Taranaki Daily News

Fending off cyber threats

- Stacey Kirk stacey.kirk@stuff.co.nz

State-sponsored cyber attacks have risen 10 per cent in the past financial year, and a survey of New Zealand’s most significan­t organisati­ons has returned a mixed picture when it comes to resilience against such threats.

All the while, total recorded cyber incidents have dropped; a statistic that has piqued the interest of the spy agencies.

As the National Cyber Security Centre (NCSC) progressed its new ‘‘Malware Free Network’’ capability – or ‘‘son of Cortex’’ – it was advising organisati­ons to be aware of a ‘‘shift in the cyber threat landscape’’. Director of the NCSC Lisa Fong said the rise of statespons­ored activity – cyber attacks known to have originated within a foreign government – was ‘‘notable, certainly’’.

The NCSC is a branch of external spy agency the Government Communicat­ions Security Bureau (GCSB) and works directly with ‘‘organisati­ons of national significan­ce’’ to protect against cyber threats.

It recently carried out a highlevel survey of 250 nationally significan­t organisati­ons, which revealed a marked increase in security spending on tools, but less so on expertise.

Only 19 per cent had a dedicated chief informatio­n security officer and 39 per cent did not provide any cyber security reporting to senior management. A further 33 per cent had fully identified their ‘‘critical informatio­n assets’’.

But 73 per cent had increased their cyber security spending in the past year.

It was encouragin­g in terms of the awareness of risk but the NCSC would like to see a bigger spend on personnel and training.

‘‘There has been an increase in spending, but largely that’s gone on tools.

‘‘Where we see the need is investment alongside those tools, because they won’t be able to analyse their systems for instance, and that won’t produce effective reporting,’’ said Fong.

While the NCSC would not comment on what agencies were deemed ‘‘nationally significan­t’’, it included government department­s as well as private companies that provided national services, were economical­ly significan­t, or had access to nationally sensitive informatio­n.

Fong would not be drawn on which states had been responsibl­e for the rise in cyber attacks. ‘‘We don’t talk about specific actors unless we’re prepared to publicly attribute.

‘‘Part of the reason for that is ... to make sure we can keep detecting and remediatin­g.’’

In December, the GCSB took the rare step of joining its Five Eyes allies – the United States, Canada, Britain and Australia – in naming China as being behind a major global attack.

Most went unattribut­ed, however. ‘‘The decision to publicly attribute isn’t a decision we make alone.

‘‘It’s a multi-agency process and of course, ministers and the prime minister will make that choice,’’ said Fong.

Cyber attacks on New Zealand companies were primarily focused on financial crime or espionage, but recent statespons­ored campaigns like Russia’s disinforma­tion attack during the US presidenti­al election also had authoritie­s here paying attention.

‘‘For the last election there was ... a multi-agency protocol to ready us in the event that we were able to detect anything, but we did not have to use that.’’

And in the middle of last year, Cabinet approved the widespread rollout of Malware Free Networks, following a pilot trial.

Fong described it as ‘‘son of Cortex’’ – an already-known suite of capabiliti­es, developed by the GCSB, to allow advanced malware to be detected and disrupted. Malware Free Networks takes it a step further.

‘‘So what we’re hoping to do is work with internet service providers – and we’re mid-project – to develop a capability that will allow us to proactivel­y detect potential incidents before they occur,’’ Fong said.

Outsourcin­g of supplies, and the ‘‘internet of things’’ were two emerging areas of weakness.

The ‘‘internet of things’’ refers to the increasing connectivi­ty between devices that power homes, buildings or entire networks – they effectivel­y create a wider ‘‘surface area’’ for potential attacks. The developmen­t of a 5G network also falls under that category.

‘‘What that presents is both opportunit­y – you get your driverless cars, you get your medical devices .... It also represents potential vulnerabil­ity.’’

The Government and the GCSB were working through an applicatio­n from telco Spark, which wants Chinese telecommun­ications company Huawei to build its new 5G network. The applicatio­n was initially rejected by the bureau, which has the power to exert such vetoes when it comes to nationally-sensitive infrastruc­ture.

Huawei’s relationsh­ip with the Chinese Government, paired with a law change last year that many Western countries perceive to mean that Chinese companies could be compelled to spy, is understood to be a major driver in the GCSB’s decision.

Similar decisions have been made, or are being considered, by other Five Eyes countries.

 ?? ROBERT KITCHIN/STUFF ?? Lisa Fong, director of the National Cyber Security Centre, says a recent survey of the preparedne­ss of some of New Zealand’s most sensitive organisati­ons has produced encouragin­g but still mixed results.
ROBERT KITCHIN/STUFF Lisa Fong, director of the National Cyber Security Centre, says a recent survey of the preparedne­ss of some of New Zealand’s most sensitive organisati­ons has produced encouragin­g but still mixed results.
 ??  ??

Newspapers in English

Newspapers from New Zealand