British Politicians Need To Better Understand Cyber Security

Given the public perception that politicians are a bit clueless on tech/security issues, UK-based cyber security/ethical hacking firm Redscan decided to poll all 650 UK MPs to understand their thoughts on the cyber security threats facing UK businesses. When it comes to the issue of cyber security, recent history doesn’t reflect too kindly on politicians. 

Last November, the Japanese minister of cyber security made headlines for admitting to never having used a computer, while in 2017, Donald Trump claims to have discussed ‘forming an impenetrable cyber security unit’ with Vladimir Putin of all people.  Closer to home, Diane Abbott, the British Shadow Home Secretary, campaign in which hackers could’ve gained control of her PC and accessed all its contents.

The truth is that politicians don’t have a reputation for being particularly security-savvy. This is something we have largely come to accept today, but should we? After all, it would be outrageous for a transport minister to say they didn’t understand the highway code, or if the foreign secretary couldn’t locate Canada on the world map.

While we should not expect politicians to be cyber experts, their decisions influence our digital safety, privacy, and online freedoms. As such, we should expect MPs to have at least a core understanding of cyber security issues, just as they should know about any matter that affects their constituencies, be it healthcare, education or law enforcement. 

As we digitise more of the critical services that underpin our society, such as transport, energy, and possibly even our election process, cyber security will become even more entwined in politics.

To that end, Redscan, a British cyber security company, recently polled the UK’s 650 members of parliament to understand where they believe cyber security should rank among the concerns of businesses. Chi Onwurah, MP for Newcastle Central, is among the most well-informed voices in Parliament when discussing technology matters, and says that earlier in her career, colleagues were extremely naïve to the scale of the cyber security threat.

“When I was Head of Telecoms Technology at Ofcom, said Onwurah. “I was asked to look at internet security. When I came back with tales of bot attacks and honey traps, DDoS and white hat wizards, Trojans and worms, phishing and pharming, I was greeted with understandable scepticism. It was as if I was describing a war in a galaxy far, far away. 

“But I knew it was just a matter of time before cybercrime went mainstream. Unfortunately, I was right.”

Fortunately, not all MPs today are as dismissive of the cyber security threat as they may have been in the past. Sir David Amess provided an example from his constituency in Southend West, where he described “cybercrime having a devastating impact on individuals and businesses.”  Amess spoke of a not-for-profit organisation being bankrupted as the result of a data breach, an all-too-familiar occurrence in recent years.

MPs themselves are not immune to suffering data breaches. Onwurah explained how her office was a victim of a cyber-attack, but fortunate that it did no real damage. “As an MP’s office we had a big department supporting us and there was no compromise of constituents’ data,” Onwurah remarked. 

“If we had been a small business, we wouldn’t have had access to that kind of support, and it could have put us out of action for a lot longer.” This is undeniably true, as data breaches have become extinction events for many businesses.
Madeleine Moon, MP for Bridgend, was quick to suggest a key reason why data breaches are now such a regular occurrence.

“Most staff don’t see cyber security as the reason they come to work, or their responsibility,” she said.

“As citizens we don’t leave our doors and windows open, trusting the police will protect us from burglars. In our online world, everyone needs to understand and follow basic rules to protect our data, our passwords and our networks. We need to learn to close those online doors and windows into our systems.” This is a fitting analogy. 

Unfortunately, people who set secure, unique passwords and activate additional security measures such as two-factor authentication are in the minority. 

Moon’s sentiments were echoed by Meg Hillier, MP for Hackney South and Shoreditch, saying “The UK has a huge challenge to step up to the level of cyber security necessary to be protected against current day threats. There is a severe current and future shortage of essential skills in this area.”

This may, in fact, be the crux of the cyber security challenge. Industry experts report a shortfall of almost 3 million cyber security workers globally, as cyber security threats continue to outpace the number of new applicants to the industry. Hillier is right, we must find a way of reversing this trend before it is too late.

Looking forward, Steve McCabe, MP for Birmingham Selly Oak, wanted to raise the issue of policing cybercrime. “I feel very strongly that there should be a requirement for mandatory reporting of cybercrime by banks and other businesses to the police. There is also a need for a cyber health check, perhaps on an annual basis, to ensure that staff and businesses are treating the issue seriously.” Likewise, Peter Dowd, MP for Bootle, said 

“The crucial issue of policing resources and awareness to tackle cybercrime is one that requires more open debate.” As cybercrime continues to rise in scale and complexity, the issue of how we secure our digital spaces, whilst protecting privacy and online freedoms is not something we have worked out yet. Not even close.

What’s clear, is that the cyber threat to businesses can no longer be dismissed as trivial, as some industry leaders and politicians once did. 

In the face of a rapidly evolving digital landscape, with threats becoming increasingly advanced, we need our politicians to understand the issues and risks at play. We need them to use their influence to raise awareness amongst business communities and shape cyber security national policy that is fit for the future.

Information Age:

You Might Also Read:

British Cyber Security Strategy Is ‘Chaotic’:

 

 

« The UK Needs Data Driven Policing
The Brexit Shaped Gap In UK Cyber Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Cyren

Cyren

Cyren is a cloud-based, Internet security technology company providing threat detection and security analytics.

Intertek Group

Intertek Group

Intertek Group provides Assurance, Testing, Inspection and Certification services. Activities include cybersecurity testing and certification.

D3 Security

D3 Security

D3's Smart SOAR platform is at the forefront of the security automation revolution, helping clients around the world to rapidly identify, analyze, and resolve advanced threats.

DG Technology

DG Technology

DG Technology is a customer-centric technology expert and business consultant that delivers services and products to minimize your information security, compliance, and business risks.

Fluency Security

Fluency Security

Fluency is the only Security Analytics & Orchestration (SAO) solution that automates correlation, detection, validation and ongoing tracking.

Saudi Federation for Cyber Security and Programming (SAFCSP)

Saudi Federation for Cyber Security and Programming (SAFCSP)

SAFCSP is a national institution under the umbrella of the Saudi Arabian Olympic Committee, which seeks to build national and professional capabilities in the fields of cyber security and programming.

IAC

IAC

IAC is a specialist Irecruitment consultancy covering Internal Audit, Risk, Controls, Governance, IT Audit, and Cyber Security roles.

RIGCERT

RIGCERT

RIGCERT provides training, audit and certification services for multiple fields including Information Security.

Sky Data Vault

Sky Data Vault

Sky Data Vault provide the simplest and most cost effective method of Disaster Recovery / Business Continuity for mission critical systems and applications.

Venrock

Venrock

Venrock helps entrepreneurs build some of the world's most disruptive, successful companies. We invest in technology: Security, Cloud Services, Big Data, Healthcare IT, AdTech.

Schweitzer Engineering Laboratories (SEL)

Schweitzer Engineering Laboratories (SEL)

SEL specializes in creating digital products and systems that protect, control, and automate power systems around the world.

Cyber Insurance Academy

Cyber Insurance Academy

Cyber Insurance Academy was founded to provide insurance professionals with the knowledge needed to work in cyber-insurance and cyber-related insurance fields.

Ibento Global

Ibento Global

Ibento organises the CyberX series of cybersecurity conferences.

Metallic.io

Metallic.io

Metallic (formerly TrapX) is a SaaS portfolio for enterprise-grade backup and recovery, designed to protect your data from corruption, deletion, ransomware, and other threats.

Sev1Tech

Sev1Tech

Sev1Tech is a leading provider of IT modernization, cloud, cybersecurity, engineering, fielding, training, and program support services.

Cyber & Data Protection

Cyber & Data Protection

Cyber & Data Protection Limited supports Charities, Educational Trusts and Private Schools, Hospitality and Legal organisations by keeping their data secure and usable.