Skip to main content

Proceeding contribution from Lord West of Spithead (Labour) in the House of Lords on Thursday, 25 June 2009. It occurred during Ministerial statement on National Security Strategy.


National Security Strategy

My Lords, first, I thank the noble Baroness, Lady Anelay, for raising a number of points. It was good to see her at the start of the debate. I have noticed that a colleague of hers has appeared on every media channel in the past two hours, talking about this national security strategy, and I must say I am impressed by the speed with which she had managed to read it and absorb it all. I apologise for the fact that there was an error in a department with a D Notice that went out quite normally. We try to protect people who have been working in very sensitive areas, but I am afraid that department put in a D Notice rather earlier than it should have done, and that led to a couple of articles. I wrote a letter to the Speaker and to the honourable Crispin Blunt in the other place, explaining that. I apologised for that having happened. The department that did it realised the error of its ways—there are some people walking on stumps—but I will not go into any more detail on that. The way we have issued this, with my right honourable friend the Prime Minister producing this as a Written Ministerial Statement, with two documents, was absolutely right. I agree with both speakers so far—I absolutely hope that there will be a debate on these really important issues. However, I had hoped that we would have the debate after people had read the documents in detail, because they are highly complicated. We could then have a deep and meaningful debate. I am aware, because of happenstance and this unfortunate D Notice, that this has all happened in rather a gallop. I certainly want to have a proper debate later, and I thank the noble Baroness, Lady Anelay, very much for the noble way she has pushed this forward today. It is unfortunate that people are talking about this without actually really knowing very much about it, and I am a little disappointed about how that has been done. The noble Baroness talked about duplicating various things, but I think the document merits considerable attention. Far from duplicating things, we are actually co-ordinating and pulling together all the work that goes on. We have been aware of these threats now for some time. When I was Chief of Defence Intelligence, back in 1997, I was aware of various threats, but of course we were not so well joined-up and so close together. When I took over this job in 2007, it became very clear to me that we needed a co-ordinated strategy. A lot of very good work was being done in the CESG in Cheltenham, in other centres of excellence, and in many of the financial institutions, but the people who were getting at us were getting cleverer and cleverer at doing it. However, we were getting more and more interconnected. There is always an extraordinary balance in which all of these lovely things we have now—these amazing computer capabilities, hand-held sets, the ability to transfer data and to use satellites—are designed to be as open as possible to let us share data. That is great for business, globalisation and for lots of things, but it is of course a huge vulnerability when there are nasty people who want to get at it. Steadily, it has got more and more complex and people have got cleverer and cleverer at actually attacking us in those areas. Therefore, it became very clear when I took over in 2007 that we needed to co-ordinate all the very good work that was going on. The noble Baroness mentioned the amount of funding involved here, and of course we will look specifically at funding. My honourable friend in the other place gave a specific commitment to come back to Parliament to look at the funding available for training people and for another work stream, which I have forgotten at the moment. He will come back with evidence on those two areas. Lots of money is being spent, and I want to co-ordinate this better. It is too easy, and it is wrong and old-fashioned, to just try to throw money at something. We need to get it co-ordinated, use all the money that is there and get this efficiency and use it properly. That is what I am trying to do within this strategy, and I think that will be achieved. The first national security strategy was a huge step forward—we had not done something like that before in this country. We looked at it across the board, for all threats, and we thought of it in terms of the citizen. We said we would develop and build on that, and that is what we have done. We are still building it around the citizen, so that we can relate this to the citizen in every single area. One of the great successes of the last strategy was that out of that I pulled a National Risk Register, which goes right down to the various local areas, to the local risk forums. In that, we said that pandemic flu was probably the most likely and most dangerous risk, and so we started making preparations. There is now a pandemic—although luckily it does not seem to be really virulent at the moment—and when it began the World Health Organisation said that Britain was the most prepared country in the world. That was because we had identified it in our national security strategy. We have now covered more areas, and are working through this is a much more structured way. There is a logical sense to the way we have gone about the strategy so that people can follow it. The average citizen can read it, work it out, and say, "Oh yes they’ve done that". The strategy looks at various domains, which is why cyber is such an instant success as a domain that we need to work in. A lot of work is going on in the maritime area, but it leapt out at me as one where there are so many fingers in the pie that we need to co-ordinate it better. That is what we will do. Within 12 months, we will actually have an answer and a proper, tied-up strategy stopping things like the attack on Mumbai coming from the sea, and piracy. We will know what is around our coast. Space was another area that we had not really addressed properly. I have said we need to co-ordinate it, and we are now doing that. However, you cannot do everything instantly—there is only limited resource in terms of brains and people. However, we have done a remarkable amount—we are delivering these things and we now know very clearly which way we are going. The cybersecurity strategy is just one chunk of that, another domain rather like maritime—it is a new domain and one we need to work in. The noble Baroness, Lady Miller, mentioned that she has talked about cybercrime for some time. I have touched on that—it has been growing and we have been aware of it. The reason we have gone about it the way we have is because the connectivity increased and the capability of attacks got bigger. We needed to co-ordinate it more, and that is why we are where we are. However, it is a complex thing, and to get all these people to work together is complex and difficult. We are very lucky in this country—we have some remarkably capable people, and we need to grow more of them. We need to become a centre of excellence in the world, because we are ahead of anywhere else. We worked really closely with our American cousins and there are very close links between GCHQ and the NSA. But of course they are in a far worse place than us because they were connected up long before we were. They were using computers and talking to each other when we were still on quill pens—not quite, but you know what I mean. But as we came into that computer age later, our government net, for example—the gsi.gov.uk net—has a very restricted number of portals. It is quite difficult for people get in, and we know the number of attacks. In the American system has more than 8,000 portals in its government network. We know from some of our pointy-headed hackers how easy it is to get into it, and therefore the Americans have a real problem to resolve. We are working very closely with them on this, and in fact we were doing this work at the same time, if not before, them. Therefore, it is rubbish when people say that President Obama has grabbed this, that he has jumped ahead of us and that we are not catching up. We have been working with the Americans and I think that we have delivered a great deal. The noble Baroness, Lady Miller, mentioned the EU convention. We are still working on that, as there are complexities and difficulties within government. The ethics part is for individuals but aspects of law are also involved. We have to get all these things right. We are still working on that and we hope that it will be completed fairly soon. The noble Baroness is absolutely right about individual members of the public. Although I have now been made the Minister responsible for cybersecurity, I sometimes feel like an ingénue in this area. It is quite daunting and horrifying to see how people who want to get money out of you or cause damage can fool you into giving up data. Part of this whole package is intended to teach our people so that they are aware of the risks. Very often, the weakest link in any net is the human being. People are sent something, they open it up and are then asked a question in a clever way. They answer and—bang—every bit of their computer is suddenly available for others to use. I will not mention some of the clever things that these people do to get information because we do not want to let other people know about them, but I can say that they are quite terrifying. Our aim is to teach people about these things. We will set things up to let people know about these matters and train them, letting them know the right things to do and putting in place mechanisms within the system to make things safer. As I said, far from this being done somewhat late and in a bit of a rush, I think that we have acted in a timely and sensible way. There is no confusion or duplication; we are tying things together. Very shortly, the Home Office will produce something on serious and organised crime. We are addressing every one of these areas and pulling them together. I think that what we have done is rather impressive, but I had better stop now and allow more questions to be asked.


Secondary information

Type
Proceeding contribution
Reference
711 c1711-4 
Session
2008-09
Chamber / Committee
House of Lords chamber
Subjects
Cybercrime Ethics Internet National security Organised crime Terrorism Electronic warfare Cyber Security Operations Centre Office of Cyber Security Cybersecurity
Link
View this Proceeding contribution on www.publications.parliament.uk