Risk
6/26/2013
10:45 AM
50%
50%

British Cyber Defenses Receive Unexpected Boost

British intelligence services and cybersecurity initiatives get increased investment, even amidst brutal government cuts.

Despite recent widespread concern over the reach of their powers, especially Internet monitoring, Britain's security services scored a financial victory Wednesday concerning the next few years of government spending: Britain's intelligence services left Chancellor George Osborne's 2013 Spending Review with a 3.4% boost in funding.

To put that in context, most British institutions saw reduced budgets, ranging from 10% for local government to 6% for Whitehall's business department. Even law enforcement had its funding crunched, with the Home Office's budget cut by 6%.

[ Information Commissioner's Office gives Google 35 days to purge personal data collected via Street View. Read Britain Orders Google To Delete Street View Data. ]

The extra money is intended for the security and intelligence agencies to achieve "key national security priorities, maintain core counter terrorist capabilities, and protect U.K. citizens and interests against terrorism threats."

Part of the funding will come in the form of extended support for cybersecurity, said to be a "the new frontier of defense -- and a priority for this government." Specifically, £210 million ($323 million) in the cross-government National Cyber Security Program (NCSP) will be invested in a broad range of projects across government to deliver the U.K.'s cyber security objectives, details of which have been promised later in the year.

Projects will be set up to protect U.K. interests in cyber space, making it harder for hostile states and criminals to target the country, and to raise business and public awareness of online threats, with a focus on how they can protect themselves and invest in the skills and standards needed to support a vibrant and internationally competitive U.K. cybersecurity sector.

The £210 million adds to the previously committed £650 million ($1 billion) funding for the NCSP. According to government sources, this money is generating significant benefit to the U.K. by increasing the capability to tackle cyber threats, turning cybersecurity into an economic opportunity and establishing the U.K. as a leader in this field.

Osborne has also called for an ongoing efficiencies package to enable Britain's intelligence and counter-intelligence agencies to operate more effectively and to encourage further collaboration between GCHQ, MI5 and MI6 as part of this process.

For the Chancellor, Britain's spies' work remains critical. He stated in his speech to Parliament Wednesday, "Silently, and often heroically, these fellow citizens protect us and our way of life."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4231
Published: 2015-07-03
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

CVE-2015-4232
Published: 2015-07-03
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

CVE-2015-4234
Published: 2015-07-03
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

CVE-2015-4237
Published: 2015-07-03
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv0...

CVE-2015-4239
Published: 2015-07-03
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report