Coalition on Secure Technology– Written evidence (NLR0051)

 

Introduction

 

1. This submission comes in three parts:

-          A consideration of the role of government

-          An outline of one of the biggest, yet mostly unrecognised, technology threats to national resilience, namely cellular (IoT) modules

-          Remarks prompted by specific questions posed by the Committee in its call for evidence

 

The role of government in national resilience

2. What does national resilience mean? Here is a description rather than a definition. National resilience is fundamentally about preserving economic and national security (in the long-term all three are the same); the basis of economic and national security is preserving critical national infrastructure (CNI); and, the essential pillars of CNI are energy, water, resources, fuel and certain technologies.[1]

3. For civil society, organisations and individuals to contribute relevantly to national resilience requires HMG to give a clear strategic lead on protecting the UK’s CNI. It must set standards, draw up and implement relevant legislation, and establish a security culture – as it did during the Cold War against the Soviet Union. Without a clear government role, there is only Tower of Babel national resilience.

4. So, the most crucial question for national resilience is, ‘What are the main threats to the UK’s CNI?’ Which of the most important areas are under threat? Which resources are most vital? Which technologies must be in British or allied hands? Which foreign powers are the source of the most serious threats IN THE LONG-TERM?

5. Technology moves in months, governments in years. This gap must be reduced. Technology is entering every facet of life, every home, and – via the Internet of Things (IoT) – most devices. This is broadening the definition of CNI. Take energy smart meters. These can be controlled remotely by a hostile foreign manufacturer or power via the embedded cellular (IoT) module. A widespread, concerted attack could bring down the UK’s grid. Another example, connected vehicles. At a time of war or high tension these could be switched off en masse by a hostile CIM or vehicle manufacturer, paralysing food or logistic systems (trucks are the greater long-term threat than private cars).

6. HMG has been noticeably reluctant to speak about the source of the threats to CNI and national resilience. The most immediate are Russia and Iran, but the greatest over the longer-term is the Chinese Communist Party (CCP). Although the CCP is considerably more transparent in its policies than is HMG, the UK government is unwilling to follow through the logic of the Chinese position.

7. The CCP declares its intention to ‘attain the dominant position’ in the world by 2049; to change global governance; to win the ‘struggle’ against ‘hostile foreign forces’ (ie the West) with whom it sees itself in a science and technology, economic systems, and trade war; and to free itself of reliance on the West, while creating western dependencies on China.[2]

8. A summary of the strategy the CCP is implementing in order to reshape global governance and power includes three elements:

  1. Dominating the industries and technologies crucial to CNI. Solar and wind power, connected vehicles, modern industrial manufacturing are prominent examples.
  2. Dominating, if not monopolising, the new technologies and their dependent industries. Of the four most crucial, artificial intelligence, quantum computing and semi-conductors are well-known. The fourth, every bit as important, is less recognised: cellular (IoT) modules.
  3. Controlling vital resources, whether the source of them, or often the refining. CCP pressure inflicted by withholding supplies of rare earths has been a leitmotiv of the last 15 years. But equally, China has invested heavily to control important minerals and metals originating in third countries.

 

9. The committee has rightly talked of the need for a “whole of society approach” to national resilience. Yet it is unreasonable to expect citizens to act sensibly if the government is not articulating the threat, setting a strategy, and above all ensuring its implementation. Why should I as an individual care, if the government does not?

10. China represents the biggest long term threat to national resilience and security. HMG must stop hiding behind its meaningless slogan of “3 Cs” – cooperate, compete, challenge. An example of why this is necessary is the recent decision on turning down investment by the Chinese company Mingyang in wind power in Scotland. After several years of wasted time, energy, money, HMG eventually ruled against on national security grounds. Had a clear strategy been in place, a speedy decision, more easily accepted (by companies, Scotland, China) would have more quickly advanced energy/environmental needs, finance and other issues.

 

The importance of technology – cellular (IoT) modules

11. In attempting to achieve its aims the CCP brings to bear three threats to our economic and national security – in other words, national resilience.

a. Leveraging dependencies. The CCP uses monopolies or dominant positions in supply to

    achieve economic and political ends. Threats to other nation’s exports or investments are a

    standard tool to advance the CCP’s geopolitical ambitions. Withholding vital components is

    used to change other countries’ policy positions. Rare earth supply is the prime example.

