David Chadwick
MP for Brecon, Radnor and Cwm Tawe · Liberal Democrat · United Kingdom
“Q3. Two weeks ago, the news leaked that Powys teaching health board is considering taking the beds out of all but two community hospitals in Powys. Some 2,500 people have already signed my petition against those cuts.”
“The imposition of tariff barriers alone is not sufficient to address the shortcomings in our steel industry. The Minister said that it is important to provide more opportunities to help people buy British steel, but there is a difference between saying that and making it happen.”
“I am intervening because the hon. Lady mentioned Port Talbot. Last year, I met the Associated British Ports in Port Talbot. It raised concerns that the current rail link into the docks may not have the gauge needed for the large structures that will be brought in for assembly or to get freight out from the new freeport that will be create…”
“My constituency is home to the Sennybridge training area, an area of vital national importance that borders Merthyr Cynog. The military training area exists only because local farmers surrendered their farms for the national interest.”
“The Foreign Secretary will know that the ongoing violence continues to take a horrific toll on civilian populations across Lebanon, Gaza and the wider region.”
“Powys has no general hospital, so my constituents are dependent on access to English hospitals for the treatment and operations they need. However, last July, Powys teaching health board made the decision to extend waiting times for Powys patients awaiting operations, with the result that many have now been waiting years, often in agonisi…”
The complete record
Every one of 456 lines we hold for David Chadwick, in date order, each linked to its source. Free to read, in full, without an account. Page 3 of 10.
“My hon. Friend will be aware that we are in the week of St David’s day, which is a terribly important day for all of us in Wales. In terms of accountability, she will be very aware of the long-standing stance that the Liberal Democrats have taken on the Crown Estate, which in Wales regrettably still has not been devolved. Its powers and funding have been devolved to Scotland, but not—”
“Likewise, the attack on Gloucester city council cost the taxpayer more than £1 million and put at risk some of the most sensitive information held on UK residents, particularly if one considers the nature of employment in Gloucestershire. The reporting from those attacks showed that local authorities, which are cash-strapped and struggling to make do as they are, had to divert staffing resources into addressing those incidents.”
“Members of the Committee who have served on local authorities will be well aware that a cyber-attack hitting a local authority creates problems with welfare payments, housing services, processing benefits payments, accessing social care for the most vulnerable in our society and collecting bins. Those are crucial activities in the day-to-day life of our society and our democracy. A cyber-attack can leave families without support, vulnerable children without protection and elderly residents without care, yet the Minister has suggested that these services are not necessary to the day-to-day functioning of society. I disagree with that. We have already seen the consequences at Tewkesbury borough council, where a cyber-attack was so severe that it triggered a major incident and crippled core services.”
“New clauses 8 and 9 would close a dangerous gap at the heart of the Government’s cyber-security strategy. Right now, the Bill creates a two-tier system. Private companies running critical national infrastructure face strict legal duties, enforcement and oversight, yet the very public institutions that hold our democracy together and protect our most vulnerable citizens are left outside statutory protection. Nowhere is that more alarming than with our local authorities. Indeed, that is where the Government’s approach diverges from some EU member states. For example, the Netherlands is applying its equivalent legislation to local authorities. When a council suffers a cyber-attack, it is not just an IT inconvenience; it means real life grinding to halt.”
“The Minister will be aware that the ramifications of the JLR attack were felt across south Wales because of the link to the steel industry supply chain. Our neighbours in the European Union already recognise this issue through the NIS2 framework, which covers food production and transport manufacturing as essential sectors. The new clauses simply ask the Government to match that seriousness. At their heart, our new clauses are about ending the two-tier approach. We seek the Government’s recognition that councils, political parties, electoral infrastructure and core supply chains are just as critical to national resilience as power stations and data centres. A country is not secure if its public services, at any level, are exposed. Its elections are vulnerable, and its economy can be brought to a standstill by a single cyber-attack.”
“An attack does not need to change an electoral result to be devastating; it need only cast doubt on the integrity of the count or prevent legitimate voters from casting their ballots. We know that trust, once lost, is extraordinarily hard to rebuild. The security of our elections is too important to be left to secondary legislation made at some future date. Finally, our new clauses would require the Government to bring critical manufacturing, food production and large-scale retail distribution into scope. When British companies such as JLR lose billions to cyber-incidents, or when national retailers such as Marks & Spencer are paralysed, it is not just a private commercial issue, but a blow to national economic security, and there is no economic security without cyber-security.”
“The hon. Gentleman makes an important point. We cannot allow these services to be interrupted. He will be well aware of the impact that bins not being collected has on our streets. Councils are being targeted because they hold sensitive personal data and provide much-needed services to the most vulnerable in society, yet they are being left as soft targets, without statutory requirements and the ringfenced resources that accompany them. We cannot claim to be building a cyber-secure Britain while leaving the frontline of public services unprotected. Resilience must extend beyond councils. Our new clauses also ask that our political parties and electoral infrastructure are properly protected, because we know that hostile states and non-state actors are actively seeking to undermine democratic systems.”
“I beg to move amendment 26, in clause 40, page 63, line 7, leave out “5” and insert “3”. This amendment would increase the frequency of the reports that must be published under Clause 40, from every five years to every three years.”
“That is a pragmatic timeline, which allows the Government to identify gaps and close them before they are exploited. The EU’s NIS2 directive explicitly mandates a review by the Commission every three years, and it is not clear why the Government have decided to diverge from that standard. Is it because they believe that the cyber-threat here is considerably less than the one facing European member states? It is simply not clear, which adds to the general sense of bewilderment about this provision. If our European neighbours are reviewing their cyber-security approach every three years, why are the UK Government content to wait for five?”
“Amendment 26, tabled by my hon. Friend the Member for Henley and Thame, seeks to ensure that the Bill keeps pace with the reality that it seeks to regulate. In the world of cyber-security, five years is a lifetime. In the past five years, the size and scale of cyber-attacks has continued to advance at pace, and we can expect the next five years to be the same. In that context, waiting five years for the first formal parliamentary review of the Bill seems dangerous. It risks leaving us with a regulatory framework designed for the threats of yesterday and not tomorrow. The cyber-threat is real, evolving and urgent. The NCSC has reported that nationally significant cyber-incidents more than doubled in 2025 alone. That is why the amendment would change the reporting cycle to once every three years.”
“I beg to ask leave to withdraw the amendment. Amendment , by leave, withdrawn . Clause 40 ordered to stand part of the Bill . Clause 41 Regulations under section 24 or Chapter 3 Question proposed, That the clause stand part of the Bill.”
“I beg to move amendment 27, in clause 43, page 66, line 11, at end insert— “(fa) a requirement to remove, disable or modify hardware, software or other facilities;” This amendment would enable the Secretary of State to issue directions to remove, disable or modify hardware, software or other facilities for national security purposes.”
“Amendment 27, which I move on behalf of my hon. Friend the Member for Henley and Thame, would give the Government the ability to remove, disable or modify hardware and software that could be used to infiltrate British national infrastructure, such as the cables underneath the now approved Chinese mega-embassy in Tower Hamlets. The Prime Minister’s greenlighting of the Chinese super-embassy in the heart of London is a grave mistake that presents an open door for the ramping up of Chinese espionage in our country. It sends a regrettable and shameful message to Hongkongers—many of whom have already been targeted, intimidated and coerced by the Chinese Communist party—that trade deals are being prioritised over their safety. The Government must take a robust stance with hostile states such as China.”
“Given the reassurances from the Minister, I beg to ask leave to withdraw the amendment. Amendment, by leave, withdrawn. Clause 43 ordered to stand part of the Bill. Clause 44 ordered to stand part of the Bill. Clause 45 Monitoring by regulatory authorities Question proposed , That the clause stand part of the Bill.”
“T2. Green GEN Cymru was granted an Ofgem licence within days of this Government coming to power. Is the Secretary of State confident in the process that took place, and can he confirm how far it had reached under the previous Government?”
“Currently, the law requires regulated persons to manage risks to the security of their systems. Amendment 28, tabled by the Liberal Democrats, explicitly inserts “risks arising from fraud” into that duty. It would make it clear that a system cannot be considered secure if it is easily exploited by scammers. Fraud should be considered a national security issue, and there is clearly a relationship between fraud and cyber-security. Scammers across the world are targeting British citizens. Elderly fraud victims in Dyfed-Powys lose £7,900 a day to a tidal wave of scams perpetrated by scammers from many countries across the world, notably Nigeria. UK-wide, in the first half of 2025 alone, criminals stole over £600 million through scams. Surely, we cannot pass a cyber-security and resilience Bill—”
“I beg to move amendment 25, in clause 8, page 7, line 31, at the end insert— “(1A) In paragraph (1), after ‘risks’ insert ‘, including risks arising from fraud,’”. This amendment would explicitly include fraud as one of the risks to the security of network and information systems relevant digital service providers must identify and manage.”
“Surely, we cannot pass a cyber-security and resilience Bill that ignores a crime that affects thousands of people. We know that cyber-security criminals across the world attack individuals to enable themselves to get into systems. Families are losing life savings, and small businesses are shutting down because of this epidemic. The Government often treat fraud as a policing issue, but the amendment would establish that it should be regarded as a cyber-security issue that needs action at the national security level. By amending regulation 12(1) of the NIS regulations, we place a legal duty on digital providers to identify these vulnerabilities proactively. If we mandate that providers manage fraud risks before an incident occurs, we will reduce the number of victims and the devastation caused to livelihoods.”
“The hon. Member is quite right to say that American companies have captured most of the market that he is talking about, particularly the cloud providers. What does he think is stopping British cloud providers from getting a larger share of the market?”
“Welsh Water’s chief executive has one of the highest paid jobs in Wales at almost £900,000 a year, and the company is hiking basic pay to get around the Government’s crackdown on executive bonuses, despite being a not-for-profit. That is even though Welsh Water presides over some of the worst sewage dumping and leaks in the UK and sky-high price rises. Will the Minister look into companies trying to bypass the new regulations in that way and ensure that those loopholes are closed?”
“The hon. Lady is making an excellent speech, and we are all grateful for the opportunity to raise these cases. I have been contacted by a constituent who left the civil service in 1992 and, more than 30 years later, has still not received the pension that she is owed, despite providing proof of service from HMRC and making repeated transfer requests. Despite the fact that the civil service later located her superannuation file, the scheme continued to insist that no record existed. Does the hon. Lady agree that such cases show that the failure is not just delay but deep-rooted maladministration within our state, and that the Government must commit to ensuring people are paid the pensions that they are legally entitled to?”
“For many of my constituents, Evri’s failures have meant money lost, ruined Christmases, wasted time and a growing sense that rural communities are once again expected to put up with worse service. Rural Wales deserves reliability, respect and accountability, not excuses. I urge Ministers to take this issue seriously, and ensure that parcel delivery works for every part of the country, not just the easiest ones to serve.”
“When a parcel company performs badly, consumers are simply stuck with the consequences. Consumer bodies back that up, and companies like Evri consistently rank bottom for customer satisfaction, yet too often nothing seems to change. That is where regulation matters. There must be clear, enforceable service standards for parcel deliveries, including in rural areas, on safe delivery practices, accurate tracking and proper access to customer support when things go wrong. Consumers who have no choice over their courier should not be left navigating automated systems or vague updates when a parcel is lost or delayed. If companies repeatedly fail customers, especially in rural and hard-to-serve areas, there must be consequences—not just guidance or warm words, but real accountability.”
“I want to be clear that, in my opinion, those problems stem from the corporate leadership of Evri. The problem is a systemic one within their business model, and rural areas are feeling the consequences first and hardest. Constituents of mine in the Teme valley tell me that their experience with Evri was awful. One constituent told me that they “have never received a single Evri parcel on time, most never ever arrive, and those that do are weeks or months late.” My constituents tell me that they often pay extra for faster shipping, but they then have to spend significant time processing refunds and working with credit card companies to recover some of the lost money. A frustration for customers is that they often cannot choose their delivery company. It is chosen for them by the retailer they are buying from.”
“It is an honour to serve under your chairmanship, Mr Stringer. I commend the hon. Member for South Shropshire (Stuart Anderson) on securing this debate, and on his excellent speech. Last year, postal services became a source of real frustration, anxiety and, frankly, anger in Radnorshire. Across Brecon, Radnor and Cwm Tawe, and right across rural Wales, we saw serious problems in the run-up to Christmas. Parcels were marked as delivered but never arrived, items were left at farm gates, on main roads or in full view of passers-by, Christmas presents went missing, and essential items were delayed for days or even weeks, and then marked as lost. When things went wrong, people found it almost impossible to speak to a real human being to sort it out.”
“How that can be consolidated is something to be explored. Put yourself in a position of an organisation that is having to make a report: there needs to be clarity on where it has to make it to and what it needs to report.”
“The requirement to have an annual report to the NCSC is a good mechanism for consolidating what we are all seeing, and then for the NCSC to play the role of drawing conclusions. It is worth emphasising that Ofcom is not an operational organisation; we are a regulator. We look to the NCSC to provide threat leadership for what is going on across the piece. I think that that answers your question about where it all comes together. Stuart Okin: I fully support that. The NSCS will be the hub for that type of threat intel and communications, in terms of risks such as pre-positioning and other areas. The gateways will help us to communicate. Ian Hulme: Bringing it back to the practicalities of instant reporting, you said that there are potentially 14 lines of incident reporting because there are 14 competent authorities.”
“It strikes me that, if one of the things that this legislation is to guard against is pre-positioning, and there are 14 parallel reporting systems in place, it could be the case that those pre-positioning attacks are not picked up as co-ordinated attacks from another nation state or organisation, because they are not pulled together in time. Natalie Black: I point to my earlier remarks about information sharing. You are right: that is one of the great benefits of the Bill. To be able to do more, particularly when it comes to pre-positioning attacks, is really important. You will have heard from the NCSC, among others, that that is certainly a threat that we are seeing more and more of. At the moment, it is too difficult to share information between us.”
“Q I would like to continue the line of questioning on the importance of having a single regulator. Other countries, such as the Netherlands, have recently merged their cyber-security organisations. The Bill introduces expanded but sector-specific reporting requirements, to apply to regulators across different sectors. Do you believe that this fragmented reporting landscape risks preventing Government and regulators from forming a coherent a cross-sector picture of emerging threats—particularly when foreign actors may be probing multiple systems simultaneously? If so, what measures could be taken to mitigate that risk?”
“Secondly, we think that there is an opportunity to improve information reporting, particularly incident reporting, and we would welcome working with DSIT and others—I have mentioned the Digital Regulation Cooperation Forum—to help us find a way to make it easier for industry, because the pace at which we need to move means that we want to ensure that there is no unnecessary rub in the system.”
“Q Do you know how you would do that information sharing at the moment? Ian Hulme: As we have already explained, the current regs do not allow us to share the information, which is a bit of a barrier for us. In the future, certainly, we will be working together to try to figure it out. I think that there is also a role for DSIT in that. Natalie Black: First, we currently have a real problem in that information sharing is much harder than it should be. The Bill makes a big difference in addressing that point, not only among ourselves but with DSIT and NCSC.”
“Over time, we will be able to design out and remove a lot of the volume you see impacting the UK public now. That is certainly the plan.”
“One of the other things we do in a much more automated and technical way—again funded by the Home Office—is the replacement of the Action Fraud system with the new Report Fraud system. That will, over the next year or so, start to ingest a lot of private sector datasets from financial institutions, open-source intelligence companies and the like, so we will have a much broader understanding of all those threats and we will also be able to engage in takedowns and disruptions in an automated way at scale, working with a lot of the communication service providers, banks and others. Instead of the traditional manual way we have always been doing a lot of that protection, we can, through partnerships, start doing it in a much more automated and effective way at scale.”
“They have the global datasets and the bigger picture; we have only a small piece of the puzzle. By working with them jointly on operations, they might bring a number of targets for us, and we can then develop that into operational activity using some of the other tools and techniques that we have. It is quite early days with that pilot, but the first investigation we did down in the south-east resulted in a seizure of about £40 million-worth of cryptocurrency. That is off a commercial contract that cost us a couple of hundred grand. There is potential for return on investment and impact as we scale it up. It is a capability that you can point at any area of online threat, not just cyber-crime and fraud, so there are some huge opportunities for it to really start to impact at scale.”
“If you think about the wealth of cyber-crime, online fraud and so on, all the data, and a lot of the skills and expertise to tackle that sit within the private sector, whereas in law enforcement, we have the law enforcement powers to take action to address some of it. With a recent pilot in the City funded by the Home Office, we have started to move beyond our traditional private sector partnerships. We are working with key existing partners—blockchain analytic companies or open-source intelligence companies—and we are effectively in an openly commercial relationship; we are paying them to undertake operational activity on our behalf. We are saying, “Company a, b or c, we want you to identify UK-based cyber-criminals, online fraudsters, money-laundering and opportunities for crypto-seizure under the Proceeds of Crime Act 2002”.”
“We know that is where most of the volumes are driven from, and obviously we do not have the powers to just go over and get hold of the people we would necessarily want to. You will not be surprised to hear that it really varies between jurisdictions. Some are a lot more keen to address some of the threats emanating from their countries than others. More countries are starting to treat this as more of a priority, but it can take years to investigate an organised crime group or a network, and it takes them seconds to commit the crime. It is a huge challenge. There are two things that we could do more of better—these are things that are in train already.”
“Q Thank you for joining us. You mentioned frauds. It is a fact that criminals across the world are targeting British citizens every day. In Dyfed-Powys, over £500,000 was lost to online fraud in 2023-24, and elderly victims are losing £7,900 a day to fraud. Clearly, these attacks are coming from all over the world. Interpol recently arrested over 800 members of a global criminal network based in Nigeria. From your perspective, how effectively are UK police forces currently able to work with international partners to investigate and prosecute overseas criminals? What additional support from the Government would most improve your ability to mitigate online fraud from overseas? DCS Andrew Gould: That is a really good question. The international jurisdiction challenge for us is huge.”
“A big discussion among CISOs is that having a CISO reporting to a CIO is a conflict of interest. A CISO is essentially a governance position, so you wind up having to govern your boss, which I would submit is a bit of a challenge. How do we help CISOs? First, with stringent application of regulatory instruments. We should also look at or discuss the idea of having C-level or board-level executives specifically liable for not doing proper risk governance of cyber-security—that is something that I think needs to be discussed. Section 172 of the Companies Act 2006 states that you must act in the best interests of your company. In this day and age, I would submit that not addressing cyber-risk is a direct attack on your bottom line.”
“Q Thank you for joining us. Reporting of several recent cyber-attacks has one thing in common: there were often insufficient security measures in place. British Airways in 2018 is just one example. Reportedly, the average tenure of a chief information security officer is 18 months. From your perspective, what do CISOs need from the Bill to help strengthen their hand when they are saying to a board, “This is what I need to do to keep our organisation secure”? Richard Starnes: On what you say about the 18-month tenure, one of the problems is stress. A lot of CISOs are burning out and moving to companies that they consider to have boards that are more receptive to what they do for a living. Some companies get it. Some companies support the CISOs, and maybe have them reporting to a parallel to the CIO, or chief information officer.”
“Do you want to open the door to a regulator coming in and then finding out it is a false positive? You are also going to have a very significant problem with the amount of alerts that you get with a 24-hour notification requirement, because there is going to be an air of caution, particularly with new legislation. Everybody and his brother is going to be saying, “We think we’ve got a problem.” Alternatively, if they do not, then you have a different issue.”
“Q We have heard concerns about definitions, particularly regarding incident reporting. What are your observations on the Bill as it stands, and those definitions? Richard Starnes: Throughout my career, I have been involved in cyber incidents from just about day one. One of the biggest problems that you run into in the first 72 hours, for example, is actually determining whether you have been breached. Just because it looks bad does not mean it is bad. More times than not, you have had indicators of compromise, and you have gone through the entire chain, which has taken you a day, or maybe two or three days, of very diligent work with very clever people to determine that, no, you have not been breached; it was a false positive that was difficult to track down.”
“There is a bit of a void at the moment around information sharing. The cyber security information sharing partnership was set up, I think, 10 years ago— Chris Parker: Yes, 10 years ago. Carla Baker: It was disbanded a couple of months ago, and that has left a massive void. How does industry share intelligence and information about the threats they are seeing? Likewise, how can they receive information about the threat landscape? We have sector-specific things, but there isn’t a global pool, and there is a slight void at the moment.”
