NCSC Annual Review 2023
Pages
Page 12 of 16
Case study: The next generation of UK cyber security services

When the NCSC was set up in 2016, a central aim was to identify and implement ideas to improve the UK’s cyber security, at reach and scale, in ways we could measure. From this came our suite of ACD initiatives designed to reduce the vast number of relatively unsophisticated attacks that impact people and organisations across the UK, by harnessing automation and data.
That core aim also drives the work we do to assure cyber security services provided to businesses and consumers by the wider cyber security industry. We assess what industry is providing against NCSC standards and use the NCSC brand to help consumers identify services that they can trust. This assurance encourages users to take up the services that provide the biggest benefits to national cyber security, at a reach and scale that government could not achieve by itself. It also stimulates the market to develop solutions to the existing and emerging cyber security challenges that we all face.
Together, these industry and NCSC-developed services provide a powerful set of solutions to a broad range of cyber security problems. They’ve had real impact as the Resilience section of this Annual Review shows in numbers. ACD has provided a model for partner nations to adapt to their own national contexts and set the scene for overarching regulatory concepts.
But we all know cyber security never stands still. For example, the general challenges our ACD products and services seek to address endure – find and fix vulnerabilities, share actionable knowledge about threats, detect and respond to breaches – but they shift as those threats develop and as the way technology is used changes constantly, for everyday life, for attack and for defence.
The big question we’re focussed on here is how to use what we’ve done and learnt so far to chart the course for cyber security services in the UK to the end of the decade. How can government and industry develop and deliver the holistic cyber security “offer” needed to keep the UK the safest place to live and work online? Closer to home, what should the NCSC do and – increasingly – how should it support others?
Where do we go from here?
We’ve come a long way by focusing on what the NCSC can – in collaboration and partnerships with others – imagine, build, test and deliver. If our intention is reach and scale, we think the time is right for an ambitious expansion in scope and purview. That means taking a fresh look at:
The NCSC – as a national technical authority and part of GCHQ – focusing on the things it does best, working in a different way with …
… new centres of cyber security excellence and endeavour being developed by government under the auspices of the 2022 Government Cyber Security 2022-2030 and 2023 Fraud Strategies, and …
… combining with the broad capacity and capability of industry and academia to catalyse and incentivise development and delivery of the range of services the UK needs and an evidence-based approach to their evaluation
Getting the relationships right between these three is key to making sure that everyone living and working in the UK feels the benefit of cyber security at a national level.
What should the NCSC's future contribution be?
The NCSC vision for its digital and assured industry services is to focus in on the things we’re set up to do best: innovation, data, and partnerships.
-
On innovation:
as a national technical authority we deal every day with the cyber security problems our customers face, and the way those challenges are likely to develop in future. We combine our technical expertise and relevant relationships from government, academia, and industry to develop solutions that can be tested against the challenges that we all face. This approach is at the heart of ACD, and we want to get back to doing more of it.
-
On data:
the cyber security community is on a journey of turning cyber security from an art, dependent on a few expert individuals, to a science that can be scaled. At its heart, this requires data; so that knowledge can be shared, hypotheses tested, and impact measured. It’s not always easy, but it is essential. Our experience to date (and the history in other fields, such as medicine) is that such an approach results in significantly improved outcomes, transparency and trust.
Over the past year we’ve been exploring with partners the challenges defender communities have working on together at an organisational, sector or national level. It’s clear that data is going to take an increasingly important role in helping defender communities to defend as one, in an efficient and increasingly evidence-backed way.
Working together is the best way to build the picture of vulnerabilities and threat we need to defend the UK. Next year the NCSC will be working to address some of the challenges identified this year, making it simpler for defender communities. We’ll also be doing the things that only the NCSC can do.
We will continue to publish our findings in line with the NCSC’s commitment to transparency and responsible use of artificial intelligence et al.
-
On partnerships:
nearly everything that the NCSC does, we do with our partners in some form. The challenge of scaling cyber security means that we need to better leverage our existing partnerships and develop new ones to make much more out of them than we currently do where our services are concerned. We need to do this in multiple areas: for example, we are working closely with the UK Cyber Security Council to develop and oversee the specialist standards the UK needs to manage its cyber risk, enabling the NCSC to focus on other areas.
How do we need government’s cyber security capabilities to develop?
We often say that cyber security is a team sport. What might that mean for the way the NCSC needs to work with government partners on the future of digital and assured industry services? Two recent developments show us the way.
The first is the development of the Government Cyber Coordination Centre (GC3), announced in 2022, which will coordinate cyber security efforts across the public sector. The GC3 will start by coordinating resilience response to incidents and vulnerabilities", transforming how cyber security data and threat intelligence is shared, consumed, and actioned across government. This presents a huge opportunity to galvanise the way services are developed, delivered, and used over the coming years, and to build the foundations for an approach to government cyber security that is driven by data and rooted in evidence.
The May 2023 Fraud Strategy emphasises “tackling fraud at source and incentivising every part of the system to take fraud seriously”. This reinforces the need for a whole ecosystem of support across the UK that builds on the unique strengths of the NCSC as national technical authority in concert with the ability of the PROTECT network and Cyber Resilience Centres amplifying on the ground across the nation.
And beyond that?
It remains a strongly held NCSC view that the “team” extends well beyond government when it comes to achieving cyber security success at the national level. Over the past 12 months, the NCSC has been working with industry to launch new schemes, targeting a wider set of customers, and assuring industry to work in new and expanded areas on behalf of the NCSC – and there is more to come. But where do we see potential to drive systemic improvement?
Simpler, more accessible services
Our work with small organisations, backed up by research, highlights a need for products and services that help users find and fix basic vulnerabilities in their websites, email configuration, and infrastructure. These need to be optimised for ease of use so that users can take manageable steps that bring about modest but effective reductions in risk from commodity attacks. Industry-provided services Cyber Essentials and Cyber Advisor give trusted expertise, whilst the initial NCSC contribution has been to prove the concept through services like Check Your Cyber Security (now incorporating Email Security Check) and we plan to do more. But – back to reach and scale – what we really want to do as a national centre is develop the general statement of what good looks like for this family of products so that others can lead the charge.
Cyber security as science
As a data-driven organisation, measuring the impact of these services is critical to ensure we are making a difference. But it's hugely challenging and still needs significant research. The four Research Institutes, supported by the broader Academic Centres of Excellence in Cyber Security Research community, offer access to world class academics which will continue to help us tackle this challenge.
An exciting future
We’re confident that, in close partnership with our colleagues across government, our collaborators in academia, and our friends in industry, the coming years are full of opportunities. Getting cyber security right allows companies and organisations to flourish; if we don’t, the risks – whether to businesses or to the functioning of society – can be existential. Only by working together can we develop, deliver, and make best use of cyber security services that we will all need to continue to live and work safely online.