Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC marks 20th anniversary of first response to state-sponsored cyber attack

Security

NCSC marks 20th anniversary of first response to state-sponsored cyber attack

The National Cyber Security Centre (NCSC) has marked the 20th anniversary of GCHQ’s first response to a cyber attack perpetrated against the UK Government by another state, with the response acting as the forerunner to a capability that became the National Cyber Security Centre, a part of GCHQ.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simone Flamigni / copyright Shutterstock

In June 2003, GCHQ experts were involved in responding to a cyber attack against the UK Government for the first time. Unlike today, in 2003 there was no government agency set up to deal with cyber attacks, nor was there a dedicated national incident management function. This all changed in 2016 with the establishment of the National Cyber Security Centre (NCSC), a part of GCHQ.

Advertisement
ADS S&P RT

The NCSC can reveal that in June 2003 cyber experts were called upon to investigate after a government employee detected suspicious activity on one of their workstations.

A suspected phishing email had been identified, so technical specialists sought help from the Communications-Electronics Security Group (CESG) – the information assurance arm of GCHQ at that time.

CESG’s analysis discovered that malware, designed to steal sensitive data and evade anti-virus products, had been installed, raising suspicions about the attacker’s intent and setting in motion a series of actions that was transformative to cyber incident investigations.

For the first time, GCHQ fused its signals intelligence capabilities with its cyber security function to investigate and identify the actor responsible.

The ground-breaking analysis, coupled with international engagement, led CESG to conclude the intent of the attack had been cyber espionage by a nation state, setting in train a mission that today is at the heart of NCSC operations; namely, understanding and responding to cyber threats to the UK.

Paul Chichester, Director of Operations at the National Cyber Security Centre, said: “Twenty years ago, we were just crossing the threshold of the cyber attack arena, and this incident marked the first time that GCHQ was involved in a response to an incident affecting the UK Government.

Advertisement
Cranfield

“It was also the first time that the UK and Europe started to understand the potential online risks we faced and our response transformed how we investigate and defend against such attacks.

“The NCSC and our allies have come such a long way since this incident, and it is reassuring to be at the forefront of efforts to develop tools and techniques to defend against cyber threats and keep our respective nations safe online.”

The National Cyber Security Centre, a part of GCHQ, was set up in October 2016 to help keep the UK safe online. It combined existing expertise from CESG, the Centre for Cyber Assessment, CERT-UK and the Centre for Protection of National Infrastructure (now the National Protective Security Authority).

The NCSC responds to cyber security incidents to help reduce the harm they cause to organisations and the wider UK, as well as working with other law enforcement, defence, the UK’s intelligence and security agencies and international partners.

 

Advertisement
PTC PTC
CCL boosts Incident Response capability with SentinelOne partnership

Security

CCL boosts Incident Response capability with SentinelOne partnership

7 February 2025

As part of its continued investment into its Incident Response services, digital forensics and cyber specialist CCL has announced a partnership with the global leader in autonomous cyber security and EDR, SentinelOne.

Goldilock expands West Midlands hub

Defence Security

Goldilock expands West Midlands hub

6 February 2025

Cyber scaleup Goldilock - the network segmentation and isolation specialist backed by NATO - has today announced the expansion of its West Midlands headquarters to support its rapid growth trajectory.

Windward launches Critical Maritime Infrastructure Protection

Defence Security

Windward launches Critical Maritime Infrastructure Protection

6 February 2025

Windward today announced the launch of its Critical Maritime Infrastructure Protection solution, a first-of-its-kind AI-powered solution designed to protect the world's essential maritime infrastructure including cables, pipelines and rigs against growing threats.

Blighter unveils AI-assisted BlighterNexus

Defence Security

Blighter unveils AI-assisted BlighterNexus

6 February 2025

Blighter has unveiled BlighterNexus, an AI-assisted connectivity and processing hub.

Advertisement
ADS S&P RT
Teledyne FLIR launches Prism Supervisor

Aerospace Defence Security

Teledyne FLIR launches Prism Supervisor

5 February 2025

Teledyne FLIR OEM, part of Teledyne Technologies Inc., today announced the release of Prism Supervisor - the latest addition to its Prism embedded software ecosystem - which integrates drone autopilot flight control systems with real-time AI-based observations, enhancing the capabilities of unmanned aircraft systems (UAS).

Cyber agencies unveil new guidelines to secure edge devices

Security

Cyber agencies unveil new guidelines to secure edge devices

5 February 2025

Cyber security chiefs in the UK and their international allies have issued a new set of guidelines to help manufacturers of edge devices make their products more secure and easier to investigate if a compromise occurs.

Advertisement
ODU RT