Ben Spencer MP: speeches
263 published records · newest first.
Speeches
- 4 Mar 2026 · Family Farms · Hansard source
More
4. What discussions she has had with Cabinet colleagues on supporting family farms in Wales.
- 4 Mar 2026 · Family Farms · Hansard source
More
International conflict and instability risk putting up food and fuel prices, and threaten our domestic food resilience. Instead of reviews and platitudes, we need action to protect our farmers and our UK food resilience. Will the Minister take action and scrap the damaging family farm tax?
- 3 Mar 2026 · Spring Forecast · Hansard source
More
Given what is happening in the middle east at the moment, there is a concern that petrol and diesel prices will spiral upwards. If that happens, taxation revenue on fuel will do the same. Can the Chancellor commit today to keeping taxation revenue at its current level, thereby reducing tax on fuel to help ease any future cost pressure?
- 3 Mar 2026 · SEND Provision: Local Authorities · Hansard source
More
The Minister is being generous with her time and I thank her for giving way. I want to reiterate the point about the families who have already gone through the system and who have fought for EHCPs, many of whom have had to go through tribunals and feel like they are having to do everything on their own. I come from a mental health background, and I am surprised that the system does not have what I would call a care co-ordinator to support families who are going through this difficult process. Families are genuinely scared that the Government’s proposed reforms will lead to a stripping away of support. In my constituency, where we are served by Surrey and Borders partnership NHS foundation trust, it takes a year and a half to get an autism diagnosis, and even longer if people need medication for ADHD. I have raised that in this place with Ministers from the Department of Health and Social Care, but can the Minister reassure me that as part of the approach to SEND, she and her Department are looking at the interface between education and health? I understand what she says about the absence of a diagnosis not meaning that a child should not be supported—we could have another debate about that—but for many children a diagnosis is very important, and it needs to be timely and treatment needs to be quick and effective. Finally, before I test your patience, Madam Deputy Speaker, may I invite the Minister to come to Meath school, a special educational needs school in Ottershaw in my constituency? It is an amazing place and every time I go there I learn so much, so it would be great if she could come along and meet the fantastic kids and teachers there.
- 2 Mar 2026 · Middle East · Hansard source
More
I have heard a lot of legal analysis from the Prime Minister but nothing on what he thinks is morally right. Is not the biggest risk to international law when leaders hide behind legal advice to avoid taking responsibility for their decisions?
- 2 Mar 2026 · Representation of the People Bill · Hansard source
More
It is a real pleasure to follow the hon. Member for Milton Keynes Central (Emily Darlington), who has spoken passionately about the risks of democratic interference. I know this is something that she has thought about in great detail. She may be aware that during the passage of the Data Protection Act 2018 we had an amendment to help to facilitate digital watermarking, which in this space would help not only with the copyright AI issue but particularly with the risk of democratic interference. Authenticity in communications is so important. In my contribution to this debate, I want to talk about votes at 16. It is an incredible privilege to live in the United Kingdom and to be a citizen of the UK. One of our privileges is that we have a long-established history of free and fair elections, and many of our ancestors fought pretty hard and made great sacrifices to get the voter franchise that we have at the moment. Voting is really important. It is important as an adult act for a citizen of our country. Voting matters. That impact matters. Voting is part of the contractual relationship that we have with the state. As citizens of our country, we have a right to vote and to influence the decisions made on our behalf by our representatives, whether that is at local or parliamentary level. I am concerned that taking away the adultness of voting, by saying that children—people below the age of 18—now have that expanded voter franchise, will diminish the status of voting in our country. It will take voting away from being an act where someone has to pass an age barrier to be recognised as an adult in our society.
- 2 Mar 2026 · Representation of the People Bill · Hansard source
More
One of those criteria should be that one is an adult, because voting is an adult act, and the other criterion should be citizenship. We do not have time for a debate today on how we approach citizenship in the UK and what that actually means, but if we start trying to unravel—
- 2 Mar 2026 · Representation of the People Bill · Hansard source
More
I thank the hon. Lady for her intervention, but I think there is a difference between representing people and people having the ability to vote for us. If we were to take that argument to its ultimate conclusion, it would expand the voter franchise not only to every single age but to non-citizens. I do not know if people agree with that— [ Interruption. ] It will be interesting to hear if that debate expands. I am sure that many people under the age of 18 have the decision-making capacity, maturity and ability to vote, but this debate is not about that. It is not about someone’s ability to vote; it is about whether they should vote and the status we afford to voting enfranchisement.
- 2 Mar 2026 · Representation of the People Bill · Hansard source
More
The point the hon. Member makes illustrates exactly why we have to use an adult citizenship criteria, not one based on capability or ability, because the moment we start to do that, all sorts of awful things risk happening. People should get the right to vote in the UK if they are a citizen and if they are an adult, and that is it. We should never put at risk someone’s right to vote because of considerations about their cognitive ability, and that goes in both directions. People should be careful what they wish for in making arguments to remove adult status and citizenship from voter enfranchisement. They may not like where they end up.
- 2 Mar 2026 · Representation of the People Bill · Hansard source
More
I am not making any sort of comment on that. My point is very simple: it is citizenship and age. If we are to apportion the respect to voting that we absolutely should—I think all of us in this House think voting is a critical thing to do—giving it the status of being an adult decision, as opposed to one made by children, is also important. To not do so is fundamentally anti-democratic. It diminishes what people have to go through in terms of the status of voting compared with other decisions. Voting is more important than being able to buy a beer, have a driving licence or join the cadets. Voting is absolutely critical, and that is why it is so important that it should be seen as an adult act, not an act that is within the scope of being a child.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
New clause 14, tabled by the hon. Member for Henley and Thame, addresses concerns regarding the capacity of SMEs to comply with their regulatory obligations, should they be brought within the scope of the Bill. That matter has been discussed on several occasions by the Committee. That is only right given that, according to figures provided by NCC Group, SMEs make up over 99% of businesses in the UK but too often lack the skills and budgets to implement proportionate cyber-protections, leaving them particularly exposed. SME cyber assistance schemes akin to the one proposed by the new clause have been rolled out in Scotland on a limited basis and in Australia, where the Government are investing 8 million Australian dollars over three years to provide free person-to-person support for small businesses during and after a cyber-attack. Those schemes have enjoyed some success in hardening cyber-resilience among SMEs that have been able to access them. That can only be welcomed. There is a case for looking more closely at whether regulation is the appropriate first step to address the cyber-resilience of the smallest organisations that might be brought within the scope of regulation, as legal compliance efforts could detract from already pressured operational defence budgets. In giving evidence to the Committee, Jill Broom of techUK called for strategies “such as financial incentives, or…tax credits” –– [ Official Report, Cyber Security and Resilience (Network and Information Systems) Public Bill Committee, 3 February 2026; c. 18, Q20.] to help SMEs improve their cyber-resilience, and techUK has suggested that funding or relief could be applied on a priority basis, with those working within the critical national infrastructure supply chain looked at first. In the light of those considerations, what analysis has the Minister’s Department conducted of the likely return on investment, in terms of sustainability and growth among smaller companies, of a cyber support service for UK SMEs?
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I beg to move, That the clause be read a Second time. This new clause would require the Secretary of State to review the effect of existing information sharing and analysis centres, with a view to determining whether further such centres should be established. The financial services industry has successful voluntary schemes—the Cyber Defence Alliance, and the Financial Services Information Sharing and Analysis Centre—which act as hubs for collaboration on all matters relating to the prevention, detection, mitigation and investigation of cyber-threats and criminality impacting members. These organisations provide an essential alerting and co-ordinating role for their members, including providing intelligence and technical support during ongoing incidents. They can assist in building partnerships contextualised to particular sector risks. According to Richard Starnes of the Worshipful Company of Information Technologists, companies “may be competing with one another in their chosen businesses, but they are all in the same boat with regard to being attacked by whatever entities are attacking them.” And he said that if the FS-ISAC were replicated “on an industry-by-industry basis, particularly ones in CNI, that would be helpful. It would also help with information sharing with entities like NCSC and GCHQ.” –– [ Official Report, Cyber Security and Resilience (Network and Information Systems) Public Bill Committee, 3 February 2026; c. 64, Q75-76.]
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
In response to the Minister’s comments, clause 40 is about a review; it does not provide any direction, other than for the Secretary of State to do their job in reviewing this area. I will press new clause 4 to a vote. Question put, That the clause be read a Second time.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
This new clause, tabled by the hon. Member for Brecon, Radnor and Cwm Tawe, would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations. Historical levels of regulatory oversight and enforcement in relation to the NIS regulations 2018 have fallen short of what is necessary to achieve meaningful cyber-resilience across regulated sectors. The second post-implementation review of the NIS regs 2018, conducted in 2022, found that incident reporting on the part of regulated entities was very low, with only 13, 12 and 22 NIS incidents reported in 2019, 2020 and 2021 respectively. A review conducted by the Worshipful Company of Information Technologists identified a near total absence of formal financial sanctions under the NIS regulations, with zero confirmed major penalties from 2021 to 2024. The model has not been conducive to effective discharge of regulatory responsibilities, with knock-on effects for cyber-resilience and regulated industries, yet regulators will be expected to oversee a far larger pool of regulated bodies and process a far larger number of incident reports under the Bill’s provisions. It is therefore right for us to scrutinise carefully whether regulators are in a position to meet these obligations. In the evidence sessions, many of my questions to witnesses, including those from Ofgem, Ofcom and the Information Commissioner’s Office, focused on their preparations to meet the demands of their expanded roles. It was clear from feedback that although regulators understand what they need to do to prepare, the practical challenges associated with securing sufficient resource are far from resolved. I would therefore be grateful if the Minister could clarify his plans to review regulators’ progress and what the key milestones will be to ensure that regulators can discharge their new duties alongside their existing ones when these provisions come into effect.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
New clause 16 would require active board oversight of security and resilience measures and accountability for board members where they fail in those oversight duties, whereas new clause 17 would require regulated entities to carry out proportionate, periodic testing of the security and resilience of their network and information systems, and provide the results to regulatory bodies upon request. On board accountability, as we have already discussed in this Committee, the existing regulatory model under NIS regulations has not been sufficiently effective in driving up cyber-resilience standards to meet emerging threats. Board engagement is a key part of that, but the stat I quoted previously in this Committee indicates that engagement is going in the wrong direction. What assessment has the Minister made of the potential advantages and disadvantages of direct accountability in the adoption of effective cyber-resilience measures, based on a roll-out of the NIS2 regulations? Proportionate testing of systems may be a useful tool in detecting and managing cyber-security risk. What consideration has the Minister’s Department given to how that topic should be approached in the Secretary of State’s code of practice?
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I beg to move, That the clause be read a Second time. The National Audit Office’s 2025 report on cyber-resilience highlighted that Government Departments and agencies are among the weakest links in the UK’s cyber-security ecosystem and lack a credible plan to become cyber-resilient in the short to medium term. The Government play a key role in the management of certain critical national industries, but the continuing cyber-security vulnerabilities in the IT systems used to operate CNI expose the UK to the threat of serious attacks that could undermine national security and the economy. That is not to mention the risk to enormous amounts of highly sensitive data held on Government systems. Dr Sanjana Mehta of ISC2 said in her oral evidence that the Department for Work and Pensions administered £288 billion of benefits over the past year, with more than 23 million people claiming benefits of some kind. That activity involves processing vast amounts of personal, medical and financial data, which presents rich pickings for malicious actors. The feedback from industry stakeholders, many of whom are being asked by the Government to take on onerous security and reporting obligations under this Bill, echoes those concerns regarding Government cyber-immaturity. There is a strong sentiment that the Government should be leading by example, as Chris Anley of the NCC Group commented in the Committee’s oral evidence sessions. In view of the growing risk posed to UK cyber-security by hostile state actors, by their affiliates and by criminal gangs, improving Government cyber-security is urgent. It is clear from the NAO’s findings and other recent reports that Government Departments have lacked the clear goals and necessary accountability to incentivise tackling this significant challenge. In his letter of 19 February to members of the Committee, the Minister said: “Government will be held to equivalent cyber security requirements that we expect of the essential and digital services in scope of the Cyber Security and Resilience (Network and Information Systems) Bill.” But as matters stand, there are no effective legal mechanisms for accountability to Parliament on increasing Government cyber-resilience to the standards necessary to meet the intensifying threats facing our Government Departments and agencies. New clause 5 would compel the Secretary of State to make yearly reports to Parliament setting out the Government’s progress towards meeting the recommendations of the National Audit Office’s 2025 report on Government cyber-resilience and towards meeting the standards they set themselves in their recent cyber action plan. Where necessary, the Secretary of State would have to account for failures to meet deadlines for implementation and issue a new plan to achieve compliance. In moving this new clause, I am aware of the challenges that successive Governments have faced in driving up cyber-resilience standards. There are serious practical and budgetary obstacles that can impede progress, such as the vast amount of legacy IT equipment that remains in use, which is inherently more vulnerable to attack. Moreover, there is the ongoing problem of recruiting highly skilled cyber-security professionals to work in these roles, given the competition in the recruitment market and constraints on public sector salaries. Illustrative of that challenge is the worrying statistic, cited by Chris Anley of the NCC Group, that “almost a third of cyber-security posts in Government are presently unfilled”. –– [ Official Report, Cyber Security and Resilience (Network and Information Systems) Public Bill Committee, 3 February 2026; c. 24, Q29.] None the less, the Government have now put in place a plan that they consider achievable, and they should be held to account for it. The new clause creates a mechanism for that much-needed accountability.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
We are a responsible Opposition and we are pleased to hear about the work that the Minister and his Department have been doing and about the shared purpose in getting this done and getting it right. Would he give us a bit more detail of the timescales and plans for public consultation? I understand that he has been doing some personal consultation in private, but will there be a public consultation? Given that the reform crosses two Departments, which Department will be taking it forward? What I am really looking for from him is a confirmation at the Dispatch Box that he is personally committed to getting this piece of work over the line during this parliamentary term.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I agree about the importance of putting things on the record. Since the hon. Member obviously has not been listening to my speech, he can check it out on the record. I acknowledged the challenges in this area— [ Interruption. ] Does the Government Whip want to intervene, or was she just chuntering? I will continue. Given that the Bill puts quite a burden on the private sector, as we discussed over several sittings before the parliamentary recess, I think it is important that the Government recognise, as my hon. Friend the Member for Spelthorne said, it would be pretty shameless not to vote for accountability for themselves while putting it on other people. Let us see how the vote goes. I commend new clause 5 to the Committee.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I am grateful to the Minister for his response, but we have seen over the past six months, especially with the alleged spying incidents in Parliament, the Government’s resistance to recognising the Chinese Communist party as a threat. When it comes to our new clause 3 and concerns over transparency, we have also seen, in the last few weeks, that there are mechanisms—for example, the Intelligence and Security Committee—to ensure the disclosure of documents, while preserving national security. I would therefore like to press new clauses 2 and 3 to a vote. Question put, That the clause be read a Second time.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I am a bit unclear about the hon. Gentleman’s intervention. The point I was making was that there is legitimate concern that people doing research into this area and doing threat assessments risk prosecution, so, across the whole of our society, that work is not being done. We have heard quite a lot of evidence from cyber campaigns about the benefits that changes to this law would make to the system, which is why we tabled the new clause. I commend new clause 19 to the Committee. I hope the Minister agrees that now is the time to address the issue. I suspect that this will be my last, or penultimate, time speaking to the Committee, so I would like to finish by thanking Members on both sides of the Committee for a fun and, at times, robust debate over the past month. I thank the Chairs, the Clerks and all the teams working on the Bill—and Sophie Thorley from my office, who has done incredible research on the Bill.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I will speak to new clause 19, tabled in my name on behalf of His Majesty’s official Opposition. The new clause would compel the Secretary of State, within 12 months of Royal Assent, to review the need for a statutory defence, encompassing legitimate cyber-research activities, to criminal offences under clause 1 of the Computer Misuse Act 1990, which is about unauthorised access to computer programs. The campaign for reform in this area, CyberUp, has argued that, in its current form, the CMA inadvertently criminalises critical activity such as vulnerability research and threat intelligence, both of which are essential for defending the nation’s digital systems. The new clause would also require the Secretary of State’s review to evaluate whether the creation of such a defence would enable regulated bodies to improve the resilience of their network and information systems via enhanced vulnerability testing and research. New clause 18, tabled by the hon. Member for Henley and Thame, relates to the same important topic and would require the Secretary of