Foreign Office hit by “serious cyber security incident”
The department sought urgent assistance from its security contractor in light of the "emergency"
The Foreign, Commonwealth & Development Office (FCDO) was the target of a “serious cyber security incident”, forcing it to seek urgent support to deal with the emergency.
The UK government revealed the existence of the incident in a public tender announcement, as discovered by The Stack. The contract award notice revealed that the FCDO paid BAE Systems Applied Intelligence £467,325.60 after it was hit by a serious cyber security incident, further details of have not be disclosed.
In response to the incident, it said that urgent support was required to support remediation and investigation. The date of conclusion of the contract was 12 January 2022, while the tender was published on 4 February 2022.
BAE Systems was the only tender received, as the FCDO was unable to comply with the time limits for the open or restricted procedures or competitive procedures with negotiation due to the urgency and criticality of the work.
“The Awarded Supplier is the Authority's long term incumbent service management integrator and as such had resources on site with significant knowledge and understanding of the Authority's infrastructure,” said the tender.
A Foreign, Commonwealth & Development Office spokesperson told IT Pro: “We do not comment on security but have systems in place to detect and defend against potential cyber incidents.”
Although the ICO originally told The Stack it had not been contacted by the FCDO about the incident, a spokesperson told IT Pro: “We are aware of media reports in relation to this matter and we will make enquiries.”
A report from the BBC adds that unidentified hackers got inside FCDO systems, but were detected.
“It’s not surprising that the FCDO has been a target of a cyber attack and is regularly targeted as such given the complex geopolitical situation we are in at present,” said Paul McKay, principal analyst at Forrester. “We do not know much about the breach and how it was detected and what the root cause is, and neither will we in all likelihood.
Vulnerability and patch management
Keep known vulnerabilities out of your IT infrastructure

“What is more surprising is that the disclosure under regular government spending disclosures was how we found out about it and does not seem to have been the intention. The FCDO will need to think about how they meet the mandates towards government spending transparency, with the need to maintain some discretion in such situations, given the sensitivity of the work FCDO performs”.
Other governments have faced cyber security issues recently. The Ukrainian government, for example, launched an investigation in January after its websites were taken down in a cyber attack. Messages appeared on the websites before they went down, warning Ukranians to “be afraid and prepare for the worst”.
Four strategies for building a hybrid workplace that works
All indications are that the future of work is hybrid, if it's not here already

The digital marketer’s guide to contextual insights and trends
How to use contextual intelligence to uncover new insights and inform strategies

Ransomware and Microsoft 365 for business
What you need to know about reducing ransomware risk

Building a modern strategy for analytics and machine learning success
Turning into business value
