The Growing Threat Of Russian Cyber Reprisals On Britain

Banks, energy and water companies are on maximum alert over the threat of a serious cyber-attack from Moscow as concern continues over the safety of Russian exiles in the UK.

Fears that Russia will target Britain’s critical national infrastructure have prompted round-the-clock threat assessments by the UK’s financial sector, energy firms and GCHQ, the UK’s largest intelligence agency, along with the security services MI5 and MI6.

The Bank of England, major financial institutions, including Lloyds and organisations such as Water UK are working with the government’s National Cyber Security Centre (NCSC) to assess the next move from Moscow following the murder of Nikolai Glushkov, 68, and the Salisbury chemical attack.

Scotland Yard on Saturday 17th March issued a renewed appeal for information for anyone who may have seen a burgundy red BMW owned by Sergei Skripal, 66, the former Russian spy who was found unconscious on 4 March in Salisbury along with his daughter, Yulia.

The pair were poisoned with a nerve agent and remain critical but stable in hospital. Glushkov, a businessman and a known critic of President Vladimir Putin, was found strangled at his home in London last week. 

Police across Britain have begun contacting Russian exiles to discuss their safety as they investigate the murder of Glushkov, understood to have been on a list of 22 “fugitives” published by the Russian embassy in London last year. Officers have yet to establish if there is a link between the attacks.

Intelligence officials, however, fear that Moscow may strike next using very different methods, referring to Russia’s involvement in the crippling NotPetya ransomware cyber-attack last year that targeted Ukraine’s financial, energy and government sectors before it spread across the world.

On Thursday 15th March the Trump administration accused Russia of engineering a series of cyber-attacks that targeted American and European nuclear power plants and water and electricity systems, the first time the United States has publicly accused Moscow of hacking into America’s energy infrastructure.

The UK’s NCSC is based inside GCHQ and notifies UK firms considered to be “critical national infrastructure” and the government of the latest threat level. It is monitoring significant Russian activity in the UK, though it is understood that no specific threat from Russia has emerged since the attempted murder of Skripal and his 33-year-old daughter and the murder of Glushkov. Robert Hannigan, a former director of GCHQ and the National Security Council, told the Observer that the NCSC was monitoring “very large volumes” of attacks every day on the UK, including its globally important financial services.
Hannigan, who was responsible for the UK’s first cyber strategy in 2009 and is now a senior associate fellow at the Royal United Services Institute, said that from his experience, which also includes three years as prime minister Tony Blair’s security adviser, he had never seen Russia so unpredictable and hostile. “In their [the Russians] current mood it’s hard to know what they will do. What’s different now is the willingness to be reckless, not to play by the rules that most civilised countries play by and not to worry about being found out. They no longer seem to care.”

Hannigan said they were continually detecting Russians on UK cyber networks. “They’re constantly being found on networks but it’s their intent that matters more than the fact they are there. The difficulty with cyber is that you can be on a network to gather intelligence or you can be on a network to do something destructive and the two look pretty much the same.”

A senior banking source, confirming that the sector was working closely with GCHQ and the security services to evaluate any threat from Russia, said they were also concerned about the risk of attack, not just from the Kremlin but from rogue elements caught up in the febrile climate that has prevailed since the Salisbury chemical attack. 

“It is possible that Russian patriots may take it upon themselves to make a point at a time like this,” said the source.
A Lloyds spokesman said: “We update and test our defences regularly and work closely with both industry bodies and law enforcement agencies to help us protect our customers.” 

A Water UK spokesperson, which represents the major water companies, said it was in regular contact with government officials to ensure its cyber defences were sufficiently robust. 

The UK government has floated the idea of fining organisations which fail to implement effective cyber security measures as part of plans to make Britain’s essential infrastructure resilient against future cyber-attacks. 

Beyza Unal, a research fellow at Chatham House’s international security department, said that the UK had been shoring up its defences in the face of the evolving cyber threat. “The UK has a really good cyber defence strategy planning as well as organisation, each sector talks to the government organisations,” she said.

Latest figures from the NCSC reveal more than 1,100 attacks over the past year, 590 significant. Thirty required action by government bodies, a number of which targeted the UK’s internationally important financial sector.

Guardian

You Might Also Read:

Russia Warns UK Against Cyber Retaliation:

British IT Bosses Fear Sophisticated Cyber Threats:

UK To Increase National Cyber Defences:
 

« North Korea's Cyber Soldiers Are Concealed Abroad
Millions Of Facebook Profiles Were ‘Harvested’ In US Election Breach »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Logicalis

Logicalis

Logicalis are a leading provider of global IT solutions and managed services.

Egress Software Technologies

Egress Software Technologies

Egress Software Technologies is a leading provider of data security services designed to protect shared information throughout its lifecycle.

Daon

Daon

Daon offers a universal biometric authentication platform for mobile devices.

Commissum

Commissum

Commissum specialise in information assurance and security testing services.

IdenTrust

IdenTrust

IdenTrust enables organizations to effectively manage the risks associated with identity authentication.

3Elos

3Elos

3Elos operates in the Information Technology market with a focus on research, development, consulting, marketing and implementation of Information Security solutions.

ICS-CSR

ICS-CSR

ICS-CSR is a research conference bringing together researchers with an interest in the security of industrial control systems.

KeyXentic

KeyXentic

KeyXentic Inc. is a professional mobile and data security service provider. We are devoted to design convenient and strong security for user’s data protection and privacy without any compromise.

Kintent

Kintent

With Kintent, compliance becomes a habit, is simple to understand and achieve, and is continuously testable so that your customers can see that you are adhering to all your trust obligations.

Hex-Rays

Hex-Rays

Founded in 2005, privately held, Belgium based, Hex-Rays SA focuses on the development of fast, stable, and robust binary analysis tools for the IT security market.

DTS Systeme

DTS Systeme

DTS Systeme is an IT service provider with a focus on the core areas of datacenter, technologies and IT security.

Cyber Chasse

Cyber Chasse

Cyber Chasse is an IT consulting and staffing company offering a full range of cybersecurity solutions, contract staffing services and online training courses.

Network Contagion Research Institute (NCRI)

Network Contagion Research Institute (NCRI)

NCRI provides pioneering technology, research, and analysis to identify and forecast cyber-social threats targeting individuals, organizations, and communities.

Silverse

Silverse

At Silverse, we specialize in building a comprehensive cybersecurity journey, anchored by our extensive experience, industry expertise, and an ecosystem of trusted partners.

SecurEnvoy

SecurEnvoy

SecurEnvoy are a leader in designing zero access trust solutions using the latest cutting-edge technologies, to protect your users, devices and data, whatever the location.

Techtron Business IT Services

Techtron Business IT Services

TECHTRON has been providing business IT services since 2004. Our focus is on SMBs and we are good at it. Our customers trust us, they love our high levels of service, and they love what we stand for.