Police Cyber Alarm: Difference between revisions
No edit summary |
No edit summary |
||
| Line 22: | Line 22: | ||
It is important to understand that we (Opendium) have not audited the Cyber Alarm software ourselves. However, we do have enough technical knowledge to understand and be extremely concerned regarding the evidence that has been published by Paul Moore. There has been no transparency regarding the audit carried out by Bytes, and the way that both the NPCC, and Pervade Software have behaved doesn't lead to us having any confidence that the product is safe and secure to run on a customer's network. | It is important to understand that we (Opendium) have not audited the Cyber Alarm software ourselves. However, we do have enough technical knowledge to understand and be extremely concerned regarding the evidence that has been published by Paul Moore. There has been no transparency regarding the audit carried out by Bytes, and the way that both the NPCC, and Pervade Software have behaved doesn't lead to us having any confidence that the product is safe and secure to run on a customer's network. | ||
= Requirements for Schools = | = Requirements for Schools = | ||
| Line 46: | Line 39: | ||
* Publish an official playbook for how they will to respond to vulnerability reports, including a commitment not to engage in legal threats in response to the publication of bug reports. | * Publish an official playbook for how they will to respond to vulnerability reports, including a commitment not to engage in legal threats in response to the publication of bug reports. | ||
* Create a "Bug Bounty" programme, to reward security researchers who discover vulnerabilities in the software. | * Create a "Bug Bounty" programme, to reward security researchers who discover vulnerabilities in the software. | ||
= Status = | |||
Opendium UTM can be linked with Cyber Alarm. If you require this, please ask our engineers to configure it. There is further technical information available on the [[Firewall logging]] page. | |||
Given the security concerns, if a school decides to run this product, at the very least they should ensure that it is only connected to a completely isolated network, not to their main LAN. | |||
== Vendor Contact Log == | == Vendor Contact Log == | ||
Revision as of 17:29, 3 August 2026
Summary
Cyber Alarm is a product developed by Pervade Software and is being promoted by the NPCC. It collects event logs from a school's firewall and uses them to identify threats, providing reports back to the school.
Concerns
We believe that there are some significant concerns regarding the security of the Cyber Alarm product, and you should consider whether installing it would introduce security flaws into your network, rather than improve its security.
Between 2020 and 2022, Paul Moore, an independent security researcher, carried out several independent audits of Cyber Alarm, finding significant security problems. He followed a responsible disclosure process to report vulnerabilities to the NPCC and allow time for them to be fixed before disclosing to the public. He has detailed the vulnerabilities that he found, together with his interactions with the NPCC and Pervade software:
- https://paul.reviews/cyberalarm-an-independent-security-review-and-why-you-should-avoid-it/ [Archive]
- https://paul.reviews/cyberalarm-testing-the-production-version-and-why-you-should-avoid-it/ [Archive]
- https://paul.reviews/police-cyberalarm-abysmal-security-yet-again/ [Archive]
Whilst this information is now several years old, the flaws highlighted in each audit were the result of extremely sloppy programming. They were the sort of mistakes that no software developer should be making, let alone those writing security products. In the intervening time, it is possible that the flaws have been fixed, and we're aware that in 2022, the NPCC engaged Bytes Software Services Limited ("Bytes") to audit the product, who expressed some concerns but largely concluded that there had never been any significant problems. That statement is no longer available on the NPCC web site, but can be accessed through The Internet Archive: https://web.archive.org/web/20220628182038/https://www.cyberalarm.police.uk/security/4.0.1.0-statement/
All software has flaws, but the types of flaws that were found, and the way that the NPCC and Pervade behaved in response is extremely concerning. For example:
- Originally, it appears that the documentation sent to customers linked to an insecure "testing" version of the Cyber Alarm product rather than the "production" version. When this was reported, the documentation was quietly corrected, and the NPCC made a statement that the researcher had "found" the test product (as opposed to being sent there by the official documentation). There was no public announcement regarding the mistake, nor to our knowledge have the NPCC contacted anyone who had downloaded the "testing" version. Those people who downloaded and installed Cyber Alarm prior to this mistake being discovered are presumably, unknowingly, running an extremely insecure "testing" version of the product, and will continue to do so indefinitely as it appeared not to contain any working automatic update mechanism.
