Bradley Thomas
MP for Bromsgrove · Conservative · United Kingdom
“Does my hon. Friend agree that is perhaps the most corrosive consequence of all? Businesses have all the pressure that is bearing down on them, and so many are telling me that it is just not worth it.”
“We know that higher-level apprenticeships are now out-earning the average degree, according to the Centre for Social Justice. The right qualification at the right time can alter the trajectory of an entire family for generations, but we must also be honest that warm words alone will not create a single apprenticeship place, and with level…”
“It would: scrap real interest rates on plan 2 student loans so that balances can no longer rise faster than inflation, saving graduates tens of thousands of pounds over the course of their careers; create 100,000 more apprenticeships for 18 to 21-year-olds by lifting funding caps and supporting employers with up to £5,000 for every Britis…”
“That aspiration is welcome, but aspiration without delivery does little for young people looking for an apprenticeship today or for the small business struggling to recruit for today and tomorrow.”
“That is why I am proud that the previous Conservative Government introduced T-levels, degree-level apprenticeships and the apprenticeship levy, and put English and maths at the heart of all vocational qualifications, helping people to climb up the ladder of opportunity and fortify their careers with the in-demand skills that businesses ne…”
“This is long overdue, and so I congratulate the Prime Minister on bringing this forward and for the tone in which he has delivered it. I would like to raise the case of Jenny and Scott, two constituents who I have been supporting in recent months. They have been fostering a child called Alfie for six years.”
The complete record
Every one of 603 lines we hold for Bradley Thomas, in date order, each linked to its source. Free to read, in full, without an account. Page 3 of 13.
“On the point about information sharing with a view to bolstering resilience, Marks and Spencer reported to me that it was surprised to have received more information from the FBI on the origin and impact of the cyber-attack that it suffered than it received from UK authorities. That should adequately demonstrate why sufficient data sharing is required to underpin our resilience and bolster our strength.”
“Given that the threshold for a significant impact event will likely be much lower for an SME than for a larger corporation, and while acknowledging and agreeing that SMEs are the backbone of the economy and make up the vast majority of companies that employ people in this country, how does the hon. Gentleman propose to strike the relevant balance between ensuring that SMEs are supported, and at the same time that they are not inundated and overwhelmed as a result of that significant impact threshold likely being much lower for SMEs?”
“While I agree with the hon. Member, and acknowledge witnesses’ evidence suggesting that cyber-security should be a board-level responsibility, does he share my concern that, given the complexity and technical nature of cyber-security, there is perhaps a risk of, for want of a better phrase, window dressing? It may be that non-competent people without the relevant technical expertise could be reliant on reports issued by other technical staff who do not sit at board level. We have to strike the right balance. Does the hon. Member share that concern, and how does he propose we address that?”
“Several weeks ago, I received a jaw-dropping email from a local Bromsgrove GP, who told me that a 10-month-old child nearly died after ambulance delays. Worse, the same day, another patient—a 66-year-old driving instructor—suffered a cardiac arrest during a driving lesson and died while being driven to the hospital by his wife. My constituents demand a better service and better response times. What are the Government going to do about this, and will the Secretary of State meet me and the concerned GP who wrote to me to address this issue?”
“Bromsgrove golf course is in open countryside. It is a beautiful, green open space and one of the most popular golf courses anywhere in the country, and it contains more than 20,000 trees. Does the Minister really think that it is suitable for development, particularly at scale? Will he rule out development on such golf courses? If not, will he meet me and members of the golf club to discuss their concerns?”
“Last year, 9.7% of vehicles sold in the UK were Chinese-manufactured electric vehicles—a near doubling of the market share that they had the year before, which stood at 4.9%. What assessment has the Secretary of State’s Department made of the threat that this may pose to national security and to our industrial resilience, and does she share my concerns?”
