NCSC CEO urges all businesses to face the stark reality of the cyber threat they face, whether in the spotlight or not.
Richard Horne
NCSC CEO, Richard Horne.
Note
This blog post is adapted from a letter, first published in the Times. (opens in a new tab, subscription required)
The high-profile cyber attacks we have seen in recent weeks must give us pause – not because they are unique, but because they are not. They merely serve to highlight the reality of what the National Cyber Security Centre sees every day.
Cyber attacks have real-world consequences; they disrupt services we depend on, impose a severe cost on businesses, and customers’ personal data is so often caught in the crossfire.
This is plainly intolerable, and the NCSC works round the clock to support victims, counter online threats with government and law enforcement, and empowers organisations to improve their defences.
The NCSC makes its advice and guidance freely available, but it is not followed nearly enough across the board. There is a widening gap between the increasing cyber risks to the UK and our collective ability to defend against them.
From local coffee shops to providers of national infrastructure, every organisation must operate in a way that minimises the risks of an incident and know in advance how they would respond – and continue to operate – were an attack to get through.
This is effective risk management, and any business leader who thinks they may be exempt from gripping cyber risks should think again.
As I said at CYBERUK in Manchester, cyber security is a contest and it requires us to control all the variables that are within our control and to be prepared for those that are not.
The recent incidents in the headlines must act as a wake-up call. Every organisation must redouble their efforts both to defend and prepare for how they would respond if an attack were successful.
We urge organisations to follow NCSC guidance to help themselves stay safe online: