A new centre to protect the UK against cyber attacks is to be officially opened by the Queen later.
The National Cyber Security Centre (NCSC) in London, which cost nearly £2bn to set up, is designed to improve Britain’s resilience to attacks and act as an operational nerve centre.
“We want to make the UK the hardest target,” Ciaran Martin, the centre’s chief executive, told the BBC.
The NCSC says the UK is facing about 60 serious cyber attacks a month.
There were 188 attacks classed by the NCSC as Category Two or Three during the last three months.
And even though the UK has not experienced a Category One attack – the highest level – there is no air of complacency at the NCSC’s new headquarters in Victoria.
“We have had significant losses of personal data, significant intrusions by hostile state actors, significant reconnaissance against critical national infrastructure and our job is to make sure we deal with it in the most effective way possible,” Mr Martin says.
As well as protecting against and responding to high-end attacks on government and business, the NCSC also aims to protect the economy and wider society.
The UK is one of the most digitally dependent economies, with the digital sector estimated to be worth over £118bn per year – which means the country has much to lose.
It is not just a crippling cyber attack on infrastructure that could turn out the lights which worries officials, but also a loss of confidence in the digital economy from consumers and businesses, as a result of criminals exploiting online vulnerabilities.
A sustained effort was required by government and private sector working together to make the UK the hardest possible target, officials say.
Russia has been the focus of recent concern, following claims it used cyber attacks to interfere with the recent US presidential election.
“I think there has been a significant change in the Russian approach to cyber attacks and the willingness to carry it out, and clearly that’s something we need to be prepared to deal with,” Mr Martin said.
French and German officials have warned of the possibility of interference in their upcoming elections, but the NCSC’s head said there was no evidence that a significant attack or compromise had yet taken place against the UK democratic process.
“There has been an identifiable trend in Russian attacks in the West, in terms of focusing on critical national industries and political and democratic processes,” Mr Martin added.
“And so it follows from that that we will look to be sure we are protecting those sectors in the UK as well as we possibly can.”
The centre will be working on a voluntary basis with political parties and giving advice to high profile individuals – including MPs – on how to protect their sensitive data.
The UK is already targeting computers in other countries being used for cyber-attack, particularly if there is no possibility of prosecution or for co-operation with authorities where the hackers are based.
“In the most serious cases, we have lawful powers where we can go after the infrastructure of adversaries – the infrastructure that people use to attack us – and we would do that in some of the most serious cases several dozen times a year,” Mr Martin said.
In the past, UK cyber protection was largely situated within GCHQ in Cheltenham, which was criticised by businesses and others as overly-secretive.
The NCSC aims to be more public facing and accessible. It will also protect a far wider range of sectors, rather than just government and national security-related industries, like defence.
GCHQ will still be the parent body for the NCSC, meaning it can draw on the intelligence agency’s skills and capabilities.
Sometimes, the intelligence arm of GCHQ spots compromised networks as it watches adversaries move across the internet.
It was through this type of work that GCHQ spotted the compromise of the US Democratic Party’s information by Russian hackers, which it then informed US authorities about.
The NCSC is working on trial services to pro-actively discover vulnerabilities in public sector websites, help government departments better manage spoofing of their email, and take down tens of thousands of phishing sites affecting the UK.
“We’re actively working to reduce the harm caused by cyber-attacks against the UK and will use the government as a guinea pig for all the measures we want to see done by industry at national scale,” says the NCSC technical director, Dr Ian Levy.
He says results would be published openly to enhance collaboration. The centre will be publishing some of its code as open source, so that others can use the techniques.
A five-year National Cyber Security Strategy was announced in November 2016, with £1.9bn of investment.
The chancellor is also due to announce the creation of a “Industry 100” scheme, which will grant 100 NCSC secondments to private sector staff.