Julia Lopez MP: speeches 2026
36 published records · newest first.
Speeches
- 4 Feb 2026 · Topical Questions · Hansard source
More
Amid the utter muck-storm of this week, it is World Cancer Day, when we should be thanking our incredible scientists whose breakthroughs give hope to patients at their lowest ebb. Does the Secretary of State think that her Government should charge VAT on medicines being supplied to those patients for free?
- 4 Feb 2026 · Topical Questions · Hansard source
More
I did not uncover any answer there. Charities and life sciences firms are telling me that this Government have begun to issue tax bills on free drugs, such that one company is stopping a compassionate access scheme and withdrawing two critical cancer drugs, and more could follow suit. This is a disaster for patients, a disaster for securing clinical trials, and a disaster for this Government’s cancer strategy. Will the Secretary of State and the Chancellor commit to stopping those bills as a matter of urgency, for the sake of patients and of our vital life sciences industry?
- 20 Jan 2026 · Mobile Phones and Social Media: Use by Children · Hansard source
More
I thank the Secretary of State for advance notice of her statement. What does an ailing Prime Minister do to demonstrate firm and decisive leadership? He launches a consultation, with a variety of options. What does he do when the Conservative party, the House of Lords, trade unions and more than 60 of his own Labour MPs line up against him on a tricky issue? Rather than take a clear position on a social media ban for children and getting phones out of schools, as the Conservative leader has done, this Prime Minister finds an unkempt meadow with some lengthy grass in it, and he boots the tricky issue right in. The House does not just need to take my word for it. One senior Labour MP has said that this consultation will “take too long”. Another said, referring to a social media ban, “The immediate reaction is that this is just a way of kicking it into the long grass.” There is a straightforward question that Ministers must answer today: is the Government’s apparent change of heart on a social media ban for real? Is this consultation a way of elegantly managing yet another U-turn, or is it simply a device to get the Prime Minister through the parliamentary week, while the position remains unchanged? If it is progress, it can be celebrated, but let us not forget that until very recently, the Prime Minister said that he was personally opposed to a social media ban for children. In December, the Culture Secretary confirmed that she is against one. The Business Secretary is opposed. The Chief Secretary to the Prime Minister said on the media this very morning that the Government do not take a view. In fact, the only senior Labour figure we know who is clearly in favour of a ban is Andy Burnham. That is some leadership. What is the Secretary of State’s personal view, and what is her message to Labour MPs who would like to vote for a ban this week? Each of those rebel MPs will be asking themselves, “After the Prime Minister has Grand Old Duke of York-ed me up and down so many hills, can I really trust him to see this through?” That is especially so given that this same proposal was tabled previously, and Labour voted it down, just as it voted down our amendment to the Children’s Wellbeing and Schools Bill on a phone ban in schools. It is just like when they were told not to support their own colleague, the hon. Member for Whitehaven and Workington (Josh MacAlister), when he had a private Member’s Bill on this issue. Knowing where the Secretary of State personally stands on a ban—not where she stands on a consultation and not what she thinks about having a variety of options—may help ease the minds of Labour MPs. What of the timeline? Does a three-month consultation mean that legislation to introduce a social media ban will be ready in time for the King’s Speech? If not, and if MPs do not vote for a ban this week, they will not have another chance to do so for 18 months. The opportunity to change things is now. How many on the Government Benches will take that chance? The Government must have a great deal of the evidence that they need. The Secretary of State’s predecessor commissioned a University of Cambridge review of children’s wellbeing in relation to smartphone use, messaging and social media, which was due to report in December. Can the Secretary of State tell us what the report said? The urgency is obvious. Everyone, especially parents, can see what social media is doing to children. It is not just exposure to extreme or explicit content, although of course that matters. The Online Safety Act 2023, which we introduced, is already addressing illegal material and age-gating, and that work is ongoing. However, the harm goes wider. Social media has created an anxious generation hooked by products designed to be addictive, displacing real-world activity and undermining attention, emotional regulation and mental health. Schools and families deal daily with the consequences: cyber-bullying, social anxiety and fractured concentration. China’s version of TikTok, Douyin, limits children to an hour a day and promotes educational content, but western platforms do the opposite: engagement loops are optimised for emotional arousal. We welcome scrutiny of those algorithms and steps to stop children’s data being exploited, but there is a simpler option, which is to keep children off these platforms altogether while allowing adults the freedom that follows. Conservatives believe in parental responsibility: we believe in freedom for adults, but we also believe in protecting children. We believe in policing age, not policing speech. It is not to strip parents of their roles and responsibilities to recognise that the online world can be a discombobulating nightmare to supervise. It is not to be a modern-day Mary Whitehouse to worry deeply about children being exposed to images and topics that they are simply not equipped to deal with. This consultation also includes a rethink on phones in schools. I see that the Education Secretary is present; for months she told us that it was a gimmick and unnecessary, although most secondary school pupils say that phones are still used extensively. By when will phones be banned in schools, and how quickly will Ofsted enforce that? Will it be enforcing against guidance or against the law, because guidance is simply not enough? We must be up front in saying that the challenges of implementing any social media ban are real. We support the Government as they navigate those challenges because we want this to work, but can the Secretary of State make it clear that digital ID will not be a requirement to pass age verification on social media sites? The truth is that the internet grew as a pioneer society, with consequences that we are all reckoning with. It now needs to be retrofitted with very clear rules for children. They need to be protected. Other countries are taking the approach of a social media ban; will this Government in the UK do the same?
- 14 Jan 2026 · Science and Discovery Centres · Hansard source
More
It is a pleasure to serve under your chairmanship, Mrs Harris. I congratulate the hon. Member for Montgomeryshire and Glyndŵr (Steve Witherden) on securing this debate and bringing parliamentary attention back to a subject that has not been properly considered for some years: the role of science and discovery centres within our tech and science ecosystem, the pressures they face, and the contribution they continue to make. I enjoyed hearing about the hon. Member’s connection to the Centre for Alternative Technology, which clearly has such personal resonance given his father’s link, as a founding member in the 1970s. I knew the hon. Member was a teacher, but I did not realise he was a drama teacher, which perhaps explains why he is so fantastic at carrying his voice in this Chamber and speaking with such incredible passion. I confess that I had not appreciated how extensive the network of SDCs is. The Eden Project, which I visited again last year, is just one of the 28 science and discovery centres spread across every part of the UK, and it is a perfect example of what these institutions do so well. It is a major visitor attraction, it is deeply rooted in its local economy, and it has scientific discovery and public engagement at the heart of its mission. These centres are not arms of the state; they are independent, agile and largely self-sustaining organisations, generating income through admissions, partnerships and commercial activity. Many SDCs were established around the turn of the millennium. Indeed, my first visit to the Eden Project was back in 2000, on my very first girls’ holiday. We did not, as Essex girls, choose Marbella; we chose Cornwall and Devon—very rock and roll. But the Eden Project really embodies the optimism of that moment. It is an old claypit, turned into a very future-focused and futuristic-looking plant wonderland with a scientific mission at its core. While there were early Millennium Commission grants and support, that funding rightly came to an end, and these centres have now operated for many years without routine public subsidy. That independence has been a strength, allowing them to innovate and respond quickly to new scientific developments and to retain the trust of the communities they serve. But there was always an understanding that the materials in the buildings designed for the SDCs would require renewal after around 25 years, which is now. Many centres have now reached that point and face major capital projects at exactly the same time in a far more difficult operating environment. SDCs are a distinctive part of our national infrastructure. They are the only places where cutting-edge science, public engagement and development of essential STEM skills come together under a single roof. Collectively, they reach more than 5 million people every year, and they have engaged with over a third of UK schools in the past two years alone. The hon. Member for Winchester (Dr Chambers) talked with beautiful passion about the role of science in his own life, having been fired up by an early visit to a planetarium. It was the same for the hon. Member for Gravesham (Dr Sullivan). We also heard from the hon. Member for Bracknell (Peter Swallow) about his connection to the Look Out; as he was speaking, I thought back to the time I was hit by a Segway in Bracknell forest, and I started to get PTSD. As SDCs rely on their own income rather than public subsidy, they have been particularly exposed to recent shocks, such as the pandemic and the energy price surge after Russia’s invasion of Ukraine. Although Government support schemes helped many organisations through that period, SDCs fell between several stools. They were not eligible for cultural recovery funding, and they did not have national lottery support either. They survived those challenges, but they did not anticipate facing simultaneous capital renewal pressures alongside the impact of the 2024 Budget. We have all spoken to hospitality businesses in our constituencies about the sharply rising costs, particularly when it comes to employing people, given the national insurance and business rates issues coming through. Those pressures are now pushing some of these science and discovery centres towards a tipping point. Two of the largest in the UK have announced significant redundancies. One set of accounts explicitly cites the inflationary impact of the Budget and increased national insurance costs, and 75 jobs have already gone at one centre. Some centres have warned that, without intervention, closures within the next 12 to 18 months are a real possibility. All of this matters because the mission of science and discovery centres is to make science, technology, engineering and maths more accessible, engaging and relevant to people from all backgrounds. They provide trusted spaces where the public can explore new technologies to understand their applications and build confidence in engaging with them—a recent example is a project to demystify AI. The hon. Members for Aberdeen North (Kirsty Blackman) and for Widnes and Halewood (Derek Twigg) mentioned how these centres play a critical role in the skills pipeline. Glasgow Science Centre’s learning labs programme has worked with thousands of teachers and reached over 100,000 pupils. That shows how these centres complement formal education and help young people to see themselves as future scientists, engineers and innovators. The hon. Member for Hexham (Joe Morris) talked about the importance of SDCs in challenging anti-science narratives. I congratulate him on his recent nuptials—I am sure Le Petit Château had a very lively night over the new year. Ministers have recognised all these strengths. The Secretary of State herself has spoken in this Chamber about the National Space Centre, which is in her own city of Leicester, and the role it plays in future jobs and prosperity. The constituency of the right hon. Member for Edinburgh South (Ian Murray), who is one of her Ministers, neighbours the amazing Dynamic Earth SDC. I know his constituency is not close to Montgomeryshire, but I am sure he does not want to take on and disappoint the Welsh mafia, if I may say that, in this Chamber by not backing SDCs very fully. That touches the heart of the problem. These centres need a Department to recognise them, engage with them and champion them, and DSIT is their obvious home. These centres were born of a Government-led vision to create trusted environments for public engagement with science and tech, and they have built strong partnerships with universities, industry and local communities. They are ready to support national missions, but they need the Government to show them that ownership. I have a number of fairly straightforward questions for the Minister, which are reflective of the very disciplined briefing behind the scenes by the Association for Science and Discovery Centres. I would be grateful if he could let us know whether DSIT will formally accept responsibility for the sector and act as its champion across Government. Will Ministers meet SDC representatives as a matter of urgency? Will the Department consider whether underspends can be directed towards the £20 million that the SDCs believe is essential for capital upgrades, which they are confident they can match-fund through partnerships? Will Ministers engage directly with DCMS colleagues on opening up access to national lottery funding for science and discovery centres? Finally, will the Minister make representations to the Treasury about the wider impact of current tax and business rates policy on SDCs, which runs directly counter to what the Government say they wish to promote when it comes to science and technology? SDCs are a quiet success story. They are independent, entrepreneurial and deeply embedded in communities. They support public understanding of science, they develop future skills and they are inspirational to future generations. They are not asking to be taken over or paid for, and they know what to do when it comes to continuing their great work long into the future, but they need help with short-term challenges that are not of their own making. They are asking to be recognised, engaged with and enabled to continue doing what they already do well for the benefit of science, society and the economy.
- 12 Jan 2026 · Social Media: Non-consensual Sexual Deepfakes · Hansard source
More
I thank the Secretary of State for advance notice of her statement. Last week, public outrage was rightly expressed about the use of artificial intelligence to undress women and children in photographs by X’s AI assistant Grok. The use of AI in that way without consent is wrong. It is disturbing, and in many cases it is illegal. We support Ofcom in taking enforcement action where an AI tool is used to generate illegal content, especially of children. We support the Government’s stance on nudification tools. X itself has warned of consequences for anyone prompting Grok to make illegal content. The tools in question have been put behind a paywall, for the easy identification via name and bank details of anyone misusing them. Beyond the platform, however, the Internet Watch Foundation has identified cases where perpetrators have used Grok in tandem with other AI tools to generate category A material. As the Chairman of the Culture, Media and Sport Committee, my hon. Friend the Member for Gosport (Dame Caroline Dinenage), has rightly said, such mainstream AI tools must not become an enabling step in the child abuse production pipeline. Law already exists to deal with much of this, including the Protection of Children Act 1978, the Criminal Justice Act 2003, the Sexual Offences Act 2003, the Data (Use and Access) Act 2025—in which the Government voted against tougher amendments tabled by Baroness Owen of Alderley Edge—and the Online Safety Act 2023. Those laws should be enforced. We await Ofcom, the independent regular, setting out its next steps. Regardless of the law, it is right to expect AI companies to anticipate and prevent misuse of products before their deployment through rigorous red teaming. I accept that for a law to deter, the enforcement threat must be credible, but its use must also be proportionate. Notwithstanding the soft back-pedalling of the Secretary of State today, the Government’s appendage swinging over the weekend was extremely serious. Ministers mooted as an urgent remedy the banning of a site with 21 million monthly users in this country, despite another Minister guffawing that banning X was “conspiracy theory No. 3,627.” Since their invention, the internet and social media have been misused—often criminally—by people traffickers, paedophiles and fraudsters: the gutter dwellers of our society. Nobody is on their side, but Government have never before proposed blocking TikTok, Google or Facebook wholesale for the frequent and often flagrant misuse of their sites. That would be an extraordinarily serious move against a platform that can be used for good—for uncovering scandals, sparking democratic revolution, and allowing the free exchange of ideas, day to day, including those that we do not like. It is that very power for good that makes Iran’s mullahs reach to block the internet in the face of courageous protesters. This episode poses legitimate questions about who holds power in the internet age. Many worry about the accrued influence of big tech titans—me included—but they worry, too, about the power of Government to divert, hide and duck accountability. They worry about this Government. The uncomfortable truth for all of us is that some of this imagery sits in a legal grey area. What Grok has produced at scale in 2026 is a modern-day iteration of an old problem, from crude drawings to photoshop. Grok is not the only tool capable of generating false or offensive imagery, and not all of this content will cross the threshold into illegality. Plenty of it is sick, degrading and morally repugnant but does not cross the criminal threshold. What, then, is the Secretary of State proposing to do about the difficult enforcement choices that a regulator or police force must make? The risk is that, with finite resource, and in a highly politically sensitive environment, regulators could be diverted from pursuing the most abhorrent and dangerous crimes. If we wish to mitigate the risk to children, one simple intervention may help stop them sharing their own image too freely: raising the digital age of consent for social media to 16. The cross-party consensus is growing. The Mayor of Manchester, Andy Burnham, agrees with that idea; does the Secretary of State? She knows that there are geopolitical consequences to her rhetoric. Figures close to President Trump have already threatened sanctions. Has the Secretary of State engaged with the US Government? Has she been advised on the nature of any retaliation, were the UK Government to block X? The US-UK tech deal has already been paused. We need clarity on what else is at stake. To conclude, the Tech Secretary has said: “We are as determined to ensure women and girls are safe online as we are to ensure they are safe in the real world”, so will she ensure that the Government enforce against themselves for their failure to advance the rape gang inquiry, their failure to stop puberty-blocking trials, their failure to implement guidance on single-sex spaces, and their inability to deport illegal migrants who have committed sex offences? This Government rightly worry about the online sphere, and we support them on that, but there is plenty to be getting on with in the real world.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
Happy new year, Mr Speaker, and thank you for putting the heating on. I am grateful to the Minister for setting out the Government’s rationale for this legislation in the Secretary of State’s stead. I do not know why the Minister was demoted either, but I want him to know that we appreciate him. The official Opposition recognise the scale of the cyber-security challenge that the country faces. If the pandemic accelerated the adoption of digital technology at a pace we had never before seen, then the advent of artificial intelligence will embed that technology into our economy in wholly new ways that bring not only opportunity but unprecedented risk. AI and automation will not only transform productivity but equip hostile states, criminal gangs and opportunists alike with tools capable of eroding our national defences at speed and at scale. It is right that Parliament legislates to raise the collective security bar. We on the Conservative Benches support that principle. However, legislation of this kind does not come around often. Cyber law takes time to develop, and once the Bill passes, it is unlikely that Parliament will return to this territory for some years. That means that we must ask two simple but very serious questions today: will this law work and is it enough? Before we answer those questions, it is worth reminding ourselves of the real-world consequences of failure. Cyber risk is neither abstract nor theoretical. Last year, the UK experienced what is widely regarded as our most economically damaging cyber-incident to date when Jaguar Land Rover suffered a major attack. That was not a sophisticated act of cyber-warfare against the state—although such acts are happening with increasing regularity—but was carried out by a band of hackers. The consequences were enormous, however. For five weeks, Jaguar Land Rover was unable to operate its automated manufacturing lines, cyber-related costs mounted to nearly £200 million, and national economic output was visibly affected in that month alone. The real damage did not stop at the factory gates: hundreds of small and medium-sized enterprises in the supply chain—many of them operating on thin margins—were pushed to the brink, workers faced uncertainty and contractors had their work paused. Ultimately, the Government had to step in with a £1.5 billion loan guarantee to prevent wider economic fallout. When we consider the Bill, we must ask whether it would do anything to strengthen our collective resilience. That is one of the tests that this legislation ought to meet, and it is not yet clear that it does. Indeed, the attack on JLR would not have been stopped, as the Minister himself has made clear, because it would not have been in scope. The cyber-threat landscape is evolving at an extraordinary pace. New research shows that cyber-attacks now cost our economy nearly £15 billion every year. High-profile breaches of businesses such as Marks and Spencer and the Co-op have demonstrated how quickly consumer confidence, jobs and supply chains can be put at risk. Last year alone, insurers paid out £197 million to help businesses recover from cyber-incidents. In fact, the collective cyber insurance bill of the FTSE 100 is now larger than the defence research and development budget. The Bill seeks to respond to one aspect of that reality by expanding the scope of regulation. Data centres, managed service providers, load controllers and designated critical suppliers will now fall within its ambit. That is a welcome acknowledgment that digitisation has introduced systemic risks that the original NIS regulations of 2018 did not adequately cover. The Bill also strengthens the powers of regulators, introduces cost recovery mechanisms and tightens incident reporting requirements. Those measures are intended to modernise our cyber framework and address clear shortcomings identified in reviews of the NIS regime in 2020 and 2022. On paper, that all sounds sensible, but intent alone is not enough, which brings me back to our central concern: whether this law will work in practice in raising the standard of our collective resilience. The uncomfortable truth is that, in some of the most high-profile cases of cyber-attack, the penetration of systems was carried out by attackers using valid credentials. That means systems behaved normally. The breaches looked like legitimate access until it was too late. Human frailties were exploited: help desks were persuaded to reset passwords, and staff and contractors were impersonated. This Bill would help mainly after an attack—not before—by mandating reporting, improving intelligence sharing and increasing accountability.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
Absolutely. The hon. Gentleman is correct: this is fundamentally about culture—that is the point that I am making. We can pass as many regulations as we like, but a lot of the holes in our cyber-security systems come down to human frailties. That means this challenge is not just about new laws but about changing a number of things to make us more resilient. It is right not to dictate technical standards in primary law that will soon be outdated in the fast-moving world of technology, so the question is whether this law has the right mix of carrot and stick to make affected firms act in a way that raises the security bar—there are several areas where we fear it may not. First, there is potentially an enforcement paradox. The Bill expands regulatory powers and increases the scale of potential fines, but the evidence from the existing regime does not suggest definitively that fines and new regulations deliver us greater cyber-resilience. Under the current NIS regulations, enforcement has been slow, inconsistent and often toothless. Very few significant penalties have been issued. Where they have been issued, the delay between incident and sanction has sometimes stretched beyond two years. That delay matters, because it actively undermines deterrence and disconnects accountability from operational reality. Simply widening the scope of regulation without ensuring that regulators are properly resourced, empowered and required to act quickly risks creating obligations that exist on paper but lack any real-world bite. We also have concerns about the Bill’s cost recovery model. Funding regulators through levies on the organisations that they oversee risks unintended consequences in terms of improving our resilience. For large firms, the cost burden may be manageable, but for smaller enterprises it amounts to an additional operational tax that could divert scarce capital away from cyber-defence, staff training and innovation. There is also a structural risk here. Regulators that are reliant on fee income might face incentives to expand scope and complexity unnecessarily, creating bureaucratic drag that crowds out voluntary, market-led initiatives, which often raise standards more effectively than prescriptive regulation. More generally, I worry that this Bill will play into tech monopolies. The companies that thrive in this kind of environment are those with big compliance and legal departments. That concentrates risk and makes our tech economy less diverse, with serious implications that I shall come on to. There may be reporting challenges too. A two-stage reporting process within 24 and 72 hours may be achievable for large, well-resourced organisations with in-house cyber teams, but for smaller operators it risks creating a compliance culture focused on speed, not substance. There is also the danger of duplication. Many organisations already face overlapping reporting obligations under UK GDPR, sectoral rules and existing legislation. Without simplification and proportionality, the administrative load could be significant, once again diverting attention and resource from the very cyber-threat management that the Bill seeks to improve. We need to avoid this legislation becoming a “something must be done” Bill that totally misses the mark. The Bill also fails to grapple properly with the human factor in cyber-security, which has already been talked about by the hon. Member for Harlow (Chris Vince). Technology alone does not keep organisations safe; governance matters. Yet board-level ownership of cyber-risk is moving in the wrong direction. Only 27% of businesses now have a board member explicitly responsible for cyber-security, down from 38% just three years ago. Without mechanisms to ensure senior accountability, fines risk becoming little more than a cost of doing business. Directors remain insulated while operational teams are left to carry the can. National cyber-resilience depends not just on systems and software, but on leadership, culture and accountability at the very top. For those reasons, ahead of Committee consideration, we on the Opposition Benches are examining how the legislation can be strengthened, while continuing to support its core objectives. In the meantime, regulators must be properly equipped with the right powers, resources and clarity from Parliament on the intent of the law. Sanctions must be applied swiftly and consistently, and guidance must be clear, so that enforcement is credible and deterrence is real. The Government should also look at how reporting obligations are calibrated. A one-size-fits-all approach might place disproportionate burdens on smaller firms, and it might be better to ensure that reporting thresholds reflect the size, complexity and risk profile of an organisation. Equally, the funding of regulators must be transparent and predictable. There have to be safeguards against regulatory expansion for its own sake and firm assurances that funds raised are reinvested directly into improving national cyber-resilience, not absorbed by administrative overheads. While the Bill rightly prioritises critical national infrastructure, it cannot afford to ignore high-risk sectors that sit beyond its immediate scope. There is also a major role for market-based solutions. Cyber insurance, sector-wide intelligence sharing and collaborative resilience initiatives can all complement regulation. These tools can reduce risk and improve preparedness without adding unnecessary legislative complexity. The review cycle set out in the Bill may be too slow for the threat landscape we face and the pace of technological change. Annual or biannual reviews might allow Parliament to scrutinise effectiveness, respond to emerging threats and ensure that the legislation remains fit for purpose. Let me make some more general points about the Government’s approach to cyber-security and resilience, and issues about the risk of dependence and threat from adversaries. I see no evidence from this Government that they are thinking with any clarity about the risks of long-term technological dependency and lock-in—quite the opposite, in fact. Large parts of our economy now depend on secure, high-quality digital infrastructure, and that reliance will only increase as AI advances. Whoever provides that infrastructure will wield huge future leverage. It was that reality that ultimately drove the change of heart over Chinese tech sitting at the core of our 5G telecom networks a few years ago. However, the Government are seemingly betting every chip on US hyper-scalers. They provide our data centres, supply the platforms on which Government Departments are run and, more often than not, are the ones winning all the Government contracts. These investments will provide our companies with things that they need, from compute power to increasingly sophisticated AI platforms, but the UK is doing little simultaneously to mitigate our increased technological dependency. When I say “technological”, we need to understand that technology is what we now run our defence systems, factories, energy networks and communications on. Technology is the plumbing of our nation. During September’s much crowed-about state visit by President Trump, this Government were visibly begging for good economic headlines after the humiliating resignations of the Deputy Prime Minister and the ambassador to the US, not to mention the uncontainable mess of the Chancellor’s first Budget and the threat of her second Budget. The US-UK tech partnership was the result, with a huge amount of smoke and mirrors deployed over what it actually contained. Whatever substance lay within it, we heard just before Christmas that it had been paused, used as leverage by the US while other trade negotiations were under way. I am not criticising the US Administration for skilfully playing their hand in their national interest; I am asking this Government rapidly to wake up to the reality of a new world in which the post-war settlement is coming to an end—one that has been giving clues to its existence for many years, since long before President Trump came into office. The United States remains a vital ally, but in this new era Britain must be very clear-eyed about risk, the reality of hard power and the need to protect our sovereign interests. Cyber-risk requires as much thought about the fundamentals of plumbing as it does about the laws that try to manage how humans use or exploit technology. The UK Government have a vast procurement budget for which our own firms ought to be able to make a successful bid, but UK tech tells me consistently that, for all the talk in the Government’s AI strategy of sovereign tech capability, it has not got a look-in since Labour has been in power. I am concerned that this Bill should not introduce new, burdensome regulation for UK firms in a way that benefits non-UK incumbents with giant compliance teams and legal resources in a way that would exacerbate the risk of vendor lock-in. Let us turn to another risk. The private sector will have noticed that the new obligations in this Bill broadly do not touch the public sector, where cyber-risk remains red-light-flashingly large, notwithstanding the public cyber strategy that was thrown out today in implicit acknowledgment of that gaping hole. Knowing that the public sector holds such enormous cyber-risk, this Labour Government choose not to minimise it, but to create a brand-new one—a hulking great identity system mandated for anyone who wants a job and, we now hear, possibly for new-born babies. It is mandatory identity by stealth, not consent, and with no honesty about it. It is not to be against the ability of people to verify themselves digitally for banking, to access certain online services or to stop fraud to think that Labour’s mandated digital identity plan is a complete rotter. The Association of Digital Verification Professionals called what Labour inherited on digital identity a “world-leading model for data sovereignty that digitised liberty rather than diluted it”. The citizen, not Government, would be in control. This naive Government are crowding out private sector expertise and making everyone have one of these identities by stealth. They have no idea what this system will cost, and they will not be honest about what it will be used for. What of the cyber-security of this system? The system on which this digital identity will be run was breached during red team testing last year. When I asked the Secretary of State if that system has now met the National Cyber Security Centre’s cyber-security standard, no answers came. Whistleblowers have continued to speak out about the vulnerabilities of the system, and there is no sense whatsoever from Government that the dodgy digital identity plan will be paused until such a point when they are confident about cyber-security.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
I welcome the strategy, but I have not yet had a chance to have a good look at it, because the Government always seem to publish these sorts of documents right at the last minute. The only way to get any information out of this Government is to apply some pressure in this House, and then, remarkably, things come flying out of the cupboard. I will be very interested to see what the strategy looks like and whether it is up to the challenge we now face. The problems and risks of cyber have increased markedly since we were in Government because of the advent of AI technology—that technology is changing the picture very rapidly, just as the defence picture is changing very rapidly. My concern is that this Government are not taking seriously enough the various defence and security challenges that this House faces; they are prioritising spending on welfare payments, union payments and all manner of other things. It is one thing to get a strategy out of the door; it is another to put in place the measures that will implement that strategy. Basically, all we have seen over the past 18 months is strategy documents, without a great deal of delivery. That is one of the reasons why the Government are so rapidly losing public confidence. In conclusion, we support this cyber Bill in principle—the threat is real and growing, and it demands action. However, it is only a tool, not a cure-all. A Government who are trying to close down gaps in one place while wilfully opening up huge new risks in a different corner are being negligent in their approach. Furthermore, if this legislation is to command confidence, it must be practical, proportionate and genuinely effective. Without meaningful improvements, the Bill risks placing new burdens on business while delivering only marginal gains for our national resilience. Cyber-security is a shared responsibility between Government, regulators, industry and the public, but leadership must come from the top, and that is where this Bill currently falls short. With the private sector taking the lion’s share of the load while gaping holes remain in public sector cyber-defences, the Bill begs obvious questions about the confidence that citizens should have in flagship Government projects such as the Prime Minister’s mandatory digital identity system. As it stands, the Bill would not have prevented high-profile cyber-shutdowns such as Jaguar Land Rover’s, it does little to address the chronic vulnerabilities in the public sector, and it certainly will not make Labour’s dodgy ID database any more secure. That is why, as the Bill progresses through Parliament, we will be pressing this Government to ensure that it delivers genuine security, proper accountability and raised cyber-defences across the board, while taking them to task on major mistakes such as mandatory ID. Cyber-security is no longer a niche compliance exercise; it is about protecting the fundamental economic and defence interests of our nation.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
The hon. Gentleman is wilfully misinterpreting what I am saying. There is not an issue with having systems tested; there is an issue with the fact that the system test failed. There is no evidence that the Government have therefore acted to deal with those systemic failures.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
The whistleblowers continue to raise serious concerns about the structures upon which the Government’s digital identity platform will be built. The hon. Member looks absolutely outraged that I might suggest there are some concerns about the cyber-security risk of a national, mandated digital identity platform. I find it extraordinary that he suggests that I am expressing concerns that a system might be tested. Of course every system must be robustly tested—that is not the point I am trying to make, and the hon. Member is being wilfully ludicrous in suggesting otherwise. This Prime Minister cannot run an economy, keep promises or control his Back Benchers, or his Front Benchers, so how on earth does anybody think he can run a secure digital identity system? At the same time as risking technological lock-in by friendly allies, we are creating new vulnerabilities for adversaries to attack. Just before Christmas, UK intelligence agencies warned about increasing, large-scale cyber-espionage from China, targeting commercial and political information. We discovered from Ministers that the Foreign Office itself was the subject of a major cyber-attack in October, which officials believe was carried out by Chinese hackers, and this came in the midst of a major row between the Government and the Crown Prosecution Service about the prosecution of spies operating here in Parliament. We will be looking closely at this legislation to identify where the Government should be addressing this cyber-reality with much greater force. An approach to cyber-resilience that looks only at introducing new regulations and compliance burdens without thinking through risks such as a mandated identity scheme, dependence on non-sovereign suppliers, the malign intent of other nations, and a failure to build up our own workforce and skills is one that will fail.
- 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
More
As my right hon. Friend is aware, local government is outside of the scope of the Bill, but it is a very juicy target—much of the public sector remains a very juicy target. In acknowledgment of that, the Government whipped out a strategy very quickly this morning that is meant to give us assurances about the public sector’s cyber-resilience. I am not sure that that strategy will provide much reassurance, which is why it is important to understand that this Bill can only be one part of a much wider arsenal to tighten gaps where they exist, in both the private and public sectors.
Published records only — not a full account of an MP’s work. How we work →