A/68/156
The threat landscape is complicated and dynamic. Systems of the Government
of the United Kingdom, along with those of business and private individuals, are
subjected to attempted intrusions on a daily basis. Motives range from political and
industrial espionage, cybercrime, disruption or control of networks or denial of
service. Threat actors range from nation States, State proxies, non-State actors, and
organized criminal gangs through to opportunistic individuals. The interconnected
nature of cyberspace means that disruptive activities against one system may cause
unintended and unpredictable effects in other systems. Attempts to counter these
threats are hampered by the difficulty in reliably attributing a cyber incident to a
particular source, the potential for the perpetrators to masquerade as others,
immature understanding of acceptable State behaviour in cyberspace, the lack of
resilience in the cyber infrastructure in some countries and the absence of
harmonized international approaches to detect, pursue and prosecute cybercriminals.
All elements of society have a role and a duty in combating these threats. It is
for Governments to lead international efforts to improve understandings over
acceptable State behaviour and in tackling cybercrime but, given that the majority of
the infrastructure of cyberspace is owned and operated by private companies, their
participation in this debate is crucial. The United Kingdom believes that improved
cybersecurity must not come at the expense of the economic and social benefits that
cyberspace brings. It is particularly important to ensure that efforts to increase
cybersecurity are not misused to impose further restrictions on freedom of
expression beyond those permitted in international agreements. In this regard, the
role of civil society organizations is particularly important.
Efforts taken at the national level to strengthen information security and
promote international cooperation in this field
National approaches
The United Kingdom’s national security strategy, published in 2010 identified
cyberattacks as one of four “tier 1” threats, alongside an international military crisis,
major accidents or natural hazards and terrorist attacks. In November 2011, the
United Kingdom published an updated cybersecurity strategy which sets out a vision
to derive huge economic and social value from a vibrant, resilient and secure
cyberspace, where our actions, guided by our core values of liberty, fairness,
transparency and the rule of law, enhance prosperity, national security and a strong
society. The achievement of this strategy is supported by four objectives:
• To tackle cybercrime and be one of the most secure places in the world to do
business in cyberspace
• To be more resilient to cyberattacks and better able to protect our interests in
cyberspace
• To help shape an open, stable and vibrant cyberspace that the public of the
United Kingdom can use safely and that supports open societies
• To have the cross-cutting knowledge, skills and capability it needs to underpin
all our cybersecurity objectives
To underpin the achievement of these objectives, the Government of the
United Kingdom allocated £650 million of additional expenditure to be used in a
four-year programme intended to transform the response to cyberthreats.
16
13-39735