GCHQ to take hub role in UK cybersecurity

NEWS

The UK's intelligence agency GCHQ will become a main port of call for businesses dealing with cyberattacks, under the government's new cybersecurity strategy revealed on Friday.

Francis Maude

GCHQ will play a larger role in protecting businesses from cyberattacks, under a new cybersecurity strategy announced by Cabinet Office minister Francis Maude. Photo credit: BIS

The Cheltenham-based agency will get an infusion of hundreds of millions of pounds to fund its larger role in the UK's cyber-defence, Cabinet Office minister Francis Maude said in announcing the The UK Cyber Security Strategy (PDF). It will have a key role in a new cybersecurity 'hub' that will be set up as a brokerage for the public and private sectors to exchange information about threats and technologies.

With the new strategy, the government is aiming to make the UK one of the safest places in the world to do business, as well as tackling cybercrime and cyber-espionage in general, according to Maude. The document, the release of which has been delayed twice, replaces a two-year-old strategy and allocates £650m in funding to set up a National Cyber Security Programme.

"The growth of the internet has transformed our everyday lives," Maude said in a statement (PDF). "But with greater openness, interconnection and dependency comes greater vulnerability. The threat to our national security from cyberattacks is real and growing."

Of the £650m in funding, around 65 percent is expected to be spent on capabilities, 20 percent on critical cyber-infrastructure, nine percent on cybercrime specifics, five percent on reserves and one percent on education.

"Around half of the £650m funding will go towards enhancing the UK's core capability, based mainly at GCHQ at Cheltenham, to detect and counter cyberattacks," the strategy document stated. "The details of this work are necessarily classified, but it will strengthen and upgrade the sovereign capability the UK needs to confront the high-end threat."

Cybersecurity hub

One of the areas GCHQ is involved in is the cybersecurity hub. The government plans to launch a pilot for the hub in December, involving companies from five sectors — defence, finance, telecommunications, pharmaceuticals and energy — as well as GCHQ. If successful, businesses in other industries will be invited to join in March 2012.

"The government cannot tackle this challenge alone. The private sector — which owns, maintains and creates most of the very spaces we are seeking to defend — has a crucial role to play too," Maude said.

This means businesses will have to form "uncomfortable partnerships", Owen Pengelly, deputy director of the Office of Cyber Security and Information Assurance (Ocsia), acknowledged earlier in November. Companies have traditionally been reluctant to share sensitive security knowledge with their peers, fearing a leak might hurt their reputation or that the information could be used against them commercially.

Some details of the hub are still being worked out, according to Ross Parsell, the director of cyber-strategy for Thales UK, which is involved in the project. These include what happens if a publicly traded company's shareholders demand that it does not disclose vulnerabilities; where the IT for the hub will be located; and whether the hub itself could become a target for attacks from nation states.

The government cannot tackle this challenge alone. The private sector — which owns, maintains and creates most of the very spaces we are seeking to defend — has a crucial role to play too.

– Francis Maude

"Somebody raising the fact they've been breached immediately affects shareholder value, as we've seen with things like Sony — how do we make it right and okay for people to do that?" Parsell told ZDNet UK. "That's still a journey we're on."

"Some companies may not wish to publicly declare that they've had a breach. The hub is a protection mechanism — you could declare to Cheltenham that you've had this, but the hub then anonymises the attack profile," he noted.

The Centre for Protection of Critical National Infrastructure (CPNI), which tests information security products destined for use by key industries, is set to have a role as well, according to Parsell. It will most likely operate the front end of the hub, where companies can exchange and access attack information.

Commercial technology

Beyond the hub, the government will look at GCHQ's secret technology with the aim of commercialising it without compromising the organisation's role of protecting the UK from online threats. In addition, the strategy calls for GCHQ to host a Joint Cyber Unit to give the UK more military capabilities in cyberspace. These moves will help boost the country's cybersecurity industry, according to Maude.

Read this

Whitehall official outlines cybersecurity funding plan

The government plans to spend £650m on projects ranging from raising consumer security awareness to increasing GCHQ's capabilities, according to a top Whitehall official

Read more+

Another goal is to improve the police's work against internet-related crime. As announced earlier, a National Cyber Crime Unit will be created within the new FBI-style National Crime Agency by 2013. The cybercrime unit brings together the Metropolitan Police Central e-Crime Unit, which will investigate botnets and other high-level e-crime, with the Serious Organised Crime Agency, which will provide intelligence.

"The NCA will also support police forces across England and Wales to drive up wider national capability on cybercrime, including through shaping the training for mainstream law enforcement on cyber-issues," the strategy document states. "A key area will be ensuring the best possible flow of information between police forces and the NCA."


Get the latest technology news and analysis, blogs and reviewsdelivered directly to your inbox with ZDNet UK'snewsletters.

Talkback

It's reassuring to know the Government are taking this seriously. As a Computer Engineer, I can report that the #1 fear folk have around computers is that of unauthorised access to their data.

Chris Sadler via Facebook 25 November, 2011 21:24
Reply

I just hope it is managed and run by IT people not civil servant types.

Burn-IT 28 November, 2011 10:16
Reply

Am I alone in thinking this is just a cover for the government setting up the ability to block any website or IP they wish at will without recourse to any legal proceedings? Sounds like it to me.

ians1 29 November, 2011 02:38
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

5 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

6 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

12 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

16 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

18 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

22 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

3 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround