Lincoln Jopp MP: speeches 2026
224 published records · newest first.
Speeches
- 9 Feb 2026 · Russian Influence on UK Politics and Democracy · Hansard source
More
It is difficult to know where to draw the line in our condemnation of Russian activity, but the hon. Gentleman makes a powerful point. He could also have mentioned the theft and indoctrination of thousands of children. I am sure that the whole House speaks as one in condemning such activities. The hon. Member for Kensington and Bayswater (Joe Powell) never misses an opportunity to raise the Abramovich billions, and he did not do so today. The hon. Member for North Herefordshire (Dr Chowns) cleverly weaved into this debate on Russian influence the issues of second jobs and electoral reform, which she refers to in most of her speeches. The hon. Member for Bolton West (Phil Brickell) talked about Nathan Gill and attempted to disavow us of the notion that he was just “one bad apple”—a point I will come back to. Although quite a lot of party politics has played out today, it is important that we do not turn a Nelsonian eye to that case, which is potentially one of the most obvious and worrying. I also thank the hon. Members for Leeds Central and Headingley (Alex Sobel) and for Tewkesbury (Cameron Thomas) for their contributions. The hon. Member for Tewkesbury quoted von Clausewitz, and shortly I will do the same. The right hon. Member for Oxford East (Anneliese Dodds) talked about the post-shame world. She made the interesting point that the normal constraints on normal activity seem to have been cast off. The hon. Member for Cardiff West (Mr Barros-Curtis) said that we need to treat disinformation as the core security threat that it is. I completely agree. The hon. Member for Llanelli (Dame Nia Griffith)—apologies to her constituents for my pronunciation—said that we do not focus enough on the manipulation of our own people and called for balance. I approach this debate by looking at three questions. Is the threat real? Is the perception of the threat high enough in the country and in this House, or should the Government do more to amplify it? Is the Government’s response sufficient? This is all crucial. The hon. Member for Tewkesbury will be delighted to hear the second bit of von Clausewitz of the day; as the Minister knows only too well, given his distinguished military career, we never tire of quoting von Clausewitz to each other in the Army. “The first, the supreme, the most far-reaching act of judgment that the statesman and commander have to make is to establish” the nature of the war that they are embarking on. So let us see the evidence on whether the threat is real and whether the perception of the threat is sufficiently real. In the strategic defence review of June 2025, the Government said: “The UK is already under daily attack, with aggressive acts—from espionage to cyber-attack and information manipulation—causing harm to society and the economy.” In the same month, in the national security strategy, the Government said: “The openness of our democracy and economy are national strengths. Therefore, it is vital to keep ahead of those who seek to exploit them with robust defences.” Is the threat perception high enough? I cannot remember which hon. Member mentioned Estonia, but I have the pleasure of serving on the Defence Committee; we visited Estonia and Finland in February last year. I can tell hon. Members that the proximity to the geographical border with Russia focuses the mind considerably. From memory, the Finnish people have a population of 4 million; they can put 3.5 million of them underground at a moment’s notice. They can field an army of 200,000 with two weeks’ notice. They, too, have cyber-resilience and anti-grey zone units that work with the Estonians and other Baltic states to counter the disinformation and grey zone activity. I feel that in this country, because of our geographical distance from Russia, we fail to have that same focus. But we must. Sir Alex Younger, the former head of MI6—and, as an aside, a former member of one of the finest regiments of foot guards there has ever been—gave evidence to the Defence Committee. He said that the United Kingdom’s digital attack surfaces are far broader and greater than those of a number of our European neighbours. Given that, as someone mentioned, geographical proximity is irrelevant in the world of information and cyber, we should be doing much more. We heard interesting evidence at the Defence Committee the other day from James Heappey, the former Armed Forces Minister, who needed to get quite a lot off his chest. He was worried about the number of documents coming across his desk that had said, “You cannot share this with Parliament. This is too secret.” It worries me that the desire for secrecy means that we have all involved ourselves in something of a conspiracy for the past 30 years. Ben Wallace was at the same session. He said that, from the mid-1990s onwards, Governments of all three colours had hollowed out defence, and they had done so because they wanted to spend their money on other things. It is the old choice between guns and butter: they chose guns, we chose butter. We need to amp up the threat perception in the House and, importantly, more widely in the United Kingdom. If not, those real balance-of-investment decisions that we need for our national security will not be made.
