Lords Grand Committee
3 septembre 2026
Lords Grand Committee
Plus d'options
Source officielle
Décalage
Décalage de la transcription
0s
Exporter
Replay
Versions de cette vidéo
Les transcriptions peuvent légèrement différer d'une version à l'autre.
00:05 - 00:25
Intervenant 1
The House is now sitting, the committee will adjourn as soon as the division bells are rung and resume after 10 minutes. Grand Committee on the Cyber Security and Resilience Network and Information Systems Bill. In clause 15, amendment 17, Baroness Neville-Jones.
00:25 - 03:25
Intervenant 2
My Lords, I rise to present amendment 17 in my name. I'm also going to take amendment 28 with it as it's closely related. 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. Neither is it, this amendment that I'm presenting doesn't affect the amendment which the government I think is going to present immediately afterwards. Now as drafted, clause 15 gives the very strong impression that an incident, quote, capable of having, unquote, an adverse effect on security must be reported.
Now if this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident which is, quote, likely to have an adverse effect. Indeed, I think it's a widely held view that the, and it's certainly the case in the industry, and it's a point with which however I agree, that the likely to have would be far too wide a definition and would lead to extensive over-reporting and quite undue and unnecessary burden on regulators. So looking at the drafting, I ask myself the question, well, what is the point of the capable of having definition in clause 15? And I'm going to put forward a hypothesis which it would be very helpful if the minister could confirm is the correct understanding of the existing draft and does not mean, does not mean that all incidents capable of having an adverse effect on security will need to be reported. Now is it right to say that the definition in clause 15 of what constitutes a, quote, incident applies across the whole of the regulations and therefore feeds into security as well as reporting duties?
That's to say, firms have a preventative duty to defend against what could be, what could happen as well as what is likely to happen. That's a preventative duty. So can the minister confirm that the phrase capable of having applies to firms to have, that they should have adequate preventative policies, but is not, and this is where the point comes in, is not the trigger for an incident to be reported as in each case this requires it to have affected or be affecting the system.
La suite de la transcription est réservée aux clients Pro
Débloquez la transcription complète, le chat et toutes les fonctionnalités d'analyse avec Polyfact Pro.