What do you think when you walk into one of the UK’s flagship cyber conferences and see the author, Dimitri Alperovitch, signing his just released best seller World on the Brink? The brink of what I hear you ask! The book lays out that the West is on the brink of war and that we are already in a Cold War, with the USA and China facing off in a number of explosive areas. However, Alperovitch lays out a strategy that, he argues, will deter war and allow the USA to maintain its leading superpower status.
Cyber UK is the UK’s NCSC annual flagship cyber conference that seeks to demonstrate to the world the strength and capacity that the UK holds in cyberspace. This year it felt that the repeated message was that the West needs to steel itself for an upcoming war. Many of the speakers, who represented the cyber leaders of the West, described what Ronald Reagan would have called the Axis of Evil ~ China, Russia, North Korea and Iran ~ using every means possible within their cyber and disinformation arsenals to destabilise the West. NCSC CEO, Felicity Oswald OBE, went as far as to say that there are clear warnings of Chinese intent to put our essential networks at risk. However, this wasn’t a simple doom-fest!
GCHQ’s Director, Anne Keast-Butler, also acknowledged the increasing risk from China but took us to the next level of understanding in what we had to do to respond to this threat. In essence, effective geopolitical cyber security in the modern era equals Resilience + Partnerships + Speed. The key component of this equation is trust.
Trust lies at the heart of any relationship. Trust is usually built, over time, by sharing information and secrets that allows individuals and groups to better understand and trust each other. The Five Eyes community is a good example. Trust is also built through actions; words can only ever carry any relationship so far and, ultimately, people make their decisions on what they see you do or don’t do! So, what does trust look like in this Digital Age? It could be argued that trust in the digital age comes down to zero trust!
Zero trust is an approach to cybersecurity where users, devices and data sources are not automatically trusted even if they already exist within a given network. Instead, strict identity verification, device compliance checks and least privileges are enforced to enhance security. In tandem, the UK Government has devised a Secure by Design approach as the de facto for ensuring that systems are foundationally secure and can iteratively demonstrate that security through auditable evidence.
If the mission is clear then what is the issue? Another theme, repeated by many speakers, was the internet is broken! The issue, therefore, seems to be an apparent failing to address this fundamental flaw! Surely when something is broken there are two fundamental options when faced with and impending crisis like a war ~ fix it or replace it; but neither option was mentioned in any detail. This worries me because we look back at history with a certain disregard and this is dangerous. Building stuff takes time and effort, and resources! Let’s not forget that the UK moved to a war footing years before Chamberlain’s doomed efforts of Peace in our Time; even before Nazi Germany shifted its industrial base to a total war footing and still the early days of World War II brought Britain to the brink ~ to use Dimitri Alperovitch’s term!
I could have cheered during the closing keynote when the new director of the UK’s National Cyber Force, AVM Tim Neal-Hopes, echoed my concerns that we appear to lack the [collective] personal agency to solve these challenges. Paraphrasing his comments, he underlined that we describe AI, tech debt and the internet being broken as things that happen to us; we need to change this victim mindset and adopt a strategic aiming point based on coalitions, campaigning and getting ready for the inevitable. His advice brings us back to the mantra of Resilience + Partnerships + Speed + Trust.
So why am I reflecting on Cyber UK 2024 in such a passionate manner? Much of Keast-Butler’s levée en masse, to coin a French Revolutionary War battle cry, already exists across the myriad of SME firms who have persistently and tirelessly worked with agencies such as DSTL to develop technologies, architectures and solutions that can form the bedrock of the UK and the West’s response to an increasingly belligerent axis of evil. However, as we move towards election season, this effort and energy is not being matched by the UK Govt which must follow its processes and “hit pause” until post the election ~ in the modern world is that really an option? Building trust and relationships takes time and resources.
Within Nexor, we have led some of the major initiatives to support these near-future demands. One example is the Single Information Environment: a secure and resilient architecture that allows information to move between different classifications at speed to provide decision makers with information advantage. Another is our Zero Trust Development Environment (ZeTruDE) that addresses the growing challenge of data and code provenance in a complex world where code and data origins can be murky at best! In Nexor, these innovations were born out of 20+ years of SME ideation and passion that has led to a suite of products and services wrapped together under Nexor’s Secure Information Exchange Architecture (SIXA).
These are the sort of components of resilience and speed that will facilitate partnerships and decision advantage through security-hardened high-fidelity intelligence but they are not battle-ready ~ SMEs cannot hold all the risk of taking MVPs to FOC! As we roll into election season in the UK, can we really afford to allow UK investment in solutions designed to facilitate coalition information exchange at speed with the necessary levels of cybersecurity and resilience simply pause until the new Government decides how it needs to proceed? To go back to AVM Tim’s challenge ~ we can’t simply look at the world through the All Too Difficult lens. The solutions are there but we all need to pull our weight to make sure that our processes do not lead us to an existential myopic state. Investment in digital innovation must continue and it must be led by the UK’s cybersecurity SME community which is amongst the best in the world.