Ben Spencer MP: speeches 2026

212 published records · newest first.

Speeches

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Natalie, I am going single out Ofcom, which has a lot on its plate at the moment, particularly when it comes to the implementation of the Online Safety Act 2023 and all its other duties. Are you set up to administer your duties under the Bill? Are your resources siloed, given Ofcom’s competing considerations, particularly over the next few years? Natalie Black: That is a great question, and I am not at all surprised that you have asked it, given everything that is going on at the moment. As well as being group director for infrastructure and connectivity, I am also the executive member of the board, sitting alongside our chief executive officer, so from first-hand experience I can say that Ofcom really recognises how fast technology is changing. I do not think there is another sector that is really at the forefront of change in this way, apart from the communications sector. There are a lot of benefits to being able to sit across all that, because many of the stakeholders and issues are the same, and our organisation is learning to evolve and adapt very quickly with the pace of change. That is why the Bill feels very much like a natural evolution of our responsibility in the security and resilience space. We already have substantial responsibilities under NIS and the Telecommunications (Security) Act 2021. We are taking on these additional responsibilities, particularly over data centres, but we already know some of the actors and issues. We are using our international team to understand the dynamics that are affecting the Online Safety Act, which will potentially materialise in the security and resilience world. As a collective leadership team, we look across these issues together. The real value comes from joining the dots. In the current environment, that is where you can make a real difference.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q What are the arguments against amending the CMA, and how would you deal with them? Professor John Child: There are obviously a number. It is always more comfortable when you have a beginning point of criminalisation. The argument to decriminalise in an environment where you want to protect against threats is sometimes a slightly unintuitive sell. Is the criminalisation that we have doing the necessary work in terms of actually fighting the threats? To some extent, yes, but it is limited. Is it doing harms? There is an argument to say that it is doing harms. This comes back to the point that was made earlier, which was perfectly sensible. When you speak to the CPS and others, their position as prosecutors is to say, “Very few people are being prosecuted, and we certainly don’t want to be prosecuting legitimate cyber-security experts, so there is no problem.” Admittedly, that means there is no problem in terms of actual criminalisation and prosecution, but that is the wrong problem. If you focus on the problem being the chilling effect of the existence of the criminalisation in the first place, you simply cannot solve that through prosecutorial discretion, and nor should you, when it comes to identifying what a wrong is that deserves to be criminalised. You certainly cannot resolve it through sentencing provisions. The only way that you can sensibly resolve this is either by changing the offence—that is very difficult, not least because, from a position of criminalisation, it might be where other civil jurisdictions begin—or by way of defence, which realistically is the best solve from the point we are at now. If you have a defence that can be specifically tailored for cyber-security and legitimate actors, you can build in reverse burdens of proof. You can build in objective standards of what is required in terms of public interest. The point here is that the worry is one of bad actors taking advantage. The reality is that that is very unlikely. The idea that the bad actors we identify within the system would be able to demonstrate how they are acting in the public best interest is almost ridiculous. Indeed, the prospect of better threat intelligence, better securities and so on provides more information and better information-sharing to the NCSC and others and actually leads to more potential for prosecution of nefarious actors rather than less. It is a more complicated story than we might like in terms of a standard case for changing the criminal law, but it is nevertheless an important one.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Do you have integration with your local primary care IT systems? For example, GPs have the old EMIS system and so on; is that integrated into your network? From your perspective, would that be a critical supplier that would need to be regulated? Stewart Whyte: Yes. There is a lot of information sharing between acute services and primary care via integrated systems. We send discharge letters and information directly to GP practices that then goes straight into the patient record with the GP. There is a lot of integration there, yes.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Thank you, Richard, for giving evidence this afternoon. I have a couple of questions. First, in your view, was the regulatory enforcement regime under NIS1 effective, and does the Bill, as drafted, tackle those challenges? Secondly, could you explain how information sharing and analysis centres improve cyber-resilience in the sectors in which they currently operate? Richard Starnes: The question about effectiveness is difficult to answer. There is the apparent effectiveness and the actual effectiveness. The reason I answer in that way is that you have regulators that are operating in environments where they may choose to not publicly disclose how they are regulating; it may be classified due to the nature of the company that was compromised, or who compromised the company. There may not necessarily be a public view of how much of that regulation is actually going on. That is understandable, but it has the natural downside of creating instances where somebody is being taken to task for not doing it correctly, but that is not exposed to the rest of the world. You do not know that it is happening, so the deterrent effect is not there. Information sharing and analysis centres started in the United States 20 or 25 years ago, when different companies were in the same boat. The first one that I was aware of was the Financial Services ISAC, which comprises large entities—banks, clearing houses and so on—that share intelligence about the types of attacks that they are receiving internationally. They may be competing with one another in their chosen businesses, but they are all in the same boat with regard to being attacked by whatever entities are attacking them. Those have been relatively good at helping develop defences for those industries.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Do you think there is a potential need for guardrails? Kanishka Narayan: I think the guardrails in the Bill are very important, absolutely. The Bill provides that, where there is an impact on organisations or regulators, there is an appropriate requirement for both deep consultation and an affirmative motion of the House. I think that is exactly where it ought to be, and I do not think anything short of that would be acceptable.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q I would also like to ask some questions on this definition of critical supplier. I know you will have heard the questions I had for the other panel. Is there a danger, in the way this Bill is approaching definitions of critical suppliers, that a supplier may end up being deemed critical solely by virtue of supplying to a critical industry, rather than the criticality of that particular supplier in the ecosystem? Chris Parker: Yes, absolutely. Carla Baker: Yes, completely. That is similar to my point, which was probably not explained well enough: how you are deemed critical should be more about your criticality to the entire ecosystem, not just to one organisation.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Notwithstanding other components to the criteria one may seek to use or will use, is there a danger that—although this is clearly not the intention in the drafting—through the back door, our entire economy ends up being in scope of this Bill? Carla Baker: I think that is part of the issue about not having clear criteria about how regulators will designate. That also means that different regulators will take different approaches, so we would welcome more clarity and early consultation around the criteria that will be used for the regulators to designate a critical dependency, which prevents having different regulatory approaches across the 12 different regulators, which we obviously do not want, and gives greater harmonisation and greater clarity for organisations to know, “Okay, I might be brought in, because those are the clear criteria the Government will be using.”

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Thank you for coming to give evidence this afternoon. I have two questions. First, what more could the Government be doing to make regulated sectors aware of the risks you have just laid out and what they can do to address them? Secondly, it has been reported recently that communications of senior Government aides were hacked by Chinese state affiliates between 2021 and 2024. In view of that threat to telecoms networks, what are the potential cyber-risks to communications infrastructure that you see arising from the intended location of China’s super-embassy in the City of London? Chung Ching Kwong: On the first question, about what can be done to help sectors understand the risks, education is paramount. At this point, we do not have a comprehensive understanding of what kind of risks state actors like China pose. We are very used to the idea that private entities are private entities, because that is how the UK system works; we do not see that organisations, entities or companies associated with China or the Chinese state are not independent actors as we would expect, or want to expect. There is a lot of awareness-raising to be done and guidance to be issued around how to deal with these actors. There is a lot of scholarly work that says that every part of Chinese society—overseas companies and so on—is a node of intelligence collection within the system of the CCP. Those things are very important when it comes to educating. Also, the burden of identifying what is a national security risk and what is not should not be put on small and medium-sized businesses, or even big companies, because they are not trained to understand what the risks are. If you are not someone specialising in the PLA and a lot of other things academically, it would be very difficult to have to deal with those things on a day-to-day basis and identify, “That’s a threat, and that’s a threat.” Sorry, what was the second question?

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Thank you for coming to give evidence this afternoon. I have a couple of questions. First, how can industry and cyber-security researchers collaborate more effectively to increase cyber-resilience in the network and information systems of regulated sectors? Secondly, and building on that, are there any model schemes or arrangements for reporting risks to affected companies that could incentivise legitimate research activities? Professor John Child: My specialism is in criminal law, so this is a bit of a side-step from a number of the pieces of evidence you have heard so far. Indeed, when it comes to the Bill, I will focus on—and the group I work for focuses on—the potential in complementary pieces of legislation, and particularly the Computer Misuse Act 1990, for criminalisation and the role of criminalisation in this field. I think that speaks directly to the first question, on effective collaboration. It is important to recognise in this field, where you have hostile actors and threats, that you have a process of potential criminalisation, which is obviously designed to be effective as a barrier. But the reality is that, where you have threats that are difficult to identify and mostly originating overseas, the actual potential for criminalisation and criminal prosecution is slight, and that is borne out in the statistics. The best way of protecting against threats is therefore very much through the use of our cyber-security expertise within the jurisdiction. When we think about pure numbers, and the 70,000-odd cyber-security private experts, compared with a matter of hundreds in the public sector, police and others, better collaboration is absolutely vital for effective resilience in the system. Yet what you have at the moment is a piece of legislation, the Computer Misuse Act, that—perfectly sensibly for 1990—went with a protective criminalisation across-the-board approach, whereby any unauthorised access becomes a criminal offence, without mechanisms to recognise a role for a private sector, because essentially there was not a private sector doing this kind of work at the time. When we think about potential collaboration, first and foremost for me—from a criminal law perspective—we should make sure we are not criminalising effective cyber-security. The reality is that, when we look at the current system, if any authorised access of any kind becomes a criminal offence, you are routinely criminalising engagement in legitimate cyber-security, which is a matter of course across the board. If you are encouraging those cyber-security experts to step back from those kinds of practices—which may make good sense—you are also lessening that level of protection and/or outsourcing to other jurisdictions or other cyber-security firms, with which you do not necessarily have that effective co-operation, reporting and so on. That is my perspective. Yes, you are absolutely right, but we now have mechanisms in place that actively disincentivise that close collaboration and professionalisation.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Presumably, all suppliers are in some way linked to your IT systems to some degree. I know the NHS sometimes uses faxes still, but we do not live in a world where things are done by paper and pen—it is all integrated into IT systems. Brian Miller: Sometimes, but sometimes not. I do not think we had any physical links with Synnovis, but it did work on our behalf. Emails might have been going back and forward, so although there were no physical connections, it was still important in terms of business email compromise and stuff like that—there was a kind of ancillary risk. Again, when things like that come up, we would look at it: do we have connections with a third party, a trusted partner or a local authority? If we do, what information do we send them and what information do we receive?

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Thanks for coming to give evidence this afternoon. I have two questions—one for each of you. Chris, from Fortinet’s perspective, what more do you think the Government can do to support SMEs to improve their cyber-resilience, while at the same time ensuring that the burden of regulation remains proportionate, particularly on smaller companies? Carla, from the Palo Alto Networks perspective, what are your views on the changes to the incident reporting regime under the Bill? Will the approach help or hinder regulators in identifying and responding to the most serious threats quickly? Chris Parker: I should point out that Carla is also co-chair of the cyber resilience committee, so you have both co-chairs here today. As large cyber companies, we are very proud of one thing that is pertinent to the sector that may not be clear to everybody outside. I have worked in many sectors, and this is the most collaborative—most of it unseen—and sharing sector in the world. It has to be, because cyber does not respect borders. When we go to the most vulnerable organisations, which one would expect cannot afford things and therefore there must be a function of price, such as SMEs—I was an SME owner in a previous life—that is very dear to us. With the technology that is available, what is really good news is that when people buy cyber-security for their small business—in the UK or anywhere in the world—they are actually buying the same technology; it is effectively just a different engine size in most cases. There are different phases of technology. There is the latest stuff that is coming in, which they may not be getting into yet. However, the first thing to say is that it is a very fair system, and pricing-wise, it is a very fair system indeed for SMEs. The second point is about making sure we are aware of the amount of free training going on across the world, and most of the vendors—the manufacturers—do that. Fortinet has a huge system of free training available for all people. What does that give? It is not just technical training for cyber-security staff; it is for ordinary people, including administrative workers and the people who are sometimes the ones who let the bad actor in. There are a lot of efforts. There is a human factor, as well as technological and commercial factors. The other thing I would like to mention is that the cyber resilience committee, which Carla and I are lucky to co-chair, is elected. We have elected quite a large proportion of SME members. There is also a separate committee run by techUK. You heard from Stuart McKean earlier today, and he is one of the co-chairs, or the vice chair, of that committee. Carla Baker: On incident reporting, as I am sure you are aware, the Bill states that organisations must report an incident if it is “likely to have an impact”. Our view, and I think that of techUK, is that the definition is far too broad. Anything that is likely to cause an impact could be a phishing email that an organisation has received. Organisations receive lots and lots of spoof emails. I will give an example. Palo Alto Networks is one of the largest pure-play cyber-security companies. Our security operations centre—the hub of our organisation—processes something like 90 billion alerts a day. That is just our organisation. Through analysis and automation, the number is whittled down to just over 20,000. Then, through technology and capabilities, it is further whittled down, so that we are analysing about 75 alerts. You can equate it to a car, for example. If you are driving and see a flashing yellow light, something is wrong. That is like 20,000 alerts. It is then whittled down to about 75, so we would potentially have to report up to 75 incidents per day, and that is just one organisation. There are a lot more. The burden on the regulator would be massive because there would be a lot of noise. It would struggle to ascertain what is the real problem—the high-risk incidents that impact the UK as a whole—and the noise would get in the way of that. We have come up with a suggestion, an amendment to the legislation, that would involve a more tiered approach. There would be a more measurable and proportionate reporting threshold, with three tiers. The first is an incident that causes material service disruption, affecting a core service, a critical customer or a significant portion of users. The second is unauthorised, persistent access to a system. The third is an incident that has compromised core security controls—that is, security systems. Having a threshold that is measurable and proportionate is easier for organisations to understand than referring to an incident that is “likely to have an impact”, because, as I said, a phishing email is likely to cause an impact if an organisation does not have the right security measures in place.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Does that also exist for local government? Does adult social care and so on have that integration too? Stewart Whyte: Yes, there is integration between ourselves and the local authorities.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q It was about China’s super-embassy in London. What cyber-security risks do you think that poses, given your experience and background? Chung Ching Kwong: There is not a lot of publicly available information on the sensitive cabling that is around the area, so I cannot confidently say what is really going to happen if they start to build the embassy and have such close contact with those cables. The limit of this Bill when it comes to the Chinese embassy is that it cannot mitigate the risks that are posed by this mega-embassy in the centre of London, because it regulates operators and not neighbours or any random building in the City. If the embassy uses passive interception technology to harvest data from local wi-fi or cellular networks, no UK water or energy company is breached. There is no breach if they are only pre-positioning there to collect information, instead of actually cutting off the cables, so when they do cut off the cables, it will be too late. There will be no report filed under the Bill, even if it is under the scope of the Bill when it comes to regulation. The threat in this case is environmental and really bypasses the Bill’s regulatory scope.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Do you not think that, as the Minister taking this through the Commons, you should have also had some of those meetings and consultations? Kanishka Narayan: I have had some meetings but, as the Minister in charge of this Bill, she has been very engaged with businesses, so I think that is fitting. We have obviously worked very closely together, as we normally do, in the course of co-ordinating across the two Chambers.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Thank you, Minister, for giving evidence this afternoon. I have a couple of questions. The first is about the definitions in the Bill, whether of MSPs or otherwise. All day long we have heard from representatives of different sectors of the industry, and pretty much everyone has talked about the importance of consultation on the definitions and when they are applied in secondary legislation. A certain amount of that stuff will be in primary legislation, so what consultation have you had with industry in setting up the definitions in the Bill in the first place? Kanishka Narayan: Thank you for the question on definitions. I have two things to say on that. First, observing the evidence today, it is interesting that there are views in both directions on pretty much every definitional question. For example, on the definition of “incident thresholds”, I heard an expert witness at the outset of the day say that it is in exactly the right place, precisely because it adds incidents that have the capability to have an impact, even if not a directness of impact, to cover pre-positioning threats. A subsequent witness said that they felt that that precise definitional point made it not a fitting definition. The starting point is that there is a particular intent behind the definitions used in the Bill, and I am looking forward to going through it clause by clause, but I am glad that some of those tensions have been surfaced. Secondly, in answer to your question on consultation, a number of the particular priority measures in the Bill were also consulted on under the previous Government. We have been engaging with industry and, in the course of implementation, the team has started setting up engagement with regulators and a whole programme of engagement with industry as well.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q Your evidence is really helpful. To help with my understanding, if you look across all the suppliers in your service, are there any that you would not consider to be critical, such that if you clicked your fingers now and one of them disappeared, it would not have a material impact on your ability to maintain patient safety and deliver healthcare? Irrespective of the debate about size, what suppliers do you not determine to be critical? Stewart Whyte: For me, it would be a slightly different assessment from Brian’s. We would be looking at anything where there is no processing of personal data. For me, that would not be a critical supplier from a data protection perspective. But there might be some other integration with NHS board systems that Brian might have concerns about. There is a crossover in terms of what we do, but my role is to look at how we manage data within the NHS. If there are suppliers where there is no involvement with identifiable data of either staff or patients, I would not see them as a critical supplier under this piece of legislation.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q I assume that you are referring to the previous Minister, who you took over from? Kanishka Narayan: I am referring to the Minister for Digital Economy, who is in the other place.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q Thank you for giving evidence this morning. The Bill would not have prevented recent attacks on high-profile parts of UK industry such as Co-op, Marks and Sparks, and Jaguar Land Rover. What more do you think can be done to mitigate the risk to jobs, supply chains and the UK economy from further large-scale cyber-attacks against out-of-scope companies? My second question is a bit more technical. Do you consider that the definition in the Bill of a managed service provider is sufficiently clear and certain for businesses to understand whether they are in scope or out of scope of the Bill? Dr Sanjana Mehta: I appear before the Committee today on behalf of ISC2, which is the world’s largest not-for-profit membership association for cyber-security professionals. We have 265,000 members around the world and 10,000-plus members in the UK. On your question about sectoral scope, our central message is that we welcome the introduction of the Bill and we believe that it will go a long way towards improving the cyber-resilience of UK plc. Yes, there are certain sectors that are outside the scope of the Bill, and we believe that there are a number of non-legislative measures that could be used to enhance the cyber-security of other industries and parts of the sector. In particular, the forthcoming national cyber action plan should be used as a delivery vehicle for improving the resilience of UK plc as a whole. On the previous panel, I think Jen mentioned that there are voluntary codes of practice. As an organisation, we have piloted the code of practice for cyber governance, and we have signed up to the ambassadors scheme for the code of practice for secure software development. We think that the upcoming national cyber action plan can further encourage the uptake of such schemes and frameworks. Most importantly, we call upon Government to focus on skills development as a non-legislative measure, because ultimately that will be the key enabler of success, whether it is for organisations that are within or outside the scope of the Bill.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q Thank you for coming to speak to us this morning. I have a different question for each of you, so I will rattle them off and ask you to go through them. Starting with Ben from Darktrace, how are developing and emerging technologies such as AI and post-quantum crypto changing the nature of cyber-security threats? Do you think the Bill responds adequately to that changing threat landscape? Moving on to Matt from Cisco, what further guidance and consultation from the Government and the Information Commissioner is needed for MSPs to comply effectively with their obligations under the Bill? Chris from NCC Group, the National Audit Office report last year highlighted lots of serious deficiencies in Government cyber-resilience. Do you think the cyber action plan goes far enough? How can Government Departments be overseen and held to account in a way that will deliver meaningful improvements in cyber-resilience? Finally, Ian from Amazon, a core feature of your business model is extensive exposure to supply chain partners. Do you think that the designation of critical suppliers by regulators under the Bill is the correct approach? What further consultation is needed to make sure that that is proportionate, prioritises the most critical suppliers and, crucially, gives a degree of certainty, whether legal or financial? Ben Lyons: AI is significantly changing cyber-security. You can think about it at three levels: first, the way in which attackers are using AI to mount cyber-attacks; secondly, the need to secure AI systems and AI within companies and organisations; and thirdly, the question of how AI is changing cyber-security on the defensive side. In brief, we see significant use of AI by attackers. Today, we are releasing the results of a survey in which 73% of surveyed security professionals say that AI-powered threats are having a significant impact on their organisation. These are things like phishing, reconnaissance, and lowering the barriers to being able to launch attacks and review more targets more effectively. Last month, the chief executive officer of Anthropic, which is one of the main frontier AI labs, warned that he sees AI-led cyber-attacks as potentially being the main way in which cyber-attacks are conducted in the future. At the level of the enterprise, you have a challenge of how you secure the enterprise, in terms of not only developing and deploying AI, but visibility of AI used in an organisation. We are certainly seeing AI transform how cyber-security vendors and organisations manage the threat: they have greater visibility, can detect threats more quickly and the like. On how the Bill responds to that, one positive in its approach is that it is setting out an agile, outcomes-based approach that means that the regulatory regime can be capable of evolving as the threat evolves. It is sensible not to talk about AI in depth on the face of the Bill, but through mechanisms such as the code of practice, it will be possible for expectations to evolve over time as the threat and the technology mature.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q The issues about complexity and how loosely the Bill is drafted have come up quite a few times, and you have given good evidence regarding your concerns. What cost to business do you anticipate if the Bill stays so loose, with so much left to secondary legislation? Jill Broom: There is probably a broader point around legal certainty, which is not given on the face of the Bill. Some of our members have highlighted language that could create some pretty significant legal jeopardy for regulated entities. The Bill needs to go a bit further. It could and should do more to provide some legal certainty, because the cost to companies could be quite significant. To the point on consistency across regulators and things like that, we need more frameworks around how that is going to work. Leaving all the detail to secondary legislation is what makes it slightly difficult to examine what is on the face of the Bill, so making sure that everything is consulted on in a mandatory and meaningful way will be important.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q Thank you, Jen and David, for coming to give evidence to us morning. Two questions. First, one to you, Jen. Lots of UK corporations have been the subject of recent major cyber-attacks, such as Jaguar Land Rover and M&S. Under the Bill as drafted, these remain outside the scope of the regulation. In your view, what is the best way to mitigate the risk to the economy, jobs and supply chains of further cyber-attacks of that scale to these important out-of-scope businesses? Secondly, and linked to that: Mr Cook, what lessons have you learnt from assisting clients with the implementation of NIS2—the second network and information systems directive—on the need for certainty in legislation? What do you think will be the most challenging areas of business to implement this Bill? Jen Ellis: There is a thing that you always hear people say in the cyber-security industry which is, “There are no silver bullets”. There is no quick fix or one easy thing, and that definitely applies when looking at policy as well. I cannot give you a nice, easy, pat answer to how we solve the problem of attacks like the ones we saw last year. What I can say is that, looking at the Cyber Security and Resilience Bill specifically, I think it could include companies above a certain size or impact to the UK economy. The Bill currently goes sector by sector— which makes lots of sense, to focus on essential services—but I think we could say there is another bucket where organisations beyond a certain level of impact on the economy would also be covered. That could be something like the FTSE350. Including those might be one way to go about it, but it is worth noting that it would not simply solve the problem because the problem is complex and multi-faceted, and this is just one piece of legislation. David Cook: With respect to NIS2, that is an example of a whole suite of laws that have come in across the European Union—the Digital Decade law; I think there is something like 10 or 15 of these new laws. They do all sorts of different things, and NIS2 sits within that. NIS2 is the reform of the NIS directive, which is the current state of play in UK law. NIS2 gives certainty and definition, by way of the legislation itself and then the implementing legislation, which means that organisations have had a run-up at the issue and a wholesale governance programme, which takes a number of years, but they know where they are headed, because it is a fixed point in the distance, on the horizon. The Bill we are talking about today has the same framework as a base. The plan then is that secondary legislation can be used in a much more agile way to introduce changes quickly, in the light of the moving parts within the geopolitical ecosystem outside the walls. For global organisations with governance that spans jurisdictions, a lack of certainty is unhelpful. Understanding where they need to get to often requires a multi-year programme of reform. I can see the benefits of having an agile, flexible system, but organisations—especially global ones, which are the sort within the scope of this Bill—need time to prepare, recruit people, get the skillset in place, and understand where they need to get to. That fixed future point needs to be defined.

  • 27 Jan 2026 · Medical Training (Prioritisation) Bill · Hansard source
    More

    As always, Mrs Cummins, it is a pleasure to serve under your chairmanship. I rise to speak to new clause 2, which stands in my name and is supported by many other Conservative Members. I declare again that I am now a non-practising doctor and my wife is a doctor. I believe that ambition should be encouraged, and success should be dependent on the talent and hard work of the individual. However, in a vocation where we really want to encourage and support the brightest and the best, the signal being beamed out by the NHS and its various arms and quangos is unfortunately quite different. We have already seen this over the years in how the NHS treats competence and excellence among doctors—someone could be the best doctor in the world and be treated exactly the same as someone who is just about competent. No other operation would approach employment, and celebrating and supporting success, in that way. I do not think, though, that I have ever seen as egregious and extreme an example of completely ignoring talent and merit as the preference informed allocation system. The shadow Minister, my hon. Friend the Member for Sleaford and North Hykeham (Dr Johnson), has laid out some of the details behind that system, but I encourage Members across the Committee to read about how preference informed allocation works—about the soulless, computerised, algorithmic method by which it allocates human beings a random number. That random number is then the sum total of those people’s dreams, hopes and ambitions when it comes to placements as they take their first steps into their medical career. To me, PIA looks better suited to the dystopian sci-fi programmes that I enjoy watching—better suited to “Logan’s Run” or “The Prisoner”, in which people are allocated numbers. It is not the way that we should be treating people in this country, and it is outrageous that such a system has been brought into force. We in this House should stand up for merit, and I really hope the Minister will affirm from the Dispatch Box today that the Government will dismantle this awful scheme.

  • 27 Jan 2026 · Medical Training (Prioritisation) Bill · Hansard source
    More

    Will the Minister give way?

  • 27 Jan 2026 · Medical Training (Prioritisation) Bill · Hansard source
    More

    I will start with what is now a traditional declaration: I am a non-practising doctor and my wife is a doctor. I thank the Secretary of State for his comments, and for thinking through the content and merits of my new clause 2, on allocation based on merit. I hope that, as the Bill proceeds through this place and the other place, he continues to focus on that, because it is a very important point. For my Second Reading speech, I am not going to focus on the details of new clause 2—I will hold that back for Committee. Instead, I want to make some general comments. In a sense, the Bill treats the symptoms of what has been happening in the medical workforce. I do not think it is a cure for the fundamental disease or the problems we have had over the years, which are in part down to a creeping de-professionalisation of the medical profession. I also think they are down to the way we have approached doctors’ appointments to placements, and how we assess their skills and CVs, and how that then leads to different appointments and places. Doctors are thrown from pillar to post, subject to the whims of a computer or a training programme. It has been shown time and again that one of the most important things in people’s eyes, or at least what gives most work satisfaction, is autonomy. Unfortunately, we have sleepwalked into a situation, in pursuit of a weird type of fairness in the allocation of jobs, that works towards equality of outcome as opposed to equality of opportunity. Doctors have found themselves unable to compete or have control over their lives. Where they are allocated to their foundation school or their specialty training has a real, material impact. Crucially, within allocations, the geographical regions are huge. That means uprooting: moving your family and your social network. In the training scheme there really is no power that a doctor can exert in terms of choice or preference. My understanding—I am a creature of the Nursing and Midwifery Council and the Medical Training Application Service, when I was coming through and applying for posts—is that we just used to let doctors competitively apply for different posts and put together a sort of portfolio CV. That has all changed. There is now the allocation to training programme schemes and national contracts, which is something I have been campaigning about for quite some time. Do not get me wrong: I think the way the BMA has behaved is absolutely appalling. I categorically and unreservedly condemn the approach that it has taken, and not just under this Government but under previous Governments over various disputes concerning junior doctors. But the fact that doctors have found themselves in a situation where they need to have a militant trade union is a consequence of the training schemes, programmes and national contracts not treating doctors as professionals when it comes to applying for jobs. It also means that the training providers, the trusts and the integrated care systems, cannot provide options that doctors might want to compete for. They cannot say, “Well, we’re a really good research unit, so we’re going to have an offering that pursues a certain type of doctor who wants to go down the academic pathway.” We do not have trusts or regions that can say, “Actually, this is an area where there is quite a lot of social and economic deprivation, so we want doctors who are interested in certain specialties.” For all sorts of different reasons, there are parts of the country that are oversubscribed and parts that are undersubscribed. We cannot use what we use in every other walk of life, which is changing remuneration to encourage people to go to other places. We cannot say, “You know what? Let’s look at flexible working arrangements.” As part of my medical school rotations, I was in Barnstaple. I can only imagine that if the trust for Barnstaple had recruitment challenges—I do not know if it does or does not—then it could look at whether people are into surfing or ensuring they could get involved in other activities outside of medicine. Dare I say, as a former doctor, that medicine is important but there are more important things than people’s careers, in particular their work-life balance. We have a system that does not enable that to happen. The behaviour of the BMA is, in a sense, a consequence of dismantling the normal human experience in the approach to the selection and allocation of jobs. That has real consequences locally. Ashford and St Peter’s, my local trust, struggles to recruit because of the proximity to London, which has London weighting. Since we are on the border of London, to look at it purely financially—if that is the main priority—it makes more sense to pop into London and work than it does being employed in my area. Runnymede and Weybridge, by the way, has house prices and a cost of living that are equal to a big chunk of London, but there is no approach to regionalisation. I am really glad that the Secretary of State is in his place to hear my contribution. I will say to him something that I have said to many previous Secretaries of State. When he is in those difficult negotiations with the BMA and hears from doctors about the workforce experience challenges that they have, would it not be better if we trusted doctors—and, for that matter, anyone who is subject to a national contract—to make decisions for their own lives, and that we devolve decision around pay and terms and conditions to some form of regional unit? For medicine, the obvious solution would be the integrated care systems, but there could be different solutions and ways of approaching it. I think ICS devolution would make the most sense, but there are other opportunities to do it. That way, it moves from the Government essentially getting stuck in the middle of doctors, who are making difficult decisions about their careers and having to balance and judge different T&Cs of work, and the employers, which are different NHS trusts, being unable to use the normal mechanism that any other employer would use to recruit and incentivise people. If we do not do that, unfortunately the consequence is a Bill like the one we are debating: ever-increasing state intervention to try, in the absence of a market system, to impose a command economy. The Secretary will have seen the issues dealing with local doctor prices. The fact that we have struggled with high locum payments for so long is because we do not allow the doctor employment market to resolve itself for adjustments in contracts. The system would save a huge amount of money overall if, rather than having a huge amount of money going to locums and a national contract system for doctors, we let the market sort it out. I will support the Bill, but I see it more as palliation than the definitive treatment that we need to solve the workforce problems for the NHS going forward.

  • 22 Jan 2026 · Local Government Reorganisation · Hansard source
    More

    I support unitarisation and the efficiency savings it brings, but may I caution the Secretary of State a little on his language? A lot of the waste he is talking about is people’s jobs. Many hard-working council workers, who have huge uncertainty about what will happen to them over the next couple of years, will be concerned to hear that sort of language used as we discuss this in the Chamber. What support is he giving local authorities to help those council workers find new jobs once the LGR process is complete?

Published records only — not a full account of an MP’s work. How we work →