Lincoln Jopp MP: speeches
327 published records · newest first.
Speeches
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Given the scenario we just discussed, it is possible that a digital service provider would have an obligation to report under the Bill, but the parent company employing its services would not. Given the requirements for confidentiality that a client company may put upon a digital managed service provider, how can that conflict be managed?
- 5 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting) · Hansard source
More
Members on both sides of the Committee have referred frequently to the fact that the incident that took Jaguar Land Rover down would not have been covered by the Bill. JLR employs a digital service provider, in the form of Tata Consultancy Services. Would that provider not be covered, meaning that JLR is in scope?
- 4 Feb 2026 · Lord Mandelson · Hansard source
More
As I am sure my right hon. Friend remembers, once the Bloomberg leak had happened, many of us said to the Government that now that those things had turned out to be true, we should turn Lord Peter Mandelson inside out as if he had been outed as a spy; surely, had the Government done so, the things that were released over the weekend would have come out. Is he surprised, as I am, that the Government did not seem to do an investigation into Peter Mandelson subsequent to him being fired?
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Brian, from your side, what about, say, PPE, gloves or blood? There must be other things that are non-data that are, nevertheless, essential services. Brian Miller: I do not want to step out of my lane. There will be clinical stuff that absolutely would be essential. I would not be able to speak in any depth on that part of it; I purely look at the cyber element of it. As an organisation, we would be identifying those kinds of aspects. In terms of suppliers, you are absolutely right. We have suppliers that supply some sort of IT services to us. If we are procuring anything, we will do a risk assessment—that might be a basic risk assessment because it is relatively low risk, it might be a rapid risk assessment, or it may be a really in-depth assessment for someone that would be a critical supplier or we could deem essential—but there are absolutely suppliers that would not fall under any of that criteria for the board. The board is large in scale, with 40,000 users. It is the largest health board in the country.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q That is a very clear answer on the steps that have to be followed. Do you envisage that each regulator in, for example, the NHS Greater Glasgow and Clyde will follow the steps from their perspective? The first one might produce 20 SMEs that need to be in scope, and the next one might produce another 20, and so on. There might be a bit of overlap. Is that the way it is meant to work, or are all the regulators meant to get together and say that they have looked at it holistically, done the step test, and now have the answer? Kanishka Narayan: The way in which I would envisage it is that each individual regulator assesses the critical nature of the risk posed to its regulated operators. If a hospital has a third party supplier, and the presence and nature of its supply means that there is a critical risk exposure for the hospital, that would be in scope for some degree of regulation in the Bill. To your question, if there is a comparable but separate hospital in a part of England that is separately regulated, but has the same third party supplier, there is obviously a question of whether that third party supplier would end up being regulated twice if the criticality threshold is met. In that instance, and in other similar instances of multiple regulators covering the same third party supplier, I would expect a high degree of co-ordination. In fact, the provisions in the Bill, as well as my hopes for subsequent guidance, are focused on our efficiency and proportionality when there are multiple regulators. However, I think the assessment has to be undertaken by each regulator on a separate basis, because the question being assessed is not the nature, the sum risk, of the third party supplier in itself, but the risk posed by its relationship to the operator it is providing to—if that makes sense.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q One of my favourite aphorisms is, “Institutions get the behaviours they reward.” We had a cry from Amazon Web Services this morning about how, when a regulator deals with a company in the event of a cyber-security attack, please remember you are dealing with a victim. I have dealt with the ICO before. Maybe it was the company that I worked in and led, but there was a culture there that, if you had a data breach, you told the ICO. There was no question about it. How are you going to develop your reactions and the behaviours you reward in order to encourage a set of behaviours and cultures of openness within the corporate sector, bearing in mind that, as was said this morning, by opening that door, companies could be opening themselves up to a hefty fine? Stuart Okin: In the energy sector, we have that culture. It is one of safety and security, and the chief executives and the heads of security really lean into it and understand that particular space. There are many different forums where they communicate and share that type of information with each other and with us. Incident response is really the purview of DESNZ rather than us, but they will speak to us about that from a regulatory perspective. Ian Hulme: From the ICO’s perspective, we receive hundreds of data-breach reports. The vast majority of those are dealt with through information and guidance to the impacted organisation. It is only a very small number that go through to enforcement activity, and it is in only the most egregious cases—where