UK’s Cybersecurity Policy For Business

The British Government has decided to embrace cloud computing as a way of combating cyber-attacks.

The UK Government is a global leader in promoting public sector use of cloud technology for example, Transport for London's contactless payment system was introduced far ahead of similar public transportation networks across the world. 

However, like all organisations, it is under increasing pressure to generate cost savings, increase efficiencies and improve services, which are a few of the reasons why the Government has decided to embrace cloud computing as a way of combatting cyber-attacks.

In truth, cyber-security related issues now cost British businesses a total of £34 billion a year, according to a joint study undertaken in 2015 by the Centre for Economics and Business Research (Cebr) and Veracode. Nearly £18 billion of that figure is attributed to lost revenue, while £16 billion relates to increased IT spend as a result of breaches. Equally worrying is that 34 percent of cyber-crime aimed at UK organisations relates to intellectual property ‘IP' theft, a ‘crown jewel' for many businesses.

It is statistics like these that have led the UK Government to significantly increase its cyber-crime budget. However, the message remains clear, that all organisations, including those in the private sector, must take charge of their own security, through both use of technology and by promoting higher levels of employee awareness. Here are 14 suggestions that everyday businesses can learn from the Government and should consider when creating their own cyber-security protection framework:

1.     Protecting moving data - Consumer data moving in-between networks should be adequately protected against tampering and eavesdropping, through a combination of network protection and encryption

2.     Asset protection and resilience - Consumer data, and the assets storing or processing it, should be protected against physical tampering, loss, damage or removal

3.     Separation between consumers - Separation should exist between different consumers of the service to prevent one malicious or compromised consumer from affecting the service or data of another

4.     Governance framework - The service provider should have a security governance framework in place that coordinates and directs their overall approach to the management of the service and information

5.     Operational security - The service provider should have processes and procedures in place to ensure the operational security of the service

6.     Personnel security - Service provider staff should be subject to personnel security screening and security education before starting their role

7.     Secure development - Services should be designed and developed to identify and mitigate threats to their security

8.     Supply chain security - The service provider should ensure that its supply chain supports all security principles that need to be implemented

9.     Secure consumer management - Consumers should be provided with the tools required to help them securely manage their service

10.  Identity and authentication - Access to all service interfaces (for consumers and providers) should be controlled to authorised individuals

11.  External interface protection - All external or less trusted interfaces of the service should be identified and have appropriate protections to defend against attacks through them

12.  Secure service administration - The methods used by the service provider's administrators to manage the operational service should be designed to mitigate any risk of exploitation that could undermine the security of the service

13.  Audit information provision to consumers - Consumers should be provided with the audit records they need to monitor access to their service and the data held within it

14.  Secure use of the service by the consumer - Consumers have certain responsibilities when using a cloud service in order for this use to remain secure, and for their data to be adequately protected

While designed for public sector organisations, these principles provide a solid framework for supporting secure cloud adoption across all industries. Trust and security remain paramount drivers, alongside industry-specific requirements, with the list above providing a solid framework for selecting a cloud services provider.

It's clear that Government IT projects are moving to the cloud, but security still remains front of mind throughout this transformation. At a time when doing more with less is essential, policy myths and data classification confusion are slowing cloud adoption. The announcement of the EU-US privacy shield represents a vital step in maintaining data flows and strengthening confidence around security in the cloud.

SC Magazine

« Preliminary Agreement On Airline Cybersecurity
Video-Gaming Is The Next Cybercrime Target »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Brinqa

Brinqa

Brinqa is a leading provider of unified risk management and security analytics.to manage IT governance and technology risk.

Zertificon Solutions

Zertificon Solutions

Zertificon is a leader in professional email encryption and data security.

Operational Center for Information Systems Security (COSSI)

Operational Center for Information Systems Security (COSSI)

COSSI is responsible for the detection and mitigation of cyber attacks directed at French Government information systems.

NetLib Security

NetLib Security

NetLib Security’s powerful, patented data security platform helps companies control data loss prevention (DLP) by managing what data can be transferred outside of their network.

BehavioSec

BehavioSec

BehavioSec uses the way your customers type, swipe, and hold their devices, and enables them to authenticate themselves through their own behavior patterns.

Alyne

Alyne

Alyne is a Munich based 2B RegTech offering organisations risk insight capabilities through a Software as a Service.

10dot Cloud Security

10dot Cloud Security

10dot Cloud Security is a security service management company. Our solutions give you contextualised visibility into your network security.

ADVA Optical Networking

ADVA Optical Networking

ADVA is a company founded on innovation and focused on helping our customers succeed. Our technology forms the building blocks of a shared digital future and empowers networks across the globe.

Intaso

Intaso

Intaso are a boutique head hunting and talent solution firm with specialist Cyber and Information Security expertise.

Truvantis

Truvantis

Truvantis is a cybersecurity consulting organization providing best-in-class cybersecurity services to secure your organization’s infrastructure, data, operations and products.

Cloud4C

Cloud4C

Cloud4C is a leading automation-driven, application focused cloud Managed Services Provider.

Open Web Application Security Project (OWASP)

Open Web Application Security Project (OWASP)

The Open Web Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.

Exiger

Exiger

Exiger is revolutionizing the way corporations, government agencies and banks navigate risk and compliance in their third-parties, supply chains and customers.

Custom Computer Specialist (CCS)

Custom Computer Specialist (CCS)

CCS offers an extensive range of services including cybersecurity solutions, consulting, implementation, and support to help our clients maximize the value derived from IT investments.

Phone Monitoring Service

Phone Monitoring Service

Phone Monitoring Service provides cyber security services, ethical hacking services, social media hacking services in the USA, Canada, Europe.

Sandfly Security

Sandfly Security

Sandfly focuses on Linux security that is high performance, high stability, high compatibility, and low risk.