00:00:07
[music] Hello and welcome to TechTV. Today we’re going to be talking about the new cyber security and resilience bill which has been introduced in the UK in the last 24 hours and has had his first reading in parliament. Highlights of the bill including the fact that it has had an extension in the terms of the definition of what qualifies as critical national infrastructure. [snorts] So that this now includes a whole host of other organizations, not just the the big cloud and infrastructure companies, but also MSPs
00:01:00
and a large number of companies within the um ecosystem that provide uh support for these companies. So addressing what one P would possibly uh refer to as the supply chain dimension. Now there’s an interesting extra dimension here that we’ll come on to talk about in terms of enforcement and penalties and some of the powers that have been granted in terms of regulation. But I’m going to turn over to Pete uh to see uh what Pete’s first thoughts are on this before we introduce our guests.
00:01:38
Well, I actually think it’s fascinating. Long overdue, incredibly overdue. It’s a long it it’s absolutely imperative that cyber security should have been taken much much more seriously. Uh I wrote a book in 2005 suggesting that we were in a terribly parlor state. So we’re a long way off that. Um, I think the main thing, the thing I find most interesting is, I suppose, what you could call the Henry VII dimension in all of this because regulations can be introduced to legislation. That means that what we’re
00:02:13
introducing is something that’s equivalent to the cyber posture that the insurance industry is very, very keen on. And that’s something that really we needed to get into the heads of British business. This isn’t a question of just ticking a few boxes. This is about being aware of what the situation is and responding to it. And and our first guest here today um uh representing the VCSBR which is a think tank that is somewhat focused on this particular issue obviously by the the denotation of its name. Uh we
00:02:51
have uh James Morris. James, thank you very much for for joining us. >> No problem. >> Would you say a few words please just introducing to everyone who the CSBRR? >> Yes. So, we’re a uh a policy center dedicated to cyber security and business resilience. Uh looking at that inter that important interreationship between cyber security and resilience. um you know to come up with policy ideas and evidence-based research about what works from a policy point of view and you know
00:03:23
really looking at how we can address the changing nature of the threat landscape that we currently face. >> Thank you very much. And our our next guest um uh Pete if you’d like to introduce Carolyn. Well, Carolyn Harrison of Issue of Clarity, this is the area that you’re uh involved in, isn’t it? Cyber resilience. You think that’s basically where the world is going to go, isn’t it? >> Absolutely. Yes. Thank you for inviting me. And yes, um I feel equally passionate like I think most people on
00:03:56
on this um session in terms of um it is about time we did something about it. We we operate in a consultancy capacity with some tech behind us and if we were getting it right then we wouldn’t be having the breaches that we see almost daily in the media. Um you know and um and some of it doesn’t even get um declared. There’s a lot behind closed doors that people just literally push under the carpet. >> That’s one of the really interesting things isn’t it James? Why now? Why is
00:04:31
this this sudden, you know, for for as I’ve said for years and years and years, people haven’t really seemed to take this very seriously. Why now? >> Well, that’s an interesting question. I mean, you know, that the gestation of this bill has actually been, you know, probably over the last four or five years. I I remember uh the previous government, you know, beginning to sort of look look at it. But I but I suppose um given the the nature of the threat landscape that we that we’ve seen over
00:04:59
the the last year, the last two years that you know there’s a real imperative here to address that issue and you know this bill is designed to try and get some structure around regulation and you know it’s an interesting what’s landed is very interesting. I mean, we did a we did an assessment of the policy statement which came out in April. Um, you know, and looking at the draft looking at the bill that was published yesterday, I I don’t think there’s anything there’s anything particularly
00:05:28
surprising in it, but it’s interesting that you refer to the sort of Henry VII powers that are contained within this bill. And it’s a bit of a double-edged sword because if you take section three of the bill, which is a fairly substantial section, that’s all about what powers are going to be given to the secretary of state to uh determine things like um the the setting of strategic priorities for all the sexual regulators. Um it gives I mean Henry VII powers as in you know the secretary of
00:06:01
state can change the regulations without necessarily parliamentary scrutiny um for national security reasons and for any other reason. So actually there is a very large section of this bill which which is accretting a lot of power to the secretary of state as a kind of overarching regulator. Now I totally understand that governments um need to be in a position to be able to respond to changing threats to national security and changing uh technology. we we you know we are move we’re in a very very