failures are so egregious that, from a regulatory perspective, it would be a failure on our part not to take action. I anticipate that is the approach we will take in the future when dealing with the instant reporting regime that the Bill sets out. Our first instinct would be to collaborate with organisations. Only in the most egregious cases would I imagine that we would look to exercise the full range of our powers. Natalie Black: From Ofcom’s point of view, we have a long history, particularly in the telecoms sector, of dealing with a whole range of incidents, but I certainly hear your point about the victim. When I have personally dealt with some of these incidents, often you are dealing with a chief executive who has woken up that morning to the fact that they might lose their job and they have very stressed-out teams around them. It is always hard to trust the initial information that is coming out because no one really knows what is going on, certainly for the first few hours, so it is the maturity and experience that we would want to bring to this expanded role when it comes to data centres. Ultimately the best regulatory relationships I have seen is where there is a lot of trust and openness that a regulator is not going to overreact. They are really going to understand what is going on and are very purposeful about what they are trying to achieve. From Ofcom’s point of view it is always about protecting consumers and citizens, particularly with one eye on security, resilience and economic growth. The experience we have had over the years means that we can come to those conversations with a lot of history, a lot of perspective, and, to be honest, a bit of sympathy because sometimes those moments are very difficult for everyone involved.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
I meant operators of essential services. Kanishka Narayan: The Bill effectively specifies operators of essential services as large participants in the essential services sectors. I think that that definition is very straightforward. The hospital in this question would be an operator of an essential service. If the question extends to critical third party suppliers—
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I want to come back to that point. Chris, you said something like, “SMEs find it very difficult, if not impossible, to bear the regulatory burden, so we have to be very careful when designating SMEs as operators of essential services.” To me, that says that you think the Bill, as currently drafted, will place too much of a regulatory burden on SMEs. Is that correct? Chris Parker: I was referring to strategic and critical suppliers, which is a list of Government suppliers. We are advocating that the level of governance and regulatory requirement inside an organisation is difficult, and it really is. It requires quite a lot of work and resource, and if we are putting that on to too small a supplier, on the basis that we think it is on the critical path, I would advocate a different system for risk management of that organisation, rather than it being in the regulatory scope of a cyber-resilience Bill. The critical suppliers should be the larger companies. If we start that way in legislation and then work down—the Bill is designed to be flexible, which is excellent—we can try to get that way. As a last point on flexibility—this is perhaps very obvious to us but less so to people who are less aware of the Bill—there is a huge dynamic going on here where you have a continuum, a line, at one end of which you have the need for clarity, which comes from business. At the other you have a need for flexibility, which quite rightly comes from the Government, who want to adjust and adapt quite quickly to secure the population, society and the economy against a changing threat. That continuum has an opposing dynamic, so the CRB has a big challenge. We must therefore not be too hard on ourselves in finding exactly where to be on that line. Some things will go well, and some will just need to be looked at after a few years of practice—I really believe that. We are not going to get it all right, because of the complexities and different dynamics along that line. Carla Baker: This debate about whether SMEs should be involved or regulated in this space has been around since we were discussing GDPR back in 2018. It comes down to the systemic nature of the supplier. You can look at the designation of critical dependencies. I am sure you have talked about this, but for example, an SME software company selling to an energy company could be deemed a critical supplier by a regulator, and it is then brought into scope. However, I think it should be the SMEs that are relevant to the whole sector, not just to one organisation. If they are systemic and integral to a number of different sectors, or a number of different organisations within a sector, it is fair enough that they are potentially brought into scope. It is that risk-based approach again. But if it is just one supplier, one SME, that is selling to one energy company up in the north of England, is it risk-based and proportionate that they are brought into scope? I think that is debatable.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Going back to our conversation with the head of IT security and compliance at NHS Greater Glasgow and Clyde and what could be designated an operator of essential services, and our subsequent conversation with Palo Alto, how do you envision that bit of the Bill working? Taking Glasgow as an example, while neither of us are doctors, we both broadly know what happens in hospitals—and there is also a doctor sitting to my right on the Committee, should we need one. On the example that I gave, given what is written in the Bill, how do you think it should work? Kanishka Narayan: Do you mean operators of essential services, or critical suppliers, as in the third party element?
