ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Foreign powers are 'main cyberthreat' to UK

Tom Espiner ZDNet.co.uk

Published: 22 Nov 2005 18:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Foreign governments are the primary threat to the UK's critical national infrastructure (CNI) because of their hunger for information, according to a government body.

The National Infrastructure Security Co-ordination Centre (NISCC), which is in charge of defending the CNI, claimed on Tuesday the most significant electronic threats to the critical national infrastructure are content-based, targeted, Trojan horse email attacks from the Far East.

"Foreign states are probing the CNI for information," said Roger Cummings, the director of NISCC.

The CNI is made up of financial institutions; key transport, telecoms and energy networks; and government organisations.

NISCC is working with its equivalents in the countries concerned to try to "shut the attacks down", according to Cummings. NISCC cannot name the countries concerned as this may "ruin diplomatic efforts to halt the attacks".

The attackers appears to be aiming to gather commercially or economically valuable information, according to NISCC.

"We call it the 'malicious marketplace'," said Cummings. "Exploit writers can make money by selling exploits. Who are the most capable organisations to make use of exploits? Foreign states are the most capable actors — they are currently sitting up at the top of the marketplace," he added.

Cummings went on to dissect the 'malicious marketplace', in which he claimed the most significant element is foreign states, whose target is information. Below them are criminals who are trying to compromise the CNI in order to sell information. Hackers motivated by kudos or money have "a variable capability", but are more serious than terrorists, who currently have a "low capability", and pose the smallest threat, Cummings claimed.

However, there is a risk these groups will increasingly work together.

"The risk from criminals [to the CNI] increases when they get into bed with hackers. The capability of terrorists will increase if they employ hackers," said Cummings. "We are concerned that the malicious marketplace will make available exploits that can do us damage," he added.

Although foreign states are currently the most capable of launching attacks, NISCC expected criminal capability to "expand and start to bump against foreign states," Cummings said.

Cyberterrorism is a controversial subject within the security industry. Some experts, such as Bruce Schneier, have claimed the threat doesn't exist. Speaking in April, Schneier said that some organisations have been abusing the term in an attempt to fuel their budgets.

Cummings said people needed to be aware of the threat from terrorism, but stressed that he didn't want to hype the threat or alarm people.

"We are constantly aware that terrorists can attack us in a whole host of ways. There is concern that terrorists can acquire exploits through the 'malicious marketplace'. We would say there is hype around cyberterrorism, but we need to remain eternally vigilant," Cummings said.

The UK government should be applauded for developing a more proactive approach to this issue, according to the Communications Electronics Security Group (CESG).

"The government is being proactive, and this is paying dividends. All information is worth protecting — potentially as it could mean people's lives. Where the squaddies are tomorrow needs to be kept secret; you can't put a price on human life," said Chris Ulliot, head of vulnerability research, CESG.

Cummings and Ulliot were speaking at SANS Institute's launch of its Top 20 Critical Internet Vulnerability Listing at the Department of Trade and Industry in London.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
93 out of 184 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Security Consultant - Immediate start

The desired candidate will have the following skillset: * Network Vulnerability Internal & External Testing * Configuration of Cisco switches / ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Acquisition - Internal Account Manager Higher Education & Schools - Sales / IT Sales

Acquisition - Internal Account Manager Higher Education & Schools - Sales / IT Sales Selling into the Transforming Local Government Marketplace, ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation