UK Will Retaliate Against Cyberattacks

The UK must be able to retaliate in kind against cyber-attacks, the chancellor has said.  Philip Hammond added that hostile "foreign actors" were developing techniques that threaten the country's electrical grid and airports.

The warning came within a speech describing how the government plans to spend a previously announced £1.9bn sum on cybersecurity. It also addressed ways to tackle cyber-scammers and defend businesses. "If we do not have the ability to respond in cyberspace to an attack which takes down our power network - leaving us in darkness or hits our air traffic control system grounding our planes - we would be left with the impossible choice of turning the other cheek, ignoring the devastating consequences, or resorting to a military response," Mr Hammond said as he described the National Cyber Security Strategy in London.

"That is a choice we do not want to face and a choice we do not want to leave as a legacy to our successors."

The strategy will help enlarge specialist police units that tackle organised online gangs. In addition, some cash will also go towards education and training of cybersecurity experts. "If we want Britain to be the best place in the world to be a tech business then it is also crucial that Britain is a safe place to do the digital business," the chancellor added. "Trust in the internet and the infrastructure on which it relies is fundamental to our economic future."

Mr Hammond's speech followed a warning from MI5 that Russia poses an increased cyber-threat. "It is using its whole range of state organs and powers to push its foreign policy abroad in increasingly aggressive ways - involving propaganda, espionage, subversion and cyber-attacks," Andrew Parker, the domestic security agency's director general, told the Guardian.

The Kremlin has dismissed the allegation. "Until someone produces proof, we will consider those statements unfounded and groundless," said spokesman Dmitry Peskov.

A rare intervention from the head of MI5 warning of aggressive Russian behaviour in cyberspace is a sign of government grappling with how to respond to a changing threat.

Cyber-espionage and crime have been around for years, but what has been new is the willingness of states and other actors to take more aggressive - even destructive - moves in cyberspace.

Until now, the US has been more inclined to confront Russia, notably relating to hacks linked to its impending presidential election. But Andrew Parker's comments, as well as the chancellor's about "striking back" in cyberspace, may be a sign that the UK is now pursuing a similar path.

Sir Tim Berners-Lee, the inventor of the web, told the BBC that it was "absolutely right" that the government was concerned about the issue. "Whether it's script kiddies sitting in their garage or it's a state actor - clearly we've seen the internet can be attacked and has been attacked in all kinds of different ways," he told the Today programme.

"The United Kingdom needs to have a strong but responsible and accountable police force, and [cyber-intelligence agency] GCHQ needs to have the tools to be able to defend us and defend the open internet."

Teens and foreign states

Mr Hammond said Britain "must now keep up with the scale and pace of the threats we face", including those carried out by foreign perpetrators who then try to deny their involvement.

He did not refer directly to Russia or any other specific country. "The ability to detect, trace and retaliate in kind is likely to be the best deterrent," Mr Hammond said. "We will not only defend ourselves in cyberspace, we will strike back in kind when we are attacked."

Ben Gummer, paymaster general, said in a statement: "No longer the stuff of spy thrillers and action movies, cyber-attacks are a reality and they are happening now.

"Our adversaries are varied, organised criminal groups, 'hacktivists', untrained teenagers and foreign states."

Finding talent

The £1.9bn to pay for the national strategy was allocated last year and will fund the programme until the end of 2020.

With the aid of industry, the government has already set up automated systems that screen out malware and spam before it reaches UK citizens. Other projects have helped the government verify where emails come from to thwart specific tax fraud campaigns aimed at the UK.

Future spending plans involved cash for recruiting more than 50 specialists who will work at the cybercrime unit at the National Crime Agency.

These will help tackle organised gangs and aim to raise the cost of engaging in hi-tech crime to make it much less attractive.

The cyber-plan also involves the creation of a Cyber Security Research Institute, "a virtual network UK universities" that will co-ordinate research into efforts to improve defences for smartphones, laptops and tablets.

Security-based start-ups will also get help via an innovation fund that will commercialise work on novel tools and defences.

A national scheme will also be set up to retrain "high-aptitude professionals" as cybersecurity experts. Prof Alan Woodward, a computer security expert from the University of Surrey, said he hoped the government spent cash on the "high volume, low sophistication attacks" that plague people and cause the majority of financial losses.

"I hope the £1.9bn will be spent in growing talent," he said. "The government talk about 50 recruits here and 50 there. I'm afraid we need many more."

Prof Woodward said it was getting "increasingly difficult" to persuade young people to study computer science and getting them to try cybersecurity was "a real headache".

"I would really like to see money put into reaching young people early enough to influence the subjects they decide upon at school and pairing an image for them of just how interesting and rewarding a career in cybersecurity can be," he said.

BBC:       UK To Increase National Cyber Defences:

« Pepper Keep’s Son Robot Dreams on Hold
Cyber-attacks & Hacking: What You Need To Know »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ITpreneurs

ITpreneurs

ITpreneurs provides IT training content, Instructors, Learning Infrastructure and services to IT Training providers.

SISA

SISA

SISA is a global forensics-driven cybersecurity solutions company, trusted by leading organizations for securing their businesses with robust preventive and corrective cybersecurity solutions.

BlueVoyant

BlueVoyant

BlueVoyant's Cyber Defense Platform is security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains.

PrimeKey

PrimeKey

PrimeKey provides organisations with the ability to implement security solutions such as e-ID, e-Passports, authentication, digital signatures, unified digital identities and validation.

Snyk

Snyk

Snyk is the leader in developer security. We empower the world’s developers to build secure applications and equip security teams to meet the demands of the digital world.

Endian

Endian

Endian’s mission is to provide a secure platform that connects distributed people and things, simplifying the digitalization of businesses.

Ponemon Institute

Ponemon Institute

Ponemon Institute conducts independent research on data protection and emerging information technologies.

Wizlynx PTE LTD

Wizlynx PTE LTD

Wizlynx PTE LTD is the Singapore branch of Wizlynx Group located in Singapore, offering Information and Cyber Security Services throughout the entire Asia Pacific (APAC) region.

Intrinsyc Technologies

Intrinsyc Technologies

Intrinsyc provides product development services and Edge Computing modules that are helping to take the Internet of Things products to the next level.

Appsian Security

Appsian Security

Appsian provides powerful solutions that help organizations take control of their business critical data and financial transactions.

Vancord

Vancord

Vancord is an information and security technology company that works in collaboration with clients to support their infrastructure and data security needs for today and tomorrow.

ITQ Latam

ITQ Latam

ITQ Latam are specialists in cybersecurity, in a convergent ecosystem of technological solutions in infrastructure, cloud and security networks.

VENZA

VENZA

VENZA is a data protection company that can help organisations mitigate their vulnerabilities and ensure compliance, keeping guests and their data safe from breaches.

2021.AI

2021.AI

2021.AI serves the growing business need for full oversight and management of applied AI.

SentryMark

SentryMark

Stay a Step Ahead of Emerging Threats. Deviate from the traditional siloed defenses and get the proactive and responsive cybersecurity solutions and services you deserve with SentryMark today.

Cyber Security Certification Australia (CSCAU)

Cyber Security Certification Australia (CSCAU)

CSCAU is the world’s first 'for mission' industry council set up to address small and medium-sized business (SMB) cyber resilience through annually updated certifiable standards.