NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 16 of 33
Resilience renewed
While ransomware and Russia attracted a particular focus this year, the NCSC ensured a “threat-informed” approach in its continued resilience-building across a wide range of sectors in the face of a sustained threat and risk to businesses and organisations.
Earlier this year it was revealed that 39% of businesses in the UK had suffered a cyber attack over the previous 12 months, 20% of which faced a material outcome, such as loss of money or data.
39%
of businesses in the UK had suffered a cyber attack over the previous 12 months
As well as threats and risks, the NCSC continued to observe the impact and potential harm from critical vulnerabilities in the global IT system. One of the most serious this year was linked to the Log4j logging system that was present in millions of computers around the world.
The vulnerability, if left unfixed, meant that attackers could break into systems, steal passwords and logins, extract data, and infect networks with malicious software. As countries and institutions raced to patch the vulnerability, the NCSC took a leading role in alerting UK citizens, organisations and businesses, and providing them with advice and services, such as Early Warning, which notifies users about attacks, risks and vulnerabilities on their systems.
The NCSC’s general resilience efforts included a continual cycle of engagement and support in the form of webinars, briefings, bulletins and workshops, to inform and alert sectors of threats, risks and vulnerabilities, while showcasing and signposting them to advice, guidance, tools and services, giving them agency to apply these resources to help improve their resilience.
Reducing the burden
At the same time, efforts and engagement continued with technology and digital service providers to better secure the internet and connected services at source and behind the scenes, in order to reduce the burden on end users.
This included providing insight, evidence and technical advice to the government for the development of the Product Security and Telecommunications Infrastructure Bill, which will require manufacturers to ensure minimum security requirements are met in relation to consumer connectable “smart” products.
In May a new data sharing capability that helps block access to scam websites instantly was announced. The new tool was made available to all UK internet service providers (ISPs) allowing them to block websites flagged as fraudulent. The “landmark partnership” with ISPs means that scams can be blocked from ever reaching the average citizen online.