“We must incentivise organisations to do more around cyber-security to improve their security posture. We heard from previous panellists about the threats that are arising, so organisations have to take a step forward. Secondly, I think the Government should use their purchasing power and their position to start supporting organisations that are doing the right thing and are championing good cyber-security. There is more that the Government can do there. They could use procurement processes to mandate certain security requirements. We know that Cyber Essentials is nearly always on procurement tenders and all those types of things, but more can be done here to embed the need for enhanced security requirements. Thirdly, I think a previous witness talked about information sharing.”
“Carla Baker: I think we are in a really interesting and exciting part of policy development: we have the Bill, and we have recently had the Government cyber action plan, which you may have heard about; and the national cyber action plan is coming in a few months’ time. The Government cyber action plan is internally facing, looking at what the Government need to do to address their resilience. The national cyber action plan is wider and looks at what the UK must do. We are at a really exciting point, with lots of focus and attention on cyber-security. To address your point, I think there are three overarching things that we should be looking at. First is incentivising organisations, which is part of the Bill and will hopefully be a big part of the national cyber action plan.”
“They do not have the capability to cover compliance and regulatory load easily, and we would probably all accept that. We have to be careful when talking about things such as designating critical suppliers. All of this wraps up into increasing collaboration through public-private partnerships and building trust, so that when the Government and hard-working civil servants want to see which boundaries are right to push and which are not, bodies such as the UK cyber resilience committee, which Carla and I are on, can use those collaborative examples as much as possible. There is quite a lot there, but something the UK certainly should be pushing to do is culture change, which we know has to be part of it—things have been talked about today by various speakers—as well as the harmonisation of standards.”
“I think it is something the UK could definitely do because of our unique position in looking at multiple jurisdictions. We also have our own responsibilities, not only with the Commonwealth but with other bodies that we are part of, such as the United Nations. It is not all good news. The challenge is that, as much as we know that harmonisation is okay, unfortunately everyone is moving. Things have started, and everyone is running hot. An important point to make is that it is one of the busiest sectors in the world right now, and everybody is very busy. This comes back to the UK having a particular eye on regulatory load, versus the important part that other elements of our society want, which is growth and economic prosperity. We talked earlier about SMEs.”
“Of course, our footprints, as big businesses, mean that we are always collaborating and talking to our teams around the world. In terms of what the UK can do more of, a lot of the things that have to change are a function of two words: culture and harmonisation—harmonisation of standards. It is about trying not to be too concerned about getting everything absolutely right scientifically, which is quite tempting, but to make sure we can harmonise examples of international cyber-standards. It is about going after some commonality and those sorts of things. I think the UK could have a unique role in driving that, as we have done with other organisations based out of London, such as the International Maritime Organisation for shipping standards. That is an aspiration, but we should all drive towards it.”
“Q Thank you both for joining us. I have a very broad, open question: what other measures, both legislative and non-legislative, could the UK Government take to enhance the cyber-resilience of the UK’s critical national infrastructure? Chris Parker: That is an excellent question. The good news is that a lot is happening already. An enormous amount of collaborative effort is going on at the moment. We must also give grace to the fact that it is a very new sector and a new problem, so everybody is going at it. That leads me on to the fact that the UK has a critical role in this, but it is a global problem, and therefore the amount of international collaboration is significant—not only from law enforcement and cyber-security agencies, but from businesses.”
“Another thing to mention is that there is a lot of effort in the cyber growth partnership, which is run through DSIT and techUK. It is initiating an idea where people will be lent from industry into academia, to offer inspiration but also to improve lecture quality and standards, because things move fast and we are running so hot. It is very hard for academia to keep up. There is quite a lot that can be done to increase the workforce and skills, but going back to our original points, with greater public-private collaboration and discussion, we will get it absolutely right on focusing on the right places to spend resources.”
“There are an awful lot of jobs in places out there that a lot of people are just not aware of, and perhaps would therefore not be volunteering or aiming towards it—even at their school. There are lots of jobs in cyber sales, marketing and analysis that do not require a very high level of mathematics, for example. Some of them do not need a very high level of mathematics at all. I think that some awareness needs to be built there. Personally, I would like to see more championing of the people who are in the sector at the moment. We have some fantastic young men and women in the sector, but we also need to make sure they are able to have chartered status. It is out there, now that we are starting, but it needs to gather pace, because we need to make sure these people are represented and feel professional, so that it can be reflected.”