Skip to main content
Annual Review

NCSC Annual Review 2023

Looking back at the National Cyber Security Centre's seventh year and its key developments and highlights, between 1 September 2022 and 31 August 2023.

Page 12 of 16

Case study: The next generation of UK cyber security services

Impact prompt: Hyper realistic image of a family stepping into a phone screen, white background, the phone screen is a window into the future of cyber security, you can see wires. Transparent overlay on the screen of the world map, bright colours.

When the NCSC was set up in 2016, a central aim was to identify and implement ideas to improve the UK’s cyber security, at reach and scale, in ways we could measure. From this came our suite of ACD initiatives designed to reduce the vast number of relatively unsophisticated attacks that impact people and organisations across the UK, by harnessing automation and data.

That core aim also drives the work we do to assure cyber security services provided to businesses and consumers by the wider cyber security industry. We assess what industry is providing against NCSC standards and use the NCSC brand to help consumers identify services that they can trust. This assurance encourages users to take up the services that provide the biggest benefits to national cyber security, at a reach and scale that government could not achieve by itself. It also stimulates the market to develop solutions to the existing and emerging cyber security challenges that we all face.

Together, these industry and NCSC-developed services provide a powerful set of solutions to a broad range of cyber security problems. They’ve had real impact as the Resilience section of this Annual Review shows in numbers. ACD has provided a model for partner nations to adapt to their own national contexts and set the scene for overarching regulatory concepts.

But we all know cyber security never stands still. For example, the general challenges our ACD products and services seek to address endure – find and fix vulnerabilities, share actionable knowledge about threats, detect and respond to breaches – but they shift as those threats develop and as the way technology is used changes constantly, for everyday life, for attack and for defence.

The big question we’re focussed on here is how to use what we’ve done and learnt so far to chart the course for cyber security services in the UK to the end of the decade. How can government and industry develop and deliver the holistic cyber security “offer” needed to keep the UK the safest place to live and work online? Closer to home, what should the NCSC do and – increasingly – how should it support others?








Published

Reviewed

Version

1.0

Written for