NCSC Annual Review 2021
Pages
Page 42 of 44
International Engagement for Real-World Impact
Over the past year the NCSC used its international partnerships to share the UK’s understanding of current threats, exchanged intelligence, responded to cyber incidents, and developed its technical capabilities.
There was collaboration with international and industry partners to inform them of compromised credentials from a VPN vulnerability, which enabled them to inform victims and prevent and detect ransomware attacks
As chair of an operational working group with the Five Eyes partners, the NCSC oversaw the first joint paper on common vulnerabilities published in July. It took a leading role in the first 6-badged product between Five Eyes agencies (ACSC, CCCS, CERT.NZ, NCSC.NZ, NCSC-UK, CISA) on approaches to uncovering and remediating malicious activity.
A top priority of the NCSC’s international agenda is to work with its partners to enhance their cyber resilience, by assisting in building their defence capabilities, and sharing best practice.
In April the NCSC, together with the UK Civil Aviation Authority (CAA), worked with the World Economic Forum (WEF) to shape international cyber resilience standards in the aviation sector. The NCSC’s work shaped the eventual WEF report and provided another platform for the UK to advocate for its regulatory approach, specifically encouraging the use of the Cyber Assessment Framework as a regulatory tool to provide a common language and baseline of practice.
In May, the NCSC’s guidance on cyber security principles for connected places was widely welcomed, prompting its international counterparts to consider their own frameworks and how they could apply the same principles.
The NCSC and DCMS are actively working with international partners to learn as well as share best practice as we tackle the security risks which affect connected places.
The NCSC’s mission of sharing its values with global partners to build a safe cyberspace was in evidence when CEO Lindy Cameron signed a Memorandum of Understanding with the Chief Executive of the Singapore Cyber Security Agency, David Koh, in November 2020. The agreement allowed the agency to use the NCSC’s Exercise in a Box model to develop its own version. International travel restrictions meant the memorandum was signed by both CEOs via webcam.
Exercise in a Box is a key product in the NCSC’s Active Cyber Defence toolbox. It allows organisations to practise their response to cyber security incidents in a safe and private environment, by providing realistic exercises and giving relevant guidance to ensure cyber resilience.
Case Study: Vaccines International Engagement
The Covid-19 pandemic created new areas of vulnerability, in creating a new requirement to protect and secure vaccine and health sector supply chains. The NCSC engaged international partners on securing the overseas supply chains for vaccines critical to UK supply, and to enhance partners’ resilience against the cyber threat to vaccines.
The NCSC liaised with manufacturers and other associated companies within overseas supply chains, assessing their cyber security, and offering protective advice. This included leveraging a network of international partners to work with 13 countries, as well as directly engaging companies and organisations (including the World Health Organisation, and GAVI, the Vaccine Alliance). It also shared threat information where possible, to raise awareness of the risks to supply chains, and worked closely with the UK’s Vaccines Task Force.
This new area of collaboration provided immediate security benefits to the UK’s vaccine and health sector supply chains and yielded longer-term benefits for bolstering the UK’s international security.