Stay up to date with notifications from The Independent

Notifications can be managed in browser preferences.

Government warned against using Russian-linked antivirus software

‘The NCSC advises that Russia is a highly capable threat actor which uses cyber as a tool of stagecraft’

Saturday 02 December 2017 17:54 GMT
Comments
Russian hackers are believed to have interfered in the last UK general election and the last US election as well as the Brexit referendum
Russian hackers are believed to have interfered in the last UK general election and the last US election as well as the Brexit referendum (Reuters)

Government departments have been warned against using antivirus software made by tech firms with links to Russia amid growing concerns over national security.

Ciaran Martin, head of the National Cyber Security Centre (NCSC), claimed Russia has the intent “to target UK central Government and the UK’s critical national infrastructure” and that there were “obvious risks around foreign ownership” of companies that produce antivirus (AV) software.

In a letter to Whitehall chiefs agreed with MI5, he described Russia as a “highly capable cyber threat actor”, which uses cyberspace for “espionage, disruption and influence operations”.

The NCSC is in discussion with the largest Russian player in the UK, Kaspersky Lab, in order to develop checks to prevent “transfer of UK data to the Russian state”, Mr Martin said.

Russia stands accused of meddling in the 2016 US election, while MPs have questioned if Moscow has sought to interfere in UK elections and the Brexit referendum.

Prime Minister Theresa May used a November speech to issue a message to Russian president Vladimir Putin that the international community was aware of his country’s efforts to spread fake news in an attempt to “sow discord in the West”.

Mr Martin has previously warned that Russian hackers have targeted the UK energy network, telecoms and the media in the past year.

However, his letter said most people and companies in the UK were not under threat of state-backed cyber attacks, but rather from criminal gangs.

He said: “The NCSC advises that Russia is a highly capable cyber threat actor which uses cyber as a tool of statecraft.

“This includes espionage, disruption and influence operations. Russia has the intent to target UK central Government and the UK’s critical national infrastructure.

“However, the overwhelming majority of UK individuals and organisations are not being actively targeted by the Russian state, and are far more likely to be targeted by cyber criminals.

“In drawing this guidance to (department heads’) attention today, it is our aim to enable departments to make informed, risk-based decisions on (their) choice of AV provider.

“To that end, we advise that where it is assessed that access to the information by the Russian state would be a risk to national security, a Russia-based AV company should not be chosen.”

The NCSC is concerned that the hackers backed by the Russian state could exploit AV software and has opened talks with Kaspersky Lab, one of the world’s largest cybersecurity firms, which has headquarters in Moscow.

Mr Martin said it is hoped they can develop an independent means of checking the company’s products to “give the Government assurance about the security of their involvement in the wider UK market”.

The company’s co-founder, Eugene Kaspersky, has denied any wrongdoing by the company, telling the BBC earlier this week: “It’s not true that the Russian state has access to the data. There are no facts about that.”

NCSC technical director Ian Levy said the issue was “complex and nuanced” and urged the public not to panic.

“We really don’t want people doing things like ripping out Kaspersky software at large, as it makes little sense,” he said in a blog.

“There’s almost no installed base of Kaspersky AV in central government,” he said.

“Beyond this relatively small number of systems, we see no compelling case at present to extend that advice to wider public sector, more general enterprises, or individuals.”

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in