Skip to main content

Proceeding contribution from Lord Vaizey of Didcot (Conservative) in the House of Lords on Monday, 7 September 2026. It occurred during Committee proceeding and Debate on bill on Cyber Security and Resilience (Network and Information Systems) Bill.


Cyber Security and Resilience (Network and Information Systems) Bill

My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.

The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.

6 pm

We all know what the Minister is going to tell us: that this is the wrong Bill for such an amendment and that there is a Home Office review. I hope that we will hold her to account for a date and timeline for when this review might come out, and some semblance of co-ordination between government bodies on all the legislation and regulations that need to be brought together and updated to provide us with a framework that supports the work that needs to be done to protect our digital infrastructure, as well as an explanation of why there has been such a delay from the Home Office on such an urgent piece of legislation.


Secondary information

Type
Proceeding contribution
Reference
859 c193GC 
Session
2026-27
Chamber / Committee
House of Lords Grand Committee
Subjects
Data protection Codes of practice Appeals Cybercrime Digital technology Fines Qualifications Ministerial powers National security Parliamentary scrutiny Research Regulation Small businesses Testing Skilled workers Supply chains Henry VIII clauses Cybersecurity UK Cyber Security Council
Legislation
Computer Misuse Act 1990
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 to 2026-27
Link
View this Proceeding contribution on hansard.parliament.uk