Defending democracy
Page 5 of 6
Guidance for political organisations

What is this guidance and who is it for?
This guidance outlines the threat to UK political organisations and sets out the measures to put in place to prevent successful attacks.
It is for staff managing the IT networks, systems and data of UK political organisations.
A political organisation is any organisation engaged in political activities aimed at achieving clearly defined political goals that benefit the interests of their members. This includes political parties, non-governmental organisations, think tanks and advocacy groups.
Individuals in politics should refer to the guidance for high-risk individuals in this collection. We recommend that political organisations also promote this guidance to staff.
What is the threat to political organisations?
Over recent years, there have been reports from several countries of cyber attacks, using a variety of techniques, targeting political organisations. These attacks are part of wider activity to influence the political process, or to undermine public confidence in democracy more widely.
Such attacks include the 2018 compromise of the Institute for Statecraft, a UK think tank whose work includes initiatives against disinformation, by Star Blizzard, a group subordinate to Russia’s Federal Security Service, the FSB. Russia’s Foreign Intelligence Service, the SVR, has also targeted the infrastructure of political organisations.
The NCSC is also aware of denial of service (DoS) attacks on UK political party websites in the run up to the 2019 General Election.
Protect your organisation
The NCSC provides a wide range of cyber security advice and guidance for organisations. This guidance summarises and signposts the most relevant guidance for countering threats to political organisations.
In common with other organisations, political organisations are increasingly using cloud-based infrastructure, such as email and collaboration tooling. Actors are adapting to this and are known to have targeted the cloud services of political organisations for intelligence gain.
The NCSC has guidance on cloud security which explains how to carry out a rapid and reliable assessment of cloud services and additional guidance on using software-as-a-service securely. You should also ask your cloud service provider for a response to the NCSC cloud principles, and even consider making it a contractual obligation.
Nation-state adversaries are known to use stolen or machine-guessed passwords to gain unauthorised access to emails or other online services. Setting up multi-factor authentication (MFA) on accounts means that even if an attacker knows your password, they won’t be able to gain access. All users, especially administrators who hold higher privileges, should have MFA set up on their email, and other internet and cloud services. This is particularly important when authenticating to services that hold sensitive or private data.
The NCSC has detailed guidance for organisations on how to implement MFA for online services.
Attackers targeting political organisations also use spear-phishing, particularly emails, to deliver targeted messages to individuals of interest to encourage them to share sensitive information. The potential for attackers to use generative artificial intelligence to create even more convincing spear-phishing content heightens this threat.
There are steps organisations can take to reduce successful spear-phishing attacks. Defences against phishing should be multi-layered and shouldn’t rely on users spotting a malicious email. The NCSC has guidance for organisations on protecting against phishing attacks.
Another established practice of nation-state actors is to launch destructive and disruptive attacks against websites of interest, usually in the form of denial of service (DoS) attacks and website defacements.
You should make sure that your website is resilient to the threat of DoS attacks and be prepared to adjust controls. The NCSC has full guidance on preventing DoS attacks and urgent steps to take if you think you are experiencing a DoS attack.
Without the right controls in place, an attacker could use your domain to send emails pretending to be your organisation, also known as spoofing. This could be used to make spear-phishing emails look more convincing. You can use the NCSC’s Check your Cyber Security service to see if your organisation is vulnerable.
Free services from the NCSC
The NCSC offers different services that can help your organisation understand the threats and vulnerabilities that might affect your digital assets and steps to take to improve their cyber security where it’s necessary:
-
Detecting and responding to a potential incident early is an excellent way to avoid threats escalating. You can register your digital assets with the NCSC Early Warning service. This is a free threat notification service available to all UK organisations which automatically notifies you of potential threats to your network.
-
Attackers will often look for ‘easy wins’ to gain unauthorised access to a network, such as common software vulnerabilities that are easy to exploit. Sometimes you may not know where your system is vulnerable. Check your Cyber Security helps you carry out simple online checks to identify common vulnerabilities in your public-facing IT, to detect and respond to these weaknesses before an attacker takes advantage. All checks are remote and there is no need to install any software, or to register.
Incident response
Whatever the size of your organisation, having in place a plan which sets out how to handle incidents will help you make good decisions under the pressure of a real incident. The NCSC has guidance to help you develop your incident response plans, as well as the Exercise in a Box toolkit which can help you rehearse, evaluate and improve your cyber incident response plans in a safe environment. The NCSC also assures a network of commercial incident exercising providers.
If you do experience a cyber attack, you should consider engaging a cyber incident response (CIR) company. Be aware of the NCSC CIR assurance scheme which provides a list of assured commercial incident response organisations if an attack happens.
If you believe your organisation has been victim of a cyber attack, you should report it to the NCSC.