Dr Allison Gardner
MP for Stoke-on-Trent South · Labour · United Kingdom
“My constituency straddles both the proposed Staffordshire unitaries quite substantially. I welcome the creation of a North Staffordshire unitary—an area that has a long-held identity and significant growth potential—but opting for the smaller proposal for North Staffordshire and creating one much larger Southern Staffordshire unitary does…”
“Lightwood in my constituency is earmarked in the emerging local plan for a whopping 3,000 new homes. Not only would a development of that size be simply too much for the area, but no masterplan has been brought forward to guide development.”
“My hon. Friend is correct. I recently met constituents in my office who are deeply concerned about the internet blackout. They are unable to find out if their families are okay and have told me some horrendous stories, including—this is unverified—that a two-year-old child has been shot.”
“Some of my constituents have been labelled terrorists because they have spoken out and are now unable to travel to visit their families, even if the blockade should end. Does my hon. Friend agree that that type of draconian abuse of the law must stop and that my constituents should not be labelled as terrorists just for speaking out?”
“The petition asks that ceramics be included in the supercharger scheme, and that is an understandable ask, but it does not solely answer all the challenges faced by the sector; nor does it address the future sustainability and the need for transition to low-carbon alternatives.”
“It is a pleasure to serve under your chairship, Dr Murrison. I thank all the people who signed this petition and commend the hard work done by my hon. Friend the Member for Amber Valley (Linsey Farnsworth) and all who fought hard for Denby and our ceramics industry.”
The complete record
Every one of 389 lines we hold for Dr Allison Gardner, in date order, each linked to its source. Free to read, in full, without an account. Page 2 of 8.
“It is precisely because I wish to save those places and create jobs that I want to support the project for the Lunar Gardens—a cultural destination that would draw on heritage while engaging with the future of the industry. It would include residencies and studios for creative work, a training centre for heritage crafts skills, continued industrial ceramics production, a park and an adventure-themed forest playground, as well as a contemporary art gallery. The proposal would not only promote our proud heritage and boost local tourism but create employment and education opportunities at the working factories. Before I close, I should also say that Longton is also putting in a bid to be town of culture.”
“The skills used at Gladstone are now being used to make parts for jet engines. I find that very iconic. A short drive away is the World of Wedgwood, an award-winning tourist destination and living museum that has the V&A Wedgwood collection and a working factory. Wedgwood’s founder, Josiah Wedgwood, was an incredible innovator and entrepreneur who invented creamware, green glaze and much more, and helped to drive the industrial revolution. Sadly, given the pressures of today, the Wedgwood factory is in discussions to reduce production and make redundancies. The financial sustainability of the World of Wedgwood and its factory is vital. This is about not just the factory workers and the skills but local hospitality such as Lunar restaurant and other shops, which we must try to save.”
“Visitors to Gladstone can watch live demonstrations of traditional crafts, explore galleries showcasing historic ceramics, tiles and sanitaryware and learn about the pottery-making process from clay to finished products. Visitors gain an incredible insight into what working conditions were like for the men, women and children who powered the pottery industry throughout the Victorian era. The museum is sited in Longton; there are many working potteries and china companies around Longton, including Susan Rose, Gluggle Jug and, further away, 1882 Ltd. Many of their skills are heritage skills, which we need. They were developed in, for example, Gladstone pottery, and are now used in places such as Mantec, an advanced ceramics company. In its research laboratory, one can see a big view of Gladstone Pottery Museum.”
“That is what makes us the Potteries. Gladstone Pottery Museum in Longton showcases the skills, craftsmanship and economic contribution made and curated by local people. Gladstone is the only complete Victorian pottery factory in the country set within a preserved coal-fired factory with traditional bottle ovens. I am sure that hon. Members will be familiar with—and not just because I talk about it all the time—“The Great British Pottery Throwdown” on Channel 4, which Gladstone Pottery Museum proudly hosts and which draws in visitors and TV presenters from across the world. That shows the importance of museums to tourism and the local economy.”
