Select Committee on Science and Technology Minutes of Evidence


Examination of Witnesses (Questions 1-19)

Mr Vernon Coaker, Mr Justin Millar, Baroness Vadera and Mr Geoff Smith

20 MAY 2008

  Q1  Chairman: 20 MAY 2008  May I welcome you and thank you very much for giving us your time to come to pursue this clearly very interesting and, from the front page of some of the papers, highly relevant topic this morning. It seems we never escape it; it is with us. I welcome too, members of the public who have come wanting to follow the proceedings as they have done very carefully in the past. May I remind you that it is of course all on the record? We have little signs out saying who we are, we know who you are and we do appreciate having two ministers at one meeting; it has taken some organising and your cooperation in this has been very helpful. What we would propose to do, unless either of you wanted to make any opening comment, is just move straight to the questions. Do either of you wish to make an opening statement?

  Mr Coaker: No, thank you.

  Q2  Chairman: May I take the first question and then we will simply move around the table with various items we want to raise? The original report that we put out was received with a lot of interest and indeed the specialist press especially took great care over some of the details in the report and the many recommendations that we made. I have to say some of us thought that the Government's response was just a little bit bland, which is one way of putting it, but we followed through, in the light not least of what has happened since then, some of the implications that have arisen for the issues that we were considering. We thought it timely to move now to further discussion and we would hope to put out a short follow-up report on this topic. Perhaps I can raise an opening question which is central to all the ground that we covered which is; in the end, who is finally responsible for personal Internet security? Is there a locus within the system, within Parliament or elsewhere, and, if not, is there someone who ought to be? We have seen various possibilities suggested; it is a matter for the individual, it is a matter for the ISP and so on, and we had our own recommendations on this. However, may I just open the discussion by asking who is responsible for personal Internet security?

  Baroness Vadera: First of all, thank you very much for the report, because I found it very interesting and read it quite recently for the first time knowing that I was going to be here. The report, which was somewhat more interesting than our response, actually had it correctly pitched, that it is distributed responsibility and that some of it is quite structural to the sector, and there is quite a lot of complexity around this which the report actually discusses very well. I found the analogy of the road system quite compelling, even though, as you say, there is no perfect analogy. I saw in some of the discussions, that there was this view that you believed that we took the view that it was the consumer who was ultimately responsible. I certainly do not think that is true. I do not believe from the discussions that I have had within the department since that, that is the department's view, so I apologise if that was the view which came across. It is distributed; it does make it complex. There is the issue around both hardware and software vendors, and the security vulnerabilities appear to come much more around the software vendors and I know that there is an issue around what their liability is. There is an interesting view around ISPs and what they have to do and there is possibly more that we could do around that. There is the Government and the consumer and of course the businesses ultimately and to try to impose, on what is quite a complex system, a single line of responsibility would have quite a lot of disadvantages which you actually explore in the report around inflexibility, inter-operability problems. Supposing you made the software vendor liable, then you could end up with a system a little bit like we have on mobile phones, which is that what is downloaded is what you get access to because, in one sense they do not control everything and they would need to control things if they felt they were liable. We do have the system that we have and we have to work to ensure that we raise the bar for each of those players.

  Q3  Chairman: I would like to come to ISPs in just a moment, but one of the concerns we had was that the way the weight of the responsibility seemed to be distributed, was that there was a very large responsibility on the individual. This is a very complex world, that is one of the things we all discover the more we immerse ourselves in it. You did query whether or not we had got it right and we wondered whether the weight should really be significantly elsewhere. Yes, individuals have responsibilities; as with credit cards, they should not leave them lying around and leave their pin numbers written down and all that sort of thing. There are comparable issues here but it is a more complicated world.

  Baroness Vadera: It is right that it cannot be weighted entirely towards consumers. As you say, it is not that they are necessarily the best informed. There is a difference, for example, when it comes to certain types of breaches of security. At the time you were doing the report, phishing was quite a big subject, but when there are things that are actually more around the behaviour of the consumer, you can see that actually they need to be careful. It is about actually listening to the fact that your bank has told you not to respond to that email, so that changes the level of responsibility. I would not say that this needs to be entirely weighted towards the consumer at all.

  Mr Coaker: Yes, that is right.

  Baroness Vadera: Certainly the Government needs to show leadership and there are some things that you suggest in the report that we need to look at. For example, you discuss a kite mark for ISPs which is interesting. I have been told since, that the BSI owns the kite mark as a concept but we might be able to look at things like a code of conduct that ISPs need to consider. We might be able to raise the game for software vendors by giving them, at the EU level perhaps, a sense of expectation of what the market will want from them so that they are not rushing things to market. Again on ISPs, we know that the ten major ISPs cover the majority, but there is a whole tail of other ISPs that we do not know about, which I know Vernon will have to worry about when it comes to things like what we have done recently. We maybe need to do some research and we need to show some leadership on this ourselves. The ISPs do do a fair bit and I have looked at some of the research which my officials showed me that showed that they do actually turn off contaminated users. I do not know whether that is the right terminology, but you know what I mean. There are things that people are in fact already doing. We know that increasingly hardware is actually sold with the software already bundled in, so there is a change and I would not want it to be believed that it was entirely an issue for the consumer but there are certain things that the consumer really needs to be aware of because there are certain things you cannot deal with in the software; they are about the way they actually use the system.

  Q4  Chairman: On the question of kite marks, the Government's response suggested you were waiting for the EU regulatory framework and we understand that there is now a draft of that out. Has that moved things ahead? Has the consideration of that within Government taken place?

  Baroness Vadera: There are two bits; I do not know which bit of the EU framework you are talking about. There are two separate things. There was the review of the Consumer Acquis where, it is fair to say, we are struggling to get the consumer side of this looked at but that is a separate issue. There is currently a framework discussion around telecoms; I was in fact in France yesterday having a discussion with the French minister responsible. They are going to take over the presidency of the EU starting on 1 July, but I am not sure that we will be covering ISPs in the regulatory framework in quite that way.

  Mr Smith: May I just add something on the framework? One of the headline issues when the draft proposals were issued was that the Commission intended to increase the security of networks. The way those discussions have gone is focusing responsibility on network providers and service providers to protect personal information, interconnection points and maintain availability of networks. So the regulatory climate is changing and there will be increased expectations on ISPs and others from 2010 onwards. Negotiations are, of course, underway and we are nowhere near finished but the background is shifting to a more security-aware environment.

  Q5  Chairman: Thank you, that was very helpful, but could you identify yourself for the record?

  Mr Smith: I am Geoff Smith, I am Deputy Director, Communication Supply, in the Department for Business.

  Q6  Lord Crickhowell: I was not on the Committee when this report was prepared, so I have picked it up, and I suppose I have picked it up as a consumer. As we started on consumers, I thought I would pick it up now, but I was pretty shaken by the statement right at the start of your response that the Government do not agree with the implication that the public has lost confidence because of the increase in trading. Well, I am a pretty experienced computer user, I was chairman of an IT net company but certainly members of my family are worried and not a day goes by without several invitations, usually from banks, but from other organisations, for me to come back to them; very often banks with which I do not do business, so I never open them. Then I order something, probably asked to by my wife—I bought something on the Internet, as it happens, 48 hours ago from a European company—and up comes a security crosscheck. I may be familiar with the organisation that is doing it, but the ordinary consumer is expected, according to the Government, to realise that half these messages from apparently respectable organisations like major banks and building societies inviting them to provide security information or their account will be closed down, to know who the organisations are that are secure when they are asked to provide the financial information to complete their purchase. I do not believe that is fair on a huge number of new consumers. Surely there is a need to safeguard the consumer by providing much more information about who the kite-mark-approved people are and indeed we ought somehow to be able to stop all these extraordinary numbers of invitations which appear on our computers daily requesting information. If they are not from well-known banks, why is something not being done to get them off the system?

  Baroness Vadera: Quite a lot of the ISPs have for starters very good systems on spam. I have a private account with an ISP, but I actually tend to find more of my emails are quarantined than spam; I end up in a situation where, actually, legitimate emails have been quarantined. So it is true and fair that people need to go with good ISPs who actually can filter emails and spam but at the end of it, if there is one basic instruction which is "Don't give out your password by invitation in an email", it is the same thing as "Don't leave your credit card lying around". There is some level of responsibility with consumers on that and I would suggest that. It is true though that the majority of transactions from banks are actually their responsibility, the reimbursement comes from the banks and they have actually therefore taken it more seriously and the level of bank security breaches has actually decreased recently. I am not going to vouch for the numbers because they come from the Banking Association so they are not our figures but it has gone down, they claim, to under £25 million when it used to be just over £30 million; it is reducing. We need to have a number of measures, including possibly the kite-marking or code of conduct with the ISPs, including making sure that banks feel a sense of responsibility, which they appear to, and the fact that consumers need to know a very basic thing. I understand it is problematic for them to recognise who is respectable and who is not respectable, for them to know not to voluntarily give somebody their password on an email is a legitimate thing to ask them to consider, and possibly for us to ensure that they are educated about.

  Chairman: I have to say I cannot resist mischievously telling you that occasionally there is an over-zealousness in excluding emails and I have had the House of Lords computer exclude an email to me from the then Scottish Executive. Perhaps that was a political statement, I do not know.

  Q7  Lord Haskel: Continuing with the interests of the consumer, in our report we recommended that there should be an exploration of the general principle of software vendor liability and, in the short term, that there should be liability for negligence. You responded that this was being discussed with the ongoing EU review of the Consumer Acquis. What is the position on this? Is it still on the "to do" list'? Is this something on the agenda for this meeting you were telling us about on 1 July?

  Baroness Vadera: As I implied earlier, it is fair to say that, in terms of the EU review of the Consumer Acquis, we are not very hopeful that this will be taken up. However, we do understand and accept the whole issue of software vendor liability. It would be fair to say that there is more that we can do, but I would be reluctant to start with the proposition that we need to legislate and basically make them liable for a number of reasons. First of all, it is actually quite hard to have attribution of liability in a system—I actually learnt this from your report in the first instance and then explored it—because of the way the Internet works on layers—and actually to find a way in which you can be clear about the liability is very difficult. If we were, it would require a degree of control that the software vendor would need, which, in the report again, you slightly shied away from. You thought that was problematic, it would lead, like mobile phones, where you only have a certain type of software that is downloaded on it, to massive inter-operability issues. It would also be very difficult to do this on a UK level. This is a global industry. We do not have, in any shape or form, the majority of the vendor industry in the United Kingdom, so we need to be global and therefore one of the things that we were interested in doing was taking it up at the EU level. On the issue of negligence, the issue is whether you could prove negligence given the complexity of the system, but if you could, then there are common law protections. What we do need to do is to find a way, either a voluntary way or at the EU level, to raise the bar of expectation on the software industry, in particular this rush to market which has decreased, famously since the memo from Bill Gates, but decreased over time, that we ensure that there is an expectation. There are also very interesting things that consumers are doing. I know that there is an issue around consumers that we discussed, but, for example, on the Microsoft Internet Explorer, that actually automatically downloads security updates every 30 days and there is an interesting thing going on, although I do not have the numbers, with a switch to an alternative, Firefox, because they do it every six days and people are beginning to become aware of that. So in one sense a bit of competition would be a good thing to make consumers feel more empowered. To start with the view that we need in the UK to have a regulation that is simply for the UK, I am pretty sure is not workable, but I know that we need to up the game and find alternatives.

  Q8  Lord Haskel: In your response you said that there should be a debate to consider both how to improve the reliability of software and to protect the interests of consumers, while not reducing the quality of software available on the market or the incentives to innovate. It does seem to me that these are rather complicated and rather ambitious objectives. What actually are you doing to promote this, because this is part of all this business of protecting the consumer?

  Baroness Vadera: We need to raise it at the EU level. I was in France yesterday and we did discuss this with the minister there; they have the French presidency. We need to do some very basic things around licensing agreements, for example. The National Consumer Council has referred 17 companies to the OFT for consumer licence breaches of some sort. Apparently, in some of these cases, you cannot actually read your licence agreement until after you have bought the product, which strikes me as slightly interesting and bizarre. So there are things that we can do but we do need to have a discussion and it does need to be at the EU level. Most of the software that is used is not produced in the UK, so we do need to have a discussion at a different level.

  Q9  Lord Haskel: Is there going to be anything in the Bill that we were promised in the statement last week?

  Mr Coaker: It is up for discussion but I do not know.

  Baroness Vadera: It sounds like it is not because none of us is aware of it.

  Q10  Chairman: "I do not know" is a good answer sometimes.

  Mr Coaker: It is an early draft, if it is a draft at all.

  Q11  Earl of Northesk: You mentioned automatic software updates. You will also be aware no doubt that over the past week or fortnight, Windows issued their SP3, Service Pack 3, update. That had the effect of freezing people out of their own computers and crashing those computers. It is all very well to say automatic updates are useful but they are not, because they have their problems. So the question I am really trying to drive at is that vendor responsibility and liability have to sit in there somewhere.

  Baroness Vadera: I am sure the fact that they have crashed systems means they will be clearly liable, but one of the things that we do need to look at is the whole issue of what is expected of them as an industry and although the culture has changed quite significantly, there is still a slight sense of rushing the next thing to the market. I can only repeat what I said, which is that we need to have a clearer sense or expectation that this is not acceptable.

  Q12  Earl of Erroll: I would like to mention that actually they do exclude liability, and what is worse is that the solution is to go online to get a fix and the trouble is they have just crashed, you so you cannot get back online so you are in a fix. Unless you know how to do rollback, there is not a lot you can do about it or it will be very expensive and it is a serious problem.

  Baroness Vadera: Yes, I understand.

  Q13  Lord Harris of Haringey: In our report, we said we wanted the Government to ensure " ... the right incentives are in place to persuade businesses to take the necessary steps, to act proportionately to protect personal data". The Government's response said "... we do not accept that the incidence of loss of personal data by companies is on an upward path". Now clearly that response did not refer to government departments. However, I suspect that things that have happened since might mean that the response would be in different terms. We also recommended that the Government examine, as a matter of urgency, the effectiveness of the Information Commissioner's Office in enforcing good standards of data protection across the business community. You responded to that that the enforcement regime was fit for purpose. Given all that has happened, have the Government changed their position on any of this?

  Baroness Vadera: It is fair to say that some of the data loss experienced by the Government has been a bit of a wake-up call. I do not know whether we would have answered the question differently. The only thing I would point out is that a lot of it has been around security practice; rather than necessarily something that is current in the software or anything else, there is an issue around security practice. The first thing is obviously for the Government to get their house in order and you will be aware, from the statements that have been made by Alistair Darling and Ruth Kelly, that there is quite a lot going on here. We have a report being done by PWC on HMRC. We have Richard Thomas and Mark Walport doing something around whether we need to look at the Data Protection Act 1998. Gus O'Donnell has been asked by the Prime Minister to work with departments and I would say that in fact probably we will find that performance on this has improved. I know for a fact that in BERR in the last six months, there have been changes so that laptops and disks and things cannot be taken out unless they are encrypted. There is stuff going on in Government. I do not know about the exact timing, whether it was just after the report, but, with reference to the Information Commissioner, the Criminal Justice and Immigration Act has actually given him powers—I think it is since the report—to impose monetary penalties. In the process of going through the Regulatory Enforcement and Sanctions Bill, if there were illegal activity then we could give the Information Commissioner an Order that would give the ability to impose monetary fines which are actually unlimited, unless we limit them in the Order. The ICO has also since published guidance on how to notify companies about breach of security. We ourselves do have a business survey on information breaches which is interesting and we are very happy to send you that; I personally found it quite intriguing. There is quite a mixed picture, some improvements and some things that are still a little bit worrying but I was pleased that of IT spend, there is a trend of increasing spend on security, although still 20 per cent or thereabouts of companies only spend less than one per cent of their IT spend on security so there is clearly more that we could do. There is a lot going on. The fact that it is something that people are very aware of—that is on the front pages of the papers—has certainly meant that business as well as Government are taking this very seriously.

  Q14  Lord Harris of Haringey: We recommended very specifically that the Information Commissioner be able to implement random audits of security measures. On 21 November Downing Street was briefed, after the HMRC incident, that the Government were taking this forward. What progress has actually been made?

  Baroness Vadera: I am afraid I do not know the answer to that. I do not know whether Geoff knows, otherwise we will let you know in writing.

  Mr Smith: That would be the best solution. I know that the Information Commissioner had been developing ideas around that and they have not been particularly well received, but that is not to mean that that is not going to happen. It may be that we might be waiting for the Thomas/Walport report which is going to be quite a fundamental look at the Data Protection Act, but yes, we will certainly write to you.

  Q15  Lord Harris of Haringey: I am sure that would be helpful. You mentioned your survey on what is being done. In the report we recommended a data security breach notification law. The Government's response was that you "would consider whether we need to find more formal ways of ensuring that companies do—as a matter of routine—contact the ICO when problems arise. Government of course is now almost falling over itself to tell us when problems have arisen, even when data has been heavily encrypted. However, the number of communications from the private sector seems to be a trickle. I cannot believe they are immune to this sort of problem, and your survey suggests that will not be the case. What is the current thinking on a breach notification law?

  Baroness Vadera: There is basically guidance that the ICO has since put out for the private sector that tells them about when and how they might consider—

  Q16  Lord Harris of Haringey: That is guidance. Do you want to make it a compulsory requirement that people should notify those whose data is distributed generally?

  Baroness Vadera: Your report and evidence that I read subsequently show that this is not straightforward, you want to find the balance between a tick box approach which makes people feel a little bit immune and actually some level of significance in the event. As you say, we are falling over ourselves to notify, as Government, every breach even when it is encrypted so we do have to find the balance. My personal view is that it is very hard and we are looking at all of this in terms of the various reviews that I have already mentioned, so I do not want to suggest something before we know what may come out of that. It would be very difficult to legislate or regulate for the level at which you should inform because it is really about proportionality and significance, is it not? All of this is being considered in the variety of reviews that are going on.

  Q17  Lord Harris of Haringey: Health and safety legislation, by placing personal responsibility on individual managers and indeed on boards of directors, has transformed attitudes towards health and safety in the workplace. Is there not a case for equivalent legislation, as far as information security is concerned, to make sure that all managers and indeed all employees and indeed those who are responsible for organisations in both the public and private sectors, take this as their personal responsibility, with perhaps implications for their personal liability if they fail to do so?

  Baroness Vadera: I do not personally believe that that would be a proportionate response, but, again, these are things that are being considered and looked at and I would not want to presume to speak before everybody has really considered all of the issues. All I would say about the health and safety regulations is that nobody said that anything is perfect and the reason I know that is because we are reviewing those as well right now in my department. We need to have something that is proportionate and is going to be effective. The most important thing is being effective rather than just to say automatically that we need to legislate.

  Q18  Chairman: Lord Harris's point does require underlining, that in the health and safety sector, major companies put policies in place and it transformed the statistics and the reality and that is worth putting on the record.

  Baroness Vadera: I did have a statistic which I cannot remember off the top of my head, but actually quite a significant proportion of companies have security policies in place, as you will see from the survey.

  Mr Smith: It is near 80 per cent.

  Q19  Earl of Erroll: I just wanted very quickly to ask whether you do actually hold out much hope of being able to strengthen the powers even if you do alter the Data Protection Act when you consider what happened in the Criminal Justice and Immigration Bill when they watered down what was originally section 216 or 219 and introduced section 75, and then further watered it down so that the powers that were to be given to the ICO basically got watered down to a fine. There is no point in fining a government department, it will merely make the service worse, and as for fining an individual, well the person who has bribed them to release the information will probably offer to pay the civil penalty. So how are you going to strengthen it, if you are going to water down your provisions the whole time? It was not under parliamentary pressure either.

  Baroness Vadera: Vernon knows more about that particular Act but on the Data Protection Act, we are still waiting for the recommendations so it would be slightly premature to talk about the fact that we are going to water down the recommendations before we have received the recommendations. That is not entirely fair.



 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008