Feeds

UK.gov security is pants

Worrying lapses

  • alert
  • submit to reddit

Security for virtualized datacentres

IT security levels in UK central and local government are worryingly poor and need significant improvements if the UK is to meet its e-government targets, a survey out this week warns.

Government security levels fall far below those of comparable IT sectors such as banking and finance, according to a report from security testing firm NTA Monitor.

Almost one in two (49 per cent) of government bodies scrutinised by NTA Monitor had greater than 10 vulnerabilities per report. An average of 73 per cent of these public sector sites showed worrying firewall vulnerabilities. This mediocre security exposes government organisations to considerable risk from malicious attack, NTA Monitor warns.

Roy Hills, Technical Director NTA Monitor, said: "With such poor security performance, government will find it extremely difficult to meet its e-government targets. What worries me most are the implications for citizen's records if they do manage to get all planned services online at current levels of security."

The UK government has set a target of making all its services available online by 2005, but inadequate security could undermine this ambitious goal.

Hills warned: "Public confidence in e-services will be crucial for their successful uptake - but given consistently poor vulnerability levels and sluggish track record of improvements, significant breaches of confidential information are risked. This could set plans back by years. Action must be taken now before the public's trust is damaged."

According to NTA Monitor's report, the government sector had the worst record overall in firewall security, with flaws oscillating between 78 per cent and 71 per cent during tests conducted over the last four years.

In 2002, vulnerabilities were found in the following risk areas, expressed as a percentage of government sector test reports: router (90 per cent), server (82 per cent), DNS (69 per cent) and firewall (73 per cent). Similarly the government sector fared joint worst in terms of the number of organisations found to have high (9 per cent) and medium-level (82 per cent) security flaws.

NTA Monitor characterises a high-risk issue as a major security vulnerability that is typically widely known and exploited by hackers to gain external access to a computer system. Medium-risk issues permit external users to disrupt services or internal users to gain unauthorised access to systems, whilst a low risk issue provides information that could be useful to a hacker in attempting an external attack.

NTA Monitor Vertical Market Security Report 2003 is based on analysis of more than 600 Regular Monitor network perimeter security tests undertaken by NTA Monitor for a broad range of blue-chip clients. The research analysed test results across the financial, government, legal, IT & telecommunications, manufacturing and services sectors.

Related Stories

UK.biz getting on top of serious security risks
Inland Revenue site 'failing to perform'
Whitehall laptop theft prompts security concerns

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.