← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Lincoln Jopp

MP for Spelthorne · Conservative · United Kingdom

IN THEIR OWN WORDS

All my residents in Spelthorne and I are desperate to get Spelthorne’s five stations into the travelcard zone. The Secretary of State has looked at this in the past, but will she look again, with South Western Railway, at the financial modelling being used to say that it is not possible?

TOPICAL QUESTIONS · 2026-07-16 · READ IN HANSARD

My residents in Spelthorne love their racecourse and have no desire to see it flattened and turned into housing so, as any Member would, I started a petition. It has received over 3,500 signatures so far. I also organised a public meeting in the Magpie pub in Lower Sunbury last week, attended by about 70 people.

FUTURE OF BRITISH HORSERACING · 2026-07-07 · READ IN HANSARD

Barratt Redrow told me on 20 March that it was going to put in a planning application by the end of this year. After I started campaigning vociferously for Kempton Park, it elicited a media statement from the company on Friday that it had no plans to put in a planning application during this calendar year.

FUTURE OF BRITISH HORSERACING · 2026-07-07 · READ IN HANSARD

In the centre, Jukebox Man; on the far side, Gaelic Warrior; and on the near side, Banbridge, in a classic renewal of the Ladbrokes King George.” The reason I focus on that is because I was there on Boxing day last year to watch the running of the King George.

FUTURE OF BRITISH HORSERACING · 2026-07-07 · READ IN HANSARD

The proposal had been seen off under previous planning rules. However, hon. Members will be aware that, under the new national planning policy framework, there is an assumed yes for planning purposes if a proposed development is within 800 metres of a train station with two departures an hour in the same direction.

FUTURE OF BRITISH HORSERACING · 2026-07-07 · READ IN HANSARD

Member for Liverpool Walton (Dan Carden), that it is “an internationally recognised venue and a major economic asset that, once lost, can never be replaced. Locally, it supports jobs and generates substantial spending for hospitality, retail, transport and many other businesses, while providing valuable green space.

FUTURE OF BRITISH HORSERACING · 2026-07-07 · READ IN HANSARD

The complete record

Every one of 599 lines we hold for Lincoln Jopp, in date order, each linked to its source. Free to read, in full, without an account. Page 5 of 12.

  1. Member for Caithness, Sutherland and Easter Ross (Jamie Stone) mentioned, we had the Russian spy ship and the threat to subsea cables—I am delighted that someone mentioned them. Importantly, when the Secretary of State took the decision to order the surfacing of the Astute-class submarine next to the Yantar to say, “We know what you’re doing and you need to pack it in,” he also made that information available in the newspapers to ensure that the public had that threat perception.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  2. It is important to look at elections to the left of the ballot box, because it is not just about going down with a polling card and ID and putting a tick in a box. The hon. Member for Llanelli said it best: we need to be much more alive to the fact that we are being manipulated and manoeuvred by information and disinformation. We can use pencils and paper, sure, but there is a way more sophisticated game going on here, and it is pretty terrifying. I come back to my theme of amping up the threat perception. We need to re-arm very quickly, not only with hard power but in the minds of our own people, so that we build national resilience to face threats more effectively across the spectrum. For example, as the hon.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  3. In preparation for this debate, I looked at the statement that the Cyber Security and Resilience (Network and Information Systems) Bill, introduced at the back end of last year, would “require organisations in critical sectors to further protect their IT systems”. I must tell the Minister that I am on the Committee for that Bill, and it does no such thing. All it does is to say that various providers from various sectors have to report after the event; it says nothing about making them more secure. I will leave the Minister with a couple of questions. Is enough being done cross-Government to raise threat perception in the nation? What is the Government’s policy on political donations being made in cryptocurrency? How have the Government changed electoral law to keep pace with a quickly evolving threat?

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  4. That relationship may be just as bad as the one he had with Epstein. As European trade commissioner, Mandelson made decisions favouring Deripaska’s company by $200 million a year. Mandelson avoided proper investigation by lying about the timing of his relationship with Deripaska. How can we find out what investigations were carried out before Gordon Brown and his Government appointed Mandelson as a Minister? Do you agree that this House needs to see that information”? —[ Official Report , 4 February 2026; Vol. 780, c. 269.] We all know how Wednesday played out after that. Lastly, I will speak about the other actions that the Government are taking.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  5. 1380.] The Foreign Office Minister in that debate did not respond to the suggestion that they turn Peter Mandelson inside out once they had realised that fact. I suspect that after the events of the past week, one or two Government Ministers wish that they had heeded that advice at the time; they might have saved themselves some problems. Last week, Members who were in the Chamber also heard the point of order made by my right hon. Friend the Member for Goole and Pocklington, who said: “On a point of order, Mr Speaker. Today’s Opposition day debate will focus on Mandelson and his relationship with the paedophile Jeffrey Epstein. However, it will not cover his relationship with another alleged paedophile, murderer, gangster, specialist in bribery and corruption, and Putin favourite: Oleg Deripaska.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  6. Friend the Member for Goole and Pocklington (David Davis) secured an emergency debate, in which I made this point: “Since December last year, our ambassador in Washington has been potentially subject to leverage and blackmail, because someone—we do not know who—had politically fatal kompromat on Lord Mandelson throughout his whole time in office. I am amazed that the Foreign Office has not gone into full lockdown and damage limitation mode, having found out that potentially Lord Mandelson could have been blackmailed this entire time. If it had turned out that he had been an agent of a foreign state, the Foreign Office would have done that. All it knows now is that someone—we do not know who—had politically fatal kompromat on him that whole time.” —[ Official Report , 16 September 2025; Vol. 772, c.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  7. The clever ones are the ones that the hon. Member cannot see. But yes, I agree that we urgently need to look at defence investment in hard power. It is a source of huge frustration in our defence industry domestically and overseas that the Government have failed to agree the defence investment plan. When I was in the Ministry of Defence, we had an old adage: “Plans without resources are hallucinations.” At the moment, our defence industry is dining on fresh air, because the defence investment plan has not yet been agreed. We have time, so I will ask your indulgence, Ms Butler, to mention that Nelsonian eye. Hon. Members will remember that in September last year the British ambassador to the United States of America was sacked. My right hon.

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  8. Is the Minister aware that, as a result of actions by the Scottish and Welsh Governments, a loophole has been created whereby people living in Wales and Scotland can now make unlimited political donations to any political party or politician? Is that something that is going to be addressed by the Government?

    RUSSIAN INFLUENCE ON UK POLITICS AND DEMOCRACY · 2026-02-09 · READ IN HANSARD

  9. I recently visited a major retailer in my Spelthorne constituency, and it reported that corporate systems for getting information to the police are so clunky that to transfer evidence of shoplifting, the police have to resort to sending round an officer to film the retailer’s footage on their body cam. As well as sorting out the technology within the police, will the Home Secretary encourage and reach out to big corporate retailer chains, so we have a seamless flow of information to drive down shoplifting?

    POLICE EFFICIENCY: TECHNOLOGY · 2026-02-09 · READ IN HANSARD

  10. Members on both sides of the Committee have referred frequently to the fact that the incident that took Jaguar Land Rover down would not have been covered by the Bill. JLR employs a digital service provider, in the form of Tata Consultancy Services. Would that provider not be covered, meaning that JLR is in scope?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  11. Given the scenario we just discussed, it is possible that a digital service provider would have an obligation to report under the Bill, but the parent company employing its services would not. Given the requirements for confidentiality that a client company may put upon a digital managed service provider, how can that conflict be managed?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (THIRD SITTING) · 2026-02-05 · READ IN HANSARD

  12. It is a pleasure to serve with you in the Chair, Ms McVey. Small and medium-sized enterprises are defined by the headcount of full-time employees, yet in the world of IT, particularly for managed service providers, data centres and digital service providers, that is not a helpful metric to understand size and scale. Did the Department consider reevaluating the size of digital and managed service providers based on the through-flow of transactions or data rather than headcount? When I worked in the world of tech, there was a ratio for headcount that was totally different from other sorts of businesses.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  13. Having read the Bill, does my hon. Friend understand that if a managed service provider provides services to, say, a hospital—so it would be covered by the regulations—and a reportable event happens to the managed service provider, there is any obligation for the hospital trust to report it as well, or is it just the managed service provider that has the responsibility? If he is not clear on that, would he ask the Minister?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  14. I thank the shadow Minister for his reply to my hon. Friend the Member for Bognor Regis and Littlehampton. Is he as surprised as I am to read in the impact assessment that the hourly rate for a contract lawyer is to be £34 an hour rather than £300 to £500 an hour, which in my experience is the market rate?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  15. Will the Minister please clarify whether he thinks that, as page 102 of the impact assessment states, the hourly rate for a lawyer changing a contract is £34?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  16. I am sorry, but that is nonsense. The footnote on the page that cites £34 an hour for a contract lawyer directs us back to the Office for National Statistics. I hope that the Minister lives in the real world—he has clearly worked in the business world—so he knows that that is nonsense. Does he agree that that pretty well undermines that section of the impact assessment?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  17. We also talked about the legal costs in an earlier sitting. I look forward to hearing the Minister’s reassuring words about how very clear the clause is and how it is not just a blank cheque, even though we do not know how many people it will affect or how much it will cost them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  18. While I am sure that the Minister will say that this provision on critical suppliers is great, and all very clear, it cannot really be that clear. Page 110 of the impact assessment states: “DSIT is not able to estimate at this stage the number of SMEs or SME DSPs that will be designated as critical suppliers”; so we cannot tell how many there are. The same page also states: “Specific duties will be set through secondary legislation so the exact cost of security measures is not possible to estimate.” We do not know how many there are or how much the measure is going to cost, but Government Members will be whipped to say, “That’s okay—that can be done by someone else at another time.” We do not really have a strong sense of the impact on real-world businesses of what we are doing here.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  19. To understand the impact of what we are discussing, we obviously look at the impact assessment. We in this place are often accused of simply making rules and passing laws with no real sense of the impact downstream, particularly on small businesses. Having worked in the tech sector for 10 years, with data centres and managed service providers, and worked to try to grow many small and medium-sized enterprises, I am acutely conscious of the need not to overburden them. It is clearly hugely important that the Government take account of the impact of the measures they are taking and the burdens they are imposing on small and medium-sized enterprises. To understand the impact of this measure, it is important to know two things: first, how many companies will be impacted and, secondly, how much it is going to cost.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  20. I do not want to add spurious hypotheticals, so I will talk about the real world. I visited the Maypole special school in my constituency the other day. It has 20 members of staff and 18 pupils. It has people coming from as far away as Wandsworth. It books the transport, and the transport is paid for by the local education authority in which the pupil lives. It is clearly critical that children get to the school—just as it would be for a hospital. Would it be up to members of staff at the Maypole school to find out whether Addison Lee used a managed service provider or a data centre? That seems quite a tricky thing to know about and then to fulfil.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  21. The Minister came back with an answer on proportionality, saying that it is not for Government to decide what is essential. He missed out the next bit, which is, “We’re just going to regulate critical suppliers and pass laws about them, but we don’t know how many there are, and we don’t know how much the policy is going to cost.” Would he accept that characterisation as the logical conclusion of what he said? The Minister also said that schools were not covered by the Bill. As far as I am aware, patient data and children’s data are two of the most precious things that we have, so I would like to know why schools are not covered by the Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FOURTH SITTING) · 2026-02-05 · READ IN HANSARD

  22. It is lovely to see the Secretary of State; the last time I saw her was in the Strangers Bar, when she was pulling a pint of Rebellion Overthrow—I can’t imagine why that stuck in my mind! The River Thames scheme has been in abeyance, essentially—in mid-project review—since May last year. Will the Secretary of State please knock some heads together at both the Environment Agency and Surrey county council, and get them to say something about what is happening at the River Thames scheme?

    WATER INFRASTRUCTURE: INSPECTIONS · 2026-02-05 · READ IN HANSARD

  23. Pride in Place funding is about £5 billion directed at our most deprived areas. I think it is worked out on a constituency basis, and that constituencies have to hit a point on two indices of deprivation to qualify, and must therefore be what the Government call “double deprived”. I have significant pockets of deprivation in my constituency, particularly in parts of Stanwell, yet they do not qualify for Pride in Place funding because it is calculated on a constituency basis, which seems pretty unfair to me. Will the Leader of the House allow Government time for us to debate the Pride in Place funding formula, so that we can understand it, and bring such anomalies to the attention of the Government?

    BUSINESS OF THE HOUSE · 2026-02-05 · READ IN HANSARD

  24. As I am sure my right hon. Friend remembers, once the Bloomberg leak had happened, many of us said to the Government that now that those things had turned out to be true, we should turn Lord Peter Mandelson inside out as if he had been outed as a spy; surely, had the Government done so, the things that were released over the weekend would have come out. Is he surprised, as I am, that the Government did not seem to do an investigation into Peter Mandelson subsequent to him being fired?

    LORD MANDELSON · 2026-02-04 · READ IN HANSARD

  25. Q On the question of closer alignment, can you give us a sense from the international picture of whether certain regulatory regimes raise the barrier to terrorists or criminals so high that they are left alone? Is that a national thing or a company-based thing? Where are the flow lines of attack and threat? Is it on a national or a corporate basis? Stuart McKean: I do not think the cyber-criminal really cares, to be blunt. They will attack anywhere. You can, of course—

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  26. Q I appreciate that. My question was about where that leads them to attack, on the basis that they will take the route of least resistance. Where is that? Is that an international thing, a national thing or a corporate thing? Stuart McKean: It is probably across all three, to be quite honest with you. It is very dependent on what they want to achieve, whether it be an economic attack or a targeted attack on a corporate entity. I do not think it has those boundaries—I genuinely think it is across the whole industry and the whole globe. The reality is that cyber-attacks everybody. We are being attacked every day. I do not see it as an international boundary, or a UK thing or a US thing. It is generally across the globe.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (FIRST SITTING) · 2026-02-03 · READ IN HANSARD

  27. The experience we have had over the years means that we can come to those conversations with a lot of history, a lot of perspective, and, to be honest, a bit of sympathy because sometimes those moments are very difficult for everyone involved.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  28. It is always hard to trust the initial information that is coming out because no one really knows what is going on, certainly for the first few hours, so it is the maturity and experience that we would want to bring to this expanded role when it comes to data centres. Ultimately the best regulatory relationships I have seen is where there is a lot of trust and openness that a regulator is not going to overreact. They are really going to understand what is going on and are very purposeful about what they are trying to achieve. From Ofcom’s point of view it is always about protecting consumers and citizens, particularly with one eye on security, resilience and economic growth.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  29. I anticipate that is the approach we will take in the future when dealing with the instant reporting regime that the Bill sets out. Our first instinct would be to collaborate with organisations. Only in the most egregious cases would I imagine that we would look to exercise the full range of our powers. Natalie Black: From Ofcom’s point of view, we have a long history, particularly in the telecoms sector, of dealing with a whole range of incidents, but I certainly hear your point about the victim. When I have personally dealt with some of these incidents, often you are dealing with a chief executive who has woken up that morning to the fact that they might lose their job and they have very stressed-out teams around them.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  30. It is one of safety and security, and the chief executives and the heads of security really lean into it and understand that particular space. There are many different forums where they communicate and share that type of information with each other and with us. Incident response is really the purview of DESNZ rather than us, but they will speak to us about that from a regulatory perspective. Ian Hulme: From the ICO’s perspective, we receive hundreds of data-breach reports. The vast majority of those are dealt with through information and guidance to the impacted organisation. It is only a very small number that go through to enforcement activity, and it is in only the most egregious cases—where failures are so egregious that, from a regulatory perspective, it would be a failure on our part not to take action.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  31. Q One of my favourite aphorisms is, “Institutions get the behaviours they reward.” We had a cry from Amazon Web Services this morning about how, when a regulator deals with a company in the event of a cyber-security attack, please remember you are dealing with a victim. I have dealt with the ICO before. Maybe it was the company that I worked in and led, but there was a culture there that, if you had a data breach, you told the ICO. There was no question about it. How are you going to develop your reactions and the behaviours you reward in order to encourage a set of behaviours and cultures of openness within the corporate sector, bearing in mind that, as was said this morning, by opening that door, companies could be opening themselves up to a hefty fine? Stuart Okin: In the energy sector, we have that culture.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  32. We have put additional controls around that, because the network perimeter extended out into the cloud. We might want to take advantage of those controls for new things that come online, integrating with national identity, but we need to be assured that the companies integrating with national identity are safe. For me, the Bill will be a terrific bit of legislation that will help me with that—if that makes sense.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  33. Brian Miller: We would work with the Scottish Health Competent Authority as our regulator; I cannot speak for other regulators and what that might look like. We are doing work on what assurance for critical suppliers outside the Bill looks like just now, and we are working across the boards in Scotland on identifying critical suppliers. Outside of that, for any suppliers or any new services, we will assess the risk individually, based on the services they are providing. The Bill is really valuable for me, particularly when it comes to managed service provision. One of the questions I was looking at is: what has changed since 2018? The biggest change for me is that identity has went to the cloud, because of video conferencing and stuff like that. When identity went to the cloud, it then involved managed service providers and data centres.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  34. Q To come back to Dr Spencer’s original question about the scope of the legislation, the current situation, as I understand it, is that there is a carve-out for small and medium-sized enterprises because we do not want to put too much regulatory burden on them, but, under the new proposed legislation, operators of essential services that are SMEs will be designated by their regulator. That brings us back to the question of which regulator that would be. Do you currently use that designation for operators of essential services, or would you have to do a piece of work, presumably looking at a number of different regulators’ points of view, to designate the operators of essential services?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  35. It could be that, from our side, a lot of the people in the supply chain would fall into that designation, but for some other sectors it might not be so critical. We have a unique challenge in the NHS because of the service we provide, the effect that cyber-crime would have on our organisations, and the sensitivity of the data we process.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  36. Q I want to make sure I have understood exactly. Is the regulator going to tell you who your operators of essential services are, or are you going to tell the regulator? Brian Miller: I think we would work with the regulator, but we are looking for more detail in any secondary legislation that comes along. We have read what the designation of critical suppliers would be. I would look to work with the Scottish Health Competent Authority and colleagues in National Services Scotland on what that would look like. Stewart Whyte: On how we would make that decision, from our perspective we are looking at what the supplier is providing and what sort of data they are processing on our behalf. From the NHS perspective, 90% of the data that we process will be special category, very sensitive information.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  37. If we are procuring anything, we will do a risk assessment—that might be a basic risk assessment because it is relatively low risk, it might be a rapid risk assessment, or it may be a really in-depth assessment for someone that would be a critical supplier or we could deem essential—but there are absolutely suppliers that would not fall under any of that criteria for the board. The board is large in scale, with 40,000 users. It is the largest health board in the country.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  38. Q Brian, from your side, what about, say, PPE, gloves or blood? There must be other things that are non-data that are, nevertheless, essential services. Brian Miller: I do not want to step out of my lane. There will be clinical stuff that absolutely would be essential. I would not be able to speak in any depth on that part of it; I purely look at the cyber element of it. As an organisation, we would be identifying those kinds of aspects. In terms of suppliers, you are absolutely right. We have suppliers that supply some sort of IT services to us.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  39. You can look at the designation of critical dependencies. I am sure you have talked about this, but for example, an SME software company selling to an energy company could be deemed a critical supplier by a regulator, and it is then brought into scope. However, I think it should be the SMEs that are relevant to the whole sector, not just to one organisation. If they are systemic and integral to a number of different sectors, or a number of different organisations within a sector, it is fair enough that they are potentially brought into scope. It is that risk-based approach again. But if it is just one supplier, one SME, that is selling to one energy company up in the north of England, is it risk-based and proportionate that they are brought into scope? I think that is debatable.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  40. At the other you have a need for flexibility, which quite rightly comes from the Government, who want to adjust and adapt quite quickly to secure the population, society and the economy against a changing threat. That continuum has an opposing dynamic, so the CRB has a big challenge. We must therefore not be too hard on ourselves in finding exactly where to be on that line. Some things will go well, and some will just need to be looked at after a few years of practice—I really believe that. We are not going to get it all right, because of the complexities and different dynamics along that line. Carla Baker: This debate about whether SMEs should be involved or regulated in this space has been around since we were discussing GDPR back in 2018. It comes down to the systemic nature of the supplier.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  41. It requires quite a lot of work and resource, and if we are putting that on to too small a supplier, on the basis that we think it is on the critical path, I would advocate a different system for risk management of that organisation, rather than it being in the regulatory scope of a cyber-resilience Bill. The critical suppliers should be the larger companies. If we start that way in legislation and then work down—the Bill is designed to be flexible, which is excellent—we can try to get that way. As a last point on flexibility—this is perhaps very obvious to us but less so to people who are less aware of the Bill—there is a huge dynamic going on here where you have a continuum, a line, at one end of which you have the need for clarity, which comes from business.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  42. Q I want to come back to that point. Chris, you said something like, “SMEs find it very difficult, if not impossible, to bear the regulatory burden, so we have to be very careful when designating SMEs as operators of essential services.” To me, that says that you think the Bill, as currently drafted, will place too much of a regulatory burden on SMEs. Is that correct? Chris Parker: I was referring to strategic and critical suppliers, which is a list of Government suppliers. We are advocating that the level of governance and regulatory requirement inside an organisation is difficult, and it really is.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  43. Q Going back to our conversation with the head of IT security and compliance at NHS Greater Glasgow and Clyde and what could be designated an operator of essential services, and our subsequent conversation with Palo Alto, how do you envision that bit of the Bill working? Taking Glasgow as an example, while neither of us are doctors, we both broadly know what happens in hospitals—and there is also a doctor sitting to my right on the Committee, should we need one. On the example that I gave, given what is written in the Bill, how do you think it should work? Kanishka Narayan: Do you mean operators of essential services, or critical suppliers, as in the third party element?

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  44. I meant operators of essential services. Kanishka Narayan: The Bill effectively specifies operators of essential services as large participants in the essential services sectors. I think that that definition is very straightforward. The hospital in this question would be an operator of an essential service. If the question extends to critical third party suppliers—

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  45. Given my professional context, I am particularly conscious of the very clear and critical third party comparable requirement in the Financial Services and Markets Act 2000, which focuses on both cyber-security and supply chain risks. That has worked relatively proficiently in that context, so I hope that there are some good lessons to learn from that.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  46. My expectation and hope would be that regulators take a much more proportionate approach there than to set the precise same conditions on those suppliers as they do on the operator in question; in particular, that the burden on them is placed specifically in sight of the directional risk that they pose to the operator, rather than the risk in sum for that third party supplier. The first thing is therefore that the Bill clearly specifies a very tight scope. The second is that it does not seem to me, as a relative novice to both the medical world and cyber-security, unusual to have a specification of this nature in a Bill.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  47. Fourthly, not only that, but that disruption would have to be sufficiently severe in its impact to be in scope. That is one set of things. Underlying that is a further test in the Bill, whereby alternative provision of that third party supply could not be secured in a practicable way. The combination of those tests means that the scope set out for the critical third party suppliers is extremely tight and robust. Then there is still the question, having gone through that five-step test, of the particular burden placed on relevant suppliers in scope.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  48. Q Sorry, I misspoke. I mean an SME that is deemed a critical supplier. Who is going to deem them so? Which of the many regulators at play in that hospital is going to decide who is a critical supplier? Kanishka Narayan: There are two things to say on this. There is at least a four-step test on the face of the Bill for what would qualify as a critical supplier. First, a critical supplier has to supply to an operator of an essential service, in this case the hospital. Secondly, the supplier itself must engage with important network and information systems. Thirdly, the disruption to that third party supplier would have to cause a material disruption to the operator in question—in this case, if the third party supplier falls over from a cyber-security point of view, there would be material and business continuity disruption to the hospital.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  49. However, I think the assessment has to be undertaken by each regulator on a separate basis, because the question being assessed is not the nature, the sum risk, of the third party supplier in itself, but the risk posed by its relationship to the operator it is providing to—if that makes sense.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD

  50. If a hospital has a third party supplier, and the presence and nature of its supply means that there is a critical risk exposure for the hospital, that would be in scope for some degree of regulation in the Bill. To your question, if there is a comparable but separate hospital in a part of England that is separately regulated, but has the same third party supplier, there is obviously a question of whether that third party supplier would end up being regulated twice if the criticality threshold is met. In that instance, and in other similar instances of multiple regulators covering the same third party supplier, I would expect a high degree of co-ordination. In fact, the provisions in the Bill, as well as my hopes for subsequent guidance, are focused on our efficiency and proportionality when there are multiple regulators.

    CYBER SECURITY AND RESILIENCE (NETWORK AND INFORMATION SYSTEMS) BILL (SECOND SITTING) · 2026-02-03 · READ IN HANSARD