- Rather than admitting fault, the NPCC made legal threats and issued statements that appeared to libel the security researcher in order to discredit his findings.
- Despite the NPCC's statements to the contrary, most of the flaws in the "testing" product were also found to be in the "production" version.
- Notifications of security flaws have largely been met with denials rather than fixes.
- Where fixes have been made, it appears that the NPCC and Pervade have made statements denying that flaws ever existed, whilst at the same time publishing new versions of the products which specifically fix those flaws. Even allegedly having the newly fixed version sent for independent penetration testing and using the results to discredit the researcher's report.
- Whilst the security researcher that discovered the flaws published detailed evidence to back up his claims, the audit carried out by Bytes resulted in only a short summary being published and provides no evidence to dispute the researcher's findings.
- Pervade Software claim to have had penetration testing undertaken, but will not make the reports public (or apparently even release them under NDA).
It is important to understand that we (Opendium) have not audited the Cyber Alarm software ourselves. However, we do have enough technical knowledge to understand and be extremely concerned regarding the evidence that has been published by Paul Moore. There has been no transparency regarding the audit carried out by Bytes, and the way that both the NPCC, and Pervade Software have behaved doesn't lead to us having any confidence that the product is safe and secure to run on a customer's network.
Requirements for Schools
The Department for Education's Risk Protection Arrangement (RPA) requires that schools register with Police Cyber Alarm, but does not require the installation of the software on the school's network. This will ensure that schools receive email notifications of any threats: https://buyingforschools.blog.gov.uk/2024/02/19/cyber-security-for-schools-the-benefits-of-the-risk-protection-arrangement-rpa/
We have been notified that some insurers may be requiring schools to install Cyber Alarm. It is extremely concerning to us that an insurer would be mandating that one specific product be used, let alone one that has had serious security questions raised. It is, however, possible that this is a misunderstanding and that merely registering for Cyber Alarm may be enough to meet the insurers' requirements.
What Could the NPCC Do?
This situation demonstrates why maintaining trust is of the utmost importance when it comes to security. The NPCC, an organisation who should attract the highest levels of trust, responded to security concerns by demonstrating that they could not be trusted to make truthful public statements regarding the security of their security product. The security researcher, Paul Moore, has said that he believes that the NPCC have been misled by Pervade Software, and it may well be true that the NPCC did not have the technical expertise to properly evaluate the security concerns, and therefore just deferred to Pervade Software, trusting their contractor more than an external whistleblower.
Now that trust in the people responsible for Cyber Alarm has been lost, it will be very hard for them to regain it.
In March 2026, Pervade Software were removed as the technology provider, and replaced with Waterstons. This is a good start, but in order for us to withdraw this statement, recommending that schools do not install Cyber Alarm:
- We would want to see a truly open audit of both the current product and the revision history of the code. Even with Pervade Software having been replaced, Cyber Alarm is still presumably code that they developed, and is therefore of questionable quality.
- The audit should provide detailed technical evidence that either supports or rebuts each point of Paul Moore's analysis, with regard to what the code looked like at the time that he reported the flaw. If the flaw existed when he reported it, but was subsequently fixed, that is good but they still need to acknowledge that the original report was correct, rather than discrediting it on the basis that the flaw no longer exists.
- It is not good enough to simply make a statement that security research (which appears to be very credible to us) is wrong, they need to demonstrate *why* it is wrong.
- Publish an official playbook for how they will to respond to vulnerability reports, including a commitment not to engage in legal threats in response to the publication of bug reports.
- Create a "Bug Bounty" programme, to reward security researchers who discover vulnerabilities in the software.
Status
Opendium UTM can be linked with Cyber Alarm. If you require this, please ask our engineers to configure it. There is further technical information available on the Firewall logging page.
Given the security concerns, if a school decides to run this product, at the very least they should ensure that it is only connected to a completely isolated network, not to their main LAN.
Vendor Contact Log
- 2022-11-30 - Request to the NPCC for technical documentation
- 2022-12-13 - Reply from NPCC with a brief technical summary