“It is a pleasure to serve under your chairship, Ms Lewell. I congratulate my hon. Friend the Member for Thurrock (Jen Craft) for securing this debate today. Our local museums are at the heart of our communities. I am incredibly lucky to have important museums in my constituency of Stoke-on-Trent South that proudly champion our pottery heritage—Gladstone Pottery Museum and World of Wedgwood. Museums are not just about the past; they can be living museums that illustrate our past, present, and indeed our future—a point that I hope to illustrate through those two museums. For generations, our famous tableware brands have crafted household favourites and shipped bespoke British products all over the world. From Wedgwood to Gluggle Jug, our companies were and are at the centre of the world’s pottery industry.”
“Synthetic cathinones, commonly known as monkey dust, are a stimulant drug causing significant harm in Stoke-on-Trent. These substances can cause severe psychosis and trigger acute health risk in the very vulnerable people who turn to them, which is having a significant impact on our local communities and public services. Will the Leader of the House make time for a debate on synthetic cathinones?”
“In a volatile world, that is increasingly putting our sovereign capability for defence manufacturing at risk. As the Minister will know, I have met Lucideon, which is based in the constituency of the right hon. Member for Stone, Great Wyrley and Penkridge (Sir Gavin Williamson). It is working very hard, in a wide partnership, to create a sovereign CMC manufacturing facility in north Staffordshire, hopefully based near the Applied Materials Research, Innovation and Commercialisation Company at Keele University. I once again ask the Minister whether he will meet me to see how we can move that forward and understand the vital strategic importance of north Staffordshire’s advanced ceramics capability to our country and our defence.”
“To bolster national security, strengthen our industrial expertise and position the UK as a leader in advanced defence technologies, we must invest in our sovereign CMC and fibre manufacturing capacity. When I recently met the UK Atomic Energy Authority, it highlighted—again with great frustration—the importance of having this sovereign capability to manufacture CMCs and fibres. The manufacturing currently happens in a few factories overseas, including in a Rolls-Royce factory in America, which produces the CMCs we need for our defence and civil aviation. Fibre manufacturing also takes place in only a few factories globally, including in Japan and Germany. It is crazy that we actually hold much of the intellectual property, and we have the skilled workers and technology, yet we are dependent on those overseas supply chains.”
“An example of such a business in my Stoke-on-Trent South constituency is Mantec, a technical ceramics company that produces ceramic molten metal filters that remove impurities from molten turbine blades used for civil aviation and defence. Investment in that technology is cost-saving because it is said that using those materials creates a £1 million fuel saving per year, which is £40 million over the lifecycle of a plane, so short-term investment now can lead to long-term savings. I must emphasise the strategic importance of securing sovereign capability in advanced defence materials, particularly ceramic matrix composites. To quote the National Composites Centre, “the future of British defence will depend on sovereign access to ceramic matrix composites”.”
“Within the allocations of defence spending and investment, and in light of current geopolitical volatility, I am sure that the Government will be looking to secure a strategic, robust and sovereign defence supply chain. In north Staffordshire, our advanced ceramics industry is a key creator of the unique advanced ceramic materials that are required for our fighting capability, including armour materials, ultra-high speed munitions, and protection and security for our defence communications. I have spoken previously to the Minister about the strategic importance of north Staffordshire in creating an advanced manufacturing cluster.”
“My hon. Friend mentioned the cost of electricity, but ceramics is a gas-intensive industry, so I again make a plea that when considering support for businesses, we remember gas-intensive industries, which includes steel, and that we have a strategy.”
“I worked for the AI and digital regulations service in the NHS. We were linking with all of the regulators to try to have a one stop, one shop door approach to how we do things. It was incredibly difficult, and three years on we were still ironing out all the glitches. New clause 7 is laudable, but because I know how difficult it is, a 12-month proposal is a very tight timeframe in which to try to get this right.”
“I will defend myself: my point was not a criticism of the Government. I just know how hard it is for regulators to work together and iron out cross-working. They were very confident in their information-sharing skills, but it is more difficult than that. It was just a kindly meant reminder that there is not an easy solution, and that 12 months is a bit of a tight timeframe.”
