← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Kanishka Narayan

MP for Vale of Glamorgan · Labour · United Kingdom

IN THEIR OWN WORDS

May I, as ever, thank the Chair of the Select Committee for such a depth of expertise and experience, and in particular for the report that she mentioned, which has formed the basis of a lot of our thinking?

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first thank my hon. Friend for championing an incredibly important cause. Content promoting eating disorders is horrific, and I have to be clear that not just at the age of 16, but under the Online Safety Act 2023, platforms must already prevent children under the age of 18 from accessing content about eating disorders or self-harm.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

This Government have led the world in tackling dangerous content online, including in law with illegal content duties that platforms must comply with, with our full backing for Ofcom’s enforcement of them, and by strengthening the law, with cyber-flashing, intimate image abuse and self-harm content all deemed priority offences needing to…

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

Do we want tougher accountability? Absolutely. That is why the codes published mean stronger review mechanisms, a direct line to law enforcement and a clear crisis playbook required of risky platforms. Do we want it to be faster? Absolutely. That is exactly why we have asked Ofcom to expedite those codes in particular.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

Keeping people safe online at moments of real danger is a top priority for this Government. That is why we have asked Ofcom to expedite its work on updates to its codes of practice under the Online Safety Act 2023. All services face strict duties to deal with illegal content.

OFCOM: CRISIS RESPONSE PROTOCOL · 2026-07-01 · READ IN HANSARD

I first pay tribute to the families that I have met who have raised the issue of suicide forums, which the hon. Member rightly raises. I have committed to them in the past that we will continue to press for quicker remedies for them when they suffer the worst tragedies imaginable.

SOCIAL MEDIA: DANGEROUS CONTENT · 2026-07-01 · READ IN HANSARD

The complete record

Every one of 602 lines we hold for Kanishka Narayan, in date order, each linked to its source. Free to read, in full, without an account. Page 8 of 13.

  1. Clause 25 introduces a power for the Secretary of State to designate a statement of strategic priorities for the implementation of the NIS regulations. The NIS regulations are enforced by 12 different sectoral regulators. Although that allows each regulator to apply its sectoral expertise, it also means that at times they have taken divergent approaches to their regulatory responsibilities. Clause 25 addresses that by allowing the Secretary of State to set overarching objectives for regulators in the wider context of a statement of strategic priorities. The statement will replace the NIS national strategy, which the Government were previously required to produce under the NIS regulations. It will set out the Government’s priorities for the security and resilience of essential services.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  2. Of course, regulators will be free to do that in the ways they think most appropriate for their sectors, in the light of their own expertise and experience. I hope that gives the hon. Member some assurance. Clause 28 requires the Secretary of State to publish an annual report setting out, in general terms, how NIS regulators have complied with their duties in relation to a statement of strategic priorities over the previous 12 months, and how they intend to meet their duties in the following 12 months.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  3. I thank the hon. Member for her point. Perhaps I can give a flavour of the objectives I might expect in a statement and assure her of the independence of sector regulators. Subject to consultation, which we would expect in the build-up to any such statement, a statement might include objectives such as encouraging regulators to seek to ensure that their sectors have plans in place to increase security, or focusing on regulatory activity in areas of greatest horizontal risk. To the hon. Member’s point about sector-specific expertise and the independence of regulators, the statement is intended to set objectives to be achieved within the parameters of regulators’ existing statutory duties, and what the overarching risks are.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  4. In terms of confidence in Parliament about actions that regulators have taken, the Secretary of State will be required to publish an annual report setting out, in general terms, the activity undertaken by regulators in the prior 12 months, alongside activity planned for the following 12 months. My expectation is that, very similarly, Parliament will have sight of that, and have the ability to scrutinise it and ask questions of the Secretary of State in the usual way.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  5. The hon. Member raises a very important point. We want Parliament to play an important role in the scrutiny of the overarching regime as a whole, but particularly in the operation of the statement. Perhaps I can break it into two parts: scrutiny of the statement in the first instance, and scrutiny of regulators’ compliance with the statement. Once a draft statement has been consulted on, the Government will be required to lay it before Parliament, and that will be subject to the negative procedure. Parliament will have 40 days to scrutinise the proposed statement and express disagreement with it, which is very similar to the procedure for statements of strategic priorities in other areas—not least online safety.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  6. I am grateful to my hon. Friend the Member for Harlow for his affirmation of that important point of parliamentary scrutiny. As I mentioned, the report in question will set out how NIS regulators have sought and will seek to achieve the objectives in the statement through the exercise of their regulatory functions. The clause requires the Secretary of State to lay the annual report before Parliament, as well as to publish it in an appropriate manner. Clause 28 also introduces information-gathering powers for the Secretary of State so that they can collect the necessary information from regulators to draft the report. I commend the clauses to the Committee.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  7. In that context, the statement of strategic priorities is intended to be one vehicle through which regulators’ compliance with overarching objectives of the Bill will be looked at as well, alongside ongoing oversight of each of the regulators through the usual departmental channels.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  8. I thank the shadow Minister for raising an important point. His broader question is one of the most important in this context: Bills are only as good as the ultimate enforcement capability, capacity and framework in which regulators enforce them. Particular aspects of the Bill are focused on that question. One ensures that regulators have not just the resource through the cost recovery and charging schemes that the Bill allows for, but the information through the information-gathering powers—and not just the information, but a statement of strategic priorities as new horizontal risks emerge across sectors. So regulators are armed with resource, information and strategic priorities that emerge from time to time. Alongside all those resources, data and information powers, regulators need also to have accountability, of course.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  9. The hon. Member raises an important point. Two or three things are really important channels of impact when it comes to skills. First, the NCSC as a convening body across regulatory areas will be able to make sure that different regulators come together and learn by being able to share information not just between themselves, but through the NCSC itself as the convening body for sharing good and prompt understanding of emerging risks. Secondly, on broader skills, the cost recovery schemes allowed under the Bill create a way for regulators to ensure they are resourced up and have the ultimate financial firepower to be able to enforce the requirements of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  10. I share the hon. Member’s recognition and her gratitude that we have not experienced the sort of incident that she described. The NCSC has told her, me and other Committee members that it brings regulators together and has done so on a number of occasions in the past to share cross-sectorally an understanding of emerging risks as well as incident-specific impacts. I take no sense of complacency from that precedent, but I do take some confidence from it. As the Minister in charge, I will ensure that the Department keeps a close eye on the ongoing implementation of the co-ordination powers under the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  11. First, I will provide some context for agreement. We want more people to be trained in cyber-security so that they can serve in the public and private sectors. Through the Bill, as well as a range of other initiatives, we are making sure that at every stage of the pipeline, there is resourcing, confidence and a demand signal that so more people can benefit from cyber-skills and serve in the industry. There is a clear financing path for regulators to at least start to hire. Earlier in the pipeline, we are looking at a series of cyber-skills programmes all the way from schools through CyberFirst—I think about 415,000 students have gone through that programme. Ultimately, we want to create a long-term pipeline so that regulators and private companies can make the most of those skills.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  12. Clause 29 Regulations relating to security and resilience of network and information systems Question proposed, That the clause stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  13. I am, of course, very happy to take on my hon. Friend’s recommendation that I be the promoter and ambassador for the Bill across the country. I am only sad not to have been invited to visit his constituency in the act of promoting said Bill, but I take his point seriously. On the broader point about skills, I entirely agree with both my hon. Friend and the Opposition in recognising that skills are central to the enforcement of the programme. I hope that the funding and the earlier focus on skills across the life cycle give some assurance that the Government are committed to that. Question put and agreed to. Clause 25 accordingly ordered to stand part of the Bill. Clauses 26 to 28 ordered to stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  14. I have already explained the critical role that clause 29 plays in enabling new regulations to be made for the purposes of cyber-security and resilience. However, I want to be clear about how those regulations will be used and reassure the Committee of their checks and balances. Clauses 30 to 35 set out what the regulations can do. Clause 30 enables the Secretary of State to use the regulation-making powers to impose requirements on regulated persons. It clarifies who can be made subject to requirements and the types of requirement that can be imposed on them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  15. I know the use of delegated powers can be a source of concern, so I will be clear that the clause is not a carte blanche—or a blank cheque, which the hon. Member for Spelthorne might be worried about—to smuggle in anything and everything under the guise of cyber-security. It is tightly constrained to ensure that any new regulations align with the original purposes of the NIS regulations. New regulations can be made only for the purposes of strengthening the cyber-security and resilience of the UK’s most critical activities, and only where they are genuinely essential to the functioning of the UK’s society and economy. Cyber-criminals will always find ways around regulations, but with this power we can stop them in their tracks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  16. Clause 29 is the key pillar of the Bill’s future-proofing powers. It allows the Secretary of State to update, amend or replace the NIS regulatory framework by creating new regulations. This is a critical provision. Due to the way in which the NIS regulations were transposed into UK law, the Government lack a way of updating the framework other than through primary legislation. As a result, our regulations have remained static amid a rapidly evolving threat landscape, leaving our essential and digital services vulnerable to attack and our resilience falling behind the EU. The clause is an important response to that problem. It will ensure that the Government can take swift action so that our cyber regulations remain relevant. It is a more proportionate and effective approach than always relying on primary legislation.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  17. In practice, the clause ensures that the Secretary of State can make changes and updates to the way that regulators carry out their cost recovery function under the NIS regime. It could, for example, be used to specify further factors that regulators need to consider when establishing approaches for charging fees in the charging schemes, in addition to those already set out in clause 17. That might be needed to deliver greater consistency in how the cost recovery measures are being applied and is something that the Government will keep under review.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  18. The clause also enables the Secretary of State to impose functions on organisations that are not regulators but that play a public role related to the cyber-security and resilience of essential services. GCHQ, in its capacity as the UK’s computer security incident response team and technical authority, is the most important. Like clause 31, this clause is essential for future-proofing NIS regulations. It allows organisations that oversee and facilitate the cyber-security and resilience of essential services to be equipped with the tools and functions they need. Clause 34 enables the Secretary of State to make provisions for regulators to recover relevant costs using the powers under clause 29(1). These are the costs incurred through their functions under the NIS regulations or other obligations imposed through parts 3 and 4 of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  19. The clause further clarifies that regulations can define “turnover” and “undertaking”, where needed, to calculate a penalty. Together, these provisions create important safeguards and flexibility. They establish proportionate and transparent parameters within which penalty amounts can be set. They also enable the Secretary of State to define and consult on terms that are essential for operationalising the Bill’s new turnover-based penalties. Like clause 31, clause 33 enables the Secretary of State to make regulations conferring functions on regulators. The functions specified in clause 33 complement the core compliance functions outlined in clause 31. They relate to the disclosure of information, issuing of guidance, record-keeping, preparation of reports, undertaking of reviews, and co-operation.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  20. It ensures that regulators can be equipped with the functions and powers they need to ensure the compliance and security of the UK’s most essential services. Clause 32 sets out details and safeguards for how the regulation-making powers can be used when they impose or amend financial penalties. Crucially, it establishes upper limits on what the penalties can be—the greater of £17 million or 10% of turnover for an undertaking, or £17 million for a non-undertaking, or £17 million for an undertaking adjusted as needed to account for inflation. The 10% threshold has been chosen as a defensible outer limit for a regulatory regime concerned with national resilience and security. It aligns with penalties for non-compliance in legislation regulating critical national infrastructure and with the Bill’s own national security powers.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  21. In other words, the clause will help us to operationalise the provisions of the Bill and update the technical details of regulatory requirements in response to new risks or technology. Clause 31 enables the Secretary of State to confer functions on regulators through the Bill’s regulation-making powers. These may be existing NIS regulators or newly appointed regulators. The types of functions that can be conferred are those concerned with compliance: monitoring and securing compliance, and investigating and managing non-compliance. To carry out such functions effectively, regulators must be able to impose penalties. Clause 31 also provides for that while putting in place important safeguards so that regulated organisations have a means of appealing penalties. The clause is essential for future-proofing the regulatory regime.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  22. Any legislation made under clause 29 will need to align with the Bill’s clearly specified purposes to protect the systems that underpin our vital services. In any case, secondary legislation will require deep consultation to ensure that businesses have the sense of clarity that they require. There is a specific bar to pass for the scope of any further provisions, and it is a high bar given the definition of the sectors and the activities covered in the Bill. Clause 30 has been designed with some clear use cases in mind. It will enable the security duties on regulated organisations to be updated with appropriate technical details. It will also ensure that more detailed thresholds for incident reporting can be set, and it is the mechanism through which we will set out the regulatory requirements for designated critical suppliers.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  23. I apologise for the pace of my speech; I will try to make sure I am speaking more slowly. On the particular point on transparency and ensuring that any amendments to cost recovery are both transparent and grounded in specific provisions, I can set out the sorts of expectations we have had for circumstances in which amendments might be made. In particular, the Bill’s powers will enable regulators to set up charging schemes, but it is not prescriptive—

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  24. Together with clauses 29 to 33, 35 and 41, clause 34 is necessary to ensure that the Secretary of State can update and amend the functions of regulators as needed in the future, and is an integral part of the Bill’s future-proofing powers. Clause 35 is the final clause that clarifies the limits and prospective uses of the regulation-making power in clause 29. It confirms that the regulations may confer functions and allow certain functions to be delegated to others—for example, it could enable a regulator to delegate functions to inspectors. It also clarifies that regulations can be made to require a person to have regard to guidance or codes of practice, or that make provision by reference to another document or piece of guidance. In short, the clause provides helpful clarity about how the regulations could be applied.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  25. The Bill’s new powers enable regulators to set up charging schemes, but it is not prescriptive about how it should do that beyond certain baseline requirements. More specific requirements, as provided for in the Bill, could become clear, such as if cost recovery mechanisms are not working effectively or if regulators are diverging unhelpfully. All regulators must consult on charging schemes. In doing so, the industry should have ample opportunity to scrutinise the approach that regulators are taking and, importantly, Parliament should be able to add to that scrutiny as well. Like clause 31, clause 34 is essential for the future-proofing of NIS regulations. Clause 34 enables the Secretary of State to make provisions for regulators to recover relevant costs; I have mentioned examples of the sorts of factors we might specify in that context.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  26. No. Question put and agreed to. Clause 29 accordingly ordered to stand part of the Bill. Clauses 30 to 35 ordered to stand part of the Bill. Clause 36 Code of practice Question proposed , That the clause stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  27. It is therefore important that there is a degree of flexibility in how they do this, to accommodate sector-specific nuances and business needs. None the less, it is crucial that the code has sufficient legal status and that the good practice it contains is not simply ignored. That is why the code can be admissible as evidence in court when deciding whether legal obligations have been met, and why the courts and regulators must consider it as evidence when assessing compliance. Clause 39 establishes a formal process for the withdrawal of the code of practice, in case that is ever needed.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  28. As we know too well, cyber-threats continue to evolve as new tactics and technologies are deployed, which is why the clause includes a power for the Secretary of State to amend the procedure for issuing the code. The Secretary of State may, for example, wish to add or amend consultation requirements or extend the 40-day period. Clause 38 establishes how the code of practice will be used and treated in legal and regulatory settings, to ensure it has the intended effect. For regulated persons, the code of practice is intended to be formal guidance, with recommendations on how to comply with their duties, but not to be legally binding itself. As we know, there can be more than one way for businesses to meet their obligations and ensure that they have in place appropriate and proportionate security and resilience measures.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  29. Given the importance of the measure in providing practical recommendations to regulated entities, it must be consulted on before it is prepared or revised, and this process is set out in clause 37. Before the code can be brought into force, a draft must be laid before Parliament, providing ample opportunity to scrutinise and, if necessary, reject it within a 40 day period. If either House objects, the Secretary of State cannot proceed with that version and may prepare a new draft. If the draft is approved by Parliament, the Secretary of State may issue it and must publish it, and it then comes into effect immediately, unless otherwise specified. The clause also clarifies how the 40-day period is calculated, to ensure consistency and transparency in the process.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  30. Clause 36 sets out that the Secretary of State may issue a code of practice for regulated entities. The code will describe recommended steps to help these entities to comply with their duties and requirements under the NIS regulations and any new regulations made under the Bill. This will make it simpler for regulated persons to understand what is expected of them, thereby driving consistency and complementing sector-specific guidance from regulators. The clause will also make enforcement clearer and more effective, as regulators must take the code into account when they assess compliance. The code is designed to be flexible: it can be updated as threats and technology change, and can be tailored to different types of organisations, ensuring that guidance is current, relevant and practical for all.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  31. On the shadow Minister’s question about ensuring appropriate timing and preparation for companies, I would very much expect that the regulators in question would be closely regulated entities to ensure the proportionate implementation of codes.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  32. First, to ensure that the shadow Minister and I are representing the intent behind the code clearly, in legal terms it is not the case that an organisation that fails to follow the code of practice is automatically a regulated organisation that has broken the law. Clause 38 makes it clear that not following the code does not by itself constitute a breach of duty or mean that an organisation is automatically liable to legal action. Organisations can take different approaches to complying with security duties, but if they adopt an approach that is not within the code, they may need to explain why their approach still meets the required standards set out in the regulations, and regulators will be required to take the code into account when preparing guidance.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  33. I am very happy to give the broad assurance that we will keep codes under review from time to time, and that any changes to the code will require deep consultation with regulators and businesses to ensure that the codes keep in touch with moving technology.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  34. I agree with the shadow Minister. The Bill’s focus is on the assessment of compliance with ultimate security duties. The codes of practice will set out approaches to do so, but they will not be the only approaches. I would be happy to write to the shadow Minister and the Committee on the particular legal interpretation, and any relevant case law that might apply. Question put and agreed to. Clause 36 accordingly ordered to stand part of the Bill. Clause s 37 to 39 ordered to stand part of the Bill. Clause 40 Report on network and information systems legislation

