Start your day with intelligence. Get The OODA Daily Pulse.
Dating back even longer than the more familiar and storied intelligence community history of collaboration between British Intelligence and the U.S. Office of Strategic Services (OSS) during World World II, the UK intelligence agencies have always been a vital partner with the U.S. intelligence community and, arguably, have been the most integral global partner in the prevention of an attack on U.S. soil since 9/11.
Enter the current cyber threat landscape, and it is instructional to review how the Brits are framing the challenges and outcomes of the last year in cybersecurity. The National Cyber Security Centre (NCSC), a part of Government Communications Headquarters (GCHQ), was created in 2016 as part of the UK’s 5-year National Cyber Security Strategy. Self-described as “the UK’s technical authority for cyber security,” the NCSC has put out an annual review every year since its inception.
In this year’s report, “Annual Review 2021: Making the UK the safest place to live and work online“, the NCSC, as part of a national security agency, is unable to disclose all its work publicly, but seeks in the annual review “to describe the year with insights and facts from colleagues inside and out of the organisation.”
Lindy Cameron, CEO of the National Cyber Security Centre since October 2020, notes in the CEO Foreword to the Annual Review:
In his Foreword Statement, Sir Jeremy Fleming (Director of the UK GCHQ) remarked that “in the UK there was an increase in the scale and severity of ransomware attacks, targeting all sectors from businesses to public services. Of course, coronavirus continues to shape what we see. Cybercriminals are still exploiting the pandemic, while hostile states shifted their cyber operations to steal vaccine and medical research. The NCSC worked..to protect those involved in the UK’s response, including the NHS, medical research and the vaccine supply chain. Its impact has been substantial and far-reaching at a time of global crisis.”
The review has as its focus five areas of cybersecurity:
The Threat: Assessing, responding to, disrupting and deterring cyber threats.
Resilience: Building a cyber-resilient UK.
Technology: Spearheading research and analysis to find new ways to secure the UK’s digital systems.
Ecosystem: Strengthening and growing the UK’s cyber security ecosystem.
Global Leadership: Advancing UK leadership in support of a free, open, peaceful and secure cyberspace.
Each chapter of the review highlights key achievements and developments, including:
“Organised crime groups spend time conducting in-depth reconnaissance on their targeted victims. They will identify exploitable cyber security weaknesses. They will use spoofing and spearphishing to masquerade as employees to get access to the networks they need. They will look for the business-critical files to encrypt and hold hostage. They may identify embarrassing or sensitive material that they can threaten to leak or sell to others. And they may even research to see if a potential victim’s insurance covers the payment of ransoms. This process can be painstaking and lengthy, but it means that, when they are ready to deploy, the effect of ransomware on an unprepared business is brutal.”
Many of the developments highlighted by the NCSC Annual Review mirror findings from the Google Cybersecurity Action Team Cloud Threat Intel Report.
In 2021, the NCSC continued to roll out their CSC’s Active Cyber Defence Services, including launching the Early Warning Service, to alert organisations to emerging threats, and the increasing success of the Suspicious Email Reporting Service, which allows the public to report potential scams. The Suspicious Email Reporting Service is run in partnership with the City of London Police, and since its launch in April 2020 has received more than 7.25 million reports from the public, with almost 60,000 scams taken down as a result.
Equivalent USG DHS CISA type services for the U.S public and private sector is the National Cyber Awareness System | CISA.
Sharing and collaborating with organisations and the public is also a core function of the NCSC, working with a range of sectors from education to farming, sport to Critical National Infrastructure (CNI), providing custom advice to each industry vertical on becoming more resilient. In an innovative effort to create “cyber awareness” amongst the general public in the UK, GCHQ’s first TV advertising campaign was launched, “directly engaging the British public with advice on how they can increase their cyber security.”
This year also marks the culmination of the most recent 5-year National Cyber Security Strategy (the first was from 2011-1016).
Director Fleming addresses the 5-year benchmark: “The Government’s investment in cyber security means we know much more about the changing threats the country faces today than we did five years ago, when the NCSC was set up. And we are looking ahead too. We can see technology leadership is shifting eastwards. The key technology we will rely on for future prosperity and security won’t necessarily have democratic values at its core. We will work with partners around the world to help the UK and allies face this moment of reckoning.”
Also, not much unlike the public-private partnership considerations and the role of the market in cybersecurity in the U.S., in 2019 an independent defense and security think-tank RUSI (the Royal United Services Institute) put together a research project “to determine the best course for UK national cyber security beyond 2021, stressing…the need for an enhanced role for private sector providers partnering with the public sector and government.” The RUSI research project found that “there must be a clear mutual understanding as to where UK government responsibility ends, and private sector accountability begins. This dialogue is at present only in the early stages.”
An early report also suggests the next National Cyber Strategy will reflect the need to develop “an industrial base that delivers innovative and effective cyber security products and services that help everyone stay safe in cyberspace.”
For more on the types of threats discussed in the NCSC Annual Review, see Cybersecurity Sensemaking | OODA Loop.
Now more than ever, organizations need to apply rigorous thought to business risks and opportunities. In doing so it is useful to understand the concepts embodied in the terms Black Swan and Gray Rhino. See: Potential Future Opportunities, Risks and Mitigation Strategies in the Age of Continuous Crisis
The OODA leadership and analysts have decades of experience in understanding and mitigating cybersecurity threats and apply this real-world practitioner knowledge in our research and reporting. This page on the site is a repository of the best of our actionable research as well as a news stream of our daily reporting on cybersecurity threats and mitigation measures. See: Cybersecurity Sensemaking
OODA’s leadership and analysts have decades of direct experience helping organizations improve their ability to make sense of their current environment and assess the best courses of action for success going forward. This includes helping establish competitive intelligence and corporate intelligence capabilities. Our special series on the Intelligent Enterprise highlights research and reports that can accelerate any organization along its journey to optimized intelligence. See: Corporate Sensemaking
This page serves as a dynamic resource for OODA Network members looking for Artificial Intelligence information to drive their decision-making process. This includes a special guide for executives seeking to make the most of AI in their enterprise. See: Artificial Intelligence Sensemaking
From the very beginning of the pandemic, we have focused on research on what may come next and what to do about it today. This section of the site captures the best of our reporting plus daily intelligence as well as pointers to reputable information from other sites. See OODA COVID-19 Sensemaking Page.
A dynamic resource for OODA Network members looking for insights into the current and future developments in Space, including a special executive’s guide to space. See: Space Sensemaking
OODA is one of the few independent research sources with experience in due diligence on quantum computing and quantum security companies and capabilities. Our practitioner’s lens on insights ensures our research is grounded in reality. See Quantum Computing Sensemaking.
In 2020, we launched the OODAcast video and podcast series designed to provide you with insightful analysis and intelligence to inform your decision-making process. We do this through a series of expert interviews and topical videos highlighting global technologies such as cybersecurity, AI, quantum computing along with discussions on global risk and opportunity issues. See The OODAcast.