Risk
6/26/2013
10:45 AM
50%
50%

British Cyber Defenses Receive Unexpected Boost

British intelligence services and cybersecurity initiatives get increased investment, even amidst brutal government cuts.

Despite recent widespread concern over the reach of their powers, especially Internet monitoring, Britain's security services scored a financial victory Wednesday concerning the next few years of government spending: Britain's intelligence services left Chancellor George Osborne's 2013 Spending Review with a 3.4% boost in funding.

To put that in context, most British institutions saw reduced budgets, ranging from 10% for local government to 6% for Whitehall's business department. Even law enforcement had its funding crunched, with the Home Office's budget cut by 6%.

[ Information Commissioner's Office gives Google 35 days to purge personal data collected via Street View. Read Britain Orders Google To Delete Street View Data. ]

The extra money is intended for the security and intelligence agencies to achieve "key national security priorities, maintain core counter terrorist capabilities, and protect U.K. citizens and interests against terrorism threats."

Part of the funding will come in the form of extended support for cybersecurity, said to be a "the new frontier of defense -- and a priority for this government." Specifically, £210 million ($323 million) in the cross-government National Cyber Security Program (NCSP) will be invested in a broad range of projects across government to deliver the U.K.'s cyber security objectives, details of which have been promised later in the year.

Projects will be set up to protect U.K. interests in cyber space, making it harder for hostile states and criminals to target the country, and to raise business and public awareness of online threats, with a focus on how they can protect themselves and invest in the skills and standards needed to support a vibrant and internationally competitive U.K. cybersecurity sector.

The £210 million adds to the previously committed £650 million ($1 billion) funding for the NCSP. According to government sources, this money is generating significant benefit to the U.K. by increasing the capability to tackle cyber threats, turning cybersecurity into an economic opportunity and establishing the U.K. as a leader in this field.

Osborne has also called for an ongoing efficiencies package to enable Britain's intelligence and counter-intelligence agencies to operate more effectively and to encourage further collaboration between GCHQ, MI5 and MI6 as part of this process.

For the Chancellor, Britain's spies' work remains critical. He stated in his speech to Parliament Wednesday, "Silently, and often heroically, these fellow citizens protect us and our way of life."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2808
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a rel...

CVE-2015-0800
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2...

CVE-2015-0801
Published: 2015-04-01
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

CVE-2015-0802
Published: 2015-04-01
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a p...

CVE-2015-0803
Published: 2015-04-01
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) ...

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.