01 Sep 2011
A security expert has claimed that the UK is devoting most of its cyber crime fighting efforts to cyber attack, leaving limited resources for defence.
Speaking exclusively to Computing, Ross Anderson, professor of security engineering at the Cambridge University computer laboratory, stated that 90 per cent of the government's recent funding injection into cyber security was going to the UK's offensive capability.
"The spooks - GCHQ [Government Communications Headquarters, pictured] - are getting 90 per cent of this new £650m for cyber security [they are responsible for cyber attacks]. The rest, about £65m, is going to the police."
Anderson blamed the imbalance on the fact that the UK's cyber defence capabilities are organisationally placed within GCHQ, the body responsible for electronic espionage, or cyber attack.
"Like the US, the UK has unfortunately got the government's offensive and defensive arms linked together.
"CESG [Communications-Electronic Security Group], which is supposedly defending the core functions of government against for example cyber espionage by the Chinese, is a small subsidiary of GCHQ whose job is exploiting those sources abroad.
"This mixed mission is very bad policy, because it means defensive interests are always less important than an offensive approach."
Anderson claimed that GCHQ's security researchers are much more likely to use any security loopholes they discover for attack than defence.
"Suppose you're a scientist at Cheltenham and you come up with a new exploit of Windows. Are you going to tell Microsoft, get it patched and protect 60 million Brits? Or are you going to keep quiet about it so you can exploit 1.2 billion Chinese and 1 billion Indians, for example?"
"Because of the way incentives work within organisations, you always find the offensive mission dominating the defensive mission, even when that is to the detriment of national interests," said Anderson.
He explained that the UK follows the US organisational model.
"In the US, the NSA [National Security Agency] does everything [including attack and defence], which is one of the reasons the UK does it this way.
"The total amount spent on cyber crime in the US by the federal government is only about $100m [£61m]. As in Britain, almost all of the cyber conflict dollars are spent on offence rather than defence.
"Even so, the US law enforcement agencies do most of the heavy lifting in the world. The UK's contribution to the overall fight against cyber crime is very small."
Anderson concluded by saying that Germany organises its cyber security in a better way, in his opinion.
"The Germans have got it organised properly in that the defensive arm, the BSI [Federal Office for Information Security] is a separate organisation that reports to the Chancellor through a separate cabinet minister from the BND [German Security Service].
"The right way to handle information, intelligence and security agencies in the modern age its to have the intelligence agency and the security agency running quite separately."
As far as official sources are concerned, GCHQ is only getting less than 56% of this £650m (the 56% are being shared between the three intelligence agencies). Even adding up the 15% allocated to the MoD, we remain far from 90% of the budget allocated supposedly for CNA...
Source: Intelligence and Security Committee - Annual Report 2010-2011, pp. 55 available at http://www.official-documents.gov.uk/document/cm81/8114/8114.pdf
Posted by: C. Guitton 29 Sep 2011
I can't see why this expenditure may be considered for the offensive capabilities ?! A study in 2003 by Berkeley outlined that outages in Electricity in the US has cost 80 billion dollars. I would believe it is the defensive and may be justified through empirical data and the models built by military may be used to protect national infrastructure. I am not sure where the author got his information from the total spent or the projected budget is 1.4 billion + 2.8 billion for the air force + 50 billion on R&D. It hasn't been confirmed how much will be spent on cyber security from that 50 billion + 101 million pounds on the new HQ in the US. As a media channel I believe you should provide your readers with empirical data
Posted by: S. Vanderloot 05 Sep 2011
Have your say on this article
Newsletters
Latest stories from Threats and Risks
You may also like
Threats and Risks jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?