BT’s response to the Joint Committee on the National Security Strategy’s call for evidence for its inquiry into

‘UK National Security in a Digital World’

 

Written evidence from BT

February 2017


BT’s response to the Joint Committee on the National Security Strategy’s call for evidence for its inquiry into ‘UK National Security in a Digital World’

  1. Introduction to BT and its history in cyber security

1.1.  BT is one of the world’s leading communications services providers, serving customers in the UK and 180 countries worldwide. We provide fixed-line services, broadband, mobile and TV products and services as well as networked IT services. We are one of the UK’s largest employers, with over 100,000 staff.

1.2.  In the UK we serve 10 million residential customers, 1.2 million business and public sector customers[1] and 8 million mobile customers through EE. The Centre for the Protection of Critical National Infrastructure (CPNI) designates our broadband, telephony and 999 call handling service as our Critical National Infrastructure (CNI) in the UK.[2] As well as forming a vital part of the UK’s CNI, our network underpins the successful operation of a far wider set of services designated as CNI. We provide connectivity and mobile data terminals used by the Police, Fire and Rescue and Ambulance services and we provide the NHS Spine network that joins up over 23,000 healthcare IT systems. Our network is relied upon day in day out by government, our armed forces, banks, utility providers, supermarkets - to manage their stock and supply chains and transport enablers such as air traffic control and navigation systems.

1.3.  The availability and integrity of our network and the confidentiality of the data we process is at the core of our ability to serve our customers, which is why cyber security has always been a primary concern for BT. We have been at the forefront of computing and cyber security development and the protection of UK cyber-space ever since Post Office engineer Tommy Flowers carried out ground-breaking work in encryption with Alan Turing throughout the Second World War. More recently, we protected the London 2012 Olympic and Paralympic Games ensuring that communications networks were kept free from outside interference, that Olympic websites were not knocked offline or defaced by hackers and that TV coverage was not disrupted. Protecting London 2012 showed us how proactive security could be enabled by data analysis. Ever since, BT has invested significantly in appropriating data feeds from our enterprise allowing us to develop intelligence driven cyber security operations.

1.4.  The capabilities we have developed to defend ourselves form the basis of the world-class security services that we sell to over 1,700 customers. We are recognised by the market as a major global provider of managed-security services which has seen ‘very strong growth in the last two and half years’.[3] Our strong local partnerships and the global reach of our infrastructure is seen as giving us ‘the most complete global reach’ amongst Managed Security Services Providers and we are recognised as a leading provider in the Asia Pacific region on account of ‘staggering triple-digit year-on-year growth’.[4]


  1. The types and sources of cyber threats faced by the UK 

2.1.  Figure 1 shows the frequency of the most serious threats against BT since January 2013. These threats would have caused disruption to our services had they been successful. We have seen a sharp rise of 1000% in the number of attacks since August 2014, alongside a step change in their complexity and sophistication.

Figure 1: Cyber attacks against BT January 2013 – January 2017[5]

2.2.  As figure 2 shows, we are at risk from a range of attackers: hackers, criminals, nation states and terrorists. However, the majority of the threats we see come from organised criminal groups.

Figure 2: Origin of cyber risk to BT

2.3.  Our unique position as a leading provider of communications infrastructure in the UK and globally enables us to have a ringside view of the types of malware that attackers try to use against our customers.

Figure 3: Most prevalent malware associated traffic seen on our UK network: snapshot from February 2017

 

2.4.  The most common malware associated traffic we saw at the beginning of February 2017 were:

Zeroaccess: a Trojan horse computer malware that affects Microsoft Windows operating systems. It is used to download other malware on an infected machine from a botnet mostly involved in bitcoin mining and click fraud, while remaining hidden on the system.

Mirai: a piece of malware designed to hijack internet facing systems such as routers and remote cameras by exploiting default usernames and passwords.

Ramnit: a computer worm affecting Microsoft Windows users that is used to steal information from compromised computers.