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q To come back to Dr Spencer’s original question about the scope of the legislation, the current situation, as I understand it, is that there is a carve-out for small and medium-sized enterprises because we do not want to put too much regulatory burden on them, but, under the new proposed legislation, operators of essential services that are SMEs will be designated by their regulator. That brings us back to the question of which regulator that would be. Do you currently use that designation for operators of essential services, or would you have to do a piece of work, presumably looking at a number of different regulators’ points of view, to designate the operators of essential services? Brian Miller: We would work with the Scottish Health Competent Authority as our regulator; I cannot speak for other regulators and what that might look like. We are doing work on what assurance for critical suppliers outside the Bill looks like just now, and we are working across the boards in Scotland on identifying critical suppliers. Outside of that, for any suppliers or any new services, we will assess the risk individually, based on the services they are providing. The Bill is really valuable for me, particularly when it comes to managed service provision. One of the questions I was looking at is: what has changed since 2018? The biggest change for me is that identity has went to the cloud, because of video conferencing and stuff like that. When identity went to the cloud, it then involved managed service providers and data centres. We have put additional controls around that, because the network perimeter extended out into the cloud. We might want to take advantage of those controls for new things that come online, integrating with national identity, but we need to be assured that the companies integrating with national identity are safe. For me, the Bill will be a terrific bit of legislation that will help me with that—if that makes sense.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q To be very clear, the three regulators we had here today were the Information Commissioner, Ofgem and Ofcom. If they thought that they had a locus because of something that that hospital did, all three would do the step test, they would come up with their bucket of SMEs that they wanted to bring into scope, and those would be added together and that would be the impact. Kanishka Narayan: Yes, I guess, added together in the sense that they would be separately regulated, but they would all come within the scope of the regulations. Where there is an overlap in the party being regulated, my hope is that the Bill provides for individual regulation, but is very much open to the prospect of a lead regulator engaging in a softer way with the other regulators, as long as each regulator feels that that has assured them of the risk.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q Sorry, I misspoke. I mean an SME that is deemed a critical supplier. Who is going to deem them so? Which of the many regulators at play in that hospital is going to decide who is a critical supplier? Kanishka Narayan: There are two things to say on this. There is at least a four-step test on the face of the Bill for what would qualify as a critical supplier. First, a critical supplier has to supply to an operator of an essential service, in this case the hospital. Secondly, the supplier itself must engage with important network and information systems. Thirdly, the disruption to that third party supplier would have to cause a material disruption to the operator in question—in this case, if the third party supplier falls over from a cyber-security point of view, there would be material and business continuity disruption to the hospital. Fourthly, not only that, but that disruption would have to be sufficiently severe in its impact to be in scope. That is one set of things. Underlying that is a further test in the Bill, whereby alternative provision of that third party supply could not be secured in a practicable way. The combination of those tests means that the scope set out for the critical third party suppliers is extremely tight and robust. Then there is still the question, having gone through that five-step test, of the particular burden placed on relevant suppliers in scope. My expectation and hope would be that regulators take a much more proportionate approach there than to set the precise same conditions on those suppliers as they do on the operator in question; in particular, that the burden on them is placed specifically in sight of the directional risk that they pose to the operator, rather than the risk in sum for that third party supplier. The first thing is therefore that the Bill clearly specifies a very tight scope. The second is that it does not seem to me, as a relative novice to both the medical world and cyber-security, unusual to have a specification of this nature in a Bill. Given my professional context, I am particularly conscious of the very clear and critical third party comparable requirement in the Financial Services and Markets Act 2000, which focuses on both cyber-security and supply chain risks. That has worked relatively proficiently in that context, so I hope that there are some good lessons to learn from that.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting) · Hansard source
More
Q I want to make sure I have understood exactly. Is the regulator going to tell you who your operators of essential services are, or are you going to tell the regulator? Brian Miller: I think we would work with the regulator, but we are looking for more detail in any secondary legislation that comes along. We have read what the designation of critical suppliers would be. I would look to work with the Scottish Health Competent Authority and colleagues in National Services Scotland on what that would look like. Stewart Whyte: On how we would make that decision, from our perspective we are looking at what the supplier is providing and what sort of data they are processing on our behalf. From the NHS perspective, 90% of the data that we process will be special category, very sensitive information. It could be that, from our side, a lot of the people in the supply chain would fall into that designation, but for some other sectors it might not be so critical. We have a unique challenge in the NHS because of the service we provide, the effect that cyber-crime would have on our organisations, and the sensitivity of the data we process.
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Do either of the other witnesses have anything to say on that? Jill Broom indicated dissent. Dr Sanjana Mehta indicated dissent .
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q On the question of closer alignment, can you give us a sense from the international picture of whether certain regulatory regimes raise the barrier to terrorists or criminals so high that they are left alone? Is that a national thing or a company-based thing? Where are the flow lines of attack and threat? Is it on a national or a corporate basis? Stuart McKean: I do not think the cyber-criminal really cares, to be blunt. They will attack anywhere. You can, of course—
- 3 Feb 2026 · Cyber Security and Resilience (Network and Information Systems) Bill (First sitting) · Hansard source
More
Q I appreciate that. My question was about where that leads them to attack, on the basis that they will take the route of least resistance. Where is that? Is that an international thing, a national thing or a corporate thing? Stuart McKean: It is probably across all three, to be quite honest with you. It is very dependent on what they want to achieve, whether it be an economic attack or a targeted attack on a corporate entity. I do not think it has those boundaries—I genuinely think it is across the whole industry and the whole globe. The reality is that cyber-attacks everybody. We are being attacked every day. I do not see it as an international boundary, or a UK thing or a US thing. It is generally across the globe.
- 2 Feb 2026 · Support for Veterans · Hansard source
More
Thank you, Mr Speaker. Whose job is it to protect and enhance the moral component of fighting power?
- 2 Feb 2026 · China and Japan · Hansard source
More
I just want clarification on the Members of this House who were formally sanctioned. The Prime Minister said: “President Xi said to me that means all parliamentarians are free to travel to China”. Does that mean that they are no longer legally sanctioned, and did he get that in writing?
- 2 Feb 2026 · US Department of Justice Release of Files · Hansard source
More
When the Prime Minister sacked Lord Mandelson as the American ambassador, Ministers came to the Dispatch Box and I pointed out to them that for the whole time he was our ambassador he had been subject to politically fatal kompromat, which left him open to leverage—as it finally played out. I said that if we had found out he was spying for Russia or China, we would be turning every single aspect of his time in office inside out, to find out the truth, and the Government said, “Well, he’s been sacked.” Does the Minister regret the fact that, following Mandelson’s sacking, the Government did not do the sort of due diligence and inquiries that might have unearthed the documents from the Department of Justice?
- 29 Jan 2026 · Encouraging Exports · Hansard source
More
Defence and aerospace make up a huge element of our export business. As the Minister knows, plans without resources are hallucinations. The defence investment plan was promised to us in the autumn, and then by the end of the year, but it is still not there. When will the Government get their act together and stop dithering over the defence investment plan so that we can fuel our export economy?
- 28 Jan 2026 · British Indian Ocean Territory · Hansard source
More
Does my right hon. and gallant Friend agree that this could well be a case of, “If you can keep your head when all about you are losing theirs, it is possible that you have failed to appreciate the gravity of the situation”?
- 28 Jan 2026 · British Indian Ocean Territory · Hansard source
More
I thank the hon. and gallant Member for his intervention. If he wants to do so, I suggest that he takes it outside, as they say. I am very time-constrained, but I want to pay tribute to my hon. Friends on the Conservative Benches who have informed the debate with incredibly detailed research and knowledge. I have been delighted to see the Minister’s PPS running backwards and forwards from the officials’ Box, because I was rather hoping that the summing up would not simply be a reheating of the opening remarks made by the Minister with responsibility for the Indo-Pacific, the Under-Secretary of State for Foreign, Commonwealth and Development Affairs, the hon. Member for Feltham and Heston (Seema Malhotra). There have been substantive points made from these Benches, which I hope will be answered in the summing up. I am very time-constrained and a lot of points have already been covered. In search of inspiration I was wondering what I might add to the debate, so I will read out a piece of casework which, although not relevant to the Chagos islands, is an interesting comparator. It comes from a member of the public who had written to his bank manager. I suppose I owe it to him to anonymise him, so I need to come up with some sort of pseudonym. I will call him Mr Powell. Mr Powell wrote to his bank manager: “Dear Sir, a number of years ago, I inherited a large seven-storey home in Mayfair. I am incredibly lucky and I acknowledge that fact. It is far too big for me to live in. I live solely in half of the ground floor. For as long as I can remember, I have had Americans living on the other floors. I like these Americans, so they live there rent-free. What I am proposing, sir, is that I give you, the bank, this house. I then propose to pay you, the bank, rent above the market rate not only for me, but for all the Americans who live upstairs. I would be very grateful for your advice on this issue.” The bank manager wrote back to Mr Powell: “Dear Mr Powell, are you okay? I am concerned for your mental state, because what you are proposing would appear to be an act of GREAT STUPIDITY.” [ Laughter. ] The bank manager went on to make the following four points: “First, you do not need to do this at all. Secondly, it will cost you a fortune. Thirdly, you do realise that at the end of all this you will have given away your house? Fourthly, on a personal note, were these arrangements ever to become public, I fear that your neighbours would laugh at you. Yours, the Bank Manager.” I simply leave that analogue there, to let my colleagues in so that we may wrap this debate up.
- 28 Jan 2026 · British Indian Ocean Territory · Hansard source
More
I thank the and hon. and incredibly loyal Member for giving way. Does he realise that, as the result of a UN judgment in 1965, the United Kingdom was required to enter into negotiations with Argentina over the future of the Falkland Islands? Those negotiations continued until 1982, when they were concluded in a rather different way from that envisaged by the UN.
- 28 Jan 2026 · British Indian Ocean Territory · Hansard source
More
It is a pleasure to follow the hon. Member for Romford (Andrew Rosindell). With his final words on self-determination echoing in my ears, I have no doubt he will be reflecting on whether he is going to afford the people of Romford the same rights that he is demanding for the Chagossian people.
- 28 Jan 2026 · British Indian Ocean Territory · Hansard source
More
My hon. Friend will have heard the Minister for the Indo-Pacific, the hon. Member for Feltham and Heston (Seema Malhotra), list the preconditions before treaty ratification can take place. I am pretty sure that I asked about America, and she said that there needed to be an exchange of letters. The position of the American Administration is that the Chagos deal as proposed by His Majesty’s Government would be “an act of GREAT STUPIDITY”. We seem quite a long way from getting American agreement and acquiescence. Does my hon. Friend, like me, foresee that we would need a protracted period of negotiation with the United States of America to get its acquiescence to this deal?
Published records only — not a full account of an MP’s work. How we work →