Skip to main content

Lindy Cameron speech at Tel Aviv Cyber Week

The CEO of the NCSC emphasises the ties between academia, industry and government in countering cyber threats.

Lindy Cameron, CEO NCSC at Tel Aviv Cyber Week

Good morning everyone. And it’s fantastic to be here again in Tel Aviv.

Thank you so much for inviting me. And thanks to those of you who are joining us online - thanks for tuning in. It's great to be back here for a 2nd year running despite the challenges of COVID.

I would like to start by congratulating Gaby Portnoy on his appointment as Director General of the Israel National Cyber Directorate earlier this year.

My own organisation - the UK’s National Cyber Security Centre - and the INCD share an awful lot in terms of mission and of outlook.

Our collaborations over the years have really delivered and I look forward to expanding the partnership in the years ahead.

Since I was here in Tel Aviv this time last year, the brutal Russian invasion of Ukraine has not only changed the geo-political landscape but transformed the context for our work on cyber security.

When the first Russian tank crossed into Ukrainian territory, the unthinkable suddenly became a terrifying reality.

Millions of innocent people have had their lives, homes and families taken from them.

And while Russia inflicted this physical oppression, they were also conducting a cyber campaign. This came as no surprise. Russia has consistently used cyber pressure to stress its rivals, distract them, and where possible disable them.

But – just as they have done on the battlefield – Ukrainian cyber defenders have done an incredible job of repelling many of these attacks. They are real heroes.

And I think resilience and preparation are at the heart of this success. I’ll come back to this point shortly.

But for all the pernicious activity that we have seen from Russia in the last few months in cyber space and beyond, we must not lose sight of the longer-term strategic challenges posed by the continued growth of China as a technological and economic power.

Because in cyber security this challenge is particularly acute because of the globalised nature of digital technology.

The Chinese government’s use of technology is about coercion and control. And the country’s technological and economic power mean they can export this vision very widely.

Once the world relies on technology delivered with an authoritarian bias, it will constrain our choices.

As allies…as equals…our more open systems can take time to reach agreement. And when we leave important choices unmade, we leave gaps in our defences which will be rapidly exploited.

So these challenges - from China, Russia and others - make it impossible for us to leave cyber security for another day.

So now is the time to innovate, educate and empower our citizens.

The democracies of the world have to challenge themselves to develop technologies and systems which allow us to avoid reliance on products not aligned with our values.

And I hope that the ‘start-up nation’ of Israel can play an important role in this innovation over the years to come.

But – even with a war raging in Ukraine – the biggest global cyber threat we still face is ransomware.

That tells you something of the scale of the problem.

Ransomware attacks strike hard and fast. They are evolving rapidly, they are all-pervasive, they're increasingly offered by gangs as a service, lowering the bar for entry into cyber crime.

And that's what makes them such a threat – not just the nationally significant incidents that my team and I deal with in the NCSC, but also the hundreds of incidents we see that affect the UK more widely every year.

These complex attacks have the potential to affect our societies and economies significantly, if it were not for the expertise of our incident management operators working in collaboration with their counterparts in industry and their international counterparts gathered here today.

So, we worked hard over the last year, to really understand, with our law enforcement partners, the criminal system behind ransomware. We want to drive down profits and drive up the risk to the criminals. We continue to work on understanding the scale, nature and evolution of their techniques.

We want to make ransomware an unprofitable and unattractive business.

Russia may dominate the headlines at the moment, but this threat of ransomware has not gone away – and nor have we stopped our relentless focus on it.

But it’s not all doom and gloom.

I’ve mentioned Ukraine, and closer to home, just look at the work undertaken by our hosts here in Israel - a shining example of what can be done when a nation takes cyber security seriously.

The technology developed here is truly world class. The talent in the cyber security sector is second to none. And your defences are some of the strongest in the world.

But making the most of our digital future is too big an issue for any one nation to handle alone.

Whether its drip feed irrigation or health and climate tech, Israel has always been proud to innovate for the benefit of people, well beyond your borders.

So, I hope you will continue to produce cyber security solutions which are safe, strong and affordable for the whole world.

Because an isolationist stance is just not going to work, long term. I think the war in Ukraine is a case in point there.

Technology and tactics developed there won't remain local problems. We've all watched that carefully.

An important part of our response to this as an international community is a clearer definition and enforcement of the rules that govern activity in cyberspace.

If we are to ensure that the digital world remains a place of opportunity, and to avoid it becoming a place of conflict and struggle, we must be clearer about the guidelines and norms that transcend international borders. We must explore innovative new technologies and share lessons learnt.

Last month, the UK's Attorney-General set out the UK views on how international law applies in cyberspace in peace time.

She focused on providing more detail on the rule on prohibited intervention. Her speech brings this to life by providing examples from key sectors of the sort of cyber behaviour that would be unlawful if conducted in peacetime.

She stressed that the United Kingdom’s aim is to ensure that future frontiers evolve in a way that reflects our democratic values and interests, as well as those of our allies.

We need clarity on the points of law if they are to be part of a framework for governing international relations and if they are to rein in irresponsible cyber behaviour.

Another very significant element is the international regulation of sophisticated cyber capabilities. Some of which have been pioneered here, in Israel.

If we’re going to maintain a cyberspace which is a safe and prosperous place for everyone, it is vital that such capabilities are produced and used in a way that is legal, responsible and proportionate.

I am delighted that Israel has tightened export controls around these tools, making it far more difficult for nations with concerning records on privacy and human rights to acquire such intrusive spyware.

It is really important that every actor, from the developer to the end-user of these types of technology and capability acts responsibly, with appropriate safeguards to protect against misuse.

There is a key role here for those of you in the private sector, for our respective cyber industries and technology companies in conducting due diligence and ensuring their products are not deployed in a manner that creates harm or undermines these principles.

One of the great benefits of coming to fantastic events like this at Tel Aviv Cyber Week is the opportunity to learn from others and exchange ideas.

In the UK, we take our ‘whole of society’ approach to cyber security really seriously. We want everyone ‘on the team’, pulling together to present a cohesive and resilient digital face to the world. Every citizen, business and utility, every school, charity and hospital. And I think that is something that we look to you for some real lessons on.

We want to help create a society that is resilient to cyber attacks, where cyber security is second nature to all of us.

Israel is already some way ahead in this process. Your cyber security ecosystem of businesses, education, and research is thoroughly inspirational. I am personally in awe of your cyber education programme – it is something that the UK’s CyberFirst scheme has learnt many lessons from.

And I appreciate that building this kind of depth of understanding, as Professor Ben-Israel said, takes time. But early investment really pays dividends.

The same is true of organisations around the world as they build resilience to cyber compromises.

Which is why my organisation has been encouraging organisations throughout the UK to follow the advice that we give as NCSC to improve their resilience – learning from the lessons we've seen in Ukraine of how to build that resilience in the face of the Russian onslaught.

And learning the lessons of Ukrainian cyber security in recent months has been something we've tried to help our companies in the UK to understand.

But to build this kind of resilience we need to create an environment where people are not too busy putting out the little fires to focus on the longer term.

Which is why the NCSC is really proud of our Active Cyber Defence programme, which helps to reduce the volume of low-level commodity attacks. And we’ve had some noteworthy successes.

Our ‘Takedown project’, for example, removed 3.1 million malicious URLs in 2021. Which we think saved the UK £223 million.

In the same period, our  ‘Protective DNS’ service handled more than 600 billion requests. 160 million of which were blocked from accessing known sources of malicious content.

And, one service that I am particularly proud of is our Suspicious Email Reporting Service, because we enlist the Great British public to help us. So far, the public have told us about 10.5 million suspicious emails, from which we’ve taken down 76,000 online scams. It's a great example of our “whole of society” approach in action and it helps our citizens feel as if they're helping us as a country, not just to protect themselves, but to protect the nation as a whole.

So, this ambitious approach to a whole of society approach to cyber. But I think to succeed, partnerships are essential. So, we are building stronger ties between academia, industry and government.

We’re reaching out to startups, with initiatives designed to spur the development of tools which will protect the UK’s smaller and medium sized businesses.

And we are engaging, as we are here, with our friends and allies.

We must come together around our shared values. Each nation bringing its own particular skills and strengths to build a network which is naturally resilient to attack, one which favours innovation, discourse and creativity over control and coercion.

They are big challenges, and they point to even larger actions. So, I look forward to discussing them with you here at Cyber Week, and in the months and years to come.

Thank you for your time.

Published

Date of speech

Location

Tel Aviv University