Ransomware is key cyber threat facing UK – cybersecurity boss

14 June 2021, 17:54

Computer virus
Ransomware locks up the computers of businesses and users (Peter Byrne/PA Wire). Picture: PA

In a keynote speech, National Cyber Security Centre boss Lindy Cameron warned that businesses must be better prepared.

Ransomware attacks are the key cyber threat facing the UK and the public and businesses must take it seriously, the head of the UK’s cybersecurity agency has warned.

Lindy Cameron, the head of the National Cyber Security Centre (NCSC), which is part of GCHQ, stressed the importance of the UK continuing to build its cyber resilience to stop attacks from reaching their targets.

Giving the annual security lecture to the Royal United Services Institute (RUSI) defence and security think tank on Monday, Ms Cameron spoke about the “cumulative effect” of the UK failing to manage ongoing cybercrime and, in particular, the increasing trend of ransomware attacks.

Ransomware is a form of cyber attack which locks files and data on a user’s computer and demands payment in order for them to be released back to the owner and has been used as part of a number of high-profile cyber attacks in recent years, including the 2017 attack on the NHS.

Ms Cameron warned that cybercriminals are becoming increasingly sophisticated in their use of ransomware, and the UK must continue to improve its response.

“Ransomware has historically been the preserve of high-end cybercrime groups with access to advanced technical skills and capabilities based in overseas jurisdictions who turn a blind eye, or otherwise fail to act, or fail to pursue these groups,” she said.

“But the ecosystem is evolving through what we call Ransomware as a Service, (RaaS); and the as a service business model, where ransomware variants and commodity listings such as listed credentials, are available off the shelf for a one-off payment or a share of the profits.

“We know there are campaigns to recruit new affiliates and as a result users can buy from developers without the costs and risks of developing it themselves.

“And that enables less experienced actors to acquire tools to conduct their own ransomware attacks.

“As the business model has become more and more successful, with these groups securing significant ransom payments from large profitable businesses who cannot afford to lose their data to encryption or to suffer the down time while their services are offline, the market for ransomware has become increasingly professional.”

The NCSC boss added that “a whole of Government response” is required in order to meet the threat.

“It starts with the efforts to prevent the activities of the groups behind these damaging attacks,” she said.

“These criminals don’t exist in a vacuum. They are often enabled and facilitated by states acting with impunity. International and diplomatic efforts need to be co-ordinated to stop them.

“And that includes seeking the strongest criminal justice outcomes for those we apprehend. There are other players with a key role such as the cyber insurance industry which has a role to play in bearing down on the payment of ransoms and cryptocurrencies entities who facilitate suspicious transactions.”

In her lecture, the cybersecurity boss also warned that think tanks in the UK are likely to become key targets for nation-state espionage groups as they seek to gain “strategic insights into Government policy, trade agreements and commercially sensitive information”.

By Press Association

More Technology News

See more More Technology News

Microsoft surface tablets

Microsoft outage still causing ‘lingering issues’ with email

The Google logon on the screen of a smartphone

Google faces £7 billion legal claim over search engine advertising

Hands on a laptop

Estimated 7m UK adults own cryptoassets, says FCA

A teenager uses his mobile phone to access social media,

Social media users ‘won’t be forced to share personal details after child ban’

Google Antitrust Remedies

US regulators seek to break up Google and force Chrome sale

Jim Chalmers gestures

Australian government rejects Musk’s claim it plans to control internet access

Graphs showing outages across Microsoft

Microsoft outage hits Teams and Outlook users

A person holds an iphone showing the app for Google chrome search engine

Apple and Google ‘should face investigation over mobile browser duopoly’

UK unveils AI cyber defence lab to combat Russian threats, as minister pledges unwavering support for Ukraine

British spies to ramp up fight against Russian cyber threats with launch of cutting-edge AI research unit

Pat McFadden

UK spies to counter Russian cyber warfare threat with new AI security lab

Openreach van

Upgrade to Openreach ultrafast full fibre broadband ‘could deliver £66bn boost’

Laptop with a virus warning on the screen

Nato countries are in a ‘hidden cyber war’ with Russia, says Liz Kendall

Pat McFadden

Russia prepared to launch cyber attacks on UK, minister to warn

A Google icon on a smartphone

Firms can use AI to help offset Budget tax hikes, says Google UK boss

Icons of social media apps, including Facebook, Instagram, YouTube and WhatsApp, are displayed on a mobile phone screen

Growing social media app vows to shake up ‘toxic’ status quo

Will Guyatt questions who is responsible for the safety of children online

Are Zuckerberg and Musk responsible for looking after my kids online?