4
both bilaterally and multilaterally, to help maintain international peace and security in
cyberspace. We also contribute to setting international standards for new
technologies, which can help prevent ICT practices that are harmful.
On behalf of the UK, Jeremy Wright QC MP, the then Attorney General, set out the
UK’s position on the application of international law in cyberspace in a speech at
Chatham House on 23 May 2018.
The UK first published a National Cyber Strategy in 2011. In October 2016, a
second edition issued, supported by funding of £1.9bn, outlining UK goals for the
continued shaping and investment in cyber security over another five-year term.
The current strategy defines our vision and ambition to be secure and resilient to
cyber threats as well as prosperous and confident in a digital world. We will continue
to pursue economic and social value from cyberspace where our actions, guided by
our core values, will enhance prosperity, national security and a strong society. The
strategy contains three main pillars, which the whole of our society has a role in
helping to deliver:
Defend our people, businesses and assets across the public and private
sectors;
Deter and disrupt our adversaries: states, criminals and hacktivists;
Develop our critical capabilities and grow our cyber security sector.
We also look to develop industry standards on security of technology, which help
build cyber resilience globally. We continue to be active in the international
standards space, as in order for this issue to be resolved, we know that there will
need to be alignment at an international level. For example, in February 2019 the
first globally applicable technical standard for Internet of Things security was
released, based on the Code of Practice for Consumer Internet of Things Security 2,
which we published in October 2018. We are now working to transpose this into a
European Standard (EN), and we encourage ETSI members to play an active role in
shaping this before then.
Norm 2 (UNGGE 2015 report, paragraph 13b) – In case of ICT incidents, States
should consider all relevant information, including, inter alia, the larger
context of the event, the challenges of attribution in the ICT environment, and
the nature and extent of the consequences
The United Kingdom, through its National Cyber Security Centre (NCSC) has
developed an integrated approach to national incident management in the public and
private sectors. This has brought together several approaches that existed for
different sectors and, in doing so, has simplified the process. The new incident
management approach has been operating since mid-2016. Since it became fully
2
https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/77
3867/Code_of_Practice_for_Consumer_IoT_Security_October_2018.pdf