Alison Griffiths MP: speeches

122 published records · newest first.

Speeches

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
    More

    Bringing MSPs into scope is the right direction of travel, and MSPs sit at points of concentrated risk, but they are not all the same and the real risk is not size alone but the level of privileged access and cross-customer dependency. Proportionality will be critical under these provisions if we want better security, not just box-ticking.

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
    More

    The clause merits close scrutiny, because it is the point in the Bill where risk is supposed to be addressed beyond the individual operator and into the supply chain. In plain terms, clause 12 will allow the regulator to designate a supplier as critical where disruption to that supplier would have a significant impact on the delivery of an essential or digital service. The trigger is impact, not size or sector. That approach is sensible, but I want to stress-test how it works in the context of operational technology. Across power, telecoms, transport, water and industry, many essential services rely on the same family of industrial control equipment. Substations, signalling systems and industrial plants may look different, but they often run on identical controlled devices and firmware supplied by a very small number of manufacturers. The risk is not hypothetical. A single vulnerability in widely deployed OT equipment can create a common mode failure across multiple sectors at the same time, even where each operator is individually compliant with its duties. At the moment, the Bill places obligations squarely on operators of essential services, but in OT environments, operators do not control the design of equipment, the firmware, the vulnerability disclosure process or the remote access arrangements that vendors often require as a condition of support. As Rik Ferguson highlighted in written evidence to this Committee, uncertainty about how and when suppliers might be brought into scope can lead to defensive behaviour and late engagement. The risk is amplified in OT, where suppliers may discover vulnerabilities before operators do, and where one operator may report an issue, while others in different sectors, using identical equipment, remain unaware. There is also a traceability problem. OT equipment is frequently sold through integrators and distributors. Manufacturers may not have a clear picture of where the equipment is ultimately deployed. Without that visibility, national-scale vulnerability notification and co-ordinated response become very difficult. UK Finance has also drawn attention to the complexity of multi-tier supply chains and the need for clear accountability when regulatory reach extends upstream. The clause recognises that reality, but its effectiveness will depend on how consistently and predictably designation decisions are made across sectors. My concern is not about the existence of the power. It is about whether, in practice, the power will be used early enough and clearly enough to address shared OT risks before they become cross-sector incidents. Operational resilience today depends less on individual sites and more on the security practices of a relatively small— I would say very small—number of OT suppliers that sit behind them. The clause has the potential to address that, but only if its application is focused on genuine systemic risk and supported by clear signals to suppliers and operators alike. For those reasons, the clause warrants careful consideration as the Bill progresses.

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
    More

    Does my hon. Friend agree that, although we support the intent behind the Bill, clause 2 does a lot of framing work but does not necessarily consider the extensive perimeter that is coming through and how proportionality will be applied in practice? I suggest that the Committee keep that in mind as we move through the detail.

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
    More

    Clause 7 is definition-heavy, and rightly so; these terms decide who is regulated and who is not. My only observation is that cloud models are, as the Minister knows, evolving quickly because of the AI revolution. Definitions that track architecture too closely will age fast, so the Committee should be alert to whether these terms will still make sense in five years’ time and not just today.

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
    More

    My hon. Friend is making a very good point, which also applies to improving board awareness and ensuring that the enforcement of the regulations incentivises boards to take the issue seriously and make sure that they are equipped to understand the commercial reality of cyber-security for their businesses. Enforcement is an important part of that.

  • 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
    More

    Clause 4 relies heavily on capacity as the trigger for regulation. I understand why that is attractive: it is measurable. But capacity is not the same as criticality, and a high-capacity facility used for redundancy can present less systemic risk than a smaller, highly concentrated one. I simply put on record that the way this threshold is applied in practice will matter more than the number itself.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q You have both mentioned the risk involved in supply chains. Do you think that, outside regulated industries, the Bill goes far enough to secure supply chains? If not, what would your recommendations be? David Cook: The legislation talks about secondary legislation, so it allows for an agile, flexible programme whereby organisations can be brought within scope very quickly if concerns make that necessary. What that leaves us with, though, is that although legislation can be changed quickly, organisations often cannot. Where there is a definition, as we see with NIS2, as to which entities are in scope, organisations can embark on a multi-year programme to get into a compliant position. They can throw money at it, effectively. What this legislation talks about, through the secondary legislation, is bringing organisations into scope and mandating specific security controls or specific requirements on those organisations in terms of security, but while the law might come in over a weekend, organisational change will not necessarily follow. There is a potential issue there. I can see the benefit and attractiveness of secondary legislation being used to achieve that aim, but having a clearer baseline as to what that sort of scope might look like—it could be ramped up or down, and the volume could be turned up or down, depending on need—would be more helpful. Reducing scope while diverging from NIS2 might be a benefit in terms of the commercial reality, but it might be a misstep in terms of security and the long tail that it takes to get more secure.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Does anyone have anything else? Jill Broom: I think that I will need to come back to you in writing on the specifics of operational technology.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q Do you think that there should be more or not? Stuart McKean: The devil is always in the detail, so any more clarity that can be put in the Bill is always going to be a good thing.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    I am so sorry. Could you possibly speak into the microphone? I cannot hear you. Stuart McKean: Sorry. I was saying that the cyber-criminal does not care about lines, geographies or standards. They do not care whether you have an international standard or you follow the legislation of a certain country. They will attack where they see the weak link.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q I have two specific questions. The first is about OT versus IT. Do you think that OT and its supply chains are sufficiently covered in the Bill? Secondly, given that you are all from commercial organisations, from your direct client experience, what is going to be the thing that moves the dial on board governance, specifically in relation to cyber? Chris Anley: On the OT versus IT question, we have mentioned specificity versus flexibility. The benefit of the UK sectoral regulator model is that regulators that are in areas where OT is predominant can set specific measures that can reinforce those environments, whereas if you try a one-size-fits-all approach, you run the risk of certain critical OT-based systems becoming subject to successful attacks. Ben Lyons: The broad approach that the UK is taking is sensible, in that the existing guidance has a range of principles around OT, as well as IT, security. Manufacturing is not in the scope of the Bill, which is probably appropriate, but it is worth looking at what could be done to improve the security of the manufacturing sector, more broadly, probably through non-legislative means. In light of recent attacks, it is important to ensure that guidance and incentives are in place to support that sector.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q Returning to the supply chain risks, I want to ask you about the difference between OT—operational technology—and IT, and whether there is sufficient detail in the Bill to protect that. If you have intelligent electronic devices from single suppliers across multiple sectors, are we confident that there is sufficient detail about what the regulatory role is in saying that suppliers should be within scope? Is more detail needed in the Bill? Stuart McKean: I am not an expert on the detail, but I would say that there is currently very little detail in the Bill regarding IT and OT.

  • 7 Jan 2026 · Engagements · Hansard source
    More

    Q4. Last year, the cargo vessel Baltic Clipper lost 16 containers off the beautiful West Sussex coastline. Beaches and seas in my constituency have been polluted with toxic debris. The clean-up was initiated and led almost exclusively by resolute local volunteers. Will the Prime Minister join me in paying tribute to all those involved for their extraordinary efforts? Will he, or the relevant Minister, meet me to ensure that the coastline is restored and that local taxpayers will not pick up any costs?

  • 7 Jan 2026 · Jury Trials · Hansard source
    More

    I hear everything my hon. Friend says. In his opening speech, my right hon. Friend the Member for Newark (Robert Jenrick) laid out a number of matters that could be acted on immediately to improve efficiency and ensure that we maintain the pillar of society that is our jury trials. Do you agree that we should be focusing immediately on that, rather than demolishing—

  • 7 Jan 2026 · Jury Trials · Hansard source
    More

    I just wonder why the hon. Lady would not look to implement the recommendations from the shadow Secretary of State before seeking to restrict jury trials.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I refer the House to my entry in the Register of Members’ Financial Interests. I commend my right hon. Friend the Member for Hertsmere (Sir Oliver Dowden) and my hon. Friend the Member for Exmouth and Exeter East (David Reed) for their excellent speeches. I particularly associate myself with their comments on the Computer Misuse Act 1990 and the need for an extension to our cyber-skills in this country. Before entering this place, I worked professionally in cyber-security and operational resilience, advising businesses of all sizes on how to reduce the risk of cyber-attacks and helping them to understand how far-reaching the consequences of a cyber-breach can be from a commercial perspective, and not just a technical one. I am vice-Chair of the Business and Trade Committee, and we have heard direct evidence for our report on economic security from Marks & Spencer, Co-op and Jaguar Land Rover, all of which suffered catastrophic breaches last year. Although the attacks were different in form and impact, as the shadow Secretary of State, my hon. Friend the Member for Hornchurch and Upminster (Julia Lopez), said, they shared a common feature: they were driven by social engineering, not technical failure. Human access was exploited, trust was abused, and controls failed further up the chain. The outcomes, however, were very different. At Co-op, a more modern, secure-by-design IT infrastructure enabled an early containment strategy, limiting the impact on customers, stores and the bottom line. Marks & Spencer, which had not prioritised early replacement of legacy infrastructure, suffered months of major disruption to customer-facing services and retail logistics. The financial impact alone for M&S is in the region of £300 million, or 45% of its prior year pre-tax profits. Jaguar Land Rover was in a different category altogether. There, the attack cut into operational technology systems tightly integrated with manufacturing operations, bringing production lines to a standstill and disrupting just-in-time supply chains. That shutdown cascaded far beyond a single company, directly impacting numerous suppliers in the midlands regional economy, as many Members have already mentioned, as well as contributing to a measurable fall in UK GDP, estimated to be in the region of £2 billion. Those cases demonstrate that cyber-risk manifests in three ways: operational risk, financial risk and reputational risk. Too often, even at FTSE level, businesses and boards fail to grasp that this is a potentially devastating combination. I hear the same message repeatedly from industry, including at the Financial Times Cyber Resilience Summit in London, where I spoke at the end of last year. There is frustration from CISOs—chief information security officers—and security vendors that it can be difficult to develop conversations with boards and audit chairs to assign the appropriate resources and strategic prioritisation. Businesses accept that standards must rise, but they want regulation that is targeted, proportionate and focused on prevention, rather than paperwork. The Bill does some things well. Updating the 2018 NIS framework, expanding coverage where it is genuinely needed and strengthening enforcement powers are all sensible in principle. Faster incident reporting has value, but reporting alone is not resilience. There are gaps that matter. First, the Bill does not go far enough on governance. Cyber failures are governance failures. Responsibility sits not only at board level, but clearly and specifically with chairs and audit and risk committees, yet the Bill stops short of driving meaningful accountability there. Without that pressure, cyber will continue to be delegated downward to IT and operations teams, rather than being owned at the top. Secondly, there is a risk of confusing activity with preparedness. Increasing reporting obligations after an incident does nothing to prevent the incident from occurring. Prevention is always better than cure, and this legislation needs a stronger emphasis on baseline capability, risk maturity and early intervention. Thirdly, we must be careful about cost, capacity and particularly enforcement. The implications for SMEs are significant, particularly those that are pulled into scope through supply chains. At the same time, regulators cannot enforce what they are not resourced to oversee. Without credible enforcement, the Bill risks becoming a paper exercise and boards will respond accordingly. Fourthly, the Bill needs to recognise the connection between, and draw a clear distinction between, IT and operational technology. What works for enterprise IT systems may be inappropriate or even dangerous in OT environments such as manufacturing, critical national infrastructure, energy and logistics. Segregation, architecture and the configuration of security devices must be assessed. Risk profiles differ; controls differ. That nuance matters. I want to be clear that the Opposition support the aims of this Bill in principle. Cyber-resilience requires a whole-of-society approach involving Government, regulators, businesses and boards working together, but if this legislation is to drive real change, it must be enforceable, proportionate and grounded in how organisations actually operate. Boards and audit committees must feel the weight of responsibility, regulators must have the tools and resources to act, and prevention must be prioritised over post-incident form filling. The National Cyber Security Centre has produced clear, practical guidance for boards, and that should sit at the heart of our approach. We need smarter regulation, properly enforced, not just more of it.

  • 5 Jan 2026 · Topical Questions · Hansard source
    More

    Sussex police is one of the most underfunded forces in England, with the number of officers per resident 27% below the national average. Following the national decrease in police officers during the first year of this Government, will the Home Secretary commit to ensuring that police officer numbers go up in 2026?

  • 18 Dec 2025 · Local Government Reorganisation · Hansard source
    More

    This is a disgraceful decision that damages our democracy and sets a dangerous precedent. To borrow a phrase, is the Minister afraid? Frightened? Frit? What does she say to my constituents whose fundamental right to have their say at the ballot box is now being taken away?

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    7. What discussions she has had with the Chancellor of the Duchy of Lancaster on introducing a nationwide digital ID system.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    A very happy Christmas to you, Mr Speaker. More than 5,300 of my constituents have signed a petition opposing digital ID, alongside nearly 3 million people nationally. In my own local survey, two thirds opposed it outright. Digital ID did not appear anywhere in Labour’s manifesto. The Government have no mandate for it and no consent from the public, so when will the Minister explain to the House on what democratic basis the Government believe they are entitled to enact their nationwide digital ID plan?

  • 11 Dec 2025 · Pubs: Bognor Regis and Littlehampton · Hansard source
    More

    Mr Speaker, “The Chancellor’s disastrous budget was the most bitter attack on the pub industry for years.” Those are not my words, but those of Iain Brown, who runs the William Hardwicke pub in Bognor Regis. Charlie Cockaday, landlord of the Fox Inn in Felpham, told me that due to increases in business rates, the minimum wage and alcohol duty, he will have to put 22p on the cost of a pint just to break even. Can the Minister tell Iain and Charlie, who are fighting just to keep their pubs alive, what on earth they are supposed to do?

  • 11 Dec 2025 · Pubs: Bognor Regis and Littlehampton · Hansard source
    More

    13. What steps his Department is taking to support pubs in Bognor Regis and Littlehampton constituency.

  • 11 Dec 2025 · Topical Questions · Hansard source
    More

    T8. Ahead of Small Business Saturday, I visited Armen at Rose Green Hardware. He told me that it has never been as tough to run a small business as it is under this Labour Government. Does the Minister believe that removing business rates relief will make things any easier?

  • 10 Dec 2025 · Seasonal Work · Hansard source
    More

    To reflect on my hon. Friend’s point about risk, employers are taking personal risk when they set up businesses and employ people. When they have so much cost piled on them, that risk-benefit equation evaporates, and with it the jobs that they deliver to other people in their communities.

  • 10 Dec 2025 · Seasonal Work · Hansard source
    More

    Will the Minister give way?

Published records only — not a full account of an MP’s work. How we work →