Proceeding contribution from Mark Pritchard (Conservative) in the House of Commons on Wednesday, 23 November 2005. It occurred during Adjournment debate on Cyber Security.
Cyber Security
I am grateful for the opportunity to bring an important issue before the House. There are four types of cyber threat—worms, viruses, trojans and spyware, which can also appear in combination. Worms are self-replicating programs designed to spread through networks and cease operations. Viruses are usually files that attach themselves to other programs and spread themselves into other programs or computers with which they come into contact. A trojan is usually a program that disguises itself as helpful, but then proceeds to replicate itself throughout the computer network, allowing external control as well as user debilitation. Spyware is a type of trojan usually attached to another program which when downloaded is used to record activity on a computer, and is then accessed by the originator. Today I will consider the national security and economic implications of the advent of new and more aggressive breeds of virus and cyber security threats to Government and the private sector. It is noteworthy that the United States Department of Homeland Security records that the number of cyber attacks increased from 10,000 in 1999 to more than 400,000 in 2004. We are all aware of major incidents that have taken place in recent years. In May 2000, the ““I love you”” virus, a macro virus that overwrites key computer files, caused some $10 billion-worth of damage across the globe. In September 2001, the ““Nimda”” virus—a worm and virus—which spread throughout north America in just one hour, attacked more than 8 million computers and took weeks to eliminate. It was spread by e-mail attachments and copied itself to mailing lists and networks. In November 2004, the ““Agobot”” virus, a dormant virus that replicated itself throughout computer networks, hit the world. It is still dormant in many computers across the globe. Nine million computers have been affected, and that figure is rising as people discover the virus on their systems. In March 2004, ““Mydoom””, the appropriately named combination of a trojan and a virus, spread to more than 1 million computers in just 56 hours, thereafter infecting another 4 million computers. The US State Department has suggested that there has been a 300 per cent. increase in trojans in the past year alone. More worryingly, those viruses have been introduced not by amateurs—although they have been involved in some cases—but by professional hackers. The rise of the professional hacker has serious implications for the UK, particularly in relation to national defence. I would be very concerned indeed if my constituents, or anybody in Britain, felt that our intelligence and defence systems and networks were being penetrated by viruses. There is also the danger that potential enemies of this country might spy on vulnerable and security-restricted areas of the internet. We know that that does occur; it has been confirmed by Governments around the world, including that of France, and, again, the US Department of Homeland Security. We hear little from the British Government, and I hope that the Minister will be able to throw some light on what Britain is doing about protecting our national security systems from such viruses and cyber security threats. I recall that in July 2001 a worm targeted a weakness in the White House network. That had serious implications for the running of the White House. All users who attempted to access that server were attacked. More than 250,000 computers were affected in three hours. It was code red. Key national infrastructures, such as energy, transport, finance, telecoms and aviation, rely constantly on an exchange of information, primarily through computer networks. A penetration of any of those networks would be a serious threat to national security, not least when it comes to the potential to access Britain's 14 nuclear power stations. I hope that if the Government decide on new nuclear power stations as part of the current energy review—clearly, there is a bit of confusion, but the Prime Minister has hinted about going new nuclear—the software and the systems involved in running new nuclear power stations will be fully protected from cyber security threats. It is interesting that the imprisoned al-Qaeda members have admitted that their organisation has been attempting to—and no doubt is still attempting to—develop cyber threats to strike western Governments. There are other issues, such as Government databases—especially those proposed for the national identity card scheme, which would contain biometric data. They have been identified by InfosecurityToday online magazine as potent targets for hacking, possibly allowing massive levels of identity fraud. That brings me to the issue of identity fraud. It is reported that more than 200,000 cases of identity fraud on the internet were recorded in 2004–05, at a cost of nearly £60 million to the UK economy alone. That is in spite of the launch by Companies House of Monitor, which seeks to secure company details—never mind the details of individuals. There is an added cost in the form of people who would shop online and access services and products—either wholesale or retail—in that way, but who are put off by the risk of being exposed to fraud. Online credit card fraud has also increased by about 29 per cent. over the past year alone, at a cost to UK businesses of at least £16 million and a cost of £260 million worldwide. That is a small proportion of the total and ever-increasing fraud on the world wide web. I have mentioned America and the French and now I should like to mention the Japanese, being a member of the all-party group on Japan. I am supporting not just Japan's rugby bid, but its anti-corporate-espionage activities. It is leading the way in preventing corporate espionage, including the theft of patents, scientific research data, business strategies and client information. In fact, the Japanese Home Office has estimated that there has been a 200 per cent. increase in corporate espionage over the past year. That could have limitless implications for British businesses and entrepreneurs. So, what can be done? The US has a unified agency called the National Cyber Security Division to assess and respond to cyber-threats. The computer emergency readiness team is a sub-agency of the division and its role is to inform the private sector of any threats and to co-ordinate private sector action and responses. The US Government have also taken several other measures to reduce the rise in cyber threats, such as a regular exchange of information between the state and the private sector to alert one another to such threats. Known threats are analysed and strategies to deal with them are developed. Software is updated and protected against the latest threats. The private sector is encouraged to develop contingency plans should the internet and computer systems, networks and servers fail. However, it is incentivised for doing so. The rise in aggressive viruses and cyber security threats is a clear and present danger to Britain's national security. It is also a threat to Britain's economic well-being. More than 90 per cent. of cyber threats have a major impact not only on the originating country but across the globe. Britain is the international hub for banking, finance houses and many other businesses, so if we get it wrong it will have implications for many other countries as well as ourselves; yet we have no international treaty or convention to deal with cyber crime. We have only a series of bilateral engagements and extradition laws. The Americans, however, extradited someone from the UK, perhaps because their laws are more robust than ours. That leads me to my questions for the Minister. Would Her Majesty's Government consider strengthening domestic laws to ensure that penalties are severe enough to act as a deterrent for all those caught and convicted of cyber crime? Would the Government work with the international community and the World Trade Organisation towards creating a standard or uniform legal approach at a global level on such issues? Would the Government consider doing what the United States has done, and establish a cyber security week or cyber security day? That would provide a platform to promote awareness and understanding of cyber security issues, and the potential damage to Britain's economy and national security. It would help if the Government were to deal separately with the impact on the private and public sectors. Would the Government consider forming a unified national cyber security agency, which would take a lead on their behalf and be a single point of cyber security information, guidance and advice for the nation? What are the Government doing to ensure a robust and co-ordinated response to cyber threats in the UK and among our allies? Viruses can often get through weaker systems. If we, with improved cyber security measures, share intelligence information with nations that do not have similarly robust firewalls—what I might call added-value firewalls—our systems will still be vulnerable. We need to be aware of that. Will the Government please consider those matters urgently? I have spoken this afternoon about defensive measures. I hope that we shall have time in the House to speak about offensive measures—about how to avoid wars and confrontation by disabling our enemies' systems before they can push the button on missiles that might strike our shores. The House should have the opportunity to debate offensive cyber-security issues. I hope that the Minister agrees with his noble Friend Lord Harris of Haringey, who said only a few months ago that the Government should consider appointing a cyber security tsar. I have expressed personal views, but there is cross-party support for them. I hope that the Minister will look upon my proposals and questions favourably.
Secondary information
- Type
- Proceeding contribution
- Reference
- 439 c474-7WH
- Session
- 2005-06
- Chamber / Committee
- Westminster Hall
- Subjects
- Hacking Cybersecurity
- Link
- View this Proceeding contribution on www.publications.parliament.uk
Librarians' tools
- Timestamp
- 2023-12-05 23:29:21 +0000
- URI
- http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_278961
- In Indexing
- http://indexing.parliament.uk/Content/Edit/1?uri=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_278961
- In Solr
- https://search.parliament.uk/claw/solr/?id=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_278961