Lindy Cameron speaking to the IIEA

It’s an honour to be here today. As a Derry girl, I’d absolutely love to be with you in person in Dublin, but it’s a real pleasure to be speaking here in Ireland (even if only virtually).
And in fact I am actually joining you today from my home, because this week I was told to self-isolate by the UK NHS Test and Trace app – a different type of virus to the one we in the NCSC usually deal with, but thankfully one I’m fully vaccinated against, so hopefully this is just a precaution.
So firstly, I’d like to thank the Institute of International and European Affairs (IIEA) and the work they do – and a congratulations for you celebrating your 30th anniversary this year.
I’m very proud to be here as the second head of the National Cyber Security Centre - and the second from Northern Ireland, after only five years, plays a key role in the UK's national security.
Its creation in 2016 showed real foresight and is widely recognised as an example others want to emulate – a partnership of government, law enforcement, intelligence and the private sector. And we have achieved a huge amount in those five years.
We have dealt with over 2,000 significant incidents.
We have protected the UK at scale through Active Cyber Defence – taking down more than 700,000 online scams in the last year alone, 80,000 of which were new tip offs from the British public through the hugely successful Suspicious Email Reporting Service.
We have raised resilience in all sectors of our critical national infrastructure, and built coalitions with businesses, charities and education to develop accessible and actionable cyber security tools and advice.
Over 55,000 teenagers have participated in the CyberFirst Girls competition and our cyber security courses.
And we have made the internet safer and easier to use for our citizens through our Cyber Aware campaign, challenging password culture and victim blaming.
Ireland - an important ally
Cyber security is, of course, a team sport, and the UK and Ireland share an important partnership that will help us both to stay as secure as possible online.
It is a relationship built on shared goals. This close alliance helps to prevent many attacks from ever happening – and when they are successful, it also improves our shared response to an incident.
We are committed to sharing threat assessments and operational lessons from incidents – and that shared understanding benefits our countries and our citizens.
And there is much to praise from the successes in Ireland. We take inspiration from the work done to transform the country into a digital hub – with Dublin’s fantastic ‘Silicon Docks’ serving as its central nerve centre.
Thanks to support from the Irish government, the tech startup ecosystem in Ireland is booming. This is a passion we share, and through the NCSC for Startups initiative we are providing support for start-ups.
This has included TrustElevate – a company led by an Irish CEO looking to make the internet a safer place for children, and Angoka – a Northern Ireland-based firm specialising in securing smart city technology.
You’ve supported the tech industry here in Ireland through the coronavirus pandemic, through Irish government grants and loans for large and small businesses.
Global tech companies such as Twitter, Facebook and Google have offices in Dublin, and I know Ireland is currently ranked just outside the top 10 of Forbes’ ‘Best Countries for Business’
And of course Ireland also has one of the highest concentration of cloud data centres in Europe – including the Amazon Web Services data centre in Dublin. This allows companies to deliver results faster and more reliably by having access to hundreds of thousands of servers in minutes.
Shared interests
There are multiple examples of shared cyber interests between Ireland and the UK. Indeed Ireland was one of the very few countries specifically referenced in the UK Government’s recent Integrated Review of Security, Defence, Development and Foreign Policy. This committed to a strong bilateral partnership and to further deepen our relationship through increasing connectivity, clean growth and international co-operation. More on that later.
Our links with Ireland’s NCSC specifically are growing and we very much welcome the recently established CNI Cyber Cooperation Working Group - whose inaugural meeting in March was hosted by NCSC-IE. In this, we’re sharing our understanding of the threat, incident management support processes, as well as methodologies for identifying CNI dependencies including critical cross-border dependencies.
Given those cross-border dependencies in many CNI sectors, there is a particular cross-over in threats facing Northern Ireland and Ireland.
For example, Energy security for Northern Ireland is based on gas pipelines and electrical interconnectors to both Great Britain and across the border, including the Single Electricity Market. The Energy sector is dependent on operational technology – connected systems that monitor and control automated industrial processes – to function effectively and efficiently.
It is a realistic possibility that this reliance on operational technology and the interconnected nature of the energy supply network on the island of Ireland combines to create a potential target for cyber attacks.
On transport, Northern Ireland’s rail link across the border, between Belfast and Dublin, is jointly operated by Northern Ireland Railways and Irish Rail. These cross-border transport links increases the potential for cyber attacks, including ransomware.
Shared threat
We all know cyber security does not respect borders, which is why a great cyber security relationship between the UK and Ireland is so important to combat our shared threats. And there are several established, capable states that seek to do both of our nations harm through cyber attacks.
In the Telecoms sector, state actors almost certainly pose the greatest cyber threat. The Telecoms sector is an attractive target both as an enabler of espionage on other sectors, and as a target for customer and communications data.
Some Managed Service Providers that operate in Northern Ireland provide services both sides of the border. It is therefore a realistic possibility that a cyber attack on a telecoms provider could impact services to both of our countries. The governments of both UK and Ireland have been clear that they will not tolerate malicious cyber activity, and we have and will publicly call out state-level attacks.
State sponsored cyber activity represents one of the most malicious strategic threats to the national interests of both the UK and Ireland. It is hugely important. Tracking and defending the UK from our most sophisticated adversaries represents much of our core business, usually working to support victims behind the scenes.
State threats are a reality in cyberspace. Four nation states – China, Russia, North Korea and Iran, have been a constant presence in recent years. As I’ve said before, we face a determined, aggressive Russia, seeking traditional political advantage by new, high-tech means.
We live in a business and corporate environment where Chinese cyber attacks on our commercial interests are something our companies treat as business as usual.
And authoritarian regimes including North Korea and Iran use digital technology to sabotage and steal.
However, there is currently no threat more prescient than ransomware –malicious software that can make data or systems unusable until the victim makes a payment. And, of course, you in Ireland know this all too well.
Irish health service attack
As you are well aware, on May 14, the Irish Health Executive (HSE) suffered a ransomware attack that caused extensive disruption to Irish hospitals and patients - and some stolen patient data was published online. The government was quite rightly clear that – even by criminal standards – this had crossed a line.
I would like to praise the Irish response not to pay the ransom. Cyber criminals are out to make money – the more times a method is successful, the more times it will be used.
And payment of ransoms is no guarantee that you will get your data back – and certainly no guarantee you won’t be attacked again - in fact, advertising a willingness to pay make someone a more interesting prospect.
So it’s important that we do all we can to ensure this is not a criminal model that yields returns. The government’s strong action of refusing to pay will likely deter ransomware operators from further attacks on health sector organisations – in Ireland or elsewhere.
Understandably, the initial reaction was concern over possible impact on COVID response – a fear calmed through clear and definitive reassurances that vaccines would not be affected.
Coverage then shifted to how other services were compromised, such as cancer appointments and surgeries. Sadly, there were real world examples of patients and families facing real-world consequences to this despicable attack.
The attack also had an impact on Northern Ireland. It affected Northern Ireland’s ability to access data held by HSE for some cross-border patient services. Thankfully the Northern Ireland Business Services Organisation, which provides IT to the NI Health sector, was able to stand up its business continuity processes to support.
The NCSC's role
In the UK, the NCSC led the response to a similar incident in 2017 when the WannaCry ransomware attack impacted 48 of the UK’s National Health Service Trusts.
As you would expect from a close partner, we did all we could to support our partners in Ireland when the HSE attack took place.
This included sharing as much relevant information as we could – both from a cyber crime and a law enforcement perspective.
So what can we say about this incident at this stage? The activity almost certainly originated from cyber criminals. The activity has almost certainly caused disruption to hospitals and endangered patient care.
And we know that the cyber criminals likely voluntarily handed over the encryption key several days after the attack. We see this as a public relations move to lessen criticism.
Ransomware
Ransomware almost certainly continues to represent the most likely disruptive threat to the health sector worldwide.
Although cyber criminals promised not to target the health sector during the COVID-19 pandemic, ransomware attacks have proliferated and are increasingly causing disruption to clinical services and patient care.
The victims of the ransomware attack in Ireland were ordinary citizens such as cancer patients whose radiotherapy appointments were postponed. A ransomware attack against New Zealand also impacted clinical services in several New Zealand hospitals.
Ransomware is the most insidious cyber security risk – not the threat from, but threat to; and not the loss of data but the impact on operations, large and small, that stops people and business from being able to live their day to day lives.
The sheer volume makes it the most impactful threat we face. We have seen it affect the NHS in the UK with WannaCry, we've also seen it prevent students accessing classes in the last few weeks. We've seen it shut down local authorities at great cost to the public purse, meaning the public cannot access services, pay their bills or, in some cases, even buy a house.
And the ransomware ecosystem is evolving through what we call Ransomware as a Service, (RaaS) and the ‘As a Service’ business model where ransomware variants and commodity listings, such as lists of credentials, are available off the shelf for a one-off payment or a share of the profits.
Users buy from developers without the costs and risks of developing it themselves, and that enables actors less experienced in ransomware to acquire tools to conduct their own attacks.
High end crime groups spend time conducting in depth reconnaissance on their targeted victims. They will identify your cyber security weaknesses that they can exploit. They will use spoofing and spearphishing to masquerade as internal employees to get access to all of the networks they need.
They will look for the business-critical files to encrypt and hold hostage. They may identify embarrassing or business sensitive material that they can threaten to leak or sell to others. And they may even research your cyber insurance policy to see if you are covered to pay ransoms.
This process can be painstaking and lengthy, but it means that, when they are ready to deploy, the effect of ransomware on an unprepared business is brutal. Everything is taken out. Files are encrypted. Servers go down. Digital phonelines no longer function. Everything comes to a halt and your business stops in its tracks.
But it doesn’t stop there. Over the last year or so these cyber-crime groups have evolved their techniques to include data extortion. Even if you have offline backups and can get back on your feet without paying a ransom, the group will threaten to leak the data they have stolen.
This can make all your business information, personal sensitive data, otherwise embarrassing content, available online for all to see. So, this is now the double whammy of ransomware; even if you have good data storage in place they can still try and hold you to ransom.
In some respects, the response to ransomware is straightforward: we need to continue to build cyber resilience so that attacks cannot reach their targets in the first place. The NCSC has great advice on how to do this with our 10 Steps to Cyber Security and we’ve made huge strides across a range of sectors.
I know the NCSC-IE does the same to help improve understanding of the cyber threat, in particular through publishing alerts and advisories that may affect Ireland.
But in many other respects it also requires a whole of government response. This starts with the efforts to prevent the activities of the groups behind these damaging attacks. These criminals don’t exist in a vacuum. They are often enabled and facilitated by states acting with impunity. International and diplomatic efforts need to be coordinated to stop them.
A coordinated response on ransomware, involving these key players, would have the added benefit of helping us meet broader national and strategic international objectives, making us a more resilient and prosperous place to live and do business online.
And we are at an inflection point in global technology, so it is imperative that we recognise this and act accordingly. Jeremy Fleming, Director of the UK’s signals intelligence organisation GCHQ, recently described a ‘moment of reckoning’, where unless the right action is taken key technologies we all rely on will no longer be shaped or controlled by likeminded democracies.
Proliferation could create unforeseen risks. There are firms that sell high end state-like capabilities that exploit computer networks – but then at the other end of the spectrum, you can buy relatively cheap SIMBoxes that can send thousands of cyber crime texts in an hour. Such threats pose a risk to people all over the world.
Shared interest - UK & EU
So alliances are vital and we, like others, must work with partners on a global stage. This includes collaboration between all four nations of the UK sharing information with global partners, starting with our closest neighbours here in Ireland.
Our Integrated Review underlined the importance of the UK as a responsible global Cyber Power, that works with its allies to actively shape the international order of the future'
It also demonstrated what is responsible behaviour for a cyber power to demonstrate. This is not a model to benefit just UK citizens – but to benefit people all over the world, and show there is a reasonable expectation no-one is left behind.
We see our international cyber engagement as vital to delivering:
A cyberspace that is free, open, peaceful, and secure, and where the multistakeholder model is reinforced;
A global market in which new technologies are secure and resilient from the outset;
A global operating environment in which our adversaries are unable to act adversely and without impunity or cost being imposed against them;
Strengthened international partnerships and coalitions that act in concert against mutual threats.
The UK cannot do this alone – with our allies and close partners across the world, we will take collective action against the threat, and work to a shared vision for the future.
So we warmly welcome Ireland’s presence on the UN Security Council and look forward to working together on our shared foreign security priorities.
Ireland will assume the Security Council Presidency in September and we have every confidence you will lead with a commitment to peacekeeping and climate security, in line with both the Taoiseach and our own Prime Minister’s priorities.
Because states have an important role in agreeing what behaviour is acceptable. By working as a global community, we can clarify and develop rules that are right for the digital age.
The UN Government Group of Experts on cyber space has built on the clear global appetite for progress captured in the consensus report by the Open Ended Working Group earlier this year. The document offers substantive text on attribution as well as landmark references to international humanitarian law – both extremely important firsts.
The ambitions set out in the Integrated Review guided the UK’s position during these negotiations and set out our position on how international law applies to state behaviour in cyberspace. We look forward to continuing to work globally on these important governance issues, including on the implementation of rules and norms.
An important part of how we make the UK a safer place to live and work online is through our international reach and support. The global nature of the cyber threat means that our international partnerships are critical to countering and deterring malicious cyber actors who want to cause harm to the UK.
But our international engagement goes beyond responding to the threat; the UK’s international engagement is also about responding to competing visions of cyberspace, asserting democratic norms and values in the technologies and standards that affect the UK’s cyber security, and addressing the vulnerabilities of global supply chains.
We have strong bilateral relationships with a number of other European partners and continued full membership of a number of multilateral groupings that are vital to information-sharing and incident response
The European Government CERTs (Computer Emergency Response Teams) remains the forum in which cooperation on cyber incidents is most mature. And ETSI (European Telecommunications Standards Institute), is of course the recognised regional standards body for telecommunications and other networks and services.
As the UK sought to leave the EU, both the UK and EU recognised that, as a shared threat, continued cooperation on cyber security issues would always be in both sides best interests.
This understanding was recognised in the Trade and Cooperation Agreement signed at the end of 2020.
This agreement included provisions:
- to create a formal dialogue in order to exchange information about relevant policy developments, including in relation to international security, security of emerging technologies, internet governance, cyber security, cyber defence and cyber crime.
- to cooperate with CERT-EU on cyber incidents, something we have always done and are continuing to do (including on the recent SOLAR WINDS incident before Christmas).
- to allow participation in specific activities of the NIS Cooperation Group, an important policy development group in which the UK has played a significant role, including on the cyber security of elections, and 5G.
- and to build a third party relationship with ENISA (European Union Agency for Cybersecurity), the EU’s Cyber Security Agency, and again, an organisation with which the UK has enjoyed a long and close relationship.
- work on implementing the Trade and Cooperation Agreement is ongoing and, we hope, will mean that the UK and EU can continue to cooperate in the spirit that both sides desire.
Future look
Finally – a look to the future. Cyber security is a rapidly moving world and while we can’t confirm what the threats of the future will be, we can move to put us in the best place possible to defend from them.
And we are doing a lot of work on creating a culture where cyber security can thrive and Northern Ireland is a great example of this - it is where the NCSC’s flagship conference CYBERUK will be held in 2023.
Like Dublin, Belfast is a leading technical hub with a thriving eco system – including being home to Queen’s University, which is recognised by us in the NCSC as one of the UK’s Academic Centres of Excellence in both Cyber Security Research and Education.
Queen’s also hosts the Research Institute in Secure Hardware and Embedded Systems, providing a global focus and working with leading international partners and manufacturers to accelerate research and innovation and translate that into new, more secure and resilient products and services.
Of course, innovation stretches beyond Belfast – and particularly to the border areas, including in the North West region where there are ambitious plans for growth.
In February, the UK Government announced a £250 million investment that will boost the economic potential of the North West and support a more prosperous and united community.
This included the creation of the new Centre for Industrial Digitisation, Robotics and Automation, which will support the exploration of technologies and innovation.
And the Cognitive Analytics Research Laboratory, which will bring together AI expertise and data analytics to help future innovation thrive.
Coupled with the UK Government’s support, there is a real opportunity for Northern Ireland to achieve its full economic potential through these means.
The Northern Ireland Cyber Security Cluster – which NCSC supports – employs more than 1,700 professionals and promotes international business, innovation and collaboration.
And the Northern Ireland Government fully supports the UK National Cyber Security Strategy and has developed its own cyber security strategy under the three pillars of Defend, Deter and Develop.
A key part of their strategy is the establishment of the Northern Ireland Cyber Security Centre, launched February 2020. The Centre is now one of the NCSC’s key partners in Northern Ireland, and a key amplification route for NCSC messaging, promoting and raising awareness of the threat and NCSC’s products and services across all NI sectors.
Another big part of the challenge to creating a safer cyber future is empowering the next generation of experts.
We run a wide range of CyberFirst courses aimed at children and young people of all ages to spark and develop their knowledge, but with the significant gender discrepancy in the cyber security workforce, we particularly focus on girls
So I was really proud to see pupils from Our Lady and St Patrick’s College in Belfast in the top 10 teams nationally, in a competition of 6500 to find the most cyber savvy young girls in the UK.
We have five CyberFirst Schools or Colleges in Northern Ireland – meaning they are recognised as sharing our aim of encouraging young people to engage with computer science and the application of cyber security in everyday technology.
Because of the commitment to the interests and threats we share with partners, we in the UK need to create a new national cyber strategy that protects our allies.
An attack on our Critical Infrastructure could impact on Ireland, and we are committed to making it as hard a target as possible for those who would seek to disrupt it.
We need to ensure that data generated and processed by the internet services we use every day are properly protected, and our privacy appropriately managed. The creative technology that we envisioned in the Integrated Review must be protected from theft by state threats .
And we need to ensure that the next generation of commodity technologies don’t repeat the security mistakes of the past. We need to ensure that our adversaries - be they state or criminal, traditional or new - think twice before attacking the UK or its allies.
Conclusion
So in conclusion, there is a clear correlation between the cyber security of the UK and Ireland - and it is one that presents us opportunities to be collectively stronger by working together.
While our shared infrastructure, goals and threats are a source of great strength they are also potential vulnerabilities that means we have a responsibility to one another.
If either of us has a weakness that is exploited, the impact can and likely will be felt by the other nation. Which is why it’s so positive that we share such a strong relationship and share an alliance that makes us stronger than the sum of our parts.
We look forward to continuing to work and learn from our inspirational partners here in Ireland, and to help move both of our nations on to a future where we can continue to make the most of the fantastic opportunities offered to us in the digital age.


