UK Discloses Offensive Cyber Capabilities Principles

The UK government continues to align its cyber response to the growing threat posed by national adversaries in line with its latest National Cyber ​​Strategy (NCS), released in December 2022.

After introducing a new MI5-hosted agency, the National Protection Security Authority (NPSA), as part of the Integrated Review Refresh (IRR) in March 2023, the government will be tasked with addressing state-sponsored threats to British businesses. I am indebted. offensive cyber capabilities.

The National Cyber ​​Force (NCF), a partnership between GCHQ and the Ministry of Defense (MoD), which conducts cyber operations to protect against threats to Britain, conducts covert offensive cyber operations at its first meeting shared the principles of That kind of guide published on April 4th.

Before outlining some of the principles governing how the UK will use its offensive cyber capabilities to respond to cyber and physical threats, the NCF shared some caveats of its own importance. .

First, it said, government agencies “rarely get involved” when other responses are better suited to address the problem effectively.

The NCF also acknowledged that cyber operations are unlikely to be decisive in isolation and should be integrated into a broader response strategy.

However, the agency also outlines why aggressive cyberattacks can be a useful tool.

  • It can also provide the only practical means of hindering an attacker’s ability to exploit the Internet and digital technologies.
  • Specific effects can be precisely targeted, avoiding the challenges of using other potentially physically destructive interventions.
  • It can produce a variety of cognitive effects that are difficult to achieve with other approaches, such as undermining the attacker’s confidence in the data they are receiving and the ability of the information system to function effectively.

These benefits may sound obvious to some, but recognizing this in government documents can be seen as a step forward in state accountability in cyberspace.

In the core section of the guide, NCF explained that its cyber operations follow three principles.

They are also governed by the “cognitive effect doctrine”. This means that the UK will use its cyber powers to limit or influence the information available to its adversaries, undermining confidence in their technology and the information it provides.

“Our work may include covert operations against IT networks or technology used by adversaries and the adoption of techniques to degrade or completely disable that technology,” the NCF said. points out.

The document advocates that the UK insists that the NCF will operate in a responsible and ethical manner, that its operations will be conducted in accordance with the legal framework and that its impact will be carefully assessed both for escalation and de-escalation. It was also an opportunity.

“By outlining current thinking, the NCF aims to foster constructive debate and contribute to demonstrating the UK’s commitment to being a responsible cyber powerhouse. It is possible,” the document said.

Sir Jeremy Fleming, director of GCHQ, said the guide could pave the way for greater cooperation between nations, or even a cyber coalition of nations in the future. “In a world of growing threats and ever-higher risks, this document serves as a benchmark for the UK’s approach, allowing like-minded governments to work together internationally to develop a shared vision and values ​​for the responsible use of cyber operations. We hope that it will be the foundation for establishing a

Announced in 2018 and formally established in 2020 as a joint agency of the GCHQ-MoD under the previous National Offensive Cyber ​​Programme, the NCF is now a joint agency of the Defense Science and Technology Laboratory (DSTL) and the UK Secret Intelligence Service. We are recruiting personnel from GCHQ and MOD, including (SIS/MI6) under one unified command.

This is the first time the UK government has revealed details about how the government works.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *