NCSC Annual Review 2023
Pages
Page 5 of 16
CEO Foreword

I am very proud to present the seventh Annual Review of the National Cyber Security Centre, a part of GCHQ. Today, seven years on, our mission remains to make the UK the safest place to live and work online.
We must continue to adapt to meet ever-evolving cyber security challenges. Whether these come in the form of rapid development of technologies such as artificial intelligence (AI), state adversaries seeking to gain advantage over us, or something that none of us have yet predicted , we must ensure that the UK, as a responsible cyber actor , stays (at least) one step ahead.
In this year’s Annual Review , we reflect on key developments, achievements and trends from the last year. We’ve also included five case studies on areas of specific interest to the cyber security community – setting out the NCSC’s thinking on AI cyber security, on securing the UK’s critical national infrastructure, on defending our democratic processes, the future of UK cyber security services (including the NCSC’s role in their provision) and reflecting back on what we have learned from Russia’s invasion of Ukraine.
To make sure that the NCSC continues to focus our work where it is most needed, and to deliver against the objectives in the government’s National Cyber Strategy, we will focus on three priorities over the coming year.
First, we must improve the UK’s cyber resilience to the most significant cyber risks. We will continue to improve our understanding of the threats we face and use this knowledge to strengthen resilience in the areas that carry the most risk for the UK, be that across government or to the companies involved in delivering our critical national infrastructure. We have learned a lot about our resilience in light of the ongoing war between Russia and Ukraine, which remains the most sustained and intensive cyber campaign ever. But as the threat landscape evolves, we will need to measure the impact we can have on resilience, as well as while working with others to maximise our success.
Secondly, we must retain our edge. Technology is developing faster than ever, and, in an increasingly unpredictable world, our adversaries are seeking to use this change for their own advantage. We must ensure the UK retains its edge in the face of future cyber security challenges, including those emanating from China, which we know poses an epoch-defining challenge in the years to come, as well as those posed by future technology shifts. We will need to ensure that the technology we deploy throughout our economy is secure by design, and that we have the technological capabilities and partnerships for the future to enable us to counter these threats as they evolve.
And finally, the NCSC will only be successful in its mission if we are the strongest organisation we can be. We must continue to evolve as the UK’s national technical authority on cyber security, deepening our expertise and continuing to increase the diversity of our workforce. We will continue to listen to and learn from external specialists, ensure our services work for those who use them, and engage in public debates about the implications of evolving technology for our democratic values.