“Heritage buildings are much loved by many members of the community. They underpin our identity. Indeed, many of them are places of worship, including the fantastic St John’s church in Bromsgrove, the spire of which has just had a £500,000 renovation. Will the Leader of the House join me in congratulating the Friends of St John’s, particularly Jo Slade, who was a driving force behind the project? Will the Leader of the House press his colleagues in government, particularly in the Treasury, to ensure that the Government always do everything they can to maximise support for these important and much-loved buildings?”
“Quite often, those conditions are laboratory conditions that do not bear any resemblance to reality, so I invite the mobile phone companies to come and do a very thorough inspection across Bromsgrove and the villages.”
“Rural Britain is far too frequently romanticised as a place of bucolic tranquillity; it is that, but it demands parity with urban Britain at the same time. What does that mean? It means that we want a reliable mobile phone signal, so that we can drive down the road on a short journey without it cutting out, and if we need to receive a call from a loved one, a relative or perhaps a GP, we can have certainty that that call will come through. Coverage maps have been drawn with a particularly optimistic crayon, and the problem with advertised speeds being hundreds of times better than reality is not merely technical; it also erodes trust.”
“I cannot stress enough how sick and tired I am of hearing from mobile phone companies that everyone is just consuming data. As the traditional telephone service is switched off, constituents—particularly those living in rural areas—are increasingly reliant on the ability to make voice calls. The lived reality for a business in rural Worcestershire attempting to submit mandatory forms online to a regulator or placing an order, is that they must drive to the nearest town to do so. Businesses cannot reliably place orders or process card payments. As banks close in our towns and villages, people are shifting or being pushed towards more online digital services, so it is crucial that we have the mobile connectivity to back that up. If I may say so, there is also a little bit of cultural condescension at work.”
“After all, rural topography presents challenges—there are hills, and trees are inconveniently organic. What cannot be forgiven, though, is the persistent gulf between what is claimed and what is delivered. It is the same with broadband; we hear broadband providers advertise speeds of up to 80 megabits per second, but the reality of what many of my constituents experience is very different. Those advertised figures are in the realm of fiction. This is not just anecdotal grumbling from the shires; a survey by the National Farmers Union has painted a sobering picture, with 21% of respondents reporting broadband speeds under 10 megabits per second in 2026. This is at a time when a single video could devour bandwidth instantly. What my constituents want is the ability to consume data and make voice calls at the same time.”
“There are farms and villages where the coverage map glows reassuringly in bright corporate colours, but the lived reality is far too often just a single bar if you stand at the upstairs window, facing north and holding your phone aloft like some kind of digital divining rod. We have already heard about how the River Severn Partnership in Worcestershire was a beneficiary of this. Quite innovatively, local councils stuck gadgets on the bin lorries that went up and down every single road, particularly the rural roads, and realised what we probably all suspect: how terrible the service is. In parts of Worcestershire, the mobile phone signal is around 900 times worse than the mobile phone operators claim. We could forgive the odd dropped call.”
“I congratulate the hon. Member for North Shropshire (Helen Morgan) on being persistent and finally securing this very important debate. Few phrases in modern Britain ring as hollow as “world-class connectivity”. Speaking plainly, rural mobile phone connectivity in this country is not merely patchy or inconsistent; in some places, it is so poor that the advertised service bears no resemblance to reality. There are areas in which actual service levels are hundreds of times worse than advertised—that is not a rounding error, or the result of momentary network congestion. It is a difference between promise and performance that is so vast that it would be comic if it were not so economically corrosive. Take Worcestershire, for example. It is a rural county, with lots of villages, small towns and industrious small businesses.”
“Land matters, and the people who steward it and rely on these mobile phone connections matter. That means that the Government should give serious consideration to rural roaming. Finally, infrastructure sharing should be pursued with seriousness to ensure that mobile phone coverage across the country, but particularly across Bromsgrove and the villages, is as robust as it can be.”
