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  30. In the event that it is reportable, in its severity and potential impact, it will require notification—to the regulator and, when customers are directly impacted in the way that is set out in the Bill, also to the customers. The test is focused on whether network and information systems are engaged, and whether the impact of any incident is likely to be severe enough, in light of the thresholds set out in the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  31. On information sharing, not only is there provision for the specific sets of purposes for which information sharing ought to take place between regulators, but there is a further check on the proportionality of that, through a particular requirement, to ensure that information that is shared in incident contexts is done precisely for the purposes set out in the Bill, and in a way that is proportionate. My hon. Friend the Member for Milton Keynes Central raised the question of hardware impacts. While the focus of the Bill is primarily on network and information systems, the test, as I think of it, would look at whether any compromise in network and information systems related to a piece of hardware triggers the severity of the impact, or potential impact, to be reportable.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  32. Having been promoted from a position of mere confidence to faith, I will tackle questions from the hon. Member for Runnymede and Weybridge first and foremost. On the question of thresholds of incident, the Bill sets out the severity of the sorts of incidents that we expect reporting obligations to apply to, and at the same time it ensures that it is proportionate in understanding that sector-specific thresholds ought to be precisely that—sector specific, set closely with relevant entities in that sector, and working with the expertise of the relevant regulators. For that reason, it has not been specified more fully on the face of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  33. I hope this does offer the clarity that the hon. Member seeks. While I will not refer to specific businesses, broadly speaking the sector of food supply is not within the scope of the Bill; the obligations on operators of essential services or direct entities that are within the scope of the Bill will not apply. However, if—in a hypothetical situation—a managed service provider within the scope of the Bill supplies to that business, the managed service provider would be within the scope of the Bill’s requirements. The customer—in this case, the food supply business—may, if the severity applies, be in receipt of reports from the relevant MSP, in this particular context. They will not be caught up in the full set of obligations in the Bill, but we would expect customers to be notified of incidents where the severity thresholds are met.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  34. For those reasons, I am unable to accept the new clause. Question put and agreed to. Clause 15 accordingly ordered to stand part of the Bill. Clause 16 ordered to stand part of the Bill. Clause 17 Powers to impose charges Question proposed, That the clause stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  35. The new clause would also require the Government to publish proposals for a single reporting platform for cyber-incidents, again within a year of the Bill’s passing. We have heard the clear ask from businesses to minimise the time they spend filling in different reporting templates following an attack, to ensure they can prioritise the technical response. I share the concerns of the hon. Member for Bognor Regis and Littlehampton, and we are exploring all options to enable a proportionate and efficient reporting system. That said, setting a fixed time limit of one year to develop proposals does not reflect the inherent complexity of the task and the need to get it absolutely right for the businesses in scope of the Bill, not least because the proposals will need to be rigorously evidenced, consulted on and tested.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  36. It is important that the effectiveness of the NIS regulations, including the reforms to incident reporting introduced by the Bill, should be reviewed periodically. That is why the Bill requires the Government to conduct a review and lay it before Parliament once every five years. That timeframe will enable the new regime to bed in and allow a meaningful period of time to measure change before the Government report on its effectiveness. As my hon. Friend the Member for Stoke-on-Trent South said, notwithstanding her and the shadow Minister’s confidence in me and the Government, to publish a review after only one year would risk giving an incomplete picture, as regulators and regulated entities may still be transitioning to the new processes.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  37. Because of the changes to incident reporting introduced by the Bill, I can confirm to the Committee that ransomware attacks will be in scope. The Bill updates the definition of “incident” so that it applies to any event that has, or is capable of having, an adverse effect on the operation or security of network and information systems. Ransomware attacks already fall well within that definition. Although I welcome the principle and intent behind the new clause, its content is already addressed by the Bill. I hope that assures hon. Members across the Committee. New clause 7 would require the Government to publish a review of the new incident reporting regime within a year of the Bill’s receiving Royal Assent.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  38. There are reasons, which we can get into later, as we have done previously, why we set the sectoral scope in that way. New clause 6 seeks to clarify that a ransomware attack falls under the definition of “incident” within the NIS regulations. I share the concerns of the shadow Minister and the hon. Member for Bognor Regis and Littlehampton about the significant disruption that ransomware attacks can cause. Indeed, last year we saw the impact of the ransomware attack on Synnovis, a supplier to the NHS, which resulted in the delay of 11,000 out-patient and elective procedure appointments. The hon. Member for Bognor Regis and Littlehampton and the shadow Minister are quite right that this kind of attack should be considered an incident under the NIS regime.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  39. Under the provisions of this Bill alone, only the entities specified as critical suppliers or operators of essential services—the relevant digital providers and so on—would be caught up in obligations if an event occurred. Assuming neither of those is true of a food supply business, the Bill’s provisions would not apply. At the same time, in the sort of incident that the hon. Member describes, we would expect the NCSC to be deeply engaged, assuming severity thresholds and wider risks are applied. We would work closely on that operationally and I am sure we would look at how that business could be supported more widely. But the Bill’s provisions are really focused on the sectors, and entities within those sectors, that have an immediate threat to day-to-day operations such as a potential threat to life.