UK Government Announces New Cyber Strategy to Protect Public Sector

UK Government Announces New Cyber Strategy to Protect Public Sector

The UK government has unveiled its first ever cybersecurity strategy, which aims to protect essential public sector services from being shut down by hostile threat actors.

In a speech in London today, Chancellor of the Duchy of Lancaster Steve Barclay announced £37.8m in funding to help local authorities boost their cyber-resilience. This will protect essential services and data, such as housing benefits, voter registration, electoral management, school grants and the provision of social care.

Barclay announced a raft of other initiatives to go alongside this funding commitment. This includes a new Government Cyber Coordination Centre (GCCC) to better coordinate responses to attacks on public sector systems and a cross-government vulnerability reporting service to enable security researchers and the public to easily report issues they identify with public sector digital services. In addition, a more detailed assurance regime will be implemented across central government departments.

The strategy is designed to combat surging cyber-attacks on the UK public sector in recent years. Notable examples include the ransomware attacks on Redcar & Cleveland and Hackney Councils in 2020, causing significant disruption and recovery costs. The government revealed that of the 777 incidents managed by the National Cyber Security Centre (NCSC) between September 2020 and August 2021, around 40% targeted the public sector.

Barclay also stated that Britain is now the third most targeted country in the world in cyberspace from hostile states.

He outlined: “Our public services are precious, and without them, individuals can’t access the support that they rely on.

“If we want people to continue to access their pensions online, social care support from local government or health services, we need to step up our cyber-defenses.

“The cyber-threat is clear and growing. But the government is acting – investing over £2bn in cyber, retiring legacy IT systems and stepping up our skills and coordination.”

Commenting on the announcement, Andrew Kays, CEO at Socura, said: “Following other recent government cyber announcements, the UK security industry will welcome the strategy and the understanding that modern public services are completely reliant on digital technology. The UK is highly targeted, and it is important that, as a nation, we defend our ability to support our citizens and the services they rely on. I would question whether £37.8m is enough to help local authorities improve cyber-resilience, given their current level of resources and the threats they face. It may prove to be a drop in the ocean, but at the £2bn investment overall is a significant sum.”

The initiative follows the publication of the UK government’s national cyber strategy at the end of last year.

In a separate announcement today, the Department for Digital, Culture, Media and Sport (DCMS) launched the International Data Transfer Expert Council, which will provide independent advice to the government on facilitating free and secure cross-border data flow following the UK’s departure from the EU. The council is meeting for the first time today and comprises leading academics and industry figures, including Google, Mastercard and Microsoft.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Experts Call for More Open Security Culture After VW Sacking

Experts Call for More Open Security Culture After VW Sacking

Security experts have stood up for cybersecurity whistleblowers after a report on Monday claimed a senior employee at a well-known carmaker was fired after raising concerns about fraud.

The Volkswagen staffer was dismissed weeks after raising the alarm about possible vulnerabilities in the company’s payments platform, Volkswagen Payments SA, which JP Morgan bought a 75% stake in back in September 2021.

That same month, the VW employee told managers they were concerned about a potential “fraud event” that had recently taken place, and suggested the need for internal “kill switches” to limit the damage from such events, according to the FT.

After hiring a law firm to look into the concerns, the world’s second largest vehicle-maker reportedly said the information provided was “irrelevant,” and the employee “was terminated due to fundamental differences in the way we work together.”

Jamie Akhtar, CEO & co-founder of CyberSmart argued that business of all types should do more to foster an open culture where employees can raise cybersecurity concerns.

“A huge proportion of successful cyber-attacks stem from some form of human error and the best way to counter this is by staff feeling comfortable in raising concerns or asking questions,” he added. “After all, you never know who in your business might spot that something isn’t quite right.”

Outpost24 CSO, Martin Jartelius, said that most firms have a fraud prevention and whistleblower system to root out wrongdoing.

“If a member of a team believes something is a risk, it’s important to investigate and escalate according to your process and making your decision based on the facts,” he added.

Volkswagen does indeed have such a system, having established an internal Together4Integrity program to encourage reporting following a 2015 diesel emissions scandal. That makes it doubly perplexing why the individual was ultimately fired.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber Essentials Overhauled for New Hybrid Working Era

Cyber Essentials Overhauled for New Hybrid Working Era

The UK government has launched a significant set of new requirements for organizations looking to comply with its Cyber Essentials scheme to bring it up to date with the way people live and work today.

Announced late last year, the changes will not impact the scheme’s overall control themes of firewalls, secure configuration, user access control, malware protection and software updates.

However, it has been expanded to address a new set of scenarios brought about by digital transformation and new post-pandemic working patterns.

There’s a new shared responsibility model to ensure organizations can better understand and fulfill their obligations to secure cloud services and infrastructure across SaaS, IaaS and PaaS.

There are also new requirements around home working, which is increasingly the norm for many workers today. This includes expectations about deploying firewall controls to users’ machines and devices.

The program has also been updated to include guidance on which multi-factor authentication (MFA) type to choose for employees, focusing on usability and accessibility.

Backups are not covered because the scheme doesn’t want to “overburden” organizations, even though it strongly recommends a rigorous backup and recovery program.

While the costs associated with Cyber Essentials will remain the same for small and micro companies, a tiered system means larger firms will pay more; now £600 including VAT.

“We still view Cyber Essentials as the minimum standard for cybersecurity in the UK but we also need to ensure it keeps evolving as the threat landscape and technology change. This major update is part of that ongoing regular review, explained “Anne W” of the National Cyber Security Centre (NCSC).

“We are also looking at what other services we can introduce to support Cyber Essentials. This includes providing an advisory service to help organizations that don’t have their own technical support with the practical configuration of their systems, and how to address the security challenges that larger organizations with complex IT estates face to meet the minimum standard.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Belarus Activists Fire Ransomware at State Railway

Belarus Activists Fire Ransomware at State Railway

A group of Belarusian cyber-activists is claiming to have successfully launched a ransomware attack on the country’s state-run train company in a bid to disrupt Russian troop movements.

The self-styled “Belarusian Cyber-Partisans” revealed the attack on Twitter.

“At the command of the terrorist Lukashenka, #Belarusian Railway allows the occupying troops to enter our land,” it claimed of their autocratic president.

“We encrypted some of BR’s servers, databases and workstations to disrupt its operations. Automation and security systems were NOT affected to avoid emergency situation.”

The group claimed to have the decryption keys that they are ready to return the train network “to normal mode.” However, its preconditions – the return of 50 political prisoners in need of medical assistance and the prevention of Russian troops entering the country – are unlikely to be met.

After reportedly rigging election victory in 2020 and putting down widespread protests with violence, Lukashenko has sought closer ties with the Putin regime in a bid to shore up his power base and gain economic and diplomatic support from the Kremlin.

A passenger notice on the official Belarusian Railways website says only that services for issuing electronic travel documents are temporarily unavailable due to unspecified “technical reasons.”

It claims work is underway to restore the service and urges individuals to contact ticket offices to arrange travel.

Russian troops began exercises in Belarus near its border with Ukraine earlier this month, which observers fear is a prelude to invasion. Attacking from Russia and Belarus would stretch Ukrainian forces thinly across a land border stretching hundreds of miles between the countries.

Belarusian cyber operatives are also increasingly launching campaigns aligned with Russia’s interests. A report from Mandiant in November 2021 attributed the notorious Ghostwriter group, or parts of it, to the Belarusian government.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains