ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Government hacker warning is a sign of the times

Cath Everett ZDNet.co.uk

Published: 16 Jun 2005 16:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The likelihood of a serious security breach in part of the UK critical national infrastructure is still remote but it is becoming increasingly probable due to standardisation of IT systems, according to security experts.

On Thursday the UK’s National Infrastructure Security Co-ordination Centre (NISCC) issued a statement that 300 government departments and businesses have been the victims of an ongoing series of trojan horse-based attacks from the Far East since the start of the year.

Neil Hare-Brown, managing director of incident response and risk management consultancy, QCC Security said the warning should stand as a wake-up call to businesses that aren't taking security seriously.

“This is about raising the bar. Attacks and payloads are getting more sophisticated all the time and so the authorities are getting much more seriously worried about it because cyber-terrorism is starting to rear its ugly head. It’s no longer just about kids playing about,” he said.

The report from the NISCC is the first time the usually low-key organisation has made such a high-profile warning. "Parts of the UK's critical national infrastructure are being targeted by an ongoing series of email-borne electronic attacks. While the majority of the observed attacks have been against central government, other UK organisations, companies and individuals are also at risk," the report stated.

But the annoucement by the NISCC seems to contradict earlier claims by governement that the chances of a severe electronic attack against critical national infrastrcture was actually quite low.

Following claims that Britain stood at risk of an "electronic 9/11" because the companies who run parts of the Critical National Infrastructure (CNI) are not compelled to maintain the highest levels of security, a Home Office spokesperson insisted that this threat is under "constant review" already, with the National Infrastructure Security Co-ordination Centre (NISCC) working "around the clock" to assess the threat of attack.

"The threat of the sort of attack that could disable a critical service is low," said the spokeswoman. "Less serious, but damaging attacks that might deface a Web site or deny service from a Web site are more likely," she added, insisting that "well-established defences" are in place in the event of a serious incident.

The CNI includes Britain's telecoms, water and power networks, as well as the emergency and health services.

Bob Jones, managing director of internet security specialist Equiinet said NISCC had woken-up to the serious issue of cyber crime and businesses should do the same. "Businesses that have been lagging behind in getting the right security protection in place need to sit up and listen to the NISCC's warning. Whilst anti-virus software and firewalls are critical components of any security infrastructure, the NISCC is right in its statement that companies need to go beyond these traditional defences."

The latest NISCC warning claims that companies using Microsoft systems are especially at risk from attack because of the pervasiveness of the software.

The more systems that are based on common interfaces and the more they use common mechanisms to interoperate, the higher the cyber-terrorism risk will grow, added Hare-Brown.

“Most people think that a real cyber-terrorism attack is still some way off because there’s still a level of diversity in the systems that people use, although this shows that it’s moving in that direction,” he explained. "The likelihood that someone is going to perform a broad-based attack where the damage is widespread also increases. That’s why the NISCC is getting more vocal because it’s worried and it’s letting people know of the growing threat."

The likelihood that a company may have its critical systems compromised is also being increased by the rise of criminal gangs paying top-level hackers huge sums to engage in industrial espionage and economic terrorism, said Hare-Brown.

“Organised crime can afford to purchase top level skills, but if you’re trying to make a political statement, there’s not generally enough money in it to pay for this. These skills don’t come cheap. This is economic terrorism, but it’s not about trying to destabilise the economy for political reasons. It’s about exploiting it for criminal gain,” he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 168 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

C++, VC++, STL / Electronic Trading / Real-time London Finance 60k

C++, VC++, STL, Boost / Electronic Trading / Real-time London Finance 60k A financial institution, being leaders in the real-time trading platform ...

DUNDEEDigital Electronic Engineer 30 - 40k depending on experience

We are looking for a well-established Digital Electronic Engineer who has experience in RF or analogue design to supplement their digital design ...

Electronic Engineer, Peterborough

An electronic design engineer is required by a leading company in a nieche sector. With clear electronic skills and a strong desire to progress and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments