NCC Group plc: written submission to the Joint Committee on the National Security Strategy’s inquiry into ‘Cyber Security: Critical National Infrastructure’
1.1. The concepts of threats to UK critical national infrastructure (CNI), and the thus required resilience of such are not new, nor is the recognition of cyber threats in this context particularly novel.
1.2. The Coalition Government, in 2014, understood that essential services’ increasing reliance on systems and networks posed challenges for their cyber security and resilience [[1]]; the UK Regulators Network (UKRN) in 2015-16 acknowledged cyber-attacks as a common threat faced by multiple sectors [[2]]; the Conservative Government’s summary of the Sector Security & Resilience Plans 2016 identified cyber security as “a particular challenge as attacks are increasingly being carried out on an industrial scale” [[3]]; and the 2017 edition of the National Risk Register of Civil Emergencies concluded that “the UK now faces an increasing number of state and non-state groups with the ability and desire to carry out attacks using cyberspace” [[4]].
1.3. What is new is the altered public perception of the threat that cyber attacks present to CNI and thus our countries’ day-to-day fabric. The May and June 2017 WannaCry ransomware and (Not)Petya destructionware attacks, it seems, have demonstrated clearly the direct effect of semi-sophisticated attacks in cyberspace on the United Kingdom and its society. The cancellation of hospital appointments presented an undeniable impact on frontline services that arguably brought home to UK media and public the relevance of the cyber threat – beyond a previous focus in reporting on the theft of personal data and financial losses.
1.4. We therefore wholeheartedly agree with the Joint Committee on the National Security Strategy that the currently heightened awareness makes this an opportune moment for its inquiry into the cyber security of the UK’s CNI to have lasting impact.
1.5. Having contributed to the Committee’s cyber security inquiry in the previous session through written and oral evidence, and having been vocal in our desire for the Committee to continue its work on cyber security, NCC Group will support the Committee as best we can in its considerations on how to prepare the UK’s CNI for more frequent cyber attacks. We would be more than happy to provide oral evidence to the Committee once more.
1.6. As the Committee will be aware, NCC Group plc is one of the largest dedicated providers of professional and managed cyber security and risk mitigation services. With more than 2,000 employees across 35 offices world-wide, we have nation state capability across our cyber security divisions. We are a CBEST red teaming and CREST STAR provider and support the National Cyber Security Centre (NCSC) in its certification, accreditation and delivery programmes including those at the highest end of national security and incident response. We are also iCAST and TIBER-accredited, and thus able to provide threat intelligence-led red teaming and cyber simulation attack testing for the financial industries in Hong Kong and the Netherlands. Indeed, following the acquisition of Fox-IT in the Netherlands, we have invested heavily in our global threat intelligence capabilities. We continue to work with CNI providers in the defence and utility sectors; and are expanding our transport security practice to meet the increasing cyber security demand across the connected and autonomous vehicle, digital railway, and maritime sectors.
1.7. The remainder of our submission to the Committee’s inquiry responds to the Committee’s interest in: the types and sources of cyber threats, the appropriate definition of CNI, the consistency of regulation, the balance of responsibilities, the availability of skills and assessment of the current approach to cyber security across CNI. It:
1.7.1. Sets out that our comments from March 2017 remain valid and relevant to the Committee’s current considerations;
1.7.2. Finds that the developments over the past months have further increased the complexity of the threat landscape, and the urgency of action; and
1.7.3. Makes four recommendations for action on how better to prepare the UK’s CNI for increased frequency and persistence of cyber attacks going forward: greater consistency in regulatory expectations across sectors and clarity of cyber responsibility across government; greater adoption of full spectrum attack simulation to test organisations’ real-world susceptibility and resilience to cyber threats; a more permissive regulatory regime for the collection of cyber threat intelligence by the private sector to inform full spectrum attack simulation; and greater clarity as to the future of cross-border information sharing and cyber defence collaboration after Brexit.
2.1. Our comments from March 2017 remain valid and relevant to the Committee’s current considerations.
2.1.1. NCC Group emphasises that organised crime groups should be considered as equally capable threat actors as most nation states, particularly where they are acting in a proxy capacity on behalf of states as traditional boundaries become increasingly blurred.
2.1.2. The threat status remains critical, driven by increasing automation and interconnectedness and an increase in the understanding of and ability to exploit threat surfaces resulting from widespread adoption of technology; a rapid expansion of threat actor capabilities, and widespread availability of off-the-shelf hacking tools; and the rise of insider threats.
2.1.3. The UK’s challenge of ageing legacy systems in operation across national infrastructure remains significant, as does the risk of creating new inherently insecure connected systems, as vividly demonstrated by the impact of the WannaCry ransomware attack on the National Health Service.
2.1.4. Despite increasingly positive developments towards the acceptance and adoption of cyber resilience, driven and championed by the NCSC, as an organisational concept, challenges remain further to improve resilience, including through addressing basic cyber hygiene, education and skills across organisations.
2.1.5. The importance of cross-industry sector, public-private sector, and cross-border collaboration remains, and is heightened further as a result of Brexit uncertainty and adversaries’ blurring of clear delineations between state and non-state actors.
2.2. Nevertheless, the developments over the past months have further increased the complexity of the threat landscape.
2.2.1. The explicitly recognised legitimacy of nation states’ offensive cyber capability in the absence of internationally accepted rules of engagement increases political volatility.
2.2.1.1. The UK government, most recently in the UK-Poland cyber co-operation commitment [[5]], affirms states’ legitimate right to develop offensive and defensive cyber capabilities. In its 2016-17 Annual Report [[6]], moreover, the Intelligence and Security Committee (ISC) reports that the UK’s National Offensive Cyber Programme (NOCP) has delivered a step change in the UK’s offensive cyber capabilities, covering the abilities to deny, disrupt or degrade target communications of weapons systems, or attack wider systems of infrastructure.
2.2.1.2. The ISC also cautions, however, of the current underdevelopment of international law as applicable to state acts in cyber space, and the considerable variation of applying existing legal norms to cyber activity. It emphasises the importance of seeking international consensus on the rules of engagement for offensive cyber while warning of increasing signs that nation states, such as North Korea, are blatantly disregarding any rules of engagement.
2.2.1.3. There are unilateral attempts to enshrine the concept of offensive cyber more widely. In the United States, for example, the proposed Active Cyber Defense Certainty Act [[7]] would allow US-American corporations the right of “self-defence” in cyberspace, by means of “hacking back” so long as their aim is to disrupt, monitor or attribute the attack, or destroy stolen files. The proposed legislation has ignited much discussion. Warnings of “cyber-vigilantism” demonstrate the difficulties involved in developing an adequate set of rules and norms to govern the use of offensive cyber, even within the confines of a nation state.
2.2.1.4. The UK Government is committed to promoting an international stability framework for cyberspace. As noted above, the difficulties in establishing and enforcing any such construct effectively are obvious. In the meantime, the proliferation of offensive cyber could see a “wild west” of state sponsored cyber attacks and retaliation in which national infrastructure systems are both deliberate targets and inadvertent victims.
2.2.2. The expansion of cyber attacks to political systems and governance processes requires consideration in the context of preparing UK CNI for cyber attacks.
2.2.2.1. Largely as a result of the United States’ ongoing inquiry into the influence of Russian cyber operatives on the 2016 US Presidential Election, there is heightened awareness of foreign state-sponsored attempts to undermine western democracies. While the NCSC provided cyber security advice to the UK’s main political parties during the 2017 General Election, and the Parliamentary Digital Service has been tasked with safeguarding the cyber security of the UK Parliament, the UK Government has thus far rejected calls more formally to include political parties in its definition of critical national infrastructure. We believe that it is important adequately to safeguard UK citizens’ trust in the integrity of the country’s political process.
2.2.3. The unchecked proliferation of connected devices, and the continued lack of consensus regarding their (required) security standards risk creating a new legacy systems of security threats.
2.2.3.1. NCC Group has said before that we have to accept that our lives and our infrastructure, in our cities and buildings, will be connected to the internet. We believe that the exponential growth of connected devices continues significantly to increase the threat surface.
2.2.3.2. We wholeheartedly agree with the ISC’s warnings that the majority of IoT devices was not historically designed with cyber security in mind. We also agree with the ISC that “until consumers or regulators demand better security, many manufacturers are likely to side-line cyber security considerations, given their potential impact on … profit”.
2.2.3.3. Various initiatives and discussions are underway. CPA schemes exist to test the cyber security of smart meters before they are rolled out nationwide; discussions are underway to include powers for the Secretary of State to require cyber security standards for connected and autonomous vehicles in the future; the UK Government is expected to recommend a kite mark scheme for secure by default products for IoT devices in due course; and the European Commission is consulting on an EU-wide cyber security certification framework.
2.2.3.4. While it is right to tailor security requirements for connected devices across industry sectors, we do believe that a plethora of separate initiatives risks fragmenting the landscape unnecessarily. We further believe that continued reliance on voluntary nudge approaches will not deliver the required adoption of secure by default approaches that is needed to prevent the creation of a new generation insecure legacy system.
2.2.4. Regulatory developments, notably the planned implementation of the Network and Information Security (NIS) Directive by May 2018, will have heightened organisational awareness but risk becoming overly compliance-focused.
2.2.5. The uncertainty regarding future information sharing and cyber defence collaboration in light of Brexit could result in the costly and confusing duplication of cyber security initiatives.
2.3. We believe that to better prepare the UK’s CNI for the increased frequency and persistence of cyber attacks urgent action is required across four related areas:
2.3.1. There needs to be greater consistency in regulatory expectations across sectors and clarity of cyber responsibilities across government.
2.3.1.1. As we seek to illustrate in the table in Annex 1, the CNI cyber security landscape remains fragmented. Overall responsibility for the protection of the UK’s CNI IT networks, data, and systems from cyber attack sits with the National Cyber Security Centre (NCSC), who are also the UK Government’s proposed single point of contact under the NIS Directive. Beyond the NCSC, different sector regulators and government departments will likely share responsibility for general resilience, and specific cyber security requirements. While it is unsurprising, moreover, that different infrastructure sectors have differing levels of maturity when it comes to their cyber security preparedness, there seems to be a distinct lack of coordination across all sectors that would set a shared minimum expectation of cyber resilience, and allow for meaningful cross-sector benchmarking.
2.3.1.2. Amidst a plethora of strategies, guidance, responsibilities and reporting lines, there is a risk that organisations providing critical infrastructure are finding it increasingly difficult to navigate the landscape, and thus improve their cyber security resilience as needed in a meaningful manner as opposed to achieving compliance.
2.3.1.3. We believe that a comprehensive regulatory framework, possibly in the context of the NIS Directive, setting out clear expectations of cyber resilience without being overly prescriptive, will support organisations in taking the right steps.
2.3.1.4. In addition, we believe that further thought should be given to improving the cyber resilience of the below-CNI sectors such as e.g. manufacturing. We commend the work of the NCSC but are aware of anecdotal evidence suggesting that some industry sectors do not feel adequately covered by NCSC guidance. We believe that below-CNI industry associations should, in the first instance, work with the NCSC in developing sector relevant cyber security guidance, to avoid further fragmentation and confusion.
2.3.2. To address concerns of a tick-box compliance culture, full spectrum attack simulation, like the CBEST scheme from the Bank of England, should be adopted more widely to assess organisations’ resilience to real-world cyber threats.
2.3.2.1. We believe that the implementation of the NIS Directive, not least through the threat of substantial financial penalties, will lead operators of essential services to taking their cyber security more seriously. While this will improve basic cyber hygiene and standards, we are concerned that compliance with the NIS Directive provisions will become a tick-box exercise that prevents organisations from genuinely understanding their real-world susceptibility to cyber threats.
2.3.2.2. Instead, NCC Group advocates the more widespread adoption of full spectrum attack simulation, as piloted by the CBEST scheme for the financial sector, and adopted by the telecoms, civil nuclear and government sectors. For one, the scheme allows the sector, regulators and the government really to understand the cyber risks and resilience they are faced with, and take actions accordingly; but we also believe it will support the long-term integration of cyber resilience into more holistic resilience concepts and scenarios across national infrastructure systems.
2.3.2.3. Schemes such as CBEST are intelligence-led, relying on real cyber threat intelligence, so that the ethical attack assessment teams are able to replicate the tactics, techniques and procedures of known threat actors in more sophisticated and persistent attacks on essential services and critical systems. Organisations subjected to the schemes gain an understanding of what attacks could impact them and how; assess their ability to detect and respond to cyber attacks; and allow them to measure the impact of their investment and training towards improving their cyber resilience in fully realistic scenarios. The regulators gain important insight as to the real-world resilience of the sector and risk to its operation.
2.3.3. To maximise the effectiveness of full spectrum attack simulations on the basis of high quality cyber threat intelligence, a review of the current regulatory framework is required.
2.3.3.1. As outlined above, full spectrum attack simulations, like the CBEST scheme, are intelligence-led. This means ethical attack assessment teams rely on a pool of threat intelligence about real-world adversaries’ likely targets and behaviours to mimic them as realistically as possible. The maximum effectiveness of such simulations depends on the availability of high quality cyber threat intelligence about adversaries’ motivations, targets, and activities. This is best provided through cross-sector, public-private sector and international collaboration and information which allows all those involved to monitor cyber threats as they evolve and built cyber resilience capabilities accordingly.
2.3.3.2. In that regard, we are concerned that the current regulatory regime, notably the Computer Misuse Act 1990, presents significant barriers to private sector operators’ threat intelligence activities: the current wording of section 1 of the Computer Misuse Act 1990 deems a person guilty of an offence if they knowingly cause a computer to perform any function with intent to secure unauthorised access to any programme or data held. In threat intelligence, researchers and analysts might frequently need to cause an already compromised and communicating computer to perform a function with the intent to secure access in order to gain further insight into the compromised machine’s behaviour to learn about attackers’ tactics, techniques and procedures. While undertaken with the objective of detecting an attack, or preventing a future one, any such behaviour currently constitutes a criminal offence.
2.3.3.3. We believe that a review, and potential reform, of the current regulatory regime is required to assess current barriers to UK-based threat intelligence work, by extension, their impact on the effectiveness of the UK CNI’s cyber resilience testing, and the changes needed to address any shortcomings.
2.3.4. Greater clarity about the future of cross-border information sharing and cyber defence collaboration after Brexit is needed.
2.3.5. We have highlighted the importance of collaboration and information sharing, and are concerned as to how this will be impacted by the UK’s departure from the European Union.
2.3.6. Despite assurances regarding the future exchange of data, and continued data flow post-Brexit, it is currently unclear how any such regime would work in practice. In addition, the UK’s continued participation in EU information exchange forums will be subject to any future partnership agreement.
2.3.7. Furthermore, as the EU, in its September 2017 cyber security package sets out clearly its ambition to make more robust and effective its cyber resilience and defence structures, it is uncertain what role the UK will continue to play in any EU-wide system, or how any divergence in responses to cross-border cyber attacks will be addressed post-Brexit.
2.3.8. So as to ensure that providers of critical national infrastructure have a sustainable framework against which to make investment decisions, and undertake cyber resilience improvements, we would like to see clarity from the UK Government as to the future arrangements for cyber security collaboration cross-Brexit.
3.1. As in our previous engagement with the Joint Committee on the National Security Strategy, NCC Group is delighted to contribute to the Committee’s considerations, and remains committed to supporting its work to help prepare the UK’s critical national infrastructure against cyber attacks in the best possible way.
3.2. We would be very happy to provide oral evidence to the Committee to elaborate on our written submission and further inform the Committee’s discussions.
Annex 1: Table illustrating the fragmented CNI cyber security landscape
Varying levels of maturity across CNI sectors | Fragmentation of responsibilities | Reality of cyber threats and impacts | ||||||
Industry sectors identified as a ‘UK national infrastructure sector’ by CPNI*
| Industry sectors identified as a UK ‘operator of essential services’ under the NIS Directive**
| Cyber mentioned as part of 2016 summary of sector security & resilience plans | Dedicated sector cyber security strategy exists | ‘BEST’ frameworks exist / in development | Designated competent authorities under NIS Directive NCSC=single point of contact) | UK regulator with resilience responsibility (as per UKRN) | Publicised cyber attack(s) on national infrastructure in UK (examples) | Publicised cyber attack(s) on national infrastructure worldwide |
Chemicals |
|
|
|
|
|
|
| October 2011: reports of malicious software PoisonIvy infecting computer of defence and chemical companies to steal design documents, formulas, and details on manufacturing processes (link) |
Civil Nuclear |
|
| BEIS published Civil Nuclear Cyber Security Sector Strategy in February 2017 | NBEST in development |
| ONR | n/a | |
Communications | Digital Infrastructure | Plan to undertake risk assessment for broadcast and telecoms sectors | Ofcom published updated guidance on the security requirements in sections 105A to D of the Communications Act 2003 in December 2017 | TBEST in development | Ofcom | Ofcom |
| November 2017: disruption of Algerian state-owned telecoms provider (link) |
Defence |
| Acknowledgement of wide-ranging risk assessments |
|
|
|
|
| October 2011: reports of malicious software PoisonIvy infecting computer of defence and chemical companies to steal design documents, formulas, and details on manufacturing processes (link) |
Emergency Services |
|
|
|
|
|
| n/a | |
Energy | Energy (electricity, gas, oil) | Risk assessment for energy networks |
|
| BEIS | Ofgem |
| December 2015: Hack of SCADA credentials to gain access to control systems fo Ukranian power grid, taking substations offline, affecting more than 230,000 residents (link) |
Finance | Banking and financial markets infrastructure is specifically exempt from the provisions of the NIS Directive. | Acknowledgement of continued cyber risks, plan to produce NCSC/FCA sector guidance to cyber security management |
| CBEST acts as best practice |
| FCA |
| March 2016: Dridex malware used to withdraw $2bn from Bangladesh Bank at Federal Reserve of New York via SWIFT network (link) |
Food |
| Plan to provide good practice guidance |
|
|
|
|
| June 2017: Petya ransomware halts production production at Cadbury’s chocolate factory in Hobart, Australia (link) |
Government |
| Acknowledgement of malicious cyber activity as major risk and remaining challenge of prevention and mitigation |
| GBEST in development |
|
| June 2017: Bruteforce attack on UK Parliamentary email accounts, exploiting weak passwords, compromising up to 90 email accounts (link) | June 2015: Hack of US Office of Personnel Management (link) |
Health | Health (Healthcare settings) | Plan for CareCERT to provide guidance and advice |
|
| DH, NHS Digital |
| May 2017: WannaCry ransomware attack hits 47 NHS trusts resulting in cancelled operation and affecting frontline services such as A&E (link) |
|
Space |
|
|
|
|
|
| n/a | |
Transport | Transport (air, maritime, road and rail transport) | Acknowledgement of DfT’s active cyber security programme across all transport modes |
|
| DfT, CAA | ORR |
| November 2016: ransomware attack on Municipal Transportation Agency in San Francisco, resulting in closure of all ticketing machines on the network (link) |
Water | Drinking water supply & distribution | Plan to undertake further work to improve cyber security | DEFRA published Water Cyber Security Sector Strategy in March 2017 |
| DEFRA | Ofwat |
| Kemuri Water Company (pseudonym) attacked via exploiting unpatched web vulnerabilities in its internet-facing customer payment portal, changed the levels of chemicals being used to treat tap water, (link) |
| Digital Service Providers |
|
|
| ICO |
|
|
|
[1] https://www.gov.uk/government/publications/communique-strengthening-the-cyber-security-of-our-essential-services
[2] http://www.ukrn.org.uk/wp-content/uploads/2016/07/2015AprCSR-Phase1Report.pdf
http://www.ukrn.org.uk/wp-content/uploads/2016/07/2016FebCSR-Phase2Report.pdf
[3]https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/568546/sector_security_resilience_plans_14_11_2016.pdf
[4]https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/644968/UK_National_Risk_Register_2017.pdf
[5] https://www.gov.uk/government/publications/uk-poland-cyber-co-operation-commitment-joint-statement/uk-poland-cyber-co-operation-commitment
[6] https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/2016-2017_ISC_AR.pdf?attachauth=ANoY7cpgA06Qy8bRLy-5JeQ5IVqN9tlbbc72grDlllK0JAa5XUe0WvfcI5_-1od19x-iG4qQBOp2tLzMolIpoqlJZ07EO__qQRy6pqoDvw4QF-OwZXjN7AYPRchoaOyfoe0vI-rGADHZYy4yndXdEoTa2K2DMp90Y1bA_DN2rsHqADEkl1K7KKxFYPKxsf3zIZxeG0PsxE1I8DKJIRQSzm2RxI4IC1xolzplIoMyaqz8SNUAPYHgIH0%3D&attredirects=0
[7] https://www.congress.gov/bill/115th-congress/house-bill/4036