Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 20 of 33

NCSC View: Actions for a resilient UK

Paul Maddinson Chief Operating Officer NCSC

This year the NCSC continued to work tirelessly to bolster the cyber resilience of the UK, which has, in our view, contributed to cyber attacks being prevented and harm being reduced.

As we have often said, cyber security is a team game. We are proud to be a captain of that team and I am pleased to see that significant steps have been taken to increase resilience across so many sectors.

Events like the Russian invasion of Ukraine, Log4j and continued ransomware attacks highlighted the need to bolster cyber resilience.

However, as the UK’s technical authority it is our duty to highlight – and help close - serious gaps in the nation’s cyber defences. While 2.1 million attacks were stopped over the past 12 months too many still get through. Breaches affect government, businesses, organisations and individuals. Poor organisational practices, processes and systems, and lack of awareness of risks and mitigations, all contribute to attacks getting through. Taking some practical and cost-effective steps, such as improving use of account authentication, could have prevented a lot of damage.

Earlier this year it was revealed that 39% of businesses had identified a cyber attack. Many of these businesses suffered a material outcome, such as loss of money or data.

So, for the UK to meet the ambitions set out in the National Cyber Strategy there needs to be a holistic, whole-of-society effort to improve resilience across the country.

It is right for government to focus on steps to secure the digital environment for all UK internet users, to prevent attacks, build basic security in products and services, and to help individuals and small businesses and organisations with practical actions to improve cyber security.

This must be a shared endeavour between the government and all parts of the economy and society. It is the responsibility of boards of businesses and organisations to manage their own cyber risk – informed, in part, by NCSC’s assessments and insight.

Meanwhile, government departments, the wider public sector and regulated operators of CNI, must raise their standards and manage their risk more proactively. Large businesses and organisations, including providers of digital services and platforms need to be more accountable for protecting their systems, services and customers as a core part of running their business.

In return, the government must continue to help secure the digital environment and tackle systemic risks and provide support through advice, tools, accreditation in the marketplace, and developing the skills that enable improvement.

For NCSC this means continuing to help organisations to understand the threats, risks and vulnerabilities and working in partnership to implement the behaviours, responses and actions that will help fulfil the vision of making the UK the safest place to live and work online.

Paul Maddinson
Chief Operating Officer, NCSC


Published

Reviewed

Version

1.0

Written for