 

b. Disruption or degrading performance. War can be carried on without fighting. The ability   

    to degrade or even turn off another country’s CNI could achieve the same ends as war – 

    even the threat to turn off might be sufficient. The CCP has been scoping out the CNI of

    liberal democracies (operation “Volt Typhoon”[3]). Understanding weak points or deep

    involvement in UK CNI systems would give to the CCP the power to blackmail or win without

    fighting.

    The ability to interfere remotely was shown by John Deere, which switched off remotely via

    the CIM agricultural machinery stolen by the Russians from Ukraine.[4] While this was the  

    action of the original equipment manufacturer, equally it could be done by the CIM

    manufacturer. While this is not a power that China would use except in extreme

    circumstances, wars happen. It is the duty of government to ensure that surrender does not

    proceed the outbreak of hostilities.

 

c. Weaponising data. Deep integration of Chinese technology in UK systems provides the

    opportunity to collect vast amounts of data. Aggregated and manipulated through artificial

    intelligence (AI), such data can undermine both economic and national security. National

    resilience could be affected either at the individual level (note that in December 2022, the

    security services stripped down the prime minister’s car because data was emanating to

    China via the “e-sim”[5]), or in CNI, emergency response etc, where the CIM has been the

    gateway to vast amounts of data, which could be exploited to make systems vulnerable to

    sabotage.

 

12. What is a CIM? Cellular modules are about the size of a thick credit card. They contain processors, memory, antennae and an e-sim to link to the internet. They are, in effect, the gateway to connected systems enabling modern equipment, processes and systems to function. They are vital, because they continually transmit data. They monitor, control, and update systems.

13. A modern connected vehicle is a good example where CIMs are crucial. Modern cars, vans, trucks are now basically ‘laptops on wheels’. On board computers control the functioning of the engine, the audio and information systems, sensors, cameras, LiDAR (Light Detection and Ranging for detailed 3D mapping of a vehicle’s surroundings, crucial for semi-autonomous or autonomous driving), and more. Through the CIM data constantly flows in and out of the vehicle; updates to software also go through the CIMs.

14. Importantly, also, the CIMs themselves must receive ‘firmware over the air’ updates. This makes them vulnerable to potential machinations and malware from the CIM manufacturer, something dangerous to put in the hands of companies which ultimately have no choice but to obey the demands of the CCP.

15. Vehicles are just one area where Chinese CIMs are a threat to critical national infrastructure. Cranes, routers, grids, pipelines, payment terminals, building control systems, logistic networks, manufacturing processes and more rely on CIMs. It is worth noting that the EU has recently taken action against inverters in power generation.[6] Within the inverter, it is the CIM which enables the connectivity and the threat. CIMs are now in systems ranging from white goods in the home, security cameras, through to the largest manufacturing and logistics systems. By 2030 it is estimated that there will be over 39 billion IoT connections globally.[7]

16. Time is running out for HMG to take action. Chinese companies now have over 70% of the global market for CIMs. Subsidy, cheap finance, and highly efficient production are squeezing non-Chinese producers. In the last few years several have shuttered their operations, while Chinese companies have also bought up competitors. The three threats of dependency, disruption and data loom ever closer. In conjunction with likeminded powers the UK should develop further the concept of trusted suppliers for CIMs and other crucial technological components.

 

- Concept of a trusted supplier.

The UK, in conjunction with allies, should establish the concept of a trusted supplier. This is work for technological experts, but any qualification for the status should include – at the least – the following elements:

- Technology and updates to firmware should not be reliant in any continuing way on Chinese  

  source codes or servers

- Manufacturing processes should not be vulnerable to Chinese interference

- Trusted suppliers and companies which certify/verify their products should have the staff 

  sufficient in number and technological competence to produce and monitor all updates.

- Trusted suppliers and the companies which certify their CIMs should have server capacity in

  the US or Europe, sufficient to service every CIM sold.

- Companies’ primary and ‘mirror’ servers must be located outside China and where they are  

  not vulnerable to Chinese penetration.

- Governments must verify the competence and integrity of the companies which certify

  trusted suppliers.]

 

17. In the last decade, HMG has passed legislation to shore up national resilience and to protect economic and national security. The National Security Investment Act and the Procurement Act are salient examples. The problem is not so much with the legislation but with its implementation. Government needs to be held to a closer account. For example, the Procurement Act contains a “debarment list”. The Minister in charge can put companies which pose a threat to national security on the debarment list, meaning that their presence in any part of a bid for a government contract rules out that bid. So far, no companies have been listed. Chinese CIM companies should be investigated and listed.

 

Some further thoughts on the Committees questions

18. A truly national approach is needed. That means ensuring that the Scottish, Welsh, Northern Irish and major mayoral authorities (eg Manchester) are kept well informed about central government thinking. The CCP devotes considerable resources to making direct contact with authorities outside the central government, precisely because it knows that local governments are not so well sighted on Chinese intentions. HMG currently devotes resources to training civil servants on courses to familiarise them with dealing with China. These courses should be funded and taken out to local governments.

19. The private sector has an imperative to make money and keep costs down. This sometimes goes against the demands of national resilience and security, and there have been instances where companies play down the threat, eg from CIMs. This underlines the importance of setting the tone and standards via the “debarment list” under the Procurement Act. It would greatly increase the development of an overall security culture.

 

Conclusion

20. The priority for action currently lies with HMG. Until HMG sets a clear strategy and agenda for action, local, organisational, individual action will lack coherence and effect. Since the greatest long-term threat to the UK’s national resilience and security comes from China, that should be the main focus. The obvious point should also be stressed: while China is undoubtedly a threat, it also represents opportunity and inevitability – the UK cannot ignore a fifth of the world’s population and the second greatest power. But until the government gives a clear and consistent steer on the main threat to national resilience, ie China, it will continue to waste time and resources.

 

Risk Assessment

1. How far are national and international risks inter-connected, including across different sectors and across short-term and long-term risks, and what are the implications for the national approach towards preparedness and resilience?

2. What national risks could have the most severe impact in a reasonable worst-case scenario, including nuclear accidents and loss of control of satellite communications?

3. Since the 2025 Strategic Defence Review, what changes have there been to the national resilience implications of the geopolitical environment for defence spending, development of the country’s industrial base, and military recruitment?

4. What risks does the private sector face, including to cyber activity and supply chains, and how do these vary across key industries, such as finance, food, water, medicine, and transport?

 

Whole of Society Approach

5. How can a shared vision be developed to improve preparedness and resilience across the whole of society?

6. How can understanding of preparedness and resilience be improved, with action encouraged at all levels of society so that these priorities are both seen as relevant and achievable in practice?

7. How can the preparedness and resilience of civil society be strengthened, such as through funding community organisations and the inclusion of people of all ages and from all backgrounds?

 

Communication and Information

8. What does the public perceive to be the biggest risks, and how can communication help to provide information about these risks, including those that are already established or materialising, and support conversations about attitudes towards preparedness and resilience?

9. What are the risks of disinformation concerning preparedness and resilience, including through digital channels and around elections, and how can these be mitigated, such as through the involvement of community organisations?

10. How should communication concerning preparedness and resilience, including the national curriculum, be targeted for particular groups, including young people aged 11-17, students, and vulnerable people?

 

Cross-cutting Issues

11. What barriers have there been to implementing improvements to preparedness and resilience, such as inaction, inappropriate structures, inadequate funding, and short-term thinking?

12. What legislative measures should be considered to improve preparedness and resilience, such as a Defence Readiness Act and duties for organisations to incorporate resilience into their internal planning and business models?

13. What lessons concerning preparedness and resilience can the UK learn from other countries, including Nordic countries, and how can it facilitate international co-operation on these issues?

14. How were preparedness and resilience achieved in the past, such as during the Second World War, and what are the implications for the current environment?

 

17 April 2026


[1] His Majesty’s Government (HMG) defines CNI under 17 headings (see for example: XXXXXX), but the 5 listed here are the most important

[2] For more on this ambition, see pages 6-9 of ‘China, science and technology: Advancing geopolitical aims’, https://www.geostrategy.org.uk/app/uploads/2025/02/No.-2025-05-China-science-and-technology-advancing-geopolitical-aims.pdf

[3] For a summary of the Volt Typhoon’s attack to scope out CNI, see https://en.wikipedia.org/wiki/Volt_Typhoon

[4] https://edition.cnn.com/2022/05/01/europe/russia-farm-vehicles-ukraine-disabled-melitopol-intl

[5] Although the report does not specify that the vehicle was the prime minister’s car, that fact was confirmed by two very well placed sources. https://inews.co.uk/news/hidden-chinese-tracking-device-government-car-national-security-2070152

[6]

[7] https://www.gsmaintelligence.com/research/iot-market-forecast-to-2030-connections-by-region-and-vertical