34
Section 5
DEFEND
• harden the UK’s critical infrastructure
and citizen-facing services against
cyber threats; and
• disrupt the business model of attackers
of every type, to demotivate them and
to reduce the harm that their attacks
can cause.
Approach
5.1.3. In pursuit of these aims, the
Government will:
• work with industry, especially
Communications Service Providers
(CSPs), to make it significantly harder
to attack UK internet services and
users, and greatly reduce the prospect
of attacks having a sustained impact
on the UK. This will include tackling
phishing, blocking malicious domains
and IP addresses, and other steps to
disrupt malware attacks. It will also
include measures to secure the UK’s
telecommunications and internet
routing infrastructure;
• increase the scale and development
of GCHQ, Ministry of Defence and
NCA capabilities to disrupt the most
serious cyber threats to the
UK, including campaigns by
sophisticated cyber criminals and
hostile foreign actors; and
• better protect government systems
and networks, help industry build
greater security into the CNI supply
chain, make the software ecosystem
in the UK more secure, and provide
automated protections for government
online services to the citizen.
National Cyber Security Strategy 2016
5.1.4. Where possible, these initiatives will
be delivered with or through partnerships
with industry. For many, industry will be
designing and leading implementation,
with the Government’s critical contribution
being expert support, advice and
thought-leadership.
5.1.5. The Government will also undertake
specific actions to implement these
measures, which will include:
• working with CSPs to block malware
attacks. We will do this by restricting
access to specific domains or web
sites that are known sources of
malware. This is known as Domain
Name System (DNS) blocking / filtering;
• preventing phishing activity that
relies on domain ‘spoofing’ (where an
email appears to be from a specific
sender, such as a bank or government
department, but is actually fraudulent)
by deploying an email verification
system on government networks as
standard and encouraging industry to
do likewise;
• promoting security best practice
through multi-stakeholder internet
governance organisations such as
the Internet Corporation for Assigned
Names and Numbers (ICANN)
which coordinates the domain name
system), the Internet Engineering
Task Force (IETF) and the European
Regional Internet Registry (RIPE) and
engagement with stakeholders in the
UN Internet Governance Forum (IGF);
• working with law enforcement channels
in order to protect UK citizens from
being targeted in cyber attacks from
unprotected infrastructure overseas;