Kanishka Narayan MP: speeches 2026
258 published records · newest first.
Speeches
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
I take the hon. Member’s point about wanting to work together. The Government are committed to doing exactly that. It is not a question of whether we act, but how we implement specific changes to secure our children’s future. I encourage her and the entire Liberal Democrat party to engage with the consultation.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
I can confirm to the hon. Member that the Government have committed to act robustly by the summer, which is about as short and sharp as a consultation can get. Instead of procrastinating on this question, I encourage her to engage intensively with the process of consultation and the national conversation. I mentioned illegal content duties, as well as child safety duties. Under those duties, services must now conduct highly effective age assurance, precisely addressing the point raised by the hon. Member for Upper Bann (Carla Lockhart), to prevent children in the UK from encountering pornography, as well as content that encourages, promotes or provides instructions for self-harm, suicide or eating disorders. Platforms are also now legally required to put in place measures to protect children from other types of harmful content. That includes abusive or hateful content, bullying content and violent content.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
I thank the hon. Member for that point, and commit to her that we are going to try to do that as soon as possible. She will be aware that the legislative process is already very tight, so I will come back to her and the House with the wording of the motion as soon as possible. Last week, as I have mentioned, the Secretary of State confirmed that we will take new legal powers to allow us to act quickly on the outcomes of the consultation, delivering on our promises to parents. We will make sure that the wording is presented to the House at the earliest opportunity. We also recognise the importance of parliamentary scrutiny and the expertise that parliamentarians in both Houses provide, and have already committed that when regulations are brought forward, they will be debated on the Floor of the House and there will be a vote in both Houses, ensuring proper scrutiny. We are clear that the question is not whether we will act, but what type of action we will take. We will ensure that we do so effectively, in lockstep with our children and in the interests of British families.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
It is a pleasure to respond to this debate, not least to further my education in my personal passion area of parliamentary procedure. Let me begin by responding to the motion, and then I will turn to the substance of the debate. The hon. Member for Twickenham (Munira Wilson) will accept that no Government could accept a motion such as that proposed by the Liberal Democrats. The motion goes against the Standing Orders of the House, which state that the Government as elected by the people control the Order Paper, apart from specific exemptions such as Opposition days. The motion would give the Liberal Democrats free rein to schedule the business on 9 March. Today they introduced a Bill. It is still not available to Members across the House, yet they are asking the House to hand them control of business to complete all stages of the Bill within a day. That is no way to make complex changes to the law in this area. This is not just a procedural outrage; more than that I am sorry to see the Liberal Democrats join the Conservative party yet again in their usual coalition of putting political desperation on this question ahead of the interests of British children and families. I urge the Liberal Democrats to forget this approach, and to take part in the Government’s consultation, which is a true attempt at engaging across parties and across the country, so that we find the right solution for children and parents. This Government have already set out a way forward that considers those vital issues in a responsible way, and allows for swift action in response. That is how we will give children the childhood that they deserve and prepare them for the future.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
I commend my hon. Friend on her consistent commitment to evidence-based policy making in this place, and beyond it too. I commit to her that both the Born in Bradford study, which she mentioned, and wider research will be in the front of the Government’s mind.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
But not today.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
I totally agree with the hon. Member’s call for urgency. I assure her that first, the Government will act by the summer in robustly responding to the consultation. Secondly, we have been focused on getting the consultation right, and not just for the wider public; we are ensuring that it is designed for young people’s engagement, which requires particular design features. Thirdly, we are not waiting for the launch of the consultation to have the national conversation. I have been in schools and met parents, as have the Secretary of State and Ministers from across Government, so the conversation has very much started, and I am sure that the consultation is also imminent. While there is consensus that problems remain, there is not yet consensus on the best way to address them. That is why the Government announced last month that we will be launching our short, sharp consultation and national conversation on further measures. We recognise that while some people support age restrictions on social media for children, there are diverse views on both the “what” and the “how”. Prominent voices in this debate, including the Molly Rose Foundation and the National Society for the Prevention of Cruelty to Children, are concerned that blunt age limits might not be the right approach and risk doing more harm than good. Even among those who support age limits, there are differing views on how to apply them, including which services restrictions should apply to. Those views are worthy of consideration, but we need to consider them properly and responsibly—we owe that to our children. That is why the consultation approach is the responsible path forward for looking at these issues, considering in a swift and evidence-based way the full range of implications and the most effective way of protecting children and enhancing their lives online. We will consult with parents, the organisations representing children and bereaved families, tech companies and—crucially—children and young people themselves. None of that would be allowed under the motion we are considering today. This consultation, backed by the national conversation, will identify the next steps in our plan to boost and protect children’s wellbeing online. The consultation will include exploring the option of banning social media for children below a certain age, as well as a range of other measures. This will include gathering views and evidence on options such as restricting access to addictive functionalities and understanding what we can do better to support parents in navigating their children’s digital lives. We will also explore whether we should raise the digital age of consent, to give parents more control over how their children’s data is used, and how existing laws on age verification could be better enforced.
- 24 Feb 2026 · Online Harm: Child Protection · Hansard source
More
The Government are seeing both urgency and responsibility in the correspondence that we are receiving and the consultation we are engaging with, not the desperate lurch to a specific answer that the Liberal Democrats are exemplifying in this instance. I want to take this opportunity to set out our approach.
- 12 Feb 2026 · Rural Mobile Connectivity · Hansard source
More
I thank the hon. Member for raising that point. I will come to that question, because I recognise the gap between the aggregate picture and the experience felt on the ground. Let me return to aggregate investment. To ensure that investment delivers coverage improvements for communities right across the UK, including in rural areas, we continue working to identify and address barriers to deployment where it is practical to do so. I may not share the significant expertise and experience of my hon. Friend the Member for Carlisle (Ms Minns) with matters of spectrum, but I certainly share her enthusiasm. When I was an undergraduate student, the global example of the last Labour Government on auction design and the 3G spectrum was very much a part of my curriculum. In that spirit, I hope to take her advice and continue the spirit of Labour, not that of the last Conservative Government or of the Liberal Democrats, who were complicit in the auction challenges of that Government. The focus on investment includes implementing the remaining provisions of the Product Security and Telecommunications Infrastructure Act 2022. I can confirm to my hon. Friend that the Government are considering where planning rules could be relaxed to support the deployment of mobile infrastructure. The shadow Minister mentioned the call for evidence, which is due to close on 26 February. In the usual spirit, I can confirm to him that we will make a prompt statement to the House, but I am afraid I cannot give him a specific date on this occasion. On the reporting of mobile coverage, Members across the House are totally right to highlight the issues with its accuracy in some cases. I feel very personally the depth of their frustration; although I cannot condone the semi-kidnapping experience described by the hon. Member for East Grinstead and Uckfield (Mims Davies), she has my particular sympathies for her pre-Valentine’s break-up with Vodafone. Accurate coverage data is essential for consumers: it allows more informed decisions as to which operator provides the best level of service for life, work and travel.
