CBN Newsletter – August 2024

Our monthly update to bring you the relevant, high-level policy and business news from across the cyber sector. 

This month, we provide an update on the new Labour government’s priorities, and highlight what the CrowdStrike incident could mean for cyber businesses.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch. 

never miss a thing

Sign Up to Hear about News and events

Headline news

New government sets out priorities
The Labour Party swept into power on 5th July, winning a near-historic 411* seats, while the Conservative share collapsed for its worst-ever result. Over the past weeks, Keir Starmer’s government has wasted no time in setting a new tone for the country; however, while the cyber sector has largely welcomed the new government’s focus on cyber security national resilience, its impact is largely yet to be felt as Parliament breaks for recess, returning 2nd September. 

King’s Speech: legislative priorities 
In July, King Charles addressed the nation during the State Opening of Parliament, to set out the Government’s policy priorities and legislative programme for the coming year. In line with previous promises, Prime Minister Keir Starmer placed a primary focus on driving economic growth.

With 40 new(ish) bills, it is an ambitious programme which promises to “take the brakes off” the economy and reaffirm financial stability. Measures include boosting construction, reforming energy production, re-nationalising the railways, developing UK skills, and increasing and improving the use of data and digital technologies in the economy.

Chancellor’s financial statement
On 29th July, Chancellor Rachel Reeves declared a £22bn “hole” in the country’s finances. Although disputed by former Chancellor Jeremy Hunt, Reeves has been backed up by the Office for Budget Responsibility (OBR), which has formally launched a review of the Spring Budget forecasts. 

Reeves then announced a number of areas where the government intends to save money – including selling off “surplus” government property, a reduction in the use of external consultants in Whitehall and a pause on certain infrastructure projects. Tax rises are now expected in the October 30th Budget, alongside the outcome of a formal spending review for 2025-2026. 

A cyber lens
Notably, a Cyber Security and Resilience (CS&R) Bill will be introduced to ensure the security of critical infrastructure and digital services, building on Security of Network & Information Systems Regulations (NIS Regulations) 2018. DSIT Minister Feryal Clark also recently said that the CS&R Bill will be designed to strengthen the UK’s defences and ensure the services – private and public – that companies rely on are protected.

Further, Science, Innovation and Technology Secretary Peter Kyle said that national resilience – particularly in relation to cyber security – “suffered terribly” under the Conservatives due to division within the party. He claimed that he only became aware of the significance of the threat upon taking office, but concern led him to “put forward a request” for the new CS&R Bill, which had “national security priority”. 

Separately, the Government has launched a “root and branch” Strategic Defence Review which, led by three external experts, will consider the threats Britain faces, the capabilities (including digital and cyber) needed to meet them, the state of UK armed forces and the resources available. The Review is expected to be delivered “at pace”, with submissions invited until the end of September and the report delivered in the first half of 2025.

*Now 404 following the temporary suspension of seven MPs

If you have any questions about what the election and policy developments means for the cyber sector or your business, please get in contact with us at secretariat@cb-network.org.  

How resilient is our global IT infrastructure? 

On Friday, 19th July, 8.5 million Microsoft Windows computers around the world crashed, causing chaos and disruption for businesses and services including airlines, banks and hospitals.

While cyber security firm Crowdstrike quickly confirmed the outage was caused by a defective software update for its Windows hosts and worked to resolve the issue, the incident nonetheless called attention to the precariousness of IT infrastructure – and what could happen if an attack was carried out by malicious actors, as was then seen last week with the Microsoft Azure DDoS attack and subsequent software failure.

Businesses across the world are now asking themselves two questions – firstly, their place within the global supply chain and the strength of their incident management and response plans, as highlighted by the NCSC. And secondly – how can they prevent future incidents from affecting them?

Although some companies may look to bring their IT security functions in-house, this is not an option for all organisations, who may start seeking to diversify their software and other security application suppliers.

In light of the government’s upcoming CS&R Bill, the sector will be watching closely for strategic direction from officials on how they will look to improve resilience and “insulate” society and the economy from future attacks.

At the same time, the cyber sector as a whole has the responsibility and opportunity to not only highlight the importance of having a robust cyber resilience programme, but also to ask questions about the concentration of risk – given 62% of the global external attack surface is covered by 15 companies – and the long-term viability of this landscape. 

In light of this, keep an eye out for an upcoming CBN webinar which will bring together policymakers and key supply chain sector leaders to provide insights for members on what this means for the sector, and how we can make improvements going forward. 

If you have questions about how you can better communicate your services to customers or wish to speak to government about future solutions, please get in touch with the CBN team at secretariat@cb-network.org

News & Updates

Policy and political

Government extends call for views on the Cyber Security of AI
Originally published in May, before the General Election, the closing date for the government’s call for views on the Cyber Security of AI has been extended to this Friday, 9th August. 

The call for views sets out specific interventions to help secure AI, so that the benefits of AI can be realised, and asks for input as to whether industry would support the gov creating a global standard for AI cyber security. To note, a “call for views” is often an initial information-gathering exercise which will go on to determine formal proposals and policy.

If you have any questions about responding to this or other a government consultations, please get in touch with the CBN team. 

G7 countries to establish operational tech cybersecurity framework
In a statement following a summit in Italy, the Group of Seven (G7) countries acknowledged the rising cyber threat to critical infrastructure, particularly energy, and agreed to “explore avenues towards establishing mutual recognition of schemes for reliable cyber-safe products.” 

The potential collective framework would apply to both manufacturers and operators, as the statement signals an intention to incentivise tech companies to build more secure Internet of Things (IoT) products. This move was in conjunction with the United States’ recent Supply Chain Cybersecurity Principles, as indicated by a statement from the White House national security advisor. 

UK statement at the UN Security Council
UK Permanent Representative to the UN, Ambassador Barbara Woodward, gave a statement at the UN Security Council regarding the importance of addressing cyber threats to protecting global security. She highlighted four “trends” – the prevalence of ransomware, expansion of artificial intelligence, malicious activities on the global stage, and the risk of disinformation – going on to indicate the UK’s work in this area.

NCSC updates

Business and industry

ICO officially “reprimands” Electoral Commission
The Electoral Commission, which oversees UK elections, has been formally reprimanded by the Information Commissioner’s Office (ICO) over the security lapse which left millions of UK voters’ personal details “vulnerable to hackers”.

Following the 2021 breach, hackers had access to the Electoral Register for just over a year, until they were detected and “booted out” in 2022. The ICO’s investigation found the Electoral Commission did not have appropriate security measures – including secure passwords and up-to-date patches – in place to protect the personal information it held, which led to the breach.

UK faces significant cyber funding and skills gap
A new report, Underfunded and Under Reported: Threats, Breaches, and Budgets, reveals the CISOs face significant problems from a lack of funding, exacerbated by a lack of talent, tools, and time. Notably, 83% of respondents feel their organisation has a gap in its cyber skills, yet they struggle to access adequate talent. 

NCA leads international operation to crack down on unlicensed pen testing 
The National Crime Agency (NCA) worked with international partners to coordinate global action against unlicensed versions of Cobalt Strike.

CyberThreat 2024
The NCSC and SANS Institute announced that CyberThreat 2024, an event designed for security practitioners with a strong technical emphasis, will take place on 9th-10th December. 

Discover new opportunities by becoming a member of CBN today!

Our membership is free to cybersecurity organisations and offers them opportunities to promote capabilities, share insights and develop lasting relationships