State to review, and report to Parliament within 12 months of the Bill’s entering into law, whether amending the Computer Misuse Act could improve the resilience of network and information systems. Hon. Members will recall the insightful oral evidence of Professor John Child of the University of Birmingham. Professor Child made a clear and compelling case for the need to amend the Computer Misuse Act to provide statutory defences for legitimate cyber-research—sometimes called ethical hacking activities. Likewise, campaign groups, industry specialists and parliamentarians have all argued that the Computer Misuse Act, which was written before the modern internet, is no longer fit for purpose. At present, the Act fails to distinguish between malicious attackers and cyber professionals acting in the public interest, inadvertently criminalising a large proportion of research that UK cyber-security professionals can carry out to protect UK critical infrastructure and the UK’s technological ecosystem. This means that cyber-security professionals working to defend UK organisations from real-world threats risk prosecution. That has created a chilling effect—talent is being lost, investment is stifled and security gaps are going unidentified. If we are to have true UK cyber-resilience—not just among regulated sectors, but across businesses of all types and throughout society—we need a multifaceted approach. Industry and private sector-led initiatives will play a strong role in that. Professor Child made clear that countries that have implemented more favourable regimes, such as the US and Israel, are benefiting from increased cyber-resilience as a result of cyber-research activity. The Government have acknowledged that reform of the CMA is a pressing issue. Indeed, the Home Office has been reviewing that question for some time. Further, the Minister for Security, the hon. Member for Barnsley North (Dan Jarvis), highlighted the urgent need for changes to the law in this area in a recent speech, stating that Government have “heard the criticisms about the Computer Misuse Act, and how it can leave many cyber security experts feeling constrained in the activity that they can undertake.” He went on to say: “These researchers play an important role in increasing the resilience of UK systems, and securing them from…vulnerabilities. We shouldn’t be shutting these people out, we should be welcoming them and their work.” Yet the Home Office has brought forward no specific proposals for reform. Parliament is unlikely to legislate again in the cyber-security domain for some considerable time; we cannot afford to kick the can down the road on this vital issue any longer if we are to have a credible plan for whole-of-society cyber-resilience.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
That information is concerning. I entirely agree with my hon. Friend that information sharing is important when dealing with evolving threats.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
My hon. Friend is absolutely right.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
On a point of order, Ms McVey. I seek your advice with reference to the debate on clause 43, on 10 February. I draw Members’ attention to my question to the Minister in Hansard about parliamentary scrutiny of directions: “Even where they are redacted because of national security concerns, somebody, or some mechanism of Parliament, will be able to scrutinise them. Can the Minister confirm that?” –– [ Official Report, Cyber Security and Resilience (Network and Information Systems) Public Bill Committee, 10 February 2026; c. 212.] The Minister responded: “Yes.” We received a letter over the recess dated 19 February—we are very grateful to the Minister for writing to us—which states something slightly different: “The Government’s default position is that copies of directions will be laid in Parliament, to enable all parliamentarians to scrutinise the Government’s use of…powers. Where this is not possible for national security reasons, alternative options for scrutiny could be used, such as allowing for directions to be read in private reading rooms or briefing individual shadow ministers. As such, we are confident that alternative options are available for scrutiny when directions cannot be laid in Parliament for national security reasons.” “Will” is different from “could” and “are available”. Given that we have moved beyond the debate on clause 43, what options are there for the Minister to either clarify those remarks or correct the record?
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I thank my hon. Friend for his intervention, which is more for the Minister and the Government Whip’s benefit than mine. Properly established ISACs will not only increase real-time awareness of cyber-risks and mitigations, but could also alleviate some of the burden on regulators in terms of sector-specific intelligence analysis. Industry feedback and experience from the adoption of the Network and Information Systems Regulations 2018 indicate that sectoral regulators are unlikely to have the capacity to assist with intelligence sharing in relation to real-time cyber-risks. We know from the sectoral regulators’ oral evidence that building sufficient capacity for effective regulatory oversight is a challenge. Where we have models for sector-led and market-led good practice in hardening cyber-resilience, we should look at how it can be rolled out further. Seeing more of these organisations emerge could even lead to broader adoption beyond NIS-regulated areas to other industries. ISACs have the potential to become integral nodes in improving whole-of-society cyber-resilience, and it is an approach called for by many cyber industry stakeholders. I therefore commend new clause 4.
Published records only — not a full account of an MP’s work. How we work →