- 12 Feb 2026 · Rural Mobile Connectivity · Hansard source
More
First and foremost, can I start by thanking the hon. Member for North Shropshire (Helen Morgan) for securing this debate on mobile connectivity in rural areas? I thank all hon. Members for their insightful contributions. While I am here speaking in place of my noble Friend in the other place, the Minister for Digital Economy, I feel the pain described by many hon. Members personally, as I too represent a rural constituency. In that context, I particularly thank my hon. Friends the Members for Stafford (Leigh Ingham) and for Truro and Falmouth (Jayne Kirkham) and the hon. Members for Berwickshire, Roxburgh and Selkirk (John Lamont) and for Caerfyrddin (Ann Davies) for their representations on behalf of farmers and agricultural communities, whom I know face a particular challenge. I also thank the hon. Members for Bromsgrove (Bradley Thomas), for Chester South and Eddisbury (Aphra Brandreth) and for Lewes (James MacCleary) for talking about not only maintaining bucolic beauty but parity and economic opportunity. I thank the Liberal Democrat spokesperson, the hon. Member for Frome and East Somerset (Anna Sabine), who raised a very concerning case about coercive control through the use of connectivity. I encourage her to write to the Department about that, as I would be keen to follow up on that particular issue. The constituency of my hon. Friend the Member for Camborne and Redruth (Perran Moon) has features of rurality and remoteness, and has coastal communities, and from my constituency I personally understand those features too. The all-party parliamentary group on digital communities, which the hon. Member for North Shropshire is a member of, along with the other Members, published in January a detailed report on this topic. It provided valuable insights and recommendations. It is well understood across the House that access to high-quality, reliable and secure digital connectivity is essential to day-to-day life, with many services now requiring an online presence. It is important not only for consumers, but for the businesses in every sector of the UK economy that depend increasingly on fixed and mobile networks in some way. From taking card payments to managing businesses online, digital connectivity is central. The focus of this debate is on mobile connectivity. The Government have an ambition for all populated areas, including rural communities, to have access to higher quality stand-alone 5G by 2030. Although stand-alone 5G is already available outside 83% of premises across the UK, I acknowledge that we need to go much further. Operators are starting to align investment and delivery plans with the ambition that the Government have set out. VodafoneThree has committed to investing £11 billion in its 5G network over the 10-year period following completion of its merger; progress against that commitment will be monitored at regular intervals by Ofcom. BT and Virgin Media O2 have set out similarly significant investment plans into their networks, both aligning with the Government’s stand-alone 5G coverage ambition.
- 12 Feb 2026 · Rural Mobile Connectivity · Hansard source
More
I confirm to the hon. Member that there is no sense of judgment on the Government Benches on the conduct of her cause. The Government continue to work with Ofcom to improve the accuracy of reported mobile coverage, building on the launch of its Map Your Mobile tool in June last year. I am glad that hon. Members recognise that that is reflected in the draft statement of strategic priorities for telecoms, spectrum and post, which the Government laid before Parliament yesterday. It will remain a firm priority for the Government, and I will make sure to represent to my noble Friend the Minister for Digital Economy the concerns that have been raised today. More accurate coverage data also allows us to understand coverage gaps. Addressing these gaps requires investment by the mobile network operators. The Government recognise that the investment climate has been difficult for the mobile sector over recent years. We are committed to working with industry to support its investment in our networks. That is why we are undertaking a mobile market review to understand the factors impacting the sector’s ability to invest, and I know that the recent digital communities APPG report calls for an independent review of the digital connectivity landscape. The mobile market review and the accompanying call for evidence, launched on Tuesday, will enable the Government to consider what we can do to support the sector too. Through the call for evidence, we are looking to gather views on the quality of mobile service and level of coverage required to harness the full benefits of stand-alone 5G, as well as where our ambitions on stand-alone 5G should go further still. As Members will be aware, as part of our work with industry, the Chancellor and the Secretary of State chaired a roundtable yesterday with CEOs of major UK telecoms firms to discuss investment challenges, as well as agreeing to a telecoms consumer charter, which looks to strengthen transparency to empower consumers, as well as to improve support for those struggling to pay. On the provision of reliable 4G connectivity, I know it is essential to many. At the spending review in 2025, the Government committed to continuing to deliver 4G coverage in areas with little or no coverage. The shared rural network has helped to deliver 4G mobile coverage to 96% of the UK land mass from at least one operator and to 81% from all four. The publicly funded elements of the shared rural network will continue to deliver improved coverage up to January 2027, with over 100 masts already delivering new coverage across the UK. Where there is no mobile coverage, we are starting to see some positive developments in the satellite direct-to-device market. To the point made by the hon. Member for Caerfyrddin, I also share her enthusiasm and hope for cost reductions as we have greater competition in that market. The UK is taking a pioneering step in enabling direct-to-device connectivity, moving ahead of European counterparts to unlock connectivity as well as growth across remote parts of the UK. Those developments have the potential to increase the resilience of our services and provide a back-up for crucial ones should territorial networks face disruption. Having coverage alone is clearly not important enough by itself. As Members have raised very clearly, there needs to be confidence that mobile networks will be available in the most difficult of times and that they are secure against threats. Though the Telecommunications (Security) Act 2021 introduced a world-leading regime for the protection and security of such contexts, I know that there is more work to do. In particular, I appreciate the points made right across the House on the resilience of mobile services to power cuts. We welcome that Ofcom is completing a detailed regulatory review on that question. I will make sure that the points raised today are represented as part of Ofcom’s considerations, and in particular I will be sure to convey the concerns of my hon. Friend the Member for Carlisle around possible ways of ensuring duration of support as backstops. We will ensure that the guidance for public telecommunications providers reflects evolving technologies and emerging threats, taking into account input from industry and expert advice from the National Cyber Security Centre. Before I finish, I will address specific points raised by Members. To the hon. Member for East Grinstead and Uckfield, I would be happy to make sure that the Minister for Digital Economy meets her as part of her recurring surgeries. To my hon. Friend the Member for Camborne and Redruth, I know that he is a strong cross-Government champion for Cornwall on all matters and I will continue to make sure that we play our part in supporting the strength of his advocacy. To the hon. Member for Caerfyrddin, there are three Home Office masts in her patch and two are already activated as part of the shared rural network. I will be happy to engage with her through correspondence on her particular concerns about those masts, should she wish to raise that. To the hon. Member for Berwickshire, Roxburgh and Selkirk who, with my hon. Friend the Member for Carlisle, raised the point on 2G and 3G switch-off, though the expectation is that operators will provide broadly equivalent levels of coverage after switching off 2G, I have heard his concerns and will make sure that both the Minister and, as a consequence, the regulator are focused on the complete delivery of that aspiration. Finally, I am conscious that the hon. Member for Berwickshire, Roxburgh and Selkirk also asked about smart meters, as did the hon. Member for East Grinstead and Uckfield. The Data Communications Company is obligated, under the conditions of its licence, to provide smart meter network coverage to at least 99.25% of premises across Great Britain. One solution for those who do not currently have smart meter wider area network coverage, which the DCC and Government have decided to focus on, involves harnessing customers’ broadband connections to also carry out smart metering communications. We are looking at how we can use modified smart meter communications hubs, as well as additional devices, to plug the gap. That is not to say that we will not continue to focus on how we can ensure mobile connectivity plays its part in that context as well. I am sure you wish for me to come to a prompt conclusion, Madam Deputy Speaker. First and foremost, I thank the hon. Member for North Shropshire, as I do all hon. Members for their contributions. I will continue, with them, to champion mobile connectivity across our rural communities.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Clause 21 reforms the enforcement regime for the NIS regulations. It seeks to ensure that providers of the UK’s most essential services are complying with their obligations under those regulations. Where they are not, it will allow for more meaningful penalties that reflect the risks they introduce to our society and economy as a whole. To do that, the clause makes a number of critical changes. First, the clause introduces a new penalty maximum based on turnover. The current maximum penalty is £17 million, which can appear disproportionately large for smaller organisations, but could also easily be absorbed by larger ones as the “cost of doing business.” The clause therefore increases the penalty limits from £17 million to a maximum of £17 million or 4% of annual turnover, whichever is higher. I am confident that that strikes the right balance within the UK regulatory context. It brings the regime in line with other UK legislation that regulates cyber-security, such as part 1 of the Product Security and Telecommunications Infrastructure Act 2022, without rushing uncritically to the more severe penalties we see in other CNI regulation. The second change is to create a simple two-band penalty structure that will provide much-needed clarity to regulators and industry about the penalty tiers for specific acts of non-compliance.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Having been promoted from a position of mere confidence to faith, I will tackle questions from the hon. Member for Runnymede and Weybridge first and foremost. On the question of thresholds of incident, the Bill sets out the severity of the sorts of incidents that we expect reporting obligations to apply to, and at the same time it ensures that it is proportionate in understanding that sector-specific thresholds ought to be precisely that—sector specific, set closely with relevant entities in that sector, and working with the expertise of the relevant regulators. For that reason, it has not been specified more fully on the face of the Bill. On information sharing, not only is there provision for the specific sets of purposes for which information sharing ought to take place between regulators, but there is a further check on the proportionality of that, through a particular requirement, to ensure that information that is shared in incident contexts is done precisely for the purposes set out in the Bill, and in a way that is proportionate. My hon. Friend the Member for Milton Keynes Central raised the question of hardware impacts. While the focus of the Bill is primarily on network and information systems, the test, as I think of it, would look at whether any compromise in network and information systems related to a piece of hardware triggers the severity of the impact, or potential impact, to be reportable. In the event that it is reportable, in its severity and potential impact, it will require notification—to the regulator and, when customers are directly impacted in the way that is set out in the Bill, also to the customers. The test is focused on whether network and information systems are engaged, and whether the impact of any incident is likely to be severe enough, in light of the thresholds set out in the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Just so that I am clear, not least for future records, I think the case described is one where the client is not in the Bill’s scope but is provided to by an MSP that is in the Bill’s scope, and where the relevant responsible individual is in the client business as an employee or agent of that business. The hon. Gentleman raises an important point. Both the obligations and the defined focus of the Bill are on regulated entities. In this instance, if the individual is not in the regulated entity and the regulated entity has complied with the entirety of the wider cyber-security reporting obligations in the Bill, we would look to other venues of legal action against the individual in question. It would be challenging for a Bill that does not regulate the entire economy to ensure that every individual and firm unregulated by it are brought into its scope as well. But that is not to diminish the significance of requiring other pieces of law to act on individuals elsewhere.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I will begin by discussing clauses 15 and 16. Clause 15 updates the incident reporting provisions in the Network and Information Systems Regulations 2018. Under the current regulations, organisations are required to report incidents only once they have had a significant impact on service continuity. It is widely recognised that this is too narrow, and results in a range of concerning incidents going unreported and a distorted picture of how secure and resilient the UK’s essential services actually are. To take two examples: a ransomware attack where confidential data has been exfiltrated from an organisation without an immediate impact on service would not be reportable; nor would a pre-positioning attack, where a hostile actor has hacked into a network and is in a position to cause significant disruption down the line, such as to the provision of drinking water. That cannot be right, and does not reflect the cyber-threats that critical services face. To ensure such incidents are caught, the clause sets a new, wider definition of incidents that must be reported. The focus is now on incidents that have successfully affected the security or operation of an organisation’s network and are likely to have a significant UK impact, which will ensure that regulators and the National Cyber Security Centre are fully aware of the range of cyber-threats affecting the UK’s essential services. The Bill sets out the factors that should be considered when assessing whether an incident has had, or is likely to have, a significant impact in the UK—including, crucially, whether the confidentiality, authenticity, integrity and availability of data has been compromised. The Government will provide further clarity in secondary legislation, setting out thresholds for each sector for when an incident is considered to have had, or be likely to have, a significant impact. That will be consulted on before it is introduced. Taken together, it means that only meaningful incidents are reported. Over-reporting has been a concern raised by hon. Members throughout the Bill’s progress, so I stress this point: things such as unsuccessful phishing emails will clearly not be reportable, as they would not be likely to have a significant impact. Given our economy’s systemic dependence on data centre facilities, for that sector alone we will also ensure that Ofcom and the NCSC receive reports on a wider range of potential incidents and near misses. That ensures that not only immediate disruptions but incidents posing future risks are reported. Clause 15 also streamlines the reporting process for all NIS sectors. It ensures that incident notifications and reports go to the NCSC at the same time as the regulator. It also sets out what those organisations can do with the information they receive, including how the information can be shared to manage the wider impacts of an incident or prevent future incidents. Finally, the clause introduces faster reporting, so that the NCSC and regulators are informed within 24 hours of entities becoming aware that a reportable incident is taking place. The 24-hour notification will be light touch, but will enable the NCSC and regulators to offer faster support to minimise the negative impacts of the incident. Fuller details will need to be reported within 72 hours of the entity becoming aware that a reportable incident is happening. The