NCSC for Startups: an ecosystem-based approach to cyber security
Andrew Roughan, CEO of the NCSC’s innovation partner Plexal, explains why a whole-of-society approach is vital for cyber security innovation.
Innovation is always more effective when you collaborate, listen and partner.
Just look at car seats. They were tested using crash test dummies that represented the average male. What manufacturers now understand is that females are not just smaller versions of males, which meant the development of care safety wasn't factoring in the needs of roughly half the population.
The cyber security sector faces similar challenges. It’s a discipline that’s too complex and important to be left to any single business, government department or agency. As the Cabinet Office's new National Cyber Strategy makes clear, we need to take a whole-of-society, ecosystem-based approach.
We need innovators to look up from their laptops and speak to the people on the defence frontline.
We need academics to influence policy and technology.
We need the government and its security agencies to shape markets, set the direction and point the ecosystem towards the right missions.
And crucially, this collaborative ecosystem has to have a shared purpose. I’m going to outline what that looks like, why it’s so important, and how the NCSC For Startups initiative is putting this into practice.
Collaboration doesn’t happen by accident
One of the myths about ecosystems is that co-location will automatically result in collaboration. It’s not enough to bring people together physically. You need someone sitting within that ecosystem – with no ulterior motives – to stimulate collisions and make sure the ecosystem is focussed on the goal. At Plexal this role is known as 'the orchestrator', and it's their job to bring together the government, investors, academia, innovators, big business, and other key players.
One of the main blockers to collaboration is often trust. Startups tend to be wary of having their time wasted or intellectual property stolen, while industry is naturally concerned about engaging with competitors. It’s crucial that you put the right guard rails in place to address this, whether it’s through legally setting out the rules of engagement, or making sure startups get paid, even for a pilot.
We’ve identified the ingredients any effective ecosystem must contain, which include:
- Mission: a defined outcome, on a global scale, that many people will be inspired by
- Infrastructure: a physical place, connectivity, transport, power, labs, flexible workspace, testbed space and events space
- Leadership: an identifiable person or organisation that sets the tone, the target and the pace
- Influence: being respected enough to inform legislation, standards, reform and policy
- Finance: access to funds so that actors in the ecosystem are incentivised and able to participate
- Intellectual property: enabling new products to be built
- Customer focus: never forget to understand who your customer is and what they need
- Network of networks: interconnections to adjacent ecosystems to create value
- Experimentation: enable trials, labs, proofs-of-concepts (not for 'innovation theatre' - make sure there’s a clear purpose)
- Programme: a thematic approach to creating progress - it could an incubator, accelerator or an innovation challenge
- Diversity of thought: you should always bring groups together that wouldn’t normally interact
- Measurement: measure everything
Why we need a cyber ecosystem
Cyber threats don’t care for verticals or siloed governmental department; they spread across sectors and borders, affecting businesses of all sizes, people from all backgrounds and even threatening our most important infrastructure, from schools to hospitals.
The lines between what should be in the public realm and what should be left to the private sector are also blurred. A company that chooses to pay a ransom affects the criminal ecosystem and can have a ripple effect on society and the economy. So is it a decision for a private sector company, or should the government play a role?
At Plexal we hear time and again from industry that they want more information sharing when it comes to emerging threats, and ways to mitigate them. Even in the most sensitive sectors (where trade secrets are closely guarded), we need to get better at creating information pathways.
Startups, meanwhile, are hungry for data and insights. Whether they’re trying to break into new markets, or want to start using their technology to solve an unprecedented cyber challenge, these startups need to be nurtured, funded and supported.
If the UK wants to develop a technological competitive advantage and counter cross-cutting threats to its national security, taking an ecosystem approach is the only answer.
NCSC for Startups is collaboration in action
There are lots of examples of how shaping technology within an ecosystem can be powerful, from DARPA, which invests in breakthrough technologies for national security purposes, to COVAX, which coordinated a global ecosystem to address vaccine production and distribution.
With NCSC For Startups, we set challenges and priorities that we want startups to address. Most recently, we’ve brought on five startups to tackle particular ransomware-related challenges that the market wasn’t already addressing, such as making sure SMEs have affordable protection. We bring together industry leaders and security experts from within the NCSC to give the startups all the insights they need to develop and adapt their technology solutions, and make them relevant to real-world solutions. If you're interested in getting access to cyber security experts from industry and the NCSC, the application process remains open for startups to apply to join our NCSC For Startups programme in 2023. You can find out more and apply by visiting the website.