6
international law. Attribution should be in line with our stated positions in
national and international fora, where we champion a free, open, peace and
secure cyberspace, and adhere to norms of state behaviour. It should
enhance the UK’s reputation as a competent cyber actor and weigh up the
risk of misattribution.
e. Wider response options: the effect of UK attribution on other deterrence
activity, which the UK government has agreed or is implementing. The timing
of attribution should be calibrated to enhance the impact of other responses.
There are challenges to attribution in cyberspace, but this does not mean it is
impossible. Nor should it be viewed in isolation; it is one tool amongst many in a
range of options (political, diplomatic, and economic) to respond to malicious cyber
activity, with the aim of deterring this activity.
Norm 3 (UNGGE 2015 report, paragraph 13c) – States should not knowingly
allow their territory to be used for internationally wrongful acts using ICTs.
The United Kingdom has criminalised wrongful acts using ICTs through, for example,
the Computer Misuse Act3. This makes it an offence to conduct unauthorised access
to computer systems, and to use this access to facilitate other offences, such as
modifying or damaging computer systems and networks.
Overall Strategy: The 2015 National Security Strategy (NSS)4 confirmed that cyber
remains a top threat to the UK’s economic and national security. The threat posed by
cyber attacks continues to grow in scale and complexity. The National Cyber
Security Strategy (NCSS) recognised that to achieve the desired outcomes over the
five years of the strategy required the UK Government to intervene more actively and
to use increased investment. The NCSS is supported by £1.9billion of
transformational investment up until 2021.
Active Cyber Defence: Through the National Cyber Security Centre, the UK has
taken an interventionist approach aimed at making the UK an unattractive target to
criminals or states. The UK’s Active Cyber Defence Programme (ACD) is an
automated set of interventions intended to tackle a range of commodity attacks. It
aims to tackle, in a relatively automated way, a significant proportion of the cyberattacks that hit the UK. In other words, ACD aims to protect the majority of people in
the UK from the majority of the harm, caused by the majority of the attacks, for the
majority of the time. This has demonstrated that there are targeted interventions that
governments can take – alongside the private sector – to improve the digital
homeland.
UK ACD measures have:
3
https://www.legislation.gov.uk/ukpga/1990/18/contents
4
https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/55
5607/2015_Strategic_Defence_and_Security_Review.pdf