NCSC Annual Review 2023
Pages
Page 10 of 16
Case study: Securing the UK's critical national infrastructure

CNI is evolving
Critical national infrastructure (CNI) consists of the most important systems in the UK today. This includes those that provide safe drinking water, electricity and keep the country connected to the internet. They keep the UK’s economy functioning and ensure the government can operate as effectively as possible.
CNI was historically focused on physical assets, such as buildings, housing, energy and infrastructure. They tend to change infrequently, as moving infrastructure to an entirely new industrial estate didn’t happen often. However, the pace of change sped up as the UK became more dependent on digital infrastructure . The systems underpinning communications, financial networks, and the internet change more rapidly and are often highly distributed. Our understanding of CNI has also evolved, moving towards a more holistic view of critical systems rather than purely physical assets. These systems often operate independently of UK-based infrastructure. These changes have delivered immense opportunities for the UK while simultaneously reshaping the risks associated with our CNI and our approach to managing them.
The threat has changed...
Due to the changing geopolitical environment, including the ongoing war in Ukraine, the rise of state-aligned groups from around the globe, and an increase in aggressive cyber activity, it is highly likely the cyber threat to UK CNI has heightened in the last year.
The NCSC still assesses that ransomware remains one of the greatest cyber threats to UK CNI sectors. This has been evidenced by international incidents, including attacks against Colonial Pipeline and the Irish Health Executive, and within the UK, against South Staffordshire Water, Royal Mail International and even one impacting NHS 111. Some of these attacks have also highlighted the possibility of disrupting CNI through attacks on key suppliers, who may have weaker security and thus present an attractive opportunity for adversaries.
While criminality online is the most significant threat in terms of volume, the most advanced threats to CNI come from nation states, including Russia, China, Iran, and DPRK.
In May, the NCSC issued a joint advisory revealing details of ‘Snake’, a sophisticated espionage malware used by Russian cyber actors against their targets. These targets included CNI operators, and the targets were in more than 50 countries across the world.
There is sometimes a misconception that state activity is all about espionage. Or that it is only targeted at trying to steal government secrets. But that’s not the case.
Another joint advisory issued by the NCSC earlier this year exposed China state-sponsored activity targeting networks across CNI sectors in the US and it carried a warning that the same malicious techniques could be applied worldwide.
It detailed how the actors had been observed taking advantage of built-in network administration tools on targets’ systems to evade detection after an initial compromise.
This kind of latent threat activity cannot be discounted and it demonstrates the interest that state-sponsored actors have not only in compromising CNI networks but persisting there too.
Jen Easterly, Director CISA, noted that such targeting “…wasn’t for espionage or data theft… it was more likely for disruption and destruction” and CNI operators should be alert to this and follow the actions in the advisory to hunt down this activity and mitigate .
Nation states and profit-oriented cyber criminals are not the whole picture, however. The NCSC published an alert to operators of the UK’s CNI in April about the emergence of state-aligned groups as an adversary, some of whom have stated a desire to achieve a more disruptive and destructive impact against western CNI. Without external assistance, we consider it unlikely that these groups have the capability to deliberately cause a destructive, rather than disruptive, impact in the short term. But they may become more effective over time.
While we don’t believe, right now, that anyone has both the intent and capability to significantly disrupt infrastructure within the UK , we know that we can’t rely on that situation persisting indefinitely. Uplifting cyber resilience can take several years to achieve, so it’s therefore important to prioritise that uplift before the threat further materialises against our CNI or its key dependencies.
The threat is evolving. While we are making progress building resilience in our most critical sectors, we aren’t where we need to be. We will continue to work with partners across government, industry and regulators to accelerate this work and keep pace with the changing threat, including tracking their resilience in line with targets set out by the Deputy Prime Minister.
Situational awareness
To counter the risk posed by these threats, we believe that it’s essential to understand the risks to our CNI before our adversaries do, so that we can reduce the window where an attack could be successful. Often critical services will rely on complex supply chains to function and so mapping supplier dependencies and relationships plays a crucial part in gaining confidence in your security. This enhanced situational awareness will be increasingly important in times of heightened threat – but being mindful about supply chain security from procurement through to deployment should be a perennial consideration for operators.
In addition to our work understanding the UK’s CNI, we need to continue improving our aperture on CNI risk. For example, it will be key to understand flaws in the design of the UK’s CNI (such as inadequate network segregation) which adversaries may seek to exploit, as well as maintaining awareness of unmanaged vulnerabilities and the attack surface visible to adversaries online. It may also be necessary to expand threat hunting for nation states who could seek to pre-position on UK CNI.
Prioritising cyber security
The UK’s CNI is operated by public and private sector organisations. However, while they are subject to the ever-increasing threats described above, they also face a range of other commercial pressures and therefore tackling cyber threats is not always prioritised as highly by CNI operators as we would like.
Operators of the UK’s CNI may be positioned to deliver shareholder value and profit, incentives that can take priority over investment in the secure operation of critical systems. Firms with less mature security can also be incentivised to constrain information sharing during incidents, limiting the NCSC’s ability to effectively support and respond.
The public sector, whilst not motivated by profit, prioritises the delivery of these critical services, but unfortunately, this can also come at the expense of security considerations.
The NCSC has been working with government, industry, and regulators to address this imbalance. The government has set targets for CNI operators to achieve resilience against common attack methods as quickly as possible and to put in place more advanced protections where appropriate. Effective regulation plays a key role so the government is also strengthening the regulatory framework, to improve its coverage, powers, and agility to adapt, within the context of broader national security risk and rapidly changing threat and technology.
The NCSC, as national technical adviser for cyber security, is central to this work, in particular by helping government, regulators and industry to measure and validate the necessary improvements in CNI cyber security and resilience, including through the development of the Cyber Assessment Framework (CAF) which has been widely adopted.
However, in addition to raising the security baseline, it’s important for organisations to understand how they will address periods of heightened threat, as we are seeing now. Those organisations need to have worked through how they will temporarily increase their cyber security and resilience measures, at all levels of the organisation, to minimise the likelihood of a successful attack and to have proactively worked to reduce the impact, should an attack occur.
What should we do next?
The NCSC has worked to address these challenges by supporting the creation of a revised criticalities process to identify and assess critical systems across the UK. In addition, we have helped create the Knowledge Base , a world-leading tool which permits the government to understand the relationships between and impact of any disruption to critical systems, regardless of the hazard involved.
To better understand the resilience of these systems, the NCSC created the CAF as a framework to assess cyber resilience and worked with regulatory authorities to set thresholds for security and resilience based on preventing, detecting, and recovering from historic and plausible future attacks. The CAF, in combination with the thought leadership available on our website, has helped to pull together the NCSC’s expertise, enabling organisations to have a much greater understanding of their cyber resilience, and take action to improve it .
However, we need to keep progressing these efforts. We need to continue to work together as a community to address the gaps in the UK’s cyber security posture. This starts with gathering better data to improve our visibility and better inform our decision making. We need to understand where organisations commonly struggle to address security challenges and how adversaries are attempting to exploit those weaknesses, so that we can work as a community to address such gaps. The NCSC, in collaboration with industry, wider government and regulatory bodies, is thus analysing data on the cyber resilience of UK CNI, to better understand how we can help ensure the resilience of our CNI.
We also need to continue to forge international partnerships to ensure that we can learn from and work together with governments, industries, and relevant forums overseas on this shared challenge. It’s clear that we all depend on similar infrastructure and face similar threats, and so creating a common toolkit for managing them is key. We’ve therefore continued to run closed information exchanges with key CNI operators and participate in international forums to better drive-up standards.
Working to limit the impact of cyber attacks against the UK’s CNI, especially those conducted by nation states , is challenging but achievable. It’s something that we need to do together.