Skip to main content

Director's Mansion House Defence & Security Lecture 2019

Full transcript of Jeremy Fleming's speech given for the Lord Mayor’s annual Defence & Security Lecture in the City of London
Frontage of Mansion House, London

Lord Mayor, Lady Mayoress, Ladies and Gentlemen,

Thank you very much for inviting me here to this important event in these impressive surroundings.

A particular thank you to the Reserve Forces and Cadets Association of Greater London for organising this evening.

The banks and investment houses here today have a proud and long history. Many of your predecessors will have been among the remarkable people who 75 years ago answered the call to arms and risked their lives to protect our country.

As we commemorated D-Day last week and remember the courage and conviction of those men and women, it’s right that we thank them for their sacrifice.

I am proud that GCHQ, which this year celebrates our centenary, was also able to play its part in what was to become the largest seaborne invasion in history.

Many of you will know our contribution to the Second World War through the well-known story of Enigma. You’ll have heard about the brilliant minds at Bletchley Park who broke German coded communications.

But code-breaking is only one part of our story. To have an impact we had to turn that into intelligence - into something useful that your partners can use.

By June 1944, Bletchley Park had access to the communications between Gerd von Rundstedt, the Commander of the German Army in the West, and his superiors in Berlin. It gave the Allies a hugely valuable insight into the enemy’s strategic capabilities and intentions.

This understanding of German communications enabled us to contribute to Operation FORTITUDE – you will remember that was the deception plan to convince the Germans that the invasion would land from another part of the UK . And later on we were also able to provide the intelligence to show General Eisenhower that the Germans had fallen for it.

Ahead of the landings, we provided crucial details of the enemy’s order of battle. And once the invasion was underway, we quickly delivered reporting of German command communications so that Eisenhower could track the impact of the allied advance across France.

So yes, we’re proud of the part we played in that operation too. It helped shorten the war and saved countless lives.

Supporting the military was one of the main reasons GCHQ – then the Government Code & Cypher School – was set up in 1919. And in the hundred years since, our staff have deployed alongside them in every overseas conflict.

But over the decades our mission has grown and we’ve evolved.

In the second World War we faced a clear existential threat, perhaps the worst the country has ever faced. Now, our adversaries may not always be as visible – but they are more complex than ever before. The battlefield has changed. It’s fuelled by a digital technology race.

As we enter the third decade of the internet age, this technology revolution is providing us with extraordinary opportunity, innovation and progress – but it’s also exposing us to increasing complexity, uncertainty and risk.

It is the case today that we face our foes in cyber space, as state actors, criminal gangs and terrorists seek to do us harm in that domain.

This is a new technology environment and a new threat. And defending the UK from it doesn’t just fall to the military, the Intelligence Agencies or the Police – it’s the role of everyone – government, business and individuals.

We need a whole-of-nation approach to this task. And I think it’s critical to make this a reality if we’re serious about addressing the threats and crucially, if we want to be a Cyber Power.

Now, I’ve set out previously what I think being a Cyber Power means for the UK. There are three broad requirements:

Firstly, and most importantly, a country must be world-class in safeguarding the cyber health of its citizens, businesses and institutions – it must protect the digital homeland.

Secondly, it must have the legal, ethical and regulatory regimes to foster public trust – without it we just don’t have the licence to operate in cyber space.

And thirdly, when the security of the nation is threatened, we must have the ability – in accordance with international law – to project cyber power to disrupt, deny and degrade our adversaries.

If we are to pioneer a new form of security, getting these three things right is essential.

Now today, I’m going to talk about what we’re doing on the first of these requirements, which I said was the most important. How we’re protecting the Digital Homeland, and especially, what we’re doing with business to make this effective.

As GCHQ turns 100, now more than ever I am focused on what the next century will bring.

And whatever it holds – and none of us truly know – my bet is that technology will become even more central to our economic prosperity and to the development of our society.

It is inevitable that this digital era brings with it new and unprecedented challenges for GCHQ as we try to protect our citizens and companies of this country and ensure that everyone can do business safely online.

We know it’s not easy.

But it’s not fundamentally different to the challenges of the past.

Throughout our history we have been a hunter and a gamekeeper. We have worked to protect information side by side with our intelligence gathering mission. As the ways and means by which we communicate have changed, so we have adapted. With the growth of the internet and an ever-more interconnected society, our security mission has just become ever more central.

We’ve been working on cyber security for well over a decade. The UK’s first cyber security strategy was launched in 2009 – and in that period we’ve learned a lot about what works and what hasn’t.

We learned early on that whatever the shape of our cyber security mission, it made no sense to silo it away from other aspects of national security, the secret world. To be effective, it had to be able to take advantage of the high-grade intelligence we and others produce in the security environment.

