Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

Soldiers faced 'threat to life' after MoD security blunder

British soldiers
British soldiers

Soldiers faced ‘threat to life’ after MoD security blunder

British soldiers faced a “potential threat to life and limb” after the MoD failed to sign a contract meant to protect the military from cyber attacks.

The MoD admitted this month that the failure to secure a contractor left soldiers potentially at risk as it raced to fix the issue.

A previous contract for “detecting and responding to cyber threats” ended in May without a new one lined up to replace it, leaving a gap that would have made it harder to detect potential digital threats.

Last week, the MoD issued a temporary nine-month, £2.9m contract to AtkinsRéalis, a Canadian engineering firm, while seeking a longer-term solution.

It was granted under rules allowing procurement without competition when it is “necessary to maintain the operational capability, effectiveness, readiness and security of the Armed Forces”.

‘Disruption or denial of systems’

In a justification for the direct award, the MoD said: “The expiry of the previous contracts has resulted in a material and ongoing degradation of defence’s cyber detection and response capability.

“A credible risk has consequently been identified that adversary cyber activity may go undetected or unmitigated, leading to disruption or denial of systems supporting command, communications, logistics, and operational planning.

“The resulting impact would be to degrade the ability of defence to coordinate and execute operations effectively.”

In the most severe case, the MoD admitted that without being able to directly award the contract and “immediately rest[ore] this capability”, it “could increase risk to personnel, including potential threat to life and limb”.

Offices with a sign saying AtkinsRealis
AtkinsRealis, a Canadian company, has been given a temporary contract worth £2.9m over nine months to provide cyber security - Getty

The MoD has not clarified the cause of the gap between long-term contracts. But it insisted no breaches or cyber incidents had occurred and all cyber systems remained protected.

In the procurement notice, the MoD said having no contract in place could lead “to disruption or denial of systems supporting command, communications, logistics, and operational planning”.

Col Hamish de Bretton-Gordon, the former head of Britain’s Chemical, Biological, Radiological and Nuclear Regiment, was “surprised” by the situation.

He said: “This is obviously a f--- up. Whether it’s a f--- up caused by a politician, civil servant or someone in the military, I’m not sure. It seems like an oversight ... and [the MoD has] suddenly realised they have little time left and they have to go with nuclear wording to sort this out.”

Col de Bretton-Gordon said the focus on finalising the defence investment plan, which at the time was months late before being released in June, may have led to an oversight. He said: “Apart from gross incompetence, I can’t think of anything else it could have been.”

Col Hamish de Bretton-Gordon in Army uniform in 2008
Col Hamish de Bretton-Gordon, pictured in 2008, says the security blunder ‘seems like an oversight’ - Richard Watt

The military’s networks create vast volumes of data every day. The MoD uses analytical software to continually sift through all this information to identify any potential digital threats.

Officials feared that allowing the gap to continue might have heightened the risk of potential malign activity going unnoticed. The MoD, however, insists it had systems in place that could have detected cyber threats during the seven weeks without a contract in place.

Through the new contract, data now collected from different MoD systems and capabilities is “onboarded” into a central platform, allowing specialists to detect potential cyber attacks and respond to them as quickly as possible. This may include log-in data or access to buildings via key passes.

During the seven-week gap, the MoD could still “exploit” data from “priority” systems already set up under the previous contract, but could not add any new ones.

‘Slow degradation over time’

The nine-month deal is a temporary measure while a “separate competitive procurement procedure and transition to a future solution… avoiding risk and disruption to defence’s cyber detection and response capability during this time” is carried out, the contract added.

Col Phil Ingram, a former officer in British military intelligence, said the threat the MoD faced from cyber hackers in Russia and China was “substantial”, but that the risk caused by the gap was low.

He said: “Theoretically the MoD could have been exposed to cyber hacks from sophisticated state actors which could have compromised its systems quite badly. It’s a slow degradation over time.

“It’s virtually impossible to say how much that will put you at risk but it will be something the team at the MoD will be well aware of and will have other agencies, like GCHQ, working on with them.”

Recommended

Russian warship opens fire off Devon

Read more

The MoD said there had been no increased cyber risk to personnel or operations because of the short gap between contracts. It added the risk identified in the contract is because of a sustained period of inactivity rather than the short capability gap.

A spokesman added: “MoD networks remained fully protected and monitored and this new contract will further enhance our ability to analyse network data and strengthen our cyber defences, ensuring we remain resilient against evolving threats.

“There has been no increased cyber risk to defence, our people or our operations.”

Sign up to the Front Page newsletter for free: Your essential guide to the day's agenda from The Telegraph - direct to your inbox seven days a week.

Read full story on The Telegraph

Related News

More stories you might be interested in.

Trump’s bizarre secret nuclear giveaway with Saudi Arabia is leaked
The Daily Beast·3 hours ago

Trump’s bizarre secret nuclear giveaway with Saudi Arabia is leaked

Self-styled “Dealmaker-in-Chief” Donald Trump plans to enter a pact with Saudi Arabia that could allow the repressive kingdom to develop nuclear weapons. Trump, 80, intends to announce and sign the deal to boost the country’s nascent nuclear program—with no concessions to the U.S.—on Wednesday. Such an agreement has been under discussion for years, but the idea had always been to force Saudi Arabia’s hand in return.

Top