UK launches dedicated cybersecurity agency

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The UK government has announced that it is to form a cybersecurity agency, one of whose functions will be to develop a cyberattack capability.

The Office of Cyber Security (OCS), dedicated to protecting Britain's IT infrastructure, will be created in line with a model proposed — and in part practised by — the US, the Cabinet Office said on Thursday. The OCS will have charge of a cross-government programme of work, while a multi-agency Cyber Security Operations Centre (CSOC), based at GCHQ in Cheltenham, will coordinate the protection of critical IT systems.

As well as cyber-defence and cyberattack coordination, the OCS will act as a conduit for information security collaboration between government and industry experts. Robert Hannigan, the prime minister's security adviser, told ZDNet UK that the OCS would be about "drawing together what people are already doing in the Ministry of Defence, the intelligence services and the police".

The government has never admitted that it has the systems and personnel to launch a cyberattack. However, according to a senior government official, who wished not to be named, the OCS will have a role in coordinating cyber-offense capabilities that will build on the resources the government currently has.

In extreme cases, the government will launch a cyberattack in response to intrusions into the UK's own systems. "Yes, we will do things proactively," the Whitehall official said at a Cabinet Office press briefing. "Information assurance has been about building stronger walls, but there's only so much you can do. You come to a point when you are allowing criminals and others a low risk in continuing to attack, and there comes a time when that has to change. This is the first time we are saying publically we are not going to sit back."

The government will develop information systems to allow it to launch denial-of-service attacks and to spy on chosen targets, said the official. "We will have a whole range of offensive capabilities, including distributed denial-of-service," said the official. "DDoS is not a first response — we definitely need graduated responses."

"Aggressive attacks are pretty far up the scale, and we want to avoid collateral damage as far as possible. It's a fine line. We don't want to get into cyber-warfare, but it's not reasonable to sit back," the official added.

The Cabinet Office official said the government would try to respond to attacks on UK systems by recourse to the law: "Whenever we can, we will pursue criminals through legal frameworks, but that only works in some countries. Clearly, in other areas of the world, people are acting with impunity."

The threat of cyber-warfare among countries was highlighted by the May 2007 attacks on the Estonian national infrastructure. Further attacks, on countries such as Georgia, have strengthened the government's resolve to address IT security issues.

The model for the OCS is similar to that in the US, which plans to quadruple the number of security experts defending against cyberattack, while cyber-offense capabilities are currently under the aegis of the US Air Force. The Pentagon will create a cyber-command to oversee US cyber-military efforts.

The OCS will come under protection of the Cabinet Office and will report to the National Security Secretariat in that office. No director has been named for the department.

The office will pool intelligence capabilities from MI5, MI6, the Ministry of Defence, the Metropolitan Police e-Crime Unit, and the Serious and Organised Crime Agency (Soca). Other government agencies involved include the Department of Business, Innovation and Skills (BIS); the Central Sponsor for Information Assurance (CSIA); CESG, the information-assurance arm of GCHC; and the Centre for the Protection of National Infrastructure (CPNI).

The OCS will launch with a staff of 16 to 20, while the CSOC in Cheltenham will have 20 to 25. "We will start small and learn from initial US attempts [to build a cyber-security department]," said a Cabinet Office official. "We want to establish a core team."

The government will also reach out to industry to create a pool of IT security expertise, given the scale of the task of securing UK public and private sector IT infrastructure. A key priority for implementing the strategy will be to develop a cyber-industry with "opportunities for high-tech businesses in the UK", according to a government statement.

In addition, the OCS plans to launch a cyber-skills strategy to address skills gaps in government and industry, and work with other countries to develop international law in that area.

The OCS will seek to strengthen links with countries, such as the US, and develop links with other European partners like Germany and France. Hannigan said cybersecurity collaboration with Nato is in the early stages, but that work is planned to build channels of communication with the European Network Security Agency (Enisa).

On Thursday, prime minister Gordon Brown announced the OCS as part of the government's 2009 National Security Strategy, which for the first time includes an IT security component called the Cyber Security Strategy 2009.

In a statement, Brown said securing cyberspace was necessary to give people confidence in the security of web transactions.

"Just as in the 19th century we had to secure the seas for our national safety and prosperity, and in the 20th century we had to secure the air, in the 21st century we also have to secure our position in cyberspace in order to give people and businesses the confidence they need to operate safely there," said Brown.

Talkback

This is all about control.

Once again the US of A are getting others to do their dirty work.

This will start a cyber war not stop it.

One has a big stick, the others then get bigger sticks.

LOL these people are stupid.

Why do you think America don't want little countries to have NUKES?

They want to be in control.

I'm getting of this stupid planet ASAP.



Mark Edgar BEng
Forres
Scotland

ADarkGerm 25 June, 2009 12:37
Reply

This is the one of the best way to protect.

MMRahman 26 June, 2009 03:42
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SPM

The 2 million number quoted is shipments not sales, an exact repeat of last year's dire sales of WP7. Sales to customers are likely to number only...

3 hours ago by SPM on Nokia earnings fail to shine despite Lumia
apexwm

It sounds like this is just another variable in the complex equation of Microsoft licensing, which often results in customers overpaying as it is....

5 hours ago by apexwm on UK customers to lose out in Microsoft licensing change
chonzchor

I am really thankful to you for this nice and beautiful information.I really like this. cable ties

5 hours ago by chonzchor on Currys £16.99 USB cable rip-off.
Brian Jones

What would be nice would be if Microsoft practiced consistent pricing between the US and Europe.

10 hours ago by Brian Jones via Facebook on UK customers to lose out in Microsoft licensing change
Karen Friar

@Scott Deagan: Ofcom dedicated a section to upload speeds - see page 19 onward of its full report:...

10 hours ago by Karen Friar on UK broadband speed climbs 22 percent
EUDataProtection

The EU proposals can all be read in full on the reform website: http://ec.europa.eu/justice/data-protection/minisite/index.html

12 hours ago by EUDataProtection on Firms face tough new EU fines for data breaches
Jake Rayson

Found out that Taskwarrior stores all data in plain text files: "Task writes all pending tasks to the file ~/.task/pending.data and all completed...

14 hours ago by Jake Rayson on Taskwarrior: command line task manager
ians1

"...based 6,000 miles away..." Indeed, so who do you complain to when things go wrong? I would not buy shares in Faecebook even if I could...

14 hours ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

These are really very useful tips of backing up the system. Each tips are important and essential to prevent loosing all the data that we have....

17 hours ago by servermanagement on Ten ways to take the sting out of IT disasters
Scott Deagan

Why is the upstream never discussed? I'd like to see Ofcom explain to Internet users why people in the UK can only get a maximum of 10Mb/s upstream...

1 day ago by Scott Deagan via Facebook on UK broadband speed climbs 22 percent
Moley

Seemingly a very strange decision, even perverse. Mind you, the basis of the decision is hardly explained here or in Cnet. Perhaps we will hear...

1 day ago by Moley on Free Maps costs Google £400K in damages in France
Jake Rayson

@OccupyACAT: I had heard mention of the Emacs extension but not the Ubiquity project. Interesting to see an idea spread almost simultaneously! Re....

1 day ago by Jake Rayson on Ubuntu HUD Intenterface? Sublime already there!
markhumphryes

With no Flash support on LoveFilm, mobile devices running Android will not be able to use it - I presume - I tried a trial via my Galaxy Tab 10.1...

1 day ago by markhumphryes on Lovefilm drops Flash, kills Linux support
manek

And people wonder why there is caution about doing business with large, consumer-focused technology companies, most of which are based 6,000 miles...

2 days ago by manek on Facebook plans to raise $5bn via share launch
manek

Yes, frameworks and smarter compilers - but I suspect a lot of the code will have to be written with parallel processing as one of its fundamental...

2 days ago by manek on Parallel computing takes a step forward
Simon Bisson and Mary Branscombe

Well, this is why I'm both fascinated and slightly worried; parallel computing and concurrency and complex architectures don't seem to be something...

2 days ago by Simon Bisson and Mary Branscombe on Parallel computing takes a step forward
ians1

Let's hope that they take more notice of their shareholders than they do of their poor customers! I have never experienced customer service as bad...

2 days ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

Thanks for the heads up. Will definitely check this HUD Intenterface.

2 days ago by servermanagement on Linux Minterface
Will A

Some more observations by an extremely frustrated user in Canada (apparently every country has a different set of "issues"): The web interfaces...

2 days ago by Will A on Cambridge researchers knock Verified by Visa
Jake Rayson

@zdnetukuser: I hope there's more conciliation and less bitterness in the graphical shell camps, I'd like to Ubuntu to succeed, I *want* to have a...

2 days ago by Jake Rayson on Linux Minterface