“I recently met Home Office Ministers to discuss the use of synthetic cathinones, often referred to as monkey dust, in Stoke-on-Trent. These substances cause significant harm to users and, indeed, communities. They are frequently sold via the dark web and imported through the post. Can the Secretary of State provide an update on her work with the National Crime Agency and Royal Mail to detect illicit substances using technology, and advise whether existing opioid detection methods can be adapted or applied to synthetic cathinones?”
“Unfortunately, you cannot create culture change quickly. When it comes to talking about human factors, it is about people becoming much more aware of it and thinking more about it. That will take time—”
“I do not think that there is anything specific in the legislation, as it is currently written, that says, “And this,” in flashing lights, “is going to change the human factors piece.” I think that the devil will be in the detail of the secondary legislation, and then in what the regulators specifically ask for. But there does need to be a general shift in the culture, whereby as sectors generally we start to talk more about this as a requirement. The financial services sector has talked about security for a long time—it has been a reality for it—but I am not sure how true that is, at breadth, in something like the water industry. I hope that that will change. I hope that we will start to see having those conversations at the top levels, and then all the way down, becoming more of a cultural norm.”
“I go back to my last answer, which was that I think one of the strengths of the Bill is that, hopefully, it will enable the regulators to engage much more on this topic and therefore to engage their covered entities much more. That is what we need to see. We need to see the leadership in organisations engage with the topic of cyber-security, not as a chore, as a tick-box exercise or as that headline they read about JLR, but actually as something that matters to their organisation—as something they are going to engage with at a board and executive team level, all the way down through the organisation. Cultural change comes from the top, typically, and we need to see that level of change.”
“Q I have a quick question. You mentioned vulnerabilities earlier, and you mentioned, Jen, the complexities of implementing cyber-security plans. As well as technological factors, human factors, not the least of which is the lack of skills, play a key role in cyber-resilience. How would or could the Bill address the human element in cyber-security? Jen Ellis: That is a great question, and a tricky one. We talk a lot about training and security awareness, and unfortunately I think it becomes yet another tick box: you start a job and watch your little sexual harassment training video, then you watch your cyber-security training video, and probably the former sticks with you better than the latter. I think we have to change that. We have to change that dynamic.”
“Jill Broom: With the board, historically, cyber has not been viewed as a business risk, but as a technical problem to be addressed by the technical teams, instead of being a valuable, fundamental enabler of your business and a commercial advantage as well, because you are secure and resilient. That has been a problem, historically. It is about changing that culture and thinking about how we get the boards to think about this. I think a fair amount of work is happening; I know the Government have written to the FTSE 350 companies to ask them to put the cyber governance code of practice into play. That is just to make cyber a board-level responsibility, and also to take account of things such as what they need to do in their supply chain.”
“Q It is interesting that you mentioned the complexity and skilled teams. Sanjana, you talked about the need for more skill and responsibility, and how distributed responsibility across supply chains is a big deal. That comes down to a duty of care on people who are procuring these things. The annual cyber security breaches survey found that board-level responsibility for cyber has declined in recent years. What explains that, and how could it be improved? As a quick supplementary question, do you think there should be a statutory duty for companies to have a board member responsible for cyber risk? Jill, I will go to you first.”
“Q But do you think there should be a statutory duty to have a board member responsible? Jill Broom: Some of our members have pointed out that the number of organisations under cyber-regulations is very small, and it is only going to increase a small amount with the advent of this particular Bill. Similarly, in the different jurisdictions there are duties at the board level. There is an argument for it. The key thing is that we need to be mindful of it being risk-based, and also that there are organisations that could be disproportionately affected by this. I think it needs a little more testing, particularly with our members, as to whether a statutory requirement is needed.”
“We talked about the cyber assessment framework and how that is likely to be the scope within which this Bill is implemented. So, we do not necessarily need to do something new. The scope of the Bill, as we said, is 0.1% of the UK private sector. There is scope to expand the existing things that we are doing, especially cyber essentials, for example, raising the bar for small and medium-sized enterprises across the economy. There is a lot that we are already doing that we could do, that we already have the scope to expand, but obviously that must be done prudently and on the basis of solid evidence.”
