British Cyber Security Strategy Is ‘Chaotic’

Responding to potential threats at a national level is unfeasible given the time ministers are currently dedicating to Brexit negotiations, says shadow Cabinet Office minister. The UK cyber security strategy is in a “chaotic” state, shadow Cabinet Office minister Jo Platt (pictured) has said.

Speaking at the ICT Public Sector event on 21 March 2019, Platt told the audience the security measures in place to protect the UK against a cyber-attack were insufficient.

“The current cyber strategy is not fit for purpose, it does not put the public interest first,” the Labour MP pointed out.

Platt said that since joining the shadow cabinet, she had met with several associations and trade bodies, many of which have said they lack direction, leadership and vision from government.

“It’s not difficult to see why. The current organisation of cyber across government is chaotic,” the shadow minister said, citing that six departments have various cyber responsibilities, with the same amount of secretaries of state and sets of civil servants, who deliver six different responses to the cyber security issue, without any cohesion.

Many point to Cabinet Office minister David Lidington for such direction, Platt said, which is unfeasible given the time he is currently dedicating to Brexit negotiations. “He just cannot be providing the focus, the drive and the steer needed,” she said.
Referring to the Joint Committee on National Security Strategy, which pointed out that ministerial responsibilities meant that everyday oversight of cross-government efforts was a task carried out mostly by officials, Platt said cyber security was not a task that could be delegated.

“Our nation’s cyber security cannot be led by ministers who just occasionally check in. I find it negligent that an issue with the gravity, the seriousness and the urgency of cyber security, an issue we know presents grave dangers, is treated as a side job, a distraction, an addition by this government,” Platt said.

The shadow minister argued that such an approach was “hardly surprising” as the government had “doubled up the role of Cabinet secretary with that of national security advisor” and “failed to appoint a chief data officer and a permanent chief security officer”.

“This is from the same government that has no idea how many public sector computers are running Windows XP, almost two years after WannaCry,” Platt said, adding that the government fails to record the number of attacks that hit the public sector each year.

Earlier this month, the National Audit Office (NAO) criticised the Cabinet Office over failings in how it set up the National Cyber Security Programme (NCSP), which means it may struggle to meet its goals. The NAO said it was unclear whether or not the NCSP, which was created in 2017 to establish a “focal point” for cyber security activity across government, would achieve any of its wider strategic outcomes by 2021.

To address the issues, Platt said a Labour government would create a new framework for tackling cyber security threats and facilitating cooperation and coordination across Whitehall and local authorities, which would also be provided with more resources.

Platt also said the current government’s cyber security plan “openly and explicitly” expects private companies to address threats.

“The UK’s cyber security measures] entrust [the private sector] to close the gaps without even a carrot or a stick. To put it simply, it too often asks private companies to find the solution to a public good,” Platt argued.
“We must be unafraid to reclaim the cyber landscape and to confidently put the public interest first, because where corners are cut, vulnerabilities lay idle and we take our eyes off the ball, other actors, hostile to us, will step in.”

Plugging the Cyber Security Skills Gap
Addressing the skills gap was also cited in Platt’s speech. She said 54% of all businesses and charities had a basic technical cyber security skills gap, but the government hadn’t even calculated the shortages in that particular area of expertise. Citing the current administration’s Immediate Impact Fund, designed to quickly plug the gap and help around 50,000 people, Platt said the fund was helping just 170 individuals.

“Clearly, the plan is failing,” she said, adding that rather than placing responsibility on the private sector to solve the skills issue, the government needed to take more effective action.

Platt said Labour intended to create regional skills councils to develop expertise and introduce a “vibrant cyber sector” to help vulnerable communities.

“We must look towards place-based schemes, not only to revitalise areas left feeling hollowed from the process of de-industrialisation, but also to ensure that no matter where a business is located, it is not compromised because of regional inequalities,” she added.

“It is only government that can provide that whole-system approach needed – stretching right from school through to employment. It must do its fair part to ensure the skills gap shrinks,” Platt pointed out.

The shadow minister concluded her speech by saying that where Conservatives had “absolved and abdicated leadership” for cyber security, Labour was ready to provide it.

“It’s clear that we need a new strategy. We cannot wait for another WannaCry or worse before we take action. We know a crippling attack is coming our way, the questions is when not if, and when it does, a Labour government will be ready for it,” Platt said.

Computer Weekly:

You Might Also Read:

No Brexit Deal? Then Its ‘Digital Dover’:

 

« AI Is The New Route For Both Cyber Attacks And Their Prevention
Five Tech Trends Driving Cyber Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Digital Forensics Inc (DFI)

Digital Forensics Inc (DFI)

Digital Forensics Inc. is a nationally recognized High Technology Forensic Investigations and Information System Security firm

RCMP Cybercrime Strategy

RCMP Cybercrime Strategy

The RCMP Cybercrime Strategy sets out in an Operational Framework and Action Plan to combat cybercrime.

Secure Thingz

Secure Thingz

Secure Thingz focus on developing and delivering advanced security solutions into the emerging Industrial Internet of Things (IIoT) and Critical Infrastructure markets.

ESG Elektroniksystem- und Logistik-GmbH

ESG Elektroniksystem- und Logistik-GmbH

ESG offer a comprehensive portfolio of cyber and IT services ranging from consulting, solutions and operations to testing, simulation and training.

CryptoCodex

CryptoCodex

Cryptocodex has developed Counter-Fight, the most advanced, yet simple to implement, counterfeit detection system.

SCADAfence

SCADAfence

SCADAfence offers cutting edge cybersecurity solutions designed to ensure the operational continuity of industrial (ICS/SCADA) networks.

GuidePoint Security

GuidePoint Security

GuidePoint Security provide information security solutions that enable commercial and federal organizations to more successfully achieve their security and business goals.

Infosec (T) Ltd

Infosec (T) Ltd

Infosec (T) Limited is an independent Tanzania based consultancy specializing in IT governance, information security and IT audit.

National Accreditation Agency of Ukraine (NAAU)

National Accreditation Agency of Ukraine (NAAU)

NAAU is the national accreditation body for Ukraine. The directory of members provides details of organisations offering certification services for ISO 27001.

SPARTA Consortium

SPARTA Consortium

SPARTA tackles hard innovation challenges, leading the way in building transformative capabilities and forming a world-leading cybersecurity competence network across the EU.

TechBeacon

TechBeacon

TechBeacon.com is a digital hub by and for software engineering, IT and security professionals sharing practical and passionate guidance to real-world challenges.

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

C-MRiC collaborates on initiatives, ranging from national cyber security, enterprise security, information assurance, protection strategy, climate control to health and life sciences.

Yellow Brand Protection

Yellow Brand Protection

Yellow Brand Protection operates 24/7 to protect brands' Intellectual Property (IP) from infringements on all kinds of online distribution channels.

TheHive Project

TheHive Project

TheHive Project is a Scalable, Open Source and Free Security Incident Response Platform for SOC, CSIRT and CERT teams.

CloudWave

CloudWave

CloudWave, the expert in healthcare data security, provides cloud, cybersecurity, and managed services to healthcare organizations.

Merlin Ventures

Merlin Ventures

Merlin Ventures is a strategic investor focused on driving growth and value for cybersecurity software companies with market-leading potential.