Link: The Communications Act 2003 and the Digital Economy Act 2017 (Consequential Amendments to Secondary Legislation) Regulations 2017
Source: Legislation .gov.uk
Press release: Government celebrates cyber security successes in Manchester
The First Secretary of State, Damian Green, spoke at the landmark opening of the new global headquarters of the NCC Group in Manchester, marking the first anniversary of the creation of the National Cyber Security Strategy (NCSS).
The NCSS was launched a year ago in response to the growing cyber security challenges and threats faced by the UK and to define the Government’s ambitions for the future.
As a part of this world-leading strategy the government invested £1.9 billion in establishing the innovative National Cyber Security Centre (NCSC), demonstrating a long-term commitment to keeping the UK safe. Since its launch the NCSC has responded to over 590 significant cyber incidents: providing support to victims, sharing information with intelligence and law enforcement, and setting up incident management structures to ensure essential services are up and running once incidents have occurred.
The First Secretary spoke at the headquarters of the NCC Group – a global expert in cyber security and risk mitigation. The newly built headquarters in Manchester equipped with state of the art technology will employ more than 500 cyber security experts providing Britain’s and Europe’s largest companies with cyber security consultancy and cyber incident response.
Damian Green, First Secretary of State and Minister for the Cabinet Office said:
This Government is committed to tackling the growing threat of cyber security and will continue to invest in the future of our defence programme.
The Government’s Cyber Schools programme aims to provide skills to nearly 6,000 young people in order to secure the UK’s position as a world leader in cyber security for generations to come.
I am delighted that a global cyber security expert has chosen to open their headquarters in Manchester – fuelling the success of the Northern Powerhouse.
Brian Tenner, Interim CEO at NCC Group said:
NCC Group continues to play a pivotal role in advising government and helping to implement national initiatives which are strengthening the UK’s cyber security posture and helping to improve the country’s technical capabilities in this area. The First Secretary’s visit is recognition of this continuing support and we were delighted to welcome him to our company headquarters today.
The threat of cyber crime is an ever-evolving issue that is increasing in severity every day. It is encouraging that the UK Government is treating this as a priority and putting concrete strategies in place to address this. We will continue to offer our assistance and work closely with the UK Government on these new initiatives in order to improve the UK’s ability to defend against modern cyber threats.
Link: Press release: Government celebrates cyber security successes in Manchester
Source: Gov Press Releases
ISO/IEC 27007:2017 Information technology. Security techniques. Guidelines for information security management systems auditing
ISO/IEC 27034-5:2017 Information technology. Security techniques. Application security Protocols and application security controls data structure
HTTP/2
Executive summary
HTTP/2 is a faster and more technically advanced version of the current HTTP 1.1 and is being widely adopted following its approval in February 2015. It is already supported by major browsers – Chrome, Firefox, IE11, Edge, Safari, and Opera – and is thought to be used by about one in ten websites.
Four vulnerabilities rated as severe have been discovered in this new version, but fixes have already been made available through a coordinated approach between the…
Link: HTTP/2
Source: NCSC Alerts
Weekly Threat Report 1st September 2017
300% increase in attacks on Microsoft cloud services
Microsoft has revealed that the frequency of attacks against users of its cloud services, including Microsoft Azure and Office 365, has increased by 300% over the last year.
“A large majority of these compromises are the result of weak, guessable passwords and poor password management, followed by targeted phishing attacks and breaches of third-party services,” said Microsoft in its ‘Security and Intelligence’…
Link: Weekly Threat Report 1st September 2017
Source: NCSC Reports
Weekly Threat Report 12th May 2017
International cyber incident affecting the NHS
On Friday a set of global cyber attacks took place against thousands of organisations, including the NHS, and individuals in dozens of countries.
The NCSC statement on the incident can be read here and guidance on how to defend your organisation against ransomware can be found here.
US restaurant chain payment process system compromised
A US restaurant chain, Chipotle Mexican Grill, recently announced that unauthorised activity…
Link: Weekly Threat Report 12th May 2017
Source: NCSC Reports
Weekly Threat Report 20th January 2017
Password security
In November 2016, a study of user passwords exposed by a Yahoo data breach revealed that “123456” was the most common password, followed closely by “password” at number two. A more recent report on the most commonly used passwords revealed that “123456” was still number one, followed by the ‘more complex’ “123456789”.
These reports highlight ongoing problems associated with conventional password policies, which tend to promote the use of complicated passwords that are…
Link: Weekly Threat Report 20th January 2017
Source: NCSC Reports
CERT-UK Annual Report 2015/16
Our second Annual Report covering the period April 2015 – March 2016 is now live.
The report covers an overview of the incidents we have dealt with this year with a breakdown by type and sector, as well as analysis of malware in the UK, a look at our predictions from last year and a new set for the coming year and a piece on the importance of automated sharing.
CiSP members can also access the Amber Annexe posted on the platform which contains more technical information including…
Link: CERT-UK Annual Report 2015/16
Source: NCSC Reports
Weekly Threat Report 2nd March 2018
Ransomware infects Colorado Department of Transportation IT system
International media reports suggest that ransomware infected computers at the Colorado Department of Transportation (CDOT) on 21 February, encrypting files and requesting payment in Bitcoin to restore them. CDOT is responsible for managing and maintaining roads as well as monitoring traffic in the US state of Colorado, but no critical operational IT systems are believed to have been affected.
The organisation has taken 2,000…
Link: Weekly Threat Report 2nd March 2018
Source: NCSC Reports