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  40. The first requirement is that regulators consult and publish a charging scheme. It must specify what functions the fees are covering, the amount of fees being charged or how those fees will be calculated, and the charging period they cover. Crucially, regulators will be able to set different levels of fee for different types of organisations—for example, varying charges according to size or turnover, or excluding organisations from the charging scheme if it would be disproportionate or counter-productive to include them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  41. Clause 17 introduces new charging powers for NIS regulators, enabling them to recover the full costs of their regulatory functions under the NIS regime. This is an important reform that will help to ensure that regulators are effectively funded as they take on their expanded responsibilities under the Bill. It will allow them to move away from a funding model that relies on ad hoc invoicing or Government grants, and to approach their duties with greater confidence and certainty. The clause sets out detailed procedural requirements that determine how and when the charging powers can be used. These will ensure that regulated organisations know what to expect from regulators; fees will be set proportionately and regulators will provide satisfactory accounting for the sums they have charged.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  42. The second requirement is to set out, transparently and clearly, what fees have been paid, what fees are still due, and what costs have been incurred in a given charging period. On Second Reading, many hon. Members discussed the need for properly resourced regulators to successfully implement the Bill. I share that concern, and this clause seeks to achieve exactly that, in a way that is fair and proportionate to regulated organisations. I commend the clause to the Committee.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  43. On the second question, regulators probably ought to look at turnover in a way that is sector-specific, in part because there are already a range of ways in which other regulatory regimes define turnover in particular sectors, so the appropriate definitions for their sectors will be familiar to both regulators and regulated entities. At a later date, secondary legislation may be used if it is found necessary to set out factors that regulators ought to consider in setting up charging schemes, including the possibility of nuanced definitions of turnover. Any future regulations for this purpose will be subject to consultation requirements and the affirmative procedure. I would very much expect, at a sector level, a clear and proportionate definition and charging structure in relation to turnover.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  44. I thank the hon. Member for those thoughtful points. On the first question, the charging scheme applies to relevant costs, which are costs that regulators incur precisely when they carry out functions under the NIS regulations relating to cyber-security specifically. Those can include the cost of audits, inspections, handling incident reports or enforcement action, as well as other aspects, such as assessments of cyber-security and the provision of advice. It is important to acknowledge that regulators can decide to recover costs in relation to specific functions or their costs relating in particular to the Bill’s provisions. I hope to have assured the hon. Member that the charging scheme has a clear, tight scope that is related to cyber-security functions.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  45. The shadow Minister raised two main points that I am keen to address. The first was about ensuring that I committed to next steps on potential guidance for the charging scheme. I can confirm that the Government will issue guidance for competent authorities. That will include general directions on how the fee regime ought to be implemented. At the same time, we do not intend to be prescriptive as to how competent authorities should recover costs to benefit from their experience and practice in setting up these regimes. It is important that each regulator is able to tailor their fee regime in a way that is consistent with and complementary to the state of their sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  46. Members that the question of regulatory enforcement is central and that the motivation behind the charging scheme is precisely to ensure that regulators are well resourced to implement the Bill. Question put and agreed to. Clause 17 accordingly ordered to stand part of the Bill. Clause 18 Sharing and use of information under the NIS regulations etc

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  47. It is appropriate that regulators and competent authorities can vary their charging schemes in the light of that. On current regulatory performance and its correlation with charging schemes, I have not observed any direct correlation. What I have seen, simply, is that some regulators are clearly doing well. We heard in evidence from a range of participants that in some cases things are working particularly well and that, in others, there is more scope for improvement. That is precisely why the Bill sets no fundamental lowest common denominator for how regulators ought to approach either charging or their enforcement duties; instead, it ensures that we are conducting oversight of each regulator as robustly as possible. I assure hon.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  48. I am reminded of the hon. Member’s point last week. I am happy to write to him on the basis of the precise figure in the impact assessment, which I understand to be based on not just an extensive survey but the application of subsequent uplifts. I am more than happy to continue that conversation in correspondence. On factors that ought to be considered in setting up charging schemes, I mentioned some, such as size and turnover, but I will flag that those are suggestive and indicative rather than exhaustive factors that regulators may consider. Regulators ought to be able to set different levels of fee for different types of organisations. There is also provision to exclude organisations from a charging scheme altogether if it would be disproportionate or counterproductive to include them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  49. I beg to move amendment 14, in clause 18, page 38, line 31, at end insert— “(aa) otherwise in connection with— (i) the security and resilience of network and information systems, or (ii) any other matter relating to cyber security and resilience,”. This amendment would allow NIS enforcement authorities to share information with persons listed in regulation 6(2) (inserted by clause 18), and such persons to share information with NIS enforcement authorities, for purposes relating to the security and resilience of network and information systems or cyber security and resilience.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  50. That in turn will mean better outcomes, more effective and informed incident response, more co-ordinated oversight and lower business burdens. The amendment will be particularly important in supporting co-ordination with the financial regulators responsible for the critical third parties regime, which could be used to designate organisations already in scope of the NIS regulations such as cloud service providers. It also anticipates the need for co-ordination for other sectors, such as civil nuclear and space, in the future. In short, the amendment is necessary to ensure that UK regulators can take a more co-ordinated approach to protecting the UK’s most essential services. Government amendments 15 to 18 are consequential on amendment 14. I urge the Committee to support the amendments, and I commend clause 18 to the Committee.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD