Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 19 of 27
Implementing effective cyber security measures

Put in place defences that will protect your critical assets against the biggest threats.
Introduction
Implementing effective cyber security measures is not only a key part of meeting your regulatory requirements, but will also help reduce the likelihood of a significant incident. Even basic cyber security controls can reduce your exposure to cyber attacks, and lessen the associated reputational, financial and legal impacts.
With a baseline of cyber security controls in place to mitigate against the most common cyber attacks, you should then tailor your defences to mitigate your organisation’s highest priority risks. Your measures will be tailored both to your technical estate (protecting the things you care about the most) and to the threat. You will need to consider various factors including your organisation's risk appetite, and the sensitivity of the data you hold.
Implemented well, security measures will also help your workforce do their jobs effectively, leading to improvements in productivity and better compliance.
What are security measures?
By security measures, we mean steps that you put in place to mitigate a known cyber security risk. It’s important to note that this will be a mixture of both explicit and implicit measures:
- an explicit measure is one that uniquely addresses a specific cyber security risk alone; for example, antivirus software is designed to detect, stop and remove viruses and other kinds of malicious software
- an implicit measure addresses a cyber security risk, but will also provide value to the business in other ways; for example, an asset management system can help you make good procurement decisions and speed up financial reporting, but it also addresses the cyber security risk of ensuring software is kept up to date (so it’s less vulnerable to cyber attacks)
This means cyber security measures won’t always be technical products or services, but are just as likely to be processes, training or policy. Although not a technical measure; Cyber insurance can assist in reducing business disruption and offering financial safeguards in the event of an incident. Additionally, it can provide support in dealing with any legal or regulatory consequences that may arise following such an incident.
Essential activities
Tailor your defences to your highest priority risks
Your organisation should take a risk-based approach to implementing cyber security measures. Your measures will be tailored to protecting the things you care about the most, against methods used by specific attackers. All measures should be traceable to the specific cyber security risks they mitigate.
Use established security controls
Cyber criminals often use common methods to attack an organisation. A lot of these methods can be mitigated against by implementing well-known cyber security controls. There are several frameworks that outline what good cyber security controls look like. These include the NCSC's 10 Steps to Cyber Security, ISO/IEC 27002 and the Cyber Assessment Framework (CAF).
Layer your defences
As with physical and personnel security, cyber security can make use of multiple measures which (when implemented simultaneously) mitigate single points of failure. This approach is commonly referred to as 'defence in depth'. Each measure provides a layer of security and deployed collectively, greatly reduce the likelihood of a cyber incident.
Conduct regular reviews of your measures
Cyber attackers adapt and evolve, and your security needs to do likewise so testing the effectiveness of your security controls is important. You can review defensive measures against suitable frameworks such as Cyber Assessment Framework (CAF), or certification schemes such as Cyber Essentials.
You should rehearse how your organisation responds to cyber attacks by using the NCSC’s Exercise in a Box resource, which provides a safe environment for your organisation to assess its resilience. In addition, it’s good to consider testing your organisation systems and security processes by emulating an attacker hacking into secure systems or data by ‘red teaming’. A ‘red team’ can be an externally contracted group of penetration testers or a team within your own organisation, tasked to hack your environment using real world techniques in order to test a wide variety of cyber attacks, breach scenarios or organisation specific risks before they occur.
Defend against someone inside your network
Your cyber security approach should recognise that a criminal (which can range from a disgruntled employee to a state funded individual intent on stealing your intellectual property) will be able to access your system. There could also be instances where an insider inadvertently causes harm due to human error, lack of awareness, or unintentional misuse of resources.This means you need to have controls in place to minimise the harm that they can do once they are inside. You can do this by restricting the access they have to service and information. Monitoring and logging are key to being able to detect signs of malicious activity as quickly as possible, and limiting the damage they can do.
A charity organisation was first aware there was an incident when their bank contacted them querying a change in a suppliers bank details.
Their CISO explained, ‘We checked the Finance Manager’s email account and discovered that a rule had been set up to divert any email containing the words ‘payment’, ‘invoice’, ’bank details’ etc to the Really Simple Syndication (RSS) feeds folder. At this point the fraudster doctored the body of the email and the invoice attachment with the fraudulent bank details. It was believable as the main body of the email had clearly come from a known supplier as it was answering questions that only they could have known. We thought at this point that we had narrowly missed making a payment to a fraudulent bank account.’
Another supplier emailed a week later to chase payment of an invoice which the organisation thought they had paid. On checking the payment details they discovered the payee’s account details were different to those on the invoice.
‘Looking back, the Finance manager had noticed that people were saying that they had emailed her but they were taking a day or two to come through but it was just thought to be a lag with the system. This will be a red flag alert going forward.’
Immediate Action Taken
- Finance Manager called the bank and alerted them to the fraud
- We reported to Report Fraud in order to obtain a crime reference number
- We reported to The Charity Commission as a serious incident
Lessons learned/further actions
- We updated our processes and procedures
• Weekly checks on email account to check no rules have been set
• check email ‘safe senders’ to make ensure authentic
• check the location of any logins to Office 365 to ensure no activity on the account
• check RSS Feed folder for rogue emails
• Bank detail for new and updated suppliers to be verified by a phone call
- If making a payment online and bank details don’t match, phone and check with the payee that the details are correct
- Implemented multi factor authentication for logging into Office 365
Indicators of success
These facilitate decision making and improve performance and accountability. They should be aligned to key business functions, and could include mean time to detect and recover from an incident. These metrics provide the board with the information needed to discuss the investments needed to bring about improvements.
While there are a lot of technical details involved in assessing threats and risks (and the measures that protect against them) if the overarching approach to determining and reviewing measures can be easily explained and is understood by the board, that is a good sign that an effective approach is being taken.
Ensuring that the focus of your cyber security measures is aligned with the risks you have identified and prioritised is a key indicator that decisions are being taken in light of the actual threats your organisation is facing.
This may include piloting them, co-designing, or testing how well they work. Engagement with the workforce is an important sign that the measures are implemented in a way that is likely to deliver value.
The nature and depth of that review may vary, but if an overall review has been conducted in the recent past, that is a good sign that you can continue to be confident that your measures have remained effective.


