Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 26 of 33

The NCSC's response

To address this, the NCSC stresses the importance of:

  • Increasing co-operation and co-ordination between allies to promote and instill their shared values into the design and development of technologies societies depend on
  • Supporting a multi-stakeholder approach to standards development, and ensuring standards encode democratic rather than authoritarian values
  • Increasing the diversity and resilience of critical supply chains so they can withstand shocks and adversarial interference
  • Continuing to invest in foundational science, research and development and early-stage industrialisation and ensuring this research is protected from hostile activity

As well as providing technological insight to support a values-driven approach to the development of tomorrow’s technologies, the NCSC continued to innovate and build capability for others to benefit from today.

The NCSC’s National Crypt-Key Centre (NCKC) continued to be the central focus for how the UK develops, operates and maintains the systems providing highly secure communications for the government, military, industry and national security partners. In May, the NCSC welcomed the National Security Council’s decision to approve the National Crypt-Key strategy; for the first time setting out a cross-government approach to the development, management and support to the UK’s use of cryptography to protect its most critical information and services.

In August, the NCSC issued its Principles for the security of machine learning. Due to the increasing presence of these systems in many aspects of life, from providing the 'smart' in smartphones to critical areas like healthcare, finance and national security, the NCSC sought to inform and equip users to help secure their personal or organisational systems, information and data.

Other key developments in technology capability included:

  • The NCSC worked to support mobile network owners in the UK to improve the security of their services. The NCSC developed and delivered a new tool, filling a critical gap, that will help discover new mobile network vulnerabilities. In addition, in partnership with Mobile Network Operators, the NCSC developed a National Telecoms Signal Monitoring Service (NTSMS) to understand the threats to our networks, to inform and improve defences and to support incident investigation.

  • The NCSC supported the introduction of new UK legislation. The Telecommunications (Security) Act which received Royal Assent in November 2021 will improve the security of our digital infrastructure. The Act introduces a stronger telecoms security framework which places new security duties on public telecoms providers, and new national security powers to address the risks posed by high-risk vendors.

  • The NCSC also assisted with the development of the new Electronic Communications (Security Measures) Regulations drawn up under the Act.

  • The Product Security Act was laid before parliament. This will provide Government with the powers to set security requirements for consumer devices, and to enforce when those requirements are not met. The NCSC launched the Device Security Principles for Manufacturers (Beta). The Device Security Principles is a guidance collection designed to help organisations gain confidence that Enterprise Connected Devices are protected against common cyber security threats and risks.

  • Refined guidance to help citizens and organisations, from advice around ‘Bring Your Own Device’ approaches in business networks to best practice for backing up data. Much of this contributed to the updates to Cyber Aware (for the citizen) and Cyber Essentials (for businesses) throughout the year.

  • Published research papers and blogs throughout the year, including on zero trust for customers looking to begin a migration journey to a Zero Trust architecture.

  • Updated all cloud guidance to reflect how much cloud services have changed in the past decade.

  • Supported HMG’s development of its Artificial Intelligence strategy in collaboration with DCMS, and continued to invest in understanding of the threats and ethics around AI. Later in the year, the Alan Turing Institute won an international competition for their NCSC-sponsored work on AI in autonomous cyber defence.

  • Notified Google about 15 suspicious mobile applications that were either advertised as SIM farms or offered customers incentives to persuade them to use their tariff contrary to their Terms and Conditions. This notification resulted in Google removing most of the offending apps.

  • Published its guide to Vulnerability Discovery and Disclosure helping companies of all sizes implement robust vulnerability disclosure processes. The guide was also published by the International Standard Body, ETSI.

  • Held two conferences (Safety, Security and Verification in Critical Systems and VICECon) bringing experts together to share on topics around vulnerability research and sharing.

Published

Reviewed

Version

1.0

Written for