“Chris Anley: In terms of what other things we could do, we have talked about voluntary codes. The value of voluntary codes was questioned in an earlier session; but the World Health Organisation best practice guide on handwashing, which is entirely voluntary, saved millions of lives in the recent pandemic. It is important to bear in mind that codes that help you to protect yourself are definitely valuable. Other actions that are already taking place that we may want to extend on the basis of solid evidence and data are the cyber essentials scheme, for example, and the various codes of practice. The cyber governance code of practice for boards was mentioned earlier, along with the Government outreach and attempting to get boards to recognise that cyber risk is a business risk and an existential threat.”
“Q I have so many questions, some of which have been touched on; I will limit myself. I was interested in the CyberUp campaign that you mentioned. What other measures, both legislative and non-legislative, could the UK Government take to enhance the cyber-resilience of the UK’s critical national infrastructure? In terms of resilience, is there any requirement to look a bit more deeply at failsafes and non-technical failsafes that we might need, because we are always going to get that? My second question is for Ben. In combining AI and cyber, you are combining technologies that come with their own unique risks with cyber-security. I am interested in how you mitigate against that. I am intrigued because, when you talk about AI, I assume you are not talking about straightforward machine learning.”
“We are accredited to a range of standards, like ISO 27001 and ISO 42001, which is a standard for AI management. We have released a white paper on how we approach responsible AI in cyber-security, which I would be happy to share with you and give a bit more detail.”
“Q Ben, are you combining two risks? Ben Lyons: That is something we think very deeply about. We see AI as helping to mitigate some of the risks from cyber-security by making it possible to detect attacks more quickly, understand what might be causing them, and to respond at pace. We are an AI native company and we have thought deeply about how to ensure that the technology is both secure and responsible. We are privacy-preserving by design. We take our AI to the organisation’s environment to build an understanding of what normality looks like for them, rather than vast data lakes of customer data. We take a lot of effort to ensure that the information surfaced by AI is interpretable to human beings, so that it is uplifting human professionals and enabling them to do more with the time they have.”
“Some of that needs to sit with the Department for Science, Innovation and Technology, which is getting a lot of feedback from all of us about how we need it to co-ordinate and make things as easy as possible for companies—many of which are important investors in our economy, and we absolutely recognise that. We are also doing our bit through the UK Regulators Network and the Digital Regulation Cooperation Forum to find the low-hanging fruit where we can make a difference. To give a tangible example, we think there should be a way to do single reporting of incidents. We do not have the answer for that yet, but that is something we are exploring to try and make companies’ lives easier. To be honest, it will make our lives easier as well, because it wastes our time having to co-ordinate across multiple operators.”
“There are pros and cons, but a single regulator will need to prioritise its resources, so you may not get the coverage you might with a sectoral approach. Natalie Black: Having worked in this area for quite some time, I would add that the challenge with a single regulator is that you end up with a race to the bottom, and minimum standards you can apply everywhere. However, with a tailored approach, you can recognise the complexity of the cyber risk and the opportunity to target specific issues—for example, prepositioning and ransomware. That said, we absolutely recognise the challenge for operators and companies in having to bounce between regulators. We hear it all the time, and you will see a real commitment from us to do something about it.”
“Ian Hulme: I suppose the challenge with having a single regulator is that—like ourselves, as a whole-economy regulator—it will have to prioritise and direct its resources at the issues of highest harm and risk. One benefit of a sectoral approach is that we understand our sectors at a deeper level; we certainly work together quite closely on a whole range of issues, and my teams have been working with Natalie and Stuart’s teams on the Bill over the last 18 months, and thinking about how we can collaborate better and co-ordinate our activities. It is really pleasing to see that that has been recognised in the Bill with the provisions for information sharing. That is going to be key, because the lack of information-sharing provisions in the current regs has been a bit of a hindrance.”
“Q I should point out that I once worked for the NHS AI and Digital Regulations Service and have also worked for a number of different regulators, including the ICO, so I have experience of the joys and frustrations of cross-regulatory working. We have heard evidence of the challenges experienced by businesses when they have to go to different regulators—I think it is as many as 14—and deal with the conflicting guidance they are often given and the skillset within each regulator. There were calls for one portal for incident reporting. The ICO is a horizontal regulator working across all sectors. In your experience, would a single cyber regulator be a good idea? What would be the benefits and the challenges? I will allow Ofcom and Ofgem to jump in and defend themselves.”
“That is where you say, “If this exists in your sector, as an industry and as a company, you can be potentially liable as an entity if you do not make sure these powers are used responsibly, and if you essentially outsource to individuals in order to avoid personal liabilities”.”
“You can have a legal regime that says, whether through accreditation or simple public interest offences, that there are certain activities that involve unauthorised access to another person’s system, which may be legitimate or indeed necessary. However, we want a professional culture within that; we do not want that outsourced to individuals around the world. You can then build in sensible corporate liability based on consent or connivance, which goes to individuals in the boardroom, or a failure-to-prevent model of criminalisation, which is more popular when it comes to financial crimes.”
“Crucially, it also allows modernisation and flexibility to move through into secondary legislation, rather than us relying purely on the maturations of primary legislation. In terms of board-level responsibility, I cannot speak too authoritatively on the civil law aspects, but drawing on my criminal law background, there is something in that as well. At the moment, the potential for criminalisation applies very much to those making unauthorised access to another person’s system. That is the way the criminal law works. We also have potential for corporate liability that can lead all the way up to board rooms, but only if you have a directing mind—so only if a board member is directing that specific activity, which is unlikely, apart from in very small companies.”
“Q I have a couple of unconnected questions. We have asked a couple of times whether senior board members should have legal, statutory responsibility for cyber. The pros are that it is not seen as a priority, and culture change has to be top-down. However, there are issues with smaller companies bearing a responsibility that is diffused along the supply chain. Also, boards that tend to have a focus on providing returns for shareholders may not be investing in this complex arena. I am interested in your thoughts on whether the Bill does enough to make senior executives responsible for their organisations’ cyber-security. Professor John Child: I think the Bill does a lot of things quite effectively. It modernises in a sensible way and it allows for the recognition of change in type of threat. This goes back to my criminalisation point.”
“The current law does not do that; it creates the problem of either doing that work under the veil of criminalisation, or not doing it, with work being outsourced to places where you do not have the back-and-forth communication and reporting regime you would need.”
“However, when you look at critical national infrastructure, although you can create layers of civil responsibility and regulation—which is entirely sensible—most of that will filter down to individuals doing cyber-security and resilience work. It is about empowering those individuals; within a state apparatus, that is one thing, but even with regulators and in-house cyber-security experts, individuals are working only within the confines of what they are allowed to do under the criminal law, as well as the civil regulatory system. The reason I have been asked here, and what a lot of my work has focused on, is this: if you filter responsibility down to individuals doing security work for national as well as commercial infrastructure, you need to empower them to do that work effectively.”
“Q Thank you—that was quite detailed. I have a very quick question: what measures would you want the Government to take to enhance the cyber-resilience of the UK’s critical national infrastructure? I am interested in your thoughts on requirements for failsafes and risk management, and indeed on the non-technical resilience measures that would be needed in case of complete failure. Professor John Child: Again, I have to draw back to the criminal law aspects. I think the Bill does the things it needs to do well; certainly, from the conversations I have had with those in cyber-security and so on, these are welcome steps in the right direction.”
“I think you are touching on the old problem of where liability lies when you have this long supply chain of diffused responsibility, but thank you.”
“Q You have answered the question I was about to ask. I may ask an addendum to that, but first I want to clarify something. If you put liability on an individual board member, that is going to cause problems. Do you think that there should be a statutory responsibility for the company to have a board member responsible for cyber-risk, and that the responsibility and accountability should sit at company level? Richard Starnes: I think this should flow from the board to the C-level executives. Most boards have a risk committee of some sort, and I think the chair of the risk committee would be a natural place for that responsibility to sit, but there has to be somebody who is ultimately responsible. If the board does not take it seriously, the C-levels will not, and if the C-levels will not, the rest of the company will not.”
“Q You mentioned stringent application of the regulatory regime. Could you explain the reasons for the lack of enforcement under the current NIS guidelines? Do you feel that the regulatory regime should be streamlined? Richard Starnes: That is a very broad question.”
“I know, sorry. I collapsed it down from quite a few. Richard Starnes: There is any number of different reasons. You have 12 competent authorities, at last count, with varying funding models and access to talent. Those could vary quite a bit, depending on those factors. I am not really sure how to answer that question.”
