Risk
6/26/2013
10:45 AM
50%
50%

British Cyber Defenses Receive Unexpected Boost

British intelligence services and cybersecurity initiatives get increased investment, even amidst brutal government cuts.

Despite recent widespread concern over the reach of their powers, especially Internet monitoring, Britain's security services scored a financial victory Wednesday concerning the next few years of government spending: Britain's intelligence services left Chancellor George Osborne's 2013 Spending Review with a 3.4% boost in funding.

To put that in context, most British institutions saw reduced budgets, ranging from 10% for local government to 6% for Whitehall's business department. Even law enforcement had its funding crunched, with the Home Office's budget cut by 6%.

[ Information Commissioner's Office gives Google 35 days to purge personal data collected via Street View. Read Britain Orders Google To Delete Street View Data. ]

The extra money is intended for the security and intelligence agencies to achieve "key national security priorities, maintain core counter terrorist capabilities, and protect U.K. citizens and interests against terrorism threats."

Part of the funding will come in the form of extended support for cybersecurity, said to be a "the new frontier of defense -- and a priority for this government." Specifically, £210 million ($323 million) in the cross-government National Cyber Security Program (NCSP) will be invested in a broad range of projects across government to deliver the U.K.'s cyber security objectives, details of which have been promised later in the year.

Projects will be set up to protect U.K. interests in cyber space, making it harder for hostile states and criminals to target the country, and to raise business and public awareness of online threats, with a focus on how they can protect themselves and invest in the skills and standards needed to support a vibrant and internationally competitive U.K. cybersecurity sector.

The £210 million adds to the previously committed £650 million ($1 billion) funding for the NCSP. According to government sources, this money is generating significant benefit to the U.K. by increasing the capability to tackle cyber threats, turning cybersecurity into an economic opportunity and establishing the U.K. as a leader in this field.

Osborne has also called for an ongoing efficiencies package to enable Britain's intelligence and counter-intelligence agencies to operate more effectively and to encourage further collaboration between GCHQ, MI5 and MI6 as part of this process.

For the Chancellor, Britain's spies' work remains critical. He stated in his speech to Parliament Wednesday, "Silently, and often heroically, these fellow citizens protect us and our way of life."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7830
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse cap...

CVE-2014-7831
Published: 2014-11-24
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVE-2014-7832
Published: 2014-11-24
mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by vi...

CVE-2014-7833
Published: 2014-11-24
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVE-2014-7834
Published: 2014-11-24
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?