- 9 Feb 2026 · Russian Influence on UK Politics and Democracy · Hansard source
More
It is important to look at elections to the left of the ballot box, because it is not just about going down with a polling card and ID and putting a tick in a box. The hon. Member for Llanelli said it best: we need to be much more alive to the fact that we are being manipulated and manoeuvred by information and disinformation. We can use pencils and paper, sure, but there is a way more sophisticated game going on here, and it is pretty terrifying. I come back to my theme of amping up the threat perception. We need to re-arm very quickly, not only with hard power but in the minds of our own people, so that we build national resilience to face threats more effectively across the spectrum. For example, as the hon. Member for Caithness, Sutherland and Easter Ross (Jamie Stone) mentioned, we had the Russian spy ship and the threat to subsea cables—I am delighted that someone mentioned them. Importantly, when the Secretary of State took the decision to order the surfacing of the Astute-class submarine next to the Yantar to say, “We know what you’re doing and you need to pack it in,” he also made that information available in the newspapers to ensure that the public had that threat perception.
- 9 Feb 2026 · Russian Influence on UK Politics and Democracy · Hansard source
More
Of course.
- 9 Feb 2026 · Russian Influence on UK Politics and Democracy · Hansard source
More
Is the Minister aware that, as a result of actions by the Scottish and Welsh Governments, a loophole has been created whereby people living in Wales and Scotland can now make unlimited political donations to any political party or politician? Is that something that is going to be addressed by the Government?
- 9 Feb 2026 · Police Efficiency: Technology · Hansard source
More
I recently visited a major retailer in my Spelthorne constituency, and it reported that corporate systems for getting information to the police are so clunky that to transfer evidence of shoplifting, the police have to resort to sending round an officer to film the retailer’s footage on their body cam. As well as sorting out the technology within the police, will the Home Secretary encourage and reach out to big corporate retailer chains, so we have a seamless flow of information to drive down shoplifting?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
Will the Minister give way?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
To understand the impact of what we are discussing, we obviously look at the impact assessment. We in this place are often accused of simply making rules and passing laws with no real sense of the impact downstream, particularly on small businesses. Having worked in the tech sector for 10 years, with data centres and managed service providers, and worked to try to grow many small and medium-sized enterprises, I am acutely conscious of the need not to overburden them. It is clearly hugely important that the Government take account of the impact of the measures they are taking and the burdens they are imposing on small and medium-sized enterprises. To understand the impact of this measure, it is important to know two things: first, how many companies will be impacted and, secondly, how much it is going to cost. While I am sure that the Minister will say that this provision on critical suppliers is great, and all very clear, it cannot really be that clear. Page 110 of the impact assessment states: “DSIT is not able to estimate at this stage the number of SMEs or SME DSPs that will be designated as critical suppliers”; so we cannot tell how many there are. The same page also states: “Specific duties will be set through secondary legislation so the exact cost of security measures is not possible to estimate.” We do not know how many there are or how much the measure is going to cost, but Government Members will be whipped to say, “That’s okay—that can be done by someone else at another time.” We do not really have a strong sense of the impact on real-world businesses of what we are doing here. We also talked about the legal costs in an earlier sitting. I look forward to hearing the Minister’s reassuring words about how very clear the clause is and how it is not just a blank cheque, even though we do not know how many people it will affect or how much it will cost them.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
The Minister came back with an answer on proportionality, saying that it is not for Government to decide what is essential. He missed out the next bit, which is, “We’re just going to regulate critical suppliers and pass laws about them, but we don’t know how many there are, and we don’t know how much the policy is going to cost.” Would he accept that characterisation as the logical conclusion of what he said? The Minister also said that schools were not covered by the Bill. As far as I am aware, patient data and children’s data are two of the most precious things that we have, so I would like to know why schools are not covered by the Bill.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
Will the Minister give way?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
Having read the Bill, does my hon. Friend understand that if a managed service provider provides services to, say, a hospital—so it would be covered by the regulations—and a reportable event happens to the managed service provider, there is any obligation for the hospital trust to report it as well, or is it just the managed service provider that has the responsibility? If he is not clear on that, would he ask the Minister?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
I thank the shadow Minister for his reply to my hon. Friend the Member for Bognor Regis and Littlehampton. Is he as surprised as I am to read in the impact assessment that the hourly rate for a contract lawyer is to be £34 an hour rather than £300 to £500 an hour, which in my experience is the market rate?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
I am sorry, but that is nonsense. The footnote on the page that cites £34 an hour for a contract lawyer directs us back to the Office for National Statistics. I hope that the Minister lives in the real world—he has clearly worked in the business world—so he knows that that is nonsense. Does he agree that that pretty well undermines that section of the impact assessment?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
It is a pleasure to serve with you in the Chair, Ms McVey. Small and medium-sized enterprises are defined by the headcount of full-time employees, yet in the world of IT, particularly for managed service providers, data centres and digital service providers, that is not a helpful metric to understand size and scale. Did the Department consider reevaluating the size of digital and managed service providers based on the through-flow of transactions or data rather than headcount? When I worked in the world of tech, there was a ratio for headcount that was totally different from other sorts of businesses.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
I do not want to add spurious hypotheticals, so I will talk about the real world. I visited the Maypole special school in my constituency the other day. It has 20 members of staff and 18 pupils. It has people coming from as far away as Wandsworth. It books the transport, and the transport is paid for by the local education authority in which the pupil lives. It is clearly critical that children get to the school—just as it would be for a hospital. Would it be up to members of staff at the Maypole school to find out whether Addison Lee used a managed service provider or a data centre? That seems quite a tricky thing to know about and then to fulfil.
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting) · Hansard source
More
Will the Minister please clarify whether he thinks that, as page 102 of the impact assessment states, the hourly rate for a lawyer changing a contract is £34?
- 5 Feb 2026 · Water Infrastructure: Inspections · Hansard source
More
It is lovely to see the Secretary of State; the last time I saw her was in the Strangers Bar, when she was pulling a pint of Rebellion Overthrow—I can’t imagine why that stuck in my mind! The River Thames scheme has been in abeyance, essentially—in mid-project review—since May last year. Will the Secretary of State please knock some heads together at both the Environment Agency and Surrey county council, and get them to say something about what is happening at the River Thames scheme?
- 5 Feb 2026 · Business of the House · Hansard source
More
Pride in Place funding is about £5 billion directed at our most deprived areas. I think it is worked out on a constituency basis, and that constituencies have to hit a point on two indices of deprivation to qualify, and must therefore be what the Government call “double deprived”. I have significant pockets of deprivation in my constituency, particularly in parts of Stanwell, yet they do not qualify for Pride in Place funding because it is calculated on a constituency basis, which seems pretty unfair to me. Will the Leader of the House allow Government time for us to debate the Pride in Place funding formula, so that we can understand it, and bring such anomalies to the attention of the Government?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Given the scenario we just discussed, it is possible that a digital service provider would have an obligation to report under the Bill, but the parent company employing its services would not. Given the requirements for confidentiality that a client company may put upon a digital managed service provider, how can that conflict be managed?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Members on both sides of the Committee have referred frequently to the fact that the incident that took Jaguar Land Rover down would not have been covered by the Bill. JLR employs a digital service provider, in the form of Tata Consultancy Services. Would that provider not be covered, meaning that JLR is in scope?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
As I am sure my right hon. Friend remembers, once the Bloomberg leak had happened, many of us said to the Government that now that those things had turned out to be true, we should turn Lord Peter Mandelson inside out as if he had been outed as a spy; surely, had the Government done so, the things that were released over the weekend would have come out. Is he surprised, as I am, that the Government did not seem to do an investigation into Peter Mandelson subsequent to him being fired?
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Brian, from your side, what about, say, PPE, gloves or blood? There must be other things that are non-data that are, nevertheless, essential services. Brian Miller: I do not want to step out of my lane. There will be clinical stuff that absolutely would be essential. I would not be able to speak in any depth on that part of it; I purely look at the cyber element of it. As an organisation, we would be identifying those kinds of aspects. In terms of suppliers, you are absolutely right. We have suppliers that supply some sort of IT services to us. If we are procuring anything, we will do a risk assessment—that might be a basic risk assessment because it is relatively low risk, it might be a rapid risk assessment, or it may be a really in-depth assessment for someone that would be a critical supplier or we could deem essential—but there are absolutely suppliers that would not fall under any of that criteria for the board. The board is large in scale, with 40,000 users. It is the largest health board in the country.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q That is a very clear answer on the steps that have to be followed. Do you envisage that each regulator in, for example, the NHS Greater Glasgow and Clyde will follow the steps from their perspective? The first one might produce 20 SMEs that need to be in scope, and the next one might produce another 20, and so on. There might be a bit of overlap. Is that the way it is meant to work, or are all the regulators meant to get together and say that they have looked at it holistically, done the step test, and now have the answer? Kanishka Narayan: The way in which I would envisage it is that each individual regulator assesses the critical nature of the risk posed to its regulated operators. If a hospital has a third party supplier, and the presence and nature of its supply means that there is a critical risk exposure for the hospital, that would be in scope for some degree of regulation in the Bill. To your question, if there is a comparable but separate hospital in a part of England that is separately regulated, but has the same third party supplier, there is obviously a question of whether that third party supplier would end up being regulated twice if the criticality threshold is met. In that instance, and in other similar instances of multiple regulators covering the same third party supplier, I would expect a high degree of co-ordination. In fact, the provisions in the Bill, as well as my hopes for subsequent guidance, are focused on our efficiency and proportionality when there are multiple regulators. However, I think the assessment has to be undertaken by each regulator on a separate basis, because the question being assessed is not the nature, the sum risk, of the third party supplier in itself, but the risk posed by its relationship to the operator it is providing to—if that makes sense.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q One of my favourite aphorisms is, “Institutions get the behaviours they reward.” We had a cry from Amazon Web Services this morning about how, when a regulator deals with a company in the event of a cyber-security attack, please remember you are dealing with a victim. I have dealt with the ICO before. Maybe it was the company that I worked in and led, but there was a culture there that, if you had a data breach, you told the ICO. There was no question about it. How are you going to develop your reactions and the behaviours you reward in order to encourage a set of behaviours and cultures of openness within the corporate sector, bearing in mind that, as was said this morning, by opening that door, companies could be opening themselves up to a hefty fine? Stuart Okin: In the energy sector, we have that culture. It is one of safety and security, and the chief executives and the heads of security really lean into it and understand that particular space. There are many different forums where they communicate and share that type of information with each other and with us. Incident response is really the purview of DESNZ rather than us, but they will speak to us about that from a regulatory perspective. Ian Hulme: From the ICO’s perspective, we receive hundreds of data-breach reports. The vast majority of those are dealt with through information and guidance to the impacted organisation. It is only a very small number that go through to enforcement activity, and it is in only the most egregious cases—where failures are so egregious that, from a regulatory perspective, it would be a failure on our part not to take action. I anticipate that is the approach we will take in the future when dealing with the instant reporting regime that the Bill sets out. Our first instinct would be to collaborate with organisations. Only in the most egregious cases would I imagine that we would look to exercise the full range of our powers. Natalie Black: From Ofcom’s point of view, we have a long history, particularly in the telecoms sector, of dealing with a whole range of incidents, but I certainly hear your point about the victim. When I have personally dealt with some of these incidents, often you are dealing with a chief executive who has woken up that morning to the fact that they might lose their job and they have very stressed-out teams around them. It is always hard to trust the initial information that is coming out because no one really knows what is going on, certainly for the first few hours, so it is the maturity and experience that we would want to bring to this expanded role when it comes to data centres. Ultimately the best regulatory relationships I have seen is where there is a lot of trust and openness that a regulator is not going to overreact. They are really going to understand what is going on and are very purposeful about what they are trying to achieve. From Ofcom’s point of view it is always about protecting consumers and citizens, particularly with one eye on security, resilience and economic growth. The experience we have had over the years means that we can come to those conversations with a lot of history, a lot of perspective, and, to be honest, a bit of sympathy because sometimes those moments are very difficult for everyone involved.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
I meant operators of essential services. Kanishka Narayan: The Bill effectively specifies operators of essential services as large participants in the essential services sectors. I think that that definition is very straightforward. The hospital in this question would be an operator of an essential service. If the question extends to critical third party suppliers—
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I want to come back to that point. Chris, you said something like, “SMEs find it very difficult, if not impossible, to bear the regulatory burden, so we have to be very careful when designating SMEs as operators of essential services.” To me, that says that you think the Bill, as currently drafted, will place too much of a regulatory burden on SMEs. Is that correct? Chris Parker: I was referring to strategic and critical suppliers, which is a list of Government suppliers. We are advocating that the level of governance and regulatory requirement inside an organisation is difficult, and it really is. It requires quite a lot of work and resource, and if we are putting that on to too small a supplier, on the basis that we think it is on the critical path, I would advocate a different system for risk management of that organisation, rather than it being in the regulatory scope of a cyber-resilience Bill. The critical suppliers should be the larger companies. If we start that way in legislation and then work down—the Bill is designed to be flexible, which is excellent—we can try to get that way. As a last point on flexibility—this is perhaps very obvious to us but less so to people who are less aware of the Bill—there is a huge dynamic going on here where you have a continuum, a line, at one end of which you have the need for clarity, which comes from business. At the other you have a need for flexibility, which quite rightly comes from the Government, who want to adjust and adapt quite quickly to secure the population, society and the economy against a changing threat. That continuum has an opposing dynamic, so the CRB has a big challenge. We must therefore not be too hard on ourselves in finding exactly where to be on that line. Some things will go well, and some will just need to be looked at after a few years of practice—I really believe that. We are not going to get it all right, because of the complexities and different dynamics along that line. Carla Baker: This debate about whether SMEs should be involved or regulated in this space has been around since we were discussing GDPR back in 2018. It comes down to the systemic nature of the supplier. You can look at the designation of critical dependencies. I am sure you have talked about this, but for example, an SME software company selling to an energy company could be deemed a critical supplier by a regulator, and it is then brought into scope. However, I think it should be the SMEs that are relevant to the whole sector, not just to one organisation. If they are systemic and integral to a number of different sectors, or a number of different organisations within a sector, it is fair enough that they are potentially brought into scope. It is that risk-based approach again. But if it is just one supplier, one SME, that is selling to one energy company up in the north of England, is it risk-based and proportionate that they are brought into scope? I think that is debatable.
Published records only — not a full account of an MP’s work. How we work →