“My hon. Friend is spot on. Constituents, particularly older residents, have contacted me because they have missed out on crucial calls from GPs and other supporting services that they require. It is about the safety and wellbeing of our constituents as much as it is about connectivity and the economy. In the limited time that I have, I have a few points that I implore the Government to focus on. First, transparency must improve. That means bolstering regulatory requirements for the mobile phone companies to advertise speeds that are realistic, not theoretical and based on laboratory conditions. Secondly, it is not just about population coverage, but geographic coverage, which must carry greater regulatory weight. Britain is not composed solely of cities.”
“It will likely be the highest increase in council tax across the country this year, and it is reprehensible, because prior to the general election in 2024, the Labour party stood clearly on a manifesto that said it would freeze council tax. Labour Members know as well as I do that they have no will to deliver that.”
“I will keep my comments brief, and they will be focused on council tax. The reason they will be brief is that I was hoping to intervene earlier on the Secretary of State. He said that he did not want to dodge difficult topics and wanted to talk about promises, but he did not take an intervention from me, probably because he knew what was coming. I will talk about broken promises and about difficult topics. The primary one affecting my residents right now across Bromsgrove and the villages, as well as people across Worcestershire, is the Government’s collusion with Reform to hike council tax by a staggering 9%. That will be the highest council tax increase that Worcestershire county council has imposed on its residents.”
“Reform thought that it could turn the sofa upside down, give it a good shake and £100 million would fall out. Well, that did not happen. Instead, I can tell the House what has happened in Worcestershire. Since last May, the overspend by the Reform administration has been £100 million. As a result, it has come cap in hand to the Government for emergency funding and for a council tax rise way in excess of inflation and of the 5% threshold for a referendum.”
“I will not give way, because the Secretary of State would not give way to me. I will not give way and be lectured to by Labour MPs who are not upholding their promises. The Government stood on a manifesto to freeze council tax, knowing full well that they would not be able to deliver that. Worse still, last May, prior to the local elections, the Reform party stuffed leaflets through the doors of residents across Worcestershire and across the country pledging that it would cut council tax. Reform spoke about this DOGE—Department of Government Efficiency—programme for local government. It is interesting that not a single Reform Member of Parliament is here in the Chamber today to defend their record. Where is this DOGE programme? Why has it revealed nothing?”
“My message to the Minister is very clear: if we want to maintain trust and integrity in politics at all levels, it is important for such promises to be stuck to and abided by, or else not to be made in the first place. Most importantly of all, in the last 48 hours more than 1,100 Worcestershire residents have signed a petition opposing this increase. It is crucial that the issue goes to a referendum, and that the people of Worcestershire have their say.”
“I thank my hon. Friend and neighbour; he is far too generous. I was leader of Wychavon district council in south Worcestershire for five years, and we proudly froze council tax for five years consistently without cutting a single service. Local government is lean. It can be run efficiently and effectively without duping the taxpayer. But let us return to that dupe. The Reform administration on Worcestershire county council went cap in hand to the Government, and the Government have granted it emergency funding. They have agreed and, in effect, colluded with Reform. Two parties have agreed to put up council tax for residents when both had promised that they would not do so, and Worcestershire residents are paying the price.”
“Residents across the country knew ahead of the general election that the Prime Minister had made various very public pledges that the Labour party would freeze council tax should it come to office. If there is a mistake on my part and those words were not in the manifesto, I apologise for that, but—here I return to my point about trust in politics—if we want residents across the country to have faith in the political system, it is important for politicians to stand by their promises, whether they are written in a manifesto or uttered on television.”
“I have two points for the Minister to address. First, could he clarify whether an organisation would face repercussions if a regulator believed in retrospect that notification should have been provided sooner? Secondly, on customer notification, can the Minister address the concern around striking the right balance between informing the customer and ensuring that the update that they receive is meaningful and not so vague that it causes further distress or worry?”
“It is undisputable that last year’s espionage trials threw a harsh spotlight on the threatening scale of state-sponsored cyber-attacks. Improving our national cyber-resilience, and safeguarding all our infrastructure and essential services, including in the private sector, is vital in order to secure a prosperous economy and reinforce public confidence in our ability to defend ourselves against such threats.”