00:06:34
fastm moving environment but one of the concerns which I’ll be raising is that when we give these kind of powers to the secretary of state you know there does need to be proper accountability and scrutiny of what those powers are and when changes are made there does need to be mechanisms of accountability u because my my my concern with the bill overall I suppose is that it’s it is quite a central izing piece of legislation uh accreating a lot of power into the hands of the government for for
00:07:08
partly for understandable reasons but we do need to be very careful that we look in detail at you know what is being proposed in that section of the bill don’t don’t we need that because you know this I I I’ve interviewed people for the past four years or so and they say that we’re at war um I I I met somebody in Panama from the State Department who said yes we’re at war because there is this continuous onslaught whether it be from cyber criminal gangs, nation states and also
00:07:44
uh you know organizations that are basically involved with cyber crime and nation states. >> Well, no, I think that does go to the heart of it. So I totally understand uh as I said that you know in a situation where there is threats to national security and that you know things need to be addressed very quickly that you there is a very strong argument to say that you do need to give secretary of state more power but there’s other sections which are about the inter relationship between the secretary of
00:08:14
state and the regulators and so the secretary of state is playing a role of making sure that there are strategic pri priorities set across the piece so we don’t get fragmentation. Now I understand that but I suppose what I’m I’m I’m also looking for is making sure that you business that is going to be impacted by these regulations um is also you know part of the consultation process that it’s not just something which is being imposed from above um because the danger of that is that we’re
00:08:46
going to expect that we’re going to expect the legislation to solve all of our problems. Now I I was a parliamentarian for 14 years and I was involved in a lot of bills and the thing about cyber security and resilience is and and this is I think a fundamental sort of philosophical point is we cannot expect legislation on its own to [clears throat] um solve all our problems. It may be able to harden our regulatory regime. As you say, you know, we we are sort of in a state of war. So, we need to be
00:09:20
mindful of that, but we’re not going to make fundamental progress unless we have a whole of society commitment to cyber security and resilience. And therefore, that I I just I just worry that we’ve got a this is that there’s a lot of centralization in this bill. And we need to make sure that as it as it begins to progress through parliament that there is scrutiny that we understand you know in more detail what is being proposed ask the right questions to make sure that we do get some bottomup engagement
00:09:52
in in you know the various powers which are being um which are being aortioned. >> Well Caroline Caroline sorry um how about that? Do you think that business will be able to enter into this? Do you do do you think that they will enjoy this or will they see this as >> they’re not going to enjoy it? They’re not going to enjoy it based on my many years of experience. Um we we’ve struggled as a nation. Um we’re not alone, but we struggle as a nation to get um businesses, particularly small
00:10:26
businesses, to just do basic cyber hygiene. Cyber Essentials was brought in to try and encourage people to, you know, do some practical steps, you know, to harden themselves, but and that was only brought in because people wouldn’t um couldn’t be bothered to do the the likes of ISO 27,0001, a standard that was for information security. So, I mean, there has been a lot of success with the likes of cyber essentials, but for most people, it’s a box ticking exercise. They don’t understand what
00:10:53
they’re doing. They know not what they do. Um and just just a point on the different sectors. I agree with you James that um and you Pete that that we’ve got a bit of a dichotomy there in terms of yes we we need to allow the relevant sectors to be involved and put practical things in place and as I understand it um the individual regulator for each sector is going to be open to interpreting some of this but but equally um you know education I’ve said it for don’t know how many years
00:11:27
unless you educate people as to what they’re doing why they’re doing it. Then you’ve got the other half which is well you’re going to have enforcement. I mean look at GDPR data protection. It it was seen as being toothless really. Um so the ICO is going to be looking after the M MSPs as we understand it and we’ve contacted them and they don’t have a plan yet. So yes, there’s a lot up in the air and I think I agree with you James, we need to be able to have a seat at the table. We need to be able to
00:11:56
advise. And just just a quick one, MSPs have never been seen as somebody that delivers security. They do it. And there’s a big difference between infrastructure, it delivering the backbone. You and a bit like software development. They’ve not been trained in security. There’s no security by design or privacy by design. >> Yeah. But how about this issue of mandatory breach reporting? We’ve needed that forever. I had arguments in 1989 about mandatory breach reporting. Yeah. I I was yanked into the cabinet office
00:12:31
because they were talking about cyber insurance. The cyber insurers cannot actually insure you unless they know what the picture is. How can you say we’re going to give you insurance if you don’t know how many attacks there are? So surely that’s a good thing. It >> is absolutely a good thing and and I you know I’m going back many years approached the insurance sector to say would you not incentivize businesses and give a reduced premium if they did certain things. They didn’t want to know
00:13:00
but so it’s really refreshing to know that now we’re actually you know they they are getting involved and they they I think have probably got the most power um to actually deliver this. So there’s um I’m hearing of largeish organizations that they’re saying um you’re not fit for purpose and therefore your insurance is going to be invalid. So I think that will hit probably have the strongest message particularly formemes. Yeah. Don’t I I don’t know if you agree James
00:13:29
I think that that that will resonate because they’re not insured. Well, James, I mean, that’s a good point, isn’t it? Because one of the things we’re meant to be in this AI age, people are talking about supply chains. One of the things that if you want to be in an AI age, you want to have efficiency. You want to be able to see through your supply chains, yet you don’t want the vulnerability of being connected to people who may not have adequate cyber security. >> No, I think absolutely. I mean, I I I
00:13:57
welcome the the I welcome those provisions in the bill around um managed service providers. Um you know, you you you look at some of the high-profile attacks that we’ve seen over the last sort of year and a half um that that probably not pointing fingers at anyone, but probably some of the vulnerabilities were coming from MSPs, IT outsource companies which had particular vulnerabilities. So I think that’s absolutely the right direction to go. Um and so and and and similarly with bringing data centers into the into the
00:14:30
definition of critical national infrastructure and all of that I think that is is is to be welcomed. Um I’m just picking up on Caroline’s point, the the the complexity that I see or potential complexity is again um you you’re looking at a new regulatory role for which I think in the bill they refer to the information um commission which I think they might proposing a a change of name of the ICO. Um but as Caroline said um I don’t think that currently the the the the information commission or the
00:15:04
ICO is sufficiently resourced to take on all the responsibilities that they’re going to be expected to do. If you look in the bill um there is lots of references to the information commission playing a role in in in sort of designation in certification in in the mandatory reporting regime um and so on and so forth. Now it might be the right place to locate it. There might you know that might be that might be fine. I think it does it raises some issues about the the resourcing of that particular organization to do all of
00:15:37
these things because as you say um mandatory reporting and again with the with this bill we we’re also um talking about the reporting of breaches which haven’t necessarily led to a kind of devastating collapse of a system. the one of the first of all you have the insurance issue which you’ve highlighted but then you also have the issue which we need it to be meaningful intelligence which can be used in order for us to understand the threat landscape on a day-to-day basis through the national
00:16:09
cyber security center the intelligence services and so on um so uh what I want to understand a little bit more about as we get into the debate on the bill is about h how all of those interreationships between the regulators is the new information commission, the national cyber security center to make sure that we don’t sort of inadvertently create some kind of labyrinthine system. >> It needs to be simple, understood, well resourced in order to be achieve the kind of hardening objective that we
00:16:40
want. Um so but I just have a few you know the concern is that we create a labyrinth of different of different people overseeing different bits and pieces without it being coherent. But surely in a sense we do need some centralization. I there there is a real feeling that this isn’t 11th hour. This is an hour after midnight. Um people are are scrabbling around at the moment. I can remember again back in 1989 the information commissioner’s office was called the data protection registra cuz
00:17:11
Margaret Thatcher hated the uh institution and she wanted to make it as meaningless as possible. Now we’re in the 21st century. we need to actually develop 20th century infrastructure and 20th century regulation very fast now. >> No to I mean I totally agree with that. Um it’s just about capacity and whether we make sure that the kind of lines of responsibility here are really clear about who’s doing what what responsibilities they’ve have and and how it all fits together. I say to you
00:17:43
the first reading my first reading of the bill uh yesterday afternoon you know picking up the number of times the information commission was being was being cited in clauses means that you know that’s going to be pretty fundamental. So we need to we need to get a clear understanding of how that organization is going to be sort of repurposed and resourced to do this jobs properly because it can’t do it as a kind of sideline of something else. As you say, this this is an important moment in the hardening of our approach
00:18:14
and we need to get it right. >> Carolyn, we put out a program last month where we were being we’ve been told that now um top executives, business executives are going to be targeted by cyber criminals. They’re going to use AI to target them. Um, and we’re als we were also told that there’s going to be an absolute tsunami of attacks from Southeast Asian scamming gangs who are going to be using AI and that they’re actually after those sorts of credentials. But that seems to be
00:18:49
outside the rem of what we’re talking about. I mean, this is an incredible world that we’re now addressing, isn’t it? This is business legislation, but then there is criminality that’s coming in and outside of that. I mean would those attacks by scamming gangs be seen as breaches? >> Well in theory yes they should be. Um um the the chief executive level or the seauite level has been the achilles heel of lots of organizations for quite a long time because there is a little bit
00:19:20
of um lousiness. I think I find that that you know the people that click on the on the the spam links and what have you can be the director the chief executive. So they’ve been a big target for for quite a while and and you know when you get access to somebody like the chief executive’s account, you can move money, you can do things. So you you the the the upside of the um uh of you know the rewards are great. So they’ll spend an awful long time trying to get to the right person. But yeah, it’s will will
00:19:54
the ICO as was and information commission going forward will it have the teeth to insist and ensure that the people take it as seriously as the rest of us. So not sure >> but again Caroline there’s there’s another issue here isn’t there which is traditionally the cyber security department has been seen as a block to uh actually achieving things and people have always tried to find ways around cyber security protocols. Uh chief executives would they like to actually report that they’ve been scammed? There
00:20:30
is a big problem and we we see this in cyber security quite a lot where people are actually enjoined to actually say look I was stupid. Nobody [clears throat] likes saying that they were stupid. Um >> this is where your education comes in because the thing is um you know you can you can put all the frameworks you know the the new calf framework and all of these things. the cyber assessment framework that a lot of this stuff will be sitting on and and it’ll be open to interpretation like we were saying for
00:20:57
depending on whether somebody’s got a low profile or a high-risisk profile as to how many of the the controls but um yeah if you I think education and explaining to to the world at large what these implications are they just think they have no responsibility um you know you think about when we brought in online banking and they they pushed the the devices at us to authenticate ourselves. But that didn’t take the um the responsibility and liability away from the banks because they were pushing it pushed on us and we
00:21:30
were like, “Well, it’s your fault. You lost it.” And lots of times they they would like reimburse us. But there is a sea change and we’re trying to say you’ve got to take some ownership. You’ve got to understand that you’ve got a part to play. But I don’t know if if a lot of Joe Public really believes that they have a responsibility. I don’t know what you think, but >> let let’s let’s let’s take that point. I I I um had a sort of a marginal runin
00:21:57
with the uh the the National Crime Agency when they’d said that they were introducing this uh legislation about um cyber and I’d said, “Well, what does that mean from the man on the street? Where are they going to report it?” And they hadn’t actually thought about that. So, James, are we taking cyber security seriously? So many people, so many small businesses say, “Well, no one would be interested in me.” >> Yeah. Well, I think that’s again this come back, this come back to this
00:22:26
fundamental point which is uh in order to change behavior, you know, you do need to have uh uh transparency and you need to have clarity of accountability and responsibility. I think that’s absolutely the case. But the broader point is that we still have a ma as you describing as as Caroline was saying we have a a big job of work to do in order to engage ordinary people if that’s the right way of describing it citizens small business people who don’t necessarily think they’re in the front
00:23:01
line to engage with this process and be part of this process. So o you know even s you know this bill which we’re talking about today was first announced in July 2024. Now since it was announced we’ve had a whole series of very high-profile attacks on large businesses which people recognize and it’s been on the BBC website as a top you know as a kind of top story. Now that might be having an effect of be beginning to change perceptions among among the broader swave of society that hold it a moment
00:23:37
something quite fundamental is happening here and the only way we’re going to make this legislation successful is to implement the legislation in tandem with this broader effort of engagement um which says you know we we we’ve got major issues here with bad guys you know state actors and others and links to criminality trying to unpick our critical national infrastructure and our economic resilience and we need to understand that this is a kind of s you know this is an existential threat to
00:24:12
the national security of the country and we and that we’re not really we haven’t really begun to have that debate and I’d like to that’s why I was encouraged actually when they when they published the press notice around the cyber security and resilience bill that they did they were much um much clearer about setting it in the context of national security than they had been even when they started talking about the bill 15 months ago. And I think that’s been the impact of these high-profile attacks and
00:24:40
the changing nature of the debate around the issue. >> I mean, it’s refreshing to see this redefinition of infrastructure, isn’t it? There used to be the time when I rang rang up GCHQ, they would say, “Why are you ringing us? Don’t you know what the GC stands for in GCHQ? Now >> we’re actually broadening that because the infrastructure is the most important thing. >> Yeah, absolutely. And if you look at you know they if you look at the I mean even even today you can see there was uh the
00:25:14
GDP figures came out and there was an estimation that they were depressed because of the result of the JLR cyber attack because car production was down etc etc and there was some estimation made in a report which the government published alongside the bill about the impact on the economy and the impact on uh GDP growth of cyber cyber attacks. So again that’s a useful link the link to national security the link to economic resilience which is not something you know which is not something which has
00:25:47
been fully and properly articulated and communicating that out as we go through the process of making sure that we have transparency and clarity uh in the legislation itself. The two need to go in hand in hand or we may find ourselves you know it takes a long time to get a bill through parliament. it it will probably take um you know north of you know 18 months to get this bill on the statute book by which time um technology would have changed and we might find it’s out of date before we’ve even got
00:26:16
there >> just as well we have those Henry VII powers and of course a jugular lander thing must must mean quite a lot to you because it’s your former constituency isn’t it >> well it’s very close by yeah I mean people in my I was I was the MP for Halo and Rally Regis so um you know the the supply chain there kind of extended out from Sihal into various other parts of the West Midlands and you know so so the fact that JLR had been um sub has has sort of changed the nature of the debate
00:26:46
because um and changed the nature of people’s perceptions about about what’s going on. >> Obviously the Jaguar Land Rover attack was something that has been in all the headlines and had a big impact on the economy. [sighs and gasps] But when we’re talking about educational awareness, you can hardly say that a big organization like Jaguar Land Rover with a CISO weren’t aware of the threats. Um, and even if we impose large fines, they’re going to pale into insignificance compared with the damage
00:27:19
done to Land Rover by the actual attack itself. So are we really going to change attitudes with these sort of penalties when it should be very obvious to the big organizations out there exactly the size of the threat anyway? What difference is this going to make? And do we do we have any confidence that this using a stick rather than a carrot approach is actually going to be effective? >> Well, I don’t know whether and it’s an interesting point. I mean um the evidence uh around you know whether
00:27:53
whether fines and and so on are going to make a difference you know I think again it it it does um it does point to this point about transparency and clarity. Um but but but as you say it I it also speaks to a changed kind of behavioral culture at the at the level of the boardroom that you know that we’re still in a position where lots of large organizations haven’t got a transparent view about the risks they face uh the inter relationships and so on and so forth. And so with with this legislation, it it kind of enables
00:28:30
certain things to happen and it needs to go in combination with um a a kind of changed behavioral culture at the boardroom level that in understanding day-to-day risk in the business and understanding the kind of strategic implications of that at the boardroom uh at the boardroom level. Um so I think it’s a it’s a combination of of carrot and stick transparency and clarity helps us. Um and then we need this behavior to continue to to see this kind of behavioral change in that cyber security
00:29:07
and resilience is not just some kind of sideline. It’s fundamental to the operational uh the operations of businesses. It’s not just something that’s you know covered by the IT department. It’s something which is absolutely fun fundamental strategic importance to the chief executive, the chairman and whoever else so that companies kind of harden their protections. >> Yeah. talk about the board level and the the attitudes at board. >> Up until now, the the possibly the the
00:29:38
most critical skill required on board is some sort of financial literacy because that’s largely how uh boardroom responsibility is seen. [sighs and gasps] Surely we need to be introducing a mandate around technological literacy at some extent on boards. Um so and we didn’t we didn’t actually see a change in behavior in areas like financial fraud or in health and safety when initial fines were introduced. It was only once fines were actually made directly applicable to individual directors rather than to the
00:30:17
company itself that we actually saw a change in attitudes there at board level towards financial crime and um financial fraud and also to health and safety. So are we missing a trick here? Are we using a stick in the wrong direction? Yeah, I mean I I I it mean I’m not I’m not uh I mean I think that the fine elements which are described in the in the bill, you know, that they’re a start and um as you say the the the the sort of the most important thing is that whatever this bill is attempting to do
00:30:56
that it provides a catalyst for behavioral change. um that we get cyber security and resilience you at the front and center of the boardroom that there’s an understanding of the risks and there’s an understanding of the potential you know the potential reputational damage the financial damage and the damage to the supply chain um and that we understand how we’re going to deal with that and mitigate it. James, there’s there’s also a big concern here that too much in the way of
00:31:31
a a stick approach uh may be effective in changing attitudes, but it could have a dilitterious effect if we end up creating a a chief incident scapegoat officer. If if that’s what the CISO becomes, uh we don’t want to treat the CISO as a scapegoat. Um, it needs to be something where any fines are effective. They change attitudes. They change behavior, but they don’t make it an impossible task for the CISO. >> Well, that’s that’s the point I was making earlier about um, you know, that
00:32:09
section of the bill that we were discussing where there are a lot of powers um, especially especially around directing regulators that are that are in the hands of the Secretary of State. Um, and it talks about, you know, putting duties on the Secretary of State to consult with the regulators to make sure that they’re happy. But what I want to see is making sure that business is engaged at that point. So, so that um you know so that all layers in this effort are are are interrelated that we
00:32:42
don’t get a gap um uh opening up between the regulatory regime and those people who are grappling with the strategic issues in companies and that they feel as though somehow there’s some kind of remote process which you know which they don’t have any agency in. That’s that’s the that’s the danger that I can see um if we don’t get all of the layers of this legislation and how it’s actually going to be operationalized right. >> Okay. Well, Caroline, you see that?
00:33:16
Um what’s your take on it? You’re you’re you’re you’re very close to these people. >> Yeah, absolutely. I think um that you know as as we was just saying earlier that um you know who who ultimately in an organization is going to be responsible for the cyber resilience and the protection of it. Uh is it the is it the seauite is it the chief exec or is it the CISO? Um and um my uh research out in the marketplace is that many people don’t want to be a CISO anymore because they just feel that they
00:33:51
don’t have the power but they’re being held accountable and responsible. So I think there is a job to be done and whether the bill can address this probably not. Um but it’s this back to the education and saying well this is more than one person’s role as I think James was saying earlier this is the whole organizational’s role and and you know if you’re in manufacturing like J um Land Rover Jaguar that you know who’s responsible for where you go between it and OT I mean who’s who’s got that and I
00:34:21
think what happens is it falls in big chasms of gaps between departments you know the biggest I find with the organizations we deal with is um is internal communications and accountability responsibility fingerpointing well it’s that’s not our responsibility but if we deal with an organization say and we’re looking at you know cyber we’re looking at PCI which is the framework for taking payments and data protection there might be three completely different departments and they don’t talk to each
00:34:52
other and what’s the difference they’re all the same all about protection aren’t they >> okay Well, that was the point that I I think James was making earlier. I think that there’s a lot to chew over. Uh we do seem to be papering over the cracks at the moment, but uh at least we’re doing that. Uh well guys, I think an enormously interesting debate and we’re very grateful to our guests for joining us and sharing us with some of their thoughts. Um it’s only obviously the
00:35:26
first reading in Parliament. We still have a long way to go here and possibly we’re looking about 18 months time potentially before this becomes law and there’s going to be plenty of time for a lot of lobbying and a lot of input. So it’ll be very interesting to follow this as it develops and we look forward to having you guys back potentially to uh share further thoughts as things unfold. Um, thank you all very much and uh hopefully uh we will have a a a situation here where we have legislation
00:35:59
that once it is finally on the statute book is refined to an extent that it really does change the attitudes and behaviors in the way that we really need. Thank you very much. >> Thank you. >> [music]




