Britain’s National Cyber Security Strategy

The British government’s has publishes it annual progress report on the National Cyber Security Strategy 2016-2021 (NCSS) and reflects on progress already made against the NCSS goals and outlines future priorities as the strategy enters its final year. 

The Covid-19 pandemic has highlighted the vulnerability of the UK’s Critical National Infrastructure (CNI) to disruption by malicious actors,and ensuring the resilience of such essential services will be a clear priority throughout 2021. 

The tumultuous events of the Coronavirus pandemic has done much to reinforce the importance of cyber security to the UK’s national wellbeing.  “Millions of us have been relying more heavily on digital technology to work, shop and socialise,” it says in the introduction. “It has been an empowering and liberating force for good at a time when people have felt confined. It has been a lifeline keeping people connected with family and friends, ensuring the most vulnerable receive medicines and food deliveries, and is underpinning the operational delivery of our ongoing response to the pandemic... alongside the clear benefits technology brings come growing opportunities for criminals and other malicious actors, here and abroad, to exploit cyber as a means to cause us harm."

In particular, the UK’s departure from the European Union presents over the life of the current 5 year strategy offers  new opportunities to define and strengthen Britain's position as independent country, including how the nation tackles existing and emerging cyber security threats at a time when the global landscape is rapidly changing.

In the past year, the government has run several initiatives to evolve and strengthen the approaches that CNI organisations take to cyber security, working across government, with various regulators and public and private sector organisations to build a collective understanding of the challenges faced by CNI owners, and develop new strategies to address them. This work has included improvements to cyber security regulatory frameworks and the establishment of a Cyber Security Regulators Forum, and the ongoing implementation of the Network and Information Systems (NIS) regulations, which a post-implementation review seems to suggest are proving quite effective at strengthening security approaches among operators of essential services. 

Throughout this year, the government will continue to work across CNI sectors to improve assessment and reporting processes, and plans to develop bespoke penetration testing frameworks to help telecom operators in particular defend against, manage and recover from cyber attacks. It will also put more energy into improving understanding of the UK’s supply chains and dependencies – which is especially vulnerable to disruption thanks to the government’s approach to Brexit. 

The report outlined plans to extend the deployment of the National Cyber Security Centre’s (NCSC’s) Active Cyber Defence (ACD) programme beyond traditional government sectors in support of private sector CNI. 

An ACD Broadening project will aim to build on the success of the programme and expand it out to a broader range of sectors to allow them to benefit from automated protection from commodity cyber threats. Currently, the service includes protective domain name services, web and mail checks, host-based capability, logging, vulnerability disclosure, the Exercise in a Box programme and the Suspicious Email Reporting Service (SERS). 

The NCSS progress report also outlined other key priorities for 2021, which include: enhancements to the UK’s threat intelligence capabilities; the expansion of cyber crime deterrence programmes such as the National Crime Agency’s (NCA’s) CyberChoices scheme. However, 2021 also marks the end of the NCSS in its current form, and there is still no clear idea as to what comes next. The NCSS has been heavily criticised, including by the National Audit Office, for missing targets and goals, and although the report made no mention of its misfires, it did highlight the need to plan for the future. 

The report highlighted several developing trends that will inform government strategy after 2021, notably: the increasing reliance on digital networks and systems as surfaced by the pandemic. 

The increasing pace of technological change and greater global competition; a wider range of cyber adversaries as more criminal groups gain access to commoditised attacks. State-backed actors enhance their capabilities; and competing visions for the future of the open Internet and the possible risk of its fragmentation, which the government said will make consensus on norms and ethics in cyber space harder to reach. 

The UK’s approach to these challenges are largely defined by the outcomes of the Integrated Review of Security, Defence, Development and Foreign Policy. “The achievements of the last four years mean we start from a position of strength,” wrote the report’s authors. “Cyber security is an area where the UK can genuinely claim to be world-leading. But a changing global context will require a renewed response.... The UK will need to strengthen our cyber resilience to drive economic recovery, get ahead of changing technologies, and enhance our international cooperation and engagement to work towards a more stable cyber space...  We will not achieve this unless we continue to work ever more effectively with partners in the UK and abroad, the devolved administrations, businesses, universities, local authorities, civil society, international allies and individual citizens, wherever they share our vision of the benefits that cyber space can bring."

The rapid evolution of the cyber landscape will constantly throw up new challenges as technology evolves which  Britain adversaries will act to exploit and the the strategy objective is to provide a range of policies, tools and capabilities that will ensure Britain can respond quickly and flexibly to each new challenge.

Gov.UK:     Gov.UK:     Security Newsdesk:      Computer Weekly:       Six Degrees:      Image: Unspalsh

You Might Also Read:

Britain's Cyber Force Toughens Up:

 

« Minimising The Impact Of Ransomware
The Qualities That Make A Successful Cyber Team »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Open Networking Foundation (ONF)

Open Networking Foundation (ONF)

The Open Networking Foundation (ONF) is a non-profit operator led consortium driving transformation of network infrastructure and carrier business models.

Ahope

Ahope

Ahope is a mobile security solution provider in Korea with a long history of security solution development.

SIGA

SIGA

SIGA provides cyber security solutions for Industrial Control Systems SCADA systems used in critical infrastructures and industrial processes.

Redborder

Redborder

Redborder is an Open Source network visibility, data analytics, and cybersecurity Big Data solution that is scalable up to the needs of enterprise networks and service providers.

SOSA

SOSA

SOSA facilitates new growth opportunities by connecting the dots between industry verticals and innovation ecosystems around the world.

EnigmaSoft

EnigmaSoft

EnigmaSoft is known for its PC anti-malware remediation utility and service under the tradename SpyHunter.

Simplilearn

Simplilearn

Simplilearn is the world's #1 online bootcamp for digital skills training in disciplines such as Cyber Security, Cloud Computing, Project Management, Digital Marketing, and Data Science.

QuantiCor Security

QuantiCor Security

QuantiCor Security is one of the world’s leading developers and manufacturers of quantum computer resistant security solutions for IT infrastructures and the Internet of Things (IoT).

Easy Dynamics

Easy Dynamics

Easy Dynamics is a leading technology services provider with a core focus in Cybersecurity, Cloud Computing, and Information Sharing.

Segra

Segra

Segra owns and operates one of the nation’s largest fiber networks and provides best-in-class broadband and data security solutions throughout the Southeast and Mid-Atlantic.

Finlaw Associates

Finlaw Associates

Finlaw Associates is a trusted cybercrime law firm providing a wide range of taxation, legal, advisory and regulatory services to the financial, commercial and industrial communities.

CyberMontana

CyberMontana

CyberMontana is a statewide initiative providing cybersecurity awareness, training, and workforce development for businesses and residents of Montana.

DeltaSpike

DeltaSpike

DeltaSpike empowers individuals and organizations worldwide through its comprehensive cybersecurity solutions.

EVVO LABS

EVVO LABS

EVVO Labs empower your business with the latest IT capabilities to get you ahead of your competitors. We are experts at converging technologies to build your digital transformation.

Whalebone

Whalebone

Whalebone develop user-centric, no-installation network security products for telcos, internet service providers, enterprises, public institutions, and governments.

DiGiT3

DiGiT3

DiGiT3 is an information technology management, support, and solutions provider. Rely on our professional team for your data security and protection needs.