Written evidence submitted by the NCC Group
Introductory comments
1.1. A global cyber security and risk mitigation provider of professional and managed services, NCC Group plc is delighted to respond to the Defence Committee’s inquiry into the North Korean threat. Our comments focus on the nature of the cyber threat from North Korea; and the UK’s preparedness to deter and counter it.
1.2. Headquartered in Manchester, NCC Group employs more than 2,000 people across 35 offices worldwide, providing more than 15,000 organisations with research & development, penetration testing and full spectrum attack simulation services, security operations centre (SOC) and networking monitoring support; cyber defence, threat intelligence and incident response services. The number and expertise of our security consultants gives us nation state capability when it comes to protecting against, detecting and responding to cyber attacks.
1.3. We continue to be involved in the aftermath of the May 2017 WannaCry ransomware attack, now attributed with a high degree of likelihood to “North Korean actors known as the Lazarus Group.” Responding to client demand, our Cyber Defence Operations and Threat Intelligence teams have undertaken assessments of the North Korean threat to UK organisations, considering its specific nature [3] and the technical detail of North Korean malicious activities [4].
1.4. As parliamentary scrutiny of the national security and defence implications of state actors’ cyber threats intensifies, we believe it is important for the UK cyber security industry to contribute to the political debate to share its experience and expertise.
1.5. The Intelligence and Security Committee’s Annual Report is but one recently published review to conclude that as nation states are developing offensive cyber capabilities, and previously accepted rules of engagement no longer apply, the emerging geopolitical landscape becomes increasingly volatile. In that context, NCC Group asks the Defence Committee to take into account the following comments as it develops it. recommendations:
1.5.1. Need for collaboration: As the cyber threat continues to evolve at unprecedented scale and pace, isolated attempts to understand and address it will become insufficient, requiring greater collaboration across all levels. This starts with parliamentary scrutiny. For example, we very much hope that the Defence Committee will work closely with the Intelligence & Security Committee, and the Joint Committee on the National Security Strategy, in developing its recommendations so as to ensure parliamentary calls to action are cohesive and clearly enable the UK Government to take action.
1.5.2. Collaboration should also, we believe, encompass a clear commitment to public-private sector cooperation. Without blurring traditional state and industry boundaries, we believe that government capabilities to counter the cyber threat currently are and will continue to be greatly enhanced through exploiting the expertise and capacity of the private sector. New rules and frameworks might have to be put in place going forward to put such collaboration in the national interest on a sustainable footing. We have seen examples in threat intelligence with regards to certain programmes operated by the National Cyber Security Centre (NCSC) yielding opportunities for close co-operation and collaboration at their facilities in London.
1.5.3. Need for new rules and frameworks: Accepting that increased public-private sector collaboration could become a core element of the UK government’s endeavours to improve its cyber defence capabilities, we believe, also requires a review of current legislative and regulatory frameworks regarding private sector actors’ ability to act. This could, for example, cover the availability of tools to aid threat intelligence collection and defence in cyberspace.
Detailed comments
2.1. Our analysis of North Korea’s cyber capabilities and our contextual assessment of North Korea as a cyber threat actor shows that North Korea is not principally different from others in its technical capabilities.
2.1.1. We describe North Korea as a nation state threat actor and an associated spectrum of proxy organisations and groups over which the state has a variable degree of control; a largely state controlled acquisitive crime group working in support of national strategic objectives.
2.1.2. The centre of mass for North Korea is its capital, Pyongyang, though North Korea does maintain an extensive network of front operations overseas, notably in Indonesia, Malaysia, India and Singapore, and in the Chinese cities of Dalian, Dandong and Shenyang.
2.1.3. The primary state structure for offensive (espionage and sabotage) operations is reportedly Bureau 121, part of the Reconnaissance General Bureau of the North Korean military, assessed to have an operational staff of approximately 1,800. The Lazarus Group is believed to be controlled directly by Bureau 121.
2.1.4. The relationship between Bureau 121 and private sector commercial and criminal organisations is unclear. The blurred distinction between conventional government infrastructure, quasi-legitimate private sector operations, freelance criminal enterprises and state-sponsored intelligence gathering and revenue generation operations makes it impossible to say with any degree of certainty what type of threat actor is behind any given attack.
2.1.5. The North Korean state is reported to have a well-established and highly focussed academic pipeline, with a military school specialising in cyber warfare, Mirim University. Within North Korea, individuals engaged in cyber warfare are highly respected and afforded additional privileges to ordinary citizens, ensuring a constant supply of highly motivated personnel.
2.1.6. Hacking groups linked to the North Korean state show the potential to be sufficiently skilled, as demonstrated e.g. through: the effective encryption of traffic between the C2 (Command & Control) servers and infected machines (showing consideration given to operational security); the use of deception and false-flag techniques (showing a level of strategic planning); and the deployment of multi-module tools to frustrate malware analysis (showing a high level of understanding of counter-intelligence processes).
2.2 However, North Korea differs from other threat actors on account of the state’s isolationism; a unique motivation for its actions; and a unique definition of ‘rationality’.
2.2.1. We agree wholeheartedly with the comments by Nigel Inkster before the Committee on 19 December who spoke of an “asymmetry of vulnerabilities” as a result of the non-networked status of North Korean society. We would argue that the general “cyber balance of power” with the majority of other states does not apply to North Korea. China and Russia, for example, have a vested interest in the continued survival of the international system: China requires growing economies to export to; Russia also depends on export markets for its natural resources. While there are shades of North Korean behaviour in Russian cyber operations – using state resources via arms-length proxy organisations to commit revenue-generating cyber-crime – none of the rational limitations on Russia’s actions apply to North Korea. As a result, the UK’s capacity to inflict ‘like-for-like damage’ in retaliation is limited, increasing North Korea’s freedom of action.
2.2.2. We agree, too, with the assessment of the Intelligence and Security Committee’s Annual Report that describes North Korea as reckless and unpredictable, prepared to use its capabilities without any concerns for attribution. Indeed, it is widely acknowledged that North Korea has “absolutely no compunction about violating international law and norms.” The country is already considered a pariah state within the international community and has excelled in the use of provocation and brinksmanship in order to achieve its goals.
2.2.3. As has been acknowledged by others, North Korea is also thought to be unique amongst nation states in its dependence on criminal activities to underpin the finances of the state due to sanctions. It is assessed to be increasingly reliant on acquisitive cyber-crime to balance the national budget and fund key strategic projects. Indeed, it is seen as highly likely that acquisitive cyber-crime aimed at the theft of large sums of money, potentially in the hundreds of millions, or billions of dollars, from the international banking system is a fundamental element of the state’s survival strategy.
2.2.4. Finally, North Korea’s unique definition of rationality makes planning or logical inference regarding the state’s actions very complex for outsiders. For example, as demonstrated by the “ghost ships” [3], in North Korea, private citizens working for the state, but motivated by personal gain, are using military resources to meet the regime’s objectives and their own needs simultaneously, driving them to take considerable risks. With regard to the North Korean cyber threat, the combination of public sector resources with a privateering approach to cyber criminality results in a particularly unstable and unpredictable threat actor, making the analysis of likely courses of action incredibly difficult, and the use of conventional terminology almost meaningless.
2.3. Notwithstanding the difficulties of defending the UK against a wholly unpredictable threat actor which frequently appears irrational in its behaviour, UK actions to support departmental and private sector defences against cyber threats would benefit from greater collaboration and a review and modernisation of the rules and frameworks governing currently allowable activities and behaviours.
2.4. The UK government, most recently in the UK-Poland cyber co-operation commitment affirms states’ legitimate right to develop offensive and defensive cyber capabilities, and commits to promoting an international stability framework for cyberspace based on applying international law and agreed voluntary norms of responsible state behaviour.
2.5. However, not only does the Intelligence and Security Committee in its annual report point out the variability with which existing legal norms are currently applied to cyber activities, but the North Korean state’s blatant disregard for any rules of engagement means that any international legal framework is likely to be ineffective for cyber defence purposes.
2.6. While we support the UK government’s work towards an international framework more broadly, we believe that more concrete, practical steps are needed to strengthen the UK’s cyber defences and enable UK organisations better to defend themselves. Effectively obstructing adversary state actors’ cyber criminal activities, we believe, ultimately supports foreign and defence policy objectives such as, for example, sanctions. To that end:
2.6.1. First, we believe that public-private sector collaboration needs to become an accepted element of national cyber defence, put on a sustainable footing which clearly enshrines the private sector’s rights and obligations amidst its greater responsibility towards UK national security.
2.6.2. Second, we would like to see a comprehensive review of the current legislative and regulatory framework governing cyber defence activities across the private sector. Amidst significant technological advances, ever greater interconnectedness, and the rapidly evolving threat landscape nationally and internationally, we believe it is right to review, and where required, modernise, now outdated legislation so as to reflect the changing realities. This should include, but not be limited to, the Computer Misuse Act 1990 some provisions of which curtail private sector operators’ ability both to defend themselves and support national defences in cyberspace.
2.6.3. And third, we believe that both public-private sector collaboration, and any regulatory reform should be undertaken with a view to maximising the benefits of threat intelligence for cyber defence purposes. The ability to collect technical intelligence through communicating with attackers’ compromised machines, and the ability to pool intelligence and share information in confidential public-private fora will undoubtedly support the UK government’s preparedness in defending against cyber threats from North Korea, and other state actors, or state-sponsored groups.
17 January 2018