UK Will Name The Nations Sponsoring Cyber Attacks

Britain will name and shame foreign states that hire hackers to carry out cyber-attacks or interfere via the Internet in national elections, the British attorney general has warned.

In a speech referring to Russian and North Korean “campaigns of intrusion”, Jeremy Wright QC called for international sanctions to be applied against countries that exploit cyberspace for illegal purposes.

“If we stay silent, if we accept that the challenges posed by cyber technology are too great for the existing framework of international law to bear, that cyberspace will always be a grey area, a place of blurred boundaries, then we should expect cyberspace to continue to become a more dangerous place,” Wright told an audience at Chatham House in central London.

“The question is not whether or not international law applies, but rather how it applies and whether our current understanding is sufficient ... Hostile actors cannot take action by cyber means without consequence, both in peacetime and in times of conflict. States that are targeted by hostile cyber operations have the right to respond to those operations in accordance with the options lawfully available to them ...

“If it would be a breach of international law to bomb an air traffic control tower with the effect of downing civilian aircraft, then it will be a breach of international law to use a hostile cyber operation to disable air traffic control systems which results in the same, ultimately lethal, effects.” 

Such rights are already established in the UN charter, Wright said, including prohibitions on interventions in the domestic affairs of states and the threat or use of force against the territorial independence or political integrity of any country. 

Cyber operations that cause, or present an imminent threat of, death and destruction on an equivalent scale to an armed attack also give rise to an inherent right to take action in self-defence as recognised under article 51 of the UN charter, Wright said.

“If a hostile state interferes with the operation of one of our nuclear reactors, resulting in widespread loss of life, the fact that the act is carried out by way of a cyber operation does not prevent it from being viewed as an unlawful use of force or an armed attack against us.”

Counter-measures cannot involve the use of force, he said. They must be both necessary and proportionate to the purpose of inducing the hostile state to comply with its obligations under international law. 

The UK does not believe that it is always legally obliged to give prior notification to a hostile state before taking counter-measures against it.

“It could not be right for international law to require a counter-measure to expose highly sensitive capabilities in defending the country in the cyber arena, as in any other arena.” 

Wright’s comments, which follow an FBI inquiry into alleged Russian interference in the 2016 US presidential election, are intended to deter hacking attacks from abroad and attempts by foreign states to influence domestic politics. Wright is keen to ensure that international law keeps up with the rapid pace of technological development and that the international community does not let cyberspace degenerate into a “lawless world”. The UK, he added, is prepared to identify states that recruit proxy actors or hackers to disguise the source of online attacks. 

The WannaCry ransomware incident last year, which affected the NHS, was attributed by the UK and its allies to North Korean-sponsored hackers.

The new National Cyber Security Centre has a mandate to protect Britain’s interests in cyberspace. In the past year it identified on average 4.5m malicious emails per month. The UK government has said it is investing £1.9bn in cybersecurity. 
Other cyber-attacks in which the UK has named and shamed state actors include the hack and leak of Democratic National Committee emails in the run-up to the US election.

This year, Britain blamed the Russian military for the NotPetya ransomware attack, which started in the Ukraine and spread around the world.

In April, the National Cyber Security Centre, the US Department for Homeland Security and the FBI issued a joint statement saying there had been an extensive and sustained Russian campaign of intrusions into the internet infrastructure of the UK and the US.

Guardian

You Might Also Read: 

Nation State Cyber Attacks Are An Act Of War:

Nation State Hacking Is On Trend In 2018:
 

« Cybercrime Is Increasing In Scotland
Facebook Gave Chinese Tech Firms Access To User Data »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Nuix

Nuix

Nuix specialise in extracting knowledge from unstructured data. Applications include Digital Forensics, Cybersecurity Intelligence, Information Governance, eDiscovery.

Portnox

Portnox

In 2007, Portnox set out to create one of the world’s easiest to use, most loved, value-driven network security solutions — and our customers will tell you we’ve succeeded.

Momentum

Momentum

The Cyber Security team at Momentum offers a professional and specialist recruitment service across Cyber & IT Security.

Apcon

Apcon

Apcon's mission is to provide valuable network insights that enable security and network professionals to monitor, secure and protect their data in both physical and virtual environments.

CERTuy

CERTuy

CERTuy is the national Computer Emergency Response Team for Uruguay.

CyberSecurity Malaysia

CyberSecurity Malaysia

CyberSecurity Malaysia is the national cyber security specialist agency under the Ministry of Science, Technology and Innovation (MOSTI).

Cloudmark

Cloudmark

Cloudmark is a trusted leader in intelligent threat protection against known and future attacks, safeguarding 12 percent of the world’s inboxes from wide-scale and targeted email threats.

ENVEIL

ENVEIL

ENVEIL’s technology is the first scalable commercial solution to cryptographically secure Data in Use.

Silverfort

Silverfort

Silverfort introduces the first security platform enabling adaptive authentication and identity theft prevention for sensitive user, device and resource throughout the entire organization.

Coursera

Coursera

Coursera provides universal access to the world’s best education, partnering with top universities and organizations to offer courses online. Subject areas include Computer Security & Networks.

Wipro

Wipro

Wipro Limited is a leading global information technology, consulting and business process services company.

Sidcon International Consulting Company

Sidcon International Consulting Company

SIDCON International Consulting Company has been providing consulting services since 2002 for private and public organizations in Ukraine and other countries.

Mondoo

Mondoo

Mondoo is a powerful security, compliance, and asset inventory tool that helps businesses identify vulnerabilities, track lost assets, and ensure policy compliance across their entire infrastructure.

SydeLabs

SydeLabs

At SydeLabs, our mission is to ensure the comprehensive security of your AI systems.

Anetac

Anetac

Developed by seasoned cybersecurity experts, the Anetac Identity and Security Platform protects threat surface exploited via service accounts.

GAM Tech

GAM Tech

GAM Tech is a Managed IT Service Provider that serves small and medium sized businesses in Alberta, British Columbia, Ontario and Quebec.