“Q I am just thinking that if you are putting liability on someone, you need to make sure that they can apply the regulation in a simple and effective manner and ensure that it is enforced, so they do not carry the full burden of liability. Richard Starnes: True, but I would submit that under the Companies Act that liability is already there for all the directors; it just has not been used that way.”
“From the reporting perspective, it would be helpful to report into one individual organisation. I noticed that in the reporting requirements we are looking at doing it within 24 hours, which could be quite difficult, because sometimes we do not know everything about the breach within that time. We might need more information to be able to risk assess it appropriately. Making regulators aware of the breach as soon as possible is always going to be a good thing.”
“We report nationally, and we work really closely with National Services Scotland’s Cyber Security Centre of Excellence, which does a lot of our threat protection and secure operations, 24/7, 365 days a year. We work with the Scottish Government through the Scottish Cyber Co-ordination Centre and what are called CREW—cyber resilience early warning—notices for a lot of threat intelligence. If something met the threshold, we would report to the SHCA. Stewart, do you want to come in on the data protection officer? Stewart Whyte: We would report to the Information Commissioner, and within 72 hours we also report to the Scottish Government information governance and data protection team. We would risk assess the breaches and determine whether they meet the threshold for reporting. Not every data breach is required to be reported.”
“To put that in context, I was speaking to them yesterday regarding our transition to the CAF, as part of our new compliance for NHS Greater Glasgow and Clyde. If there was a reportable incident, we would report into the SHCA. The thresholds are really well defined against the confidentiality, integrity and availability triad—it will be patient impact and stuff like that. Organisationally, we report up the chain to our director of digital services, and we have an information governance steering group. Our senior information risk officer is the director of digital, and the chief information security officer role sits with our director of digital.”
“Q I am interested in who you report to should you identify a cyber-incident. I am talking about not just data breaches but wider ones that can affect operational systems. Which regulators do you deal with? If it is multiple regulators, do you feel there is a case for having one distinct regulator to cover cyber-resilience and manage that quite difficult landscape? Brian Miller: That is a great question. I will touch on some different parts, because I might have slightly different information from some of the information you have heard previously. On reporting—Stewart will deal with the data protection element for reporting into the Information Commissioner’s Office—we report to the Scottish Health Competent Authority. It is important that we have an excellent relationship with the people there.”
“Q I have loads. Before I come to the question I was going to ask, I want to pick you up on the worry about information sharing. I have worked across regulators, and they seemed to be really confident about information sharing, but I know that is not always the case. There is some protection of turf, and other Acts might prohibit that information sharing. Could you expand on that area of concern? What would be your recommendation? Carla Baker: My comment on information sharing was about what else the Government could do. It was not necessarily specifically to do with the Bill. If you want me to elaborate on the wider issue of information sharing, I am happy to.”
“Particularly between regulators, and how that would work. Carla Baker: I cannot necessarily talk in much detail about information sharing across regulators. It is more about information sharing across the technology industry that I can talk about.”
“I think it is getting better—from the senior execs that I speak to in industry, there is more understanding—but generally speaking, there is a view that cyber-security is an IT issue, not a business issue. I am sure you have heard throughout the day about understanding the risks we have seen around vulnerabilities, and the incidents that have affected the retail or manufacturing sectors. Those are substantial incidents that have impacted the UK and have systemic knock-on effects. Organisations have to understand the serious nature of cyber-security, and therefore put more emphasis on cyber at the board level. Should we be mandating board-level governance? That is useful for this debate to seek information and input on, but the burden on SMEs has to be risk-based and proportionate, however it is framed.”
“You can effectively make a pack and write a checklist, even if you are a very small company with a board of two people, and go through your own things and make sure your checklists are there. The data and the capability are there to give support. Whether it is signposted enough, and whether we are helping on a local level, to make sure that people are aware of those things is perhaps something we could do better at in this country. But I am sure that industry will do our part, and we do, to share and reinforce the good sharing of things like that website, to guide good governance for SMEs especially. Carla Baker: That board-level accountability is really important, and it is crucial for cyber-security.”