Emily Darlington MP: speeches

118 published records · newest first.

Speeches

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q I have a question for Ian Hulme. In your role at the ICO, you are clearly looking at data security. Data is obviously one of the main goals of cyber-attacks. Data issues cut across every sector, and you are looking at a really broad sector of data, from individual identifiers to names, addresses, bank accounts or whatever it might be. This could happen in any sector. How does the Bill give you additional powers to take action, particularly on those co-ordinated through AI or foreign actors, and do you think it is sufficient for what you feel we will be facing in the next five years? Ian Hulme : We need to think about this as essentially two different regimes. The requirements under data protection legislation to report a data breach are well established, and we have teams, systems and processes that manage all that. There are some notable cases that have been in the public domain in recent months where we have levied fines against organisations for data breaches. The first thing to realise is that we are still talking about only quite a small sub-sector—digital service providers, including cloud computing service providers, online marketplaces, search engines and, when they are eventually brought into scope, MSPs. A lot of MSPs will provide services for a lot of data controllers so, as I explained, if you have the resilience and security of information networks, that should help to make data more secure in the future.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q I note your interest in how the Bill will affect smaller businesses. There is not much detail in the Bill, but how do you think the code of practice could create an environment that lifts everyone’s security up without prescribing too great a burden? Richard Starnes: You just stepped on one of my soapbox issues. I would like to see the code of practice become part of the annual Companies House registrations for every registered company. To me, this is an attestation that, “We understand cyber-security, we’ve had it put in front of us, and we have to address it in some way.” One of the biggest problems, which Andy talked about earlier, is that we have all these wonderful things that the Government are doing with regard to cyber-security, down to the micro-level companies, but there are 5.5 million companies in the United Kingdom that are not enterprise-level companies, and the vast majority of them have 25 employees or fewer. How do we get to these people and say, “This is important. You need to look at this”? This is a societal issue. The code of practice and having it registered through Companies House are the way to do that. We need to start small and move big. Only 3% of businesses are involved in Cyber Essentials, which is just that: the essentials. It is the baseline, so we need to start there.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
    More

    Q I want to move from software to hardware that is particularly vulnerable to potential cyber-attack, particularly from the integration of Chinese tech into SIPs, possibly making them vulnerable to cyber-attack by someone who knows the code into those bits of hardware. Should we be doing more to protect against that vulnerability? Should that be covered by the Bill? Chung Ching Kwong: It should definitely be covered by the Bill, because if we are not regulating to protect hardware as well, we will get hardware that is already embedded with, for example, an opcode attack. Examples in the context of China include the Lenovo Superfish scandal in 2015, in which originally implemented ad software had hijacked the https certificate, which is there to protect your communication with the website, so that nobody sees what activity is happening between you and the website. Having that Superfish injection made that communication transparent. That was done before the product even came out of the factory. This is not a problem that a software solution can fix. If you were sourcing a Lenovo laptop, for example, the laptop, upon arrival, would be a security breach, and a privacy breach in that sense. We should definitely take it a step further and regulate hardware as well, because a lot of the time that is what state-sponsored attacks target as an attack surface.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q I want to go back to basics and get a bit of insight from you. What cyber risks are businesses currently facing, and how do you feel the Bill addresses those risks? David Cook: The original NIS regulations came out of a directive from 2016, so this is 10 years old now, and the world changes quickly, especially when it comes to technology. Not only is this supply chain vulnerability systemic, but it causes a significant risk to UK and global businesses. Ransomware groups, threat actors or cyber-criminals—however you want to badge that—are looking for a one-to-many model. Rather than going after each organisation piecemeal, if they can find a route through one organisation that leads to millions, they will always follow it. At the moment, they are out of scope. The reality is that those organisations, which are global in nature, often do not pay due regard to UK law because they are acting all over the world and we are one of many jurisdictions. They are the threat vector that is allowing an attack into an organisation, but it then sits with the organisations that are attacked to deal with the fallout. Often, although they do not get away scot-free, they are outside legislative scrutiny and can carry on operating as they did before. That causes a vulnerability. The one-to-many attack route is a vulnerability, and at the moment the law is lacking in how it is equipped to deal with the fallout. Jen Ellis: In terms of what the landscape looks like, our dialogue often has a huge focus on cyber-crime and we look a lot at data protection and that kind of thing. Last year, we saw the impact of disruptive attacks, but in the past few years we have also heard a lot more about state-sponsored attacks. I do not know how familiar everyone in the room is with Volt Typhoon and Salt Typhoon; they were widespread nation-state attacks that were uncovered in the US. We are not immune to such attacks; we could just as easily fall victim to them. We should take the discovery of Volt Typhoon as a massive wake-up call to the fact that although we are aware of the challenge, we are not moving fast enough to address it. Volt Typhoon particularly targeted US critical infrastructure, with a view to being able to massively disrupt it at scale should a reason to do so arise. We cannot have that level of disruption across our society; the impacts would be catastrophic. Part of what NIS is doing and what the CSRB is looking to do is to take NIS and update it to make sure that it is covering the relevant things, but I also hope that we will see a new level of urgency and an understanding that the risks are very prevalent and are coming from different sources with all sorts of different motivations. There is huge complexity, which David has spoken to, around the supply chain. We really need to see the critical infrastructure and the core service providers becoming hugely more vigilant and taking their role as providers of a critical service very seriously when it comes to security. They need to think about what they are doing to be part of the solution and to harden and protect the UK against outside interference. David Cook: By way of example, NIS1 talks about reporting to the regulator if there is a significant impact. What we are seeing with some of the attacks that Jen has spoken about is pre-positioning, whereby a criminal or a threat actor sits on the network and the environment and waits for the day when they are going to push the big red button and cause an attack. That is outside NIS1: if that sort of issue were identified, it would not be reportable to the regulator. The regulator would therefore not have any visibility of it. NIS2 and the Bill talk about something being identified that is caused by or is capable of causing severe operational disruption. It widens the ambit of visibility and allows the UK state, as well as regulators, to understand what is going in the environment more broadly, because if there are trends—if a number of organisations report to a regulator that they have found that pre-positioning—they know that a malicious actor is planning something. The footprints are there.

  • 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
    More

    Q A huge thank you to the panel. Many of my colleagues have already asked the question, so I appreciate you talking about the futureproofing in quantum, the international regulatory environment and the use of standards alongside regulation to drive up quality. You all have a huge amount of UK clients, and I want to ask you about how good cyber culture gets embedded, and what the role of the Bill is within that. To pick up on Ben’s point around the security by design within his own firm, do you think that is well understood among your colleagues in the UK? How do we get the balance right between what is in the regulation and what should be done through a standards model, working with the British Standards Institution and others? Dr Ian Levy: The previous set of witnesses talked about board responsibility around cyber-security. In my experience, whether a board is engaged or not is a proxy indicator for whether they are looking at risk management properly, and you cannot change corporate culture through regulation—not quickly. There is something to be done around incentives to ensure that companies are really looking at their responsibilities across cyber-security. As the previous panellists have said, this is not just a technical thing. One of the things that is difficult to reconcile in my head—and always has been—is trying to levy national security requirements on companies that are not set up to do that. In this case I am not talking about Amazon Web Services, because AWS invests hugely in security. We have a default design principle around ensuring that the services are secure and private by design. But something to consider for the Bill is not accidentally putting national security requirements on those entities that cannot possibly meet them. When I was in government, in the past we accidentally required tiny entities, which could not possibly do so, to defend themselves against the Russians in cyber-space. If you translate that to any other domain—for example, saying that a 10-person company should defend itself against Russian missiles—it is insane, yet we do it in cyber-space. Part of the flow-down requirements that we see for contracting, when there is a Bill like this one, ends up putting those national security requirements on inappropriate entities. I really think we need to be careful how we manage that. Matt Houlihan: Can I make two very quick points?

  • 14 Jan 2026 · Engagements · Hansard source
    More

    Q9. If reports are correct, Elon Musk has climbed down today under pressure from this Government. Let’s be clear: stripping women naked without consent in real life or online is abuse. However, we do not know whether to trust what X says today, and this is not just happening on X. Will the Prime Minister join me and men and women across this House and across our nation to say to any app or AI company that we will not tolerate any abuse of men, women or children in this country and that we will act on enforcement?

  • 12 Jan 2026 · Social Media: Non-consensual Sexual Deepfakes · Hansard source
    More

    I thank the Secretary of State for her absolutely clear message that what X is doing, through the use of Grok, is illegal. That is as much the platform’s responsibility as it is the user’s. I am afraid that there is less confidence in Ofcom’s ability to enforce the Online Safety Act as it stands, or in the improvements being made. Does she agree with the many people across the country who believe that we need to see real action from Ofcom by the end of this week, or we will judge Ofcom’s leadership as failing the British public?

  • 7 Jan 2026 · Ukraine and Wider Operational Update · Hansard source
    More

    I thank the Secretary of State and the Prime Minister for their leadership on defending Ukraine not just in wartime but in peacetime, which will really reassure the many Ukrainian families who have sought refuge in Milton Keynes and across the UK. I would like to ask the Secretary of State’s advice. It is clear that Russia is challenging not just Ukraine, but the UK. It is carrying out incursions into our airspace and our waters, using cyber-attacks to undermine us and using social media to undermine our democracy. What advice would the Secretary of State give the British public on creating vigilance against the Russian attacks we are seeing increasing, over and over, on the UK?

  • 7 Jan 2026 · Bletchley Railway Station: Eastern Entrance · Hansard source
    More

    My hon. Friend and constituency neighbour is making a fantastic speech and a good case for the eastern entrance. It is a case that we have made for many years and that was promised by the previous Government—the previous MP even claimed that £6 million was set aside—yet it is another broken promise by a Conservative MP and a Conservative Government. Does my hon. Friend agree that the Conservatives have consistently let down Bletchley and have not seen the potential of the place and the people, which he demonstrates in his work?

  • 7 Jan 2026 · Bletchley Railway Station: Eastern Entrance · Hansard source
    More

    I thank the Minister for his commitment to East West Rail, which the Labour-run city council in Milton Keynes and the three Labour MPs for the area have been fully behind. Can he clarify that, alongside the commitment to amalgamate Woburn Sands and Bow Brickhill stations in my constituency is a commitment for the two bridges that are then needed to ensure continued access to housing and key industries, such as Red Bull Racing?

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I welcome the Bill and the cyber action plan for public services, which was published today. As we have heard from right hon. and hon. Members’ many great speeches today, this is so important to the UK economy and public. Despite being one of the smaller countries in the world, we are still one of the biggest targets for cyber-attacks. In the past 12 months, there has been some good news: only four in 10 businesses and three in 10 charities have had cyber-security breaches—the figures are down on the previous year. However, there has been a huge increase in nationally significant cyber-incidents, which have more than doubled in the past year, including the malicious cyber-attacks on critical infrastructure by Russia and China. These matters are important to companies based in Milton Keynes Central, where one in three jobs are in technology. Milton Keynes is a leader in the development of AI and tech services, including in legal services, financial services and autonomous vehicles. Those companies have experienced cyber-attacks, so the Bill is very welcome. The difficulty is that it misses a huge portion of the discussion, and Ministers have somewhat neglected to mention sovereign technology in their comments or in the strategy. I hope that they will do so in the wind-up. One role of sovereign technology is to fight cyber-crime. There are many definitions of sovereign technology, so what does it actually mean? To me, most of the public and the industry, it means UK innovation and technology. It is developed in the UK and is UK-owned intellectual property. It means a company paying UK taxes. Most importantly, it means a UK company being accountable to the UK. The Government have talked a lot about their commitment to developing and securing sovereignty, but that needs to be extended to all critical technology and infrastructure. Not only is that important in cyber-security terms, but it has other advantages, too: it is good for the economy, creates innovation and sets the highest standards, and it thereby gets public support and confidence and achieves small business support for absorbing the innovation. It achieves growth by creating not only UK customers, but—ambitiously—worldwide customers. The Government have done that quite well in the past. They have created safe and secure solutions. Crown Hosting Data Centres is a really good example of a joint venture between the Government and Ark Data Centres. Unfortunately, only 3% to 4% of Government servers actually use it, and we must ask why. What are we doing to promote safe and secure solutions in the UK that would help us to fight for cyber-security and ensure that it is promoted across the public sector, and to ensure that those solutions gain support in the private sector? Instead of using Crown Hosting Data Centres, many are using ones run by foreign firms with securities and standards developed outside the UK. Outages at Amazon Web Services in cloud hosting have cost business millions. Let us look at other areas where the public rightly worry about cyber-attacks and cyber-security, such as NHS data. We have heard about the impact of cyber-crimes on the NHS and on lives, but it also impacts public confidence. Palantir has a £330 million contract to bring together all NHS data. That is a fantastic initiative and really important, and the public support it because they do not want to have to repeat their health story to each and every doctor, nurse or other health professional that they meet. The difficulty is that using a foreign firm with some questionable alliances has led to an erosion of public trust and to a lack of trust among doctors, slowing the take-up of this important innovation in NHS services. That is partly because the co-founder of Palantir called our pride in the NHS “Stockholm syndrome”. Unfortunately, he misunderstands the very body to which he is selling services and is thereby eroding public trust. I know many UK firms that could have done just as good a job—and probably better, because trust among the public and doctors would have increased. We hear that Palantir has just won a £240 million contract with the Ministry of Defence for “data analytics capabilities supporting critical strategic, tactical and live operational decision making across classifications”. Again, it is hugely important that we are using the latest technology to promote our MOD and that we are tying all that up. I do not think anybody in this House has concerns about the MOD making these kinds of investments; it is who we choose to partner with that drives the concern. As I have already argued, the reality is that cyber-security has to be UK-focused. We have to protect our national interest and ensure that our partners put our national interest and cyber-security first and foremost. The views of organisations such as Palantir on the NHS and its integration into US Immigration and Customs Enforcement—otherwise known as ICE—lead us to worry that it does not share UK values. It creates a strategic vulnerability. That is what the sector is saying to us, and we should listen to it. Cyber-security is not just about reporting; it is about the investments we make ahead of time. Imagine if those two contracts and their economic opportunities had been given to UK firms. There would be enhanced UK-based cyber-security and greater confidence in our most critical areas of health and the military. Let me raise another example which, if The Daily Telegraph is correct, I am sure will raise significant public trust concerns. It has reported today that the Government are considering using Starlink for the emergency services network, replacing the existing radio set-up that is used by ambulances, police and the fire service in an emergency—our most critical infrastructure. This company is controlled by a man who has shown his willingness to turn off satellites in Ukraine at his own political whim.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I thank the hon. Member for raising that point. It is important to note that Elon Musk turned off Starlink at very strategic points for the Ukrainian military when it was advancing on Russian-held territory. It is not just that he chose to turn it off; he chose to turn it off at a critical time for the Ukrainian military. I worry that somebody who chooses to do that, and who encourages violence among the UK public at a far-right rally, at which he said, “Whether you choose violence or not, violence is coming to you. You either fight back or you die”, is not an appropriate or safe partner for our emergency services. I absolutely support the comments made by my right hon. Friend the Member for Oxford East (Anneliese Dodds) about transparency, and about some of the actions being taken by those who have been willing to stand up to these companies and demand transparency. While that is probably not the subject of today’s debate, I think we must take those actions as a warning for what is to come. I welcome the Bill and the action plan, but to truly make the UK safe and secure from state-sponsored or criminal cyber-attacks, we need to ensure that there is a UK sovereign infrastructure, capacity and capability. The Government can lead the way through their own procurement practices by making sure we are partnering with UK sovereign firms. That is good for security, good for protecting us against cyber-attacks, and good for the economy and public trust.

  • 5 Jan 2026 · HMP Leyhill: Offender Abscondments · Hansard source
    More

    Some Opposition spokespeople clearly think that it is still pantomime season; they should take this issue with the seriousness that it deserves. What is the consequence for absconding from an open prison? Being in an open prison is a privilege, as part of rehabilitation; it is not the right of any prisoner to be there.

  • 5 Jan 2026 · Rights of Women and Girls: Afghanistan · Hansard source
    More

    Milton Keynes is proud to host four hotels full of Afghan evacuees. I have had the pleasure of meeting many women who completed their education, become professionals, finished university and become judges, lawyers and doctors. They could no longer work in their country and were evacuated. Their fear above all was for their younger sisters, who they left behind, and who are now under this cruel regime. Their fear was that these young girls would never experience the joy of learning, the joy of practising and the joy of being able to do their job. Does my hon. Friend agree that it is unconscionable, in a world where women should be as valued as men, that these girls have no hope for the future?

  • 5 Jan 2026 · Northern Ireland Troubles Bill: Armed Forces Recruitment and Retention · Hansard source
    More

    I thank my hon. and gallant Friend the Minister for his service—we should thank people for their service more often. I had the pleasure of being part of the armed forces parliamentary scheme, through which we got to visit a training academy and see the cadets. It was a fantastic experience, but when we talked to the people on the estate, they said that two things were limiting the number of young people who could be part of the programme. The first was the number of people who were able to act as trainers, and the second was the facilities. What is the Minister doing to address those two concerns, at a time when so many people are responding to the Spotify adverts and signing up to be part of our armed forces?

  • 5 Jan 2026 · Middle East and North Africa · Hansard source
    More

    I thank the Minister for taking over an hour’s-worth of questions on the updates he has provided on the situation right across the region. He has a very difficult job to do, particularly given the decimation of the United States Agency for International Development, and the cuts in our aid. What are we doing to open the borders for those people who have family in, and connections to, the UK, so that they can escape the horror that they are in in Gaza, and can get a visa to visit family in the UK? Can he update the House on any progress in getting those borders open, or any discussions that he has had with the Home Office to stop biometrics-related restrictions, and to help people apply for visas from Gaza?

  • 18 Dec 2025 · Ukraine · Hansard source
    More

    May I thank the Minister for reiterating the UK’s commitment to stand by Ukraine in this illegal war by Russia? This is another Christmas that many Ukrainians in the UK will be spending away from their family and their home. Will he join me in wishing them a merry Christmas, making a commitment that we will always be a safe haven for them, and thanking people, such as Viktoriya Shtanko, who are leading efforts in the UK to make sure that they have a happy Christmas?

  • 18 Dec 2025 · Violence against Women and Girls Strategy · Hansard source
    More

    I want to say a huge thank you to the Safeguarding and Victims Ministers. I was struggling not to get over-emotional as my hon. Friend was making her statement, because many of us have come to this place to make a change for the women and girls in our lives and in our constituencies. This is a watershed moment and it is a chance for us to take individual actions, bringing together good men and good women across our constituencies to speak out and speak for the kind of society we want. If the strategy is to be truly successful, it will have to increase the confidence of victims, in which case we may see the number of incidents that are reported rise; for me, that will be an indicator of the success of the strategy. One way to increase confidence is to ensure that no matter how high-profile someone is as a self-declared misogynist, they are held to account and brought back to this country to face criminal charges here. Does my hon. Friend agree that this Government should be doing all that they can to ensure that they pursue every single rapist, abuser, perpetrator, stalker, and that that will be the way to ensure that women and girls feel confident in our police and our court system?

  • 17 Dec 2025 · Local Government Finance · Hansard source
    More

    As a former deputy leader of Milton Keynes city council, I welcome this announcement. As a reminder, Milton Keynes city council faced £200 million-worth of cuts—55% of our grant—while Buckinghamshire and Northamptonshire were protected and got bail-outs. This settlement is, for once, going to give us the funding we need to protect Britain’s fastest-growing city, so I thank the Minister. Will she meet us to talk about some of the things we can do to encourage councils to build homes at the same rate as Milton Keynes?

  • 17 Dec 2025 · Puberty Suppressants Trial · Hansard source
    More

    I appreciate the science-based approach taken by the Secretary of State. We use puberty blockers for many different conditions, so will the trial look at the data that has been amassed from the use of puberty blockers for other conditions? I wish to state on the record that puberty blockers are reversible. The evidence shows that when people stop taking them, they stop working—that is the science behind them. Finally, young people in my constituency are more likely to age out of gender services than to get their first appointment, so what are we doing to shorten the waiting time, not just for puberty blockers but for the whole range of services provided to trans children by the NHS?

  • 16 Dec 2025 · Electoral Resilience · Hansard source
    More

    I welcome the Secretary of State’s comments on social media, and I hope we can meet the Under-Secretary of State for Housing, Communities and Local Government, my hon. Friend the Member for Chester North and Neston (Samantha Dixon), who is responsible for elections, ahead of the publication of the elections Bill to see what we can do about those protections. The Secretary of State has announced a very good review. Will the money that is coming into this country, particularly related to changing our politics on abortion rights, trans rights and other areas, be within scope of the review?

  • 16 Dec 2025 · Transgender People: Provision of Healthcare · Hansard source
    More

    My hon. Friend is making a powerful speech and bringing the debate back to people, which is where it needs to be. I want to highlight a case in my constituency of a young transgender person who spent two years on the under-18s waiting list for an initial appointment. They have now aged out of that waiting list and potentially have a six-year wait, meaning that when they are able to speak to a doctor or a health professional it will have been eight years. Their parents approached me to tell me how much that is damaging their young one.

  • 16 Dec 2025 · Africa: New Approach · Hansard source
    More

    Although I do not disagree with any of the principles set out in the strategy, I am disappointed by its level of ambition and detail. It does not reflect what we did when we were last in government with the Commission for Africa, which was an all-encompassing report looking at how we work together at the university level as well as on skills, trade, women and girls—all those issues—and build democracy. Unfortunately, it also does not address the real risk from Russia and China’s role in Africa. We have 21 Commonwealth countries in Africa, and they are telling us that they desperately need us as a partner so that we can bring the stability and prosperity to the continent that we all want to see.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    I appreciate what the Minister says—that these powers are in legislation—yet the process is still the social media platforms marking their own homework. We are in a vicious circle: Ofcom will not take action unless it has a complaint based on evidence, but the evidence is not achievable because the algorithm is not made available for scrutiny. How should Ofcom use those powers more clearly ahead of the elections to ensure that such abuse to our democracy does not occur?

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    My hon. Friend raises two really important points. First, if we try to create legislation to address what companies do today, it will be out of date by the time that it passes through the two Houses. What we do must be done on the basis of principles, and I think a very good starting principle is that what is illegal offline should be illegal online. That is a pretty clear principle. Offline legislation has been robustly challenged over hundreds of years and got us to where we are with our freedom of speech, freedom of expression and freedom to congregate. All those things have been robustly tested by both Houses.

Published records only — not a full account of an MP’s work. How we work →