Published on PublicTechnology.net (https://www.publictechnology.net)

Home > GCHQ unveils cybersecurity playbook after pilot with ‘UK’s most spoofed brand’ HMRC

GCHQ unveils cybersecurity playbook after pilot with ‘UK’s most spoofed brand’ HMRC

Written by Sam Trendall on 30 June 2017 in News
News

Four initiatives made available free to public sector bodies

The four measures include protected DNS and anti-spoofing technology

The National Cyber Security Centre (NCSC) has created four “simple and free measures” that public sector bodies can implement to immediately become safer online. The body is also hoping that, in time, UK businesses will also be able to adopt the initiatives.

In the NCSC’s own self-described lay person’s terms, the four measures comprise: blocking bad stuff from being accessed from government systems; blocking bad emails pretending to be from government; helping public bodies fix bad things on their website; and removing bad things from the internet.

In the former case, the centre – which is part of GCHQ – has created a Domain Name Service (DNS), which it characterises as “the phonebook of the internet”. The service will collate data from GCHQ and its partner organisations in the private sector to maintain a register of malicious addresses, which civil servants will be prevented from visiting. Departments can register for the service here [1]. 


Related content

  • Cabinet Office announces first Scottish cyber security research centre of excellence [2]
  • Government cyber security survey shows concern over ransomware [3]
  • Cyber attacks bolder and more aggressive than ever [4]before, [4] says cybersecurity centre [4]

The second of the four initiatives relates to the DMARC anti-spoofing protocol, which is designed to confirm the authenticity of an organisation’s communications.  The protocol, which aims to make email spoofing much more difficult, was trialled by HMRC last year. During the pilot, the department – which NCSC said is “the UK’s single most spoofed brand” – blocked 300 million malevolent emails. 

Alongside the protocol, the NCSC has created a Mail Check service to track adoption of DMARC, ensure that data on malicious communications is shared with NCSC as well as any relevant commercial partners, and analyse trends. Some 613 government domains were using DMARC as of the end of March. The permanent secretaries of any departments yet to roll out either DMARC or Mail Check will be contacted by the centre shortly with information on their department’s uptake, and where they are placed “in the league table of adopters”. To implement the service departments can email dmarc@ncsc.gov.uk [5].

To help “public bodies fix bad things on their website”, the NCSC is offering a free website scanning offering called WebCheck. The service will scan bodies’ sites and provide feedback on vulnerabilities and advice on mitigating cybersecurity risks. 

WebCheck is due for formal launch later this month, following the completion of an ongoing trial involving 150 users drawn from 114 different organisations covering the breadth of the public sector. This scheme is primarily aimed at the local government space, but central government entities are also free to sign up. Users can find out how to join by registering here [6] and quoting the reference wbchk04/7.

The final measure is intended to remove “bad things from the internet”. This initiative has seen NCSC team up with Bath-based anti-phishing and research specialist Netcraft. The company’s services have already been deployed across central government, but departments are encouraged to improve the service by notifying Netcraft if they are targeted by a phishing campaign. To do so, they should send any relevant emails and other attachments to scam@netcraft.com [7]. 

About the author

Sam Trendall is editor of PublicTechnology

Tags
Cybersecurity [8]
Policy [9]
Categories
Business and industry [10]
Government and politics [11]
#block-views-events-popup-block{ position: fixed; bottom: -30px; padding: 25px 22px; width: 360px; max-width: calc(100% - 30px); text-align: center; border-radius: 0 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; -ms-transform: translateY(100%); -webkit-transform: translateY(100%); transform: translateY(100%); -webkit-transition: all .35s ease-in-out; transition: all .35s ease-in-out; z-index: 2; } #block-views-events-popup-block.show{ bottom:10px; transform:none; -webkit-transform:none; } #block-views-events-popup-block a.btn.btn--outlineWhite { border-color: #fff; color: #fff; background: transparent; } #block-views-events-popup-block .events-popup-close{ position: absolute; cursor: pointer; top: -30px; left: 0; height: 32px; padding: 7px 20px; border-radius: 4px 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; font-size: 13px; } #block-views-events-popup-block .events-popup-close .icon--events-popupClose{ padding-left: 10px; font-family: inherit !important; } #block-views-events-popup-block .icon--events-popupClose:before { content: ''; width: 12px; height: 12px; margin: -1px 7px 0 0; background: url(https://www.publictechnology.net/sites/www.publictechnology.net/themes/pubtech_override/img/close-thin.svg) center no-repeat; background-size: 10px; vertical-align: middle; position: absolute; left: 10px; top: 10px; } #block-views-events-popup-block .views-field.views-field-nid .field-content{ display:none; }

jQuery(window).load(function() { if(jQuery('#event-popup-nid').length){ var eventId = jQuery('#event-popup-nid').text(); jQuery.cookie('eventPageId',eventId); var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; var combinedValueValue = eventId+'-'+countCurrentValue; var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; jQuery.cookie('combinedValueName',combinedValueValue); const result = combinedValueValue.split('-'); if( result[1] <= 3 ) { jQuery('section#block-views-events-popup-block').addClass('show'); countCurrentValue = parseInt(result[1]) + 1; jQuery.cookie('countCurrentName',countCurrentValue); combinedValueValue = eventId+'-'+countCurrentValue; jQuery.cookie('combinedValueName',combinedValueValue); } jQuery('.events-popup-close').click(function(){ jQuery('section#block-views-events-popup-block').removeClass('show'); }); } });

(function(e,t,o,n,p,r,i){e.visitorGlobalObjectAlias=n;e[e.visitorGlobalObjectAlias]=e[e.visitorGlobalObjectAlias]||function(){(e[e.visitorGlobalObjectAlias].q=e[e.visitorGlobalObjectAlias].q||[]).push(arguments)};e[e.visitorGlobalObjectAlias].l=(new Date).getTime();r=t.createElement("script");r.src=o;r.async=true;i=t.getElementsByTagName("script")[0];i.parentNode.insertBefore(r,i)})(window,document,"https://diffuser-cdn.app-us1.com/diffuser/diffuser.js","vgo"); vgo('setAccount', '253344499'); vgo('setTrackByDefault', true); vgo('process');
Close
Sign up for our free daily newsletter
Register here
6472
Dods PublicTechnology.net is a Merit Group plc title

Quick Links

  • Home
  • News
  • Opinion
  • Features
  • Private Sector Insight
  • Cyber Week
  • White Papers
  • Events
  • On Demand Webinars
  • Partner Directory
  • About
  • Contact

Services

Dods People Dods Political Intelligence Dods ResearchDods EventsDods Training

Media & Publishing

PoliticsHome Parliament MagazineHolyroodThe House MagazineCivil Service WorldTraining Journal

About Dods

Dods Group Part of Merit Group Privacy Policy Terms & Conditions Advertising Sponsorship
Privacy PolicyTerms & ConditionsAdvertisingSponsorship Subscriptions
  • Registered office: 11th Floor
  • The Shard
  • 32 London Bridge Street
  • London SE1 9SG
  • Company number: 04267888
  • © Merit Group plc 2021

Source URL: https://www.publictechnology.net/articles/news/gchq-unveils-cybersecurity-playbook-after-pilot-%E2%80%98uk%E2%80%99s-most-spoofed-brand%E2%80%99-hmrc

Links
[1] https://nominet.service-now.com/csm
[2] http://www.publictechnology.net/articles/news/cabinet-office-announces-first-scottish-cyber-security-research-centre-excellence
[3] http://www.publictechnology.net/articles/news/government-cyber-security-survey-shows-concern-over-ransomware
[4] http://www.publictechnology.net/articles/news/cyber-attacks-bolder-and-more-aggressive-ever-says-cyber-security-centre
[5] mailto:dmarc@ncsc.gov.uk
[6] https://www.webcheck.service.ncsc.gov.uk/
[7] mailto:scam@netcraft.com
[8] https://www.publictechnology.net/tags/cybersecurity
[9] https://www.publictechnology.net/tags/policy
[10] https://www.publictechnology.net/categories/business-and-industry
[11] https://www.publictechnology.net/categories/government-and-politics