Bradley Thomas MP: speeches
234 published records · newest first.
Speeches
- 11 Feb 2026 · Local Government Finance · Hansard source
More
Will the Secretary of State give way?
- 11 Feb 2026 · Local Government Finance · Hansard source
More
I will not give way, because the Secretary of State would not give way to me. I will not give way and be lectured to by Labour MPs who are not upholding their promises. The Government stood on a manifesto to freeze council tax, knowing full well that they would not be able to deliver that. Worse still, last May, prior to the local elections, the Reform party stuffed leaflets through the doors of residents across Worcestershire and across the country pledging that it would cut council tax. Reform spoke about this DOGE—Department of Government Efficiency—programme for local government. It is interesting that not a single Reform Member of Parliament is here in the Chamber today to defend their record. Where is this DOGE programme? Why has it revealed nothing? Reform thought that it could turn the sofa upside down, give it a good shake and £100 million would fall out. Well, that did not happen. Instead, I can tell the House what has happened in Worcestershire. Since last May, the overspend by the Reform administration has been £100 million. As a result, it has come cap in hand to the Government for emergency funding and for a council tax rise way in excess of inflation and of the 5% threshold for a referendum.
- 11 Feb 2026 · Local Government Finance · Hansard source
More
I thank my hon. Friend and neighbour; he is far too generous. I was leader of Wychavon district council in south Worcestershire for five years, and we proudly froze council tax for five years consistently without cutting a single service. Local government is lean. It can be run efficiently and effectively without duping the taxpayer. But let us return to that dupe. The Reform administration on Worcestershire county council went cap in hand to the Government, and the Government have granted it emergency funding. They have agreed and, in effect, colluded with Reform. Two parties have agreed to put up council tax for residents when both had promised that they would not do so, and Worcestershire residents are paying the price. My message to the Minister is very clear: if we want to maintain trust and integrity in politics at all levels, it is important for such promises to be stuck to and abided by, or else not to be made in the first place. Most importantly of all, in the last 48 hours more than 1,100 Worcestershire residents have signed a petition opposing this increase. It is crucial that the issue goes to a referendum, and that the people of Worcestershire have their say.
- 11 Feb 2026 · Local Government Finance · Hansard source
More
I will keep my comments brief, and they will be focused on council tax. The reason they will be brief is that I was hoping to intervene earlier on the Secretary of State. He said that he did not want to dodge difficult topics and wanted to talk about promises, but he did not take an intervention from me, probably because he knew what was coming. I will talk about broken promises and about difficult topics. The primary one affecting my residents right now across Bromsgrove and the villages, as well as people across Worcestershire, is the Government’s collusion with Reform to hike council tax by a staggering 9%. That will be the highest council tax increase that Worcestershire county council has imposed on its residents. It will likely be the highest increase in council tax across the country this year, and it is reprehensible, because prior to the general election in 2024, the Labour party stood clearly on a manifesto that said it would freeze council tax. Labour Members know as well as I do that they have no will to deliver that.
- 11 Feb 2026 · Local Government Finance · Hansard source
More
Residents across the country knew ahead of the general election that the Prime Minister had made various very public pledges that the Labour party would freeze council tax should it come to office. If there is a mistake on my part and those words were not in the manifesto, I apologise for that, but—here I return to my point about trust in politics—if we want residents across the country to have faith in the political system, it is important for politicians to stand by their promises, whether they are written in a manifesto or uttered on television.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
It is a pleasure to serve under your chairmanship, Dr Murrison. When introducing new legislation, it is essential that those who fall under its new regulations be clearly identified and given adequate time to prepare for compliance. However, despite the aims of the Bill and the wish to avoid worsening a cyber-attack incident, the Bill still presents far too much ambiguity. It is right to recognise the cyber landscape as continuously evolving. There is no dispute that this terrain becomes increasingly complex each day, requiring a level of flexibility in legislation to ensure that it keeps pace. However, this desire to safeguard such adaptability, and the goal of future-proofing, must not come at the expense of the effectiveness of legislation in the present day. The powers afforded to the Secretary of State to change the classification of essential activity, and to bring new sectors into scope of the Bill at any time, undoubtedly create uncertainty for many sectors and cast a shadow over long-term compliance. To be clear, we want organisations to comply with this legislation. We want to improve national cyber-resilience, gather vital intelligence and restore public confidence in our security. Why, then, would there not be a significant effort to make these regulations as easy to apply as possible, rather than leaving thousands of businesses second-guessing whether they fall within scope, with the pressure of large financial penalties hanging over their heads? In addition, many will know that I am a firm supporter of parliamentary process. I support the notion that all legislation should receive the scrutiny it is due by the democratically elected Members of the House of Commons. That is why I believe the Bill must not only set out clearer guidelines for who is in scope, but require an official amendment, debated in the House, to permanently bring any new sectors into scope after the Bill has been passed. I understand that, in times of emergency, the longer process of House of Commons scrutiny may not always be possible. That is why the Secretary of State should have powers to bring in sectors necessary in an emergency temporarily into scope, with less imposing of non-compliance penalties until their inclusion is made permanent by the House. Such an approach would not only allow for the quick reactions that cyber-security demands, but respect parliamentary processes and safeguard against organisations’ being unaware that they had suddenly been brought into scope until they received a potentially financially ruinous penalty notice for non-compliance. Looking at the need for more definitive guidelines on who will be regulated under the Bill, we have already heard from numerous industry stakeholders that are unsure whether they, or other organisations in their sector, will fall within the mandatory scope. In addition, industry experts have publicly shared concerns about how far the net may be cast in some sectors, leading to the unintentional inclusion of organisations that are critical only to a single larger organisation, rather than to our national security, while ignoring other essential sectors altogether. Looking at recent cyber-attacks that have had a significant impact on our country, it is concerning that the definition of essential services may not include them within scope. While it is predicted that many of Jaguar Land Rover’s supply chains will be in scope, it has been publicly questioned whether it will be included. As the largest car manufacturer in the United Kingdom, it directly employs over 30,000 people across the UK and supports around 100,000 jobs indirectly. It is therefore no surprise that the cyber-attack it endured, estimated to have had a financial impact of over £1 billion, was significant to many, including more than 5,000 organisations impacted and many of my constituents, with JLR being one of the largest direct and indirect employers in the west midlands region. How, then, if a key aim of the Bill is to ensure that all essential services whose disruption would profoundly impact our nation in the event of a cyber-attack report all major incidents, can the vagueness of the definition of essential services be allowed to stand—especially when it creates a situation in which previous key victims are excluded? Of course, JLR is not the only victim where questions of inclusion remain. Also potentially falling outside the regulatory reach is Marks & Spencer, whose recent cyber-attack was another stark reminder of the rapidly advancing cyber-crimes scene and caused significant disruption, with costs estimated to run into the millions of pounds. Having met with M&S representatives recently, I had the opportunity to discuss their experience of enduring such an attack. Archie Norman, M&S chair, gave evidence to the Business and Trade Sub-Committee on Economic Security, Arms and Export Controls, where he said that “a growth economy” is “a cyber-resilient economy”. Having a cyber-resilient UK, and making the UK the safest place to do business, is a competitive advantage. I agree with that sentiment and firmly believe that increasing our cyber-resilience can only benefit our economy. It is imperative that we get this right. These cyber-threats are not going away; they are only going to get stronger and more technically advanced. We have seen that in the past year, with the National Cyber Security Centre reporting a 50% increase in British cyber-incidents deemed highly significant. Indeed, representatives of M&S told me that, at times, they found it much easier to get updates and information from the United States FBI than they did from our own authorities. We also know that foreign hostile states are becoming bolder in their actions against us. A few months ago—as a reason for introducing my ten-minute rule Bill, the Cyber Extortion and Ransomware (Reporting) Bill—I stated that research had revealed that 74% of UK IT leaders cited China and 71% cited Russia as their top cyber-security concerns. It is undisputable that last year’s espionage trials threw a harsh spotlight on the threatening scale of state-sponsored cyber-attacks. Improving our national cyber-resilience, and safeguarding all our infrastructure and essential services, including in the private sector, is vital in order to secure a prosperous economy and reinforce public confidence in our ability to defend ourselves against such threats.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
On the point about banding, can the Minister assure us that there will be consistency applied across regulators so that different events are not differentially penalised depending on the regulatory body? On the question of turnover and the financial penalty, can the Minister elaborate on how the figure was derived?
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I have two points for the Minister to address. First, could he clarify whether an organisation would face repercussions if a regulator believed in retrospect that notification should have been provided sooner? Secondly, on customer notification, can the Minister address the concern around striking the right balance between informing the customer and ensuring that the update that they receive is meaningful and not so vague that it causes further distress or worry?
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Can the Minister elaborate on how he will ensure that regulators have the capacity to cope with large-scale data reports?
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I have much sympathy with the hon. Gentleman’s arguments about the importance of local government, and I believe that it should be within scope of the Bill. Essential services are provided by councils on a day-to-day basis, but local councils are increasingly cash-strapped. Does he share my concern about the burden of compliance falling on councils, many of which differ in size and scale from their adjacent neighbours? They have differing degrees of IT infrastructure capability. We run the risk of increasing the compliance and regulatory burden on councils at a time when they may already have stretched budgets and lack the resource and capacity in the system to accommodate that additional burden.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I have two points for the Minister to address. First, can he address concerns around whether funds raised will be directly reinvested into improving cyber-security, rather than covering administrative overheads? Secondly, there is no specific reference to turnover thresholds, so how can the Minister be sure that a one-size-fits-all approach will not be used, causing many similar organisations to suffer financially?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Will the Minister give way?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
The risk and the threat from hostile states is plain to see. Does my hon. Friend have any sympathy for the ten-minute rule Bill that I introduced a few months ago on the Floor of the House? We need to strike a balance between the risk that bureaucratic administration poses to small businesses and the very real risk that cyber-attacks pose to the economy in general. The Government should have the private sector in scope and look at setting a threshold that does not become burdensome on smaller businesses. My proposal was for any company that turns over £25 million or more to be scope, in order to not bear down too heavily on small companies that would otherwise find the process, the risk and the burden of reporting too onerous.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Given the blurring of boundary lines between cyber-attacks and financial crime, I can see the compelling reasons why the amendment has been tabled, but does the shadow Minister agree and acknowledge that fraud detection often requires a different skillset from standard network security, so it is important to strike the right balance?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
What consideration has been given to the potential conflict between data centres’ contractual obligation regarding customer confidentiality and mandatory rapid reporting? What assurance can the Minister give us that data centres will ensure that the conflict does not impact their future business?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Does the shadow Minister agree that the Government should heed the message of Chris Dimitriadis, the chief global strategy officer at the Information Systems Audit and Control Association? He said: “The era when cyber regulation could focus solely on critical national infrastructure is over. Today, every major employer is part of the digital economy—and therefore part of the threat landscape.” Surely the Government should heed that message.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
On the growth of this industry, and with 78% of UK enterprises relying on cloud-based services, 96% of companies expected to use public cloud services, 35% of UK businesses outsourcing IT support and, as of last year, 63% of organisations planning to continue or increase their IT outsourcing over the next 12 months, does my hon. Friend the shadow Minister agree that greater consideration—or at least elaboration—must be given to the vulnerability of the supply chain of large load data centres?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
Does my right hon. Friend agree that the public are sick and tired of people who appear to fail upwards in public life, simply for the reason that they appear to move in the right circles?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
At the point immediately prior to Peter Mandelson’s appointment as ambassador, the UK had a respected ambassador to the United States already in Dame Karen Pierce. Given that fact, the known abhorrence of Jeffrey Epstein and the appalling previous judgment of Peter Mandelson, why did the Government still decide that, on balance, it was a risk worth taking to appoint paedophile-adjacent Peter Mandelson to the post of ambassador?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
Aside from the evident, persistent and consistent failures in the Prime Minister’s integrity, does this issue not raise massive questions about the hold over the Government and those at the top of the Labour party by someone whose name has been a byword for sleaze for the last two or three decades?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
Does my hon. Friend agree, particularly following her point about the writing being on the wall, that the Minister, when he wraps up on behalf of the Government, needs to quash any rumours that the Prime Minister is hunkered down in Downing Street and planning a reshuffle to stabilise a sinking ship?
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q What additional resources will you need in order to implement and enforce the requirements of the Bill? Ian Hulme: Again, to contrast the ICO’s position with that of other colleagues, we have a much larger sector, as it currently exists, and we will have a massively larger sector again in the future. We are also funded slightly differently. The ICO is grant in aid funded from Government, so we are dependent on Government support. To move from a reactive footing, which is our position at the moment—that is the Government’s guidance to competent authorities and to the ICO specifically—to a proactive footing with a much expanded sector, will need significant uplift in our skills and capability, as well as system development in order to register and ingest intelligence from MSPs and relevant digital service providers in the future. From our perspective at the ICO, we need significant support from DSIT so that we can transition into the new regulatory regime. It will ultimately be self-funding—it is a sustainable model—but we need continued support during the transition period.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q With regard to skills, given the acute shortage and the growth of this industry, what do you propose to ensure that the public sector is adequately resourced, given what will undoubtedly be a very lucrative private sector appeal for that talent? Kanishka Narayan: This is a great question. There are two things on my mind. One is that the Government have published a cyber action plan, the crux of which is to make sure that, from the point of view of understanding, principles, accountability and, ultimately, skills, there is significant capability in the public sector. The second thing to say is that we have a very broad-based plan on skills more generally across the cyber sector, public and private. For example, I am really proud of the fact that, through the CyberFirst programme, some—I think—415,000 students right across the country have been upskilled in cyber-security. It is deeply important that the public sector ensures that we are standing up to the test of hiring them and making the attraction of the sector clear to them as well. There is a broad-based plan and a specific one for the public sector in the Government context.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Do you think they should be within scope? Kanishka Narayan: Let me place the focus of this Bill in the global context. As we have heard, there is a range of legislative as well as non-legislative measures on cyber-security. It is deeply important that every organisation, whether in scope of the Bill or not, acts robustly, and we will look at that, not least through the cyber action plan, which I know industry welcomed earlier today and which we are looking forward to publishing very soon. The particular focus of this Bill is on essential services, the disruption of which would pose an imminent threat—for example, to life and to our economy—in the immediate context. For reasons that we can dive into, if you look at a market such as food supply, the diversity, competitive nature and alternative provision in that market are so obvious that to designate it as fitting the definitional scope I have just highlighted would not be an evidence-led way of engaging.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Would the cyber-attacks on JLR and M&S that took place last year be in the scope of this Bill? Kanishka Narayan: I am shy of making comments on specific incidents, but as a broad brush, clearly the food supply or automotive manufacturing sectors are not directly in scope of the Bill, for reasons I am very much happy to discuss.
Published records only — not a full account of an MP’s work. How we work →