Allison Gardner MP: speeches 2026
72 published records · newest first.
Speeches
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
I know, sorry. I collapsed it down from quite a few. Richard Starnes: There is any number of different reasons. You have 12 competent authorities, at last count, with varying funding models and access to talent. Those could vary quite a bit, depending on those factors. I am not really sure how to answer that question.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I should point out that I once worked for the NHS AI and Digital Regulations Service and have also worked for a number of different regulators, including the ICO, so I have experience of the joys and frustrations of cross-regulatory working. We have heard evidence of the challenges experienced by businesses when they have to go to different regulators—I think it is as many as 14—and deal with the conflicting guidance they are often given and the skillset within each regulator. There were calls for one portal for incident reporting. The ICO is a horizontal regulator working across all sectors. In your experience, would a single cyber regulator be a good idea? What would be the benefits and the challenges? I will allow Ofcom and Ofgem to jump in and defend themselves. Ian Hulme: I suppose the challenge with having a single regulator is that—like ourselves, as a whole-economy regulator—it will have to prioritise and direct its resources at the issues of highest harm and risk. One benefit of a sectoral approach is that we understand our sectors at a deeper level; we certainly work together quite closely on a whole range of issues, and my teams have been working with Natalie and Stuart’s teams on the Bill over the last 18 months, and thinking about how we can collaborate better and co-ordinate our activities. It is really pleasing to see that that has been recognised in the Bill with the provisions for information sharing. That is going to be key, because the lack of information-sharing provisions in the current regs has been a bit of a hindrance. There are pros and cons, but a single regulator will need to prioritise its resources, so you may not get the coverage you might with a sectoral approach. Natalie Black: Having worked in this area for quite some time, I would add that the challenge with a single regulator is that you end up with a race to the bottom, and minimum standards you can apply everywhere. However, with a tailored approach, you can recognise the complexity of the cyber risk and the opportunity to target specific issues—for example, prepositioning and ransomware. That said, we absolutely recognise the challenge for operators and companies in having to bounce between regulators. We hear it all the time, and you will see a real commitment from us to do something about it. Some of that needs to sit with the Department for Science, Innovation and Technology, which is getting a lot of feedback from all of us about how we need it to co-ordinate and make things as easy as possible for companies—many of which are important investors in our economy, and we absolutely recognise that. We are also doing our bit through the UK Regulators Network and the Digital Regulation Cooperation Forum to find the low-hanging fruit where we can make a difference. To give a tangible example, we think there should be a way to do single reporting of incidents. We do not have the answer for that yet, but that is something we are exploring to try and make companies’ lives easier. To be honest, it will make our lives easier as well, because it wastes our time having to co-ordinate across multiple operators.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q You have answered the question I was about to ask. I may ask an addendum to that, but first I want to clarify something. If you put liability on an individual board member, that is going to cause problems. Do you think that there should be a statutory responsibility for the company to have a board member responsible for cyber-risk, and that the responsibility and accountability should sit at company level? Richard Starnes: I think this should flow from the board to the C-level executives. Most boards have a risk committee of some sort, and I think the chair of the risk committee would be a natural place for that responsibility to sit, but there has to be somebody who is ultimately responsible. If the board does not take it seriously, the C-levels will not, and if the C-levels will not, the rest of the company will not.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I will be quick. Much of my question was already asked. I will just say that proportionality is a known principle within regulation and I take that into account. I want to push on an issue that was raised. When you are dealing with different regulators with a cross-regulatory theme, you often get conflicting guidelines. It is a big headache for people. Again, you get the gaps and the duplication. To ensure my understanding, who will oversee making sure that the regulators align with each other to make it easier for people working within the sectors? Otherwise, they will go to one regulator and it will say one thing, and another will say another thing. Kanishka Narayan: It is an important point. We know that the quality of current regulation for cyber-security varies across regulators. As an earlier panellist said, there is virtue in the fact that we have not set an effective cap on where regulators can go by having a single standard. At the same time, we need to make sure that we are raising a consistent floor of quality and proportionality judgments. First, there is obviously constant oversight of each regulator through the lead Departments. In my case, for example, we consistently engage with Ofcom on a range of areas, including this one, to ensure the quality of regulation and that proportionality judgment is appropriately applied. Secondly, there is a clear commitment in the Bill for the Secretary of State to report back, on a five-year basis, on the overall implementation of the regime proposed in the Bill. That will be when we can get a global view of how the whole system is working.