changes will protect the UK’s essential services, ensuring that the NCSC and regulators are able to provide the best support that they can. Clause 16 sets out requirements for managed service providers, relevant digital service providers, and operators of data centres to inform customers who are likely to have been adversely affected by a reportable incident. Under the current regulations, there is no requirement for any regulated entity to inform its customers if it has been impacted by a reportable incident. That may have made sense when the NIS regulations were more heavily focused on operators of essential services and the primary concern was service disruption, but it would be an inexcusable omission now that the Bill is expanding to include managed service providers and operators of data centres, in addition to the digital service providers already in scope. These are organisations that, if compromised, could leave their customers’ systems, data or services exposed or inaccessible. In such circumstances, it is vital that their customers are notified, so that they can take whatever steps they need to in order to mitigate those risks.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
As I have mentioned to the shadow Minister, the Minister for Digital Economy, the Secretary of State and I have engaged with a number of the regulators in scope here. Both those conversations, and the broader framework of this Bill, are intended to drive consistency across sectors through common security requirements, clear guidance and a statement of strategic priorities, which will set objectives that regulators must seek to achieve. I hope that is sufficient assurance not only that those conversations have started, but that they will be a fundamental focus as we ensure consistent regulation across the board. Question put and agreed to. Clause 19 accordingly ordered to stand part of the Bill. Clause 20 Powers to require information Question proposed, That the clause stand part of the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I beg to move amendment 14, in clause 18, page 38, line 31, at end insert— “(aa) otherwise in connection with— (i) the security and resilience of network and information systems, or (ii) any other matter relating to cyber security and resilience,”. This amendment would allow NIS enforcement authorities to share information with persons listed in regulation 6(2) (inserted by clause 18), and such persons to share information with NIS enforcement authorities, for purposes relating to the security and resilience of network and information systems or cyber security and resilience.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I thank the hon. Member for those thoughtful points. On the first question, the charging scheme applies to relevant costs, which are costs that regulators incur precisely when they carry out functions under the NIS regulations relating to cyber-security specifically. Those can include the cost of audits, inspections, handling incident reports or enforcement action, as well as other aspects, such as assessments of cyber-security and the provision of advice. It is important to acknowledge that regulators can decide to recover costs in relation to specific functions or their costs relating in particular to the Bill’s provisions. I hope to have assured the hon. Member that the charging scheme has a clear, tight scope that is related to cyber-security functions. On the second question, regulators probably ought to look at turnover in a way that is sector-specific, in part because there are already a range of ways in which other regulatory regimes define turnover in particular sectors, so the appropriate definitions for their sectors will be familiar to both regulators and regulated entities. At a later date, secondary legislation may be used if it is found necessary to set out factors that regulators ought to consider in setting up charging schemes, including the possibility of nuanced definitions of turnover. Any future regulations for this purpose will be subject to consultation requirements and the affirmative procedure. I would very much expect, at a sector level, a clear and proportionate definition and charging structure in relation to turnover. The second requirement is to set out, transparently and clearly, what fees have been paid, what fees are still due, and what costs have been incurred in a given charging period. On Second Reading, many hon. Members discussed the need for properly resourced regulators to successfully implement the Bill. I share that concern, and this clause seeks to achieve exactly that, in a way that is fair and proportionate to regulated organisations. I commend the clause to the Committee.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Although I will not specify prescriptively what the activity and flow ought to be, I can share from my experience that many large-scale businesses—and indeed many medium and small-sized businesses—have a very clear business continuity plan mapping their critical suppliers. In this case, I would expect the regulator and the regulated entities to engage. Who sends the email first is an open question, and I would not want to specify it in the Bill, but I would expect each regulator and their regulated entities to work very closely to understand the critical suppliers that meet the tests specified in the Bill, and to engage with those critical suppliers as a consequence.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
The shadow Minister raised two main points that I am keen to address. The first was about ensuring that I committed to next steps on potential guidance for the charging scheme. I can confirm that the Government will issue guidance for competent authorities. That will include general directions on how the fee regime ought to be implemented. At the same time, we do not intend to be prescriptive as to how competent authorities should recover costs to benefit from their experience and practice in setting up these regimes. It is important that each regulator is able to tailor their fee regime in a way that is consistent with and complementary to the state of their sector.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I thank the hon. Member for asking and repeating the question. The purposes of the provisions on information requirements are focused on ensuring that regulators can conduct their duties as provided by the Bill. I would not expect information notices to require an exhaustive list in every instance, but instead to primarily focus on a more proportionate set of asks relating to risk vectors to the security of the regulated entities and to wider national security and cyber-security. Question put and agreed to. Clause 20 accordingly ordered to stand part of the Bill. Clause 21 Financial penalties Question proposed, That the clause stand part of the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I can see the shadow Minister’s hypothetical point, but I assure him that if there is some universal, consistent practice on the part of an MSP to avoid liability, where liability should reside with them, that should be in scope of how the regulator assesses the performance of that MSP. Secondly, I assure him that there remains a degree of competition in the MSP market, given the attractiveness of the UK customer and end user market for MSPs. I would therefore very much expect any MSP that adopts a falsely defensive posture of the sort that the shadow Minister describes not only to be assessed as doing so by the regulator, but to fall foul of the competitive market context that we have and want in the UK. To conclude, an effective regulatory regime must be backed by fair but effective penalties to ensure that it is followed. The clause ensures that that is the case for NIS regulations, and for that reason I commend it to the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
The shadow Minister makes a really important point: cyber-security must be taken seriously at the highest level—at board level. It is part of the cyber assessment framework, which the Government have put at the heart of how we think about assessing cyber-security in firms as well as public sector organisations. It is also part of the guidance we are looking at in the cyber action plan and our wider cyber-security strategy. I take those very seriously. In terms of making sure that businesses have a razor sharp focus, the intent of the fine regime is to ensure that there is a deterrent effect and that it is felt at decision-making levels, which must include boards. Question put and agreed to. Clause 21 accordingly ordered to stand part of the Bill. Clause 22 Enforcement and appeals Question proposed, That the clause stand part of the Bill.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
I thank the hon. Member for those two thoughtful points. On the first, in terms of retrospective regulatory action on the adequacy of notification, I expect that the regulators will set out—in their guidance and by working closely with the entities in scope—their expectations about the nature and timeliness of the notification. That will be one input into a regulator’s broader assessment of entities’ compliance with the regime. I expect that timely notification will be assessed on an ongoing basis by the regulator, but I would not expect it to be an exclusive or primary aspect. On the question of customer notifications being proportionate, I share the hon. Member’s concern about ensuring that it is timely and efficient and at the same time meaningful for the relevant customers. I hope that exactly those principles are embodied in the guidance that regulators share about notification requirements. Customers being notified is all the more important given that in many cases, those customers will themselves be operators of essential services and other critical national infrastructure. The Bill therefore places new transparency requirements on managed service providers, relevant digital service providers and operators of data centres. Similar requirements were introduced under the NIS2 regulations in the European Union. Clause 16 requires those regulated entities to take steps to establish which of their customers, if any, are likely to be adversely affected by a reported incident. It then sets out the information that the entity must share with those identified customers. These new requirements will support the overall resilience of the UK’s essential services and economy, which depend so heavily on these services, and reduce the overall impact of disruptive cyber-attacks.
- 10 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting) · Hansard source
More
Clause 22 sets out, through schedule 1, consequential changes to the regulations in relation to enforcement and appeals. That is to ensure that the regulations work effectively in relation to the new entities brought into scope, such as managed service providers, data centres and large load controllers, so that the enforcement and appeal systems work as intended. Government amendment 19 makes a minor drafting correction. I commend clause 22 and schedule 1 to the Committee. Question put and agreed to. Clause 22 accordingly ordered to stand part of the Bill. Schedule 1 Enforcement and appeals Amendment made: 19, in schedule 1, page 86, line 33, at end insert— “(ea) in sub-paragraph (da), after ‘14A;’ insert ‘or’;”.— (Kanishka Narayan.) This amendment would make a minor drafting correction. Schedule 1, as amended, agreed to. Clause 23 Minor and consequential amendments etc Question proposed, That the clause stand part of the Bill.
Published records only — not a full account of an MP’s work. How we work →