British Politicians Need To Better Understand Cyber Security

Given the public perception that politicians are a bit clueless on tech/security issues, UK-based cyber security/ethical hacking firm Redscan decided to poll all 650 UK MPs to understand their thoughts on the cyber security threats facing UK businesses. When it comes to the issue of cyber security, recent history doesn’t reflect too kindly on politicians. 

Last November, the Japanese minister of cyber security made headlines for admitting to never having used a computer, while in 2017, Donald Trump claims to have discussed ‘forming an impenetrable cyber security unit’ with Vladimir Putin of all people.  Closer to home, Diane Abbott, the British Shadow Home Secretary, campaign in which hackers could’ve gained control of her PC and accessed all its contents.

The truth is that politicians don’t have a reputation for being particularly security-savvy. This is something we have largely come to accept today, but should we? After all, it would be outrageous for a transport minister to say they didn’t understand the highway code, or if the foreign secretary couldn’t locate Canada on the world map.

While we should not expect politicians to be cyber experts, their decisions influence our digital safety, privacy, and online freedoms. As such, we should expect MPs to have at least a core understanding of cyber security issues, just as they should know about any matter that affects their constituencies, be it healthcare, education or law enforcement. 

As we digitise more of the critical services that underpin our society, such as transport, energy, and possibly even our election process, cyber security will become even more entwined in politics.

To that end, Redscan, a British cyber security company, recently polled the UK’s 650 members of parliament to understand where they believe cyber security should rank among the concerns of businesses. Chi Onwurah, MP for Newcastle Central, is among the most well-informed voices in Parliament when discussing technology matters, and says that earlier in her career, colleagues were extremely naïve to the scale of the cyber security threat.

“When I was Head of Telecoms Technology at Ofcom, said Onwurah. “I was asked to look at internet security. When I came back with tales of bot attacks and honey traps, DDoS and white hat wizards, Trojans and worms, phishing and pharming, I was greeted with understandable scepticism. It was as if I was describing a war in a galaxy far, far away. 

“But I knew it was just a matter of time before cybercrime went mainstream. Unfortunately, I was right.”

Fortunately, not all MPs today are as dismissive of the cyber security threat as they may have been in the past. Sir David Amess provided an example from his constituency in Southend West, where he described “cybercrime having a devastating impact on individuals and businesses.”  Amess spoke of a not-for-profit organisation being bankrupted as the result of a data breach, an all-too-familiar occurrence in recent years.

MPs themselves are not immune to suffering data breaches. Onwurah explained how her office was a victim of a cyber-attack, but fortunate that it did no real damage. “As an MP’s office we had a big department supporting us and there was no compromise of constituents’ data,” Onwurah remarked. 

“If we had been a small business, we wouldn’t have had access to that kind of support, and it could have put us out of action for a lot longer.” This is undeniably true, as data breaches have become extinction events for many businesses.
Madeleine Moon, MP for Bridgend, was quick to suggest a key reason why data breaches are now such a regular occurrence.

“Most staff don’t see cyber security as the reason they come to work, or their responsibility,” she said.

“As citizens we don’t leave our doors and windows open, trusting the police will protect us from burglars. In our online world, everyone needs to understand and follow basic rules to protect our data, our passwords and our networks. We need to learn to close those online doors and windows into our systems.” This is a fitting analogy. 

Unfortunately, people who set secure, unique passwords and activate additional security measures such as two-factor authentication are in the minority. 

Moon’s sentiments were echoed by Meg Hillier, MP for Hackney South and Shoreditch, saying “The UK has a huge challenge to step up to the level of cyber security necessary to be protected against current day threats. There is a severe current and future shortage of essential skills in this area.”

This may, in fact, be the crux of the cyber security challenge. Industry experts report a shortfall of almost 3 million cyber security workers globally, as cyber security threats continue to outpace the number of new applicants to the industry. Hillier is right, we must find a way of reversing this trend before it is too late.

Looking forward, Steve McCabe, MP for Birmingham Selly Oak, wanted to raise the issue of policing cybercrime. “I feel very strongly that there should be a requirement for mandatory reporting of cybercrime by banks and other businesses to the police. There is also a need for a cyber health check, perhaps on an annual basis, to ensure that staff and businesses are treating the issue seriously.” Likewise, Peter Dowd, MP for Bootle, said 

“The crucial issue of policing resources and awareness to tackle cybercrime is one that requires more open debate.” As cybercrime continues to rise in scale and complexity, the issue of how we secure our digital spaces, whilst protecting privacy and online freedoms is not something we have worked out yet. Not even close.

What’s clear, is that the cyber threat to businesses can no longer be dismissed as trivial, as some industry leaders and politicians once did. 

In the face of a rapidly evolving digital landscape, with threats becoming increasingly advanced, we need our politicians to understand the issues and risks at play. We need them to use their influence to raise awareness amongst business communities and shape cyber security national policy that is fit for the future.

Information Age:

You Might Also Read:

British Cyber Security Strategy Is ‘Chaotic’:

 

 

« The UK Needs Data Driven Policing
The Brexit Shaped Gap In UK Cyber Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Help Net Security

Help Net Security

Help Net Security has been a prime resource for information security news and insight since 1998.

Red Hat

Red Hat

Red Hat is a leader in open source software development. Our software security team proactively identifies weaknesses before they become problems.

Steptoe & Johnson

Steptoe & Johnson

Steptoe is an international law firm with offices in the USA, Europe and China. Practice areas include Cybersecurity, Privacy & National Security.

Oppida

Oppida

Oppida provides tailored IT security services to help you identify security gaps and assist in finding the most effective remediation.

Mondo

Mondo

Mondo is the largest national staffing agency specializing exclusively in high-end, niche IT, Tech, and Digital Marketing talent. Areas of expertise include Cybersecurity.

Focal Point Data Risk

Focal Point Data Risk

Focal Point is a pure-play data risk management provider capable of offering end-to-end consulting, implementation, and training services.

Ensign InfoSecurity

Ensign InfoSecurity

Ensign InfoSecurity is Southeast Asia’s largest pure-play cybersecurity firm.

Accertify

Accertify

Accertify is a leading provider of fraud prevention, chargeback management, and payment gateway solutions.

Aspisec

Aspisec

Aspisec is a cybersecurity company specialized in Firmware Security and Critical Infrastructure Protection.

NetSecurity

NetSecurity

NetSecurity is a Brazilian company specializing in Information Security. We provide Managed Security Services (MSS), network security solutions and other specialist services.

NASK SA

NASK SA

NASK SA is an integrator of telecommunications services. We provide advanced ICT security services, collocation and hosting, data centre services, and build corporate networks.

Guernsey

Guernsey

Guernsey provides a wide range of engineering, architecture and consulting services to multiple markets, including cybersecurity consulting and CMMC certification.

Incognia

Incognia

Incognia have created a ubiquitous private identity based on location behavior, that enables a personalized frictionless experience with mobile apps and connected devices.

Astrill VPN

Astrill VPN

Astrill VPN is a Seychelles based Virtual Private Network(VPN) Company.

Innov8tif

Innov8tif

Innov8tif is an AI company specialised in providing ID assurance solutions — helping digital businesses to prevent frauds by verifying and authenticating customers identity.

Brightside AI

Brightside AI

Brightside AI is a Swiss cybersecurity SaaS that helps teams combat AI-enabled phishing threats. Protect your team today.