We also learned that we needed to invest more in getting the public and private partnership really working. And we needed to set even clearer lines of accountability so we could respond when cyber incidents happen. And these and many other flaws in the UK’s cyber landscape would not have been fixed because there were neither the means nor the incentive to sort them out.

In 2015, the Government took all that learning and turned it into a five-year National Cyber Security Strategy. This brought new thinking to the management of cyber incidents, led to the creation of the Active Cyber Defence programme and set the conditions for a different partnership with the private sector.

And of course, much of this was to be given home in the National Cyber Security Centre, which itself was to be part of GCHQ. This was a ground breaking decision. It gave the NCSC a mandate to deliver cyber security in a different way. And for the first time in GCHQ’s history, it gave us responsibility for a major national security risk.

Nearly three years later, I am confident this approach has made a real difference to improve the cyber health of the nation. Since its formation, the NCSC has co-ordinated responses to some of the biggest cyber threats the country has faced. Our incident management team has worked on more than 1,500 significant cyber security incidents. And using automation, it has reduced the harm from tens of thousands of cyber attacks.

I’m proud of the progress we’ve made, but there’s certainly room for more.

Britain may not have faced a Category 1 attack yet – that’s one that causes sustained disruption to the UK’s essential services or affects our national security. We still think it’s a matter of when not if this will happen. But in the meantime, we’re seeing lots of cyber-attacks which have the potential to critically disrupt business and the lives of our citizens.

The impact of cyber-crime is particularly acute. My friend at the National Crime Agency, Lynne Owens, recently launched the National Strategic Assessment for Serious Crime. It makes for stark reading - the chronic impact of serious crime is there for all to see.

It costs our country, businesses and citizens at least £37 billion a year. And it is now the case that the most commonly experienced crime is fraud. In the 6 months from April 2018 we saw 3.6 million incidents in England and Wales. Financial loses increased by 32%.

And 84 percent of those frauds were cyber-enabled.

You don’t need me to tell you the terrible impact this has on you and your customers. Or the detrimental effect it has on the City and the UK’s economy.

Prosperity underpins our very way of life. Attacks on our financial institutions and businesses are an attack on us all.

So what have GCHQ and the NCSC been doing to help address this situation and make the UK the safest place to do business online?

Well we have been taking a bold, interventionalist approach to involve a wider set of stakeholders in protecting the nation’s cyber security.

Through our Active Cyber Defence programme we’ve used automation to block attacks on an enormous scale. Our goal is to make the internet automatically safer for businesses and people to use.

One of our most effective strategies so far has had a huge impact on phishing attacks. In March, the UK’s Global share of this pernicious activity fell below 2% for the first time. When we started in 2016 it was 5.4%.

This is seriously strategic innovation. And we think we can expand it both domestically and internationally to make a transformative difference on a grand scale.

We are also working in partnership with Government Departments. HMRC is an excellent case study. In 2016, it was the 16th most phished brand globally, accounting for 1.25 percent of global phishing emails. Today it is ranked at 146th and accounts for less than 0.1 percent.

Our protective DNS system has prevented 57.4 million visits from public sector accounts to known bad sites, and in so doing has stopped an enormous amount of malware and ransomware infections.

And we’re working hard to put in place similar programmes to help small businesses. This year, we identified over 1,200 sites which were serving malicious code to illicitly copy credit card transactions. We were able to help these small businesses fix the problem and protect their customers and their reputation.

Of course, no defence system is fool-proof, and when breaches occur the NCSC aims to share the latest information and coordinate the response.

For example, earlier this year we learned of a new and credible threat to the banking sector. We saw an Indian bank lose around £13m in 2hrs from a coordinated ATM cash scam. Within a very short period of time we pulled together more than 50 UK financial organisations, including many of you here today, to brief them on the threat and advise on specific protective measures.

But we’ve learned that it’s not just technical solutions and rapid response that make a difference. We’re also here to provide expert advice to improve cyber security practices and cultures.

To do this we’ve created a range of products aimed at helping businesses both large and small.

Many of you will have used The Board Toolkit – produced for FTSE 350 companies – it’s designed to encourage the right discussions about cyber security around the Board table. We want to make sure those of you at the top understand cyber risk and how your organisations should respond. It’s great to see how many of you have started to use it to structure conversations and shape your strategies. It feels very different to me from just a few years ago.

The Small Business Guide and our upcoming Response and Recovery Guide will help businesses improve their security and quickly respond if they’re hit.

And this week, we’re launching a training package for companies of any size to help raise the cyber skills of all their employees.

Of course, the NCSC, GCHQ, the Government – isn’t doing all of this work alone. Business is playing its part too.

You know this. Your customers are making it clear to you that you have a responsibility to keep both them and their money safe online. And your staff feel that responsibility too.

I recognise and commend that the City is already doing a huge amount in this area to protect systems and customers.

It is clear to me you’ve invested heavily in cyber security and I know that much of this, and the Security Operations Centres I’ve visited, are world-class.

You’re also sharing sensitive information about breaches and attacks. This helps us to understand the wider threat, to provide focused technical advice to the financial sector, and to co-ordinate responses when required. Taken together this is undoubtedly strengthening the resilience of the City as a whole, and making your partners and customers safer online.

Nationally, the picture’s a bit more patchy, but there are plenty of green shoots and areas of best practice. Over 26,000 companies have demonstrated a basic level of cyber security hygiene by gaining certification under our CyberEssentials scheme.

Many companies invested in Industry 100 – that’s the NCSC’s initiative to facilitate close collaboration with the best and most diverse minds across business and government.

Many of your colleagues have worked with us inside the NCSC, challenging our thinking, testing innovative ideas and ultimately enabling greater understanding of cyber security and better cyber policy.

Right now we have the coordinator of the Law Enforcement Cyber PROTECT network seconded into the NCSC. And we have representatives from all of the major sectors across our economy and critical national infrastructures.

Many of you have taken our guidance and repackaged and tailored it for partners and consumers. In particular, I comment the work of the big banks passing on our small business advice to their customer base, either in the form of direct engagement through webinars or in their own public-facing campaigns. It’s making a difference.

We’re also grateful for the work that the British Retail Consortium have done with us to deliver a toolkit of tailored cyber security advice to retailers across the country.

The reach you have through your industry bodies, supply chains and customer bases is second to none and it’s helping to drive greater cyber security throughout the whole economy.

This is real progress. But we can’t be complacent. We know that the rate of technology change and the diversity of its use is only going to increase. The cyber security task is getting harder.

So what does that future look like? And what does it mean for us in Government and for you in business?

Firstly, it’s clear to us all that we’re going to be ever more interconnected: 5G is going to be one of the most important and impactful technologies of this or any era.

It’ll massively enhance how we use the internet, be a catalyst for new technologies, and over time will transform the way we think about how our data is used. It’ll also make us more interwoven and more inter-dependent.

The average citizen will see hugely faster data for their handsets. But behind the scenes 5G will enable smart cities using its networks of cheap sensors. It will help us to manage our congested urban environments better – and encourage the growth of new consumer and customer services. The impact will be far reaching, rapid and for those businesses which fail to adapt, it will be fatally disruptive.

Secondly, we will see enormous growth in the data economy. It will be driven by a combination of vast amounts of data, huge processing power and a new generation of advanced skilled people. It will enable AI and Machine Learning and provide opportunities for humans to use advanced systems to help deal with this growing complexity.

Much of this is already at the heart of the City’s financial success and it’s increasingly relevant to GCHQ’s work too.

We’re seeing data and analytics-driven enterprises delivering radical new products alongside the old ones. They are challenging our traditional thinking that change is incremental or requires a complete systems refresh to be successful.

Challenger banks, non-bank and shadow banking new entrants are succeeding because they are less constrained by ‘legacy systems’. This is enabling them to build, or buy as a service, highly scalable systems, with controls and analytics built in – they’ll deliver greater business and consumer value.

Quantum computing and sensors will provide further market opportunity and disruption. They will enable us to tackle previously impossible mathematical challenges. Some of those will be security related – and as many of you will already know, many will be financial. And they have the potential to give UK companies another area of strategic advantage.

For example we can already see that the move from GPS to immensely precise quantum timing will have a major impact on international trading.

None of these will be a cliff-edge transition, and they do not entirely change how we think about security.

However, navigating this exciting, transformative technology is going to be difficult.

Some nations will want to beat us in the race to master these technologies. Getting the balance right between security and the economy will be key.

So whether it’s synthetic biology, neuromorphic chip design, post-Quantum cryptography – we’re going to have to work together to stay ahead of the change curve. And we’re going to have to evolve a rules based system fit for the digital age.

If we get this right the benefits for business and society are huge.

So I think it goes without saying that Government can’t realise this vision for the future alone. It needs to be done in partnership with industry, academia and the public.

In the UK, this sense of a Team Cyber is spreading way beyond the normal national security community. Law enforcement colleagues are lining up with intelligence partners, businesses and universities.

We’re reaching down into schools, hiring communications specialists to get the security mindset messages to stick and working with venture capitalists and start-ups to foster emerging technologies for the next generation.

So, what does that look like for the business sector?

We think it means we need to share strategic knowledge about malign actors and more tactical cyber threat information.

This is a two way process, we’re committed to sharing even more in real time, to help you defend yourselves and your customers.

To enable this we have made it simple for our analysts to share time critical, secret information in a matter of seconds. With just one click, this information is being shared already and action is being taken.

In the coming year, we will continue to scale this capability so – whether it’s indicators of a nation state cyber actor, details of malware used by cyber criminals or credit cards being stolen on the Dark Web – we will aim to declassify this information and get it to those best placed to act on it.

We also need to do more to ensure our citizens and your customers aren’t the weak point in this cyber security ecosystem . We are doing our bit to make citizens cyber literate. This has to be the first line of defence - ensuring they understand what they can do to keep themselves and their digital lives safe online.

The deterrence we’re aiming for goes way beyond cyber security products and systems. It’s a mindset, a coalition of citizens and businesses, informed by practical and easy to digest advice.

But the gap we face is stark - only 15 percent of people understand how to protect themselves online. This lack of awareness is particularly marked amongst older people. Their most frequent concern is still that their money will be stolen – nearly half feel they will be a victim in the next few years.

Analysis we published earlier this year found that 23.2 million victims of hacks used the password 123456 to protect their accounts. It’s clear we have got a way to go to improve knowledge, and many people need to improve their password security.

We’ll keep pushing out guidance to help educate the population. But most of the burden of this education and the imposition of appropriate security features will fall to you, to business. We’re committed to leveraging that amazing reach.

Improving the average digital literacy of the population is only part of the problem. We also need to work together to grow the cyber skills of our workforces. I know this is a particular focus of the Lord Mayor and I welcome the work he’s doing to shine a spotlight on the skills agenda, including during this London Tech Week.

According to recent research, the global shortage of cybersecurity professionals is close to three million people. Over 63% of organizations report a shortage of dedicated cybersecurity staff and as a result nearly 60% say their organization is at extreme or moderate risk to cyber attack.

We are all battling with this. Fighting with each other over a limited talent pool will not fix the problem, we’ve got to invest in developing the workforce of the future.

That’s why events such as this London Tech Week are so important. It allows us to come together across all sectors and disciplines and bring our collective minds to bear solve this difficult issue. It provides the opportunity to harness the incredible innovative mindset of this community and realise the vision of a thriving and dynamic digital economy with people at its heart.

One thing I believe is key, is that we need to do a better job of selling the potential of careers in cyber and the utility of cyber skills to almost every form of employment. This reaches deep down into our education systems – we’ve got to encourage new generations from all backgrounds to take up STEM subjects. Too few of our children can see themselves working in this world. Too few understand what they can bring to it.

Inspiring them to be part of shaping our digital future is mission critical for our nation.

For our part, the CyberFirst programme is identifying and nurturing a diverse pipeline of future cyber security professionals.

Our CyberFirst Adventurers initiative aims to engage 11-13 year olds. We follow this up with activities for 14-17 year olds, such as our summer courses which offer over 1,100 free places.

And our CyberFirst girls competition aims to tackle the systemic issue around gender diversity in Cyber and in STEM. This year’s has been the most successful yet with the online round attracting nearly 12,000 girls with entries from over 800 schools.

And remember, only 2,000 girls took computer science at A-level last year.

Aspiration is key, but that has to be matched with education. At the heart of CyberFirst is a bursary scheme intended to encourage students into a career in cyber security as well as support them through their studies. Over 500 students have been enrolled onto the programme so far and we are well on course to meet our target of 1000 students by 2021.

Studies often show that work experience is a key factor in employment and it’s critical that all of those involved in these schemes get appropriate work placements. This year we have placed 250 students across 15 government organisations and 71 private sector partners – many of you are here today.

Its an excellent example of government and business working in partnership. I’d like to thank you to those of you already supporting it, and ask those of you not to please consider it.

We all know that there’s much, much more to do. So, I’d encourage you all to keep investing in your people. They are, after all, our most important strategic asset.

Between us we have everything we need to inspire and nurture the next generation and build a workforce fit for our digital future.

At the beginning of this speech I talked about D-Day and the impact the UK had as a global military power when the nation came together against a common foe.

The situation today is very different. We face enormous complexity but also enormous opportunity. The threats are diffuse and powered by the very technologies which drive fair, just and successful societies.

To navigate this environment, for the UK to be able to exercise its role as a global cyber power we need to harness the best of the Government and the Private sector.

The City is a crucial partner in this endeavour. You have the skills, international clout and resources to make sure we prosper in this digital age.

We’re most grateful for your support.

I look forward to answering your questions.

Thank you.


Published

Date of speech

Location

Mansion House, London