2nd March 2018

 

Cyber security: Critical National Infrastructure inquiryUKCloud response

 

1.              About UKCloud

 

1.1              UKCloud is a British cloud services company providing highly secure cloud services exclusively to the UK public sector. Customers include the Ministry of Defence, the Ministry of Justice, the Home Office and many other public-sector bodies that hold sensitive data. As a UK company, our cloud platform - and the data that resides within it - is only hosted in the UK, our services have been accredited by NCSC on behalf of our customers as suitable for data at OFFICIAL (including OFFICIAL-SENSITIVE) level. Last year, UKCloud was awarded the Queen’s Award for Enterprise in recognition of achievements and innovation in the sector, and in 2016 topped the Sunday Times Hiscox Tech Track 100 list of the UK’S fastest growing technology companies.

 

2.              Summary

 

2.1              In this short response to the committee’s inquiry, we have focussed on the relationship between Government and cloud service providers, as cloud services are becoming increasingly important in CNI delivery. We provide evidence on the balance of responsibility between Government and the private sector and the effectiveness of the Government’s relationships with private sector operators.

 

3.              The balance of responsibilities between the Government and private-sector operators in protecting Critical National Infrastructure against cyber-attack.

 

3.1     As the Government’s National Cyber Security Strategy recognised, the overwhelming majority of cyber-attacks have a contributing human factor. Government is responsible for ensuring that public sector staff have a firm grasp of cyber risk and that the correct processes are in place to properly manage these risks. They also need to ensure that private sector companies responsible for CNI have effective security controls in place, and that these security controls are reflected throughout the supply chain.

 

3.2     However, companies supplying Government with data storage and cloud computing solutions clearly have a responsibility to keep information secure. In 2014, Government rightly mandated that all suppliers must be compliant with Cyber Essentials controls, and in addition, the Network and Information Security Directive which is expected to be transposed in the UK in May 2018 will be applicable to CNI and cloud providers.

 

3.3     Nonetheless, as sensitive government data increases both in volume and in value, and where much of the CNI is directly or indirectly exposed to the internet, Government needs to guard against taking a “tick box” approach to compliance with NIS and other security protocols such as Cyber Essentials, and ensure that sufficient due diligence is performed on  CNI providers, and their supply chain, to understand and manage vulnerabilities which in some cases may be complex – for example the extent to which CNI services enable, or mitigate, human error[1].

 

3.4     Given that cyber threats to CNI are increasingly international in nature, Government needs to ensure that its sovereign capabilities and industries are recognised and developed. For example, some cloud companies will access and maintain services from abroad, even if the data is stored and processed in the UK. The extent of this risk is often unknown[2]. Whilst malicious acts on the part of individuals can never be predicted with 100% accuracy, instilling some basic hygiene factors, such as ensuring CNI services are only ever accessed and delivered by security cleared UK national personnel will considerably reduce risk.

 

3.5   With cloud services becoming increasingly important in CNI delivery, it is important for Government to understand which other consumers or organisations might be sharing the cloud service that is also storing and processing CNI data. Adequate separation between third party information and CNI information is essential, and this is best achieved by creating communities of interest within a cloud platform to logically segregate CNI sensitive data.

 

3.6   The introduction of third party devices (Internet of Things) connected at scale across the CNI landscape considerably expands the cyber threat. How these devices connect and are granted access to a cloud service becomes critical in mitigating risk. High assurance network connectivity would provide opportunities for further segregation of CNI data traffic in transit.

 

4.              The effectiveness of the Government's relationships with, respectively, private-sector operators and regulators in protecting Critical National Infrastructure from cyber-attack.

 

4.1   Cyber threats can come from anywhere in the world, and the global nature of internet enabled services can also create jurisdictional complexities with regards to data. Data sovereignty is therefore a critical issue when examining the effectiveness of the Government’s relationships with private sector businesses and their ability to protect CNI.

 

4.2   Data stored by non-UK companies, or stored outside of the UK, will be subject to foreign laws and there are high-profile case studies currently being played out in the US that clearly demonstrate the issue[3]. Recently, the Australian Government took steps to ensure that their CNI was protected. In June 2017, Global Switch was purchased by a Chinese firm, and citing security concerns, the Australian Defence Department decided to terminate their ongoing contracts[4] to ensure that no data was held by a foreign power.

 

4.3   When concerns were raised in the House of Commons about the Chinese stake in Global Switch[5], the Prime Minister’s response was that this was a good news story about China’s willingness to invest in the UK.  Whilst inward investment is of course important, and a crucial barometer of the UK’s post Brexit prospects, it is equally important for Government to live by the aspirations for economic growth set out in the Industrial Strategy White Paper, “our investments in infrastructure, and our decisions on procurement, are among the government’s most significant interventions in the economy”, and the Digital Strategy’s aim “to help more British digital technology suppliers benefit from government’s own spending”.

 

4.4   In February 2018 the European Commission revealed that it is preparing to introduce laws to force technology companies to reveal details on citizens, even if those details are stored on servers outside EU territory[6]. Although this is intended to bolster security in the EU, we believe that post Brexit there is a strong argument, rooted in national and economic security and citizen trust, for Government to recognise and make the case for data localism when it comes to the sensitive data that lies at the heart of the CNI.

 

 

 

© UKCloud Ltd, 2018                            Version 1.0

                            Page 3 of 3


[1] http://www.bbc.co.uk/news/technology-42839462

[2] http://www.cloud-council.org/deliverables/CSCC-Public-Cloud-Service-Agreements-What-to-Expect-and-What-to-Negotiate.pdf “For example, even the remote access to customer data by an

agent working for an outsourced call center might present a challenge: in the course of fixing an issue,

records or files manipulated by the remote technician may reside, even if temporarily, in a different

jurisdiction than was initially intended”.

[3] https://www.nbcnews.com/politics/supreme-court/gov-t-battles-microsoft-email-privacy-case-supreme-court-n851216

https://www.theregister.co.uk/2018/02/07/big_tech_biz_back_us_proposals_to_ease_overseas_data_transfers/

[4] https://www.theregister.co.uk/2017/06/20/department_of_defence_pulling_kit_out_of_global_switch/

[5] https://hansard.parliament.uk/Commons/2016-09-07/debates/FFB960A3-F628-49CE-A522-DBA2C3960920/G20Summit#contribution-8F9D5A44-B571-4A7E-B4B5-AAA714ACD110

[6] http://www.iteuropa.com/?q=ec-will-control-data-stored-anywhere