<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Ciaran's Crispy Cogitations]]></title><description><![CDATA[

Mostly cyber security. Occasionally constitutional politics. Very occasionally crisps.

From the former/founding head of the UK National Cyber Security Centre; now at the University of Oxford]]></description><link>https://ciaranmartin.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!VfxR!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F36f1cfef-d4d5-415c-828a-bcc1ead2c5a2_400x400.png</url><title>Ciaran&apos;s Crispy Cogitations</title><link>https://ciaranmartin.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 01 Sep 2026 06:19:05 GMT</lastBuildDate><atom:link href="/__u/ciaranmartin.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Ciaran Martin]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ciaranmartin@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ciaranmartin@substack.com]]></itunes:email><itunes:name><![CDATA[Ciaran Martin]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ciaran Martin]]></itunes:author><googleplay:owner><![CDATA[ciaranmartin@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ciaranmartin@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ciaran Martin]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Control. Ownership. Perspective.]]></title><description><![CDATA[Three lessons from the latest AI cyber security testing problems]]></description><link>https://ciaranmartin.substack.com/p/control-ownership-perspective</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/control-ownership-perspective</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Wed, 05 Aug 2026 21:56:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HPuT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!HPuT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!HPuT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ciaranmartin.substack.com/i/209963136?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!HPuT!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390b3bf2-9545-40b3-8b8d-f2b13ef5d9d9_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Here we go again. </p><p>For the third time in as many weeks we have a frenzy about apparently terrifying AI agents seemingly going rogue and embarking on a hacking spree of innocent victims. </p><p>Once again, it&#8217;s a safety test at the root of the problem. This time, however, it&#8217;s not an American frontier lab - <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI</a> and <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic </a>have already disclosed what went wrong with their tests. It&#8217;s a British Government agency - the AI Security Institute - which has earned a deserved reputation as the foremost independent evaluation body in the world for frontier AI security testing. </p><p>The team at AISI were testing tools developed by Anthropic and OpenAI, but the operation was theirs, not that of either frontier lab. So it is they who are responsible for an agent that breached GitHub. To their credit, AISI have taken responsibility in a refreshingly accessible and candid <a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">blog</a>. To their even greater credit they have made very significant and immediate changes. Others should follow their lead. </p><p>There are three lessons we should learn from this spate of incidents: </p><ul><li><p>the first is surprisingly simple. It&#8217;s about <em>monitoring</em> <em>and, crucially, <strong>control </strong>in the testing environment</em><strong>. </strong>There&#8217;s a problem with the way we currently do AI security testing and it&#8217;s really obvious it needs to change. Happily, but unusually for AI, it&#8217;s surprisingly easy to fix. Rather than do what Governments and companies normally do and waffle on about reviewing procedures and sharing information collaboratively in partnership, AISI have said simply and clearly they&#8217;re going to change the way they test. From now, during testing, their agents will always be monitored in real time and they are going to introduce ways to ensure that if the agent does things it&#8217;s not supposed to the agent can be stopped. This is the right change to make. Others involved in AI security testing should follow their lead;</p></li><li><p>the second is conceptually simple but practically very complicated. It&#8217;s about <em>accountability rooted in <strong>ownership </strong>of the AI agent </em>across the entirety of agentic AI<strong>.</strong> These recent incidents arise from artificial testing scenarios designed to force us to think about what might happen in the real world. And in these three scenarios AI agents are behaving like very badly behaved small children who don&#8217;t know right from wrong. That&#8217;s because they absolutely don&#8217;t; they don&#8217;t understand what they&#8217;re doing. With small children, parents are supposed to set boundaries. If they fail in that, and something goes wrong, in the laws of most countries, parents are responsible for those very badly behaved children. This is not a bad starting analogy for thinking about AI agents. If you don&#8217;t set proper boundaries for your AI agent and something goes wrong, then you should expect to be held liable. So the starting principle of codes, conventions, rules and ultimately laws for AI agents is that someone owns it and is responsible for it. This will be hard to roll out in practice. But it is the right starting concept.;</p></li><li><p>finally, we need to keep this in <strong>perspective</strong>. All three cases disclosed are highly artificial testing environments. These conditions are not likely to be replicated in the real world; not yet anyway. The capabilities are dazzlingly impressive but the real world harm is negligible; arguably it is zero. And for all the freakout, frenzy and hype, these three incidents are not even the biggest issue in cyber security right now. In case you missed it, last week it seems that the<a href="https://www.pbs.org/newshour/show/what-we-know-about-the-cyberattacks-on-water-systems-in-7-states"> Iranian state came very close to disrupting the water supply to ordinary citizens in parts of the United States via a cyber attac</a>k. This genuinely terrifying episode had nothing whatsoever to do with AI. Is that why it received so little attention? If so, that&#8217;s nuts. Other things beyond AI testing procedural problems need the attention of those who want to help bolster vital cyber defences. </p></li></ul><p>Let&#8217;s look at each of these three lessons - control, ownership and perspective - in turn. </p><h2>Control </h2><p>The AI Security Institute&#8217;s blog setting out what happened is not just accessible and candid. In terms of lessons learned, it is also commendably specific. As in the other two cases, AISI&#8217;s exercise involved setting an agent off on a task but then not fully monitoring in real time what it was doing. So in all three cases no one - indeed no thing - was watching when the agent went off on its unsolicited hacking spree. And even if someone, or something, been watching, it&#8217;s not clear that anyone would have been able to stop the agent from going about its hacking.</p><p>Now that we know this has happened - three times - it is perfectly clear that we should not do AI cyber security testing like this. The testing status quo is indefensible. However, unlike Anthropic and OpenAI, AISI have said very explicitly that they understand this. They will not conduct another test without real time monitoring and the ability to switch the agent off. This must be right. AISI are to be commended for pledging this swiftly and unequivocally. Everyone else involved in AI testing should do the same. </p><p>Ollie Whitehouse, the Chief Technical Officer of the National Cyber Security Centre in the UK, put out a very good <a href="https://www.ncsc.gov.uk/news/ncsc-statement-in-response-to-recent-incidents-resulting-from-frontier-ai-evaluations">three-paragraph statement</a> on the implications of his British Government colleagues&#8217; disclosure. Inevitably, the first paragraph - how this reminded us of the power of AI - was widely carried in media reporting; we seem to love to marvel at the capabilities of supposedly &#8216;rogue&#8217; AI. Depressingly, the final paragraph - how this reminds us of the importance of basic cyber hygiene - was ignored. But it&#8217;s the middle paragraph that is most important:</p><div class="callout-block" data-callout="true"><p><span>&#8220;These technologies must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens. Relying on detection alone after the fact of an incident will not be enough.&#8221;</span><em><span> </span></em><br></p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!gMeX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!gMeX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2019951,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ciaranmartin.substack.com/i/209963136?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!gMeX!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f9f05e-fd2c-4129-86a7-10db76a056b8_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Daniel Card, the well known British cyber security expert, put it a little more <a href="https://x.com/UK_Daniel_Card/status/2084964729437503522">agriculturally</a>:</p><div class="callout-block" data-callout="true"><p>&#8220;if your AI starts hacking s**t&#8230;if you monitor what it&#8217;s doing you can, you know, turn the f***ing power off&#8221;</p></div><p>AISI have followed this inexorable logic swiftly. This must be the way of the future. I suspect the main regret at AISI is that they didn&#8217;t make this change immediately after the OpenAI/Hugging Face disclosure - this test was carried out the week after. Had they done so, the incident disclosed today would not have happened. </p><p>But the correct decision has now been taken. And it&#8217;s a surprisingly simple one. As the AISI blog sets out in painstaking detail, the circumstances as to how this happened are extremely bespoke to testing and highly unlikely to be replicated in the real world. The same point is implicit in both the OpenAI and Anthropic disclosures, but the - in my view unhelpful - focus in those blogs on how powerful the attacking capabilities are blunts this important message. Don&#8217;t test without monitoring, and don&#8217;t monitor without control - the ability to press stop if you see something is going wrong. That should now be policy everywhere. </p><p>Last week I detected a mood change in the cyber security community. Since the <a href="https://www.anthropic.com/glasswing">Glasswing </a>report in April, the prevailing atmosphere has been one of respect and gratitude towards the frontier AI labs for taking security seriously and being transparent and collaborative. Some of this has been sincere, and some of it contrived out of a feeling of necessity, and it&#8217;s been hard to work out the balance. But the attitude shifted with the OpenAI and Anthropic agent disclosures. Lots of cyber security veterans opined wryly that if they&#8217;d undertaken capability tests in this way they&#8217;d at best be in serious commercial trouble and facing multiple lawsuits, and at worst on remand awaiting trial. The great <a href="https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html">Bruce Schneier </a>had a point when he wondered aloud what sort of hellish international crisis would have occurred if a Chinese model had been responsible for the Hugging Face incident, rather than OpenAI. </p><p>AISI can hardly be blamed for testing Anthropic and OpenAI&#8217;s capabilities in the same way as those companies themselves. But it is quite clear from the evidence of the past few weeks that these practices have to change, and it is good AISI have led the way in changing them. </p><p>Testing must be monitored and agents being tested must be capable of being controlled. </p><h2>Ownership</h2><p>All three incidents do highlight, however, the power of AI agents as hackers and their potential to carry out illegal and dangerous activity in pursuit of the objective they have been set. So, working on the assumption that such agents at some point become widely and generally available, how can they be controlled outside testing environments if and when they become widely available? </p><p>This is also conceptually easy but - sadly - much harder in practice than AISI&#8217;s changes to testing. The good news there is some time to think it through because the testing scenarios are not yet available in real world situations for most potential users, good and bad. </p><p>There is a semantic struggle to describe these capabilities and events accurately. The word &#8216;rogue&#8217; is not fully accurate because the agent is simply trying to find ways to complete a task humans have set. But, as AISI have set out very clearly, the agent is behaving roguishly by trying to conceal things it&#8217;s done in pursuit of that objective. Similarly, the word &#8216;autonomous&#8217; doesn&#8217;t quite work because the agent is doing something it&#8217;s been instructed to do and only that - which is anything but autonomous. At the same time, it is taking steps to carry out its task which those who instructed it really don&#8217;t want it to do. That&#8217;s very much autonomy in action. </p><p>I am afraid I don&#8217;t have a word that fully captures what these agents are doing and how we might think about controlling the consequences of that. But I do have a principle for how we should deal with it. It&#8217;s around ownership of the agent and accountability for its actions. </p><p>Let&#8217;s call it the Watling Principle. Bear with me&#8230;</p><p>In a superb episode of the <a href="https://www.youtube.com/watch?v=wd5Kt9Elx3o">Times podcast </a><em><a href="https://www.youtube.com/watch?v=wd5Kt9Elx3o">The General and The Journalist </a></em><a href="https://www.youtube.com/watch?v=wd5Kt9Elx3o">in June this year, Dr Jack Watling of the Royal United Services Institute</a> talked about how drones are changing the war in Ukraine. He was asked a more general question about responsibility for AI military capabilities. His response was very thought provoking, in two ways.</p><p>First, he said that autonomy in AI posed real challenges for military leaders. The nature of military command was to restrict autonomy, not expand it. Soldiers have dangerous missions that rely on discipline and the collective interest. Impulsive individual decisions can jeopardise the mission. That is why commanders are responsible for the actions of their subordinates, and why commanders are therefore compelled to try to find sensible limits to autonomy and on-the-spot decision taking while allowing for good decisions in response to changing circumstances. </p><p>This led to the second, and for our purposes, more important insight. This is about ownership and accountability. For Dr Watling, core concepts and principles don&#8217;t change. It doesn&#8217;t matter what capability the commander uses. He is still accountable for everything that happens because he owns the capabilities, whether human or technical. </p><p>Dr Watling used the example of targeting a building. If a commander believes a building is full of enemy combatants, and he drops a 2,000lb bomb on it, but it turns out it is full of civilians, the commander bears responsibility for this humanitarian and operational fiasco. If the commander sends a swarm of AI robots into the same building to kill anyone it finds, the commander bears exactly the same responsibility for the same disastrous outcome. It follows that if the men, or the robots, go &#8216;rogue&#8217;, the commander is still responsible because he gave them their instructions. </p><p>This is the principle was should apply in these civilian environments too. We have already applied it in cyberspace in relation to two infamous incidents in 2017. Both were what can be called malicious accidents: no one thinks North Korea - in the <a href="https://en.wikipedia.org/wiki/WannaCry_ransomware_attack">Wannacry </a>case - intended to launch an attack that hit both Taiwan and China, both Russia and Ukraine, as well as German railway stations and British hospitals. Similarly, no one thinks Russia was trying to destroy Maersk, the shipping giant, Merck, the pharma titan, or to close down Cadbury&#8217;s chocolate factory in Tasmania. But that&#8217;s what happened when they launched <a href="https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/">NotPetya</a>. And what did western Governments do? We <a href="https://www.bbc.co.uk/news/world-us-canada-42407488">blamed North Korea</a> for the destruction wreaked by the first attack, and <a href="https://www.cfr.org/cyber-operations/notpetya">Russia for the second</a>, and tried to hold them accountable. That they didn&#8217;t mean it didn&#8217;t matter. It was their &#8220;agent&#8221;. </p><p>The AISI report is commendably clear that this was their agent and their responsibility. Rolling out this principle more widely in the full deployment of agentic AI in all circumstances is going to be fiendishly difficult. But it&#8217;s the right place to start. Who owns the agent? With that ownership comes accountability. Let&#8217;s work out how to get that principle right in practice, rather than marvel at the scary capabilities. </p><h2>Perspective</h2><p>Finally, let&#8217;s keep all this in perspective. What we are seeing are the consequences of maturing, and therefore flawed, safety tests. This is not even accidental use of AI by normal businesses, let alone undefendable attacks by cyberninja adversaries armed with magical AI powers. All three of OpenAI, Anthropic and AISI have said they were testing the most powerful capabilities they have, and that in doing so they were removing the normal safety features. That is not normal. It&#8217;s a test. </p><p>Moreover, there is no actual damage. Intrusion into a network <a href="https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/">may (or may not, in these circumstances) be illegal</a>, it may be discombobulating, but it is not in and of itself harmful or damaging. No one suffered here. In terms of most people&#8217;s understanding of the word &#8216;harm&#8217;, none has been done. We can learn from this, and it&#8217;s not learning the hard way. </p><p>What is, however, truly extraordinary therefore - and needs calling out - is the obsession with these disclosures to the detriment of other things. These incidents are extremely interesting. They are concerning, and must surely give added impetus to the urgent and comprehensive measures needed to get secure AI deployment right. But <a href="/__u/ciaranmartin.substack.com/publish/posts/detail/208968626?referrer=%2Fpublish%2Fposts">there is no cyberapocalypse</a>, and no sign of one. </p><p>In the headspace of policy makers and opinion formers, cyber security competes with many other unpleasant and difficult challenges for much needed attention. So focusing on the right things when we get that attention really matters. This gives rise to the most depressing conclusion of the last fortnight. </p><p>It is widely believed that over the past few weeks the Iranian state has successfully infiltrated the civilian water supply in the state of Minnesota in the US, and possibly in seven other states. The full picture is unclear, but there seems to be credible evidence that had it not been for very considerable recovery work, actual supplies to civilians could have occurred. The causes of the attack will be investigated, but, as the redoubtable <a href="https://www.nytimes.com/2026/08/02/opinion/iran-water-hack-trump.html">Jen Easterly, former head of America&#8217;s cyber defense agency, set out in the </a><em><a href="https://www.nytimes.com/2026/08/02/opinion/iran-water-hack-trump.html">New York Times</a>,</em> they illustrate serious vulnerabilities in the world superpower&#8217;s critical infrastructure. As Easterly put it:</p><div class="callout-block" data-callout="true"><p>&#8220;For all the attention devoted to an artificial-intelligence-powered cyberapocalypse, one of the most consequential cyber stories in America this week is much less futuristic&#8221;. </p></div><p>I am writing from the United Kingdom, not the United States. But until the specifically British aspect of the AISI revelation in the past day or so, none of the major cyber security studies of the past fortnight had anything specifically to do with Britain. But look at British media coverage of cyber and general cyber discourse in that period. OpenAI and Hugging Face? Freakout. Anthropic&#8217;s triple rogue agent? Frenzy. Our closest ally nearly having its drinking water knocked out by a regime that doesn&#8217;t much like us either and could try the same on us? Barely a ripple. </p><p>If we focus our efforts and attention exclusively, or even predominantly, on the eye-catching results of the latest frontier AI testing mishap to the exclusion and detriment of long-standing threats and vulnerabilities, we don&#8217;t stand a chance. Let&#8217;s keep these incidents in perspective. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[From Frenzy to Freakout]]></title><description><![CDATA[AI and the New Wave of Cyber FUD]]></description><link>https://ciaranmartin.substack.com/p/from-frenzy-to-freakout</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/from-frenzy-to-freakout</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Wed, 29 Jul 2026 13:05:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1EK0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong>From Frenzy to Freakout </strong></h1><h2><strong>AI and the new wave of cyber security FUD</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!1EK0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!1EK0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1964139,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ciaranmartin.substack.com/i/208968626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1EK0!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38731a13-0f3e-40e2-83ea-f57e1ca9bdfc_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two seemingly contradictory things can be true at the same time:</p><blockquote><p><span>1. </span>Advances in frontier AI and the new capabilities they bring represent a very significant change in what&#8217;s possible for cyber attackers. This is real and it&#8217;s really important. It requires changes in strategy, tactics and posture among cyber defenders and a real sense of urgency around some of the defensive improvements needed, as well as difficult challenges for policymakers;</p><p><span>2. </span>At the same time, the near four months (and counting) since the <a href="https://www.anthropic.com/glasswing">Mythos/Glasswing announcement</a> has prompted the biggest outbreak of cyber FUD<a href="#_ftn1"><sup><span>[1]</span></sup></a> since former US Defense Secretary Leon Panetta warned of a &#8220;<a href="https://nsarchive.gwu.edu/document/21479-document-78">Cyber Pearl Harbor</a>&#8221; in a 2012 speech. Lots of cyber harms happened. But cyber Pearl Harbor never took place, and that was entirely predictable. The apocalyptic narrative is equally wrong now. For sure, we are heading towards some potentially very tough times in cyber security. But many of the current problems we&#8217;re experiencing in cyber security are long standing, unaddressed ones. We can also expect AI to lead to cyber security improvements in the medium term.</p></blockquote><p>There is probably a stormy period ahead. But storms pass. We are not heading towards some AI cyber apocalypse. Creating the expectation of one is harmful as it distracts from serious but manageable cyber security challenges. And drawing the wrong lessons from the latest reveal doesn&#8217;t help either.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ciaran's Crispy Cogitations is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>Two articles, two authors: </strong></h3><h4><strong>(1) AI &amp; FUD; (2) Hugging Face &#8211; AI is not attacking us</strong></h4><p>There&#8217;s a lot more to say on all this and I am working on a longer article that sets the new outbreak of FUD more fully in its historic and current context, along with why it is damaging. But the prompt for this shorter and quicker intervention was two-fold. One was an excellent SANS Institute discussion on the recent agentic AI cyber attack on Hugging Face which you can watch <a href="https://www.sans.org/mlp/sandbox-let-it-out-guardrails-locked-us-out#video">here</a> (interest declared: I do paid work with SANS; that said, as this video makes very obvious, they don&#8217;t try to censor their contributors or make them toe a party<span> </span>line.) </p><p>The other was an outreach from my friend <a href="https://www.surrey.ac.uk/people/alan-woodward">Professor Alan Woodward of the University of Surrey</a>, who sent me his own thoughts on the hype surrounding the Hugging Face incident. Alan is away and tied up on other things, and he is not in a position to publish this article himself. So it&#8217;s my privilege to do so on his behalf and with his permission as an accompanying piece, and I do so below (so please note these are two distinct articles, one by me and the other by Alan).</p><p>Alan&#8217;s insight is vital: AI isn&#8217;t attacking us. The AI didn&#8217;t know what it was doing. And that&#8217;s a different problem set that requires a different set of solutions.</p><p>So first me, then Alan. And apologies this Substack has been so dormant for so long, especially to those who have supported it. I will try to do better. </p><h4><strong>Article 1: AI and the new wave of cyber security FUD &#8211; from frenzy to freakout</strong></h4><h4><strong>By Ciaran Martin </strong></h4><p>The cyber security community has been on quite a journey since the Mythos/Glassing announcement almost four months ago. Hugging Face is the latest stop on the ride. Unusually (and entirely because of the general apocalyptic hype around AI which has been around for several years), this time the wider bubble of media and politicians are interested as well; it&#8217;s not just us in the specialist cyber field.</p><p>The first few days after Mythos saw something of a freakout with all sorts of apocalyptic predictions, mainly based on a knowledge gap between what Anthropic had published about their own model and what the wider world knew. So although the freakout was a bit distracting, it was understandable.</p><p>Then, as the days passed and the knowledge base grew, an unhelpful freakout gave way to a more constructive frenzy: a period of frenetic activity. That was because as a community we were beginning to understand the significance of what was unfolding and what to do about it. The mood was one of manageable urgency: we needed to promote realistic awareness among leaders, and at a technical level do sensible things like reduce the attack surface. Addressing technical debt was becoming more urgent &#8211; as the great <a href="https://www.kusari.dev/blog/facts-and-mythos">Katie Moussouris put it</a>, AI meant the technical debt repo man was on his way. In other words, AI was finally making it imperative for organisations to do all the things they should have been doing for years (plus some newer things).</p><p>So the freakout subsided. The ensuing frenzy &#8211; racing to fix things for the age of AI &#8211; was justified. But here we are again.</p><p>Over the past few days the global media has been back in freakout mode. On <em>Times Radio </em>and <em><a href="https://www.channel4.com/news/uk-national-cyber-security-centre-founder-on-openai-rogue-hacking-attack#:~:text=Ciaran%20Martin%20founded%20the%20UK's,to%20Channel%204%20News%2C%20from">Channel 4 News</a>,</em> I struggled to convince two very respected and hardnosed British journalists (Stephen Sackur &#8211; I mean he hosted <em>HardTalk </em>for goodness sake) &#8211; and Matt Frei, that we shouldn&#8217;t freak out about the Hugging Face incident. The hysteria was getting it all wrong (as Alan&#8217;s piece explains, this was not a rogue, autonomous AI agent, it was an OpenAI agent doing what it was told to do and achieving it because the testing environment wasn&#8217;t safe enough). Moreover, the circumstances of this episode are so extraordinary &#8211; they raise as many questions about frontier AI testing environments as they do about hacking &#8211; they are very unlikely to become commonplace.</p><p>And yet we are back to freakout mode. And for reasons I&#8217;ll elaborate on in the fuller article, freakout mode doesn&#8217;t help. It&#8217;s FUD on steroids &#8211; the capabilities are too powerful, everything is going to go pop, and there&#8217;s precious little we can do about it. That last bit is particularly corrosive &#8211; it infantilises people who are in a position to improve their defences and sends them chasing after the wrong problems. It sends Governments into a tailspin, feeling forced to react quickly rather than taking time to assess things strategically. Interestingly Secretary Panetta, asked years later about his Cyber Pearl Harbor remark, said he knew that things were more complicated than the phrase implied but he was addressing &#8220;the <a href="https://cyberscoop.com/cyber-pearl-harbor-911-cyberwar-hacking-leon-panetta-ciaran-martin/">jackass who wouldn&#8217;t pay attention</a>&#8221;.</p><p>Why do we do this to ourselves? It&#8217;s easy to blame commercial incentives. Maybe that&#8217;s part of the reason, though I do have some sympathy with Alan&#8217;s argument below that demonstrating your capabilities to be uncontrollably dangerous is a funny way to sell things. That said, in security, few businesses, if any, have ever lost money hyping up a cyber threat. But there&#8217;s more to it than than just marketing.</p><p>The most important point is, as the legendary Marcus Hutchins <a href="https://www.linkedin.com/posts/malwaretech_the-ai-discourse-is-way-too-focused-on-theoretical-activity-7487679784853049344-n3Yi?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAEMJZKUBY2YaDQaPvnJj5NwUhzFv97Fqn9s">has said quite recently</a>, a tendency to focus too much on the new capabilities and not enough on attacker behaviour and incentives. There are all sorts of things in life that are possible and very dangerous, but bad actors tend not to do them because there are barriers in the way, or because they&#8217;re too expensive, or because they don&#8217;t actually fit with what they want to achieve. But in the AI and cyber security debate we tend to ignore all this, and just assume that because something devastating is possible, anyone and everyone will both be able to do it and want to do it.</p><p>But there are huge barriers to most attackers being able to harness these new AI capabilities to do us serious harm, as Marcus has set out repeatedly in a series of LinkedIn posts. As he put it in one of his <a href="https://www.linkedin.com/feed/update/urn:li:activity:7488093294988726272/">most recent posts</a>: &#8220;The whole idea of agentic models mass-hacking sites is ridiculous. Who is allocating billions of dollars worth of compute to hacking a bunch of shoe-string budget organizations with no money?&#8221;</p><p>Moreover, and this is a hill I will die on, we are <strong>not</strong> <strong>yet</strong> seeing massive adoption of new AI techniques by attackers. Yes, there are smart innovations, like the one <em><a href="https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/">Seriously Risky Business</a> </em>exposed recently about ransomware negotiations. But they&#8217;re not using hugely powerful new techniques no one can defend against. We&#8217;re not in the first flush of AI: it&#8217;s been around as a commodity product for several years. And what are we seeing? For criminals, <a href="https://mb.com.ph/2026/07/20/sophos-report-identity-based-attacks-overtake-software-flaws-as-leading-ransomware-entry-point">malicious emails and phishing</a> are still the most common way of illicitly entering an organisation&#8217;s network. Why? Becauseit&#8217;s a lot cheaper and easier than using frontier AI, partly because of all the things we haven&#8217;t fixed. </p><p>There is one thing I will push back on strongly on this point. That is people responding to with comments like: &#8220;you don&#8217;t know what we&#8217;re seeing behind the scenes. It&#8217;s mindblowing&#8221;. I get this all the time when I say out loud that so far, most attackers have not seriously or strategically adjusted their current posture to include new AI hacking capabilities. These responses are pure FUD. I am not in Government anymore, but I do talk to Government cyber experts across the world and they are not briefing privately about invisible actors doing crazy things with AI that no one can stop. Were that happening, these days it&#8217;s their duty to warn of these things publicly. So they&#8217;re warning that it <em>could</em> happen, because that&#8217;s where the capabilities are going. And they&#8217;re telling us we need to up our game. That&#8217;s fine, sensible and accurate. But one of the things I can vouch for from years doing this in a Five Eyes Government is that while there is all sorts of murky activity going on, there is no massive secret digital battlefield where all sorts of mind-blowing things are going on that are totally invisible to everyone else. </p><p>Second, and far more importantly because the first point requires you to take me on trust, but the second one doesn&#8217;t &#8211; the vast majority of significant cyber attacks are either immediately or ultimately publicly observable. You can&#8217;t take out a hospital&#8217;s network (as the ransomware thugs often do) without anyone noticing. You can do a data exfil secretly (that&#8217;s the point, at least until you&#8217;re done) but usually, in the end, someone finds out what&#8217;s happened. Yes, there are secret espionage operations that never get discovered or disclosed. But the point is, if we were experiencing an AI cyber security disaster, we&#8217;d know about it. And we&#8217;re not. We are, however, experiencing a lot of the same things that have been harming us for years. There is not yet any hugely significant change in observable attacker behaviour. And there are very good explanations for that, mostly around economics, intent and incentives.</p><p><strong>The Greenwood Declaration &#8211; there will be no AI cyber apocalypse</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ZVkY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ZVkY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!ZVkY!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faac8d250-52ed-4fe7-8b96-470da44b75f7_4032x3024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But what if that doesn&#8217;t hold? What if their behaviour changes? Well, speaking of Marcus Hutchins, we were enjoying a beer in the Greenwood Pub underneath the NCSC in a sweltering London a few weeks ago. We found ourselves talking about the new wave of cyber FUD. Neither of us consider ourselves infallible, so we were wondering, as one always should &#8211; what if we&#8217;re wrong?</p><p>The problem for people like us is that if we&#8217;re wrong, it&#8217;s going to be horribly visible. There will be a huge spate of huge AI-powered cyber security disasters. But if we&#8217;re right, the corresponding problem doesn&#8217;t arise on the other side of the argument. If the AI cyber apocalypse doesn&#8217;t happen in 2027, plenty will argue that it&#8217;s just round the corner in 2028, or that it was averted by all the warnings, or by the product they sold. Nearly a decade ago, in a controversial but brilliant speech, Ian Levy, then Technical Director of the NCSC under my leadership, likened this play to <a href="https://www.theregister.com/security/2017/02/03/gchq-cyber-chief-slams-security-outfits-peddling-medieval-witchcraft/1147463">medieval witchcraft</a>. He was right then, and we could be seeing the new AI powered version a decade later. We&#8217;ve seen this movie before. So many times.</p><p>So at the risk of career ruination in 2027, and speaking only for myself, here is a prediction which I&#8217;ll call<span> </span>- in jest &#8211; the Greenwood Declaration after the pub I first had the confidence to say it out loud in. </p><p>We are not heading for an AI cyber security apocalypse.</p><p>The central case for 2027 and a bit beyond is a stormier cyberspace with more harm than we&#8217;ve had this year and in most years since the 2021-22 explosion of disruptive ransomware (<a href="https://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack">Colonial Pipeline</a>, the <a href="https://en.wikipedia.org/wiki/Health_Service_Executive_ransomware_attack">Irish healthcare crisis</a>, <a href="https://en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack">Kaseya</a>, <a href="https://en.wikipedia.org/wiki/2022_Costa_Rican_ransomware_attack">Costa Rica</a> and so on). It could be a bit worse than that. But, as the Cloud Security Alliance and SANS paper put out just after Mythos Glasswing rightly called it, it&#8217;s a <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv92.pdf">storm</a>. And storms pass (as the 2021-22 ransomware one did).</p><p>Some storms leave you wet and grumpy. Others destroy your house and village. Whether it&#8217;s the benign or malign outcome depends on the severity, which you can&#8217;t control, and your preparation, which you can.</p><p>Then things are likely to get significantly better if we get our response right. Alan&#8217;s piece below is especially important on the lessons for policymakers from the Hugging Face incident. </p><p>So, at the risk of repeating the fateful mistake in 1987 of the British weatherman Michael Fish<a href="#_ftn2"><sup><span>[2]</span></sup></a>, there is not going to be an AI fuelled digital apocalypse.</p><p>The AI cyber capabilities are real. That means frenzied work to improve security is not just justified but necessary. But just because these capabilities exist doesn&#8217;t mean they&#8217;re going to be easily and widely used by the world&#8217;s baddies, and the lesson from Hugging Face is the need to learn how to control them much better. </p><p>So a freakout is not justified and harmful.</p><p>Stop the FUD. Fix the stuff. </p><p>***</p><h4><strong>Article 2: The Problem Isn&#8217;t That AI Wants to Hack You**</strong></h4><h4><em>It doesn&#8217;t want anything. That&#8217;s what should worry us.</em></h4><h4>By Professor Alan Woodward</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!bvwW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!bvwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg" width="400" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ciaranmartin.substack.com/i/208968626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!bvwW!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e633aba-682b-44f3-bc9a-d84149fbd2e9_400x400.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Earlier this month, a set of OpenAI&#8217;s most capable models were running a cybersecurity exercise inside what the company described as an isolated testing environment. Their guardrails had been deliberately loosened, because that is the point of a red-team lab. Then they used stolen credentials, discovered a vulnerability nobody knew existed, and got into the production servers of Hugging Face, a rival AI company. Hugging Face detected an intrusion. It took days to learn where the attacker had come from.</p><p>Within hours, the story had a shape: the AI went rogue.</p><p>That framing is wrong, and the wrongness is expensive. Nothing broke out of anything. As Hannes Cools, a social scientist at the University of Amsterdam, pointed out, calling this an agent acting on its own is anthropomorphization that conveniently shifts blame away from the people who built the lab. &#8220;It is a human decision to switch off specific safeguards,&#8221; he said. The models were told to find complex attack paths through a computer system. They found one. It led somewhere nobody had thought to fence off.</p><p>Let me concede the part that skeptics usually fumble. These systems are formidable. When Anthropic announced its Mythos model in April, it reported that the model had autonomously identified and exploited previously unknown vulnerabilities across every major operating system and browser, and chained them into working exploit sequences. That is real, it is verified by people outside the company, and anyone telling you frontier models are just fancy autocomplete has not been paying attention. Capability is not the thing being oversold.</p><p>What is being oversold is intent.</p><p>Read the fine print of the very reports that generated the panic. When Anthropic disclosed last year that its models had been used in an espionage campaign, the details undercut the headline. A human operator picked the targets. Of roughly thirty attempts, a handful worked. And the model lied &#8212; it fabricated credentials it had never obtained and routinely inflated its own findings, to the point that the attackers would have had to check its homework. Anthropic&#8217;s own authors conceded this was an obstacle to genuinely autonomous attacks. A system that misreports its results to the people running it is not a mastermind. It is an unreliable subcontractor with root access.</p><p>This is the distinction the public conversation keeps collapsing. We are not facing an adversary that understands what it is doing and chooses to harm us. We are facing an optimizer that has no model of what we meant, only of what we measured. Machine learning researchers have documented this for a decade under the unglamorous name of specification gaming. Given a boat race and a reward for collecting points, a system learns to spin in a circle hitting the same three targets forever rather than finish the course. It is not cheating. It has no concept of cheating. It found the shortest path to the number you asked it to make bigger.</p><p>Now give that same disposition a network, a credential store, and an instruction to find complex attack paths.</p><p>Why does the diagnosis matter? Because the two stories point at completely different remedies, and we are currently buying the wrong ones. If the threat is a hostile intelligence, the response is to make the model itself more refusing &#8212; better guardrails, more alignment training, a smarter conscience baked into the weights. That is where enormous effort is going. But guardrails are a property of the model, and the Hugging Face incident happened precisely because a company chose to turn them down, in an environment it wrongly believed was sealed. One security researcher, Jake Williams of IANS Research, called the isolation claim &#8220;either a cop out or a marketing strategy,&#8221; and suspected a straightforward control failure in the lab.</p><p>If instead the threat is a powerful, literal-minded system that will reach whatever goal you name by whatever route exists, the response looks like ordinary engineering discipline: real network segmentation, credentials that expire and can be revoked, permissions scoped so tightly that a runaway process cannot reach anything that matters, and logging good enough that you learn about the breach from your own telemetry rather than from the victim. Boring work. Nobody announces it at a keynote.</p><p>There is a policy gap here that deserves more attention than it is getting. Almost every AI rule now under discussion governs how models are released to the public. Very little of it touches what the AI companies do with their own systems internally &#8212; which is exactly where this month&#8217;s failure occurred. The most dangerous models in the world spend their early lives inside the labs that built them, subject to whatever containment that lab decided was sufficient. We regulate the loading dock and leave the factory floor to the honor system.</p><p>None of this makes the alarm-raisers villains, and I am not persuaded by the cynical read that these disclosures are simply marketing. Publishing that your own model broke into a competitor&#8217;s servers is a strange way to sell a product.</p><p>But the alarm is pointed at the wrong thing. The fear on offer is of a machine that understands us well enough to want our downfall. The reality is a machine that does not understand us at all, cannot tell us reliably what it has done, and will take any door we forget to lock.</p><p>We keep handing it the keys and then acting surprised about which door it opened.</p><div><hr></div><p><a href="#_ftnref1"><sup><span>[1]</span></sup></a> <sub>For the happily uninitiated, FUD stands for Fear, Uncertainty and Doubt and is a pejorative term long used in the cyber security community for apocalyptic warnings about cybergeddon used primarily as sales strategies.</sub></p><p><a href="#_ftnref2"><sub><span>[2]</span></sub></a><sub> Again for the uninitiated, Michael Fish was a much-loved British weatherman of the 1980s. Close to retirement, he said on live TV that he&#8217;d received a call from a woman saying a hurricane was on the way. He told everyone not to worry. You can guess </sub><a href="https://www.youtube.com/watch?v=eKPQLl5rupg"><sub>what happened next</sub></a><sub>.</sub></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ciaran's Crispy Cogitations is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[On the matter of the British Library cyber incident]]></title><description><![CDATA[The most important lesson to figure out is why it is taking so long to restore services. That will tell us how to prevent such a calamity in other vital national institutions.]]></description><link>https://ciaranmartin.substack.com/p/on-the-matter-of-the-british-library</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/on-the-matter-of-the-british-library</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Sat, 20 Jan 2024 10:21:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XH44!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!XH44!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!XH44!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg" width="650" height="350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:350,&quot;width&quot;:650,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:62827,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!XH44!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d58c67a-c331-4809-ac1b-aebc24dfe323_650x350.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/on-the-matter-of-the-british-library?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/on-the-matter-of-the-british-library?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><h4>Introduction, apology, caveat, and then another apology</h4><p><em><strong>The introduction: </strong></em>For nearly three months, the British Library has been close to unusable because of what has invariably been called "a cyber incident&#8221;. Lots of people have asked me in recent months: &#8220;what on earth is going on with the BL and why isn&#8217;t it getting more attention?&#8221; </p><p>At the start of this week, the BL <a href="https://www.theguardian.com/books/2024/jan/15/british-library-begins-restoring-digital-services-after-cyber-attack">announced </a>the partial restoration of its capabilities. So it seems a good time to take stock of one of the most impactful cyber incidents in British history. </p><p><em><strong>The apology: </strong></em>This is the first post on this Substack for, well, a very long time. Apologies to those who supported me when it started. Many of you will know there were various circumstances which meant 2023 was a hard year for me to sustain it. I won&#8217;t make any promises about how often I will post, but I will try to reactivate it, based on an article at least once a month. Consider this January&#8217;s offering. And feedback on content and ideas for more is always welcome.</p><p><em><strong>The caveat: </strong></em>This post is based open-source information, my own judgments, and nothing else. I used to run the UK&#8217;s National Cyber Security Centre, but I stopped doing that in 2020 and left public service. I have not asked former colleagues about the case. Nor have I spoken to the British Library. No one should assume anything I say here reflects the position of the Government or any part of it. </p><p><em><strong>The other apology. </strong></em>Pursuant to that caveat, I am acutely conscious that this is an article about an extremely hard-pressed organisation trying its best to serve its users under the most extraordinary pressure. Being at the centre of a cyber crisis is absolutely horrible. It normally also means something has gone wrong, somewhere. In commenting on some of those potential causes of the problems, I do not mean to criticise those working flat out to fix things. I apologise if any of this post inadvertently comes across that way. Indeed I&#8217;d want to thank BL staff for what appears to have been an extraordinarily effort in a long slog to get to this important recovery point this week. I would encourage anyone else commenting on this or other cyber incidents to remember the human beings at the centre of the crisis. <a href="https://static.rusi.org/ransomware-harms-op-january-2024.pdf">A paper from the Royal United Services Institute</a> this week rightly identified psychological damage to staff as a consequence of these types of attacks. We should always remember this.</p><h4>What happened at the British Library?</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!4Zom!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!4Zom!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg" width="650" height="350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:350,&quot;width&quot;:650,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!4Zom!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6200ae1-4604-4bd7-aa98-bc8019534e78_650x350.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To the issue at hand, and first, some facts. In early January, Alex Scroxton at the indispensable <em>Computer Weekly</em> <a href="https://www.computerweekly.com/feature/British-Library-cyber-attack-explained-What-you-need-to-know">wrote a superb overview of the British Library cyber incident</a>. In the interests of brevity, the following points are the most important:</p><ul><li><p>on the last weekend of October, the British Library fell victim to what it called, inevitably, a &#8216;cyber incident&#8217;, acknowledging disruption to its services; </p></li><li><p>serious disruption to services continued throughout November, with all the hallmarks of a ransomware attack (for the uninitiated, this is when a hacker locks you out of your network and demands payment to let you back in, normally via cryptocurrency);</p></li><li><p>towards the end of November the fact that this was ransomware was confirmed. A new(ish) criminal group calling itself <a href="https://www.theguardian.com/technology/2023/nov/24/rhysida-the-new-ransomware-gang-behind-british-library-cyber-attack">Rhysidia </a>claimed the attack on their (so-called dark) webpage. In doing so they confirmed this event was also what is known as &#8216;<a href="https://www.zscaler.com/resources/security-terms-glossary/what-is-double-extortion-ransomware">double extortion ransomware</a>&#8217;; that is when the demand for payment to decrypt the network is accompanied by a threat to release stolen data from the network, or sell it to other criminals, if the ransom isn&#8217;t paid;</p></li><li><p>Rhysidia listed the ransom and the price of the stolen data set at 20 bitcoin. At the time, this was worth about &#163;600,000. With presumably no ransom paid, and presumably no buyer (the data is worth far less than &#163;600K to a criminal; the awful bluff that is data extortion is a subject for another day) Rhysidia then dumped 573GB of British Library corporate data, including staff details, onto the dark web;</p></li><li><p>as 2023 gave way to 2024, the costs of the crisis both to the BL and its users became more and more apparent, as the disruption continued. <a href="https://www.ft.com/content/4be5d468-0cc3-4881-a5fb-b5d0163de93e?sharetype=gift">The </a><em><a href="https://www.ft.com/content/4be5d468-0cc3-4881-a5fb-b5d0163de93e?sharetype=gift">Financial Times </a></em>reported that the BL would have to burn through nearly half its reserves to cover the costs, which, at an estimated &#163;6m-&#163;7m, were some ten times the demanded ransom. Meanwhile, <em><a href="https://www.theguardian.com/books/2024/jan/06/authors-missing-borrowing-royalties-british-library-cyber-attack">The Guardian</a></em><a href="https://www.theguardian.com/books/2024/jan/06/authors-missing-borrowing-royalties-british-library-cyber-attack"> reported</a> on the plight of authors who missed out on valuable royalties payable when their books were borrowed. Media coverage of what was a disaster for academic research went <a href="https://www.newyorker.com/news/letter-from-the-uk/the-disturbing-impact-of-the-cyberattack-at-the-british-library">global</a>; </p></li><li><p>the BL this week <a href="https://blogs.bl.uk/living-knowledge/2024/01/restoring-our-services-an-update.html">announced </a>a partial restoration of the main catalogue, but in read-only, and therefore much less useful, form. So the crisis continues, but this is a significant mitigation for users. </p></li></ul><p>Two key points flow from these events. The first is that it can safely be inferred that neither the BL nor anyone else paid the ransom (though no one has, to my knowledge, commented officially on this). If the ransom had been paid but the criminals had failed, for whatever reason, to restore access to the BL&#8217;s network we would know about that by now, one way or the other. </p><p>The second, and most important part of the whole story, is that for more than two and a half months this vital national resource has been essentially unusable. At the start of the crisis it seems that nothing at all worked: the basic staff computers, the phones, and even the public Wi-Fi for a bit. But the longer term damage was caused by the total inaccessibility of the main BL catalogue, described by the BL&#8217;s boss itself as &#8220;one of the most important datasets for researchers around the world&#8221; with its record of some 170 million items dating back centuries. </p><p>A particular problem is understood to be that most of the collection is stored in a <a href="https://gigazine.net/gsc_news/en/20231114-every-library#:~:text=The%20majority%20of%20the%20approximately%20170%20million%20items,in%20West%20Yorkshire%2C%20in%20the%20north%20of%20England.">giant facility belonging to the BL in West Yorkshire</a>. Users are supposed to order from the catalogue and the item will be transported south in a few days. Without the catalogue, this became impossible. Whilst some workarounds could be done in the BL&#8217;s magnificent London headquarters, if the text you wanted was in Yorkshire, and it probably was, no one had any way of knowing where it was, and how to get it. </p><p>Although plenty of people have asked why this episode hasn&#8217;t received more national attention, it is clearly one of the worst cyber incidents in British history. So what are the lessons of it?</p><p>For me, there are three. None are new, but not all of them receive enough attention. And the last one needs to resonate thunderously throughout all organisations. </p><h4>Lesson 1: The perpetrators are in Russia. They will likely never appear in a British court. We have to work within this reality</h4><p>The British Library cyber crisis has nothing and everything to do with geopolitics. Nothing, in that the only motivation for it is money. Everything, in that the only reason it can happen with impunity is because the Rhysidia group, like nearly all the major ransomware groups, are based in Russia. </p><p>It is well documented that the Russian state has no interest in shutting these groups down and putting the leaders in prison, providing they don&#8217;t harm Russian interests and cooperate with the state when required. <a href="https://tass.com/politics/1640023">It is against current Russia law for the state to extradite its own citizens</a> (this must be the first time I&#8217;ve linked to <em>Tass</em>). So these people are almost certain never to appear in a British court, and very unlikely to face even a Russian one anytime soon.</p><p>But, like all comparable democracies, the British state is configured to treat this type of incident as an arrestable and prosecutable crime. &#8220;Cyber crime is just the same as other crime&#8221; is something I heard a lot from law enforcement colleagues in Government. But there is one crucial difference. For the first time in human history, it is possible to inflict sustained, large-scale criminal damage on another country without the perpetrator or a single accomplice setting foot in it. </p><p>We have consistently underestimated just how much cyber crime breaks our model of policing. In rule of law democracies, the contract between citizen and police is based in part on an assumption that when someone is a victim of crime, the police will pursue the perpetrator. And with cybercrime, there are some in the UK we can go after. And with the Russians, every so often <a href="https://www.axios.com/2022/08/26/hackers-take-holidays-summer-cyberattacks">some idiotic cyber criminal goes on holiday to a Western country</a>, or <a href="https://www.nationalcrimeagency.gov.uk/news/hacker-from-russian-crime-group-jailed-for-multi-million-pound-global-blackmail-conspiracy">contracts for a criminal service with someone in East London,</a> and the police can do what police are supposed to do.  But these are the exceptions.</p><p>What police forces are doing increasingly well - normally via multinational operations led by the FBI - is orchestrating <a href="https://edition.cnn.com/2023/08/29/politics/fbi-dismantled-network-hacked-computers/index.html">takedowns of digital infrastructure used by the criminals.</a> But these interventions, while welcome, are invariably whack-a-mole operations and the criminals reappear in another guise with new infrastructure. </p><p>Can anything be done? Things got so bad in 2021, with the <a href="https://www.techtarget.com/whatis/feature/Colonial-Pipeline-hack-explained-Everything-you-need-to-know">attack on Colonial Pipeline</a> in the US, alongside serious healthcare disruption in the US and <a href="https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf">Europe</a>, that President Biden used his <a href="https://www.zdnet.com/article/biden-and-putin-spar-over-cybersecurity-ransomware-at-geneva-summit/">Geneva summit with Vladimir Putin</a> in June of that year to demand Russia clamp down on the rampant ransomware crime emanating from its territory. For a brief period, this seemed to have some effect, with the somewhat <a href="https://www.bbc.co.uk/news/technology-59998925">theatrically broadcast arrest of the REvil gang</a>, one of the most notorious groups. </p><p>But then came the invasion of Ukraine. A dictatorship willing to defy the White House over the invasion of a neighbour is unlikely to be swayed by American demands about criminals on its own territory. And a West that would support Ukraine but not take direct military action on its behalf is not going to take direct action against individuals protected within Russia&#8217;s vast borders. Both the Russian state and the criminals know that. </p><p>Therefore, the brief period when some of Russia&#8217;s ransomware thugs flew a bit too close to the sun and became a nuisance to the Kremlin is now over. All the evidence of 2023 suggests that the criminal safe haven has been fully restored. There will come a time in the future when Washington, London, Brussels and others can talk to Moscow about dealing with this scourge. But that time is not now, or soon. </p><p>It is of no benefit to pretend otherwise. Australia&#8217;s otherwise hugely impressive response to the disastrous theft by cyber criminals of more than a third of the population&#8217;s medical records  - <a href="https://www.economist.com/international/2023/12/31/how-ransomware-could-cripple-countries-not-just-companies">what I&#8217;ve called elsewhere (&#163;)</a> a masterclass in devaluing a stolen dataset to the criminal - provides a case in point. In a press conference in November 2022, the <a href="https://www.afr.com/politics/federal/data-breaches-surge-as-minister-warns-against-paying-ransoms-20221110-p5bxac">head of the Australian Federal Police</a> claimed the identities of the hackers were known to the AFP and pledged to bring the perpetrators to justice in Canberra via cooperation with Russian law enforcement. Any reasonable Australian watching could have concluded the police thought they had a good chance of locking up the villains. But, as was widely predicted at the time, this has not happened, and there appears next to no chance that it ever will. </p><p>It is always hard for Governments and public authorities to admit they can&#8217;t do something, especially when the &#8216;thing&#8217; is being able to catch and convict criminals who&#8217;ve laid waste to something that&#8217;s very important to lots of citizens. But the lesson from Australia, the British Library, and countless other ransomware crises is that normal policing doesn&#8217;t work in most of these cases because the suspects are safely holed up in Russia. </p><p>So we should stop pretending that conventional policing can do much about this, and look instead at other things we might be able to do.  This article is long enough already without prescribing in detail what the approach should be: that is for another day. However, here are three starting points:</p><ul><li><p>in the short term at least, serious policy needs to eschew basing our strategy on fantasies of &#8220;striking back&#8221; or &#8220;imposing costs&#8221; on criminals who just want to make money and currently shelter in the world&#8217;s largest safe house. Impose costs when we can: there are things we can do to harass and harry cyber criminals. But this will not be a strategic solution for as long as the Russia safe haven exists;</p></li><li><p>the question of ransom policy and law cannot be avoided forever. The UK&#8217;s <em>de facto </em>position is that state bodies like the British Library will never pay, but private entities can, with no questions asked (even if the Government pretends to discourage them). This stands in marked contrast to Britain&#8217;s uncompromising approach to terrorist kidnappings, where ransoms are never paid, whatever the (sometimes terrible) consequences. But the Government has yet to publish any analysis or evidence as to why it takes a hardline approach for kidnaps and a soft one for cybercrime. Indeed, it doesn&#8217;t really have a cyber ransom policy at all (a detailed look at the ransom policy question is an issue for another article, but policymakers must take a hard look at it);</p></li><li><p>nor does the state really have a counter-ransomware strategy. A rich seam of possible policy measures to explore has been provided by Parliament&#8217;s <a href="https://committees.parliament.uk/publications/42493/documents/211438/default/">Joint Committee on National Security Strategy</a> report of December 2023. The Government could do worse than start there.  </p></li></ul><p>Many of the reforms in that report have merit and deserve consideration. But the Committee&#8217;s overarching point is that countering ransomware needs serious political leadership and attention. </p><h4>Lesson 2: The BL case perfectly exemplifies the sort of area where the UK is most vulnerable to cyber disruption </h4><p>That sort of strategic review of our approach to ransomware requires us to look hard at our own national vulnerabilities. Here the BL crisis provides some valuable lessons.</p><p>Harm happens in cyberspace because we have a three decades-long legacy of weak security in our software, hardware and wider digital infrastructure. Famously, <a href="https://finance.yahoo.com/news/father-internet-vint-cerf-says-143006405.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAAHVN1FswS977Yt0D50Fs9DNP5lI0WHut1KeHn5auFHK5J5miUko8MSLKxJL9K7xQhc_8q6l6WxEPhMIk6OZd-YdMQOPatWPrNwVDcPlSzYDy6qzGQ3f0Jdd2D39bheW1ccc63zZaz-f_jvCpeCvHJblNiLbBuvpWymFhv9MZalCO">the Internet was not built with security in mind</a> - and we&#8217;re plagued with poor incentives for providers and users to do anything about it. That is slowly changing, but it is improving much more for newer technologies more than for our existing tech stack. </p><p>As all IT security professionals know, legacy systems in old organisations pose the hardest problems. There are no really transformative options until new systems come along. There are only mitigations. These mitigations require a lot of high quality technical and human resources. So they are expensive. They also require a lot of skilled people, as well as management attention and sponsorship. But it&#8217;s hard to explain the benefits of these measures to hard-pressed management facing many other pressures. And security reforms are often unpopular with staff and users because they add complexity to everyday work.</p><p>So it&#8217;s easy to see why some organisations are incentivised to take cyber security and resilience seriously, and some aren&#8217;t. Any service where public safety is at risk will invest heavily in security, safety and resilience, and test it all the time. The system and the organisation will probably be inspected. A regulatory license to operate might well depend on that evaluation. Put simply, no one should ever do something where their physical safety is dependent <em>only </em>on a computer staying connected, and most regulatory systems rightly don&#8217;t allow this. </p><p>So, for example, when part of the <a href="https://www.theguardian.com/world/2023/aug/30/uk-air-traffic-control-failure-what-caused-it-and-who-will-have-to-pay">UK&#8217;s National Air Traffic Control system failed (accidentally) last August</a>, there was no risk to safety to the planes already in the air because of the way much-tested backups work. Because the air traffic control system is such an obvious part of critical national infrastructure it is highly likely that Government agencies will pay attention to and assist with the cyber protection and resilience of the service. Similarly, in the private sector, banks invest heavily in cyber security capabilities and people because they know the risks of large scale financial loss are existential. Moreover, they can afford to. And the Government and regulator will want to help too, to avoid systemic risk within the financial system. </p><p>But consider the British Library in this context. It is a very important national institution, for sure. But if you&#8217;re tasked with identifying the most important national IT networks for protection against attack, the British Library will not get anywhere near the top of the list for attention. As we have seen, no one gets hurt or dies if the BL goes down. The health service will still function. So will the banks. The lights will still be on. People&#8217;s bills will still be accurate. The data of vulnerable populations will not have leaked. And so on. </p><p>As a cultural institution, the BL is important and famous. It also a <a href="https://www.gov.uk/government/organisations/british-library">public body</a>. It is not, however, a political or budgetary priority. Constrained by public sector budgets and salaries, it will find it hard to source the people and capabilities it needs for cyber security (<a href="https://www.telegraph.co.uk/business/2023/03/30/ex-gchq-chief-treasury-cyber-security-job-advert-salary/#:~:text=The%20posting%20for%20the%20head,starting%20salary%20of%20%C2%A3450%2C000.">the British Treasury was widely mocked</a> for advertising for a head of cyber security with an annual salary of between &#163;51,000 and &#163;57,000 when the industry standard is multiples of that figure). It is hard to imagine the BL being able to pay more, or finding it easy to recruit cyber security professionals. </p><p>This matters, because it is within hundreds of networks like the one the BL depended on that serious national risk lies. </p><p>The history of cyber security is pockmarked with warnings of <a href="https://www.economist.com/leaders/2010/07/01/cyberwar">mass casualty digital apocalypses</a> threatening civilisation as we know it. It turns out that&#8217;s the <a href="https://www.jstor.org/stable/26593685">wrong problem</a>: as the <a href="https://direct.mit.edu/isec/article/46/2/51/107693/The-Subversive-Trilemma-Why-Cyber-Operations-Fall">brilliant work of Lennart Maschmeyer </a>has shown, hacking into, say, a power grid and depriving civilians of supply even for a short time via cyber means is possible, but it is painfully slow and hugely resource intensive for the aggressor. Moreover, for cyber security and other security reasons these systems are better protected than &#8216;normal business&#8217; networks, and have manual or other backups. That&#8217;s why cyber attacks don&#8217;t directly kill people.</p><p>It turns out, however, that our more immediate cyber security problem is that by crippling these so-called &#8216;normal business&#8217; networks an aggressor can hugely harm a society without that much effort. We now know <a href="https://www.darkreading.com/cyber-risk/colonial-pipeline-critical-infrastructure-operators-blind-cyber-risks">you can shut down a crucial oil pipeline in the United States</a> not by attacking the pipeline, but by shutting down the ordinary software systems that support its administration. It turns out you can <a href="https://www.hhs.gov/sites/default/files/lessons-learned-hse-attack.pdf">cripple the entire healthcare system of a rich EU nation</a> not by touching hospital equipment or systems but by locking out the network of the body that allocates doctors appointments and schedules surgeries. And it turns out that you can bring part of the British academic sector to a crashing halt by taking a massive library catalogue offline. </p><p>So what else can an aggressor do to networks that don&#8217;t look to be of &#8216;strategic&#8217; importance? That is that question we should be asking ourselves in the light of the BL fiasco. We should then be moving resources, expertise and monitoring accordingly as best we can. We also need to think about how we better incentivise the leaders of these organisations to improve basic security and resilience, because ransomware attacks are not, in general, sophisticated.</p><p>This is an election year in the UK, and after the votes are counted we can expect someone to try to form a stable administration with a five year horizon. Much is made of short-termism in politics, but we have to work with the world as it is, not as we&#8217;d like to be. In that spirit, here are two planning assumptions on national cyber risk for the next five-year Parliament: </p><ol><li><p>a devastating, highly sophisticated, threat-to-life cyber attack against the UK in the next five years is <em>unlikely</em>, and if it happens, its impact will be mitigated so long as we continue to ensure that safety-critical systems are not wholly dependent on computer networks; </p></li><li><p>by way of contrast, serious economic and social disruption, including an incident that could threaten public order or safety arising from a cyber operation (the disruption of healthcare administration, the criminal justice system, or food or oil distribution being some examples) is <em>very likely. </em>Indeed, an incident of the severity of the BL attack is <em>likely in each of the next five years. </em> </p></li></ol><p>This lesson of national vulnerability from the BL case, and these assumptions, would make a good starting point for the sort of serious discussion about ransomware that is urgently needed. </p><h4>Lesson 3: Organisations, whether public or private, must be able to recover far more quickly than the BL did</h4><p>And the one thing above all else that would make a difference to the problem is finding a way of forcing organisations to be able to recover more quickly than the British Library did.</p><p>To understand why, we have divert back briefly to ransoms. As noted earlier, the British state doesn&#8217;t pay ransoms, and most other Governments don&#8217;t. Throughout this crisis the Government did not come under any serious pressure to pay (unlike, for example, the Irish Government during the healthcare cyber crisis of 2021 because of the huge impact on health services). </p><p>The private sector is another matter. Because there is no reporting requirement in most jurisdictions, including the UK, to report when a ransom has been paid, there are no reliable figures for how many organisations pay (the cyber security company <a href="https://www.coveware.com/blog/2023/1/19/improved-security-and-backups-result-in-record-low-number-of-ransomware-payments#:~:text=Over%20the%20last%204%20years,76%25%20in%202019.">Coveware </a>has made as decent a fist as any of tracking trends over time, and the latest figures show a significant decrease to fewer than half of organisations in 2022, down from seven out of every eight a few years earlier). </p><p>The blunt reason why the private sector often pays, but governments hardly ever do, is that Governments can throw far more resources and support at recovery. That was certainly the case in Ireland, where the military and a number of major cyber security companies were deployed with no expense spared. Private companies cannot afford to surge in capabilities like this, and they can&#8217;t call in the Army. And unlike the state, they can go bankrupt. </p><p>So for private organisations, paying can be more effective than not paying. In this case, the cost to the BL was far more than the ransom. This is not always the case: <a href="https://www.bbc.co.uk/programmes/m000xs0h">a BBC File on Four documentary</a> in 2021 tracked the impressive response of the Harris Federation of London, a major schools provider. They held their nerve and the overall cost to them was less than the ransom demanded. And paying does not mean avoidance of harm: Colonial Pipeline paid the ransom, but the pipeline was still out for several days. </p><p>But Governments do not want to pay ransoms and, certainly in Britain, it is unlikely that taxpayers want them to. The crucial point is that not paying the ransom only works if the organisation can recover quickly. </p><p>The heroic efforts of Irish healthcare workers, and IT professionals from the civil service, the military and the private sector got the system back up and running to some sort of basically acceptable level in a similar amount of time as it takes a victim who paid to recover. Similarly, the Joint Committee on National Security Strategy heard from the leader of Redcar and Cleveland about how staff from the National Cyber Security Centre <a href="https://therecord.media/british-government-minister-told-council-to-keep-quiet-after-ransomware-attack">slept in the council&#8217;s offices</a> during a ransomware crisis to ensure that the system dealing with the cases of at-risk children were recovered quickly. </p><p>Moreover, we need to ask ourselves: what if there is no ransom? What if a hostile hacker working for a nation state does exactly the same thing as a ransomware attacker, but the objective is to damage the UK by destroying the network, rather than to extort money by temporarily locking it? </p><p>In such a scenario, recovery is the only option.  Ransomware highlights our digital vulnerabilities to others who have motives even worse and more strategically damaging than the criminals. And if there is no effective system backup that can easily be deployed, or no way of restoring the old system in some way, - in other words, if there&#8217;s no way of recovering quickly - then we&#8217;re stuffed. Recovery capability is paramount for national security.</p><p>Here, the obvious point to make about the British Library is that it has taken - and is taking - an inordinately long time for its catalogue, one of its most important services, to be restored. That&#8217;s even, presumably, with help from Government experts and others. Of all the high profile ransomware cases throughout the world, it is hard to think of many that have dragged on for this long with this degree of severity. </p><p>This slowness to recover is the most painful and most important lesson from the British Library cyber incident. </p><p>There are, no doubt, very good specific reasons for it. A 170 million item catalogue is bound to be very complicated. A replica backup would no doubt be very expensive and hard to maintain. (And, as stated at the start, this analysis implies no criticism of those working round the clock and over Christmas to try to get services back up and running; it is impossible to retrofit a solution that did not exist before the crisis).  </p><p>But faced with the likelihood and potency of this threat to myriad public and private entities, we must no longer accept a situation where important national organisations, public or private, cannot withstand the lost of their enterprise computer network for such a long period of time. If we tolerate this, the likely consequences in terms of economic and social disruption will prove intolerable. Planning for the loss of a key network, and being able to recover quickly from it, needs to be a core part of good public and corporate governance that every organisation models and practices. </p><p>The way to get to this point is not to indulge in the classic British tradition of holding a what-went-wrong-and-who-can-we-hang-out-to-dry inquiry. This is not the Post Office IT scandal. There is not a single allegation of malice, bad faith or wilful negligence. Instead, an organisation with a reputation for being well-run and held in high public esteem found itself without the systems and plans in place to recover from being the victims of criminals. They deserve sympathy and support.</p><p>But we have to figure out why. What constraints were there, (and what incentives weren&#8217;t), that prevented this otherwise capable organisation from protecting itself and recovering quickly? Where else is this a risk? And what can be done about it?</p><p>The American answer to this conundrum has been to establish a <a href="https://www.cisa.gov/resources-tools/groups/cyber-safety-review-board-csrb">Cyber Safety Review Board</a>, based on the successful model in aviation safety. The aim is not to hunt for blame but to look at the rational explanations for why things went wrong and make constructive recommendations to address them. Such an approach could work in this case. The last thing we need are hours of theatrical hearings in a courtroom or committee room of Parliament, with exhausted witnesses defensive and humiliated. That makes for good TV and terrible public policy. </p><h4>Summary</h4><p>The UK has, by and large, suffered less major harm from ransomware than most comparable nations. But the British Library case is a warning. The critical lessons of it are:</p><ul><li><p>ransomware is now a national security issue, likely to cause significant and possibly dangerous disruption in the near future;</p></li><li><p>this requires a strategic national response, which, due to the Russia safe haven problem, has to be predicated on policing not being able to do what it normally does to deter and punish crime;</p></li><li><p>there are a bunch of useful policy mitigations on the table, which need to be brought together in a coherent way. This has to include a thought-through, publicly articulated posture on ransoms;</p></li><li><p>but once an attack gets through, the one thing that matters above all else is the ability of the victim organisation to recover quickly. All organisations, whether public or private, need to test their ability to withstand the loss of a key network and show that they can recover at least partially within an acceptable amount of time.  </p></li></ul><p>This work is not easy. But it is vital, and urgent. And it is doable, with the right focus and leadership. Otherwise, in the well-chosen title of the Parliamentary report, national security is a hostage to fortune. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/on-the-matter-of-the-british-library?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/on-the-matter-of-the-british-library?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Lessons from Down Under's Data Disasters Pt. 3 ]]></title><description><![CDATA[We still need to talk about ransoms. And do some serious policy work about them.]]></description><link>https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Tue, 17 Jan 2023 18:04:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Knft!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" width="810" height="540" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/adf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:810,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><h4><strong>Recap</strong></h4><p>This is the third in a five part series looking at the vast and varied implications of two major data breaches in Australia in the period September to November 2022.</p><p>The first post, which can be found <a href="/__u/ciaranmartin.substack.com/p/five-lessons-from-down-unders-data">here</a>, covered the background to the two breaches at Optus, a major telecoms company, and Medibank, a health insurer which covers nearly 10 million of Australia&#8217;s 26 million population. It also discussed how our failure to distinguish between the severity of different types of data breach has bred a degree of complacency about data security.</p><p>The second post on the lessons of these incidents for Governments and their role in cyber security can be found <a href="/__u/ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters">here</a>. </p><p>This third post analyses the issue of the the payment of ransoms. </p><p>The remaining posts in this series will cover:</p><ul><li><p>how we discuss and report cyber harms, and why that matters (Part 4);</p></li><li><p>the safe haven problem in cyber crime (Part 5).</p></li></ul><h4><strong>Lesson 3: sorry, but we still really need to talk about ransoms&#8230;</strong></h4><p><em>&#8230;whether it makes sense to pay, and, yes, whether it should be allowed</em></p><p>The Optus and Medibank data heists were accompanied by initial ransom demands of around ten million dollars. </p><p><em>Ten million dollars.</em></p><p>Yes, it was probably an opening pitch in a negotiation. </p><p>Yes, the Optus demand was apparently dropped, and Medibank, to their credit, didn&#8217;t pay. </p><p>But the fact that the demand was credibly set at ten million dollars shows we have normalised ransom payments, big and small.</p><p>In neither of these attacks was the actual operation of the company affected. In that respect, neither attack was even &#8216;proper&#8217; ransomware as we have traditionally understood it. </p><p>These were threats to publish data, not cripple the operations of a company. Serious situations, for sure, particularly in the case of Medibank, given the sensitivity of personal medical records. But they weren&#8217;t the equivalent of, for example, the <a href="https://www.bbc.com/news/world-europe-58413448">crisis </a>in Irish healthcare in 2021, when the national system for allocating healthcare stopped working, with devastating results for patients. </p><p>And yet the demand for such a huge sum seemed normal. </p><p>That&#8217;s because it was. </p><p>Ransoms are the oxygen of cyber crime. </p><p>They have become <em>the</em> source of income for some of the most effective cyber criminals. Ransomware earnings go far beyond the potential for monetising stolen data on the dark web, the original digital age criminal business model. </p><p>In 2021 the British firm <a href="https://www.elliptic.co/blog/darkside-ransomware-has-netted-over-90-million-in-bitcoin#:~:text=Elliptic%20was%20first%20to%20identify%20the%20Bitcoin%20wallet,to%20the%20East%20Coast%20of%20the%20United%20States.">Elliptic</a> traced $90 million of ransom payments to just one group - the Darkside group - in a nine month period. In December last year, a joint advisory from the <a href="https://www.spiceworks.com/it-security/cyber-risk-management/news/cuba-ransomware-update/#:~:text=According%20to%20the%20updated%20advisory%2C%20the%20Cuba%20ransomware,average%20ransom%20earned%20from%20each%20victim%20at%20%24600%2C000.">FBI and the Cybersecurity and Infrastructure Security Agency</a> said that the Cuba ransomware gang has extorted its way to more than $60 million, out of &#163;145 million demanded from more than one hundred organisations. </p><p>Chris Krebs, CISA&#8217;s founding head, has set out <a href="https://twitter.com/C_C_Krebs/status/1400529344213229572">three </a>reasons why ransomware has emerged as the pre-eminent cyber threat of our our times. First, there is endemically weak security in Western organisations. Second, Russia (and some other countries, but primarily Russia) provide a safe haven for cyber criminals. Third, the criminals&#8217; business model works. </p><p>Ransoms, along with low operating costs and low barriers to entry, are central to the criminal business model. And part of making that business model work (and these are my words, not those of Mr Krebs) is what I call a &#8216;pro-criminal narrative&#8217; around ransoms. In other words, too many times organisations are told, through a variety of means, that the easiest or indeed only way out of the lonely and difficult crisis they face is to pay. </p><p>So victims do pay, and the vicious circle continues. </p><p>You can take the view that there&#8217;s nothing to be done about this (give or take a bit of chasing after cryptocurrency payments). And you may be right. It&#8217;s a hard problem. </p><p>But perhaps a better starting point is to accept that allowing mostly Russian-based computer thugs to extort payments on this scale from law abiding companies with impunity on an ongoing basis represents an epic failure of global public policy.  </p><p>We might want to think harder about whether there is something we can do before giving up. </p><p>If, as the last piece in this series argued, cyber security is a much a policy, economic, social and legal problem as much as a computer network security one, then this is one of the hardest, but most important, policy challenges of all. </p><p>So we need to talk about ransoms. And then do some serious policy work. </p><h4>Why ransomware works </h4><p>Why does ransomware work for the criminals? Let&#8217;s take a look. </p><p>Below is the start of a statement by the meat giant JBS USA in June 2021. It is the main publicly available account from the company explaining why they paid $11 million -  <em>eleven million dollars</em> - to the REvil group, one of the main Russian ransomware groups.</p><p>It merits careful reading. </p><p> </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2ynF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2ynF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg" width="1169" height="999" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/aa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:999,&quot;width&quot;:1169,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:184763,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!2ynF!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faa91ff89-f0a5-42fb-9805-110a405a3f9d_1169x999.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>The opening of JBS&#8217;s explanation of its 2021 decision to pay $11m in ransom</em></p><p>There are essentially two different problems to which paying a ransom is seen as the answer. </p><p>The first is to get systems that are not working to work by decrypting them. That is how ransomware has conventionally worked: the victim&#8217;s system doesn&#8217;t work as users are locked out, so the organisation cannot function. It must therefore buy a decryptor key to get back in to the network.</p><p>But in this case, JBS said that &#8220;at the time of payment, the vast majority of the company&#8217;s facilities were operational&#8221;. </p><p>The second reason, increasingly common (often alongside the first, though in the Medibank case it appeared on its own) is to prevent the publication of sensitive data. Essentially it&#8217;s &#8220;give us the money or we publish all your data&#8221;. </p><p>But in this case, the company says that the payment was made before data was exfiltrated, and indeed cites preventing the <em>exfiltration </em>(not publication) of data as a reason for paying. </p><p>The justification for paying <em>eleven million dollars </em>is &#8220;to mitigate any unforeseen issues&#8221; and &#8220;prevent potential harm to our customers&#8221;. </p><p>To be clear, JBS were perfectly entitled to take this entirely lawful decision. And, it may well have made sense to the company&#8217;s leaders for reasons they chose not to disclose.  But, based only on the publicly available information the decision makes no sense (as a <a href="https://www.secureworld.io/industry-news/-jbs-meat-pays-11-million-ransom-to-hackers">handful of people </a>tried to point out at the time). </p><p>Moreover, note the intriguing reference to the advice of internal and third-party cybersecurity experts. Despite - if we take the company&#8217;s statement at face value - the absence of either disruption or data loss - the advice was to pay to make the problem go away. Again, this may have been perfectly reasonable to those with full knowledge of the case, though - again - it is not justified by the presentation of the facts alternatively. </p><p>But it is a powerful example of just how strong the incentives to pay are. </p><p>This is what I mean by a pro-criminal narrative. </p><p>If what happened at JBS happens at scale, continuously, then we&#8217;re stuffed. </p><p>JBS is perhaps an extreme example: in most of the known cases where victims pay there is a clear and obvious reason to pay. It&#8217;s either because the network is locked, or the criminals are threatening to publish data.</p><p>Still, it is apparent that in far too many cases the answer - however the advice is gathered and the decision is taken - is to pay. </p><p>Research presented today by at the SANS/UK National Cyber Security Centre Cyber Threat conference in London by Ifigenia Lella of the European Union&#8217;s cyber security agency ENISA <a href="https://www.enisa.europa.eu/publications/enisa-threat-landscape-for-ransomware-attacks">disclosed </a>that some 60 per cent of organisations paid the ransom in more than 600 cases analysed by the agency. This is the latest among a great deal of research about the prevalence of paying. </p><p>It is understandable. Victims of serious crime - which is generally committed from jurisdictions beyond the reach of domestic law enforcement - will want a way out of the problem as quickly and efficiently as possible. No one likes paying criminals, and no one should blame desperate victims for doing so. That&#8217;s especially the case when they&#8217;re told that the way out is to pay. </p><p>But this leaves us with the classic public policy problem where individual and collective interests collide.  </p><p>What might make sense for individual entities is a recipe for serious collective harm. </p><p><em>That</em> is a failure of public policy. </p><p>So are there different ways of doing things? </p><h4>It doesn&#8217;t always have to be like this, and sometimes it isn&#8217;t </h4><p>Not every organisation pays, and not every organisation suffers critical harm when they refuse to pay.</p><p>So it&#8217;s worth analysing some of the better known cases where victims chose not to pay, to see what we can learn. Here are three.</p><p><em>The Health Service Executive in Ireland, 2021</em></p><p>The first is the Irish healthcare system. Crippled by Conti ransomware in 2021, the Irish state faced <a href="https://www.thejournal.ie/cyber-attack-ransomware-5441367-May2021/">numerous calls</a> to pay in the light of the &#8216;double extortion&#8217; problem - the severe damage to the provision of healthcare caused by being locked out of the system, combined with the threat of the disclosure of population level personal health data. </p><p>Eventually, the hackers backed down and provided the (only partially functional) decryptor key for free. (Why they did that is unknowable. Some ransomware operators steer clear of healthcare and abandon the operation when it becomes clear they&#8217;ve done over a hospital. In this case, speculation was rife that either the Kremlin and/or other ransomware operators were furious with Conti for engaging in such a venal attack so publicly, thus shining a light on this often quietly lucrative criminal enterprise). </p><p>What is interesting is not so much why the criminals backed down, but why the Irish Government held firm. </p><p>Even with the national healthcare system in crisis, the Government of the Irish State had to take the totality of the national interest into account. Had the decision been left solely to the affected body, the Health Services Executive, the incentives would surely have pointed towards paying. That&#8217;s why American hospitals pay all the time - their duty is only to their patients and their owners. But in Ireland, the decision was taken at whole of Government level, because the affected body was a public authority. The Irish State took the view that letting the world&#8217;s cyber criminals know that the Irish Government paid up carried even greater risks overall than those they were already facing with the crisis in healthcare. </p><p>Moreover, the full resources of the state could be directed at pace to support the stricken service. Irish Defence Force experts and American commercial expertise were swiftly brought in as the state threw the kitchen sink at the problem.</p><p>In the 2020s it has become increasingly common to talk of ransomware as a <a href="https://www.nbcnews.com/politics/national-security/they-are-hair-fire-biden-admin-mulling-cyber-attacks-against-n1269575">national security threat</a>, at least when it comes to operations against critical infrastructure. But for the most part, Governments leave the absolutely critical decision on whether or not to pay entirely to the affected organisation. <a href="https://www.cnbc.com/2021/06/08/colonial-pipeline-ceo-testifies-on-first-hours-of-ransomware-attack.html">Colonial Pipeline</a> is a good example of that; the American company shut down its pipeline which provides much of the East Coast&#8217;s gasoline and paid the ransom, leaving the federal Government to invoke emergency procedures to ensure supply, but the recovery up to the company. </p><p>Letting companies pay and leaving them to recover is, of course, entirely consistent with their status as private entities. But, when the incident has consequences which could be regarded as meeting the threshold of national security -  as it surely is when energy supplies or healthcare is compromised - it is not consistent with treating ransomware as a national security threat. It is subcontracting one of the most critical decisions - whether or not to pay the attacker - to a private entity. </p><p>Put it this way, if someone bombed a pipeline, it would be seen as a national security issue for the Government to lead on. Why is shutting down the pipeline via a cyber operation different? If a hospital is stopped from functioning, should it really depend on <em>how </em>it happened to determine who is responsible for the response? </p><p>Ireland is an easy an example to focus on because the victim organisation was a public authority and therefore the Health Services Executive had no choice but to follow the decision of the Government not to pay. It is obviously much more complicated when the victims is a private company, even if it is providing a vital public service.</p><p>But Governments should think of the problem like this. If the decision to pay is left entirely in the hands of a single private entity, expect that entity to consider only its own interests, imperatives and duties. Do not expect the private company - voluntarily, without legal compulsion - to evaluate the wider public interest at the expense of its own priorities. That would be wholly unreasonable. </p><p>In other words, if policy doesn&#8217;t change, expect your critical national infrastructure companies to pay ransoms, at least some of the time. </p><p>And, consequently, expect the criminals to come back for more. </p><p>And, consequently, expect more critical services disruption from ransomware. </p><p><em>The Harris Federation of Schools in London, 2021</em></p><p>A different example involves the Harris Federation of some 50 London schools, ransomwared in April 2021. It, too, is instructive, but for a different reason. And a fascinating overview of it, courtesy of BBC Radio, can be found <a href="https://www.bbc.co.uk/programmes/m000xs0h">here </a>(a 30 minute listen).</p><p>Throughout the attack, the Federation&#8217;s schools remained largely operational, though there were some impacts (for example, at one school, Internet-controlled gates would not open and had to be manually over-ridden). But the organisation was nonetheless badly affected, being unable to pay invoices, for example. </p><p>The initial ransom demand came in at $4million. This was completely unaffordable for Harris, which is a charity. Professional negotiators managed to get the demand down to south of $1 million. </p><p>But the organisation still decided not to pay. It looked coolly at the situation. Its main educational mission was continuing because that did not depend completely on the network. The computer network was already very badly damaged and would take time and money to recover, even with a decryptor key. Harris were cognisant of advice that not all decryptor keys work perfectly, and about 5 per cent don&#8217;t work at all. They knew there were other ways to recover.  </p><p>So they held firm. Eventually, they calculated the cost of recovery at around $600,000; cheaper than the final ransom demand of $750,000. </p><p>It is not always cheaper and easier to pay. </p><p><em>The Medibank breach in Australia</em></p><p>This brings us to the Medibank case in Australia.</p><p>It is not hard to see that paying the ransom looked like an attractive option to Medibanks&#8217;s leaders, given public concern at the potential exposure of nearly ten million private medical records. </p><p>But, as the company presumably realised, extortion based on denying the availability of service and extortion based on the breaching the confidentiality of data are two completely different things. In the case of the former, the attacker can continue to lock out the victim, causing ongoing disruption. And the attacker has a clear &#8216;product&#8217; to sell: the decryptor key. So there is a clear and obvious transaction to make. </p><p>In the case of extortion based on threatening to breach confidentiality through a data dump, this is not the case. Rather that a &#8216;positive&#8217; action in return for money - the provision of the key - the victim is attempting to pay for a &#8216;negative&#8217; action: not disclosing data, in perpetuity. &#8216;Guarantees&#8217; that stolen data has been deleted cannot be verified. </p><p>As the cyber security firm <a href="https://cyware.com/news/ransomware-gangs-are-now-leaking-stolen-data-more-often-a43085c6">Coveware</a> put it in a 2020 study showing that some victims who had paid had seen either data released anyway, or had a further extortion demand levied later on: </p><p><em>&#8220;once a victim receives a decryption key, it can&#8217;t be taken away and does not degrade with time. With stolen data, a threat actor can return for a second payment at any point in the future.&#8221;</em> </p><p>Furthermore, the dynamic is different in such cases because the network is still functional. Medibank may have been plunged into a serious crisis but, unlike the Irish Health Services Executive, its ability to arrange healthcare for its customers was unaffected. </p><p>Finally, as ever, the victim and wider society has agency in how it responds. As the next post in this series will explore, Australia handled the disclosure of medical data as threatened by the attacker&nbsp;deftly. A grown up conversation between the Government, the company, the media and socia media ensured responsible reporting of the leak, containing the harm to individuals and blunting the severity of the disclosure threat from the criminals. In both Ireland and Australia, public fears that personal health data would be <em>easily</em> available did not materialise.  </p><h4>Three cases, two lessons</h4><p>Not for the first time in cyber security, details matter. Setting even legality and ethics aside, and focussing just on the practicalities and business realities of the situation, in both the Harris Federation and Medibank cases, it made sense not to pay the ransom. </p><p>Two separate questions arise from these three cases:</p><ul><li><p>Question 1: <strong>the law.</strong> What should the law be around paying ransoms? Should payments remain legal, and who should take the decisions on paying? </p></li><li><p>Question 2: <strong>the narrative.</strong> Assuming that, at least for now, paying ransoms remains legal, how can we reduce the incentives to pay? </p></li></ul><h4>Question 1: The law</h4><p>Whether or ransomware payments should be prohibited has been one of the most vexed issues in contemporary cyber security policy. </p><p>The <a href="https://securityandtechnology.org/wp-content/uploads/2021/09/IST-Ransomware-Task-Force-Report.pdf">Ransomware Task force</a> - a US led group of international experts spanning the public and private sectors - conspicuously failed to agree on this topic amidst a welter of unanimous, useful recommendations. This is not to criticise them: it&#8217;s an enormously complex and contentious subject, and to their considerable credit they set out (at page 49 of their report) a balanced account of the debate on both sides. Indeed this published, accessible, and reasonable analysis, based on expert input, is more than any Government I know of has produced on the subject. </p><p>The UK Government has said nothing discernible at Ministerial level on the subject. This is in marked contrast to the British state&#8217;s robust, two-decade long policy on banning ransom payments to designated terrorist organisations for kidnaps <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/540539/CTS_Bill_-_Factsheet_9_-_Kidnap_and_Ransom.pdf">via primary legislation with extra-territorial effect</a>. Terrorism and cyber extortion are two very different issues, but the UK Government has not said why it takes such different approaches to the two when it comes to ransoms.</p><p>The US&#8217;s position <a href="https://home.treasury.gov/news/press-releases/jy0471">appears</a> to be that ransom payments are legal, unless they are paid to groups designated under the Office of Financial Assets Control (OFAC).  Some individual hackers and well-known cyber threat groups are designated under OFAC, and so in theory paying them is illegal. However, many cyber criminal groups are not covered. And for those that are, extensive mitigations are set out in the US Government&#8217;s guidance. Moreover, as <a href="https://therecord.media/15-of-2020-ransomware-payments-carried-a-sanctions-violations-risk/#:~:text=Around%20one%20in%20six%20ransomware%20payments%20in%202020,Chainalysis%2C%20a%20company%20specialized%20in%20analyzing%20blockchain%20transactions.">Recorded Future</a> have set out, knowing whether or not criminals demanding ransoms are on a sanctions list is beyond many smaller organisations. RF&#8217;s report estimated that 15 per cent of payers in 2020 may well have breached US Treasury rules by paying ransoms. So it is hard to see the logic of these rules, or how they can effectively be enforced.  </p><p>For most of the rest of the western world, the policy on ransom payments is not to have a policy. More than that, it&#8217;s not to even think about having a policy.</p><p>It&#8217;s a hard question, for sure. So it&#8217;s understandable that Governments want to duck it. But if they do, they should expect nothing to change.  </p><p>In July 2021, the American cyber security expert Tarah Wheeler and I tried to set out an <a href="https://www.brookings.edu/techstream/should-ransomware-payments-be-banned/">analytical framework</a> for thinking about the law on ransoms from initially opposing perspectives (she instinctively opposing prohibition of payments, me instinctively favouring it).  </p><p>We agreed that a simple outright ban with no mitigations would likely prove a disaster. To have a chance of being workable, a ban would have to be accompanied by significant guarantees of support, probably from the state, to be effective. </p><p>We also looked at the misalignment of incentives, responsibilities and information that encourage so many to pay.</p><p>Our conclusion was this: </p><p><em>&#8220;if a ban on ransom payments is to be a credible part of a strategy to stop the flow of money to such criminals, then surely an essential precondition is more effective state intervention in the response to attacks, reflecting the gravity of the problem as a national security threat&#8221;.</em> </p><p>Having set out how such interventions might be developed and tested, we continued:</p><p><em>&#8220;Whether or not payments are banned, a more activist approach is needed anyway, even if it means legislating for more interventionist levers over privately-owned critical infrastructure.&#8221;</em>&nbsp; </p><p>A huge part of the ransomware problem relates to policy. The reasons why it&#8217;s outstripped other forms of cyber harms are not technical or operational: they&#8217;re about the business model.  </p><p>To go back to Chris Krebs&#8217;s <a href="https://twitter.com/C_C_Krebs/status/1400529344213229572">triplet</a>, countering ransomware means taking on the criminal groups operationally, improving cyber security at home, and also breaking the business model. </p><p>And this last part needs policy solutions. </p><p>Policy is normally formulated at least in part via the gathering of evidence, and formal expert consultation. </p><p>Yet Governments, when they comment at all, usually say simply that a ban on ransom payments won&#8217;t work. But no Government (to my knowledge) has tested the proposition properly through any recognisable, publicly disclosed policy evaluation process. </p><p>Some of the arguments against a ban are very powerful (threat to life situations in healthcare, for example, and the perverse outcomes that would arise from exempting the healthcare sector). But others do not bear up to scrutiny.</p><p>For example, one common argument against a ban is that it would drive payments underground. As Troy Hunt, the Australian cyber security expert, has <a href="https://twitter.com/troyhunt/status/1592363103571742721">argued</a>, this is essentially saying that company directors would knowingly and willingly break the criminal law. There is absolutely no evidence to support this claim: plenty of company directors dislike the EU&#8217;s General Data Protection Regulation but that doesn&#8217;t mean they&#8217;ll consciously ignore their reporting requirements under pain of prosecution.  </p><p>Furthermore, whether a ban is workable or not, policies on responding to ransomware incidents need further development. Specifically, returning to the lessons of the Irish and American healthcare examples, what is the balance between the public and private sectors when public safety is endangered by the compromise of a private entity? Should companies in critically important (and therefore already heavily regulated) sectors have a duty to report breaches? Is there a case for going even further and requiring them to consult, or even seek the consent, of the Government before paying? And if not, aren&#8217;t we just <a href="https://www.prospectmagazine.co.uk/science-and-technology/privatised-cyber-security-hackers-ciaran-martin-gchq-revil-darkside">privatising national security risk</a>? </p><p>This is complex, contentious stuff. The point is that all of the arguments for and against a ban, and other policy measures need to be tested in a formal process of policy evaluation and consultation. </p><p>What we have at the moment on the ransomware business model - and ransoms in particular - is policy inertia, justified by assertion.  </p><h4>Question 2: The narrative</h4><p>That&#8217;s not good enough, but it is where we are. </p><p>Therefore, given the ransom policy inertia in most capitals, it is a prudent assumption that in the short term at least, the legal position in most countries will remain as it is. </p><p>Therefore, Governments, along with the wider cyber security community, must work harder to change the pro-criminal narrative that paying is often the best option.</p><p>It is easy for public authorities to &#8216;advise&#8217; companies not to pay. That advice is genuine but, to a company in serious crisis, it is often meaningless. Governments understand this, and sometimes the don&#8217;t pay &#8216;advice&#8217; is accompanied by thoughtful nods indicating that the authorities understand if the organisation takes the &#8216;wrong&#8217; decision. </p><p>That is why stories like the Harris Federation&#8217;s gloriously stubborn refusal to pay - and saving money in the process - are so important. It is why understanding that extortion for availability and extortion for data protection are completely different things is so important.  It&#8217;s why the <a href="https://blog.barracuda.com/2021/11/04/dont-pay-the-ransom-a-three-step-guide-to-ransomware-protection/">Barracuda</a> research that 80 per cent of organisations who paid got hit again is so important. It&#8217;s why research such as that by <a href="https://www.hiscoxgroup.com/news/press-releases/2022/08-11-22">Hiscox Insurance</a>, which shows that 29 per cent of victims of data extortion who paid up still had some data leaked is so important. </p><p>It&#8217;s also why the national dialogue in Australia about how to report and discuss the Medibank fiasco responsibly is so important (the subject of the next post in this series in two week&#8217;s time). </p><p>We have to shift the pro-criminal narrative. </p><h4>Conclusions: the case for a substantive, inclusive, expert policy review  </h4><p>A holistic approach to ransomware will bring together operational and policy measures across like-minded allied nations. </p><p>President Biden&#8217;s 30 nation strong counter-ransomware group has announced a range of <a href="https://edition.cnn.com/2022/10/31/politics/ransomware-hacks-hospitals-critical-infrastructure/index.html">operational activity</a> to try to mitigate ransomware. These measures absolutely have their place and we must hope they make the desired breakthroughs. </p><p>But ransomware is as much of a policy problem as it is an operational one, if not more so. </p><p>Yet when it comes to policy, Governments are mostly asserting that policy changes won&#8217;t work. But they&#8217;re doing that without engaging in the normal process of expert engagement, evidence gathering, and evaluation of options. </p><p>They are vindicating the age-old bureaucratic saw that doing nothing is <em>always </em>an option.  </p><p>The case for substantial policy and legal changes to counter ransomware is not yet made. But nor is the case for dismissing the options without carefully examining them. There is a compelling case in many countries for a substantive, open-minded, consultative policy review of counter-ransomware policy options. This should be debated, published, and then - depending on the outcome - action should follow. </p><p>And in the meantime, there is a compelling case for a renewed effort to shift the narrative away from the criminals. </p><p>By telling the stories that show that paying doesn&#8217;t always pay.</p><p>We can and must do better. </p><h4>Coming up next in the series</h4><p>The fourth part in this series, on the way Australia managed the disclosure of data in the Medibank breach, will be published in early March. </p><p>In the meantime, there may be one or two other posts on other subjects on this Substack page.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters-78c?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p><h4></h4><p></p>]]></content:encoded></item><item><title><![CDATA[Some constitutional cogitations from Cardiff]]></title><description><![CDATA[The aggressive Anglocentric British nationalism of the post-2016 period doesn't work for the wider UK, especially Northern Ireland. I looked at why, and what might instead.]]></description><link>https://ciaranmartin.substack.com/p/some-constitutional-cogitations-from</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/some-constitutional-cogitations-from</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Thu, 22 Dec 2022 10:07:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cm36!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cm36!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cm36!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg" width="575" height="322" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:322,&quot;width&quot;:575,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Hadyn Ellis Building takes shape - News - Cardiff University&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Hadyn Ellis Building takes shape - News - Cardiff University" title="Hadyn Ellis Building takes shape - News - Cardiff University" srcset="/__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!cm36!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6e10b7d5-737e-41d5-b03d-d8a344c29014_575x322.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/some-constitutional-cogitations-from?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/some-constitutional-cogitations-from?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><h4>Background to this post</h4><p><em>On 22 November I was invited by the First Minister of Wales, Rt. Hon. Mark Drakeford MS, to give a lecture at the Hadyn Ellis building at the University of Cardiff. It is part of a series of lectures he and his team are hosting on the constitutional future of the United Kingdom. </em></p><p><em>The text of my talk is published below. At some point a video of the event, including the question and answer session afterwards, will be published online.</em></p><p><em>For now, here is the text of the lecture. (As always, a check against delivery caveat when the video comes out).</em></p><p><em>A point on timing. This lecture was delivered exactly one month ago today. It was delivered the day before the Supreme Court ruling that the Scottish Parliament did not have the power to hold an independence referendum. It was also delivered before the launch of the report containing proposals for constitutional reform by the former Prime Minister, Rt. Hon. Gordon Brown, and before the publication of the interim report of the Independent Commission on the Constitutional Future of Wales. However none of these developments alter the fundamental arguments in the lecture. </em></p><h4>Text of lecture - check against delivery </h4><p>I am really honoured to be here with you this evening. Thank you for the privilege.</p><p><em>[audience specific introductory remarks omitted]</em></p><p>My main message tonight is aimed at those who want to see a reformed, multinational UK.</p><p>Your moment might well be coming.</p><p>But meaningful, durable reform is a lot harder than it might look.</p><p>And it might be the last chance for it, given the strength of forces on each side:</p><ul><li><p>those who wish to bring the UK in its current form to an end;</p></li><li><p>and those who wish to roll back devolution in favour of a much more singularly British, unitary form of Government.</p></li></ul><h4>You wouldn&#8217;t start from here: legacy of the last decade</h4><p>Let&#8217;s start by looking at the situation a decade ago in 2012. (This was when I was working on the constitutional brief in Whitehall). </p><p>As Leighton Andrews of this parish has <a href="https://onlinelibrary.wiley.com/doi/full/10.1111/1467-923X.13044">observed</a>, we&#8217;d just had Danny Boyle&#8217;s opening ceremony for the 2012 Olympics.</p><p>This was what Leighton called &#8220;the emotional and cultural high point&#8221; of what he called &#8220;progressive unionism&#8221;: confident, respectful, inclusively multinational.</p><p>Although a referendum in Scotland had been conceded and agreed following the SNP landslide of 2011, support for independence was so low &#8211; hovering between 25 and 33 per cent &#8211; that few seriously thought the UK was going to break up.</p><p>Indeed, the agreement to the referendum was seen as a confident and respectful acknowledgement of Scotland&#8217;s participation in a voluntary union.</p><p>I also remember pointing out to David Cameron the extraordinary statistic that support for the Union in Northern Ireland was even higher than in Scotland, with 65 per cent, as against 17 per cent for unification. The Executive in Belfast was in one of its longest periods of continuous existence. Relations between London and Dublin were strong. </p><p>The one poll done in Wales during that period found 3 per cent support for independence, rising to 10 if Scotland left. Wales had continued on its path of gaining losers&#8217; consent following the division of 1997, and was seen, from the outside anyway, to be working well.</p><p>No one was seriously contemplating leaving the EU: it remained, for the Coalition, as for John Major&#8217;s Government, a case of managing querulous backbenchers.</p><p>Inter-governmental relations were decent. The Joint Ministerial Committee occasionally met, and, while I don&#8217;t want to rose-tint the past, it sometimes even had useful discussions.</p><p>Much of the Coalition&#8217;s constitutional efforts (other than on the Scotland campaign) were spent trying to improve things in England&#8217;s regions, (though the chosen mechanism, City Deals, seemed to involve raising money from local areas and giving it back to them with huge strings attached in return for relatively tiny freedoms and small amounts of cash, and calling it decentralisation). &nbsp;</p><h4>You wouldn&#8217;t start from here: where we are now</h4><p>Ten years on, the only unchanged feature from that landscape is that Whitehall and English localities are still wrangling over pitiful amounts of money and the devolution of weak powers. Whitehall still has more than one hundred central &#8216;pots&#8217; or funds, including, and I am not making this up, one for removing chewing gum in local areas, and another for improving public toilets.</p><p>But other than that, everything else has changed.</p><p>What the whole of the UK now has in common with the situation in England is that the constitution is stuck.</p><p>And, particularly in Scotland and Northern Ireland, it is stuck in a tense and polarising way.</p><p>In Scotland, the 45 per cent vote for independence has turned into a floor, not a ceiling, for independence.</p><p>Now, independence is the all-consuming issue.</p><p>One side shouts: &#8220;you had your chance in 2014&#8221;.</p><p>The other yells back: &#8220;but Brexit!&#8221;.</p><p>And round we go again.</p><p>Northern Ireland is definitely stuck and tense, something I will return to later, at the organisers&#8217; request.</p><p>Is Wales stuck? You tell me and I hesitate to comment in front of this audience. Again, from the outside, things look relatively stable.</p><p>Devolution is doing its job: Wales can do things differently in certain areas from a Westminster Government that doesn&#8217;t have a majority here.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Fxac!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Fxac!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg" width="600" height="400" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/afe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Rt Hon Mark Drakeford MS: First Minister of Wales | GOV.WALES&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Rt Hon Mark Drakeford MS: First Minister of Wales | GOV.WALES" title="Rt Hon Mark Drakeford MS: First Minister of Wales | GOV.WALES" srcset="/__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Fxac!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fafe10a3c-1041-427f-93da-a7b643d1c14e_600x400.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>First Minister of Wales Mark Drakeford spoke of a UK Government &#8220;hostile to devolution&#8221; </em></p><p>But I can&#8217;t help but be struck by the remark by the First Minister in July last year that he considered, for the first time this century, we had a UK Government in his words &#8220;hostile to devolution&#8221;.</p><p>And I can&#8217;t help but note that the excellent Leighton Andrews article I cited earlier is entitled &#8220;The Forward March of Devolution Halted&#8221;.</p><p>And across the UK, inter-governmental relations have certainly been scratchier.</p><p>So what is going on?</p><h4>Centralising tendencies: it&#8217;s hard to let go</h4><p>Part of it is to do with the enduring strength of centralising forces in the UK.</p><p>The groundhog day debate and reforms around localism in England under Labour, Coalition and Conservative Governments over the past 20 years prove this.</p><p>So too does the fact that devolution changed Government everywhere in the UK &#8211; <em>except</em> Whitehall.</p><p>London still struggles with devolution, as we saw in the pandemic.</p><p>But much more fundamentally than that, we now have three competing visions for the future of the UK.</p><p>The first vision is simple enough: to bring it to an end through independence (or unification, in the case of Northern Ireland). That doesn&#8217;t &#8211; yet &#8211; have the numbers to achieve its objective.</p><p>The second is the vision of an increasingly devolved UK: the one architected in the late 1990s and now seeking renewal via vehicles such as Mr Brown&#8217;s commission and the one under the leadership of Lord Williams and Professor McAllister. I will return to the challenges facing such efforts at the end of this talk.</p><p>The third vision receives far too little attention given its strength in Westminster.</p><p>It has been driving much of the constitutional redesign of the UK since the 2016 vote to leave the EU.</p><p>This is sometimes called muscular unionism, or &#8211; incorrectly &#8211; English nationalism.</p><h4>Anglocentric British nationalism: a clunky phrase for a powerful force</h4><p>Although it&#8217;s a clunky phrase, a better description of it is one I picked up from the former Labour Cabinet Minister John Denham, though he denies authorship.</p><p>It&#8217;s Anglocentric British nationalism.</p><p>And here are four characteristics of it:</p><ul><li><p>First, it considers that there is really only one nation and it is a British one. Westminster sovereignty is all; hence the hostility to the EU. It&#8217;s majoritarian: for example, it doesn&#8217;t matter if whole chunks of the UK don&#8217;t buy into its form of Brexit, because it has the numbers to face down inconvenient dissent. That those numbers are drawn largely from England makes it Anglocentric;</p><p></p></li><li><p>Second, for the Anglocentric British nationalist, devolution is, in Boris Johnson&#8217;s word, a &#8220;disaster&#8221;. There shouldn&#8217;t be real alternative centres of real power to Westminster. Sporting and cultural national identities are fine, but not real power. For as long as devolution cannot be reversed, it must be contained. However, in the words of Lord Frost, devolution can &#8220;evolve back&#8221;, as the Johnson Government showed with the UK Internal Market Act;</p><p></p></li><li><p>Third, Anglocentric British nationalism pushes back on the idea of the UK as a voluntary union. It talks of the UK as a unitary state &#8211; correct in legal terms but politically highly contested, including here in Wales. That is why Anglocentric British nationalism refuses not just the present demands for another referendum in Scotland, but to engage in any discussion as to how and when another one might be held;</p><p></p></li><li><p>Finally, there is an inherently transactional nature to it. It is happy to remind the rest of the United Kingdom not of the joys of partnership, but of the costs of leaving. For that reason, I sometimes call it &#8216;know-your-place unionism&#8217;. &nbsp;&nbsp;</p></li></ul><p>Anglocentric British nationalism successfully secured a hard Brexit for Great Britain.</p><p>Its record in driving the devolution agenda is more mixed.</p><p><em>Its</em> symbolic high point, so far, was the refusal of Liz Truss to speak to the devolved administrations&#8217; leaders for the entire duration of her short premiership.</p><p>The new administration, thankfully, seems less interested in this type of approach.</p><p>But Anglocentric British nationalism is still a powerful force.</p><p>As a result, devolution is no longer a one-way street, if ever it was.</p><p>It can evolve back, and some people want it to.</p><p>And this vision of the UK&#8217;s future, whilst not particularly popular right now, will not go away.</p><p>And it still matters, particularly with regard to the paralysis in Northern Ireland.</p><h4>Northern Ireland: where Anglocentric British nationalism doesn&#8217;t work</h4><p>Anglocentric British nationalism has been, and remains, a disaster for Northern Ireland.</p><p>Contemporary Northern Ireland is based on three things.</p><p>First, affirmation of its legitimate place as an integral part of the United Kingdom, but with a right to leave it and join the rest of Ireland, depending on the majority&#8217;s will. That was unionism&#8217;s great triumph of 1998: acceptance of the legitimacy of the Northern Ireland state by plebiscite throughout the island. But that acceptance depended on compromise. </p><p>Second, a key part of that compromise was smooth economic and social relations with the rest of the island of Ireland, reflecting the traditional minority&#8217;s desire for as close ties as possible. </p><p>Third, and - again - a part of this compromise, power-sharing, devolved Government based on cross-community support.</p><p>Anglo-centric British nationalism, and the form of Brexit it gave rise to, crashes up against all three of these pillars of contemporary Northern Ireland.</p><p>First, it imposes a view of British sovereignty that is at odds with the 1998 Agreement. The Protocol Bill, that article of faith among Anglocentric British nationalists, states the supremacy of the 1800 Act of Union.</p><p>But, as Dr Andrew McCormick, who led for the Northern Ireland Civil Service on Brexit, has <a href="https://consoc.org.uk/publications/the-belfast-good-friday-agreement-and-brexit-by-andrew-mccormick/">written</a>, under the 1998 Agreement, endorsed by referenda on both sides of the Irish border, supremacy is given to the people of Northern Ireland, not to a 222 year old statute, which, under the Diceyan interpretation of the constitution so beloved of Anglocentric British nationalists, has no particular standing above the 1998 Agreement or other statutes in general. &nbsp;</p><p>Under the Agreement, the people of Northern Ireland have the right decide whether they want to remain in the United Kingdom or join an all-island state.</p><p>For Dr McCormick, that means that Mrs Thatcher&#8217;s totem that Northern Ireland is &#8220;as British as Finchley&#8221;, recently re-stated by the Foreign Secretary using his own constituency in <a href="https://www.newsletter.co.uk/news/politics/protocol-latest-northern-ireland-as-much-part-of-the-uk-as-essex-says-foreign-secretary-as-he-fields-questions-on-return-to-violence-3919657">North Essex</a>, is a nonsense.</p><p>People in North Essex do not have the right to join another state, or to hold the passport of another country. There are no joint institutions with another sovereign state responsible for parts of the governance of North Essex. All of these things, by treaty and Parliamentary statute, are in place for Northern Ireland.</p><p>The 1998 Agreement is one of the foundational documents of the modern UK.</p><p>It <em>explicitly</em> acknowledges that the UK can be broken up, and that some of its constituent parts should have highly exceptional forms of local administration.</p><p>It is highly unusual, as some unionists point out, for a state to provide for its own breakup. But the United Kingdom does.  </p><p>Once that principle has been established, everything else is a matter of degree.</p><p>The simplicity of Anglocentric British nationalism cannot be accommodated within this complex mosaic.</p><p>Second, withdrawal from the Single Market completely changes the nature of North-South relations.</p><p>The 1998 Agreement did not mention the EU because it did not need to. The entry of both the UK and the Republic of Ireland into the Single Market in 1993 transformed economic relations on the island, particularly in border areas, even before the ceasefires and the removal of border security apparatus.</p><p>Crucially, as well as reducing trade friction on the island, joint single market membership on the island was a significant cultural and economic moment.</p><p>As John Hume pointed out repeatedly at the time, the reduction in the emphasis on binary&nbsp; national identity mattered hugely. The sense that being primarily British or Irish was of less importance in the age of greater European integration was profoundly important to the historically minority nationalist community.</p><p>Along with the removal of discrimination against Catholics in the 1970s, and the introduction of power sharing in 1998, joint participation in the European Single Market with the rest of Ireland was one of the three reasons why Northern Ireland&#8217;s traditional minority community reconciled itself to the Northern Ireland state and voted overwhelmingly - even if some of its leaders won&#8217;t say it out loud - to recognise its legitimacy. </p><p>The shock at the removal of the single market - without consent - is still palpable in this community.</p><p>Finally, given this, Brexit, and particularly withdrawal from the Single Market, was a fundamental change in the governance of Northern Ireland.</p><p>History would suggest that fundamental change in Northern Ireland is best done, as in 1998, with cross-community support.</p><p>But cross-community support was never, could never, and will never be given for Brexit.</p><p>Inevitably, the subsequent attempts to exempt Northern Ireland from aspects of Brexit to reduce the impact on cross-border relations has led to the opposite problem: the withdrawal of consent for power sharing in the unionist community.</p><p>All this has proved is that, in the words of Tom McTague of <em>The Atlantic, </em>(a writer not unsympathetic either to Brexit or to Northern Ireland&#8217;s unionists)<em> </em>Brexit has led to a set of problems in Northern Ireland that<a href="https://www.theatlantic.com/international/archive/2022/05/eu-brexit-role-in-northern-ireland/629905/"> &#8220;cannot be solved, only managed&#8221;.</a></p><p>That means there are no easy answers, and no perfect one. So what to do?</p><p>Stronger local leadership must be part of the answer. But tonight I want to look at what the UK Government, as the sovereign power, should think about.</p><p><em>First</em>, the UK Government must recognise Northern Ireland for as it now is, rather than what it might appear doctrinally in a simplistic, post-Brexit, sovereignty first way.</p><p>The lead of unionist parties over nationalists in first preference votes at May&#8217;s Assembly elections could fit into Windsor Park stadium, one of international football&#8217;s smallest venues.</p><p>Both unionism and nationalism are now minorities. The future will be decided by the non-aligned.</p><p>At the moment, the non-aligned break decisively for the Union, were there to be a referendum on unity.</p><p>But they do not break for sovereignty-first British nationalism.</p><p>Northern Ireland used to vote this way. </p><p>In 1987, in the first general election after the Anglo-Irish Agreement which unionists reviled for giving Dublin a consultative role in Northern Ireland, unionists implacably opposed to the deal won more than 55 per cent of the vote.</p><p>Now <a href="https://www.belfasttelegraph.co.uk/news/politics/lucidtalk-poll-59-call-for-dublin-role-in-northern-ireland-if-assembly-not-restored-42141195.html">polls </a>suggest that if the Assembly is to remain moribund, 60 per cent support some form of role for the Irish Government.</p><p>Moreover, a clear majority in the Assembly were returned last year on manifestos to support some form of Protocol arrangements.</p><p>Unionism may hate the Protocol, and that matters.</p><p>But political unionism is no longer a majority, and that matters too. &nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hnBx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hnBx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;EU Referendum: NI Remain vote declared - BBC News&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="EU Referendum: NI Remain vote declared - BBC News" title="EU Referendum: NI Remain vote declared - BBC News" srcset="/__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hnBx!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F94ef527d-b1cb-4ddc-8d12-beed79bcdcfb_1920x1080.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>The Brexit vote in Northern Ireland. Note that not a single border area voted to leave. Indeed, at present, no constituency touching the border is represented at Westminster by a unionist.</em></p><p>The present &#8216;majority&#8217; in Northern Ireland, insofar as there is one, expects to remain in the UK for some time to come. It wants governmental arrangements that will work, for however long that is.</p><p>But this &#8216;majority&#8217; is perfectly happy for Northern Ireland to be treated differently from the rest of the UK, and indeed sees some advantages to such arrangements.</p><p>So Northern Ireland is not North Essex, and doesn&#8217;t want to be.</p><p>But this does not, of course, solve the current problem of unionist consent, the piece that is currently lacking.</p><p>So the <em>second</em> part of the answer, which may seem unsatisfactory and incomplete but I think is important, is about process.</p><p>Process matters.</p><p>In an outstanding <a href="https://ukandeu.ac.uk/northern-ireland-protocol-process-still-matters-in-northern-ireland/">paper </a>for the UK in a Changing Europe think tank in August, Sir Jonathan Stephens, recently retired Northern Ireland Office permanent secretary and key protagonist in many of the key negotiations of the past quarter century, wrote that &#8220;the process around the Protocol has been fundamentally flawed because the key players who need to accept and work with the outcome &#8211; the parties in Northern Ireland &#8211; have never properly been involved&#8221;.</p><p>He noted that in the run up to the Agreement 25 years ago, the advice to British Ministers was that the process they oversaw was far more important that any specific solutions. And an important part of that process was, despite clear and obvious differences, London would treat Dublin as a partner, not as an opponent.</p><p>From this sort of inclusive process, solutions might emerge. Without it, we cannot know what solutions will stick.</p><p><em>Third</em>, the problem must be treated now as a Northern Ireland issue first and foremost, rather than a consequence of negotiations between the UK and the EU.</p><p>Trade is, of course, the major part of the technocratic dimension. And that&#8217;s a London to Brussels issue.</p><p>But we have to remember that Brexit fundamentally ruptured Northern Ireland politics because it removed the Europe-wide framework where binary national identities mattered less.</p><p>You cannot solve a political crisis about identity, consent, all-island relations, relations between the islands, relations between communities, and much more &#8211; with chilled meat protocols or reciprocal arrangements for veterinary standards. &nbsp;</p><p>The EU will continue to have concerns about the integrity of its single market. But it&#8217;s increasingly obvious it will want to support something that could command genuine cross party support in Northern Ireland. &nbsp;</p><p>Fourthly, and this is the biggest hurdle to overcome, all this requires a rebuilding of trust. Over the course of the last year, trust in the UK Government to deal with the protocol, as measured by Queen&#8217;s University, has nearly <a href="https://www.qub.ac.uk/News/Allnews/2022/public-support-protocol-increases.html">doubled </a>&#8211; to 7 per cent.</p><p>It is not hard to figure out why trust is so low. We had:</p><ul><li><p>a Secretary of State during the referendum campaign assert that leaving the EU would not affect arrangements in Northern Ireland;</p></li><li><p>a Prime Minister in 2019 assert that his deal was similarly benign for Northern Ireland;</p></li><li><p>and a later Secretary of State on New Year&#8217;s Day in 2021 assert there was no sea border just as film footage of new inspections were being broadcast on TV the very same day.</p></li></ul><p>Really substantive progress, in my view, is impossible for as long as the line from London remains that Brexit is no big deal when it comes to Northern Ireland.</p><h4>Beyond Northern Ireland: challenges for the UK&#8217;s reformers</h4><p>It may be, therefore, that change in approach might need to await a change of Government, (though on the other side of the Irish Sea the seismic prospect, though not the inevitability, of a Sinn F&#233;in led Government in Dublin from 2025 might act as an incentive for more urgency).</p><p>In any case, I hope that the example of Northern Ireland &#8211; unique as it is, shaped by a tragic and brutal recent history thankfully absent from the rest of the United Kingdom &#8211; is enough to show that a simplistic application of post-Brexit, sovereignty-first, Anglocentric British nationalism is not the right approach for at least one part of the UK.</p><p>The question now arises as to what&#8217;s next for the rest of the United Kingdom.</p><p>In that context, let me return to the second group seeking to shape the future of the UK: the reformers.</p><p>I detect great excitement in this community that, with the polls as they are, and reformers on the brink of outlining new plans for a reconstituted UK, tensions within the territorial constitution will dissipate in the next Parliament.</p><p>And that will sweep away Anglocentric British nationalism from its position of influence within the UK Government.</p><p>And in doing so, it will weaken support for separation, especially in Scotland.</p><p>That may be so.</p><p>But looking beyond that timeframe, it is also credible to think of this as the last chance for meaningful reform of the UK in its current form.</p><p>Consider this outline of the future.</p><p>There&#8217;s a change of UK Government in 2024.</p><p>A Labour or Labour-led Government introduces constitutional reforms designed to strengthen devolution.</p><p>A Westminster Conservative opposition, hardening against devolution out of office, as it did over Europe after its 1997 defeat, opposes those reforms and pledges to reverse them.</p><p>The economic inheritance of the new Government proves too tricky: it is short-lived and in the late 2020s or early 2030s a form of Conservatism that is much more anti-devolution than before comes into power.</p><p>The argument of 2024 in Scotland (and possibly Wales) that you don&#8217;t need independence to protect you from a Conservative Government you didn&#8217;t vote for falls away, along with the new constitutional reforms.</p><p>In the meantime, let&#8217;s assume that because of these political difficulties there has been no significant movement in national sentiment in either Scotland or Northern Ireland.</p><p>But demographics are taking their course, so support for leaving the UK is rising. And in Scotland, it&#8217;s now not far off the point where a &#8216;generation&#8217; has actually passed since 2014.</p><p>In this scenario, the 2030s <em>could </em>see a winner-takes-all contest for the future of the UK, with the middle ground nowhere to be seen. </p><p>That&#8217;s why what happens in the rest of this decade <em>could</em> be the last chance for reform.</p><h4>Conclusion: the case for reform, and making it</h4><p>So what might reform involve? Here are some brief concluding thoughts.</p><p><em>First</em>, there are plenty of areas where there is scope for imaginative reform.</p><p>Issues like immigration and trade need to be settled on a UK wide basis but there is no reason why there cannot be mechanisms for greater consideration of interests across the UK in setting those policies.</p><p>The fiscal frameworks are less lopsided than they were when they were designed in the 1990s, but they still contain many disincentives for the devolved nations to use the powers they have.</p><p>The mooted ideas for rebalancing the upper House might gain traction.</p><p>In the other direction, surely we might learn from Covid about how better to coordinate crises &#8211; that might even mean understanding when it makes sense for Westminster to take some powers back in return for better consultation and coordination with devolved administrations about how to use them.</p><p>There is much still to explore in terms of how the governance of the UK works.</p><p><em>Second</em>, meaningful reform must contain some proposals for agreeing a mechanism on how the constituent parts of the UK can leave if they want to.</p><p>The position in Scotland is unsustainable: if the pursuit of independence is regarded as a legitimate political pursuit, then a way of achieving that must be provided.</p><p>At present, there is no such mechanism.</p><p><em>Third</em>, the process matters. This cannot any longer be a conversation among the non-English parts of the UK only.</p><p>But this is really, really hard.</p><p>England cannot forcibly be decentralised or broken up into regions it doesn&#8217;t recognise.</p><p>England resents when the other nations are seen to be able to dictate their place within the UK.</p><p>Again, there are no easy answers.</p><p>Can, for example, any of the suggested changes to the upper chamber be done in a way that strengthens non-English nations&#8217; role in UK wide life but is done in a way that commands England&#8217;s consent?</p><p>And now to the most important points.</p><p>Penultimately, is there a way of making changes permanent and enduring? I know Sir David Lidington, in an earlier address in this series, dwelt on this topic.</p><p>After a contested Brexit, and with the renewed strength of sovereignty-first British nationalism, many, including me, will be sceptical about the durability of any reforms beyond the lifetime of the Government that introduces them. I was no great fan of the Fixed Term Parliaments Act. But its fate is a reminder of how temporary constitutional reform can be.</p><p>Is there actually a way of ensuring the permanent powers of national institutions outside England given the doctrine of Parliamentary sovereignty?</p><p>That question is also really, really hard. But it is really, really important. </p><p>So serious, impactful, enduring reform will be difficult. And it could be the last chance.</p><p>But, my final point is that if these problems can be overcome, then their advocates should make the case for the reforms as a something good in their own right, not as a concession. .</p><p>If you think the UK is better governed as a multinational state under messy but workable arrangements, rather than in a singular, Anglocentric British nationalist way, then say so. </p><p>For too long the decentralisation of power outside England has been presented defensively: the &#8216;Vow&#8217; to Scotland in the dying days of the 2014 campaign being the most obvious occasion.</p><p>Contrast that with where I started.</p><p>The 2012 multinational union, comfortable in its multinational diversity, presented to the world in the Olympics had much to commend it.</p><p>Wales is perhaps uniquely suited to this proposition.</p><p>Its devolved arrangements have secured the consent of the many who did not originally want them.</p><p>It has the only devolved Government that can convincingly go to London saying it wants to make the UK work, even if political leadership is different.</p><p>Wales has a vibrant, non-political national life, shown by, among other things, the remarkable resilience, and now expansion, of the Welsh language.</p><p>Again, from an outsider&#8217;s perspective, if anywhere is to make the case for a thriving, multinational, reformable state, it is probably Wales.</p><p>So reformers should make their case. </p><p>In 2016, pro-Europeans found that if you&#8217;ve spent years presenting something in negative terms, boasting instead about how successfully you&#8217;ve used it to resist something else, then don&#8217;t be surprised when people aren&#8217;t particularly enthusiastic when you ask them to endorse it in its own terms.</p><p>If you&#8217;ve taken the trouble to work out how to do it, then make the case for it. If you believe in a devolved, respectfully multinational UK, then make the case for it in its own right, not as a way of stopping something else.  </p><p>Thank you for listening to me this evening. &nbsp;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/some-constitutional-cogitations-from?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/some-constitutional-cogitations-from?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Lessons from Down Under's Data Disasters, Pt 2]]></title><description><![CDATA[Many of the problems in cyber security are economic and social, not technical. And digitisation privatises public risk like never before. That's why Governments are increasingly required to step in]]></description><link>https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Tue, 20 Dec 2022 08:52:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Knft!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" width="810" height="540" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/adf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:810,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Recap</strong></h4><p>This is the second in a five part series looking at the vast and varied implications of two major data breaches in Australia in the period September to November 2022. </p><p>The first post, which can be found <a href="/__u/ciaranmartin.substack.com/p/five-lessons-from-down-unders-data">here</a>, covered the background to the two breaches at Optus, a major telecoms company, and Medibank, a health insurer which covers nearly 10 million of Australia&#8217;s 26 million population. It also discussed how our failure to distinguish between the severity of different types of data breach has bred a degree of complacency about data security.</p><p>The remaining posts in this series will cover:</p><ul><li><p>the payment of ransoms in cyber incidents (Part 3);</p></li><li><p>how we discuss and report cyber harms, and why that matters (Part 4);</p></li><li><p>the safe haven problem in cyber crime (Part 5).</p></li></ul><h4><strong>Part 2: Governments and the cyber security problem</strong></h4><p>This post covers the role of Government in cyber security. </p><p>Over the past decade, Governments have become increasingly active in this space. State operational capabilities have been improved in many countries. Critical infrastructure is increasingly regulated for cyber safety and resilience. Data protection laws abound. </p><p>But there&#8217;s a lot more to cyber security than this. </p><p>Many of the deeply entrenched problems in cyber security are rooted in economic, social and behavioural factors as well as technical and legal ones. Governments have, by and large, steered clear of many of these challenges or confined their interventions to the occasional toe dipped in the water. </p><p>A key underlying tension has been where public and privately owned risk collide, whether before or after an incident. This is where recent events in Australia are important. </p><p>In dealing with the Optus and Medibank breaches in late 2022, the Australian Government has been strikingly active. It has since signalled its desire for far reaching reform of the way the country does cyber security.  </p><p>This potentially accelerates a trend of increasingly interventionist Governmental behaviour across the West in recent years. That trend is uneven (and the United States, with its size, constitutional framework and the luxury of having most of its own tech run from its own jurisdiction, will always have its own, often different story). </p><p>But the wider trend towards Government activism in cyber security is unmistakable and important. And Australia is going to be a country to watch because of the apparent breadth of its ambitions, and its status as a key Five Eyes cyber power. </p><h4>The strikingly activist response of the Australian Government </h4><p>First, it is worth taking a look at what this activist response has involved so far. </p><p>It is an age old ritual, as old as cyber security itself and much mocked in the cyber security community, for a victim organisation to describe itself as being the target of &#8220;an unprecedently sophisticated attack&#8221;, or variants on those words. True enough, Optus duly used this line at press events on 22 and 23 September.</p><p>An essential part of the ritual is that it is not contradicted by Governments or the mainstream press. Cyber security professionals might poke fun at the &#8216;sophisticated&#8217; narrative on social media, but, by and large, it goes uncontested, feeding a sense that organisations are powerless when faced with hostile cyber activity.</p><p>This is where Australia broke with tradition. </p><p>On 26 September, Clare O&#8217;Neil, Australia&#8217;s Minister for Home Affairs and Cyber Security (one of the most senior positions in the Federal Government, which has seen the phrase &#8216;Cyber Security&#8217; added to it for the first time upon Ms O&#8217;Neil&#8217;s appointment in June) made a direct, forceful and accurate intervention. She said <a href="https://twitter.com/clareoneilmp/status/1574361824102711296?lang=en-GB">bluntly</a> that the operation was not sophisticated, adding that Australia &#8220;should not have a telecommunications provider in this country that has effectively left the window open for data of this nature to be stolen.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!c_6M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!c_6M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg" width="400" height="400" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21951,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!c_6M!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c7276-36a5-49a6-9242-74f8e6536ec4_400x400.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Australia&#8217;s Minister for Home Affairs and Cyber Security. Clare O&#8217;Neil</em></p><p>Moreover, as the incident developed, Optus came under increasing pressure to organise and pay for replacement passports for those affected by the compromise, some of the pressure coming publicly from the Federal Government. Canberra had no power to compel Optus to do this, but the company eventually announced it would, and agreed a process with the Government (as the issuer of passport documents) to arrange it. </p><p>Subsequently, Medibank provided a different challenge. The operation against the company appears to have been much more sophisticated and the company made no questionable claims about the sophistication of its provenance. There was no comparable issue to replacing passports. But given the extent of public concern about health records being publicised the Government, and Ms O&#8217;Neil specifically, took a very active role in communicating with Australians about who was responsible, what course the incident was likely to take, what risks people were exposed to, and what the Government would do in response (some of these points are explored later in this series). </p><p>Finally, taking both cases together, Ms O&#8217;Neil and her colleagues have signalled a willingness to revamp Australia&#8217;s national management of cyber security and develop a new strategy to deal with the problem. On 8 December, she <a href="https://minister.homeaffairs.gov.au/ClareONeil/Pages/expert-advisory-board-appointed-as-development.aspx">announced</a> a process to develop a new cyber security strategy <em>(full disclosure: I have accepted an invitation to be part of a group of unpaid international advisers supporting an Australian-led expert panel in developing this process. The Australian Government does not, and does not seek to, approve or influence anything I write on this or any other topic).</em> </p><p>The terms of reference of this strategic review are, as is the way with these things, reasonably short and therefore open to interpretation. However to date they imply a far reaching review that goes way beyond just &#8216;fighting the last war&#8217; and confining the process to a review of data laws. </p><p>The announcement speaks - intriguingly - of &#8220;increasing whole-of-nation cyber security efforts to protect Australians and our economy&#8221;. </p><p>This leaves in scope pretty much anything. But the direct reference to economic interests implies it will go beyond a narrow interpretation of national security or public protection interests. </p><h4>Why and how Governments are getting involved</h4><p>Why has it come to this?</p><p>In short, because we&#8217;ve struggled, mostly in vain, to delineate private from public risk in cyber security. And incentives are working against good cyber security in too many ways. And we&#8217;re suffering as a result. </p><p>In the middle part of the last decade, when setting up and then running the UK&#8217;s National Cyber Security Strategy, my team and I wrestled for months - years - with the question of who we should help, and when.  Part of the challenge was to avoid, in the words of a senior Conservative Minister to me privately - &#8220;nationalising cyber security&#8221;. So we started a big programme of work mapping out when we&#8217;d intervene, based on separating private and public risk.</p><p>Eventually we gave up. </p><p>It was just too hard. In a sophisticated digital economy, the interplay between privately owned damage and public harm was ubiquitous. Should we offer to help a company if it supplied a key public service, but not if it didn&#8217;t? If passports were lost because they&#8217;re government documents, but not bank cards? If the attacker was a nation state, but not a criminal? If the victim organisation&#8217;s cyber security was strong but not if it was faulty? We couldn&#8217;t answer any of these questions conclusively. </p><p>An illustration in the UK from earlier this year proves the point. In August, a private sector software company suffered a crippling ransomware attack. Among its customers was the publicly run National Health Service (details are <a href="https://www.theguardian.com/society/2022/aug/11/fears-patient-data-ransomware-attack-nhs-software-supplier">here</a>). As a result, the health service&#8217;s helpline, and some mental health services, were badly affected. The National Cyber Security Centre confirmed it was assisting. When I was asked live on radio by a former senior politician why the state should help a private company in this sort of situation, my reply was simple: public health provision was being disrupted. </p><p>This might not be a neat delineation of risk. It might even be effectively subsidising the consequences of weak cyber security practice in the company. But it is what the British public would expect and what the health service needed at that moment in time. </p><p>Therefore, at the NCSC, out triage efforts rationed our interventions based on an assessment of the harm to the nation, whether it originated in Government or the private sector. </p><p>This is very difficult to judge. But, in our view, it made for a more sensible set of interventions than trying to work out whether or not the Government should get involved based on who owned or operated the network. </p><p>It&#8217;s the consequences that matter. </p><p>The Optus and Medibank breaches show the same point.</p><p>Neither are first order national security crises. Reasonable people can debate and differ on how damaging they are. </p><p>But both involve clear public risk and potential harm in some way. </p><p>Medibank is the more obvious and serious example. Medical records are deeply sensitive and the company stored not far the records of two fifths of the national population. In such a scenario it is inevitable the population will look to its government for a narrative about what is likely to happen, including what risk they&#8217;re at. They will look to Government to do what it can to prevent wholesale disclosure of the dataset. And they will look to Government for the pursuit of the guilty and the prevention of a recurrence of such a data disaster on a national scale.</p><p>Optus is a more subtle example. There is a debate to be had about whether Governments should engage in a public debate about whether or not an attack was sophisticated or not (though for what it&#8217;s worth I would argue that Canberra&#8217;s leaders were right and courageous in this case to do so.) </p><p>But where the public interest is obviously engaged is in the part of the dataset that involved passports and driving licenses. These are two of the primary identifiers issued by the state. When, as the last post in this series set out, 1.2 million of the 9.7 million records compromised (and a further 900,000 expired ones), it falls to the state to make an assessment as to the risk of harm arising from this, whether the documents are still usable, and, if not, whether any special process needs to be established to replace them. Some might take the view that this is not a particularly serious issue, and that might be correct. But it still falls to the state to make the assessment. </p><p>Therefore, in both the Optus and Medibank cases, privately held risk materialised in a way that engaged the wider public interest. This is increasingly inevitable in advanced digital economies. And that in turn leads to a requirement for the state in many cases to take a leading role in incident response. </p><p>One of the reasons the UK&#8217;s National Cyber Security Centre was set up was as a result of the breach at the telco TalkTalk in October 2014. This was the first time a cyber breach had led the British national news. The case is instructive because, over time, it emerged that the breach was considerably <em>less</em> serious than initially thought. The early narrative around the case assumed, as always, a sophisticated attack that left the company&#8217;s four million customers at direct risk of serious financial fraud. In fact, a basic hack had accessed the dated and limited records of 150,000 customers. But it took several days for this to emerge, and the Government stayed mostly silent amidst the (unnecessary) panic. </p><p>Though no national security risks arose in the TalkTalk case, the Government at the time later concluded that the state needed a national cyber security incident management function akin to that for terrorism, floods or public health outbreaks. What was needed, they argued, was a system where someone in authority would give an official assessment of what has happened, who is at risk, from what, and how they might go about managing their risk. This because one of the core functions of the NCSC.</p><p>The UK&#8217;s more activist approach to managing incidents was one of a number of significant developments in state involvement in cyber security in the West over the past decade or so. Others have broadly fallen into three categories.</p><p>The first, and most extensive, is regulation of critical national infrastructure (CNI). This is unsurprising given what is at stake. Moreover, it is where the privatisation of serious national security risk is most acute (for more on that, see <a href="https://www.prospectmagazine.co.uk/science-and-technology/privatised-cyber-security-hackers-ciaran-martin-gchq-revil-darkside">here</a>). Australia is among several countries to have acquired regulatory powers over cyber security in CNI. The UK has recently taken powers for telecommunications akin to those already in place for financial services. The EU&#8217;s two Network Information Systems (NIS) Directives of 2016 and 2022 set out sweeping requirements for a range of critical sectors. The problem here is that critical infrastructure is very difficult to define, and what we regard as critical changes all the time. </p><p>A second, and growing, area is in the safety of technology itself. The EU (through its 2019 Cybersecurity Act) and the UK (through the just enacted Product Security and Telecommunications Infrastructure Act) have followed Singapore in introducing detailed regulation of Internet of Things (IoT) products. This takes advantage of the change in the internet economy represented by IoT: instead of web-based services where the price of entry is data, these are products and services that can be more easily evaluated and, therefore, where security standards can be more easily specified. These reforms are hugely important, but they do not address long-standing defects in network security.   </p><p>The third is the trickiest and most underdeveloped but seeks to address the limitations of the existing approaches: trying to use the power and influence of Government to improve general network security across all sectors of the economy. </p><p>That is where the reference to the &#8216;whole of nation&#8217; approach in Australia&#8217;s strategic review is so intriguing, and it&#8217;s one that presents a plethora of opportunities and risks. </p><h4>Governments and cyber security: opportunities and risks</h4><p>The great conundrum of Western cyber security over the years is why so much money has been spent on a clearly recognised problem, and yet so many areas of fundamental difficulty remain. </p><p>It is hardly new to talk of market failure in cyber security, but it&#8217;s a huge part of a difficult story. There are some areas where the ordinary functioning of market economics has led to the development of powerful capabilities to combat cyber security threats - threat intelligence is an obvious example. But there are many other examples of weak security practices and enduring digital pollutants which illustrate the problem.  </p><p>Here are a number of ways in which the state can shape a nation&#8217;s posture around cyber security and address market failures (they are absolutely not specific to Australia or linked to its current strategy development process, or to the UK, or anywhere else). They are instead a list of possible areas for Governments to consider what their appropriate policy is: </p><ul><li><p>First, setting the national risk appetite. In less technocratic language, this means deciding what a country and its companies and citizens need to care about. Key to this is understanding harm. How much should it care about data breaches? Which ones? Which threat actor matter more than others? Which aspects of the problem can only be left to Government? </p></li><li><p>Second is the cyber security environment for businesses. What risks are businesses to be reasonably expected to manage? Once that&#8217;s decided, how are the rules to be implemented? Does Government have a role to play in nudging corporate governance rules to be adapted to incentivise better cyber security? Why hasn&#8217;t cyber insurance - insurance being a regulated industry - worked to anything like its full potential? Can the Government use its convening power to help fix these problems? And if not, does further regulation become the default?</p></li><li><p>Third, the regulatory framework. If the answer, at least in part, is more law, then the key is a balanced set of regulations that seek to take care of the totality of the problem. Two examples: first, what we think of as critical infrastructure changes all the time; and second, if data protection is the only legal obligation, organisations won&#8217;t be incentivised to protect against more disruptive threats. </p></li><li><p>Fourth, the Government as an active defender. The Government can harden its own networks by direct action, not just by persuasion and/or law. That not only shows leadership by example, but also takes away a large part of the national attack surface given then size of the state in modern economies.</p></li><li><p>Fifth, direct intervention in areas of clear market failure. If no-one has a commercial incentive to try to take down malicious websites, the Government can try. If there are ways to block automatically, it might be within the Government&#8217;s powers to do so. (Some of these types of initiatives have been tried by the UK in the NCSC&#8217;s <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/introduction">Active Cyber Defence</a> programme).</p></li><li><p>Finally, the deterrence and pursuit of wrongdoers. A key role of the state is to prevent and deter harm against its citizens and punish those who do. This becomes harder with regard to cyber attacks because, for the first time in human history, large-scale, persistent harm can be initiated without the adversary ever setting foot on national territory. In a domain where impunity is easier than before, to what extent can the state reasonably be expected to thwart malevolent actors? To what extent can taxpaying businesses and citizens rely on such protections?</p></li></ul><p>Inherent in these questions are many of the risks and challenges for Governments:</p><ul><li><p>the UK Minister who worried about &#8216;nationalising&#8217; cyber security might not find himself reassured by this list. Governments need to navigate the obvious moral hazard associated with a more activist approach. But, arguably inactivity is worse. </p></li><li><p>Getting the right regulatory posture is hard and the consequences of getting it wrong can be severe. One striking feature of the Irish healthcare crisis of 2021, when most of the state&#8217;s healthcare commissioning system was taken offline, leading to severe consequences for patient care, was that the main law incentivising the Health Services Executive to take cyber security seriously was the General Data Protection Regulation (GDPR). This had skewed incentives prior to the crisis; however serious health data is, it&#8217;s not as serious as losing access to the cancer consultations scheduling system. But the regulations incentivised data protection, not service continuity. </p></li><li><p>Bringing the business community along with Government reforms is essential. It can be done - the new UK telecommunications security act, for example, was brought in with industry encouragement and input. However, GDPR provides an opposite case study. In the UK, it led to a temporary chilling effect in Government cooperation with business over data breaches: the Chief Information Security Officer (CISO) was replaced by the General Counsel in key operational meetings with Government agencies. As a result, the NCSC came together with the data protection regulator, publishing a <a href="https://www.computerweekly.com/news/252462242/NCSC-and-ICO-pledge-to-support-data-breach-victims">memorandum</a> designed to provide regulatory incentives to victim organisations to work with the Government to help manage the problem.</p></li><li><p>Finally, greater Government involvement increases some of the risks to the Government itself. If stiff penalties are inflicted on the private sector for cyber security failures, it is reasonable to expect commensurate accountability in Government, and the challenges in protecting networks are no less acute in the public sector. Moreover, some of the tensions in public policy become more acute; for example around Governments&#8217; real and perceived stance around end-to-end encryption.</p></li></ul><p>At the heart of realising the opportunities and managing the risks is changing the way in which <em>incentives </em>work. Incentives have been broken in cyber security for some time. Hope for the best has been a perfectly rational strategy for many organisations. That has to change. </p><p>Here, a key choice for countries is the balance between compulsion at one extreme and exhortation on the other. This will vary according to local circumstance, governing systems, and the political preferences of those in power. The United States is likely to remain at the more exhortatory end of the spectrum for all sorts of reasons: the cultural and constitutional reluctance to compel businesses; the difficulty of passing effective regulation through Congress; the location of many tech and cyber security giants within the United States, and the sheer power and scale of America&#8217;s state cyber security agencies. </p><p>Yet, all that said, the underlying diagnosis in this article of more Government activism does not, to me anyway, seem out of step with some of the thinking currently driving US policy. One only has to look at the brilliant article by President Biden&#8217;s National Cyber Director, Chris Inglis, in February of this year arguing for a new <a href="https://www.foreignaffairs.com/articles/united-states/2022-02-21/cyber-social-contract">Cyber Social Contract</a> to see how the difficulty in delineating risk between the private and public spheres is at the heart of the Administration&#8217;s considerable efforts to ramp up partnership between government and the private sector in cyber security. </p><p>In any case, most countries, even the US&#8217;s close Five Eyes partners like the UK and Australia, do not have any of the specific factors driving the US&#8217;s less directly interventionist approach. So it will not be surprising if most of the US&#8217;s allies end up taking a more direct role, including through legislation, than America does. Whilst it will be some time before Australia&#8217;s policy review process is completed, it could be an early indicator of an important trend. </p><h4>Conclusion</h4><p>Modern highly digitised societies share cyber security risk between the private and public sectors. It is often impossible to work out exactly where private risk ends and public risk starts. </p><p>Capable Governments can develop their own tools to take care of their side of the bargain. But a modern Government also has a key role in shaping the incentives of the private sector to do its part. </p><p>All this is taking the state beyond its traditional areas of intervention in cyber security -  like critical infrastructure, data protection and product regulation - and into a more complex area of incentives, economics, general corporate regulation and so on. </p><p>And that leads to some very important public policy challenges. </p><h4>Coming up next in the series</h4><p>One very specific policy challenge is the vexed question of the payment of ransoms. This has been a feature of many of the most serious cyber security incidents of the 2020s, and has prompted some of the most heated debates within the cyber security community of recent times. </p><p>This question will be examined in Part 3 of this series. It will be published on Tuesday 17 January, following the Christmas and New Year break. </p><p>In the meantime, there may be one or two other posts on other subjects on this Substack page.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/lessons-from-down-unders-data-disasters?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Five Lessons from Down Under's Data Disasters: Part One]]></title><description><![CDATA[The lessons from the Medibank and Optus data breaches are vast, varied and vital. The first in a five part series argues that we lost our way figuring out why and when data loss matters]]></description><link>https://ciaranmartin.substack.com/p/five-lessons-from-down-unders-data</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/five-lessons-from-down-unders-data</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Tue, 06 Dec 2022 11:00:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Knft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_webp, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Knft!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp" width="810" height="540" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/adf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:810,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:127976,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_424, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_848, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1272, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Knft!, /__u/ciaranmartin.substack.com/w_1456, /__u/ciaranmartin.substack.com/c_limit, /__u/ciaranmartin.substack.com/f_auto, /__u/ciaranmartin.substack.com/q_auto:good, /__u/ciaranmartin.substack.com/fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf43680-9da7-45d2-b767-d23dd61748ff_810x540.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/five-lessons-from-down-unders-data?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/five-lessons-from-down-unders-data?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p>Maybe we&#8217;d forgotten about data breaches. Maybe we&#8217;d started to think of them old-fashioned and pass&#233;. </p><p>In Western cyber security circles we (understandably) spent most of 2022 studying the digital dimensions of Russia&#8217;s murderous invasion of Ukraine (more on that in future posts). We (again, understandably) spent 2021 fretting about an explosion of disruptive ransomware when systems didn&#8217;t work, often with potentially dangerous consequences (think of the serious disruption to Irish healthcare, or the disorderly lines queuing for gas on the US eastern seaboard). We spent (yes, understandably) 2020 trying to figure out how to work remotely safely, and cope with all these new Covid scams, as well as how to prevent vaccine espionage and misinformation. </p><p>But data breaches? It&#8217;s been a while&#8230;</p><p>Recent events in Australia should remind us of the centrality of data protection to the health of the digital domain. The lucky country&#8217;s extended period of luck in cyberspace finally ran out. Two major breaches have not just shaken one of the world&#8217;s richest, happiest and digitally advanced countries but have raised just about every major public policy issue relating to cyber security that there is. There are no easy answers, but we have to pay attention to the questions.</p><p>Taken together, the two incidents are among the most consequential in recent cyber security history. The lessons arising from them are vast, varied and vital.</p><p>This series identifies five of the most important. They are by no means exclusive to the incidents in Australia, but each feature in the cyber security crisis there.</p><p>The series starts today with a look at how our failure to understand the differing severity of harm caused by different data breaches has hampered our ability to understand the problem and tackle it.</p><p>It will be followed by four further posts over the coming weeks on other crucial lessons of events on the other side of the world.</p><h3><strong>What&#8217;s happened?</strong></h3><p>But first, given that the incidents have received surprisingly little attention in the northern hemisphere, even among cyber geeks, a quick recap is necessary:</p><ul><li><p>on 22 September, <strong>Optus</strong>, one of Australia&#8217;s largest telcos, announced a data breach affecting up to 10 million customers (a very good early timeline of the Optus case is <a href="https://www.theguardian.com/business/2022/sep/29/optus-data-breach-everything-we-know-so-far-about-what-happened">here</a>). In keeping with tradition, the company called it &#8220;a sophisticated attack&#8221;. In a striking (and welcome) break with said tradition, Clare O&#8217;Neil, Australia&#8217;s new(ish) Minister of Home Affairs and Cyber Security (the last part of her title being completely new) pointedly rejected this characterisation, accusing the company of leaving the door open by way of a public API endpoint which required no authenitication and was therefore open to anyone. Just over 10,000 records were published (and then taken down) on the dark web, removed by an apparently penitent actor. The behaviour of whoever accessed the data was, on the whole, a bit weird: an apparent ransom demand for US$1m in crypto, in return for not publishing the information, was made and then dropped. </p><p></p><p>It later emerged that while most of the exposed records were the classic basic trove of email records, phone numbers, dates of birth and not much more. However, for thousands of Australians the breach involved the compromise of much more important identifiers, principally driving licenses and passport numbers. Under pressure from the Federal Government, Optus agreed to pay for the replacement of the passports of those affected. There has not, at the time of writing, been any further evidence of data leakage resulting from the Optus breach. </p><p></p></li><li><p>if Optus took the form of the classic commercial data breach, with a bit of passport data to make it more serious than most, then the <strong>Medibank</strong> affair was of a different order, quickly turning into one of the most serious and sickening data breaches in history (a good timeline of the early stages in the saga is <a href="https://www.cshub.com/attacks/news/iotw-everything-we-know-about-the-medibank-data-leak">here</a>). </p><p></p><p>In mid October, Australia&#8217;s largest health insurer detected a significant breach. Throughout the rest of October the company seems to have gone through the classic process of data breaches from denial to acceptance. Its early statements played down the incident, but by the week of 7 November they&#8217;d been contacted by the malicious actor and it had become clear that 9.7 million medical records had been stolen and it was time to come clean about the severity of the incident. </p><p></p><p>The behaviour of the criminals behind this attack showed much more planning and foresight. Technically, this did at least have some indicators of a sophisticated operation. The hackers knew what they were doing and used conventional methods of demanding a ransom (pricing it at a dollar per customer, or $9.7m) in return for not publishing the information. On 7 November the company announced publicly both the extent of the breach and its refusal to pay the ransom. Two days later, the hackers began to release sensitive medical records relating to thousands of people onto the darkweb. The first files apparently related to women&#8217;s reproductive health and patients with alcohol or mental health problems. Yes, it really was that bad. </p><p></p><p>As a result, the case became headline news in Australia (it is as rare for a cyber incident to lead the news in Australia as it is in the UK or US). On 11 November, the Australian Federal Police held a remarkable press conference where they announced that the attackers were criminals based in Russia whose identities were known to the Australian authorities but were not publicly disclosed. They announced a plan to pursue the criminals through the Russian authorities and Interpol. The Federal Government announced a new offensive cyber unit, to be staffed jointly by the AFP and the Australian Signals Directorate (think the NSA or GCHQ for Australia) to go after the criminals&#8217; digital infrastructure. At the end of November, after further disclosures of apparently intelligible information, the hackers published an odd message saying &#8220;case closed&#8221; and purporting to dump all the data online onto the darkweb; however the data was, in the seemingly accurate view of Medibank itself, &#8220;incomplete and hard to understand&#8221;. </p></li></ul><h3><strong>Why do these hacks matter? (beyond the obvious)</strong></h3><p>So for a period of nearly three months, and particularly in November, serious and scary data breaches have been at the top of the political agenda in Australia in a way not seen in other major Western economies for some years. The new Labor administration in Canberra have taken the incidents extraordinarily seriously. The Government seemingly plans a wide ranging reviews of Australia&#8217;s cyber security laws and strategic posture. </p><p>Clearly, and for obvious reasons, these incidents matter to the millions of Australians affected. But their implications go well beyond Australian shores (there is absolutely no reason to believe that Australia, a wealthy Five Eyes country with excellent security services, is somehow uniquely bad cyber security). </p><p>As well as reminding us that data breaches haven&#8217;t gone away, the incidents throw up some of the most important and unsolved challenges of doing cyber security in advanced digital economies. These incidents therefore have global resonance and importance. </p><h3>The five lessons from Australia</h3><p>Here are the five lessons from Australia&#8217;s recent experience that will be the focus of this series:</p><ul><li><p>first, data breaches still matter. But some matter way more than others. Our failure to distinguish between incidents in terms of severity is helping fuel complacency about data security. That is the focus of this first post in the series.</p></li><li><p>second, Governments are going to be far more involved in cyber incidents and cyber regulation in most countries, whether the private sector likes it or not. The Australian Government has shown significant and innovative leadership in its response. It&#8217;s used its public platform well. And it seems to be embarking on a wide-ranging review of its posture. All that is likely to have resonance further afield.</p></li><li><p>third, we still really, really need to talk about ransoms. We need to talk about whether companies should pay, and, yes, if they should be allowed to. That discussion is paused, not finished.</p></li><li><p>fourth, and related, how we talk about cyber incidents, and how the media reports it, really matters. There&#8217;s a public interest in reporting serious problems with cyber security. There&#8217;s also a public interest in not spreading fear that fuels a pro-criminal business model. Australia has valuable lessons here in responsible public discussion. </p></li><li><p>finally, the safe haven problem is the biggest and hardest challenge we face in cyber security. The ability of criminals to hang out in various countries with impunity, especially Russia, is cyber security&#8217;s least technical but most pressing and yet intractable problem.</p></li></ul><h3><strong>Lesson 1:</strong></h3><h3><strong>Data breaches still matter, but some way more than others</strong></h3><p><em>&#8230;and headline numbers of records is a terrible and damagingly misleading measure.</em></p><p>This week&#8217;s inaugural post focuses on how we think about data breaches and why that matters, and in what ways we need to get better.</p><p>When we talk about data loss there is still a tendency to think of all data breaches as being more or less the same, with the differentiator being how many records have been stolen. This is particularly true of broader public discourse, though it still happens a bit in specialist cyber security circles too.</p><p>That&#8217;s wrong, and it&#8217;s a problem.</p><p>Why?</p><p>Many data breaches lead to no direct harm, and the indirect harm they do cause is hard to prove or, sometimes, even to observe. So many data breaches aren&#8217;t particularly scary, and it&#8217;s right that we don&#8217;t scare people about them.</p><p>But some data breaches are extremely serious and it&#8217;s vital we&#8217;re able to distinguish between those that are and those that aren&#8217;t so bad.</p><p>But we&#8217;re not very good at doing so.</p><h4><strong>How data breaches all came to look the same</strong></h4><p>A decade or so ago, data breaches with <em>very large and scary headline numbers </em>were the dominant theme in cyber security stories that hit the media and therefore registered in the public consciousness.</p><p>The world&#8217;s professional class got a jolt as early as 2012 when LinkedIn got popped, losing the personal data of 700 million users (ten years on, cyber security trainers on courses still tell students to put their email into <a href="http://www.haveibeenpwnd.com">Troy Hunt&#8217;s epically useful data breach notification</a> service <em>haveibeenpwnd.com </em>and many of the positives come from this breach). A year later, Target lost 70 million customer records and 40 million (at least partial) credit and debit card records. Yahoo! trumped even that, with three billion (<em>three billion!) </em>accounts compromised in the same year. Equifax (2017) carried a headline of 147 million affected Americans and more beyond. Facebook&#8217;s headline figure in the 2018 breach was 533 million users. And so on.</p><p>But we struggled to relate this to actual harm resulting from these breaches. The &#8216;technical&#8217; reason for this - if it can be called that - is that in most of these breaches the number of human beings involved in the dataset was huge, but the actual <em>content </em>and therefore <em>value </em>of the data involved about each person was often relatively modest. Put bluntly, your email and home address and date of birth isn&#8217;t worth that much to criminals if that&#8217;s all they get, even if they get hundreds of millions of such records. They can&#8217;t do that much &#8216;harm&#8217; - directly at least - with this information. </p><p>Therefore, &#8216;headline&#8217; numbers of &#8216;victims&#8217; was, and remains, a terrible way of talking about data breaches.</p><p>It gives no indication of the severity of the harm done, or likely to ensue, to the people whose data was on the stolen list. If it was just a name, email address, physical address and last four digits of a bank card then the risk to the victim is not negligible but it is low, and nothing more than a bit of online financial vigilance is required. Add in a password and you&#8217;ve got a wider fraud or impersonation risk given the inevitable reuse of passwords and you need to do something (at least change the password you&#8217;ve been using anywhere else you use it). Add in a passport and you&#8217;re getting into serious risk of identity fraud and/or the onward sale of high value personal data. Add in a dataset involving myriad sensitive personal details - think mortgage application form or security clearance details, or, of course, your medical history - and some serious damage has been done.</p><p>But the way we&#8217;ve talked about data breaches doesn&#8217;t capture this nuance. In many of the big headline cases (Equifax is a great example) the severity of the breach in terms of the actual data stolen was at the milder end of the scale.</p><p>The consequence of this is that people got used to being notified that their data had been lost in a breach. But they then often did not suffer any obvious detriment in the aftermath. Contrary to some opinion in cyber security, people are generally smart and rational, and they reacted accordingly. So many people stopped being all that worried about data breaches.</p><p>In a seminal moment in the UK in October 2014, the country went into a blind panic for a weekend about what appeared to be a major breach at the telco TalkTalk. That was before the country realised that actually it wasn&#8217;t very serious at all, affecting 150,000 quite old and limited records, not the full, up-to-date accounts of the company&#8217;s four million customers. The company was fined nearly the maximum under the pre-GDPR data laws but that was because of negligent security practices; there was no evidence customers actually suffered any harm.</p><p>As a result, public perceptions of data breaches began slowly to change. In many cases, they became no big deal. For the most part, despite the constant headlines of spectacular data breaches, for the most part we learned to live with risk and move on.</p><p>Consider <a href="https://www.ncsc.gov.uk/guidance/ncsc-advice-ticketmaster-customers">this</a> official UK Government advice from 2018 following a breach at Ticketmaster, the online concert and sports tickets service. I declare an interest as both the head of the organisation that produced the guidance at the time, and as a Ticketmaster customer who got a notification. It&#8217;s cited here to illustrate a typical, late 2010s UK Government response to a data breach. In essence it says: if you&#8217;re affected, then it&#8217;s not great but don&#8217;t panic. The type of data stored can&#8217;t really directly be used to harm or embarrass you, so don&#8217;t do anything (except, as in this case change your password for this site and anywhere else you use the same one) and watch out for suspicious activity.</p><p>Or take <a href="https://www.bbc.co.uk/news/uk-england-stoke-staffordshire-63809829">this</a> live example from the UK. It&#8217;s a low key news story about the breach of a water company in Staffordshire. The company has taken steps to prove that the provision of safe water is unaffected, which is true, and to be expected. Then on the data breach itself, the company is saying that&#8217;s it&#8217;s complicated to assess the damage done by the criminals when they accessed customer data. There is no sense of panic or any massive harm done to customers.</p><p>The subliminal message in both cases is: get on with your life and don&#8217;t worry too much.</p><p>And this is a good thing. We have enough FUD - fear, uncertainty and doubt - in cyber security without terrifying people even further and undermining trust in our vital digital economy. If people aren&#8217;t really at risk, then we should reassure them.</p><p>But a downside of our - rightly - grown up discussion about the damage of data loss is that we&#8217;ve lost sight of when it gets really bad. Ten years or so ago we scared people about the risk of very big data losses. We then told people most of the time they weren&#8217;t that serious. But we lost track of which ones mattered, and how to talk about that to help people and organisations manage risk. </p><h4><strong>The really bad cases were long ago, or far away</strong></h4><p>For an example of a data breach with <em>really bad</em> consequences, we can go back to the hack of the Office of Personnel Management in Washington in 2015. The admission by the US Government that the Chinese state had copied the data of more than 20 million Americans who had sought a security clearance in the first fourteen years of this century was - justifiably - a spine-chilling moment for that nation because a security clearance form requires telling the Government pretty much everything about you. The headline number for the Equifax breach may have been more than seven times that of the OPM but the level of detail in each OPM dataset was far, far greater, and it had gone to a hostile state. It remains, in my view, the most strategically significant digital data breach in known history.</p><p>In very different examples, the hacks of the hook-up services Ashley Madison (2014) and Adult Friend Finder (2016) caused great distress to many on the list just by virtue of the embarrassment of being on it (and, sadly, at least one suicide has been at least speculatively linked to the Ashley Madison hack).</p><p>For a harbinger of the horrors of Medibank, we can look to the Vastaamo compromise in Finland in 2020. Vastaamo was a private provider of psychotherapy. A cyber criminal stole the records of, it seems, some 30,000 patients. As well as demanding payment from the company, the attackers also sent demands to thousands of individual patients, threatening to disclose details of their consultations with their doctors about their mental health problems.</p><p>But these cases seemed to be exceptions. The American examples were dated. Events in Finland tend not to get a great deal of attention in places like the US or UK. So, even as Europe, including the UK, hardened regulation of data security with the advent of the General Data Protection Regulation (GDPR), &#8216;traditional&#8217; data breaches stopped dominating concerns about cyber security.</p><h4>Even GDPR didn&#8217;t really help us understand data harm</h4><p>Indeed, the problem in assessing harm permeated the new regulatory environment. Before the pandemic, the UK&#8217;s Information Commissioner (the country&#8217;s data protection regulator) imposed swingeing fines of &#163;183m and &#163;99m on British Airways and Marriot Hotel Group respectively under new GDPR powers. Both incidents had what might be called &#8216;aggravating factors&#8217; that took them beyond the &#8216;normal&#8217; data breach: Marriott had millions of passport numbers retained, while in BA&#8217;s case 77,000 of the 380,000 records included full bank details including the CVV number which, most unusually in a data breach, made them fully usable by the criminals. They could spend actual money on the cards, not just sell them to other criminals on the dark web, or use them as the basis for identity fraud. That&#8217;s relatively rare in data breaches, and obviously serious. </p><p>Even in the BA case, however, it was hard to find examples of real, direct harm caused by the breach. And it was harder in the Marriott case even though passport numbers, a valuable criminal commodity, were included in the dataset. Eventually, the fines were reduced to &#163;20m and &#163;18m respectively, but this was explicitly done as a &#8216;mercy&#8217; decision to help two companies in sectors almost wholly shut down by Covid-19. Had the cases been litigated, which appeared likely before the pandemic, the case would no doubt have centred on the companies demanding that the regulator justified the severity of the punishments in terms of actual harm caused. </p><p>That would have required a British court to assess the harm done by a data breach. And that would have been a tough question. With no case taking place, we do not have a legal precedent on which to base future planning about how British courts view data harm.</p><p>In the absence of any such ruling, how we assess and price data harm is clearly something governments, regulators, the cyber security industry and large data holders need to think about. </p><p>Ideally, we&#8217;d have spent more time recently thinking through these problems and coming up with solutions. But, set against the ransomware horrors of 2021, with a major pipeline shut in the US, hospital administrative systems in chaos in Ireland, France and elsewhere, fresh food being thrown away in Sweden because it couldn&#8217;t be sold, and so many other deeply damaging ransomware cases, all of a sudden data dumps didn&#8217;t seem to be so big a deal. And as the West began to worry about the potential - and thankfully this remains potential - uptick in disruptive cyber aggression from Russia in the context of the invasion of Ukraine, data security slipped further down the consciousness of many parts of cyber security&#8217;s body politic. In many ways it was rational to begin to downplay data in the hierarchy of cyber risks. </p><h4>Why what happened in Australia matters</h4><p>But Australia&#8217;s painful experience reminds us that data security as a problem hasn&#8217;t gone away. It can cause real damage to an advanced digital society, and as a result needs the attention of the cyber security community and of governments.</p><p>Initially, the Optus case looked like it could have been just another data breach with one of those <em>very large headline numbers of victims </em>(estimated at 9.7 million), with data of limited value. But this swiftly changed. What became known as the &#8216;crucial subset&#8217; - those with more important identifiers like passports and driving licenses - took longer to work out. Eventually the company disclosed that some 1.2million valid records of this type, and a further 900,000 expired ones, had been stolen. Such a large scale breach of important personal identifiers is what turned Optus into more than the usual common data breach.</p><p>Medibank, a few weeks later, required little explanation of its complexity to hit home with the general public. The problem with the theft of nearly ten million medical records being out in the wild was obvious: this was the Vastaamo crisis in Finland at population level scale. </p><p>Sadly, comparing Optus and Medibank provides a really good way of thinking about how we assess harm because the headline numbers involved in the dataset are almost identical at 9.7 million each. But the entirety of the Medibank dataset involves personal medical histories, so its impact is much, much worse. One only has to look at the Australian media when the details emerged to see the sort of impact that had in the general population. Many more instances of this and we could have a serious crisis of confidence in the digital economy. </p><p>That said, the Australian public reacted calmly and the company put in place what has been mostly regarded as a helpful set of communications to concerned customers about what may or may not be happening to their data. Moreover, and as we shall discuss further in the fourth post of this series, the way in which the breach has been reported and discussed in Australia and beyond has generally been responsible, which has helped limit the damage. But the Medibank affair shows us that data breaches can cause national scale concern and even fear in some parts in the population of a wealthy, highly digitised country. </p><h4>Where do we go from here?</h4><p>If Australia&#8217;s experience forces us to reprioritise basic data security, what should we do? </p><p>The most important thing we can do is really quite a geeky, technocratic thing. </p><p>We need to find ways of measuring harm that helps us distinguish between different levels of severity in data breaches. </p><p>This matters in getting regulation right. </p><p>It matters for the fledgling but important cyber insurance market. </p><p>It matters for corporate risk management. Companies need ways of calculating what they need to protect most.</p><p>Most of all it matters profoundly for the public understanding of cyber risk. People manage risk better, and react more rationally when problems occur, when they understand what&#8217;s going on. </p><p>So all of this should matter to those looking after our cyber security.</p><p>Where we need to get to is a situation- not just a regulatory regime but an accepted understanding in society at large - where the relative value of different datasets and therefore the difference in harm done by their compromise is widely understood.</p><p>A situation where we automatically recognise that the compromise of healthcare records is demonstrably more serious than a basic customer dataset. That we take into account cyber security when designing data storage policies and practices with all these nuances and subtleties in mind. </p><p>Ultimately, the destination is one where our reaction to a data breach isn&#8217;t determined by the headline number of records compromised. Instead, there&#8217;s a general understanding of what happens when data disappears. How often there&#8217;s not much to worry about, but that sometimes it&#8217;s more serious. And even then we understand that it&#8217;s not clearcut: that even in the worst case scenario it&#8217;s unlikely that health records will end up on an easily available website but we that we do need to take steps to make sure we&#8217;re not susceptible to extortion, identity fraud and other forms of harm.</p><p>This involves a lot of hard, unglamorous but vital work. And it&#8217;s another example of how solving cyber security&#8217;s major problems sometimes involves doing things that aren&#8217;t really about the technical aspects of computer network security. </p><p>In short, we need better ways of understanding the price of data loss. A lot of progress could flow from that. And serious data breaches which damage public confidence in the digital economy still matter, even with all the other problems in cyber security.</p><h4>Next up: Governments and cyber incidents after the events in Australia</h4><p>Perhaps inevitably, given the obvious public concerns about passport data and especially healthcare records, the Australian Government&#8217;s role in the response to both Optus and Medibank has been notably activist. But it&#8217;s also been distinctive and innovative in some areas. That is likely to have wider ramifications for how Governments approach not just major cyber incidents, but cyber security strategy as a whole.</p><p>That issue - the probable increasing role of Governments in cyber security in the light of Australia&#8217;s experience - is the focus of the next post. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/p/five-lessons-from-down-unders-data?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/p/five-lessons-from-down-unders-data?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><h4></h4>]]></content:encoded></item><item><title><![CDATA[Coming soon]]></title><description><![CDATA[Launching 6 December 2022]]></description><link>https://ciaranmartin.substack.com/p/coming-soon</link><guid isPermaLink="false">https://ciaranmartin.substack.com/p/coming-soon</guid><dc:creator><![CDATA[Ciaran Martin]]></dc:creator><pubDate>Fri, 18 Nov 2022 09:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VfxR!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F36f1cfef-d4d5-415c-828a-bcc1ead2c5a2_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>This is Ciaran's Crispy Cogitations</strong>, launching on 6 December 2022.</p><p>It will be (initially) a weekly long from post about (mostly) cyber security, with some occasional reflections on the UK constitution, or something else.</p><p>It&#8217;s written by Ciaran Martin, Professor at the Blavatnik School of Government, University of Oxford, and former/founding head of the UK&#8217;s National Cyber Security Centre, part of GCHQ. I&#8217;m also an adviser to a small number of brilliant cyber security companies.</p><p>I was a senior UK civil servant for a very long time. Before I became obsessed with cyber, I was a Treasury, national security and constitutional obsessive. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ciaranmartin.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ciaranmartin.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item></channel></rss>