“These cyber-threats are not going away; they are only going to get stronger and more technically advanced. We have seen that in the past year, with the National Cyber Security Centre reporting a 50% increase in British cyber-incidents deemed highly significant. Indeed, representatives of M&S told me that, at times, they found it much easier to get updates and information from the United States FBI than they did from our own authorities. We also know that foreign hostile states are becoming bolder in their actions against us. A few months ago—as a reason for introducing my ten-minute rule Bill, the Cyber Extortion and Ransomware (Reporting) Bill—I stated that research had revealed that 74% of UK IT leaders cited China and 71% cited Russia as their top cyber-security concerns.”
“Also potentially falling outside the regulatory reach is Marks & Spencer, whose recent cyber-attack was another stark reminder of the rapidly advancing cyber-crimes scene and caused significant disruption, with costs estimated to run into the millions of pounds. Having met with M&S representatives recently, I had the opportunity to discuss their experience of enduring such an attack. Archie Norman, M&S chair, gave evidence to the Business and Trade Sub-Committee on Economic Security, Arms and Export Controls, where he said that “a growth economy” is “a cyber-resilient economy”. Having a cyber-resilient UK, and making the UK the safest place to do business, is a competitive advantage. I agree with that sentiment and firmly believe that increasing our cyber-resilience can only benefit our economy. It is imperative that we get this right.”
“It is therefore no surprise that the cyber-attack it endured, estimated to have had a financial impact of over £1 billion, was significant to many, including more than 5,000 organisations impacted and many of my constituents, with JLR being one of the largest direct and indirect employers in the west midlands region. How, then, if a key aim of the Bill is to ensure that all essential services whose disruption would profoundly impact our nation in the event of a cyber-attack report all major incidents, can the vagueness of the definition of essential services be allowed to stand—especially when it creates a situation in which previous key victims are excluded? Of course, JLR is not the only victim where questions of inclusion remain.”
“In addition, industry experts have publicly shared concerns about how far the net may be cast in some sectors, leading to the unintentional inclusion of organisations that are critical only to a single larger organisation, rather than to our national security, while ignoring other essential sectors altogether. Looking at recent cyber-attacks that have had a significant impact on our country, it is concerning that the definition of essential services may not include them within scope. While it is predicted that many of Jaguar Land Rover’s supply chains will be in scope, it has been publicly questioned whether it will be included. As the largest car manufacturer in the United Kingdom, it directly employs over 30,000 people across the UK and supports around 100,000 jobs indirectly.”
“Such an approach would not only allow for the quick reactions that cyber-security demands, but respect parliamentary processes and safeguard against organisations’ being unaware that they had suddenly been brought into scope until they received a potentially financially ruinous penalty notice for non-compliance. Looking at the need for more definitive guidelines on who will be regulated under the Bill, we have already heard from numerous industry stakeholders that are unsure whether they, or other organisations in their sector, will fall within the mandatory scope.”
“I support the notion that all legislation should receive the scrutiny it is due by the democratically elected Members of the House of Commons. That is why I believe the Bill must not only set out clearer guidelines for who is in scope, but require an official amendment, debated in the House, to permanently bring any new sectors into scope after the Bill has been passed. I understand that, in times of emergency, the longer process of House of Commons scrutiny may not always be possible. That is why the Secretary of State should have powers to bring in sectors necessary in an emergency temporarily into scope, with less imposing of non-compliance penalties until their inclusion is made permanent by the House.”
“The powers afforded to the Secretary of State to change the classification of essential activity, and to bring new sectors into scope of the Bill at any time, undoubtedly create uncertainty for many sectors and cast a shadow over long-term compliance. To be clear, we want organisations to comply with this legislation. We want to improve national cyber-resilience, gather vital intelligence and restore public confidence in our security. Why, then, would there not be a significant effort to make these regulations as easy to apply as possible, rather than leaving thousands of businesses second-guessing whether they fall within scope, with the pressure of large financial penalties hanging over their heads? In addition, many will know that I am a firm supporter of parliamentary process.”
“It is a pleasure to serve under your chairmanship, Dr Murrison. When introducing new legislation, it is essential that those who fall under its new regulations be clearly identified and given adequate time to prepare for compliance. However, despite the aims of the Bill and the wish to avoid worsening a cyber-attack incident, the Bill still presents far too much ambiguity. It is right to recognise the cyber landscape as continuously evolving. There is no dispute that this terrain becomes increasingly complex each day, requiring a level of flexibility in legislation to ensure that it keeps pace. However, this desire to safeguard such adaptability, and the goal of future-proofing, must not come at the expense of the effectiveness of legislation in the present day.”
“I have two points for the Minister to address. First, can he address concerns around whether funds raised will be directly reinvested into improving cyber-security, rather than covering administrative overheads? Secondly, there is no specific reference to turnover thresholds, so how can the Minister be sure that a one-size-fits-all approach will not be used, causing many similar organisations to suffer financially?”
“On the point about banding, can the Minister assure us that there will be consistency applied across regulators so that different events are not differentially penalised depending on the regulatory body? On the question of turnover and the financial penalty, can the Minister elaborate on how the figure was derived?”
“I have much sympathy with the hon. Gentleman’s arguments about the importance of local government, and I believe that it should be within scope of the Bill. Essential services are provided by councils on a day-to-day basis, but local councils are increasingly cash-strapped. Does he share my concern about the burden of compliance falling on councils, many of which differ in size and scale from their adjacent neighbours? They have differing degrees of IT infrastructure capability. We run the risk of increasing the compliance and regulatory burden on councils at a time when they may already have stretched budgets and lack the resource and capacity in the system to accommodate that additional burden.”
“What consideration has been given to the potential conflict between data centres’ contractual obligation regarding customer confidentiality and mandatory rapid reporting? What assurance can the Minister give us that data centres will ensure that the conflict does not impact their future business?”
“On the growth of this industry, and with 78% of UK enterprises relying on cloud-based services, 96% of companies expected to use public cloud services, 35% of UK businesses outsourcing IT support and, as of last year, 63% of organisations planning to continue or increase their IT outsourcing over the next 12 months, does my hon. Friend the shadow Minister agree that greater consideration—or at least elaboration—must be given to the vulnerability of the supply chain of large load data centres?”
“Does the shadow Minister agree that the Government should heed the message of Chris Dimitriadis, the chief global strategy officer at the Information Systems Audit and Control Association? He said: “The era when cyber regulation could focus solely on critical national infrastructure is over. Today, every major employer is part of the digital economy—and therefore part of the threat landscape.” Surely the Government should heed that message.”
“The risk and the threat from hostile states is plain to see. Does my hon. Friend have any sympathy for the ten-minute rule Bill that I introduced a few months ago on the Floor of the House? We need to strike a balance between the risk that bureaucratic administration poses to small businesses and the very real risk that cyber-attacks pose to the economy in general. The Government should have the private sector in scope and look at setting a threshold that does not become burdensome on smaller businesses. My proposal was for any company that turns over £25 million or more to be scope, in order to not bear down too heavily on small companies that would otherwise find the process, the risk and the burden of reporting too onerous.”
“Given the blurring of boundary lines between cyber-attacks and financial crime, I can see the compelling reasons why the amendment has been tabled, but does the shadow Minister agree and acknowledge that fraud detection often requires a different skillset from standard network security, so it is important to strike the right balance?”
“At the point immediately prior to Peter Mandelson’s appointment as ambassador, the UK had a respected ambassador to the United States already in Dame Karen Pierce. Given that fact, the known abhorrence of Jeffrey Epstein and the appalling previous judgment of Peter Mandelson, why did the Government still decide that, on balance, it was a risk worth taking to appoint paedophile-adjacent Peter Mandelson to the post of ambassador?”
“Does my right hon. Friend agree that the public are sick and tired of people who appear to fail upwards in public life, simply for the reason that they appear to move in the right circles?”
“Aside from the evident, persistent and consistent failures in the Prime Minister’s integrity, does this issue not raise massive questions about the hold over the Government and those at the top of the Labour party by someone whose name has been a byword for sleaze for the last two or three decades?”
“Does my hon. Friend agree, particularly following her point about the writing being on the wall, that the Minister, when he wraps up on behalf of the Government, needs to quash any rumours that the Prime Minister is hunkered down in Downing Street and planning a reshuffle to stabilise a sinking ship?”
“Part of the problem with security is that you have small teams running things that are used ubiquitously. We have to think a little differently about this. We have seen outages in recent years that are not necessarily maliciously driven, but have demonstrated to us how reliant we are on technology and how widespread the impact can be, even of something like a local managed service provider. One that happened to provide managed services for a whole region’s local government went down in Germany and it knocked out all local services for some time. You are absolutely right: we should be looking at privately held companies as well. We should be thinking about impact, but measuring impact and figuring out who is in scope and who is not will be really challenging.”
“Q Picking up on what Jen mentioned about FTSE and publicly traded companies being within scope, is there a view on ensuring g that privately owned companies of a particular scale are within scope, and if so, how will you determine that? Might it be based on things such as turnover or number of employees, or would it be some other identifiable characteristic? Jen Ellis: For sure, it should not come down to whether you are public or private; it should be about impact. Figuring out how to measure that is challenging. I will leave that problem with policymakers—you’re welcome. I do not think it is about the number of employees. We have to think about impact in a much more pragmatic way. In the tech sector, relatively small companies can have a very profound impact because they happen to be the thing that is used by everybody.”
“In terms of the where and the how, we are also in favour of a single reporting platform, because that reduces friction around the process, and it allows businesses, ultimately, to know exactly where they are going. They do not need to report here for one regulator and there for another. It is a streamlined process, and it makes the regime as easy as possible to deal with, so it helps incentivise people to act upon it. I have another point to add about the sequencing of alignment with other potential regulation. We know that, for example, the Government’s ransomware proposals include incident-reporting requirements, and they are expected to come via a different legislative vehicle. We need to be careful not to add any additional layers of complexity or other user journeys into an already complex landscape.”
“Our members would agree with it. Companies need to be clear about what needs to be reported, when it needs to be reported and where they need to report it. A bit of clarity is required on that, certainly around definitions. As Sanjana said, it is good to see that the definition is expanding, but definitions such as “capable of having” a significant impact remain unclear for industry. Therefore, we need a bit more clarity, because again, it means that we could risk capturing absolutely everything that is out there, and we really want to focus on: what is most important that we need to be aware of? Determining materiality is essential before making any report.”
“In the absence of those thresholds, our concern is that regulated entities may be tempted to over-report rather than under-report, thereby creating more demand on the efforts of the regulators. We must think about regulatory capacity to deal with all the reports that come through to them, and to understand what might be the trade-offs on the regulated entities, particularly if an entity is regulated by more than one competent authority. For those entities, it would mean reporting to multiple authorities. For organisations that are small or medium-sized enterprises, there is a real concern that the trade-offs may result in procedural compliance over genuine cyber-security and resilience. We call on the Government for immediate clarification of the thresholds linked to those factors. Jill Broom: I would like to come in on that point.”
“It is good to note that the definition of reportable incident has expanded in the current legislation. One of the concerns that the post-implementation reviews had from the previous regulatory regime was that the regulated entities were under-reporting. We note that the Bill has now expanded the definition to include incidents that could have an adverse impact on the security and operations of network and information systems, in addition to those incidents that are having or have had a negative impact. While that is clear on the one hand—some factors have been provided, such as the number of customers affected, the geographical reach and the duration of the incident—what is not clear at the moment is the thresholds linked with those factors.”