Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Sunday, 7 July 2013

Businesses, UK government team against cyber attacks

Lockheed Martin, BT, and BAE Systems are among a group of defense and security companies that have pledged to support the U.K. government in bolstering the security of the country against sophisticated cyber attacks.

By pooling their experience of operating under constant threat of attack, the so-called Defense Cyber Protection Partnership (DCPP) says the alliance will identify and implement actions that have a real impact on the cyber defenses of the members of the partnership and the U.K. defense sector as a whole.

The DCPP model is intended to lead the way in industry collaboration and action on cyber security and to act as a template which can then be followed by commercial sectors to improve resilience across U.K. industry.

"I'm absolutely delighted by the level of commitment shown by the participating companies in helping us to build our national resilience against cyber attack, and I look forward to more of our key contractors coming on board," said Minister for Defense Equipment, Support and Technology Philip Dunne.

"This is a clear demonstration that government and industry can work together—sharing information, experience and expertise—to make sure we do everything we can to protect these critical networks, ensuring that the business of Defence is robustly protected."

A total of nine companies will work alongside the Centre for the Protection of National Infrastructure (CPNI), Government Communications Headquarters (GCHQ) and the Ministry Of Defence (MOD) to offer their expertise. These include BAE Systems, BT, Cassidian, CGI, Hewlett Packard, Lockheed Martin, Rolls-Royce, Selex ES, and Thales UK.

Throughout the rest of 2013, the partnership will focus on three specific areas: increasing awareness of cyber risks across the supply chain; defining risk-driven approaches to applying cyber security standards; and sharing threat intelligence.

Organisations within the DCPP will also share threat intelligence and wider expertise on tackling cyber threats with other industry sectors and government through the recently announced national Cyber Security Information Sharing Partnership.

"This is an issue which demands a concerted and coordinated approach between Government and Industry and the DCPP is a critical component of this," said Vic Leverett, DCPP chair. "Collaboration between industries and with Government has been first class, reflecting the joint commitment to succeed with our 2013 objectives. The whole is proving to be significantly better than the sum of the parts."

The U.S. Department of Defense has warned of coordinated cyber attacks that could harm industry as well as governmental operations.

Follow me on Twitter @sajilpl

EU Parliament OKs stricter penalties for cyber attacks

Cyber criminals could face tougher penalties across the European Union under new rules adopted by the European Parliament, which include the creation of a specific offense of using botnets.

The draft directive adopted by the parliament on Thursday defines specific criminal offenses for cybercrime and sets specific sanctions for each. It also requires E.U. countries to assist fellow member states and respond to urgent requests for help within eight hours in the event of a cyber attack.

The text has already been informally agreed with member states, and that agreement is expected to be formalized shortly. The member states will the have two years to implement it in national law.

Under the draft law, using botnets to establishing remote control over a significant number of computers by infecting them with malicious software carries a penalty of at least three years' imprisonment.

Meanwhile criminals responsible for cyber attacks against "critical infrastructure," such as power plants, transport networks and government network would face at least five years in jail. The same would apply if an attack is committed by a criminal organization or if it causes serious damage.

"Attacks against information systems pose a growing challenge to businesses, governments and citizens alike. Such attacks can cause serious damage and undermine users' confidence in the safety and reliability of the Internet," said Home Affairs Commissioner, Cecilia Malmström, welcoming the news.

Companies or organizations would also be liable for offenses committed for their benefit, for example hiring a hacker to get access to a competitor's database.

The directive, which updates rules that have been in place since 2005, also requires member states to allow judges the possibility to sentence criminals to two years in jail for the crimes of illegally accessing or interfering with information systems, illegally interfering with data, illegally intercepting communications, or intentionally producing and selling tools used to commit these offences.

Minor cases are excluded, but it is up to each country to determine what constitutes a "minor" case.

However technology blogger Glynn Moody expressed concern about possible mission-creep. "I predict laws will be abused by E.U. governments to attack coders and geeks," he said on Twitter.

The directive will apply across all E.U. member states with the exception of Denmark, which decided to opt out.

Thursday, 27 June 2013

No sign of cyber leaker Snowden on flight to Cuba

MOSCOW - A Russian passenger plane left Moscow for Havana on Thursday without any sign of former U.S. spy agency contractor Edward Snowden on board, witnesses said.

Cuba is considered a possible destination for Snowden on his way to Ecuador, where he is seeking asylum.

The 30-year-old American is wanted in the United States on espionage charges and is thought to have remained in the transit area of Moscow's Sheremetyevo airport since flying in from Hong Kong on Sunday.

Russia carrier Aeroflot confirmed the plane's departure but declined comment on the passenger list. Airline sources had said earlier on Thursday that Snowden had not registered foe the flight.

Follow me on Twitter @sajilpl