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Okay, I am glad I clarified, because that is quite interesting. I will ask my actual question, and I am trying to get my head around this. You recommend mandating that company boards be accountable for mitigating cyber-risks, and as we know from the annual cyber-security breaches survey, there are declining levels of board responsibility for cyber in recent years, which links to whether there should be a statutory duty. I am a little worried about small and microbusinesses having to deal with that regulatory burden, especially if they are designated as critical suppliers. I am trying to marry those two things together, and the concern of where liability sits, because we are very dependent on service providers. I do not know if that makes any sense to you, but could you clarify my thinking? Chris Parker: It is a concern. I will start off with a small point about where there is a statutory requirement, certainly for large companies. I personally believe—and I am pretty sure that most industry people I speak to would say this—that it would be very surprising if we did not have cyber-focused people on boards and in much bigger governance, as we would in a financial services company, where people who are expert in financial risk are able to govern appropriately. As we get smaller and smaller in scale, that is much harder to do. The good news is that there are some brilliant—and I really mean that—resources available from probably the most underused website in the world, but the best one, which is the National Cyber Security Centre website. It has some outstanding advice for boards and governance on there. You can effectively make a pack and write a checklist, even if you are a very small company with a board of two people, and go through your own things and make sure your checklists are there. The data and the capability are there to give support. Whether it is signposted enough, and whether we are helping on a local level, to make sure that people are aware of those things is perhaps something we could do better at in this country. But I am sure that industry will do our part, and we do, to share and reinforce the good sharing of things like that website, to guide good governance for SMEs especially. Carla Baker: That board-level accountability is really important, and it is crucial for cyber-security. I think it is getting better—from the senior execs that I speak to in industry, there is more understanding—but generally speaking, there is a view that cyber-security is an IT issue, not a business issue. I am sure you have heard throughout the day about understanding the risks we have seen around vulnerabilities, and the incidents that have affected the retail or manufacturing sectors. Those are substantial incidents that have impacted the UK and have systemic knock-on effects. Organisations have to understand the serious nature of cyber-security, and therefore put more emphasis on cyber at the board level. Should we be mandating board-level governance? That is useful for this debate to seek information and input on, but the burden on SMEs has to be risk-based and proportionate, however it is framed.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Thank you—that was quite detailed. I have a very quick question: what measures would you want the Government to take to enhance the cyber-resilience of the UK’s critical national infrastructure? I am interested in your thoughts on requirements for failsafes and risk management, and indeed on the non-technical resilience measures that would be needed in case of complete failure. Professor John Child: Again, I have to draw back to the criminal law aspects. I think the Bill does the things it needs to do well; certainly, from the conversations I have had with those in cyber-security and so on, these are welcome steps in the right direction. However, when you look at critical national infrastructure, although you can create layers of civil responsibility and regulation—which is entirely sensible—most of that will filter down to individuals doing cyber-security and resilience work. It is about empowering those individuals; within a state apparatus, that is one thing, but even with regulators and in-house cyber-security experts, individuals are working only within the confines of what they are allowed to do under the criminal law, as well as the civil regulatory system. The reason I have been asked here, and what a lot of my work has focused on, is this: if you filter responsibility down to individuals doing security work for national as well as commercial infrastructure, you need to empower them to do that work effectively. The current law does not do that; it creates the problem of either doing that work under the veil of criminalisation, or not doing it, with work being outsourced to places where you do not have the back-and-forth communication and reporting regime you would need.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q You mentioned stringent application of the regulatory regime. Could you explain the reasons for the lack of enforcement under the current NIS guidelines? Do you feel that the regulatory regime should be streamlined? Richard Starnes: That is a very broad question.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I have a couple of unconnected questions. We have asked a couple of times whether senior board members should have legal, statutory responsibility for cyber. The pros are that it is not seen as a priority, and culture change has to be top-down. However, there are issues with smaller companies bearing a responsibility that is diffused along the supply chain. Also, boards that tend to have a focus on providing returns for shareholders may not be investing in this complex arena. I am interested in your thoughts on whether the Bill does enough to make senior executives responsible for their organisations’ cyber-security. Professor John Child: I think the Bill does a lot of things quite effectively. It modernises in a sensible way and it allows for the recognition of change in type of threat. This goes back to my criminalisation point. Crucially, it also allows modernisation and flexibility to move through into secondary legislation, rather than us relying purely on the maturations of primary legislation. In terms of board-level responsibility, I cannot speak too authoritatively on the civil law aspects, but drawing on my criminal law background, there is something in that as well. At the moment, the potential for criminalisation applies very much to those making unauthorised access to another person’s system. That is the way the criminal law works. We also have potential for corporate liability that can lead all the way up to board rooms, but only if you have a directing mind—so only if a board member is directing that specific activity, which is unlikely, apart from in very small companies. You can have a legal regime that says, whether through accreditation or simple public interest offences, that there are certain activities that involve unauthorised access to another person’s system, which may be legitimate or indeed necessary. However, we want a professional culture within that; we do not want that outsourced to individuals around the world. You can then build in sensible corporate liability based on consent or connivance, which goes to individuals in the boardroom, or a failure-to-prevent model of criminalisation, which is more popular when it comes to financial crimes. That is where you say, “If this exists in your sector, as an industry and as a company, you can be potentially liable as an entity if you do not make sure these powers are used responsibly, and if you essentially outsource to individuals in order to avoid personal liabilities”.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Very quickly—I apologise if I am taking too much time—accountability is slightly different from liability. In the case of a cyber-breach that has caused harm, where would you see the liability lying? Chris Parker: That is a harder question. There is precedent here—of course, we can think back to the precedents that this great building has set on allowing things such as, post-Clapham train disaster, the Corporate Manslaughter and Corporate Homicide Act 2007 putting it very firmly on boards, evolving from the Health and Safety at Work etc. Act 1974. We are not there yet, but do not forget that we are starting to legislate, as is everyone else in Europe and America who are on this journey. I believe that we will see a requirement at some point in the future. We all hope that the requirement is not driven by something terrible, but is driven by sensible, wise methodology through which we can find out how we can ensure that people are liable and accept their liability. We have seen statements stood up on health and safety from CEOs at every office in this country, for good reason, and that sort of evolution may well be the next phase. Carla and I talk about this a lot, but we have to be careful about how much we put into this Bill. We have to get the important bit about critical national infrastructure under way, and then we can address it all collaboratively at the next stage to deal with very important issues such as that.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Particularly between regulators, and how that would work. Carla Baker: I cannot necessarily talk in much detail about information sharing across regulators. It is more about information sharing across the technology industry that I can talk about.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
I think you are touching on the old problem of where liability lies when you have this long supply chain of diffused responsibility, but thank you.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I have loads. Before I come to the question I was going to ask, I want to pick you up on the worry about information sharing. I have worked across regulators, and they seemed to be really confident about information sharing, but I know that is not always the case. There is some protection of turf, and other Acts might prohibit that information sharing. Could you expand on that area of concern? What would be your recommendation? Carla Baker: My comment on information sharing was about what else the Government could do. It was not necessarily specifically to do with the Bill. If you want me to elaborate on the wider issue of information sharing, I am happy to.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q Ben, are you combining two risks? Ben Lyons: That is something we think very deeply about. We see AI as helping to mitigate some of the risks from cyber-security by making it possible to detect attacks more quickly, understand what might be causing them, and to respond at pace. We are an AI native company and we have thought deeply about how to ensure that the technology is both secure and responsible. We are privacy-preserving by design. We take our AI to the organisation’s environment to build an understanding of what normality looks like for them, rather than vast data lakes of customer data. We take a lot of effort to ensure that the information surfaced by AI is interpretable to human beings, so that it is uplifting human professionals and enabling them to do more with the time they have. We are accredited to a range of standards, like ISO 27001 and ISO 42001, which is a standard for AI management. We have released a white paper on how we approach responsible AI in cyber-security, which I would be happy to share with you and give a bit more detail.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q It is interesting that you mentioned the complexity and skilled teams. Sanjana, you talked about the need for more skill and responsibility, and how distributed responsibility across supply chains is a big deal. That comes down to a duty of care on people who are procuring these things. The annual cyber security breaches survey found that board-level responsibility for cyber has declined in recent years. What explains that, and how could it be improved? As a quick supplementary question, do you think there should be a statutory duty for companies to have a board member responsible for cyber risk? Jill, I will go to you first. Jill Broom: With the board, historically, cyber has not been viewed as a business risk, but as a technical problem to be addressed by the technical teams, instead of being a valuable, fundamental enabler of your business and a commercial advantage as well, because you are secure and resilient. That has been a problem, historically. It is about changing that culture and thinking about how we get the boards to think about this. I think a fair amount of work is happening; I know the Government have written to the FTSE 350 companies to ask them to put the cyber governance code of practice into play. That is just to make cyber a board-level responsibility, and also to take account of things such as what they need to do in their supply chain.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q But do you think there should be a statutory duty to have a board member responsible? Jill Broom: Some of our members have pointed out that the number of organisations under cyber-regulations is very small, and it is only going to increase a small amount with the advent of this particular Bill. Similarly, in the different jurisdictions there are duties at the board level. There is an argument for it. The key thing is that we need to be mindful of it being risk-based, and also that there are organisations that could be disproportionately affected by this. I think it needs a little more testing, particularly with our members, as to whether a statutory requirement is needed.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q I have a quick question. You mentioned vulnerabilities earlier, and you mentioned, Jen, the complexities of implementing cyber-security plans. As well as technological factors, human factors, not the least of which is the lack of skills, play a key role in cyber-resilience. How would or could the Bill address the human element in cyber-security? Jen Ellis: That is a great question, and a tricky one. We talk a lot about training and security awareness, and unfortunately I think it becomes yet another tick box: you start a job and watch your little sexual harassment training video, then you watch your cyber-security training video, and probably the former sticks with you better than the latter. I think we have to change that. We have to change that dynamic. I go back to my last answer, which was that I think one of the strengths of the Bill is that, hopefully, it will enable the regulators to engage much more on this topic and therefore to engage their covered entities much more. That is what we need to see. We need to see the leadership in organisations engage with the topic of cyber-security, not as a chore, as a tick-box exercise or as that headline they read about JLR, but actually as something that matters to their organisation—as something they are going to engage with at a board and executive team level, all the way down through the organisation. Cultural change comes from the top, typically, and we need to see that level of change. I do not think that there is anything specific in the legislation, as it is currently written, that says, “And this,” in flashing lights, “is going to change the human factors piece.” I think that the devil will be in the detail of the secondary legislation, and then in what the regulators specifically ask for. But there does need to be a general shift in the culture, whereby as sectors generally we start to talk more about this as a requirement. The financial services sector has talked about security for a long time—it has been a reality for it—but I am not sure how true that is, at breadth, in something like the water industry. I hope that that will change. I hope that we will start to see having those conversations at the top levels, and then all the way down, becoming more of a cultural norm. Unfortunately, you cannot create culture change quickly. When it comes to talking about human factors, it is about people becoming much more aware of it and thinking more about it. That will take time—
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q I have so many questions, some of which have been touched on; I will limit myself. I was interested in the CyberUp campaign that you mentioned. What other measures, both legislative and non-legislative, could the UK Government take to enhance the cyber-resilience of the UK’s critical national infrastructure? In terms of resilience, is there any requirement to look a bit more deeply at failsafes and non-technical failsafes that we might need, because we are always going to get that? My second question is for Ben. In combining AI and cyber, you are combining technologies that come with their own unique risks with cyber-security. I am interested in how you mitigate against that. I am intrigued because, when you talk about AI, I assume you are not talking about straightforward machine learning. Chris Anley: In terms of what other things we could do, we have talked about voluntary codes. The value of voluntary codes was questioned in an earlier session; but the World Health Organisation best practice guide on handwashing, which is entirely voluntary, saved millions of lives in the recent pandemic. It is important to bear in mind that codes that help you to protect yourself are definitely valuable. Other actions that are already taking place that we may want to extend on the basis of solid evidence and data are the cyber essentials scheme, for example, and the various codes of practice. The cyber governance code of practice for boards was mentioned earlier, along with the Government outreach and attempting to get boards to recognise that cyber risk is a business risk and an existential threat. We talked about the cyber assessment framework and how that is likely to be the scope within which this Bill is implemented. So, we do not necessarily need to do something new. The scope of the Bill, as we said, is 0.1% of the UK private sector. There is scope to expand the existing things that we are doing, especially cyber essentials, for example, raising the bar for small and medium-sized enterprises across the economy. There is a lot that we are already doing that we could do, that we already have the scope to expand, but obviously that must be done prudently and on the basis of solid evidence.
- 20 Jan 2026 · Mobile Phones and Social Media: Use by Children · Hansard source
More
Organisations such as the Molly Rose Foundation highlight that evidence to support social media bans remains very uncertain and warn that blanket restrictions could unintentionally cause harm by pushing young people towards unregulated platforms, remove trusted online spaces, undermine digital literacy and, indeed, create a cliff edge at the age of 16. Does the Secretary of State agree that we must take a calm, evidence-based approach to this complex issue and ensure that children’s voices are central to the consultation?
- 14 Jan 2026 · Northern Powerhouse Rail · Hansard source
More
I welcome the Government’s announcement today on Northern Powerhouse Rail. However, in Staffordshire and Stoke-on-Trent we are still in stasis, with legacy issues such as the HS2 compound at Yarnfield, which is costing millions. I ask the Secretary of State for clarity on plans for our railway services in Staffordshire and Stoke-on-Trent and for HS2 legacy issues such as the Yarnfield compound.
- 8 Jan 2026 · Economic Growth: Transport System · Hansard source
More
7. What steps she is taking to help ensure that the transport system supports economic growth.
- 8 Jan 2026 · Economic Growth: Transport System · Hansard source
More
My constituency of Stoke-on-Trent South and the villages is home to internationally recognised visitor attractions, including the iconic World of Wedgwood and the stunning grade-II listed Trentham Estate and its gardens, yet public transport access to those sites remains limited. Two local railway stations, Barlaston and Wedgwood, continue to be placed under a lengthy temporary closure of 19 years. Will the Secretary of State support the reopening of the Stoke-on-Trent South railway stations to better connect communities with jobs, skills and tourism opportunities to boost economic growth in my constituency?
- 7 Jan 2026 · UK Town of Culture · Hansard source
More
It is a pleasure to serve under your chairship, Ms Furniss. I thank my hon. Friend the Member for Halesowen (Alex Ballinger) for securing this debate. I am delighted to speak today to shine a spotlight on Longton, a proud town in my constituency and a place where culture does not just sit in museums but runs through everyday life. Longton stands proud among Stoke-on-Trent’s six towns—five not six, Mr Arnold Bennett—all of which retain their own identity. Longton’s culture is inseparable from its history. It made a significant contribution to the UK’s heritage and culture through our proud pottery industry, which to this day still ships British products all over the world. Duchess China provides its china to the House of Commons and the House of Lords, and Sarah Rose provides china to No. 10—we are everywhere. Longton was once at the beating heart of the industry, and visitors from all over the world now come to marvel at our pottery heritage at the beloved Gladstone Pottery Museum, home of “The Great Pottery Throw Down”. But Longton’s heritage is not just a relic of its past. The skills, creativity and pride forged through generations of pottery and craft continue to shape our future. The ceramics industry has faced real challenges, but there is an enormous opportunity to grow tourism and breathe new life into our many heritage buildings. Local businesses are already capitalising on the opportunity to showcase our culture. The Kiln at Number 12 offers visitors pottery, painting and hands-on craft experiences. I am sure Members have seen those fish-shaped drinking jugs—they are from the Gluggle Jug factory, in my constituency. Roslyn works, a grade II listed pot bank, is now an entrepreneurial centre that showcases the work of brilliant local artisans and hosts the smallest pottery kiln in the country. Launch It, which operates in Longton town hall, is a local hub for young entrepreneurs, creatives, artists and makers to seek business and start-up support—supporting new arts, crafts and creative businesses to thrive. Our culture extends beyond pottery to arts and music. In our town centre, we have beautiful murals commemorating the world wars, as well as commemorating the world-renowned Belstaff brand, which started in Longton and now sells clothes all over the globe. There are plans for another huge mural opposite our train station to commemorate our proud pottery heritage, plus a new statue outside our town hall celebrating female potters. Music is central to Longton. At Methodist Central Hall, we have frequent choirs, including Stoke male voice choir. We are incredibly lucky to have Urban Wilderness, a charity that delivers place-based events and arts programmes to empower our local community. It has recently secured funding to turn an old bank into a new art centre, expanding on its Moony Club programme—a free-to-access arts programme in Longton Exchange. In 2023, Urban Wilderness started its famous Longton carnival and pig walk parade. It is based on a local heritage story about Mayor John Aynsley, who won a bet with the Duke of Sutherland by walking a pig through the centre of Longton, thereby winning the Queen’s parkland for the people of Longton. I thank Isla Telford at Urban Wilderness for putting forward Longton’s bid for the UK town of culture, and Roz Ryan, in the vibrant Longton Exchange, for putting the idea forward. Their bid proposal will look into themes of work and play, young people, and the legacy of our great ceramic heritage, including our canals and our connections to coal. They will be working with multiple partners to deliver a future-focused bid that builds on the centenary of Stoke-on-Trent and celebrates Longton’s unique blend of industrial manufacture, play and connectivity. Longton’s story is not just a local one. It is a story of British industry, British creativity and British communities refusing to give up. I am confident that, with the right support, Longton can continue to be a vibrant town centre, and that it would be a great UK town of culture.
Published records only — not a full account of an MP’s work. How we work →