NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 13 of 33
Resilience

Introduction
Building cyber resilience and maturity is fundamental to the UK's economic and national security interests. This means having strong cyber defences where most attacks are prevented or blunted, and the ability to prepare, respond, recover and learn when attacks get through.
To that end the NCSC played a key role this year in helping UK institutions and organisations better understand the nature of cyber threats, risks and vulnerabilities, helping them to take action to secure the systems and services that society depends on; stopping attacks upstream and bolstering preparedness for when incidents occur, to minimise the impact and recover more effectively.
As well as supporting organisations and institutions, the NCSC’s resilience efforts also incorporated citizens, businesses, essential and critical services, government and the public sector.
This “whole of society” approach is central to the government’s new National Cyber Strategy (NCS), which was published in December. It set the ambition of “building a resilient and prosperous digital UK” and defined three areas of focus: managing risk, securing systems and being resilient.
As stated in the NCS
significant progress has been made in the last decade in improving our cyber resilience, with the establishment of the National Cyber Security Centre (NCSC), increased availability of advice, guidance and other tools, and the implementation of legislation … But serious gaps remain. Cyber breaches affect government, businesses, organisations and individuals; many organisations still report high numbers of cyber security breaches or attacks.
In addressing these challenges, the NCSC continued to do all it could to stop attacks getting through. In total, 2.1 million malicious cyber campaigns were removed this year. At the same time the NCSC engaged and equipped citizens and sectors with new and updated resilience advice, tools and services. And in partnership with the government, industry, law enforcement and other agencies it continued to:
-
monitor, assess and prioritise multiple threats and risks
-
make the internet automatically safer, preventing attacks and building-in basic protections
-
reduce the security burden on citizens, businesses and organisations, and doing more to protect those who are vulnerable
-
secure systems to prevent and resist cyber attacks
-
support the government in becoming an exemplar in cyber security
-
support embedding cyber security as a core part of organisational risk management through use of regulation and other incentives
-
harness the power of threat insight to build communities that can defend themselves
This chapter sets out more detail about how the NCSC is helping to bolster the UK’s cyber resilience and describes some of the key issues and actions that need to be considered to fulfil the ambitions in the NCS.