← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Alison Griffiths

MP for Bognor Regis and Littlehampton · Conservative · United Kingdom

IN THEIR OWN WORDS

The Leader of the House will know that I hold him in great respect, but over the two years for which I have been in this place, I have seen a pattern of behaviour in the final week before the recess—business is announced at the very last second, particularly when it concerns local government reorganisation—and we are seeing an increase in…

BUSINESS OF THE HOUSE · 2026-07-14 · READ IN HANSARD

Last week, I met Paul Greenwood of the Selsey coastguard, one of a team of CROs who cover my constituency. The Court ruled that coastguards can be workers when paid for duties; it did not order Ministers to scrap payments.

MARITIME AND COASTGUARD AGENCY · 2026-07-08 · READ IN HANSARD

Local businesses in Bognor Regis and Littlehampton tell me that they are not recruiting due to the additional cost and uncertainty created by the Employment Rights Act 2025. Has the Secretary of State assessed the impact of Government policy? Employment rights count for little if people cannot get a job in the first place.

TOPICAL QUESTIONS · 2026-06-29 · READ IN HANSARD

T10. My constituent, Joanna, has worked tirelessly to highlight the lack of a dedicated selective mutism pathway in West Sussex. Children are being left without the support they need, so will the Secretary of State commit to ensuring that this gap in provision is finally addressed?

TOPICAL QUESTIONS · 2026-06-22 · READ IN HANSARD

It is a pleasure to serve under your chairmanship, Mr Dowd, and I join other Members in thanking you for chairing this debate. Also, if your Wikipedia page is correct, may I be the first to wish you a very happy birthday for Saturday? I am grateful to the hon.

HUMAN RIGHTS: SUPPLY CHAINS · 2026-06-18 · READ IN HANSARD

The question is whether the Government are prepared to deliver serious enforcement, potentially with the support of new technologies and businesses such as Oritain; or whether they will simply pile fresh cost and complexity on to responsible British businesses while the worst offenders continue to evade accountability.

HUMAN RIGHTS: SUPPLY CHAINS · 2026-06-18 · READ IN HANSARD

The complete record

Every one of 325 lines we hold for Alison Griffiths, in date order, each linked to its source. Free to read, in full, without an account. Page 2 of 7.

  1. The Government have, in effect, acknowledged the issue by proposing limits in lieu—caps on how far they might go—but that does not answer the underlying question. It just manages it. Because this is not about whether the number is 5% or 10%. It is about whether that power should exist at all. There is a broader point here: bigger schemes and consolidation can bring benefits, but only if they improve outcomes, not if they are driven by a single model applied from the top down and not if well-performing schemes are pushed into structures that do not suit them.

    PENSION SCHEMES BILL · 2026-04-15 · READ IN HANSARD

  2. If the Government believe in the strength of their growth agenda, they should make the case for it. They should create the conditions for investment, and they should not need a reserve power to lean on pension funds if that case does not land. The same concern sits at the heart of the Lords amendments to clause 40. Those amendments would strip out what is known as the “asset allocation requirement”. In plain terms, they would remove the mechanism in the Bill that would allow Ministers to set conditions on how pension schemes invest their assets as part of the approval framework. We are told those are only backstop powers that may never be used, but if that is true, why fight so hard to keep them? Why remove amendments that simply take that power off the table?

    PENSION SCHEMES BILL · 2026-04-15 · READ IN HANSARD

  3. There is a simple question running through what we are debating today: who is ultimately in control of people’s pension savings? When I speak to residents in Bognor Regis and Littlehampton, they assume that the answer is straightforward. They assume that their pension exists to deliver the best possible outcome for them, not to serve a wider policy aim and not to be steered from the centre. That is why Lords amendment 1 matters. It would do something very simple. It would remove the ability for Ministers, through regulations, to require schemes to invest in particular assets, particular sectors, or in particular places. It would set a clear boundary. It would say that those decisions sit with trustees, acting in the best interests of savers.

    PENSION SCHEMES BILL · 2026-04-15 · READ IN HANSARD

  4. The situation at Zachary Merton hospital in my constituency is causing deep concern locally. Services there were closed on what residents were told was a temporary basis, but that closure has now been made permanent. The evidence behind that decision has not been clearly set out. Communities rightly expect candour when decisions are taken about the future of local healthcare provision. Does the Leader of the House agree that there is a wider issue here about transparency and accountability for NHS service decisions, and will he consider granting a debate in Government time on the future of community healthcare provision?

    BUSINESS OF THE HOUSE · 2026-03-12 · READ IN HANSARD

  5. Will my hon. Friend join me in thanking and celebrating the fantastic women of Bognor Regis and Littlehampton, who do exactly what she has just described in businesses, in our local democracy, in our third sector and in shaping the futures of our girls in community groups and schools?

    INTERNATIONAL WOMEN’S DAY · 2026-03-12 · READ IN HANSARD

  6. Following International Women’s Day and with English Tourism Week approaching, I have been meeting female entrepreneurs across Bognor Regis and Littlehampton, including Kathleen at the Navigator Hotel, who featured on “The Hotel Inspector” only last week, and many others through my business club. These businesses are vital to coastal economies, but many women say it remains difficult to scale and grow. What assessment has the Minister made of the barriers facing women entrepreneurs in sectors like tourism and hospitality?

    INTERNATIONAL WOMEN’S DAY · 2026-03-11 · READ IN HANSARD

  7. Businesses in my constituency have told me categorically that they are very concerned about this. Entrepreneurs who have taken all the risks to create jobs in their communities run the risk of the Fair Work Agency, which will be given these powers, coming into their businesses and riding roughshod over the work they are creating. How is that liberal and democratic?

    DRAFT EMPLOYMENT RIGHTS ACT 2025 (INVESTIGATORY POWERS) (CONSEQUENTIAL AMENDMENTS) REGULATIONS 2026 · 2026-03-10 · READ IN HANSARD

  8. I recently launched my Bognor Regis and Littlehampton business club. Many who joined are independent hospitality and leisure businesses, and their No.1 concern is how difficult it is to take on new staff under this Government. What assessment has the Department made of the impact of the Treasury’s new jobs tax, and the Government’s new employment regulations, on job creation in coastal constituencies such as mine? What steps is the Secretary of State taking to mitigate those effects?

    UNEMPLOYMENT · 2026-03-09 · READ IN HANSARD

  9. New clause 5 simply asks the Government to commit to reporting back on meeting the milestones they have set themselves for increasing cyber-security standards. Is the Minister confident in the Government’s ability to deliver on their cyber strategy, or is the document not worth the paper it is written on?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  10. The continued use of legacy IT equipment is a particular vulnerability across the Government estate. That will take some time to address entirely, but is there a strategy in place to prioritise the upgrading of this legacy equipment, given that it is one of the greatest areas of exposure?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SEVENTH SITTING) · 2026-02-24 · READ IN HANSARD

  11. I am delighted to hear the Minister’s response. Zachary Merton hospital in Rustington was closed temporarily, but that closure became permanent and the site is being progressed for disposal. More than half of residents in Rustington are elderly, and rely on intermediate and step-down care. They have not been consulted on the permanent closure, despite assurances from Sussex community NHS foundation trust and NHS Sussex integrated care board. Will the Minister confirm whether he considers that a substantial variation in NHS services? Will he consider exercising his call-in powers before the site is irreversibly sold?

    CARE IN THE COMMUNITY · 2026-02-24 · READ IN HANSARD

  12. In my constituency and across West Sussex, the number of EHCPs has risen by 75% since 2019, but the funding to support them has risen by only 37%. Can the Secretary of State reassure parents that the correct funding—not just £24,000 per school—will be in place for support?

    SCHOOLS WHITE PAPER: EVERY CHILD ACHIEVING AND THRIVING · 2026-02-23 · READ IN HANSARD

  13. The new clause would also require that proposals for a single cyber-incident reporting channel be published. That is not a bureaucratic exercise; it reflects concerns raised in evidence that resilience is undermined, not strengthened, when reporting becomes fragmented at moments of stress. Taken together, new clauses 6 and 7 are about making the system clearer at the front end and more usable overall. Clear definitions encourage timely reporting and coherent reporting channels make that reporting effective. I hope that the Committee will give serious consideration to both new clauses.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  14. The Bill expands reporting requirements and introduces new notification duties. That is understandable, but UK Finance told the Committee that many firms already support cyber-incidents under multiple regulatory regimes and that additional reporting layers risk duplication rather than resilience. When an incident is live, that duplication causes friction, slows the response and increases costs. It can reduce the quality of information being shared because teams are stretched across parallel processes rather than focused on managing the incident itself. We do not seek in new clause 7 to reopen the policy intent of the Bill; the new clause would require a review, once these changes are in force, of how the reporting requirements are working in practice. That review would consider costs and interactions with other reporting frameworks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  15. That is the right direction of travel, but when organisations are under pressure, particularly in the first 24 hours of an incident, uncertainty slows action. Time is lost debating definitions rather than focusing on containment, escalation and reporting. New clause 6 addresses that problem directly. It makes it explicit that a ransomware attack is an incident for the purposes of the NIS regulations, and sets out clearly what is meant by ransomware attack. It would not create a new duty; it would remove doubt from an existing one. Clear definitions support better behaviour when organisations are operating under real pressure. New clause 7 follows naturally from that point. If we want faster and clearer reporting, the system into which organisations are reporting has to work in practice, not just on paper.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  16. New clauses 6 and 7 sit together and are linked by the same practical concern regarding clarity and workability when an incident is unfolding. I will start with new clause 6. Ransomware is no longer an occasional or unusual cyber-event; it is now one of the most common and disruptive threats facing essential services, digital providers and their supply chains. Written evidence to this Committee was clear that ransomware incidents are now routine, high-impact events, and that uncertainty at the outset of an attack often makes the consequences worse. The Bill rightly broadens the definition of an incident to capture events that are capable of causing harm, not just those that already have.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  17. Secondly, if Parliament were to require rapid expansion of scope, how confident are the Government that regulators would have the capacity to supervise a much larger and more diverse population without diluting oversight elsewhere? I am not seeking to land a conclusion on new clause 1 today—I understand why it has been tabled and I recognise the seriousness of the issues that it highlights—but if we are going to widen scope, to food or otherwise, the Committee is entitled to press the Government on the discipline and guardrails that will sit behind those decisions. This needs to remain a targeted and credible regime, rather than one that expands without a clear and consistent logic.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  18. The Association of British Insurers, for example, supports higher standards of cyber-resilience, but it also emphasises the importance of clear definitions and coherence between regimes, particularly where firms are already subject to overlapping regulatory requirements. Its point is not about resisting regulation, but about avoiding uncertainty and duplication, which do not improve resilience. My questions are ones of principle rather than position. First, what is the settled test that the Secretary of State will apply when deciding to bring a sector into scope under the clause 24 powers, and how will that judgment be made transparent to Parliament?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  19. If that is the rationale for bringing food into scope early, it inevitably raises questions about other high-value sectors where a single incident can have national economic consequences. That brings us back to clause 24 and the role of the Secretary of State. The Bill is clearly designed to allow scope for provisions to evolve through secondary legislation as risks change. That flexibility is sensible, but flexibility works only if the criteria for widening scope are clear, predictable and capable of being explained to industry, regulators and Parliament. If decisions appear to be reactive or driven by the most recent or most visible incident, confidence in the regime will suffer rather than strengthen. That concern is reflected in the written evidence we have received.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  20. I am vice-Chair of the Business and Trade Committee, and over the past year we have taken evidence on economic security from major UK firms that have experienced serious cyber-incidents. One example everyone here will be familiar with is Jaguar Land Rover. Evidence to our Committee indicated that the cyber-incident there contributed to UK GDP being around 0.1% lower than expected in the third quarter last year, which was not a marginal effect. That reflected disruption to tightly integrated manufacturing systems, with production lines brought to a halt and knock-on impacts across just-in-time supply chains and regional economies. I make that point to underline something simple: cyber-risk presents simultaneously as operational, financial and reputational risk, and in combination those effects can be felt economy-wide.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  21. I want to use new clause 1 as a lens to view a wider question that sits underneath clause 24, rather than as a verdict on the clause itself. That question is how we decide, in a disciplined and credible way, which activities are sufficiently critical to be brought into the scope of the regime, and how that judgment is applied consistently over time. New clause 1 would bring much of the food supply chain directly into scope through primary legislation. I understand the instinct behind that. Food supply is fundamental to public confidence, and disruption would be felt very quickly. However, if the underlying test for inclusion is systemic impact, food is not the only sector that raises these questions.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIFTH SITTING) · 2026-02-10 · READ IN HANSARD

  22. As we heard in written evidence from the ABI, clarity about roles really matters. Can the Minister confirm that the statement of strategic priorities is not intended to operate as indirect instruction, and that regulators will retain clear discretion where sector evidence points in a different direction?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  23. As the Minister is saying, clause 28 is meant to help Parliament understand how regulators are responding to the statement of strategic priorities. Can he say a little about how substantive that reporting will be, and whether it will genuinely allow Parliament to assess how those duties are being exercised in practice?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  24. Having worked in business, I know that the words we use to ensure that the capabilities are there are easy to say but not always easy to deliver. How will the Minister ensure that when we have a multi-sector issue, which could easily come up—particularly, as we have already discussed, around OT and the use of IEDs across multiple sectors—the National Cyber Security Centre and other regulators will have access to the skills, people and resources necessary to manage what could be a catastrophic incident? We already know that cyber-skills are in short supply as it is, even in the commercial sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  25. I thank the Minister for his patience. He mentions a specific example of where he will ensure that the NCSC is resourced up. Do we have specific examples that have happened already of those powers having been put in place successfully? From conversations with the NCSC, I understand that it is reliant on its accredited bodies across the country, but we have not yet—I am touching the wood of my desk, as I speak—had to respond to a complex multi-sector issue. I challenge the Minister on whether he is confident about our capability to respond to one.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  26. My question relates to clause 29 but also clause 30. As the Minister says, the powers are deliberately wide. The Institution of Engineering and Technology noted in evidence that predictability matters more than compliance. Will the Minister explain exactly how the Government will judge when risks require new statutory duties rather than updated guidance, so that businesses are not left guessing?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  27. As the Association of British Insurers has highlighted in its written evidence, the way cost recovery operates will shape behaviour on the ground. Can the Minister reassure the Committee that changes made under clause 34 will be transparent and proportionate and will not inadvertently discourage investment in cyber-resilience, particularly for smaller firms in supply chains? On a personal point, could I ask him to speak more slowly? I am really struggling to hear him.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  28. Further to that point of order, Mr Stringer. Genuinely, I simply need the Minister to speak slowly and clearly. Yes, I am wearing hearing aids; I am sure that others wear them too. I am doing my very best to make sure that I can lip-read, but that is almost impossible given the speed the Minister is speaking at. One cannot lip read when he is looking down all the time either.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  29. We heard from the Information Systems Audit and Control Association that codes work best when they reflect operational reality. Given their evidential status, can the Minister reassure the Committee that codes will remain practical and iterative and not quietly harden into rigid compliance rules?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  30. These procedures are standard, but the powers they apply to are significant. Where regulations under part 3 would materially expand duties or bring new actors into scope, have the Government considered whether those should receive deeper scrutiny in practice, even if the formal procedure remains the usual one?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SIXTH SITTING) · 2026-02-10 · READ IN HANSARD

  31. Does my hon. Friend agree that, although we support the intent behind the Bill, clause 2 does a lot of framing work but does not necessarily consider the extensive perimeter that is coming through and how proportionality will be applied in practice? I suggest that the Committee keep that in mind as we move through the detail.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  32. Clause 4 relies heavily on capacity as the trigger for regulation. I understand why that is attractive: it is measurable. But capacity is not the same as criticality, and a high-capacity facility used for redundancy can present less systemic risk than a smaller, highly concentrated one. I simply put on record that the way this threshold is applied in practice will matter more than the number itself.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  33. My hon. Friend is making a very good point, which also applies to improving board awareness and ensuring that the enforcement of the regulations incentivises boards to take the issue seriously and make sure that they are equipped to understand the commercial reality of cyber-security for their businesses. Enforcement is an important part of that.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  34. Clause 7 is definition-heavy, and rightly so; these terms decide who is regulated and who is not. My only observation is that cloud models are, as the Minister knows, evolving quickly because of the AI revolution. Definitions that track architecture too closely will age fast, so the Committee should be alert to whether these terms will still make sense in five years’ time and not just today.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  35. Bringing MSPs into scope is the right direction of travel, and MSPs sit at points of concentrated risk, but they are not all the same and the real risk is not size alone but the level of privileged access and cross-customer dependency. Proportionality will be critical under these provisions if we want better security, not just box-ticking.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  36. I think my hon. Friend is about to reference the commercial impacts on MSPs. We have already referenced the fact that they are of many different sizes. One of the concerns the Committee will need to consider is whether new contracts will need to be written. The level of uncertainty being created may render the existing frameworks within which they operate redundant.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  37. On my hon. Friend’s point about the lack of clarity in the Bill, there is a real possibility that firms will find that an MSP has one view of an issue while their client has another. Unless there is sufficient clarity in the wording of the Bill, we will have issues.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  38. My concern is not about the existence of the power. It is about whether, in practice, the power will be used early enough and clearly enough to address shared OT risks before they become cross-sector incidents. Operational resilience today depends less on individual sites and more on the security practices of a relatively small— I would say very small—number of OT suppliers that sit behind them. The clause has the potential to address that, but only if its application is focused on genuine systemic risk and supported by clear signals to suppliers and operators alike. For those reasons, the clause warrants careful consideration as the Bill progresses.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  39. The risk is amplified in OT, where suppliers may discover vulnerabilities before operators do, and where one operator may report an issue, while others in different sectors, using identical equipment, remain unaware. There is also a traceability problem. OT equipment is frequently sold through integrators and distributors. Manufacturers may not have a clear picture of where the equipment is ultimately deployed. Without that visibility, national-scale vulnerability notification and co-ordinated response become very difficult. UK Finance has also drawn attention to the complexity of multi-tier supply chains and the need for clear accountability when regulatory reach extends upstream. The clause recognises that reality, but its effectiveness will depend on how consistently and predictably designation decisions are made across sectors.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  40. The risk is not hypothetical. A single vulnerability in widely deployed OT equipment can create a common mode failure across multiple sectors at the same time, even where each operator is individually compliant with its duties. At the moment, the Bill places obligations squarely on operators of essential services, but in OT environments, operators do not control the design of equipment, the firmware, the vulnerability disclosure process or the remote access arrangements that vendors often require as a condition of support. As Rik Ferguson highlighted in written evidence to this Committee, uncertainty about how and when suppliers might be brought into scope can lead to defensive behaviour and late engagement.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  41. The clause merits close scrutiny, because it is the point in the Bill where risk is supposed to be addressed beyond the individual operator and into the supply chain. In plain terms, clause 12 will allow the regulator to designate a supplier as critical where disruption to that supplier would have a significant impact on the delivery of an essential or digital service. The trigger is impact, not size or sector. That approach is sensible, but I want to stress-test how it works in the context of operational technology. Across power, telecoms, transport, water and industry, many essential services rely on the same family of industrial control equipment. Substations, signalling systems and industrial plants may look different, but they often run on identical controlled devices and firmware supplied by a very small number of manufacturers.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  42. The clause is drafted broadly, which is understandable, but in practice many of the supply chains, as my hon. Friend has ably demonstrated, involve several layers of providers and sub-providers. I would welcome clarity on how regulators are expected to approach designation in these cases, so that responsibility is clear and preparation can happen upstream, rather than only after an incident.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  43. What this legislation talks about, through the secondary legislation, is bringing organisations into scope and mandating specific security controls or specific requirements on those organisations in terms of security, but while the law might come in over a weekend, organisational change will not necessarily follow. There is a potential issue there. I can see the benefit and attractiveness of secondary legislation being used to achieve that aim, but having a clearer baseline as to what that sort of scope might look like—it could be ramped up or down, and the volume could be turned up or down, depending on need—would be more helpful. Reducing scope while diverging from NIS2 might be a benefit in terms of the commercial reality, but it might be a misstep in terms of security and the long tail that it takes to get more secure.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  44. Q You have both mentioned the risk involved in supply chains. Do you think that, outside regulated industries, the Bill goes far enough to secure supply chains? If not, what would your recommendations be? David Cook: The legislation talks about secondary legislation, so it allows for an agile, flexible programme whereby organisations can be brought within scope very quickly if concerns make that necessary. What that leaves us with, though, is that although legislation can be changed quickly, organisations often cannot. Where there is a definition, as we see with NIS2, as to which entities are in scope, organisations can embark on a multi-year programme to get into a compliant position. They can throw money at it, effectively.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  45. I am so sorry. Could you possibly speak into the microphone? I cannot hear you. Stuart McKean: Sorry. I was saying that the cyber-criminal does not care about lines, geographies or standards. They do not care whether you have an international standard or you follow the legislation of a certain country. They will attack where they see the weak link.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  46. Q Returning to the supply chain risks, I want to ask you about the difference between OT—operational technology—and IT, and whether there is sufficient detail in the Bill to protect that. If you have intelligent electronic devices from single suppliers across multiple sectors, are we confident that there is sufficient detail about what the regulatory role is in saying that suppliers should be within scope? Is more detail needed in the Bill? Stuart McKean: I am not an expert on the detail, but I would say that there is currently very little detail in the Bill regarding IT and OT.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  47. Q Do you think that there should be more or not? Stuart McKean: The devil is always in the detail, so any more clarity that can be put in the Bill is always going to be a good thing.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  48. Does anyone have anything else? Jill Broom: I think that I will need to come back to you in writing on the specifics of operational technology.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  49. Ben Lyons: The broad approach that the UK is taking is sensible, in that the existing guidance has a range of principles around OT, as well as IT, security. Manufacturing is not in the scope of the Bill, which is probably appropriate, but it is worth looking at what could be done to improve the security of the manufacturing sector, more broadly, probably through non-legislative means. In light of recent attacks, it is important to ensure that guidance and incentives are in place to support that sector.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  50. Q I have two specific questions. The first is about OT versus IT. Do you think that OT and its supply chains are sufficiently covered in the Bill? Secondly, given that you are all from commercial organisations, from your direct client experience, what is going to be the thing that moves the dial on board governance, specifically in relation to cyber? Chris Anley: On the OT versus IT question, we have mentioned specificity versus flexibility. The benefit of the UK sectoral regulator model is that regulators that are in areas where OT is predominant can set specific measures that can reinforce those environments, whereas if you try a one-size-fits-all approach, you run the risk of certain critical OT-based systems becoming subject to successful attacks.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD