5
operational in 2016, the NCSC’s cyber security front line has helped to support with
1,167 cyber incidents – including 557 in the last full 12 month period (October 2017October 2018). The latest NCSC annual report reveals most attacks against the UK
that are managed by the NCSC, are carried out by hostile states.
Since January 2018, the UK’s cyber community has implemented a new incident
categorisation framework. This new approach fully aligns the NCSC’s work with law
enforcement agencies to defend against the growing threat, with incident responders
now classifying attacks into six specific categories (C1-6) rather than the previous
three. The new system ranges from attacks targeting the Government and critical
national infrastructure through to individual citizens.
The NCSC will produce an impartial assessment of the nature of the incident
drawing upon and weighing up the evidence from a wide range of sources. Incident
Assessment Reports usually answer the following questions: based on intent and
past form, and who is most likely to be responsible, and is this incident part of a
wider trend? The report will open with a set of key judgements, followed by a
confidence statement, which is based on the certainty behind the source material
used. Further commentary is provided to support and expand upon the key
judgements.
Based on this assessment, the UK will consider how to respond. The UK will use a
range of options across diplomatic (including but not limited to attribution), economic
and law enforcement to respond. Any decision to respond will take into account the
wider context at the time and be in accordance with international law.
On attribution specifically, the UK Government’s starting point is that attribution is a
political decision and can be a powerful deterrence tool when deployed effectively.
The UK will decide whether attribution – public or private – is in the UK’s national
interest. We consider attribution a sovereign political decision on a case by case
basis. Attributing is a first step and opens up further response options, in the UK
national interest and under international law.
When considering attribution, the UK Government will consider, alongside a
technical assessment from the National Cyber Security Centre:
a. Geopolitical and bilateral factors: our wider objectives towards the State in
question, including national security objectives, regional stability, the
sensitivities of our allies and the likelihood of counter-response.
b. Impact on victim: the impact of UK attribution (especially public) on the
victim(s) of a cyber-incident will be reviewed.
c. Impact on law enforcement activity: the impact of UK attribution (especially
public) on the law enforcement investigation of a cyber-incident; for instance
the effect on our ability to arrest and prosecute.
d. UK values and ability to operate: attribution should not limit the UK’s ability
to carry out our own cyber operations in full adherence to domestic and