Skip to main content
Loading…
Chamber and committees

Meeting of the Parliament [Draft]

Meeting date: Thursday, October 8, 2026


Contents


Cyber Resilience

The next item of business is a debate on motion S7M-01517, in the name of Neil Gray, on strengthening Scotland’s cyber resilience. Members who wish to speak in the debate should press their request-to-speak buttons now.

15:08

The Cabinet Secretary for Justice (Neil Gray)

Digital technology underpins every aspect of our lives. It supports our hospitals, schools, businesses, transport networks, economy and wider public services. It connects us to one another, enables innovation and provides opportunities that previous generations could barely have imagined.

However, as our reliance on digital technology has grown, so, too, has our exposure to cyber threats. Cyber resilience is therefore no longer a technical issue but a matter of national resilience and security. It is fundamental to our economic prosperity, to public confidence in our institutions and to the delivery of essential services.

The cyber threat landscape is evolving rapidly, and cyber criminals are agile. They change their tactics to exploit any vulnerability and operate across international borders and boundaries. Earlier this week, some users of the ASOS shopping platform received a notification displaying a message that was reportedly from a threat actor and took credit for compromising ASOS systems. Detailed profiles of millions of users might have been compromised. The incident has gained attention due to the unusual way in which the threat actors notified the public at the same time as the organisation about the alleged attack.

Ransomware continues to pose a constant threat to public services, businesses and communities. Supply chains are more complex and interconnected, which creates new opportunities to target multiple organisations through a single point of compromise.

We are witnessing the emergence of a new generation of threats associated with artificial intelligence and other rapidly developing technologies. The opportunities presented by AI are considerable, and those new technologies have the potential to improve research and productivity, enhance public services and support economic growth. However, we must recognise that malicious actors are exploiting the very same technology. Artificial intelligence is already used to automate attacks, identify vulnerabilities, breach systems around the world and support sophisticated forms of online deception. AI-enabled crime makes phishing attempts, online content, emails and messages more convincing, all in an effort to steal money, data and identities from individuals and businesses.

Daniel Johnson (Edinburgh Southern) (Lab)

I am interested in the cabinet secretary’s introduction, because it does not distinguish between the individual and the corporate, or between the public and the private. Is there perhaps a trap if we view the issue in terms of public sector resilience, when we need to be thinking as much about individual resilience and security, because there is no distinction in the criminals’ or state actors’ minds between those different categories?

Neil Gray

Daniel Johnson is absolutely correct, and I completely agree that we must take that approach. I will come on to talk about some of the exercising that must be done in the public sector and in business, as well as by us as individuals, to understand the resilience that we require to prepare for the inevitability of successful cyber attacks in various organisations.

Patrick Harvie (Glasgow) (Green)

I was also interested in the cabinet secretary’s comments about the risks and vulnerability that come from the way in which AI is being used and is likely to be used in the future. Does the cabinet secretary think that the Government’s AI strategy adequately covers the risks and the actions that need to be taken to mitigate them? That section of the strategy amounts to about one page with very few actions attached.

Neil Gray

The debate has been timed to ensure that we are considering, as a collective and as a Parliament, all those issues, including the challenge for the Government and our strategies, the challenge for the wider public sector, business and the economy, and the challenge for us all individually, as I said in response to Daniel Johnson.

I accept what Patrick Harvie says about the challenges. We must ensure that our strategies evolve in order to deal with the evolving threats that are coming. That is why the motion that is before us for debate, the substance of which I think we all agree with, is about ensuring that we collaborate domestically, across the United Kingdom, and internationally to ensure that we are informed of the threats that are coming.

We must embrace innovation, but we must do so safely. We need to ensure—

Will the cabinet secretary take an intervention?

If I have time, Presiding Officer, I will give way one final time, to Mr Cole-Hamilton.

Alex Cole-Hamilton

The cabinet secretary talks about cross-border collaboration across these islands, which is a really big part of this, particularly as it speaks to my amendment on cable security. Will he tell us what, if any, involvement the Scottish Government has had with the United Kingdom Government’s Department for Science, Innovation and Technology regarding cable resilience?

Neil Gray

I thank Mr Cole-Hamilton for his intervention and for what he has set out in his amendment. Part of the reason why I have lodged the motion for debate today is that I want to see better collaboration between our Governments. We have a consensus among the devolved Governments on the need for greater information sharing and collaboration to ensure, apart from anything else, that devolved Governments with responsibility for critical national infrastructure are informed by the intelligence and information that is held by UK-based agencies. I do not say that as a constitutional point, as Mr Cole-Hamilton will be aware, but as a point of collaboration.

Will the cabinet secretary give way on that point?

I will give way for the last time.

Stephen Kerr

It is important to amplify what the cabinet secretary has just said. He has basically said that he agrees that there is an interdependence here. We, in Scotland, depend on Government Communications headquarters, the National Cyber Security Centre and UK intelligence services, and there really is no space for constitutional game playing when it comes to such a vital matter.

Neil Gray

I whole-heartedly agree.

The growing scale of the challenge is reflected in the data. Cyber crime remains a significant and persistent threat, fraud and scams are increasing, and a growing proportion of criminal activity now has a digital element. Over the past year, Police Scotland recorded an estimated 14,200 cyber crimes in Scotland. Tackling those harms cannot be achieved through enforcement alone. It requires agencies to work together, with advice that can be trusted, and victims of cyber crime need to know where and how to report it and get help. That is why cyber resilience matters.

Improving organisational and public awareness and strengthening personal online security must remain an important part of Scotland’s wider cyber resilience efforts. Over recent years, Scotland has learned valuable but difficult lessons from several significant cyber incidents. There was the ransomware attack against the Scottish Environment Protection Agency in 2020, the incident at Western Isles Council in 2023, the cyber attack on West Lothian Council last year and the targeted attack on NHS Dumfries and Galloway in 2024.

Beyond the public sector, in the business world, the cyber attacks on the Co-op and Jaguar Land Rover in 2025 are a reminder that cyber incidents can have real-world consequences far beyond the organisations that are directly targeted. Such incidents reinforce the importance of preparation, exercises, recovery planning and organisational resilience.

Cyber resilience is not simply about preventing attacks. No organisation, Government or nation can realistically expect to prevent every cyber incident. Cyber resilience is also about ensuring—this responds to Mr Johnson’s point—that organisations can withstand that disruption, maintain essential services, recover quickly and apply lessons learned to emerge stronger. The Government therefore recognises the importance of preparedness at a national level and conducts annual exercises to test the Scottish cyber incident management plan. Beyond that, the Scottish Government is participating in the National Crime Agency-led cyber exercise this winter, bringing together a number of Government agencies. That principle sits at the heart of our national approach.

The question is no longer whether organisations will face a cyber incident, but whether they and members of the public are prepared enough to minimise and mitigate harm and disruption when one occurs. We can all agree that cyber resilience must underpin digital transformation, public service innovation and sustainable economic growth. Over the past decade, through successive national strategies, the Government has scaled and strengthened its cyber posture. We have improved collaboration across sectors and nations and are continuing to build an increasingly mature and effective national cyber resilience ecosystem. Our “Strategic Framework for a Cyber Resilient Scotland 2025-2030” provides a clear vision and determination to ensure that Scotland thrives as a digitally secure and resilient nation.

The CyberScotland partnership has become one of the standout strengths of our approach. It brings together organisations from across the public, private and community and voluntary sectors to create a collaborative model that has reduced duplication of effort and ensures that cyber awareness reaches into communities across Scotland. Through the CyberScotland portal at cyberscotland.com, CyberScotland week and our national awareness campaigns, the partnership ensures that individuals and organisations have access to trusted advice, guidance and support, regardless of where they are or the sector in which they operate. I am delighted to confirm to Parliament today that, this week, the Confederation of British Industry Scotland and the Data Lab are the newest CyberScotland partners. That further strengthens our collaborative approach to building a safe, secure and resilient digital nation.

We continue to invest in cyber skills and workforce development. We have supported education and learning initiatives that introduce cyber resilience from an early age and encourage the next generation of cyber professionals. The Scottish Government has provided more than 50,000 primary 1 pupils with a copy of “Cy Bear at School” this year. It introduces early concepts of cyber security through storytelling. More than 90 of our secondary schools are delivering dedicated cybersecurity learning. In the past five years, more than 7,000 pupils have achieved their national progression award in cyber security. That is critical, given the increased risk faced by us all from online harm and exploitation, particularly our young people.

We have expanded opportunities for upskilling and professional development across the public and community and voluntary sectors, funding more than 800 cyber security training courses to date. We have also established the Scottish cyber co-ordination centre, known as SC3, to co-ordinate multi-agency responses to cyber incidents. In partnership with Police Scotland and the National Cyber Security Centre, SC3 is helping us to stay ahead of cyber threats and to respond effectively when public sector incidents occur. Every day, SC3 works behind the scenes to provide threat intelligence, issue early warnings and co-ordinate responses to cyber incidents. Intelligence sharing is vital to ensuring the timely and effective action that can be taken to protect critical national infrastructure and critical public services. That close collaboration across our four nations and law enforcement ensures that information is shared, which strengthens our collective defence to known cyber threats.

Importantly, SC3 also helps us to better understand the cyber resilience of the entire Scottish public sector. That is crucial, because effective policy must be driven by evidence. We cannot improve what we do not understand, and we cannot target support appropriately if we do not know where the greatest risks exist. That relates to Stephen Kerr’s point, and it is exactly why the collaboration must happen across all nations.

Key lessons from recent incidents have reinforced that cyber resilience must be considered not simply by technical specialists but also by chief executives, boards, senior leaders and decision makers. Technology tools and processes are important, but leadership is critical. Cyber risk must be recognised and managed as a strategic business risk. That is particularly important where organisations deliver critical and essential services. The public rightly expect services to be resilient, secure and trustworthy, and they should have confidence that organisations are taking cyber risk seriously.

We continue to work closely with the UK Government to improve legislation such as the Cyber Security and Resilience (Network and Information Systems) Bill, to strengthen regulation, and to deal more effectively with national threats. We passed a legislative consent motion on that bill last night.

Strong leadership, greater accountability and a culture of continuous improvement are key principles in the strategic framework for a cyber resilient Scotland. As our understanding of cyber maturity develops, we gain valuable insights into both our strengths and the challenges that remain.

Through the cyber observatory and the cyber resilience assessment process, we now have our clearest picture yet of the cyber maturity of Scotland’s public sector. Although the findings demonstrate substantial progress, they also sharpen our focus on the challenges that remain. That insight helps us to target investment, provide support more effectively and accelerate the adoption of best practice. Now is the time to strengthen that governance and assurance across the public sector. The organisations that deliver our critical and essential services must achieve, maintain and evidence robust cyber resilience standards. However, that must not be about creating unnecessary bureaucracy. It must be about ensuring that organisations are supported to achieve, maintain and demonstrate appropriate levels of cyber resilience.

No discussion of cyber resilience would be complete without addressing the impacts of artificial intelligence and other emerging technologies. Those technologies have the potential to drive innovation, improve public service delivery and increase productivity. At the same time, however, those technologies, which can support our prosperity, are being exploited by malicious actors around the world. Recent international events have demonstrated that the cyber risks that are associated with AI are no longer theoretical. As Governments and organisations grapple with the benefits of those technologies, we must ensure that innovation is matched by appropriate security, governance and resilience to avoid serious consequences.

Our challenge, then, is not whether to adopt those technologies, but how to do so safely and securely. We must ensure that governance keeps pace with rapid technological change. This Government must and will engage closely with industry, academia and UK and international partners to share expertise, good practice and future plans as well as information and intelligence, and I intend to pursue that in a collaborative way with UK colleagues.

The Government cannot tackle the challenge alone, and neither can individual organisations. Success depends on partnership and collaboration. Businesses must be equipped to understand and manage cyber risk and they must have strong cyber resilience. That is not only good security practice, but good business practice. It protects reputation, supports strong growth and strengthens supply chains.

Community and voluntary sector colleagues must also be supported to continue delivering essential services securely. They support many people in our society, which is why we fund the Scottish Council for Voluntary Organisations to deliver cyber awareness and learning activities for voluntary organisations.

Collaboration is the central pillar of our approach. No Government can tackle today’s cyber challenges alone. We must understand the risk of emerging technologies and work across not only sectors but national and international boundaries. Leaders across all sectors must be accountable for their organisations’ cyber security and resilience, and the Scottish Government commits to working alongside them so that our country can thrive as a digitally confident and resilient nation.

I move,

That the Parliament recognises that strong cyber resilience is essential to protecting people’s rights, safety and access to essential public services as well as ensuring Scotland’s national resilience, economic prosperity and the delivery of public services; notes that the increasing reliance on digital technologies is exposing individuals, businesses, public services and the democratic system to growing cyber threats, including cyber crime, online fraud, scams, and ransomware; acknowledges the importance of improving public awareness and personal online security and protecting people’s safety; recognises that cyber resilience is a shared responsibility requiring coordination and action across all sectors, and robust regulation of new technologies; welcomes progress through the Strategic Framework for a Cyber Resilient Scotland, the CyberScotland Partnership and the Scottish Cyber Coordination Centre; recognises that these strategies must be effectively resourced; supports more robust cyber resilience standards for public, private and third sector organisations, and supports continued collaboration and cooperation with partners across Scotland, the UK and internationally to identify, manage and respond to evolving digital risks.

I call Pauline McNeill to speak to and move amendment S7M-01517.1.

15:24

Pauline McNeill (Glasgow) (Lab)

As we have heard, Scotland faces a persistent and growing threat from ransomware and cyber attacks, but it is the speed at which this criminal space is developing that is quite alarming. In fact, only this morning, the Scottish Parliamentary Corporate Body discussed the threats to the Scottish Parliament, and rightly so. We need to catch up apace in response to that issue.

That is why Labour welcomes the UK Government’s Cybersecurity and Resilience (Network and Information Systems) Bill, which would expand existing regulations, would have extraterritorial reach and would beef up the powers of regulators, so that Scotland and the UK would be better protected against cyber attacks.

I particularly welcome what the cabinet secretary said about upskilling, because without the skills, we will not meet this challenge.

I want to elaborate on where the risks are. We are now seeing AI accelerate cyber threats, while hostile states are increasingly targeting critical infrastructure, as the cabinet secretary said. The targeting of essential services across the UK is the most worrying thing. A recent report has named the UK as Europe’s “most targeted” country for state-backed cyber attacks—a fact that I did not know until I prepared for this debate. Richard Horne, who is the head of the UK’s National Cyber Security Centre—which is part of GCHQ, a body that everyone will know—has

“warned that hostile states are driving the majority of cyber activity targeting the country’s critical infrastructure, saying around 75 per cent of attacks can be linked to state actors.”

The more you go into the issue, the more alarming it becomes. Richard Horne also reported that the agency has managed more than 200 cyber incidents affecting critical national infrastructure just during the past year. He said that countries such as Russia, China and Iran—although not those countries exclusively—are increasingly focusing on systems that underpin essential services.

Last month, the National Cyber Security Centre, as well as agencies in 15 other countries, supported activities of a group referred to as “Laundry Bear”, which specialises in covert acquisition of email data. The group is thought to be a Russian state-supported cyber actor that is targeting western organisations with a malicious campaign that uses a zero-click exploit to steal emails. People think, “If I don’t click on it, I’ll be okay,” but that has changed. Beth Hopkins, the chief operating officer at the National Cyber Security Centre, said:

“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organisations.”

It is believed that hackers based in Russia were behind another recent attack when a pathology provider known as Synnovis, a public-private partnership, was the victim of a ransomware attack. That attack crippled the pathology services of the national health service in London, delaying critical blood test results and causing the cancellation of about 11,000 appointments, at an estimated cost of £32 million. Unfortunately, it was linked to the death of one person. Again, the more we dig into this issue, the more we see how alarming it will be if we do not catch up.

Cyber criminals are increasingly turning to AI agents, as the cabinet secretary said in the last parts of his speech. Chatbots autonomously plan to carry out cyber attacks, as autonomous artificial intelligence systems can carry out complex cyber intrusions without step-by-step human direction. In addition, William Altman, director of cyber threat intelligence at CyberCube, has said:

“When the cost of running a full attack chain approaches zero, criminals do not need to be selective.”

We have probably learned growing up that there is a cost to making attacks; however, if it does not cost any money and you know what you are doing and have a level of skill—well, we can see the attacks that are being made on infrastructure. Altman continued:

“Small and medium-sized businesses that were safe because they weren’t worth a dedicated team’s time become viable targets at scale.”

That is obviously a message for all businesses, regardless of size, and it is a huge cause for concern. One in eight small businesses in Scotland has already experienced a cyber attack—we need to get them equipped to deal with that.

The UK Government’s AI Security Institute has highlighted that AI models have engaged in a level of autonomy and deception that we have not seen before. In July this year, OpenAI admitted that some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test. The company software that it developed—an AI system that can operate alone after human instruction—was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits. The software targeted Hugging Face, an online library of AI models, gaining access to some internal company systems. Hugging Face eventually detected and stopped the attack. We can stop those attacks if we invest in skills and realise the extent of the issue.

Will the member give way?

Of course I will.

Neil Gray

I thank Ms McNeill for giving way, and for the considered approach that she has taken in her contribution, all of which I very much agree with.

Building on Patrick Harvie’s intervention on me with regard to AI, I recognise that the Scottish Parliament does not have powers to carry out successfully the regulation that is required in this space, and nor does the UK Government, because the issue is international.

Would Ms McNeill agree with me on that point? Does she believe that we need a much greater international focus on better regulation of artificial intelligence so that we can adequately deal with what we are facing, not just from artificial intelligence companies and AI potentially going rogue but from the hostile state actors that she spoke about in her introduction?

Pauline McNeill

I absolutely agree with that, and it highlights the central point: there are no borders where the internet is concerned. We know that from our experience of tackling organised crime. However, given the scale of this issue, the more I look at it, the more I worry that we may not be as equipped as we should be. We need to work with all the international players that face the same threats as us; otherwise, we will simply not meet the challenge, and the consequences are very serious if we do not.

In a similar case, Anthropic—

Will the member take an intervention on that point?

Yes, of course.

Stephen Kerr

What has been said is true, but it does not absolve us from doing everything in our power to create appropriate and ongoing defensive strategies to protect ourselves, especially our vital public services. We should make no mistake about it: the foreign states that wish to undermine this country do so economically and by seeking to undermine our democracy and public confidence, and their intent is to create chaos and division. We can do something about all of that. Some of it relates to technology, but much of it has to do with the way in which we conduct our politics.

Pauline McNeill

Yes, I agree with Stephen Kerr. He talks about the disruption caused, which is important. It is not all about money; it is to disrupt what we do and to disrupt our services. I agree, therefore, that, as the first line of investment, we have to take responsibility for what we can do here. However, I also believe that tackling this issue cannot be done alone, because we do not know everything that is going on, and it is vital that we work together with other countries that face similar threats.

I will close soon, Presiding Officer. As I said, we cannot ever eliminate cyber attacks, but we need to work with our UK and European partners to improve capabilities in order to ensure that we are best equipped to deal with the attacks when they happen. It is clear that the UK and Scotland have to fight on new frontiers of crime and against new levels of disruption to stop these hostile attacks by foreign actors, and it is vital that the Parliament continues to discuss the issue so that we are all up to date with the action that is being taken.

I move amendment S7M-01517.1, to insert at end:

“; welcomes the UK Government’s Cyber Security and Resilience (Network and Information Systems) Bill as a step towards building nationwide protocols for protecting critical infrastructure, and calls on the Scottish Government to ensure that areas within its devolved competence are adequately resourced to establish any additional security measures or reporting mechanisms that may be required.”

15:32

Amanda Bland (Central Scotland and Lothians West) (Reform)

I welcome the opportunity to speak on strengthening Scotland’s cyber resilience, and I thank the cabinet secretary. I also thank Pauline McNeill for her interesting contribution. The cabinet secretary is right that cyber resilience is about far more than technology. It is about protecting people, essential public services, our economy, businesses and Scotland’s national resilience.

Our reliance on digital technology brings huge opportunities but also significant risks. Individuals face fraud and scams; businesses face cybercrime and ransomware attacks; public services can be disrupted; and sensitive information can be compromised. We have seen that happen locally, as the cabinet secretary noted. In May 2025, West Lothian Council, in my region, was subject to a cyber attack. A small percentage of data was stolen in the council’s education network.

When something goes wrong, the key question is whether essential services can continue. My amendment makes the important point that having the right framework is only the beginning, and Scotland already has a substantial framework. We have the strategic framework for a cyber resilient Scotland, the CyberScotland partnership and the Scottish cyber co-ordination centre, and the Government’s motion rightly recognises that progress.

However, our amendment recognises that significant gaps remain in implementation across Scotland’s public sector. The Scottish Government’s latest cyber activity report tells us that only 64 per cent of Scottish public sector organisations reported that they had carried out cyber exercising in the previous 12 months. That level of 64 per cent cannot be the finishing line. Cyber resilience cannot simply be assumed—it must be tested.

An organisation can have policies, plans and procedures, but when a cyber attack happens, those arrangements matter only if people know what to do and if the systems work.

Neil Gray

I thank Amanda Bland for the points that she has put on the record. Does she accept that the 64 per cent figure that she cited is out of date, because developments have taken place since then? Does she also accept that, as I said in my opening speech, work is being done on exercising to ensure that we have a resilient public sector, the need for which is the issue that she is raising?

Amanda Bland

I look forward to receiving the updated figures.

That is why our amendment calls for

“clear minimum standards for regular testing of cyber defences and incident response arrangements across the public sector”.

It is not a question of imposing a rigid one-size-fits-all model, because different organisations face different risks, but there should be clear minimum expectations. Can ransomware take down critical systems? Can essential services continue? Can an organisation respond if systems are unavailable? Can it recover? Those are basic questions of resilience. The Government’s report says that regular exercising should be realistic and should test scenarios such as prolonged outages, loss of identity systems, loss of email and extortion attacks. Testing alone is not enough.

Our amendment also recognises that resource constraints are limiting organisations’ ability to implement lessons learned from incidents and exercises. The Government’s report makes the same point. Exercises are identifying lessons, but many organisations lack the capacity to implement them, while staffing and resource shortages are preventing some organisations from exercising in the first place. That matters.

Identifying a vulnerability is not the same as addressing it. If testing identifies weaknesses in back-up systems, specialist expertise or legacy technology, public bodies must have the capacity to fix those weaknesses. That is why our amendment calls for public bodies to have

“sufficient financial, technical and specialist resources to address identified vulnerabilities.”

That is consistent with the motion’s recognition that cyber resilience strategies “must be effectively resourced”.

Our amendment also makes a clear choice on priorities. There will always be a place for strategies. Threats change, technology changes and new risks emerge, but we should resist the tendency to create further strategies and frameworks to achieve objectives that we already know need to be delivered. We have the framework. Now we need robust implementation. We have the standards. Now we need robust testing. We have identified vulnerabilities. Now we need the resources to address them. That is the purpose of our amendment.

I do not see our amendment as contradicting the motion; I see it as taking the next step. The motion recognises the importance of strong cyber resilience standards. The amendment says, “Let us make sure that those standards are implemented and tested.” The motion recognises the importance of resources. The amendment says, “Let us make sure that public bodies have the resources to act on what the testing reveals.” We are not asking for a different direction to be taken; we are asking for delivery.

The motion is right to support co-operation across Scotland, the UK and internationally, but co-ordination works only if organisations have the capability to act. Identifying a threat is only the first step. The real test is whether we can respond. Our priorities should be clear: implementation, testing and resources. For those reasons, I move the amendment in my name.

I move amendment S7M-01517.3, to insert at end:

“considers that, despite a substantial framework of strategies, significant gaps remain in the implementation of cyber resilience across Scotland’s public sector; expresses concern that only 64% of Scottish public sector organisations have reported carrying out cyber resilience exercises in the previous 12 months; believes that the priority should now be the effective implementation, testing and enforcement of existing cyber resilience standards and to resist the tendency to create further strategies and frameworks to achieve simple objectives; understands that resource constraints are limiting the ability of organisations to implement lessons learned from incidents and exercises to address identified weaknesses, and calls on the Scottish Government to establish clear minimum standards for regular testing of cyber defences and incident response arrangements across the public sector, and to ensure that public bodies have sufficient financial, technical and specialist resources to address identified vulnerabilities.”

15:39

Maggie Chapman (North East Scotland) (Green)

Cyber resilience is important, but it is not a good or an end in and of itself. Cyber resilience that does no more than protect corporate profits is not inherently desirable. Making more secure systems that have climate-destroying energy requirements is simply robbing Peter to benefit Paul. We must ask ourselves: cyber resilience for whom and to what end? Ultimately, resilience should be about protecting people, the services that we rely on and our collective ability to make democratic choices about the technologies that we use.

Stephen Kerr

Maggie Chapman surely agrees that we also need to take cyber security seriously for the purpose of protecting businesses. Businesses are not just about profits, as she described them; they are about people’s jobs and our economy. Does she not agree with that? She was very sweeping in her opening statement about businesses and profits—perhaps predictably. Does she understand my point?

Maggie Chapman

I thank Stephen Kerr for that intervention, entertaining as it was. I am 45 seconds into my speech—give me a chance. I am coming on to exactly those points.

Cyber resilience is important because almost all the services that we need to live happy and healthy lives are substantially or entirely digital. The consequences of attacks or outages are not just downed systems or lost trade but disruption to essential services that we all—especially the most marginalised—rely on.

We have seen that in tangible ways. Pupils in Edinburgh were temporarily locked out of revision materials following a targeted phishing attack on the City of Edinburgh Council’s schools network. Patients in NHS Lanarkshire had appointments cancelled due to malware attacks. Our environment, climate and animals have suffered, too. The 2020 attack on SEPA demonstrated that cyber resilience is about our ability to protect the environment and enforce environmental standards. SEPA was, in effect, locked out of its systems and data, requiring a major rebuild. We are talking about the resilience of our institutions, including those that protect our environment, public health and communities.

We must look at the consequences of poor cyber resilience for staff in our public and private sector. Information technology staff are at the front line of ensuring that our public services are secure against attacks. When we do not invest in them, and when we cut posts and allow austerity to tear through our public sector, we make their job of protecting us harder, and the risk of attacks increases. When attacks happen, it is the IT professionals who bear the brunt.

The experience of the Western Isles is instructive. When its council was hit by ransomware in 2023, five of its 17 IT posts were vacant. Audit Scotland found significant implications for disaster recovery and cyber resilience work, while staff were placed under enormous pressure. We must make sure that our essential workers have the right support and skills to keep themselves, their unions and the people whom they support safe. I pay tribute to the work of Scottish Union Learning on that. Funded by the Government’s cyber resilience unit, it has run interactive cyber security workshops for 8,000 workers and union reps on how to spot attacks and store data securely.

Ultimately, however, it is not workers who should be responsible for our cyber security. Organisations and technology providers must be required to build security into systems from the outset and by default. Secure by design, secure by default—that must be the norm and not an aspiration. It will be much easier to achieve if we wean ourselves off our dependence on a very small number of multinational technology companies that are based and regulated elsewhere in the world and whose interests and motivations are not necessarily the same as ours. That concentration of power makes us vulnerable to disruptive cyber attacks and outages; it also locks public services and businesses to a small number of providers from which it can be hard to switch.

We must focus more on digital sovereignty and our ability to control our destiny in a world that is more and more digital. That is not about pretending that Scotland can or should build every piece of technology itself. It is about having choices: diversified suppliers, interoperable systems, open standards, open-source technologies where appropriate, and the skills and infrastructure to avoid dangerous dependencies.

The European Union is making progress on the issue. Its tech sovereignty package brings together measures on chips, cloud, AI, open source and energy to reduce strategic dependencies and strengthen technological autonomy and resilience. Its open-source strategy is particularly relevant here, too. It identifies open source as a way of reducing technological dependency, avoiding lock-in and giving public bodies and private businesses greater control over critical digital infrastructure.

Digital sovereignty is also about who has power over our data, our infrastructure and our choices. It must therefore sit alongside privacy, human rights and democratic safeguards. Digital sovereignty cannot become a justification for disproportionate surveillance or the erosion of civil liberties.

This is where the question of independence matters. An independent Scotland would need to be able to protect essential services, manage strategic dependencies and make democratic choices about the technologies on which we depend. We should not wait, though, until independence to begin that work. If we believe that Scotland should be capable of determining its own future, we should also believe that Scotland needs the capacity to determine its own digital future. That means beginning the work on a Scottish digital sovereignty strategy now.

In closing, cyber resilience is about much more than protecting computers and data: it is about protecting the public services that we depend on and have human rights to; supporting the workers who deliver those services, not blaming them when services fail; building technology that is secure by design, environmentally sustainable and subject to democratic oversight; and ensuring that the technology on which our society depends does not leave us powerless to make our own choices.

Ultimately, resilience is not simply the ability to survive an attack; it is the ability to retain control over our collective future when the systems around us are under pressure. That is what cyber resilience should be for.

I move amendment S7M-01517.2, to insert at end:

“; recognises that digital sovereignty is an increasingly important aspect of cyber resilience, including the risks arising from excessive dependence on a small number of multinational technology companies and foreign-owned digital infrastructure; further recognises the importance of strong privacy, human rights and democratic safeguards; supports diversified, interoperable and secure digital infrastructure, open standards, responsible public procurement and investment in Scotland’s cyber security skills, research and public-interest technological capability; notes steps being taken at a European level to strengthen digital sovereignty; agrees that the UK Government should be more proactive in pursuing digital sovereignty, and believes that the Scottish Government should begin work to develop a Scottish digital sovereignty strategy, given that this will be necessary in the event of independence.”

15:47

Alex Cole-Hamilton (Edinburgh North Western) (LD)

The strongest password in the world cannot protect us from a severed cable. We can have sophisticated firewalls, world-class cyber expertise and systems that are designed to repel the latest digital attacks, but all that ultimately relies on the infrastructure beneath it remaining secure.

Cyber criminals adapt, technologies change and hostile actors develop new capabilities. As our economy and public services become increasingly digitally connected, the consequences for disruption become far more serious. We cannot base our resilience on yesterday’s threats. We must anticipate the next vulnerability and always stay one step ahead.

The scale of that challenge is already significant. The Scottish Government’s first “Scottish Cyber Activity Report”, which was published earlier this year and which we have heard something of in the debate, found that there had been 183 cyber incidents across Scotland’s public sector since 2018, including 43 in 2025 alone. This is happening now.

The UK Government’s latest cyber security breaches survey paints an equally stark picture for business, with nearly seven in 10 large businesses experiencing a cyber breach or attack in the previous 12 months. Those figures show why we cannot afford any complacency. The stronger standards and the co-ordination and collaboration that are recognised in today’s motion from the Government are important.

Cyber threats do not respect organisational or national boundaries, and neither can our response to them, but as those threats continue to evolve, we need to keep challenging ourselves as to what we mean by cyber resilience and where our vulnerabilities lie. That is why I will be pleased to move my amendment. Cyber security is about protecting not only the systems we use but the physical infrastructure that those systems depend on.

For most of us, our digital world exists in the cloud—in the very air around us, it sometimes seems—but it has a very physical backbone, and the services that we rely on depend on infrastructure, from fibre-optic cables and landing stations to telecommunications masts and data centres. That infrastructure can be damaged accidentally or deliberately disrupted, including by hostile actors. There can be no cyber resilience without physical resilience of the infrastructure that underpins it.

A UK parliamentary inquiry has warned of vulnerabilities in our subsea cable network, particularly around our island communities and cable landing points. Cyber security cannot stop at a firewall. We need to understand where those vulnerabilities and single points of failure are, and contingency arrangements must be put in place.

What happens when the infrastructure fails? That question is not separate from the issue of cyber security. A digital service can be lost because its systems are attacked but also because the physical infrastructure carrying it fails. We need to be prepared for both events, and the experience of Shetland and Orkney shows us why.

The SHEFA-2 cable is a vital fibre-optic link connecting Shetland and Orkney with mainland Scotland and the wider telecommunications network. In July 2025, it was damaged off Orkney when a fishing vessel made contact with it, leaving hundreds of people without service for 12 days. Then, months later, it happened again: in October 2025, SHEFA-2 suffered another rupture, this time due to bad weather. For some customers, the resulting outage lasted 26 days. Imagine what a three-week outage means for a business, a general practitioner surgery, a ferry booking system or a business that relies on card payments.

I note that those were not isolated incidents. Evidence to the Scottish Affairs Committee in the House of Commons earlier this year revealed that SHEFA-2 has suffered 20 serious breaks in just 19 years. However, what is most important is what happened when the cable failed. Some customers could be rerouted and remain connected, and others just could not. That is the difference between being connected and being resilient. Cyber resilience is ultimately about continuity, and whether the digital services that we depend on can withstand that disruption and recover when something goes wrong.

Neil Gray

I thank Alex Cole-Hamilton for emphasising the point about the outage that was faced by customers in Orkney and Shetland. He will know that my family members were impacted by that. It is a real example of the point that Daniel Johnson raised about individual resilience and individuals’ understanding of what is happening when something goes wrong, and about the importance of organisational resilience.

Does Alex Cole-Hamilton accept that, in relation to our defence posture and our broadband connectivity posture—both concern reserved issues—we need strong interaction across the four nations to ensure that our defence and critical infrastructure postures meet the demands of our cybersecurity threats?

Alex Cole-Hamilton

I agree. We have to have a more joined-up approach to this issue, both with DSIT and the UK Government as a whole and across these islands. There was no sophisticated malicious code or ransomware in the outages that I highlighted. A fishing vessel just made contact with the cable, yet the result was disruption to the digital connectivity on which many people and businesses such as that of Mr Gray’s family absolutely depend.

That is why physical infrastructure belongs firmly within our understanding of cyber resilience. We need to understand where failures could cause significant disruption and where those contingency arrangements are not strong enough to respond to disruption when it occurs. Right now, it is the responsibility of the private sector—cable owners—to effect repairs. It is not clear to me that there is an element of Government co-ordination, and that matters far beyond whether someone can get online.

The issue is about whether businesses can operate, whether public services can function, whether critical data can move and communities can remain connected. For Scotland’s islands and remote communities, in particular, the resilience of the infrastructure that underpins connectivity is vital. It cannot be an afterthought.

Although those incidents involved accidental damage, the same physical infrastructure can be exposed to deliberate disruption. Scotland lies at the Atlantic approaches. The grey-zone activity of Russia means that disruption to our connectivity is cheap and below the war threshold, and is easier to effect with plausible deniability.

A severed cable does not care whether it was damaged accidentally by a fishing vessel or deliberately by a hostile actor. We need to be prepared for that, we need to acknowledge it and we need to plan for it.

I move amendment S7M-01517.4, to insert at end:

“; recognises that cyber resilience depends on the security and resilience of the physical infrastructure on which digital services rely; understands the risks to critical digital infrastructure of accidental, environmental and deliberate disruption, including sabotage and the actions of hostile actors, and recognises the particular importance of resilient and diverse connectivity for Scotland’s island and remote communities.”

I call Stephen Kerr. You have up to six minutes, Mr Kerr, and we do not have much time in hand.

15:54

Stephen Kerr (Mid Scotland and Fife) (Con)

That is a great pity. I would like a good debate—although we seem to be agreeing with one another, so I am not sure how much of a debate we are having.

Frankly, Alex Cole-Hamilton is right. We are in a grey-zone war, and we should recognise that. The first responsibility of a Government is to protect the people it serves, and today that means protecting the digital systems on which our country depends. Scotland’s national resilience rests on hospitals treating patients, electricity reaching homes, water supplies operating, businesses paying staff and democratic institutions functioning freely. The hostile foreign actors understand those dependencies and see opportunities to steal, spy, disrupt and undermine public confidence. That threat must shape this debate.

The Government’s motion recognises national resilience and the protection of our democratic system. I welcome that. However, it names fraud, scams and ransomware without explicitly naming hostile state activity. Russia, China, Iran and North Korea feature prominently in the National Cyber Security Centre’s threat assessments. Their objectives differ. Their operations may seek intelligence or intellectual property. Some of them seek money, political influence or disruption. State-aligned groups further complicate that picture.

Daniel Johnson

Does Stephen Kerr agree that, as much as we should examine our systems and processes, we must also examine our overall political discourse? Those state actors do not seek only to destabilise our systems; they want to destabilise our democratic process itself.

Stephen Kerr

We should all guard against being useful fools in the hands of those manipulative foreign actors. That is a reality, so I welcome Daniel Johnson’s intervention.

The operations that we are describing take place below the threshold of conventional warfare. That is why they are called grey-zone operations. An adversary can weaken a country by stealing research, interrupting essential services and undermining confidence in democratic institutions. Are we prepared for an adversary that keeps attacking, targets several services or exploits an international crisis? Ministers should explain how that threat shapes their planning, preventative investment and public procurement decisions. We cannot be defenceless. In June, the National Cyber Security Centre’s chief executive reported that it had managed more than 200 incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May.

Neil Gray

I absolutely agree with Stephen Kerr. I think that he will understand that I am not seeking to divest responsibility, but does he agree that those of us with responsibility for critical national infrastructure in devolved Governments require those agencies to share the information to ensure that we can take informed decisions about where the threats arrive from? He is right about the state actors about which he has spoken, but they are not the exclusive threats that come to our shores.

Stephen Kerr

I completely agree. It is a policy area primed for very high-level and intensive interministerial and intergovernmental work. It has to be. We cannot allow ourselves to end up in silos or pockets when we are dealing with such a joined-up, planned and deliberate strategy from some, including organised criminals, as I think Neil Gray was alluding to. However, by the National Cyber Security Centre’s estimation, nearly three quarters of the activity is down to state actors. Those incidents underline the threat to essential services.

Scotland is exposed through our energy infrastructure, defence-related industry, financial services, universities and public institutions. Our research strengths are assets that others might seek to disrupt and, indeed, exploit. Earlier generations—our forebears—built walls to protect their communities. Today, we depend upon invisible walls. We should attend to building those invisible walls: secure networks, controlled access, protected information and the capacity to keep functioning when those defences are breached. Those walls require investment, maintenance, testing and vigilance.

The motion welcomes strategies, partnerships and co-ordination. Parliament must establish whether those deliver dependable protection. What assessment have the Scottish ministers received of hostile state targeting of Scottish institutions? What practical action followed? How do ministers verify that intelligence warnings produce improvements across devolved public services?

Scotland benefits from the capabilities of GCHQ, as I intervened to say earlier. As the cabinet secretary himself said, co-operation across the United Kingdom—and, indeed, more widely in our network of allies—is fundamental to our security, but the Scottish ministers remain responsible for preparedness in the services that are within their remit. Councils, health boards and agencies must know their responsibilities. Those warnings from the security services must reach the people who are responsible for our services, and ministers must know that they have acted.

We have seen the consequences. In the limited time that I have, I refer to the incidents that have been mentioned by other speakers, including those that occurred in Dumfries and Galloway and the Western Isles.

Deputy Presiding Officer, do I have to conclude now?

No—the member has additional time as he took interventions.

Stephen Kerr

That is wonderful. It is music to my ears—the kind of music that I like.

Those cases demonstrate damage to services and confidentiality, but they do not necessarily establish foreign state involvement, so the question that I ask Neil Gray is: have ministers verified that lessons have been learned in other councils and health boards? Who has checked that corrective work was completed in those instances and across the board?

A determined adversary could seek to disrupt several services simultaneously. Electricity failure can affect water, telecoms, transport and healthcare, so a compromised supplier can expose multiple organisations. When was Scotland’s last national exercise for testing that situation? Which operators and suppliers participated? Were arrangements with UK authorities rehearsed? What serious weaknesses emerged that remain unresolved? Those are questions that I hope the cabinet secretary will address in his summing up.

Public awareness matters, of course. Citizens cannot personally secure a hospital network or electricity control system, so institutional responsibility must be clear. The Government’s framework involves independent testing and a 14-day standard for patching critical vulnerabilities. How many bodies meet those standards? How many serious exceptions remain? Ministers can provide sensitive assurance confidentially to Parliament, and they should, because that is our duty. How many public bodies have actually tested whether they can restore an essential service quickly enough? Where are the high-risk legacy systems, and what is the funded timetable for replacing or securing them?

Deputy Presiding Officer, I appreciate your willingness to show me some latitude this afternoon. Our invisible walls protect Scotland’s safety, prosperity and freedom. Ministers must tell Parliament where those walls are weak—not as a game plan for those who seek to undermine us, but so that we know who is responsible for repairing them and when the work will be finished. That is the assurance that I want from this debate.

We move to the open debate. I call Calum Kerr to speak for up to six minutes.

16:02

Calum Kerr (Midlothian South, Tweeddale and Lauderdale) (SNP)

I am pleased that we are having this debate. Technology is so central to our lives that it is incumbent on us to go a bit deeper, understand it properly and debate both the opportunities and the challenges that it brings. We do not all need to become experts, but we do need to understand enough to ask the right questions, make sure that the right structures and support are in place, and legislate where that is needed.

I spent 28 years in enterprise technology, from voice networking to data networking and on to global contact centre projects and AI. I have to confess that, back then, security was seen as a necessary evil—even a painful one. I lost count of the projects that were delayed and of the changes that failed because of firewall rules.

However, over that time I have seen considerable change. As systems moved online and into the cloud, technology brought new risks and offered new solutions. I remember well the first time that a company came to us, having suffered a ransomware attack, and asked for help. We rerouted their calls and built them a new contact centre in under two days—something unheard of before then.

That shift also changed how organisations planned for the worst. We moved from disaster recovery—simply restoring the system—to business continuity, keeping the organisation running, and now cyber resilience, which is planning for an attack that we know will come. Cyber security is about preventing an attack. Cyber resilience asks the harder question about what happens when prevention fails—because sometimes it will.

Last month, I hosted an event in the Parliament with Cyber and Fraud Centre Scotland and Arnold Clark. Arnold Clark took cybersecurity seriously. It has more than 200 people in IT, including a dedicated cyber team. Despite that, in 2022, it was hit by a cyber attack. More than 4,000 customers were affected immediately, including 700 who were waiting to collect cars. The impact was far wider than that: stolen customer data was published online. An organisation may have thousands of potential vulnerabilities to protect. The attacker only needs to find one of them.

Most organisations are not like Arnold Clark. Many small businesses and charities have no IT team at all. For them, a single attack can threaten their survival. That is why standards must be proportionate and why the free support that is already available needs to reach them.

The damage does not end when the systems come back up. Often, the greater harm occurs when the stolen data is sold on the dark web and, increasingly, used to extort the individuals behind it. On the last big contract I worked on, liability for data breaches was the final thing that had to be agreed on, and the contract was delayed while that was done. Businesses have learned to take that seriously; the law has been slower to catch up.

Patrick Harvie

Does Mr Kerr agree that companies are already behind the curve in relation to protecting data because they think that, for the moment, it is encrypted and safe? That encryption will not last more than a few years and, if it is already being harvested, that is being done before the technology is available to decrypt it.

Calum Kerr

There is a saying that, “If you always do what you always did, you’ll always get what you always got.” That is no longer true. Everything is moving quickly. I welcome this debate and add that there are opportunities to harness AI and new technology on the defensive side—Nvidia and CrowdStrike have recently developed a system to do exactly that.

Patrick Harvie is absolutely right that we do not know what data has already been stolen, or whether anyone is holding that stolen data and waiting to be able to decrypt it. He makes an excellent point.

Stephen Kerr

It is true across the board—and it is important to amplify the point in this debate—that although, in many ways, AI is a threat when it is in the hands of people with malicious intent, we can also deploy it: we can use our research and capabilities as a country to counter that threat. In fact, if necessary—in the most extreme circumstances—we could use it to go on the offensive.

Calum Kerr

I thank Stephen Kerr for that intervention. I am finding it disturbing how often I am agreeing with him in this debate. I look forward to normal service being resumed after recess.

Currently, there is no explicit offence that covers the knowing purchase of stolen personal data. Scots law deals with knowingly handling stolen goods through the crime of reset, but it is much less clear whether stolen data counts as property in the same way. The founding head of the National Cyber Security Centre has said that that loophole should be examined and, if it is as serious as it looks, it should be closed. Reset is a matter for this Parliament, but data protection law is reserved, so part of the answer lies here and part lies at Westminster. As the cabinet secretary alluded to, a four-nations approach makes sense.

Recently, I met the cabinet secretary and Jude McCorry from the Cyber and Fraud Centre Scotland to discuss exactly that. I welcome the cabinet secretary’s engagement and his commitment to look at the issue further.

As we have heard, AI is changing the nature of the threat, mostly by making familiar attacks faster, cheaper and more convincing. Phishing is still by far the most commonly reported type of attack on UK businesses and charities. What AI adds is scale: an attacker can now produce thousands of convincing, personalised messages in the time it used to take to write one.

AI is an accelerator. It accelerates the attacker and it can accelerate the defender too. Our organisations and our regulations have to keep pace. That is why the human side matters so much.

Will the member take an intervention? [Interruption.] Sorry, I have knocked my card out of the slot.

I am happy to give way.

Michelle Campbell

Does Calum Kerr agree that it is important that we recognise during this debate that women are disproportionately affected by the impacts of cyber attacks and data breaches? They are weaponised against women in a very particular way, so, when we talk about the priority of dealing with violence against women and girls, we cannot separate the fact that cyber attacks have also been weaponised against women.

Calum Kerr

That was one of the points that I did not have time to make. A huge percentage of cyber crime is sexualised images, and I thank Michelle Campbell for putting that on the record.

In every company that I have worked for, cyber security training was an annual requirement, rightly so. Cyber resilience is an organisational capability, and it needs to be resourced as such. The Government’s approach starts from the same place. Attacks will come, so organisations must be ready to respond and recover. That is why I welcome the strategic framework, the work of the Scottish cyber co-ordination centre and the cabinet secretary’s focus on working with partners across Scotland, the UK and beyond.

On 27 October, members will meet to establish a new cross-party group on AI and cyber, with Cyber and Fraud Centre Scotland providing the secretariat. Anybody who is interested in getting involved should get in touch with me or Zen Ghani, as we are setting that up together.

Cyber resilience might sound technical, but ultimately it is about trust—trust that our records are safe, that public services keep working, that businesses can recover from an attack and that the voice on the phone really is who it claims to be. That is a responsibility for all of us, and I support the motion.

16:11

Zen Ghani (Glasgow Cathcart and Pollok) (SNP)

I declare an interest as an elected member of Glasgow City Council.

I welcome the motion on strengthening Scotland’s cyber resilience. Almost every part of modern life now depends on digital systems. We bank online, shop online and work online. Increasingly, the public services that we all rely on depend on digital systems simply to function. That has brought huge benefits to Scotland. It has opened up new opportunities for businesses, changed the way we work and made many everyday services faster and easier to access. However, that dependence has also created risks, because as more of our lives move online, so do the people who want to exploit us—scammers, criminal gangs, hostile actors and those using new technology to make existing threats faster, cheaper and harder to detect. That is why cyber resilience matters, not only to the Government and large organisations, but to every business, every public body and every person in Scotland.

Protecting our data is one part of that, but cyber resilience is also about protecting the systems and services that we all rely on—transport, financial services, local government, our NHS and our businesses, large and small. If those systems fail, the consequences are not just technical but are felt by people. When we talk about cyber resilience, we are talking about whether those vital services can continue when something goes wrong. Something will go wrong. That is part of the challenge, and the answer cannot be to simply pretend that every cyberattack can be prevented; it cannot. It is right that we acknowledge that some risks cannot be solved simply by spending more money.

Old systems, outdated practices and weak processes can create vulnerabilities of their own. Sometimes, resilience means investing in new technology, and sometimes it means making better use of what we already have. It means making sure that, when an incident happens, organisations can respond quickly, recover and keep essential services running.

That is why this is a shared responsibility. No single Government, council, business or organisation can deal with those threats alone. It requires co-operation between the public sector, private sector and third sector. It requires good information sharing. It requires working with partners across the UK and internationally, because cyber crime does not stop at national borders.

That is why I welcome the strategic framework for a cyber-resilient Scotland and the work being taken forward through the CyberScotland partnership and the Scottish cyber co-ordination centre. The aim is not to create a Scotland where cyber incidents never happen, because that would not be realistic, but to create a Scotland that is harder to attack, better prepared when attacks do happen and faster at recovering from those.

We can already see why that matters. The Scottish cyber co-ordination centre has responded to 183 co-ordinated cyber incidents across Scotland’s public sector since 2018, including 43 in 2025 alone. Those figures remind us that the threat is not theoretical. Graeme Downie MP yesterday published a report on the so-called “Putin tax”, which estimates that Russia-linked cyber activity alone is costing the UK around £1.5 billion every year. His work points to more than 300 Russia-linked cyber incidents affecting UK companies since 2022 and says that 75 per cent of significant cyber incidents affecting critical national infrastructure have been linked to hostile states. The threat is not simply from individual criminals sitting behind their laptops; increasingly, cyber resilience is part of our national security.

That threat is changing quickly and AI is a good example of that. It has enormous potential: it can help businesses be more productive, can support research, improve services and help us to identify threats more quickly. However, the same technology can also be used against us. AI can help criminals to produce convincing phishing messages at scale and can be used to imitate voices and identities. It can produce deepfakes and help attackers to identify vulnerabilities far more quickly than before. The Scottish Government’s own cyber advisory work has warned that AI is increasing the speed, scale and accessibility of existing cyber threats, including fraud, phishing and impersonation attacks.

That means that the basic rules of cyber security matter more, not less. Keeping systems up to date, training staff, using strong authentication and knowing how to respond when something looks wrong all matter, as does making sure that people understand the risks that they face online.

Cyber resilience is not only about protecting organisations: it is about protecting the people of Scotland and the UK. As the technology becomes more sophisticated, public awareness must keep pace with that. That is why I welcome the motion’s focus on public awareness, personal online safety and stronger standards across the public, private and third sectors. Cyber resilience cannot be treated as an optional extra for a modern country. It is part of our economic and national resilience and, increasingly, it is part of how we protect people in their everyday lives.

Scotland should embrace new technology. We should be ambitious about AI, digital services and the opportunities that they can bring, but ambition also means being prepared for the risks that come with that. If we want Scotland to be a modern digital nation, we must also ensure that it is a secure and resilient one, and that requires us all to play our part.

16:18

Pauline Stafford (Bathgate) (SNP)

I draw members’ attention to my entry in the register of members’ interests. I am a sitting councillor on West Lothian Council, which has already been mentioned in the debate. I welcome the opportunity to contribute.

Cyber resilience matters to every one of us, but as we work to build a cyber-resilient Scotland we must recognise the simple reality that we are doing so on shifting ground. Technology is evolving at an extraordinary speed and so are the threats that we face. My generation was the last of the pre-internet world. As I was preparing for the debate, I remembered getting my first email address when I was 16 and thinking to myself, “What am I going to need that for?” If only I had known. I also remembered the difficulty of explaining to my children the purpose of a phone box that we once found on holiday. They are part of a generation who carry supercomputers in their pockets and their world is light years away from anything that we could have imagined.

Cyber resilience is not a niche IT problem; it is a health issue and an economic one. It is a public service issue, and for children, families and staff in West Lothian last year it became an education issue. On 6 May 2025, West Lothian Council’s education system suffered a catastrophic ransomware cyber attack. For many, including me as both a councillor and a parent, something that had been a distant and abstract threat was suddenly very real.

Reporting and safeguarding systems went down. Access to teaching resources disappeared. Reports had to be handwritten. We were thrown back 20 years. I take the opportunity to commend the efforts of West Lothian Council’s IT and education staff at that time, who responded with professionalism and determination to minimise disruption and keep services running. Education continued and exams went ahead, much to the disappointment of some students.

One of the key lessons from that incident is that operational excellence must be matched by clear and transparent leadership. When cyber incidents occur, transparency is essential to maintain public confidence and contain the threat as quickly as possible. Although the immediate disruption lasted only a few hours, the effects of the attack continue to be felt more than a year later.

Education presents perhaps the clearest example of the balance that we must strike between risk and opportunity, which we have heard about today. Our schools, colleges and universities are vulnerable precisely because they are open, collaborative environments that are built around sharing knowledge—yet that openness is also their strength. The answer is not to close doors but to build resilience, because although education systems are a target for cyber attacks, they are also one of our most powerful defences against them. The skills and awareness that we develop in learners today will determine Scotland’s cyber resilience tomorrow.

We have had many references to AI in discussions in the chamber. It is clear that AI is supercharging cyber threats by compressing attack execution times from weeks to hours and drastically lowering the technical skills required for sophisticated breaches.

Most cyber security experts consider the occurrence of an attack a matter of when, not if. During evidence taking in the Criminal Justice Committee last year, the head of cyber security at NatWest presented the shocking statistic that the bank faces 100 million cyber attacks per month. Large banks such as NatWest have the resources available to invest in defending themselves against such attacks, but, as they come under increasing financial pressure, councils and third sector organisations face much more of a challenge in allocating appropriate resources.

That means that cyber defence must be a whole-nation effort, with responsibility shared across our society. If our goal is a cyber-resilient Scotland, the key question is how we collectively understand and mitigate those risks. Technology and legislation alone cannot solve that challenge; we need digital equity and digital literacy for every citizen if Scotland is to seize the opportunities of a digital age.

Today’s young people will inherit a world that is shaped by AI, automation and technologies that are evolving faster than ever. Many will work in jobs that do not yet exist. If we are serious about building a cyber-secure Scotland, we must equip them not only with the technical skills but with the confidence and critical thinking to navigate both the opportunities and the risks of this digital age.

I recently met the Young Women’s Movement in the Parliament, which has developed online guidance and a resource library to help young women to form a critical understanding of AI. With reference to Michelle Campbell’s point, that shows that young people understand the risks, challenges and dangers that they face, and they know the importance of getting this right.

Other examples, such as Abertay University’s cyberQuarter, show how Scotland can harness world-leading expertise in areas such as ethical hacking and threat detection. Ultimately, our strongest defence is not technology alone but educating the next generation and empowering them with that.

As the tools to defend ourselves become more sophisticated, without upskilling users, we will not only remain vulnerable but will be the vulnerability. Bad actors targeted our education system in West Lothian, yet education is fundamental to our resilience. As our devices and their software become smarter and more integrated in our lives, we must become smarter in their use. They connect us all at work, at home and socially, but they also connect us all in a shared risk. It is only by working collectively that we will succeed in building a cyber-resilient Scotland.

16:24

Bob Doris (Glasgow Kelvin and Maryhill) (SNP)

The collection and use of data, both personal and financial, the deployment of technology, the use of online platforms and the use of AI can all drive good-quality public service reform. As convener of the Public Service Reform Committee, I thought that it was worth considering the area of cyber resilience in that context. During the summer, our committee met the Data Lab and CivTech—both organisations were very impressive—to discuss how data and systems can be best used for the public benefit and can be taken forward safely.

Only this morning, the committee heard from Scotland Excel. As people in this place will know, but people outside might not, Scotland Excel is a public body that works with Scotland’s 32 councils to secure best value in a whole range of procurement and commissioning activities. Its witness told us that it is working to support local authorities in developing their cyber resilience. I understand that the local government Digital Office, an organisation hosted by the Convention of Scottish Local Authorities and funded by councils,

“has been working on a project with Scotland Excel to develop a single supplier framework for councils to call off for Security Operations Centre (SOC) services.”

I am sure that you know exactly what that means, Presiding Officer, but I did not, so I will quote further from the Digital Office website:

“A SOC is one of the best ways that an organisation can increase their cyber security. Cyber attacks can happen at any time, and cyber criminals often choose times when they know staff will be thin on the ground, with bank holidays being a popular target for this reason.

A SOC provides 24x7x365 monitoring of council systems and can take actions when certain types of incident are seen or escalate to chosen points of contact.”

Here is the key aspect:

“Developing this kind of service in-house, with round-the-clock monitoring and specially trained staff would be beyond the reach of a council, so using the private sector to provide this service is the best way to make vital services available to councils.”

At the heart of our public sector reforms, we must feel confident about embracing technologies, but with cyber resilience embedded within them. The public must feel safe.

Glasgow had its own cyber attack last year. Thanks to the use of a SOC and partner agencies, the only impact that the public felt was that bin collection data was not available in real time online, and some people could not pay their fines in the online systems. My point is that that attack was dealt with effectively because of partnership working across 32 local authorities and the private sector—and it was affordable.

Calum Kerr

Bob Doris is making a number of excellent points. The attack on Arnold Clark took place on 23 December—exactly as he said, those behind the attack picked a sensitive moment. Part of the reason for that was the lack of staff at that time. Attackers are keen for companies to roll over and just pay the ransom. Arnold Clark decided to go public and spend even more money repairing things, but we do not know how often such ransoms are paid because that is the only way that a company can see a way out of the situation.

Bob Doris

Let me respond to Calum Kerr’s intervention in this way, in case I run out of time later. I was very impressed with Mr Kerr’s speech and his expertise in the matter. The Parliament should develop expertise here on an ongoing basis. I am not sure if that sits well with any individual committee; I wonder if it requires a small-membership specialist cross-party committee of MSPs to review this area on an ongoing basis. Indeed, Mr Kerr might wish to sit on that.

A cross-party group.

Bob Doris

That sort of idea would be of absolute value for the Parliament’s scrutiny. [Interruption.] I think that the idea has just been seconded by Mr Kerr himself. The Parliament should consider how we scrutinise this area with expertise in the future.

I was going to go on to make a point about outcomes, but I will take an intervention.

Stephen Kerr

Bob Doris is making a good speech, as he often does.

On public awareness, Bob Doris mentioned the example of Glasgow City Council. The lack of awareness about things being disrupted is actually a problem. There is a general complacency among the population that things simply ought to run on, and that there ought to be no disruptions. The lack of awareness among many of our fellow citizens about the real threats that our country is facing, both from hostile actors and from organised crime, is something that we should be speaking much more about, so that the general awareness of the population will rise.

Bob Doris

I agree with Mr Kerr in relation to all of that, but we should also seek to reassure Mr Kerr. We are keen to use all the various new technologies for the benefit of society and our public services, and we do not want to get our citizens so worried that they do not engage with all the opportunities that can be secured. There is a balance to be struck.

I was trying to make the point that there needs to be cross-sector collaboration in all of this, with the third sector and the private sector, so that good practice and lessons learned can be shared. I know that that is part of outcome 4 of the strategy that we are debating. That co-ordinated approach should benefit us all.

I want to talk a little bit about the impact on business. In preparing for the debate, I noted that Glasgow Chamber of Commerce specifically referenced a British Chambers of Commerce report that says that 42 per cent of UK businesses experienced some form of crime in the past year, which includes cyber crime and attacks. It is not only large businesses that are affected, as 32 per cent of microbusinesses had experienced crime. Businesses are in the same position as local authorities. How on earth can they have the cyber resilience and security that they need? We ought to look at the Scotland Excel example and consider how we can provide cyber resilience and security expertise at an affordable price to all our businesses.

Glasgow Chamber of Commerce has picked out four recommendations from the British Chambers of Commerce report. I do not have time to list them all, but the first is that a national business crime strategic assessment be carried out across the UK. It also notes that the creation of a single cyber attack reporting system for firms would reduce administrative burdens while improving protection. The second is the creation of regional business crime hubs with business crime reduction partnerships and the expansion of cyber and fraud resilience support for small and medium-sized enterprises.

My expertise on this is limited and I do not know which parts of the UK and Scottish Governments have collaborated on the framework. However, as British Chambers of Commerce is saying that those things are important and that has been echoed by my local chamber of commerce, I want to ensure that the Parliament looks at the matter to ensure that businesses in Scotland are well served.

I will finish in a slightly different tone. Andy Burnham is in Berlin today, and the press release on his visit says that

“Britain and Germany are joining forces to find, expose and disrupt”

cyber attack activity. Mr Kerr said in his intervention on the cabinet secretary that this is not about constitutional wrangling, which perhaps showed his humour early in the debate. Irrespective of our constitutional positions, we can all agree that the challenge goes beyond Scotland and beyond the UK. It is a global challenge for society, and we have to act together in solidarity to meet it.

We move to the closing speeches.

16:32

Alex Cole-Hamilton

Cyber resilience does not start with firewalls. It starts with cabinets, cables and cable landing stations. Digital services run on physical things that can be sabotaged by being cut, crushed or flooded. We have talked about the grey zone, and Russia’s approach is deniable, below the threshold of war and cheap. We know that there is pretty much constant Russian submersible activity around the cables in the North Sea, testing their resilience and weak points. Scotland sits at the threshold of the north Atlantic approaches, with transatlantic cables, energy interconnectors and Shetland’s high-voltage direct current link. All of those are prime targets should relationships deteriorate further in this increasingly hostile world.

As I said at the end of my first speech, a severed cable does not care whether it was damaged accidentally or sabotaged by a hostile actor. Either way, the challenge for Government is to ensure that the system is resilient enough to cope. That means protecting critical infrastructure and ensuring that robust contingency and recovery arrangements are in place when it fails. For Scotland’s island and remote communities, it means making sure that their geography does not leave them disproportionately exposed when something goes wrong.

Cyber threats will continue to evolve and our response must evolve with them. The focus of the motion is on awareness, stronger standards, preparation and collaboration. All those things are important, but we must also recognise that cyber security does not exist solely in cyber space. Our digital services rely on physical infrastructure. The resilience of one depends on the resilience of the other. This is about protecting our systems from attack and ensuring that the services that we depend on can withstand disruption and recover when something goes wrong.

Whether disruption begins with malicious code, a hostile actor or physical damage, we have to be prepared for it. That is why understanding physical vulnerabilities that underpin our digital networks must form part of Scotland’s approach to cyber resilience. My amendment speaks to that, and I was gratified to hear the cabinet secretary talk of collaboration with our partners in the United Kingdom so that we can have an islands-wide approach to cyber resilience.

16:34

Stephen Kerr

I will finish on the question that I think matters, which is about what will change after this debate. It is undoubtedly important that we have debated this issue, but what will change? The motion contains words that everyone can support, about having stronger standards, resources and co-operation, but I think we would all agree that words in a motion will not protect a hospital or a council. What matters is whether those standards are enforced and weaknesses are repaired, and whether someone is answerable when they are not. One of my colleagues in the House of Commons, Ben Spencer MP, put the question bluntly: what does further regulation achieve if existing requirements are not enforced?

To me, that is at the heart of the debate. A public body can have policies—we always have plenty of policies—committees, risk registers and presentations, but none of them can repair a vulnerability. A standard that nobody checks is not protection. A deadline with no consequence is merely a date on a piece of paper. Who requires action when a Scottish public body falls short? Who signs off the remedial work? What happens when it is late or never completed? Responsibility cannot disappear into a system. It must rest with accountable officers, chief executives, boards and, ultimately—I am sure that the cabinet secretary is pleased to hear me say this—ministers. The same applies to supply chains.

Neil Gray

I was going to touch on some of that in my conclusion, but, as Stephen Kerr has raised the issue directly, I will touch on it now.

He is right about the expectation that there are accountable officers for when there is a failure in a public body, and I will give an example of where that is already in place. NHS Dumfries and Galloway had a cyber attack. Its cyber resilience plans had been audited shortly prior to that cyber attack, so it was in a robust position. That highlights the point, which many members have made, that, even with a robust cyber posture, we can still be vulnerable. The issue is not whether there is robustness or whether there has been a failure; it is ensuring that lessons are learned and shared. I can categorically guarantee that that is happening across the public sector.

Stephen Kerr

I welcome that, because this is a dynamic landscape. There is nothing static about this—things are constantly moving—so I completely accept the premise of what the cabinet secretary has said.

That also extends to supply chains. A public body might secure its own network and then give a supplier privileged access to it. That supplier might rely on subcontractors and cloud services elsewhere. One weak link could compromise the whole chain. Before a contract is awarded, who tests that risk? Do contracts impose security and incident-reporting duties? Can services continue if the supplier is compromised? Who checks the subcontractors? I realise that I am asking a lot of questions in my speeches this afternoon—perhaps there is nothing new there—but those are very important questions.

If we are serious—and we cannot afford not to be serious about this issue—we have to admit that a lot of public service contracts in the past few years have been determined largely on price, and we have to be very cautious about that. A cheap contract is no bargain if, in the process of acquiring the cheap goods or services, we end up importing an expensive vulnerability.

Ben Spencer argued that these decisions must reflect intelligence about hostile states. We have had a debate in this Parliament about a hostile state that has wanted to install something in our country. We had a party-political division on that. I would argue that we need to give pre-eminence to consideration of national security. Ministers must act on security advice, even when that decision is not convenient, as was the case in the example that I am thinking of, and which I am sure the rest of the Parliament is thinking of. Procurement cannot be separated from national security, and neither can economic development.

Ministers may say that annual reporting already exists, and I know that it does. The Government conducts an annual assessment of public sector cyber maturity, and the Scottish cyber co-ordination centre publishes an annual activity report. However, that is not the end of the question—it is clearly the beginning of it.

I will, therefore, ask the cabinet secretary another set of questions. Will ministers publish information on how many bodies meet the required standards and how many do not? I recognise that that will be a snapshot. How much of that assurance is down to self-assessment, and how much is independently verified? Those are critical questions. How many essential services have tested their recovery arrangements? I asked that question in my first speech, and I ask it again now. How many failed elements of those tests, and how many of those failed elements were fixed, and by when?

I appreciate that the member took a lengthy intervention, but he must bring his remarks to a close.

Stephen Kerr

I will conclude simply by saying that we do not need more strategies and reporting structures—we need the existing system to produce evidence on challenges and consequences. This is a matter of vital importance to us all. Although today’s debate is sparsely attended, I think that we would all agree that, in the event of a national incident of the proportions that we are discussing, every seat would be filled, because the issue is so important.

16:40

Patrick Harvie (Glasgow) (Green)

My entry in the register of members’ interests shows that I am a member of the Open Rights Group. I thank the Government for bringing the debate to the chamber; it has been important. I think that we will be in a position to have a more useful debate in Parliament if we come back to the issue in the context of cross-portfolio committee work that goes into the subject in more detail. Bob Doris’s speech gave me good reason to think that that will happen, and that not just the Public Service Reform Committee but other committees will be interested in working together to achieve progress on that.

I acknowledge the level of agreement among parties on the text of the Government’s motion. Scottish Greens recognise the extreme scale of the risk and the pace at which things are changing, and the fact that this is not a threat for the future. It is not imminent—it is happening now. As Pauline Stafford discussed, the scale and the number of attacks that are already happening is shocking. I think that a great many members of the public are unaware of that and would be shocked and disturbed to know about the number of attacks, not just at private sector institutions but in our councils and public institutions, and in other places.

Yes, there is a shared responsibility across all sectors, but the responsibility for regulating new technology falls squarely on Government—not just the Scottish Government, but the UK Government—and internationally. I remain concerned that we are not seeing such an approach, particularly with AI. Both the Scottish and UK Governments seem to be more in thrall to the potential economic benefits than they are alive to the very real risks.

As for the amendments, we will support them all, with one exception. The idea of calling the issues that we are addressing in this debate “simple objectives” is pretty absurd, and I wonder whether artificial intelligence was the only kind of intelligence that was used in drafting that amendment.

I have a couple of comments on the Labour amendment, which Scottish Greens will support. We voted for the legislative consent motion on the UK Government’s Cyber Security and Resilience (Network and Information Systems) Bill yesterday, and we can accept that it is a positive step, but it is a modest one. Despite a strong case—

Will the member give way?

Patrick Harvie

In just one moment.

Despite a strong case being made by some at Westminster, the UK Government is, so far, resisting the call to develop a digital sovereignty strategy. Like the Scottish Government, it seems to perceive more opportunities than risks from AI.

Alex Cole-Hamilton

The member’s amendment surfaces some important points, particularly on digital sovereignty. I share his anxieties about the UK Government’s apparent unwillingness to embrace a sovereignty strategy, but I think that that will change over time, and I am anxious that, if Scotland were simply to plough on with its digital sovereignty strategy, it would need to be redone when we come together. We need a whole-islands approach to the issue and, unfortunately, even though he and I disagree on the destination of independence, I think that we will always need to work with the rest of the UK on this matter, irrespective of that.

Patrick Harvie

We will, and we will need to work with the rest of Europe and other countries, too. That includes Scotland—I am not for a moment suggesting that Scotland should be dealing with the matter on its own, but the approach certainly includes Scotland, regardless of our constitutional destination.

Further in relation to the UK approach, the UK Government has also been inviting the likes of Palantir into UK service delivery and, by doing that, it has unquestionably worsened vulnerability that comes from overreliance on a handful of big tech companies, despite the deeply troubling ethical questions that their behaviour raises. This is, but is not only, a matter of foreign states that may pose a threat. It is also about threats to our security and our democracy that corporations pose.

I would challenge anyone to deny that the likes of Musk and Thiel pose a threat to our democratic values. I mentioned my membership of the Open Rights Group, which has done a significant amount of work on our overreliance on the likes of Amazon, Microsoft, Oracle and Google. I welcome the fact that the Scottish Government has not repeated the error of inviting Palantir into the mix, but the problem remains. The industry spends vast amounts of money persuading Governments around the world to adopt its systems. The public sector becomes locked in and, as it does so, becomes less able to resist the industry’s efforts to oppose responsible regulation. As the industry’s power grows, the state becomes more vulnerable to overseas companies or countries pulling the plug.

Calum Kerr

It has been an interesting debate, and it is great to hear sovereignty being mentioned. It is a shame that we did not have enough time for sovereignty to have been included as a strand in the debate on data centres. Does Patrick Harvie agree that the issue is one not only of sovereignty but of data residency? It is all very well to have sovereignty in terms of the laws governing data, but if the data resides in a place where a cable can be cut, we are fundamentally in a vulnerable position.

I also draw Mr Harvie’s attention to the fact that one of the subjects that the cross-party group on science and technology is looking at is sovereign AI and small models, which are very good for Scotland.

Patrick Harvie

I will do my best to come along to the CPG.

The point about physical location is only one aspect of the issue. Control by companies and countries is also part of the threat. We have already seen the Trump regime and Microsoft acting in such a way—the International Criminal Court’s email systems and electronic banking were politically targeted by them in recent times. Digital sovereignty will not be quick or easy to achieve, which is why we need to start now.

I want to briefly mention the concept of Q-day, which will make the Y2K issue seem like a storm in a teacup. Q-day involves the projection that, at some point soon, quantum computing will have the ability to break pretty much all the cryptographic and encryption systems that are used around the world. Earlier this year, Google and other major companies brought forward their estimate. We are not talking about something that could happen well into the 2030s; it could happen in the next three years.

Data harvesting is already happening in anticipation of that. Data that we consider secure today is being harvested because the companies involved know that it will not be secure in the future. There is a clear connection between that threat and the AI arms race. The motion recognises the need for robust regulation of new technologies, yet we still seem to be framing AI principally as a source of growth.

In closing, I want to draw attention to some data of my own. The world’s losses on AI are astonishing. Globally, about £1 trillion more has been spent by the companies that are developing AI than has been earned by them. If we look down the list of those that are making a loss and those that are making a profit, we see that it is only AMD, Micron and NVIDIA that are making a profit. The companies that are manufacturing the chips and the data hardware that everybody else is using to lose money and increase our vulnerability are the ones that are making a profit. In the time that we have been having this debate, an extra £178 million has been lost globally. That is the scale of the losses. Therefore, I ask those who frame the issue as one of economic growth, does that look like growth? All that we can see is red line after red line after red line.

Governments need to have the confidence to govern, and that means regulating to ensure that new technologies make people’s lives better instead of serving the vested interests of an industry that is too often led by the most toxic examples of the world’s super-rich.

16:48

David Kirkwood (South Scotland) (Reform)

When most people hear the word “cyber”, they tend to think of the internet and connected communications, and that has been the subject of most of the contributions to the debate. However, the term actually refers to any kind of electronic data processing or messaging.

I first encountered what we now call IT almost 50 years ago, I started to use it professionally about 40 years ago and I became a full-time freelance IT consultant 30 years ago, so I have seen massive changes in cyber security and resilience over that time. In the good old days, very few people even had a computer, so it was not an issue for the ordinary person. Once personal computers started to appear in offices during the 1980s, cyber security meant locking up the floppy disks at night. During the 1990s, networking started to become common, and we all suddenly realised the value of file system access controls and electronic firewalls.

Around the turn of the century, the internet started to become endemic in normal lives, and email and the worldwide web brought many imaginative ways for baddies to plunder people’s wallets, personal information and general wellbeing. Phishing, pharming, impersonation, malware and trolling all took their toll.

At a personal level, browsers had to become more sophisticated to protect untutored users against online threats, and it is generally much more difficult for intruders to penetrate a reasonably well-protected computer now than it used to be. However, the cyber arms race continues and, as new software defects appear, malicious actors—many of them nation states—are quick to exploit them.

In the past few months, the application of AI to source code review has uncovered enormous amounts of legacy bugs in mainstream software. In September, Microsoft used patch Tuesday to issue 974 Windows patches in an attempt to fix rafts of newly found problems. That is up from the few dozen patches that usually appear every month. A huge proportion of the patches will have been to close long-standing operating system holes that might let—and might have already let—bad actors into affected systems. Microsoft noted that at least two of the defects were under active exploitation at the time that the patches were issued.

Baddies move quickly, and users need to move even quicker to keep their systems updated. Microsoft Windows uses closed source code, which means that it is not published, and there is no way for an independent expert to inspect it for security flaws. At least in part because of that, many people have migrated to Linux, which is God’s own operating system and entirely open source. That does not necessarily mean that it is more secure, but many more people are able to scan the source code to look for problems, and new Linux systems are updated regularly and, generally, very quickly after flaws are discovered.

Many flaws would be discovered at source if software were adequately tested, and, as a former professional test manager, I would like to use the opportunity to address the software industry directly: just test the stuff properly before you foist it on your customers, will you? You might be saving money by using your customers as testers, but it is costing the rest of us a huge amount of money, sleepless nights and frustration.

I am glad to have got that off my chest after all these years—that is a lot of frustration gone there. I will make an honourable exception of McLaren Software Group in Glasgow, which, of all my clients over 30 years, has proved to be the most professional of any software company that I have ever dealt with—brilliant company and wonderful software.

Even with fully patched systems, the weakest link in cyber security is often more animal than technical. In IT support, we have an acronym for some problems: PICNIC—problem in chair, not in computer. It was often the case that I would go to the desk of a user who had reported a problem only for them to turn their keyboard over to check the password on the Post-it note underneath.

Clever social engineering can bypass any technical security, and there is a recent worrying development of AI-generated telephone calls using a convincing simulacrum of the voice of a trusted colleague to try to persuade nefarious access to be granted. We are now at the point of having to agree passwords with colleagues beforehand so that we can identify them in telephone calls.

Bad actors are becoming more professional and might look towards long-term gain rather than quick wins. Patrick Harvie referred to that aspect a couple of times in the debate. Harvesting is now undertaken for exploitation at some point in the future—a point that is possibly not even known yet.

Ransomware attacks are an unfortunate aspect of modern life, as many of our institutions have found out over the past few years. For a well-prepared organisation, recovering from those attacks used to be a relatively simple matter of shutting down and wiping the affected systems and restoring the most recent good back-ups. However, ransomers are developing patience and might leave their malicious code in place for many weeks or months before triggering it, by which time good back-ups might no longer be available. New recovery strategies need to be developed to cope with such longitudinal threats.

Cyber security involves more than just controlling network access. I am sure that many of us remember when the entire UK child benefit database was burned on to a couple of CDs, which were then left on a train. Training users in the proper application of the general data protection regulation can obviate most of the more egregious data leakages, but even with fully patched and isolated systems and trained users, things can still go wrong. Resilience means being able to recover efficiently from any catastrophe.

I have been present at a few system disasters and even had a hand in one. I have seen that the difference in the success of a recovery operation depends on how prepared the organisation was before the event. There is a saying in IT that no back-up can ever be considered secure until it is restored. There are many tales of organisations that discover that their backups are corrupt and unrecoverable only once disaster strikes.

The multiplicity of computers and cyber networks in Scotland together comprise part of our national strategic infrastructure, and careful management must be applied at every level to ensure that the security and prosperity of the nation are preserved.

I call Daniel Johnson—seven minutes, please.

16:55

Thank you, Presiding Officer. It is good of you to arrive in the chamber specifically to hear me speak, and I am sure that that is the case.

It was long planned.

Daniel Johnson

Earlier in the debate, Stephen Kerr—I do not know whether he was complaining or observing—said that this is not really a debate because everyone seems to be agreeing. That might be the case, but it certainly makes it very difficult to sum up, because there were a broad range of views.

I have a bit of a framework for summarising those views, but Patrick Harvie made an overarching point about encryption and Q-day that does not completely fit into it. We may be facing a point where all our approaches to cyber security will be rendered null and void because of our inability to use encryption, because virtually all of cyber security is underpinned by it. We must get to grips with that overarching point and have some approaches and strategies for it, because that situation is looming and impending.

I thank the cabinet secretary for the way in which he framed the debate. I was concerned that perhaps we would look at systems, structures and guarantees, but how we use technology is all-encompassing. It affects every element of our lives—it spans the personal through to the social, commercial, political and national. It is important to understand the scope of the issue. The cabinet secretary acknowledged the point—and she reflected on it well—that many of the threats do not acknowledge those boundaries at all. They seek to exploit individual issues or vectors at a social or national level.

It is also important to acknowledge personal issues. Michelle Campbell made a very good point in her intervention about females very often being the victims of cyber crime. We need to start considering the issue by thinking about things such as sexploitation approaches.

Pauline Stafford made the excellent point that our starting point needs to be education. Ultimately, addressing the vulnerabilities that arise from individuals using systems has to start with education and making sure that we all take security-aware approaches.

This issue is part of everyday life; it is a bit like teaching kids how to cross the road. Cyber security is something that we all need to be thinking about all the time. Because of the nature of information systems, it is all-encompassing. I highlight the contributions from Reform members and from Alex Cole-Hamilton about needing to be very clear about the nature of the systems that we have and the contingencies that are involved.

There are several important points to make. We need transparency around the posture on resilience across all our institutions. Although concern was raised in the chamber about whether that might heighten fears, I think that we need that transparency.

Furthermore, several members raised the issue of what happens when systems fail. We absolutely must seek to defend ourselves against these threats, but the frequency and scale of the incidents are now such that we need to think about whether things can continue to operate and services can continue to be delivered if systems are completely compromised in their entirety and if elements are removed from service on a permanent basis.

I would like to address the points around state actors in particular—we heard a number of very good contributions on that. I would also like to highlight a point that we alighted on midway through the debate. As part of the indivisible scope of these threats, we need to think about the issue at a political and democratic level. Again, these state actors will seek to undermine how we go about our daily lives and how we seek to operate at a political level. That involves issues such as system attacks as well as disinformation. We need to encompass that in our debate.

A number of members, including Pauline McNeill and Stephen Kerr, made the very good point that we need to be cognisant of the level of threat we are facing from foreign actors, particularly China, Iran and Russia. We have seen a number of attacks on power plants, on national retailers, on manufacturers, on local government and on schools and education institutions. It is notable that many members were able to reel off examples of attacks that have happened. They are things that we do not need to look very hard to find. If we were having this debate 10 or 20 years ago, we would have had to try to find niche examples, but the attacks are now commonplace. Further, we are at a point where they have gone from being simply inconvenient to causing significant disruption, if not damage.

Does Daniel Johnson agree that everyone in this chamber has an obligation to make the public more aware of the real-life threat of the grey-zone warfare that this country has become involved in because it is a target of those hostile states?

Daniel Johnson

I agree, and I see that the cabinet secretary is indicating that he agrees, too. That is why we are having this useful debate. I very much appreciate Zen Ghani’s reflections on my colleague Graeme Downie MP’s recent work on the Putin tax. The fact that that could be costing this country more than £2.5 billion a year—that is just in terms of identified costs coming from direct attacks—is important, and we need to increase public awareness of it.

We also need to remind people that many of these attacks are hybrid. They are seeking to attack us in any way they can. This is why cyber is such a central point of the strategic defence review that the UK Government undertook. Although it is very much focused on the fact that we need to defend ourselves against these grey-zone attacks, hybrid attacks and cyber and other attacks—I highlight that it also says that we must not make a division between cyber attacks and hybrid attacks. The strategic defence review makes very clear that we need to be ready for an attack, whether that be a cyber attack or a physical attack. It makes a call for civil contingency, resilience and co-ordination across the public sector. Although I absolutely agree that that requires information sharing, it also requires us not to wait to take action on this, and to think about what defence means in those terms. That is not something that, hitherto, the Scottish Parliament has had to do, and that is a new challenge for us.

I call Neil Gray to wind up the debate. You have up to 10 minutes, cabinet secretary.

17:03

Neil Gray

Often, as we hurtle towards recess, our tempers can become frayed in this place, so I am glad that we have had such a considered and consensual debate. Let it be known to Stephen Kerr that my nature is to bring people together, and so we have done today with this debate.

In all seriousness, it is critically important that we come together on this issue, because we have highlighted a clear recognition of the importance of cyber resilience to Scotland’s future. Members from across the chamber have reflected on the challenges that are posed by an increasingly complex cyber threat landscape, the opportunities presented by new digital technologies and the importance of ensuring that our public services, our businesses and our communities remain resilient in the face of those evolving risks.

Although there might be differences in emphasis on some aspects of delivery, investment or future policy direction, it is clear that cyber resilience underpins everything that we do. It matters to our economy, our public services, our communities and the people of Scotland, who increasingly rely on digital technologies in every aspect of their daily lives.

The debate has shown that we are all becoming familiar with the growing sophistication of cyber criminals, the continued threat posed by ransomware—whether from serious and organised crime or state actors and their proxies—as well as the continued threat of online fraud, scams and the opportunities and risks associated with artificial intelligence and other emerging technologies. The threats that we face today are faster, more sophisticated and increasingly capable of operating at scale—Calum Kerr made that point eloquently in his speech.

Cyber incidents can have severe and long-lasting impacts on individuals, essential public services and the organisations that communities depend on. Pauline Stafford referred to that point in relation to the issues that West Lothian Council’s education department faced last year. From local authorities and health services to businesses, charities and critical infrastructure, the consequences of cyber disruption are real and increasingly significant. Every online scam, fraudulent transaction, cyber attack and disrupted service can expose individuals and families to cyber threats and leave victims to deal with the consequences.

I referred earlier to the fact that this was a consensual debate, which might have caused an element of consternation or frustration for Stephen Kerr. However, that consensus should not mask the undeniable quality of the debate. We have had considered and informed speeches that have made a significant contribution to raising awareness, which was my intention in contributing to Mr Johnson’s speech from a sedentary position. I am grateful to everybody for their contributions. Calum Kerr, Zen Ghani, Pauline Stafford, Bob Doris and Daniel Johnson made considered, informed and very helpful contributions.

Alex Cole-Hamilton

The cabinet secretary spoke eloquently about the threats to our online resilience that we face from hostile actors—particularly criminal gangs. However, so far, he has not covered much about the physical resilience that we require. I talked about SHEFA-2, the cable that was damaged by storm Amy, which led to an outage of 26 days in the northern isles. Is he confident that lessons have been learned from that natural disruption to our cyber resilience? Is the co-ordination with private companies and the UK Government now in place to ensure that another such outage would not be so long lasting?

Neil Gray

We had interaction across the chamber on that point, and I accept the focus that Alex Cole-Hamilton has given to it. In summing up the debate, I will start with his speech.

We will accept the Liberal Democrat amendment, although I have to say that it must not have gone past Liam McArthur in its drafting, given that it comments on our rural and island communities as being remote. I know that he shares my consternation on that point. I leave that aside and will ensure that we still support the amendment in the consensual way in which we seek to bring people together. Alex Cole-Hamilton is absolutely right that we must ensure that our physical infrastructure and the lessons learned from some of the issues that he raised are part of the Government’s consideration and our four-nations approach.

Pauline McNeill made a good speech that focused on the threat from hostile states and the targeting that is coming to the UK and all of us as a result. We support the Labour amendment. What we face is deeply concerning. On Patrick Harvie’s point, the UK legislation for which we provided a legislative consent motion last night takes us forward, but there is more for us to do.

I agree with much of what Amanda Bland put on the record. I also agree with much of the Reform amendment and about the need for better exercising. However, that needs to be done not just in a Scottish context—that must happen—but more frequently at a four-nations level. I recognise the exercise that is due to take place this winter.

I agree with a substantial amount of Ms Bland’s amendment, but we cannot support it, for the reasons that I set out earlier around the data that informs it. I also feel that, as an alternative, Ms McNeill’s amendment covers the need for intervention.

Maggie Chapman’s contribution was very strong and, again, we agree with the Green amendment.

Stephen Kerr contributed a significant amount to the debate, both in his speeches and in the interventions that he took and made. He asked a direct question regarding the national cyber exercises. The last exercise was in March 2025 and was led by SC3. In total, 23 organisations participated, including the Scottish Government, Police Scotland, SEPA and the NHS, as well as BT and Capita, which contributed as strategic suppliers. To give him reassurance around our exercises, the next national exercise will be in December, and we will ensure that that work is taken forward with haste.

Cyber resilience cannot be viewed simply as a technical issue. It is about protecting people, services and the systems that underpin modern life. Improving awareness, providing up-to-date guidance and strengthening personal online security all help to build trust and public confidence. Although there may be different views on how best to achieve it, I believe that today’s debate has shown that there is broad agreement across Parliament on the importance of cyber resilience and its place as a central thread in our national security posture.

First, there is a recognition that the threat continues to evolve. Regardless of political perspective, we all agree that Scotland must remain prepared for that increasingly complex and dynamic cyber environment. In that context, I agree with Stephen Kerr’s intervention on Pauline McNeill regarding our own resilience in Scotland.

Secondly, there is a recognition that Scotland is making progress. We have developed our cyber resilience ecosystem, we are establishing new capabilities, we are strengthening our public sector and we are collaborating to bring meaningful improvements across a wide range of organisations.

Thirdly, there is recognition that cyber resilience is a shared responsibility. No organisation or Government can solve these challenges alone. Success depends on individuals, businesses, public services, academia, the community and voluntary sector, law enforcement, Government and international partners all playing their part. Although we should recognise all of those, we must also be clear-eyed about the challenges ahead and build on the progress made so far.

As Scotland’s cyber resilience arrangements continue to mature, it is right that we consider how best to strengthen preparedness, assurance and governance across our essential services. Organisations that deliver critical services must equip themselves to manage cyber risk effectively and demonstrate resilience in the face of these evolving threats. We expect organisations delivering our public services to understand risk, ensure robust governance, prepare appropriately and learn lessons. With regard to the intervention from Stephen Kerr, I hope that that gives him reassurance. That is why developments such as the cyber observatory and cyber resilience assessment processes are so important. They provide the evidence that allows resilience to be continuously monitored and improved rather than simply assumed.

I acknowledge the contribution made by all those involved in this work: cyber professionals who work behind the scenes; public servants who are responsible for bringing partners together to deal with the risks; organisations and businesses that support awareness raising and skills development; those who invest in resilience; and universities that drive research and innovation and, alongside schools and colleges, develop the next generation of talent.

Cyber resilience is not solely a technology issue—it is a national resilience issue. The security and resilience of our digital systems is integral to our economic prosperity, community wellbeing and public confidence in our essential services.

As Scotland continues to embrace innovative technologies, harness innovation and pursue public services reform, cyber resilience will remain critical to that success. If we are to build a trusted, adaptable and high-performing Scotland, we must ensure that we embed that resilience into everything that we do.

The progress made over the past decade demonstrates what can be achieved through collaboration. That collaborative approach remains one of our greatest strengths and will be essential as we navigate the opportunities and challenges that lie ahead.

Our task now is to build on that progress to ensure that technological innovation is matched by strong governance, robust standards and effective partnerships that will enable our people, services and economy to flourish in an increasingly digital world.

That concludes the debate on strengthening Scotland’s cyber resilience.