The Growing Threat Of Russian Cyber Reprisals On Britain

Banks, energy and water companies are on maximum alert over the threat of a serious cyber-attack from Moscow as concern continues over the safety of Russian exiles in the UK.

Fears that Russia will target Britain’s critical national infrastructure have prompted round-the-clock threat assessments by the UK’s financial sector, energy firms and GCHQ, the UK’s largest intelligence agency, along with the security services MI5 and MI6.

The Bank of England, major financial institutions, including Lloyds and organisations such as Water UK are working with the government’s National Cyber Security Centre (NCSC) to assess the next move from Moscow following the murder of Nikolai Glushkov, 68, and the Salisbury chemical attack.

Scotland Yard on Saturday 17th March issued a renewed appeal for information for anyone who may have seen a burgundy red BMW owned by Sergei Skripal, 66, the former Russian spy who was found unconscious on 4 March in Salisbury along with his daughter, Yulia.

The pair were poisoned with a nerve agent and remain critical but stable in hospital. Glushkov, a businessman and a known critic of President Vladimir Putin, was found strangled at his home in London last week. 

Police across Britain have begun contacting Russian exiles to discuss their safety as they investigate the murder of Glushkov, understood to have been on a list of 22 “fugitives” published by the Russian embassy in London last year. Officers have yet to establish if there is a link between the attacks.

Intelligence officials, however, fear that Moscow may strike next using very different methods, referring to Russia’s involvement in the crippling NotPetya ransomware cyber-attack last year that targeted Ukraine’s financial, energy and government sectors before it spread across the world.

On Thursday 15th March the Trump administration accused Russia of engineering a series of cyber-attacks that targeted American and European nuclear power plants and water and electricity systems, the first time the United States has publicly accused Moscow of hacking into America’s energy infrastructure.

The UK’s NCSC is based inside GCHQ and notifies UK firms considered to be “critical national infrastructure” and the government of the latest threat level. It is monitoring significant Russian activity in the UK, though it is understood that no specific threat from Russia has emerged since the attempted murder of Skripal and his 33-year-old daughter and the murder of Glushkov. Robert Hannigan, a former director of GCHQ and the National Security Council, told the Observer that the NCSC was monitoring “very large volumes” of attacks every day on the UK, including its globally important financial services.
Hannigan, who was responsible for the UK’s first cyber strategy in 2009 and is now a senior associate fellow at the Royal United Services Institute, said that from his experience, which also includes three years as prime minister Tony Blair’s security adviser, he had never seen Russia so unpredictable and hostile. “In their [the Russians] current mood it’s hard to know what they will do. What’s different now is the willingness to be reckless, not to play by the rules that most civilised countries play by and not to worry about being found out. They no longer seem to care.”

Hannigan said they were continually detecting Russians on UK cyber networks. “They’re constantly being found on networks but it’s their intent that matters more than the fact they are there. The difficulty with cyber is that you can be on a network to gather intelligence or you can be on a network to do something destructive and the two look pretty much the same.”

A senior banking source, confirming that the sector was working closely with GCHQ and the security services to evaluate any threat from Russia, said they were also concerned about the risk of attack, not just from the Kremlin but from rogue elements caught up in the febrile climate that has prevailed since the Salisbury chemical attack. 

“It is possible that Russian patriots may take it upon themselves to make a point at a time like this,” said the source.
A Lloyds spokesman said: “We update and test our defences regularly and work closely with both industry bodies and law enforcement agencies to help us protect our customers.” 

A Water UK spokesperson, which represents the major water companies, said it was in regular contact with government officials to ensure its cyber defences were sufficiently robust. 

The UK government has floated the idea of fining organisations which fail to implement effective cyber security measures as part of plans to make Britain’s essential infrastructure resilient against future cyber-attacks. 

Beyza Unal, a research fellow at Chatham House’s international security department, said that the UK had been shoring up its defences in the face of the evolving cyber threat. “The UK has a really good cyber defence strategy planning as well as organisation, each sector talks to the government organisations,” she said.

Latest figures from the NCSC reveal more than 1,100 attacks over the past year, 590 significant. Thirty required action by government bodies, a number of which targeted the UK’s internationally important financial sector.

Guardian

You Might Also Read:

Russia Warns UK Against Cyber Retaliation:

British IT Bosses Fear Sophisticated Cyber Threats:

UK To Increase National Cyber Defences:
 

« North Korea's Cyber Soldiers Are Concealed Abroad
Millions Of Facebook Profiles Were ‘Harvested’ In US Election Breach »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Detectify

Detectify

Detectify is a web security service that simulates automated hacker attacks on your website, detecting critical security issues before real hackers do.

Guardsquare

Guardsquare

GuardSquare is the global reference in mobile application protection. We develop premium software for the protection of mobile applications against reverse engineering and hacking.

Dermalog Identification Systems

Dermalog Identification Systems

Dermalog Identification Systems is a pioneer in biometry and the largest German manufacturer of biometric devices and systems.

NSEIT

NSEIT

NSEIT offers end-to-end Information Technology products, solutions and services including cybersecurity to organizations in the financial sector.

Kickstart

Kickstart

Kickstart supports your startup in scaling deep technology businesses in Switzerland in areas such as AI, Blockchain and Cybersecurity.

Bugraptors

Bugraptors

BugRaptors is a certified software testing company with extensive experience as a third-party testing vendor, effectively proven as a leader in software testing & QA Services.

Templar Shield

Templar Shield

Templar Shield is a premier information security, risk and compliance technology professional services firm serving North America.

VariQ

VariQ

VariQ is a premier provider of Cybersecurity, Software Development and Cloud services to federal, state, and local government.

7layers

7layers

7layers has established itself as one of the world’s leading test house groups for mobile devices and the growing number of wireless devices, modules and chipsets.

Capital Network Solutions

Capital Network Solutions

Capital Network Solutions are a highly accredited managed IT services and consultancy provider, specialising in cyber security, infrastructure and communications.

Progress Partners

Progress Partners

Progress Partners is a corporate advisory firm that works with buyers and sellers of emerging growth companies to complete M&A or private placement transactions. Our sectors include cybersecurity.

Intelligent Technical Solutions (ITS)

Intelligent Technical Solutions (ITS)

We help businesses manage their technology. Intelligent Technical Solutions provide you with the right technical solution, so you can get back to running your business.

VP Techno Labs

VP Techno Labs

VP Techno Labs is an award-winning cybersecurity firm focusing only cybersecurity to develop cutting edge solutions for emerging business.

CyberNut

CyberNut

CyberNut are a security awareness training solution built exclusively for schools.

Security Solutions Services (S-3)

Security Solutions Services (S-3)

S-3 specialize in crafting tailored network design, security hardware, software, and storage solutions for businesses of all sizes.

Health Sector Cybersecurity Coordination Center (HC3)

Health Sector Cybersecurity Coordination Center (HC3)

HC3 was created by the US Department of Health and Human Services to aid in the protection of vital, controlled, healthcare-related information.