Feeds

'Better IT could have stopped 7/7 bombings'

Spooks cleared of operational failures

3 Big data security analytics techniques

Better connections between police and MI5 intelligence databases may have helped stop the July 7 suicide bombings, according to a parliamentary investigation.

The report by the Intelligence and Security Committee (ISC), published today, found that MI5's failure to prevent 52 deaths on London's public transport in 2005 was the result of "understandable and reasonable" operational decisions. The Prime Minister accepted the ISC's finding.

The cross-party group of MPs - which meets in private and provides the main parliamentary oversight of MI5, MI6 and GCHQ - examined in detail why MI5 did not have the leader of the four bombers, Mohammed Siddique Khan, under surveillance.

The report found MI5 had records on Khan, but had not connected them. "Prior to 7/7, Mohammed Siddique Khan's name had appeared on a number of occasions in different versions, linked to different addresses, telephone numbers and vehicles, on various databases and in connection with separate incidents," the ISC wrote.

Prior to the bombings, Khan had crossed the path of law enforcement three times. The first was an assault unrelated to national security, so details were not shared with MI5.

Then, after the attack, West Yorkshire police found that they had filmed Khan at a terrorist training camp in 2001 with 40 other men. At the time attempts to identify him had failed.

Finally, in 2003 he had been seen briefly meeting an extremist who was being followed in a joint operation by MI5 and West Yorkshire Police. The meeting lasted three minutes and was not followed up.

"Of these three events, only the training camp in 2001 was a significant lead," the ISC wrote.

Following the attacks, MI5 also discovered Khan's and fellow 7/7 plotter Shazad Tanweer's connection to an earlier bomb plot. They had been seen by agents twice meeting Omar Khyam, who was sentenced to life in 2007 for planning a fertiliser bombing campaign. MI5 possessed records that were later found to show Khyam also had phone contact with Khan, who was never placed under surveillance because they did not discuss bombings when they met and "there was nothing to indicate that these telephone calls were significant".

Police did follow a car registered to Khan to his home address in order to "house" him following one of his meetings with Khyam, but the lead was never used.

Assessing whether MI5 should have joined the dots on Mohammed Siddique Khan when his name came up several times, the ISC wrote: "With the resources and time to do so, MI5 could have connected the names, albeit without 100% certainty given the different spellings and address."

MI5 told the committee however that even if they had connected the names, "there was still nothing to indicate that he was involved in a plot to carry out terrorist attacks and therefore they would not have done any more to investigate him given what else was going on at the time".

Jonathan Evans, the head of MI5, said: "I believe that given the same circumstances and resources, which I think is an important point, as were available to us in 2004, we would probably have made the same operational decisions."

However, the committee did find that processes should be improved with better IT systems and intelligence sharing. MI5 is not automatically informed when information of interest is added to regional Special Branch databases, for example.

"There remain, even today, many different IT systems that are not connected. There should be much better connectivity and automation between counter-terrorism and intelligence databases," the ISC wrote.

"This would allow the connections that we have now been able to draw (over the course of our 13-month investigation) between the name Siddique Khan and a number of counter-terrorism operations to be flagged up automatically in the future."

Since the 7/7 bombings, the total intelligence budget has been increased from about £1.5bn to more than £2bn, including significant IT investments. One major information sharing IT project, Scope Phase II, had to be cancelled, at a cost of tens of millions of pounds.

It was aimed at improving international intelligence however, rather than the regional information sharing the ISC said could have flagged the name to agents Mohammed Siddique Khan before he led the bombers to London. Scope Phase I, thought to be aimed at just that, was implemented last year. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
US Supreme Court supremo rakes Aereo lawman in oral arguments
Antenna-array content streamers: 'Ruling against us could dissipate the cloud'
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
prev story

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.