David Chadwick MP: speeches 2026
95 published records · newest first.
Speeches
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
One of the measures that the new clause would introduce is a requirement for board members to receive education. Clearly, it is necessary for boards to understand cyber-security risk, and the new clause is about putting that into legislation. Board accountability is the cornerstone of corporate governance. Corporate governance is one of the reasons for the Bill. We have seen drastic failures in corporate governance across the UK in numerous sectors. Financial services, historically, is one sector that corporate governance has completely failed in, yet the Conservatives continued to support it with tax cuts. All we are saying with our new clause is that boards need to be held accountable for the cyber-risk that they pose, and that making boards responsible for that obligation helps the cyber-security professionals responsible for securing those organisations to do their jobs properly. ISACA has 8,000 members. They are the people who will be carrying out this work. Surely, we should listen to them when they tell us that this is what they need. It was not just one organisation that told us that either. Boards have an obligation to oversee financial risk, for which they need financial literacy. Cyber-risk deserves the same treatment. Importantly, this would bring the UK into line with international best practice. The European Union’s NIS2 framework explicitly places cyber accountability at senior management level, and makes the same demands of board oversight in these areas. That is why it is confusing again to see the Government diverging from that framework without a clear explanation of why. It is not clear why the UK should be settling for less. Why have the Government taken that out?
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I beg to move, That the clause be read a Second time.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
In our previous sitting, the hon. Member for Runnymede and Weybridge set out clearly the cyber-threat posed by China, and argued that, through new clause 2, China should be explicitly recognised as a foreign power presenting a significant risk to the United Kingdom. He rightly highlighted the precedent in UK legislation for maintaining registers of hostile or high-risk state actors to protect national security. I agree that Parliament should be unequivocal in recognising the Chinese Communist party as a strategic cyber-threat, particularly given evidence of state-linked cyber-espionage, infrastructure compromise and the targeting of critical national infrastructure. We have seen data from the Cabinet Office last week indicating that the Government plan to drastically reduce the integrated security fund spending on domestic cyber and tech to counter cyber-attacks. It will be cut from £113.3 million to £95 million by 2028-29, which is a reduction of 16%. Domestic spending to counter Russian threats in the same period will incur a drop of more than 20%. Those reductions leave us dangerously exposed and are in direct opposition to the Government’s promises to support the UK’s national security priorities. New clause 2 offers the chance to identify and monitor state actors that pose a threat to UK cyber-security. The register must also reflect the evolving nature of cyber-risk. Threats do not arise solely from formally hostile states, but also from jurisdictions where hostile cyber-actors operate at scale, using digital infrastructure to target UK systems and citizens. We have seen that in countries such as India and Nigeria, where organised cyber-criminal networks have run sophisticated international operations against the UK, exploiting cloud services and telecommunications infrastructure. In India, law enforcement has dismantled major cyber-crime hubs linked to international targeting, including operations specifically affecting large numbers of British victims. In 2025, the National Crime Agency worked in partnership with India’s Central Bureau of Investigation to raid an organised crime group in Uttar Pradesh, which had targeted more than 100 UK citizens with pop-ups stating that their devices had been compromised, losing them more than £390,000. That is not only an unacceptable financial loss for our citizens, but a significant waste of resources. In Nigeria, long-established cyber-criminal networks continue to conduct large-scale digital fraud campaigns aimed at overseas targets including the United Kingdom. Interpol’s Operation Serengeti in 2025 tackled high-impact cyber-crimes in Nigeria and 17 other nations, arresting 1,209 suspects and recovering nearly $100 million that had been stolen through cyber-fraud. Although these states might not be hostile in a geopolitical sense, hostile cyber-actors operating within their borders are none the less inflicting sustained harm and placing heavy burdens on our cyber-defence and law enforcement resources. I support the aims of new clause 2, but urge Ministers to ensure that the framework is flexible enough to capture not only hostile states but jurisdictions that consistently serve as bases for large-scale hostile cyber-activity. Data from the Cabinet Office shows that integrated security fund spending on Russia is set to fall over 20% between 2026 and 2029, which shows that the Government are not taking threats from Russia, or other hostile nations, seriously enough.
- 24 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting) · Hansard source
More
I beg to move, That the clause be read a Second time. The purpose of new clause 10 is to ensure that regulatory authorities and regulated persons have adequate resources and capabilities to carry out their responsibilities. Fundamentally, this is a question of state capacity. Surely it is hard to disagree with that statement. We can pass legislation in this House, but if the regulators tasked with enforcing that legislation lack the resources and capabilities to fulfil their duties, and if the businesses subject to the new requirements lack clarity about what is required of them, the Bill will remain little more than words on a page. Cyber-resilience cannot be achieved through legislation alone, poor and weak though this piece of legislation is; it must be delivered by regulators with properly trained staff, clear guidance and sustained investment in enforcement and oversight. Without that foundation, even the strongest legal framework risks becoming ineffective. The new clause would create a vital statutory reality check. It would require the Secretary of State within one year of the Act coming into force to consult with regulators and regulated organisations, and report to Parliament on whether the regulatory system is equipped to function under the new rules. The new clause asks a simple but essential question: do the bodies responsible for protecting our critical digital infrastructure have the people, funding, tools and skills that they need to succeed? Laws work only if the people enforcing them have the time, money, expertise and systems to do so properly. The scale of the challenge is already clear. Research from ISC2 shows that 88% of organisations that have suffered cyber-incidents link those breaches directly to skills shortages. If regulators themselves face similar skills or operational shortages, enforcement will be slow, inconsistent and ultimately ineffective, and may leave businesses facing uncertainty about what is required of them. The new clause would help to ensure that issues are identified early and addressed proactively, rather than after a major cyber-security incident exposes weaknesses in our regulatory system. For this legislation to work, it requires fully funded and effective regulators. That is why I will press the new clause to a vote.
- 24 Feb 2026 · Andrew Mountbatten-Windsor · Hansard source
More
My hon. Friend will be aware that we are in the week of St David’s day, which is a terribly important day for all of us in Wales. In terms of accountability, she will be very aware of the long-standing stance that the Liberal Democrats have taken on the Crown Estate, which in Wales regrettably still has not been devolved. Its powers and funding have been devolved to Scotland, but not—
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
New clauses 8 and 9 would close a dangerous gap at the heart of the Government’s cyber-security strategy. Right now, the Bill creates a two-tier system. Private companies running critical national infrastructure face strict legal duties, enforcement and oversight, yet the very public institutions that hold our democracy together and protect our most vulnerable citizens are left outside statutory protection. Nowhere is that more alarming than with our local authorities. Indeed, that is where the Government’s approach diverges from some EU member states. For example, the Netherlands is applying its equivalent legislation to local authorities. When a council suffers a cyber-attack, it is not just an IT inconvenience; it means real life grinding to halt. Members of the Committee who have served on local authorities will be well aware that a cyber-attack hitting a local authority creates problems with welfare payments, housing services, processing benefits payments, accessing social care for the most vulnerable in our society and collecting bins. Those are crucial activities in the day-to-day life of our society and our democracy. A cyber-attack can leave families without support, vulnerable children without protection and elderly residents without care, yet the Minister has suggested that these services are not necessary to the day-to-day functioning of society. I disagree with that. We have already seen the consequences at Tewkesbury borough council, where a cyber-attack was so severe that it triggered a major incident and crippled core services. Likewise, the attack on Gloucester city council cost the taxpayer more than £1 million and put at risk some of the most sensitive information held on UK residents, particularly if one considers the nature of employment in Gloucestershire. The reporting from those attacks showed that local authorities, which are cash-strapped and struggling to make do as they are, had to divert staffing resources into addressing those incidents.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
The hon. Gentleman makes an important point. We cannot allow these services to be interrupted. He will be well aware of the impact that bins not being collected has on our streets. Councils are being targeted because they hold sensitive personal data and provide much-needed services to the most vulnerable in society, yet they are being left as soft targets, without statutory requirements and the ringfenced resources that accompany them. We cannot claim to be building a cyber-secure Britain while leaving the frontline of public services unprotected. Resilience must extend beyond councils. Our new clauses also ask that our political parties and electoral infrastructure are properly protected, because we know that hostile states and non-state actors are actively seeking to undermine democratic systems. An attack does not need to change an electoral result to be devastating; it need only cast doubt on the integrity of the count or prevent legitimate voters from casting their ballots. We know that trust, once lost, is extraordinarily hard to rebuild. The security of our elections is too important to be left to secondary legislation made at some future date. Finally, our new clauses would require the Government to bring critical manufacturing, food production and large-scale retail distribution into scope. When British companies such as JLR lose billions to cyber-incidents, or when national retailers such as Marks & Spencer are paralysed, it is not just a private commercial issue, but a blow to national economic security, and there is no economic security without cyber-security. The Minister will be aware that the ramifications of the JLR attack were felt across south Wales because of the link to the steel industry supply chain. Our neighbours in the European Union already recognise this issue through the NIS2 framework, which covers food production and transport manufacturing as essential sectors. The new clauses simply ask the Government to match that seriousness. At their heart, our new clauses are about ending the two-tier approach. We seek the Government’s recognition that councils, political parties, electoral infrastructure and core supply chains are just as critical to national resilience as power stations and data centres. A country is not secure if its public services, at any level, are exposed. Its elections are vulnerable, and its economy can be brought to a standstill by a single cyber-attack. These new clauses hope to close those gaps and make Britain safer.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
Amendment 27, which I move on behalf of my hon. Friend the Member for Henley and Thame, would give the Government the ability to remove, disable or modify hardware and software that could be used to infiltrate British national infrastructure, such as the cables underneath the now approved Chinese mega-embassy in Tower Hamlets. The Prime Minister’s greenlighting of the Chinese super-embassy in the heart of London is a grave mistake that presents an open door for the ramping up of Chinese espionage in our country. It sends a regrettable and shameful message to Hongkongers—many of whom have already been targeted, intimidated and coerced by the Chinese Communist party—that trade deals are being prioritised over their safety. The Government must take a robust stance with hostile states such as China.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
I beg to move amendment 27, in clause 43, page 66, line 11, at end insert— “(fa) a requirement to remove, disable or modify hardware, software or other facilities;” This amendment would enable the Secretary of State to issue directions to remove, disable or modify hardware, software or other facilities for national security purposes.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
I beg to move amendment 26, in clause 40, page 63, line 7, leave out “5” and insert “3”. This amendment would increase the frequency of the reports that must be published under Clause 40, from every five years to every three years.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
Amendment 26, tabled by my hon. Friend the Member for Henley and Thame, seeks to ensure that the Bill keeps pace with the reality that it seeks to regulate. In the world of cyber-security, five years is a lifetime. In the past five years, the size and scale of cyber-attacks has continued to advance at pace, and we can expect the next five years to be the same. In that context, waiting five years for the first formal parliamentary review of the Bill seems dangerous. It risks leaving us with a regulatory framework designed for the threats of yesterday and not tomorrow. The cyber-threat is real, evolving and urgent. The NCSC has reported that nationally significant cyber-incidents more than doubled in 2025 alone. That is why the amendment would change the reporting cycle to once every three years. That is a pragmatic timeline, which allows the Government to identify gaps and close them before they are exploited. The EU’s NIS2 directive explicitly mandates a review by the Commission every three years, and it is not clear why the Government have decided to diverge from that standard. Is it because they believe that the cyber-threat here is considerably less than the one facing European member states? It is simply not clear, which adds to the general sense of bewilderment about this provision. If our European neighbours are reviewing their cyber-security approach every three years, why are the UK Government content to wait for five?
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
Given the reassurances from the Minister, I beg to ask leave to withdraw the amendment. Amendment, by leave, withdrawn. Clause 43 ordered to stand part of the Bill. Clause 44 ordered to stand part of the Bill. Clause 45 Monitoring by regulatory authorities Question proposed , That the clause stand part of the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting) · Hansard source
More
I beg to ask leave to withdraw the amendment. Amendment , by leave, withdrawn . Clause 40 ordered to stand part of the Bill . Clause 41 Regulations under section 24 or Chapter 3 Question proposed, That the clause stand part of the Bill.
- 10 Feb 2026 · Topical Questions · Hansard source
More
T2. Green GEN Cymru was granted an Ofgem licence within days of this Government coming to power. Is the Secretary of State confident in the process that took place, and can he confirm how far it had reached under the previous Government?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
The hon. Member is quite right to say that American companies have captured most of the market that he is talking about, particularly the cloud providers. What does he think is stopping British cloud providers from getting a larger share of the market?
- 5 Feb 2026 · Water Company Executives: Undisclosed Payments · Hansard source
More
Welsh Water’s chief executive has one of the highest paid jobs in Wales at almost £900,000 a year, and the company is hiking basic pay to get around the Government’s crackdown on executive bonuses, despite being a not-for-profit. That is even though Welsh Water presides over some of the worst sewage dumping and leaks in the UK and sky-high price rises. Will the Minister look into companies trying to bypass the new regulations in that way and ensure that those loopholes are closed?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Surely, we cannot pass a cyber-security and resilience Bill that ignores a crime that affects thousands of people. We know that cyber-security criminals across the world attack individuals to enable themselves to get into systems. Families are losing life savings, and small businesses are shutting down because of this epidemic. The Government often treat fraud as a policing issue, but the amendment would establish that it should be regarded as a cyber-security issue that needs action at the national security level. By amending regulation 12(1) of the NIS regulations, we place a legal duty on digital providers to identify these vulnerabilities proactively. If we mandate that providers manage fraud risks before an incident occurs, we will reduce the number of victims and the devastation caused to livelihoods. We cannot claim to protect our digital economy while ignoring the billions of pounds lost to scams.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
I beg to move amendment 25, in clause 8, page 7, line 31, at the end insert— “(1A) In paragraph (1), after ‘risks’ insert ‘, including risks arising from fraud,’”. This amendment would explicitly include fraud as one of the risks to the security of network and information systems relevant digital service providers must identify and manage.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Currently, the law requires regulated persons to manage risks to the security of their systems. Amendment 28, tabled by the Liberal Democrats, explicitly inserts “risks arising from fraud” into that duty. It would make it clear that a system cannot be considered secure if it is easily exploited by scammers. Fraud should be considered a national security issue, and there is clearly a relationship between fraud and cyber-security. Scammers across the world are targeting British citizens. Elderly fraud victims in Dyfed-Powys lose £7,900 a day to a tidal wave of scams perpetrated by scammers from many countries across the world, notably Nigeria. UK-wide, in the first half of 2025 alone, criminals stole over £600 million through scams. Surely, we cannot pass a cyber-security and resilience Bill—
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Apologies for the preview.
- 4 Feb 2026 · Postal Services: Rural Areas · Hansard source
More
It is an honour to serve under your chairmanship, Mr Stringer. I commend the hon. Member for South Shropshire (Stuart Anderson) on securing this debate, and on his excellent speech. Last year, postal services became a source of real frustration, anxiety and, frankly, anger in Radnorshire. Across Brecon, Radnor and Cwm Tawe, and right across rural Wales, we saw serious problems in the run-up to Christmas. Parcels were marked as delivered but never arrived, items were left at farm gates, on main roads or in full view of passers-by, Christmas presents went missing, and essential items were delayed for days or even weeks, and then marked as lost. When things went wrong, people found it almost impossible to speak to a real human being to sort it out. I want to be clear that, in my opinion, those problems stem from the corporate leadership of Evri. The problem is a systemic one within their business model, and rural areas are feeling the consequences first and hardest. Constituents of mine in the Teme valley tell me that their experience with Evri was awful. One constituent told me that they “have never received a single Evri parcel on time, most never ever arrive, and those that do are weeks or months late.” My constituents tell me that they often pay extra for faster shipping, but they then have to spend significant time processing refunds and working with credit card companies to recover some of the lost money. A frustration for customers is that they often cannot choose their delivery company. It is chosen for them by the retailer they are buying from. When a parcel company performs badly, consumers are simply stuck with the consequences. Consumer bodies back that up, and companies like Evri consistently rank bottom for customer satisfaction, yet too often nothing seems to change. That is where regulation matters. There must be clear, enforceable service standards for parcel deliveries, including in rural areas, on safe delivery practices, accurate tracking and proper access to customer support when things go wrong. Consumers who have no choice over their courier should not be left navigating automated systems or vague updates when a parcel is lost or delayed. If companies repeatedly fail customers, especially in rural and hard-to-serve areas, there must be consequences—not just guidance or warm words, but real accountability. For many of my constituents, Evri’s failures have meant money lost, ruined Christmases, wasted time and a growing sense that rural communities are once again expected to put up with worse service. Rural Wales deserves reliability, respect and accountability, not excuses. I urge Ministers to take this issue seriously, and ensure that parcel delivery works for every part of the country, not just the easiest ones to serve.
- 4 Feb 2026 · Civil Service Pension Scheme: Administration · Hansard source
More
The hon. Lady is making an excellent speech, and we are all grateful for the opportunity to raise these cases. I have been contacted by a constituent who left the civil service in 1992 and, more than 30 years later, has still not received the pension that she is owed, despite providing proof of service from HMRC and making repeated transfer requests. Despite the fact that the civil service later located her superannuation file, the scheme continued to insist that no record existed. Does the hon. Lady agree that such cases show that the failure is not just delay but deep-rooted maladministration within our state, and that the Government must commit to ensuring people are paid the pensions that they are legally entitled to?
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Got it. The other question is about board-level responsibility. Numerous witnesses said that they would like to see more on board-level responsibility and people working within organisations, particularly chief information security officers, to strengthen their hands and make sure cyber-security measures are in place. What is your response to that? Kanishka Narayan: It is absolutely critical that boards take their responsibilities to the organisation and the consequences of being in a regulated sector very seriously. The scope of the Bill has been mentioned. The Secretary of State wrote to FTSE 350 businesses, as well as a range of small businesses, to make that point very clear. The cyber assessment framework has particular requirements for boards to take their cyber-security responsibilities seriously. In the course of implementing the Bill and in the secondary legislation process, we will look to ensure that specified security and resilience activities, including the possibility of specific responsibilities, are set out very clearly.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Thank you for joining us. Reporting of several recent cyber-attacks has one thing in common: there were often insufficient security measures in place. British Airways in 2018 is just one example. Reportedly, the average tenure of a chief information security officer is 18 months. From your perspective, what do CISOs need from the Bill to help strengthen their hand when they are saying to a board, “This is what I need to do to keep our organisation secure”? Richard Starnes: On what you say about the 18-month tenure, one of the problems is stress. A lot of CISOs are burning out and moving to companies that they consider to have boards that are more receptive to what they do for a living. Some companies get it. Some companies support the CISOs, and maybe have them reporting to a parallel to the CIO, or chief information officer. A big discussion among CISOs is that having a CISO reporting to a CIO is a conflict of interest. A CISO is essentially a governance position, so you wind up having to govern your boss, which I would submit is a bit of a challenge. How do we help CISOs? First, with stringent application of regulatory instruments. We should also look at or discuss the idea of having C-level or board-level executives specifically liable for not doing proper risk governance of cyber-security—that is something that I think needs to be discussed. Section 172 of the Companies Act 2006 states that you must act in the best interests of your company. In this day and age, I would submit that not addressing cyber-risk is a direct attack on your bottom line.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Thank you for joining us. You mentioned frauds. It is a fact that criminals across the world are targeting British citizens every day. In Dyfed-Powys, over £500,000 was lost to online fraud in 2023-24, and elderly victims are losing £7,900 a day to fraud. Clearly, these attacks are coming from all over the world. Interpol recently arrested over 800 members of a global criminal network based in Nigeria. From your perspective, how effectively are UK police forces currently able to work with international partners to investigate and prosecute overseas criminals? What additional support from the Government would most improve your ability to mitigate online fraud from overseas? DCS Andrew Gould: That is a really good question. The international jurisdiction challenge for us is huge. We know that is where most of the volumes are driven from, and obviously we do not have the powers to just go over and get hold of the people we would necessarily want to. You will not be surprised to hear that it really varies between jurisdictions. Some are a lot more keen to address some of the threats emanating from their countries than others. More countries are starting to treat this as more of a priority, but it can take years to investigate an organised crime group or a network, and it takes them seconds to commit the crime. It is a huge challenge. There are two things that we could do more of better—these are things that are in train already. If you think about the wealth of cyber-crime, online fraud and so on, all the data, and a lot of the skills and expertise to tackle that sit within the private sector, whereas in law enforcement, we have the law enforcement powers to take action to address some of it. With a recent pilot in the City funded by the Home Office, we have started to move beyond our traditional private sector partnerships. We are working with key existing partners—blockchain analytic companies or open-source intelligence companies—and we are effectively in an openly commercial relationship; we are paying them to undertake operational activity on our behalf. We are saying, “Company a, b or c, we want you to identify UK-based cyber-criminals, online fraudsters, money-laundering and opportunities for crypto-seizure under the Proceeds of Crime Act 2002”. They have the global datasets and the bigger picture; we have only a small piece of the puzzle. By working with them jointly on operations, they might bring a number of targets for us, and we can then develop that into operational activity using some of the other tools and techniques that we have. It is quite early days with that pilot, but the first investigation we did down in the south-east resulted in a seizure of about £40 million-worth of cryptocurrency. That is off a commercial contract that cost us a couple of hundred grand. There is potential for return on investment and impact as we scale it up. It is a capability that you can point at any area of online threat, not just cyber-crime and fraud, so there are some huge opportunities for it to really start to impact at scale. One of the other things we do in a much more automated and technical way—again funded by the Home Office—is the replacement of the Action Fraud system with the new Report Fraud system. That will, over the next year or so, start to ingest a lot of private sector datasets from financial institutions, open-source intelligence companies and the like, so we will have a much broader understanding of all those threats and we will also be able to engage in takedowns and disruptions in an automated way at scale, working with a lot of the communication service providers, banks and others. Instead of the traditional manual way we have always been doing a lot of that protection, we can, through partnerships, start doing it in a much more automated and effective way at scale. Over time, we will be able to design out and remove a lot of the volume you see impacting the UK public now. That is certainly the plan.
Published records only — not a full account of an MP’s work. How we work →