NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 18 of 33
Resilience tools and services
The NCSC’s website continued to be its online centre for its latest advice, guidance, blogs, tools and services. A total of 18 new pieces of guidance were published in 2022, along with 50 blogs on a range of topics, with over 1.6 million unique user visits. The most searched terms were “password(s)” and “phishing”, with 4,051 and 3,518 unique searches respectively.
While there is a large range of resources on the NCSC’s website, the following are some of the key products for general cyber resilience, many of which were refreshed this year.
| Audience | Resources and tools | |
|---|---|---|
| Citizens and families | Cyber Aware | |
| Sole traders & microbusinesses | ||
| Small & medium sized organisations | Small Business Guide: Cyber Security |
|
| Medium & large sized organisations | ||
Resilience round-up
Equipped with up-to-date insights on threats, risks and vulnerabilities — and with new and refreshed tool and services — the NCSC sought to engage, influence and shape the whole of society’s efforts to bolster the UK’s resilience:
-
Guidance for retailers to prevent websites becoming Black Friday cyber traps was published in November. The NCSC notified over 4,000 small business sites whose customers' payment details were being stolen after it identified that hackers were exploiting a vulnerability in popular e-commerce software. Later that month the NCSC alerted Christmas shoppers about keeping secure online over the festive period.
-
Launched its new-look Cyber Essentials scheme to support organisations to stay ahead of the cyber threat. This followed a major review of the scheme, which remains a key tool to help any size organisation improve their resilience through the implementation of five key technical controls and protects them against the majority of common, internet-based attacks.
-
New guidance for organisations who used SMS and phone calls to communicate with customers and service users was published in January. The telephony best practice was produced to help businesses reassure their audiences by ensuring messages were consistent, trustworthy, and reached customers without being blocked or deleted as suspicious. This came at a time when cyber criminals continued – albeit in smaller numbers - to spoof identities of trusted and well-known organisations, such as the NHS or HMRC.
-
Launch of latest Cyber Aware campaign in March urging citizens, sole traders and microbusinesses to improve their email security by adopting two-step verification and a strong and separate password using three random words.
-
Recognising that the supply chain for IT and technology services is a common vector for cyber attacks, the NCSC alongside international partners published updated related guidance.
-
In April the latest version of the NCSC’s Cyber Assessment Framework (CAF) was published. The CAF was first launched in 2018 to assess how well suppliers of essential services were managing cyber security risks. Version 3.1 was released to support core users, including CNI organisations and those subject to Network and Information Systems (NIS) Regulations.
-
Welcomed the publication of the first ever Government Cyber Security Strategy (GCSS), setting the approach for cyber resilience to 2030.
-
Related to the GCSS, in a blog published later in the year, the NCSC explained how CNI organisations could improve the security posture of their internet-facing services.
-
At the NCSC’s annual flagship event, CYBERUK in May, it launched its new email security tool to help organisations check their defences. The free service was developed to help organisations to identify vulnerabilities that could lead to spoofing or email privacy being breached.
-
In July the NCSC announced the new Cyber Advisor Pilot Scheme, a new initiative that offers assured cyber security consultancy services to small and medium sized companies, helping them achieve a minimum standard of security.
-
Schools continued to use the NCSC’s training for teachers and school staff. By July, views of the video resource on YouTube had exceeded 138,000.
-
In August construction firms working on major building projects, such as HS2, were offered bespoke advice aimed at helping them keep sensitive data safe from attackers: an important step in maintaining the integrity of projects critical to the UK’s future infrastructure.
-
Throughout the year, the NCSC continued to provide advice and support to Parliamentarians and senior government officials in the use of their work and personal systems and devices to prevent hostile actors accessing classified or sensitive information.
-
As well as supporting cyber security aims, the NCSC sought sustainable outcomes to extend the life of devices, including longer manufacturer support periods for devices and advice for those repurposing second hand devices.
-
Whilst necessarily not in the public eye, the NCSC continued to work on one of its most important duties: supporting the UK’s Armed Forces, from protecting the integrity of their digital-dependent assets from cyber threats to the development of future cyber defence capability.