2.5. Avalanche-tiny-banker: a malware program that targets financial institution websites. It is a modified form of an older form of viruses known as Banker Trojans, yet it is much smaller in size and more powerful. It works by establishing man-in-the-browser[6] attacks and network sniffing.[7]

2.6.  Two of the most prevalent macro trends we continue to see are phishing attacks against our customers and Distributed Denial of Service (DDOS) attacks against our own and our customers’ networks.

2.7.  Phishing is a form of fraud whereby the attacker sends a communication (normally an email) to victims purporting to be from a legitimate organisation such as their bank. The email encourages users to click on attachments or links that will either download malware onto a victim’s computer or direct them to a fake website which asks them to enter genuine details such as login credentials, credit card details, etc.

2.8.  BT saw a strong rise in the number of phishing websites from 2012 to 2014. Although we saw a temporary decrease in 2015 numbers have now started to creep up again as you can see from figure 4 overleaf. In the last 12 months BT has identified and closed over 4,500 phishing websites.

 

 

 

Figure 4: Phishing websites identified and closed by BT

2.9.  A Distributed Denial of Service (DDOS) attack is used by attackers to take websites and internet based services ‘offline’ by flooding them with so many bogus requests that they become unable to operate and therefore not available to legitimate users. A DDOS attack does this by harnessing the computing power of thousands of compromised devices connected to the internet such as laptops, phones and video cameras which attackers have been able to hack and control remotely. Recently, a successful DDOS attack against dyn, an internet infrastructure provider that directs users internet requests to the websites they are looking for, brought down platforms such as Netflix, Twitter and CNN. The attack was one of the largest ever seen with 1.2 terabytes of computing power driving it.

2.10.                       DDOS attacks are a daily occurrence for BT, they are carried out against our internet-facing websites and live streaming services such as BT Vision and BT Sport. We have seen DDOS attacks grow in frequency and size and have invested heavily to ensure that our estate is protected.

2.11.                       Figure 5 shows a seasonal variance in the number of attacks that we see with the number of attacks rising in October, the late winter months and early spring.

Figure 5: Volumes of recorded DDOS attacks against BT February 2016 – January 2017


 

2.12.                       The largest DDOS attack recorded by BT last year was an attack of 450 Gbps in June.

Figure 6: largest attack recorded by BT per month February 2016 – January 2017

2.13.                       We measure the top 10 source countries in terms of size of attacks rather than the number of attacks as this gives a more accurate picture of where large botnets are located. The largest attacks (in terms of volume of traffic) launched against targets in the UK and Ireland most often originate from the US and from the UK itself from which 14% and 13% of the largest DDOS attacks originate. After this, the sources of large attacks are spread fairly evenly across Western Europe, Australia, Canada, China, India and Russia.

Figure 7: Top 10 source countries from which DDOS attacks were launched against targets in UK and Ireland in 2016

 

  1. The effectiveness and coherence of the strategic lead provided by the National Security Council, Departments, agencies, and the National Cyber Security Centre

3.1.  BT works successfully with every lead department involved in delivering the National Cyber Security Strategy, as shown in section 6.

3.2.  We recognise some of the problems highlighted by the National Audit Office (NAO) in its recent report Protecting data across government’ such as the existence of numerous government bodies with overlapping remits. This makes it confusing, time consuming and therefore expensive for industry to reach out to government, especially for SMEs.

3.3.  However, we also agree with the NAO’s finding that the set-up of the National Cyber Security Centre (NCSC) as the Government’s Single Point of Contact (SPOC) with industry will go a long way towards addressing this issue and make it easier for new industry voices to engage with government. If this is to be the case, it is vital that the NCSC establishes itself as the ‘centre of gravity’ for cyber security in Government. Teams with overlapping remits elsewhere in government should be stripped of these responsibilities. Otherwise the status quo will continue.

3.4.  With the rush to start work on the new strategy, Government departments need to take care that, as duplication is stripped out in some areas, it is not introduced in others. For example, as organisations working to defend the UK come together in the NCSC, government needs to carefully manage the setup of its plethora of innovation initiatives to help develop the UK’s cyber security industry. There are currently five different innovation programmes being set up by the Department for Culture Media and Sport.[8] As BT has previously advised, it would be easier for entrepreneurs and SMEs to engage with these programmes if their delivery was streamlined.

  1. Learning points drawn from the first Cyber Security Strategy and the fitness for purpose of the second Cyber Security Strategy

4.1.  In BT’s view the major development in the second iteration of the National Cyber Security Strategy is the introduction of more tangible outcomes, such as the concept of Active Cyber Defence; making changes to the digital infrastructure of the UK at a macro level to make it more resilient against cyber attack. BT has been leading work with the Government in this area for years in addition to its investments to enhance its own security, in order to help increase protection for UK citizens. In particular we are:

4.2.  Actions such as the above will go a considerable way towards making it more difficult and therefore less attractive for criminals carrying out relatively unsophisticated cyber crimes (which account for roughly 80% of cyber crime) to operate against UK targets. However, Active Cyber Defence will have most effect if implemented at an international level and it is important for the Government to advocate adoption of these measures through the relevant bilateral organisations and agreements.

  1. Whether the UK has committed sufficient human, financial and technical resources to address the scale of the cyber security challenge

Resource investment across the public sector

5.1.  The Government has designated cyber security as a Tier One threat in its latest National Security Strategy and has provided £1.9bn of funding to help implement the commitments made in the National Cyber Security Strategy. The funding covers both technical and human resources. The Government has also implemented innovative programmes to help increase the skilled resource available in the UK such as the Cyber First scheme which provides bursaries, summer employment and graduate jobs for STEM students with a promising aptitude for cybersecurity. In BT’s view, the Government is a step ahead of many other national governments in terms of deterring adversaries, protecting the UK and developing cyber security skills and the economic benefits it offers.

5.2.  In terms of the security of government and public sector organisations themselves, we see a broad spectrum of maturity across the UK. Some public sector organisations have a mature cyber posture, actively hunting for threats with integrated intelligence, threat monitoring and vulnerability scanning, whereas others have a far less developed approach focusing on responding to threats only once they’ve materialised into incidents. Overall, as BT has previously highlighted, there is no coherent strategy as to how the public sector will protect itself from cyber attack. It is not clear to us, for example, whether departments plan to share threat intelligence in real time, whether the Government will consolidate its cloud estate or whether it will have one national Security Operations Centre or individual departmental ones. In order for cyber security suppliers to make sure they are investing money and resources in the right areas and offering government the best products and services available on the market, BT believes that the Government should work with industry partners in order to develop such a strategy. The existence of a visible, clearly articulated strategy will make it easier for all suppliers but especially for SMEs, who have less resources to invest in business development, to understand requirements and do business with the public sector. In BT’s view the NCSC is ideally placed to lead this type of project, partly because it will be ultimately responsible for government’s cyber security and partly because it will provide the interface between industry and government.

Resource investment across the private sector

5.3.  Across the private sector investment in the resources needed to ensure strong cyber security is uneven. Research that BT recently undertook with KPMG indicates that, whilst awareness in the private sector is high, investment is much lower than it needs to be. As our infographic in Annex A shows, we found that only 22% of companies who had already been a victim of an attack were fully prepared to deal with any future incidents and, although 55% have seen an increase in cyber attacks, only 23% have insurance in place to deal with the cost of a major incident. These findings are corroborated in a number of industry reports and suggest that, whilst awareness of cyber security risk is high, resources to match the level of risk are not always committed.

5.4.  Many companies operating CNI however will have made much more significant investments. BT’s financial investment in security has increased three fold in the last three years. We announced the creation of 900 new security jobs last year and now have a 2,500 strong security practice. We invest heavily in training to make sure that our teams are prepared to face the latest threats. This year, we expect 80,000 hours will be spent in learning and development across BT Security. A big focus for us is our investment in future generations of cyber practitioners. BT currently has 75 cyber security apprentices and 13 former apprentices who have now graduated and continue to pursue a cyber security career at BT. As part of their apprenticeships, apprentices undertake a foundational degree at De Montfort University which the best performers have the opportunity to extend to a full degree.

5.5.  As a high value target for cyber criminals and hackers it is vital that we invest in the latest cutting edge technologies to help defend BT and our customers. In order to do this we are constantly ‘horizon scanning’ for new innovative startups and technologies. We run a Cyber Assessment Lab (CAL) with a dedicated team that assesses new technologies from 200 companies a year. We also have a scouting team, including a permanent presence in Israel from where we see a lot of promising startups emerge. In addition to this we spend nearly £50m a year on security related research.

  1. Ways in which the UK Government can work with the private sector to build cyber resilience and cyber skills

6.1.  The Government already works successfully with the private sector to deliver the three central aims of the Cyber Security Strategy 2016: Defending the UK, Deterring cyber adversaries and Developing skills and a thriving UK cyber security industry.

6.2.  Figure 8 overleaf shows just some of the headline cyber security initiatives that BT works with the Government to deliver.


Figure 8: Highlights of BT’s joint projects with Government departments leading the implementation of the Cyber Security Strategy

 

6.3.  In the DETER space we work very closely with the National Crime Agency to disrupt organised cyber crime. We sit on the NCA’s Industry Strategic Group and provide input into its annual Strategic Crime Assessment. We are also closely involved with operational work, supporting investigations and working to build new capabilities to enable us to jointly investigate criminal infrastructure. Of particular importance for us is disrupting the infrastructure behind Distributed Denial of Service (DDOS) attacks and we are part of a joint government - industry working group focused on this. We also share best practice and contribute towards policy development in areas such as incident response.

6.4.  Under the DEFEND workstream we have a long standing partnership with GCHQ and CPNI focused on improving the resilience of the telecommunications infrastructure in the UK against cyber attacks. Most recently we have collaborated to help set up the National Cyber Security Centre and to implement priorities for Active Cyber Defence as outline in section four above. As part of this work we are undertaking a series of secondments with the NCSC, seconding in individuals with skills they are missing in-house to upskill their teams and giving NCSC secondees the opportunity to work in a real network environment. We are a founding member of the Fusion Cell, a joint industry/Government operational team within the Cyber Security Information Sharing Partnership which collates, assess and distributes intelligence from industry and government sources to its members.

6.5.  Industry and government partnerships could be further improved by developing automated real-time intelligence gathering and sharing, using machine-to-machine mechanisms such as STIX and TAXI to transfer intelligence and act on it more rapidly. We are now working towards this with the NCA. It is also important that all participants in the intelligence-sharing partnerships actually input intelligence rather than just benefit from the output. The Government could do more to drive this reciprocal approach to intelligence sharing by amending the terms and conditions of participation on Government-sponsored platforms such as the CisP, The adoption of stronger cyber security measures across the private sector could also be driven by the Government adopting measures to promote the take up of schemes such as Cyber Essentials, designed to give organisations the basic levels of cyber security needed to be resilient against the 80% of unsophisticated cyber attacks. One way in which the Government could do this would be to mandate the use of the Cyber Essentials scheme across its supply chain, as we are doing.

6.6.  The Government also works in close partnership with industry to deliver its priority workstreams to develop cyber security skills and world-leading companies. BT’s CEO, Gavin Patterson, co-chairs the Cyber Growth Partnership (CGP) with the Minister of State for Digital and Culture, The Rt Hon Matt Hancock MP. The CGP advises the Government on the implementation of its initiatives to help entrepreneurs turn great ideas into successful startups and to grow them into profitable businesses. BT is also a member of GCHQ’s Cyber Invest scheme which brings industry together with universities designated as Accredited Centres of Excellence by the Government to carry out joint research projects.

6.7.  There are a number of additional ways in which the Government could work with industry, to increase effectiveness in building cyber skills in the next generation.

6.8.  Cyber security education needs to be linked more closely to industry at all levels. BT sits on DCMS’s Cyber Skills Strategy Advisory Group but believes there is a greater opportunity to involve industry in the practical delivery of cyber security education. BT is pioneering this approach with a number of schools through its Cyber4Schools programme, which sees BT staff developing connections with local schools and delivering lessons which teach pupils about the history of cyber security and the opportunities a career in the field holds, as well as getting them involved in practical code-breaking puzzles. We also work with universities such as De Montfort.  We, and other industry partners, work with the university to co-develop the cyber security curriculum ensuring that, when students complete their degrees, they are ready to enter the workplace and familiar with the most cutting-edge developments in the industry. In our view, extending this approach to far more schools and universities will ensure a larger pipeline of pupils interested in the sector and a larger cohort of graduates with the skills industry is looking for when they graduate.

6.9.  The Government could also look at ways in which it could best support industry sponsored initiatives such as the establishment of the new National Cyber Security College set up by the industry group QUARFO. This college will be based at Bletchley Park and take 500 students at sixth-form level when it opens in 2018.

6.10.                       Finally, the Government could look at expanding the work being piloted to help young hackers who are in danger of clashing with the law to direct their talents in a more positive direction. Under Project Properlise, the NCA is working with companies such as BT to reach out to individuals who have come to their attention and to invite them to workshops where they can learn more about the opportunities that a career in cyber security could hold for them. 20 young people attended the first workshop and the aim is to increase this to 300 after the first year of trials. BT strongly supports the development and expansion of this programme.

  1. The balance of responsibilities between the Government and private sector in protecting critical national infrastructure

7.1. BT defines CNI as: those facilities, systems, sites, networks or other assets (whether physical or logical and including information systems), the loss or compromise of which would have a major detrimental impact on the availability or integrity of essential services leading to severe economic or social consequences or to loss of life. In the UK, CPNI designates its broadband, telephony and 999 services as CNI.

7.2.  In BT’s view, private sector companies delivering CNI are responsible for protecting their customers, assets and brand and, where they are publicly listed, to continue to deliver value for their shareholders. It is for government to define and implement control strategies for national level risk, which may involve placing requirements upon the private sector.

7.3.  As outlined above, BT invests heavily in protecting its infrastructure. Our investments in understanding our IT inventory and estate, gearing up our operations teams for effective incident response and utilising data feeds from across our estates to implement intelligence driven cyber operations, have enabled us to significantly cut our response times to major vulnerabilities. When the Heartbleed vulnerability was discovered in 2014 it took us 28 days to fully update all of our defences. When the DROWN vulnerability was exposed in 2016 however, it took us five minutes. [9]

7.4.  We work hard to protect our customers from attacks. We offer bundled security services at no extra cost when they purchase our broadband packages and we actively search the internet and the darknet for stolen user credentials associated with BT such as login details for email accounts. We use authentication systems to watch for signs that customer login credentials being presented to us are not from the person they claim to be, for example if they are being used on multiple machines at once or are being sent from an unexpected geographical location. We block sites that we know to be malicious, such as phishing sites, and where we identify such sites we issue the company that hosts them with a notice requiring them to take them down. We also reach out to key stakeholder parties such as browser providers - so that they too can block malicious sites from browsing searches. We provide our customers with secure email where they can be confident that an email arriving in their inbox is from the organisation it says it’s from. To do this we have invested in measures that prevent attackers from impersonating legitimate organisations. We also prevent spam and phishing emails from being delivered to customers and make the links customers could click on in phishing emails, less effective.

7.5.  We have worked with law enforcement for more than 10 years to identify compromised devices and notify customers. We are trialing a programme to notify customers whom we can see have banking trojans installed on their machines by writing to them and providing them with a web address where they can go to fix the problem. We have trialed this with 1000 consumer and business customers to date.

7.6.  We also work voluntarily with the Government, above and beyond these responsibilities, to help protect the UK. We were the first operator in the UK to block access to child-abuse images and we invest in the Active Defence measures and public – private initiatives outlined in sections four and six above. We also invest to develop our ability to derive intelligence from our networks so that we can identify evolving threats that aren’t detected through commercial anti-virus packages. For example, we can identify compromised devices in consumer homes that are being used as part of a botnet.

7.7.  These measures are carried out in addition to the investment and action we need to undertake to fulfil our obligations to protect our customers and shareholders.

  1. What is the appropriate role for Government in regulating and legislating in relation to cyber both nationally and internationally? 

Provide a legal framework to tackle cyber protection

8.1.  There is no ‘cyber’ law in the UK; rather, the law has evolved to cover cyber issues.  We do not think further widespread review of the law is needed following the extensive review of the relevant legal principles, at both UK and EU level, over the last five years. 

8.2.  However, the range of EU and UK law that currently impacts on what BT does in the field of cyber security is extremely broad. For example:

Under NNR, CSPs may block content to preserve the integrity and security of the network, of services provided via that network, and of the terminal equipment of end-users. The precise boundaries of these categories have yet to be established and there is an argument that in any event, CSPs could and should be permitted to block harmful content in a broader context, which would require additional legislation in the UK. The Digital Economy Bill offers the Government the opportunity to address the issue of content filtering holistically, and it is disappointing that legislative proposals to date focus only on compulsory blocking in relation to certain pornographic content. 

Provide practical guidance

8.3.  So, there are clearly some substantive issues that we consider should be addressed, and we also believe that it would be helpful for the various government authorities to perhaps come together to provide some consolidated but simple guidance on the applicability of the various legal requirements; and for the NCSC to produce guidance on the various statutory provisions that apply to cyber.

  1. How the UK can co-operate with allies and partners on the development of capabilities, standard setting and intelligence sharing

9.1.  The UK’s work on measures such as Active Cyber Defence will only be truly effective if replicated internationally, hence BT’s membership and support for international coalitions such as the World Economic Forum, Global Cyber-Security Alliance, the European Commission’s Cyber Public-Private Partnership, EU – China Expert Group on Cyber Security and the National Security Telecommunications Advisory Council. The Government is an active participant in international cyber security initiatives and we support its continued participation in order to maximise the effectiveness of the world leading approach we have adopted in the UK. Enhancing information sharing between allies is a key part of working together effectively, BT is part of a joint government-industry team setting up an automated intelligence sharing mechanism between the UK, US and Canada. BT supports the extension of programmes such as this to all appropriate allies.

Further enquiries can be directed to: David Pincott, Head of Political Research, Policy and Briefing, BT Group plc.

Tel: 020 7356 6585/email: david.pincott@bt.com

 

BT Group

February 2017


Annex A

Headline findings from BT and KPMG’s report ‘Taking the Offensive, working together to disrupt digital crime’

 

1

 


[1] 1.2m business and public sector customers in the UK and Ireland.

[2] Every 999 call in the UK is received by a BT operative before being passed to the emergency services control room

[3] Current Analysis, Managed Security– Product Assessment (Global), John Marcus, October 2016

[4] Ovum Decision Matrix: Selecting a Global Telco Managed Security Services Provider, Sep 2014, Mike Sapien

And IDC MarketScape: Asia Pacific Managed Security Services 2016 Vendor Assessment

[5] Reactive events are attacks that have been perpetrated against us whereas proactive events are new vulnerabilities we have discovered through activities such as vulnerability scanning and red teaming enabling us to fix them before they can be exploited.

[6] Man-in-the-browser attacks install disguised malicious code known as a ‘Trojan Horse’ onto a user’s computer to modify the users web transactions in real time. When the user initiates an online banking session the Trojan is triggered into action. It waits until the user has passed all the authentication stages and has initiated a money transfer. The Trojan then substitutes the legitimate payee details with those of a mule account.

[7] Network sniffing – a network sniffer monitors data flowing over a computer network in real time enabling attackers to read a victim’s communications and retrieve sensitive data such as passwords and usernames, email contacts and message content.

[8] Innovation programmes being set up by DCMS: 1 - Academic Start-Up an initiative seeking to transform the best ideas from UK universities into commercially exploitable products; 2 - Hut Zero an early stage accelerator designed to help turn nascent ideas into viable commercial proposals; 3 - Innovation Centers (in Cheltenham and London) which will provide support to develop innovative products into new startup companies; 4 - SME Bootcamps which will provide essential business knowledge and coaching to entrepreneurs; 5 - Cyber 20 which aims to assist a select group of more mature SMEs to grow into successful exporters.

 

[9] Further information on the Heartbleed and DROWN attacks available through embedded links