VerbatimParliament, as it happens

Cybersecurity: Infrastructure

Asked by Dan AldridgeLabourDepartment for Science, Innovation and TechnologyTabled Answered 28 March 2025UIN 40033

The question

To ask the Secretary of State for Science, Innovation and Technology, what assessment he has made of the effectiveness of (a) cyber security laws and (b) supporting regulatory guidance in preventing supply chain attacks on critical (i) services and (ii) infrastructure.

Answered by Feryal Clark

Our current cyber security laws – the NIS Regulations (2018) – are inherited from the EU and are the UK’s only cross-sector cyber security-specific legislation. The cyber threat has since evolved since 2018 due to AI and other technology and geopolitical trends. The laws therefore require an urgent update to ensure UK infrastructure and economy is not comparably more vulnerable. This is why we announced the Cyber Security and Resilience Bill, which will improve the UK’s cyber defences, strengthen our regulatory approach and protect more digital services and supply chains.

The government announced in September 2024 that data centres have been designated as critical national infrastructure, meaning the sector will benefit from greater government support in preparing for and managing critical incidents. Further details on the content of the Cyber Security and Resilience Bill will be published in due course.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim