19
Section 3
STRATEGIC CONTEXT
Terrorists
Hacktivists
3.11. Terrorist groups continue to aspire
to conduct damaging cyber activity against
the UK and its interests. The current
technical capability of terrorists is judged
to be low. Nonetheless the impact of even
low-capability activity against the UK to
date has been disproportionately high:
simple defacements and doxing activity
(where hacked personal details are ‘leaked’
online) enable terrorist groups and their
supporters to attract media attention and
intimidate their victims.
3.13. Hacktivist groups are decentralised
and issue-orientated. They form and select
their targets in response to perceived
grievances, introducing a vigilante quality
to many of their acts. While the majority
of hacktivist cyber activity is disruptive in
nature (website defacement or DDoS), more
able hacktivists have been able to inflict
greater and lasting damage on their victims.
“Terrorists using the Internet for
their purposes does not equal cyber
terrorism. However, by increasingly
engaging in cyber-space, and given the
availability of cyber-crime as a service,
one can assume that they would be in
the position to launch cyber attacks”
ENISA Threat Landscape 2015
3.12. The current assessment is that
physical, rather than cyber, terrorist attacks
will remain the priority for terrorist groups
for the immediate future. As an increasingly
computer-literate generation engages
in extremism, potentially exchanging
enhanced technical skills, we envisage
a greater volume of low-sophistication
(defacement or DDoS) disruptive activity
against the UK. The potential for a number
of skilled extremist lone actors to emerge
will also increase, as will the risk that a
terrorist organisation will seek to enlist an
established insider. Terrorists will likely
use any cyber capability to achieve the
maximum effect possible. Thus, even a
moderate increase in terrorist capability
may constitute a significant threat to the
UK and its interests.
INSIDERS
Insider threats remain a cyber risk to
organisations in the UK. Malicious
insiders, who are trusted employees
of an organisation and have access
to critical systems and data, pose
the greatest threat. They can cause
financial and reputational damage
through the theft of sensitive data and
intellectual property. They can also pose
a destructive cyber threat if they use
their privileged knowledge, or access, to
facilitate, or launch, an attack to disrupt
or degrade critical services on the
network of their organisations, or wipe
data from the network.
Of equal concern are those insiders
or employees who accidentally cause
cyber harm through inadvertent
clicking on a phishing email, plugging
an infected USB into a computer,
or ignoring security procedures and
downloading unsafe content from the
Internet. Whilst they have no intention
of deliberately harming the organisation,
their privileged access to systems and
data mean their actions can cause just
as much damage as a malicious insider.
These individuals are often the victims of
social engineering – they can unwittingly
provide access to the networks of their
organisation or carry out instructions in
good faith that benefit the fraudster.
National Cyber Security Strategy 2016