PARLIAMENTARY DEBATE
Jaguar Land Rover Cyber-attack - 9 September 2025 (Commons/Commons Chamber)
Debate Detail
The National Cyber Security Centre has been working with Jaguar Land Rover since last Wednesday to provide support in relation to the incident. I am sorry that there is a limit to what I can say on the specifics because I do not want to prejudice the ongoing investigations.
The cyber-security of the UK, however, is a key priority for the Government—crucial to protecting the public, our way of life and the successful growing economy. We have been taking significant action to help protect businesses against cyber-attacks. We are reducing cyber-risk across the economy by making technology more secure by design. That includes the Product Security and Telecommunications Infrastructure Act 2022, introduced by the previous Government, which requires manufacturers to build security into the manufacture and operation of internet-connected devices; the software security code of practice, which sets out how vendors and developers should make their software more secure; and the AI cyber-security code of practice, which sets out how AI developers should design and operate AI systems securely.
We are also providing businesses with the tools, advice and support to protect themselves from cyber-threats. That includes the cyber governance code of practice, which shows boards and directors how to effectively manage the digital risks to their organisations; the highly effective cyber essentials scheme to prevent common attacks, reducing the likelihood of a cyber insurance claim by 92%; and a wide range of free tools and support from the National Cyber Security Centre, including training for boards and staff, the “Check Your Cyber Security” tools to test IT systems for vulnerabilities, and the early warning system to get notified about cyber-threats to networks. I urge all businesses to take up these tools and improve their cyber-defences.
It is not for me to announce future business of the House, but when parliamentary time allows the Government will introduce the cyber-security and resilience Bill to raise cyber-security standards in critical and essential services, such as energy, water and the NHS.
The JLR Halewood plant in my constituency is an important and valued employer. Many of my constituents are employees, which is also the case for my neighbouring Merseyside MPs. Thousands of jobs in the supply chain have been affected. I am disappointed that despite the cyber-attack happening just over a week ago to one of our most important businesses, which has nearly 33,000 direct employees and, of course, a huge supply chain, no statement has been made to Parliament on what actions have been taken to help the company or to prevent future attacks.
The latest attack raises wider issues following on from the attack on Marks & Spencer. The two instances in themselves are very worrying. One would like to believe that all companies reviewed their cyber-security after the M&S attack. If these attacks continue, there could be an ongoing and even more serious effect on our economy. What are the Government doing to help protect our businesses from cyber-crime? I have heard what the Minister has said today, but it is in our national security interest for them to work closely with business. Is there an underlying weakness in how business is dealing with cyber-security? In that regard, we heard from Ciaran Martin, former head of the National Cyber Security Centre, on the “Today” programme this morning, suggesting that companies are perhaps focusing more on protecting customer data at the expense of the security of their operations.
This House needs to hear more in the coming months about what the Government are doing to work with business and to help prevent these attacks being successful, because they are a threat to our economy and to national security.
My hon. Friend pointed to one person; I point to another—Richard Horne, the chief executive officer of the National Cyber Security Centre—who recently stressed that the UK faces increasingly hostile activity in cyber-space. We simply cannot afford any degree of complacency in this. There are major criminals operating in this space, as well as some malicious state actors, and some 40% of companies in the UK reported last year that they had faced some kind of cyber-attack. It is a very important issue that we take seriously.
This attack on Jaguar Land Rover is extremely concerning. The impact on that world-leading business, and on its suppliers and workers, has been significant. I hope that the whole House agrees that we must use the full force of the state to crack down on cyber-criminals. I appreciate that the Minister is constrained in what he can say, but when were the Government and the National Cyber Security Centre informed of the attack? What kind of support are the Government and law enforcement agencies able to offer Jaguar Land Rover? How much longer do the Government expect the disruption, which is impacting on the supply of vehicles, to continue?
The attack is just another in a series against British brands and iconic institutions—the Minister says that 40% of our businesses have been affected—including the attack earlier this year on Marks & Spencer. Will he elaborate on what the Government are doing to prevent future attacks? Has he identified who is responsible for the attack? Can he rule out its being a state-sponsored attack? If the group responsible for the attacks on Jaguar Land Rover and Marks & Spencer are linked, what progress have law enforcement agencies made in pursuing them?
First, the shadow Minister asked when the NCSC was notified and engaged. It has been engaged since last Wednesday. We have an undertaking that when people get in touch with the NCSC, the response will be very immediate.
The shadow Minister asked what engagement there is from the Government. The primary engagement is through the NCSC, which is fully engaged and devoted to the work. It is also in the public domain that the Information Commissioner’s Office was notified. I should clarify that that was not because JLR was certain that there had been a data breach, but it wanted to ensure that it had dotted every i and crossed every t, which is why it notified the Information Commissioner’s Office.
The shadow Minister asked about a timeline for getting this resolved. I wish that I could provide one, but I cannot. I think she will understand why: this is a very live situation that has been ongoing for a week. I note the points that JLR has been making. As I say, there will be an invitation for all local MPs—my hon. Friend the Member for Widnes and Halewood (Derek Twigg) should already have had one—for a Q&A session on Friday morning, when JLR hopes that it will be able to provide more information.
The shadow Minister asked what else we are doing. This summer, the Home Office undertook a consultation on our policy on ransomware. I am not saying that that relates specifically to this case—we do not know that yet and I am not coming to any foregone conclusions—but that is one of the things that we must address, and it was heartening to see resolute support from the vast majority of companies in the UK for our ransomware policy. Maybe we will come to that later.
The hon. Lady asked whether I can say who is responsible. I am afraid that I cannot. I note what is in the public domain, but I have no idea whether that is accurate and I do not want to impede the investigation. She asked whether the attack was state sponsored. Again, I do not want to jump to conclusions, and I can neither confirm nor deny anything. She also asked whether the case is linked with that of M&S. Again, I cannot answer that as fulsomely as I would wish, simply because I do not know, and I do not think anybody has come to any secure decisions on that. In one sense, all cyber-attacks are linked, in that it is the same problem, which is relatively new. The previous Government were seeking to tackle it, and we are seeking to tackle it in broadly the same way. Some of the techniques used are remarkably old-fashioned, such as ringing up helplines, which are designed to be helpful. That is exactly the same as when News of the World was ringing up mobile companies and trying to get PINs to hack other people’s phones. This is an old technique. The new bit is that sometimes people use AI-generated voices, which are remarkably accurate and can lead to further problems. I am not saying that that is what happened in this case, but some of the patterns are across the whole sector.
When we took evidence from Archie Norman and Marks & Spencer in the wake of that cyber-attack, we were given a distinct impression that more could have been done by agencies to help M&S. Will the Minister reassure the House that all the lessons from how the M&S case was handled have been learned, and that the state will bend over backwards to ensure that JLR has every assistance it needs to get back up and running, and to prosecute the guilty?
On the main point about whether we have learned all the lessons from M&S, I certainly think we have. I have read Archie Norman’s evidence to the Committee, and I hope that M&S has also learned the lessons that he laid bare. I hesitate in trying to make too immediate a connection between one case and another, because as my right hon. Friend will know, I do not want to prejudge what has happened in this particular set of circumstances.
I do not know what the right hon. Gentleman meant about me surviving. I love him too.
In the royal town of Sutton Coldfield, we are extremely concerned about this incident. The Minister mentioned WHS Plastics, which is based in Minworth in my constituency. I spoke to the chief executive yesterday in some detail; he has 2,000 employees and eight plants, and the vast majority of his business goes to Jaguar Land Rover. The Minister will know that throughout the west midlands, there are probably more than 200,000 people in the supply chain who are directly affected, and I understand that all the factories globally have been shut down.
May I ask two questions to the Minister and support what was said by the Chair of the Business and Trade Committee, the right hon. Member for Birmingham Hodge Hill and Solihull North (Liam Byrne)? First, can we have an absolute assurance that we will have full help from all the relevant agencies of the state, and that they are seriously and 100% engaged in all this? Secondly, will the Minister press for maximum transparency, so that the staff who are being sent home in very large numbers, and who are naturally very anxious and worried about this issue, can be reassured to the greatest extent possible?
“the most wonderful thing about Tiggers is I’m the only one!”
One thing that all businesses can do now is get a certificate for cyber-essentials, which is a programme that helps businesses to protect themselves better. I am very hesitant to jump to conclusions about overseas involvement in this situation at JLR, but of course the Government take very seriously the fact that there are undoubtedly foreign state actors who want to interfere in our businesses and, for that matter, in the way we do politics in this country. We need to keep our eyes wide open for that.
The devastating JLR cyber-attack is one of a series of cyber-attacks that have been wreaking havoc on British businesses and consumers and undermining public confidence. Will the Minister confirm my understanding that neither JLR nor Marks & Spencer are deemed to be providers of essential services under cyber legislation, and are therefore not required to meet the highest levels of cyber-security and reporting requirements? If that is the case, will that change under the new cyber-security and resilience Bill, which he mentioned? If not, how will he improve cyber-resilience in our industry and society without such measures?
One other thing I will say is that all businesses, whether large or small, should avail themselves of the early warning tool available from the National Cyber Security Centre whenever they think that they may have had an attack. It is really important that we have a real idea of the prevalence of this problem across the whole sector, and that we are able to join up the dots between different incidents.
I slightly take issue with the right hon. Gentleman’s delineation of those three groups; I think there is just one, which is a bunch of criminals. Their intent sometimes mixes a desire for cash with a desire for some kind of spurious infamy, but I just think of all of them as criminals. As for my inimitable style, I can neither confirm nor deny it.
Mr Speaker, I am sure that some kind of digital identification service will be available for identifying the right MP to call.
Contains Parliamentary information licensed under the Open Parliament Licence v3.0.