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  35. I thank the hon. Member for Brecon, Radnor and Cwm Tawe for moving amendment 26, in the name of the hon. Member for Henley and Thame. It seeks to reduce the period for publishing a report on the operation of the legislation from at least every five years to at least every three. I reassure him that the Government recognise the importance of regular assessments of the regime to ensure that it is as effective as possible. The legislation sets five years as the minimum period. That is an appropriate and proportionate timeframe in which to meaningfully assess the progress, at a regular frequency, of the entire regime set out in the Bill, following the approach set by existing legislation such as the Online Safety Act 2023.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  36. Clause 42 sets out the consultation requirements and parliamentary procedure that apply where regulations are used to designate new essential services or regulators, to impose regulatory requirements or change regulator functions, or to amend requirements for the five-yearly legislative review.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  37. Clause 41 gives further detail on the sorts of provisions that can be included in regulations made under clause 24 and chapter 3 as a whole. It confirms that regulations can make different provisions for different purposes, different categories of person or different areas; can make provisions for how those regulations apply to the Crown or UK territorial waters; and can include consequential, supplementary, incidental, transitional or saving provisions. The clause also defines how certain terms used in regulations should be interpreted, such as “relevant UK waters” or “primary legislation”. In summary, the clause provides important points of clarification about how the regulation-making powers in the Bill can operate. I propose that clause 41 stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  38. In each of the cases I mentioned, clause 42 requires the Secretary of State to undertake consultation with appropriate persons before any regulations can be made. It also specifies that regulations of this kind can be approved only through the affirmative parliamentary procedure. These provisions ensure that any substantive regulations made through the Bill’s future-proofing powers will be properly tested. They provide the necessary checks and balances that such wide-ranging powers require, and they will ensure the credibility and legitimacy of future regulations made using these powers. For those reasons, I propose that clause 42 stand part of the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  39. I thank the hon. Member for that important point. The expectation is that the powers used here are scrutinised appropriately. If it helps, I can set out which uses of the power, particularly under clause 42, will trigger consultation requirements and the affirmative procedure, which will perhaps give her the assurance she seeks. In essence, all changes that may have considerable impact on how the NIS regime operates will be subject to consultation and the affirmative procedure. In practice, this means that regulations concerning the designation of essential services, as well as changes to the duties of regulated entities and functions of regulators, will be subject to both consultation and affirmative procedure requirements.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  40. On the broader point about application to the devolved Administrations, changes in UK legislation may indeed need to be reflected in devolved legislation, such as where it refers to and references the name of UK legislation. In those contexts, it is important that consequential provision can be made to ensure coherence. We will continue to engage with our devolved colleagues on the implementation. I am very happy to write to the hon. Gentleman and the Committee, particularly on the Northern Ireland point. Question put and agreed to. Clause 41 accordingly ordered to stand part of the Bill. Clause 42 ordered to stand part of the Bill. Clause 43 Directions to regulated persons

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  41. The list is therefore not exhaustive, and for good reason. It is not possible or desirable to specify every action that might be needed to address a national security risk. That would restrict the Government’s potential avenues to address urgent national security threats, and would risk the legislation being too narrow to address novel threats to the UK’s national security.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  42. I will start by addressing amendment 27, moved by the hon. Member for Brecon, Radnor and Cwm Tawe, which would add to the non-exhaustive list of requirements that could be included in a national security direction. It specifies that a direction could include requirements to “remove, disable or modify hardware, software or other facilities”. I reassure him that the Bill, as currently drafted, allows the Secretary of State to impose those types of requirements. Clause 43(3)(f) specifies that a direction may include “a requirement relating to removing, disabling or modifying goods or facilities or modifying services”. That already encompasses the types of requirements specified in amendment 27. Furthermore, clause 43(3) lists the requirements that may “in particular” be included in a direction.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  43. The Bill currently provides for clear parliamentary scrutiny. The Secretary of State is responsible for coming to Parliament, although some information may not be able to be presented in public. I am happy to write to the shadow Minister about the mechanisms that other similar regimes have used to ensure that Parliament’s scrutiny is informed in those cases, whether in Committee or otherwise. The primary mechanism is the one we use for constant parliamentary scrutiny, and it would be unfair for any of us to suggest that most of those channels would not be appropriate for the sort of scrutiny we are looking at.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  44. To repeat, exactly as I said: once a direction is issued, it will be laid before Parliament for scrutiny. If there is any misunderstanding, I am happy for the shadow Minister to write to me so that I can confirm it.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  45. At present, however, the Government lack powers to require regulated entities to take necessary action in response. That gap could be exploited with increasing frequency and impact. The clause will remedy that, ensuring that the Government have the necessary powers to act quickly to protect our national security.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  46. Clause 43 grants the Secretary of State the power to direct an NIS-regulated entity to take necessary and proportionate actions in response to national security threats. The power can be used where the entity’s network and information systems have been compromised or there is a threat of such compromise. The clause sets out the sorts of action that a direction could require. A direction could, for example, require an energy provider to take action to remove a hostile actor’s presence from their networks, in response to intelligence that a hostile state actor was pre-positioned for an attack. Cyber-attacks on NIS sectors represent a serious and growing threat to the UK’s national security. High-capability actors and hostile states can mount increasingly targeted and sophisticated attacks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  47. To return to the point made by my hon. Friend the Member for Milton Keynes Central about the Bill’s provisions, the Bill looks at particular risks posed by hostile states, related actors and a wide range of other actors. Network and information systems for essential services and the identity of risk sources may be one consideration for organisations and regulators as well as the NCSC. The Bill does not look at specific actors but the outcome of the risk. Of course, hostile actors are an important part of that. I am happy to write to my hon. Friend about wider initiatives outside the Bill, particularly in the public sector, which I know is an important concern for her in relation to hostile state actors. There are a range of initiatives that the Government are taking forward in that context.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  48. A direction could therefore require an entity not to report that national security risk for the period in which the risk was being remedied. They may ordinarily have had to report that national security risk to comply with standard reporting requirements. The clause will resolve that conflict and provide certainty to recipients of directions about what they must do to ensure that the national security risks in a direction are addressed.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  49. I could not judge a specific situation but, broadly speaking, that is the sort of situation, especially if it is an NIS-regulated entity, and in particular where the exercise of the power is focused on the entity’s network and information systems, that I would expect to come in scope of the powers specified here. Under clause 44, a direction can be issued only when necessary for national security. It is possible that, in some circumstances, what is needed to protect UK national security could conflict with standard regulatory duties. For example, a direction might relate to a particularly sensitive national security risk, where only those involved in addressing the risk should be aware of it. That is to minimise the risk of hostile actors becoming aware of a vulnerability.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  50. The clause also grants these powers to regulators, where the regulator has been directed or requested to monitor compliance on behalf of the Secretary of State. This will ensure that they can provide the Secretary of State with the most accurate information. I commend the clauses to the Committee.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD