The UK Government is partnering with France to invite consultation under the Pall Mall Process, an international initiative to explore policy options and new practices addressing the threat of commercial cyber proliferation.
Through this joint initiative the governments of both countries are seeking to engage with stakeholders from among industry, civil society, and other nation states to share views on tackling commercial cyber-intrusion, whereby threat actors essentially buy “off-the-shelf’ products or services for system penetration or interference from third parties developers.
The Pall Mall Process declaration was initially signed in February this year, after an international conference hosted by the UK and France in London which brought together a range of collaborators, including states, tech companies, cybersecurity experts, investors, and researchers.
Twenty-six nations participated in the conference, including the United States, Ireland and Germany, while global companies like Microsoft, Google, and Meta were also represented. The result was an agreement to improve the oversight, accountability, and transparency of the commercial market for cyber-tools that could impact national security, human rights and fundamental freedoms around the world.
Recommended reading
- NCSC Warns Organisations to Prepare for Long Ukraine Conflict
- UK Gov at Risk of “Catastrophic” Ransomware Attack
- 82% of Firms Say the Exposure Management Gap is Widening
At the time, Jonanthan Ellison, National Cyber Security Centre director of national resilience and future technology, said: “In the NCSC, we recognise this is a complicated issue with no quick fixes. It requires action and commitment from the full range of stakeholders, and everyone has a unique part to play.
“By coming together — under the Pall Mall pillars of accountability, precision, oversight and transparency — we can reduce the impact of irresponsible activity that threatens all of our cybersecurity.”
Concerns regarding commercially available cyber-intrusion tools have risen sharply over recent years, with the NCSC estimating that at least 80 countries have purchased commercial cyber-intrusion software, or spyware in the last decade, with thousands of individuals targeted globally each year.
Experts argue that these cyber-tools have lowered the barrier of entry for threat actors to cause harm they might not otherwise be capable of, with evidence that commercial spyware has been used by some states to target journalists and political dissidents, as well as ‘hacking-as-a-service’ models becoming more popular in the corporate world.





