Queen opens Centre to protect against Attacks

The Queen was shown how hackers could target the UK's electricity supply as she opened a centre to protect the nation from cyber-attacks.

The National Cyber Security Centre, part of intelligence agency GCHQ, started work in October as part of a £1.9bn five-year strategy.

Staff in Victoria, central London, will be joined by experts from the private sector to help identify threats. NCSC chief Ciaran Martin said: "We want to make the UK the hardest target".

The secondments to the centre by 100 private sector employees will be funded by their own companies.

Announcing the initiative, Chancellor Philip Hammond said the "best and the brightest in industry" will help "test and to challenge the government's thinking" in cyber security.

Russia Concern

There were 188 cyber-attacks classed by the NCSC as Category Two or Three during the last three months.

And even though the UK has not experienced a Category One attack, the, highest level, an example of which would have been the theft of confidential details of millions of Americans from the Office of Personnel Management, there is no air of complacency at the NCSC's new headquarters.

Ciaran Martin, the Centre's Chief Executive, told the BBC: "We have had significant losses of personal data, significant intrusions by hostile state actors, significant reconnaissance against critical national infrastructure, and our job is to make sure we deal with it in the most effective way possible."

As well as protecting against and responding to high-end attacks on government and business, the NCSC also aims to protect the economy and wider society.

The UK is one of the most digitally dependent economies, with the digital sector estimated to be worth over £118bn per year, which means the country has much to lose.

It is not just a crippling cyber-attack on infrastructure that could turn out the lights which worries officials, but also a loss of confidence in the digital economy from consumers and businesses, as a result of criminals exploiting online vulnerabilities.

A sustained effort was required by government and private sector working together to make the UK the hardest possible target, officials say.

Russia has been the focus of recent concern, following claims it used cyber-attacks to interfere with the recent US presidential election.

"I think there has been a significant change in the Russian approach to cyber-attacks and the willingness to carry it out, and clearly that's something we need to be prepared to deal with," Mr Martin said.

French and German officials have warned of the possibility of interference in their upcoming elections, but the NCSC's head said there was no evidence that a significant attack or compromise had yet taken place against the UK democratic process.

"There has been an identifiable trend in Russian attacks in the West, in terms of focusing on critical national industries and political and democratic processes," Mr Martin added.

"And so it follows from that that we will look to be sure we are protecting those sectors in the UK as well as we possibly can."

The centre will be working on a voluntary basis with political parties and giving advice to high-profile individuals - including MPs - on how to protect their sensitive data.

The UK is already targeting computers in other countries being used for cyber-attack, particularly if there is no possibility of prosecution or for co-operation with authorities where the hackers are based.

In the past, UK cyber protection was largely situated within GCHQ in Cheltenham, which was criticised by businesses and others as overly secretive.

The NCSC aims to be more public facing and accessible. It will also protect a far wider range of sectors, rather than just government and national security-related industries, like defence.

GCHQ will still be the parent body for the NCSC, meaning it can draw on the intelligence agency's skills and capabilities. Sometimes, the intelligence arm of GCHQ spots compromised networks as it watches adversaries move across the Internet.

It was through this type of work that GCHQ spotted the compromise of the US Democratic Party's information by Russian hackers, which it then informed US authorities about.

The NCSC is working on trial services to pro-actively discover vulnerabilities in public sector websites, help government departments better manage spoofing of their email, and take down tens of thousands of phishing sites affecting the UK.

"We're actively working to reduce the harm caused by cyber-attacks against the UK and will use the government as a guinea pig for all the measures we want to see done by industry at national scale," says the NCSC technical director, Dr Ian Levy.

He says results would be published openly to enhance collaboration. The centre will be publishing some of its code as open source, so that others can use the techniques.

BBC

 

« Dell Says Security Is Plaguing Business
Bitcoin Is Increasing Ransom Attacks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Skybox Security

Skybox Security

Skybox combines firewall and network device data with vulnerability and threat intelligence, putting security decisions in your unique network context.

Hack in the Box Security Conference (HitBSecConf)

Hack in the Box Security Conference (HitBSecConf)

HITBSecConf is a platform for the discussion and dissemination of next generation computer security issues. Our events feature two days of training and a two-day multi-track conference

National Cyber and Information Security Agency (NUKIB) - Czech Republic

National Cyber and Information Security Agency (NUKIB) - Czech Republic

NUKIB is the central Czech government body for cyber security, the protection of classified information in the area of information and communication systems and cryptographic protection.

OEDIV SecuSys

OEDIV SecuSys

OEDIV SecuSys (formerly iSM Secu-Sys) develops high-quality IT software solutions, setting standards as a technology leader in the area of identity and access management.

ZenMate

ZenMate

ZenMate is a Virtual Private Network services provider offering secure encrypted access to the internet.

Zamna

Zamna

Zamna (formerly VChain Technology) is an award-winning software company building GDPR compliant identity platforms for the aviation industry.

Jump Capital

Jump Capital

Jump provides series A and B capital to data-driven tech companies within the FinTech, IT & Data Infrastructure, B2B SaaS and Media sectors.

Cyberspace Solarium Commission (CSC)

Cyberspace Solarium Commission (CSC)

The Cyberspace Solarium Commission was established to develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences.

Syndis

Syndis

Syndis is a leading information security company helping to defend organizations by providing bespoke services and innovative security solutions in the global market.

Vietnamese Security Network (VSEC)

Vietnamese Security Network (VSEC)

Vietnamese Security Network (VSEC) is an information security company providing website vulnerability scanning and monitoring services.

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

AWS Marketplace eBook: Optimizing your cloud deployments to accelerate cloud activities, reduce costs, and improve customer experience.

Ankura Consulting Group

Ankura Consulting Group

Ankura is a global expert services and advisory firm that delivers services and end-to-end solutions in a wide range of areas including cybersecurity and digital transformation.

Think|Stack

Think|Stack

Think|Stack is a managed IT services company specializing in cloud and cybersecurity with human-centered design.

Tenable

Tenable

Organizations around the world rely on Tenable to help them understand and reduce cybersecurity risk across their attack surface—in the cloud or on-premises, from IT to OT and beyond.

Mindsprint

Mindsprint

Mindsprint (formerly Olam Technology and Business Services - OTBS) are a leading edge technology and business services firm.

MiDO Technologies

MiDO Technologies

MiDO Technologies has a mission to change the narrative around digital enabling tools on the continent of Africa and prepare African youth.