NCSC Annual Review 2021
Pages
Page 40 of 44
Setting standards, certifying professional practice and assuring services and products
Defining what ‘good’ looks like
The NCSC uses its technical authority to endorse the quality of cyber security products and services. In doing so, it is creating a trusted marketplace, one that helps consumers improve their resilience and raises standards. From products such as Smart Meters, to professional services like Incident Response or Cyber Security Consultancy, the NCSC defines what ‘good’ looks like - whether this is at a national level or for small businesses that need to meet growing requirements.
Cyber Essentials
The NCSC’s Cyber Essentials scheme continued to help develop and grow the ecosystem while at the same time bolstering the UK’s resilience to cyber attacks. The government backed scheme helps organisations, whatever their size, guard against a whole range of the most common cyber threats. This not only reassures customers and organisations of a foundation level of protection against cyber attacks, but increasingly government contracts often now require this basic certification too.
Since its launch, the certification scheme - which is jointly overseen by DCMS and delivered in partnership with The IASME Consortium - has awarded over 75,000 Cyber Essentials certificates to enable users to gain official recognition for understanding and applying a set of 5 basic technical controls.
In September 2020 NCSC helped DCMS deliver a £500,000 funding package to enable vital healthcare suppliers to improve cyber security and gain Cyber Essentials certification. The scheme helped 170 small and medium-sized businesses, including medical suppliers and primary care providers, improve their cyber resilience and ensure the continued delivery of services throughout the pandemic.
In May, to help organisations better understand what they need to do to attain this base level of security, the scheme developed further with the launch of the Cyber Essentials Readiness Tool. The free online resource, which was launched at CYBERUK, helps organisations prepare for the certification process by asking a series of questions about hardware, software, and boundary devices such as firewalls, as well as use of passwords. On completion of the survey, organisations are presented with a bespoke action plan that outlines the steps needed to prepare for the certification process. 11,181 users have used the Readiness Tool since its launch with the biggest users being SMEs.
Through Cyber Essentials, the NCSC is fuelling the growth of the UK’s cyber security industry, licensing the assessment process to certification bodies across the UK and Crown Dependencies. There are now over 273 cyber security companies licensed to deliver Cyber Essentials employing 803 assessors. Over 80% of these companies are micro and small businesses.
This year 24,806 Cyber Essentials certifications were awarded, including 4,591 organisations achieving Cyber Essentials Plus status.
There are two levels of certification to demonstrate an organisation’s implementation of a set of technical controls:
- Cyber Essentials, an independently verified self assessment
- Cyber Essentials Plus, has the addition of a technical audit by a qualified assessor
Benefits of being certified include:
- automatic cyber liability insurance for any UK organisation who certifies their whole organisation and have less than £20m annual turnover
- you can demonstrate compliance with government procurement rules
- reassure customers and potential new business leads that cyber security is taken seriously
Driving professionalisation in cyber security
As the cyber security sector continues to grow, and as more businesses and organisations consider their resilience or broaden their cyber security controls (for example to meet government procurement requirements) there has been an increasing demand for cyber security professionals and services.
To help identify varying levels of standards the NCSC updated its Certified Cyber Professional (CCP) scheme this year. This saw a move away from ‘roles’ to the certification of specialisms, allowing specialists to demonstrate their competence through rigorous assessment – setting a benchmark for cyber security.
As both an assessor and an applicant, and as someone involved in winning work and recruiting, CCP is the only scheme where the balance of academia, experience and human behaviours are assessed properly to ensure practitioners can operate independently. Applying such rigour provides a level of confidence in the people we trust to support customer needs, as well as the authority to act on behalf of the NCSC.
Ian Hughes, Principal Security Consultant, Thales
In July the NCSC launched Risk Management as its first certifiable specialism under the revised scheme. A new ‘Security Architecture’ specialism is being piloted, with others expected to follow. The NCSC also announced it now formally recognised two levels of expertise in the cyber security professional as:
- Certified Cyber Professional means that the NCSC affirms an individual can apply their knowledge and skills in a range of organisations, with an ability to deal with technically more complex scenarios and different environments.
- Associate Cyber Professional means that the NCSC affirms an individual’s expertise in a range of typical scenarios, and that they are an effective and skilled member of a team or within established organisational processes.
Certified Cyber Professional assurance scheme
The NCSC developed the Certified Cyber Professional (CCP) assurance scheme in consultation with government, industry and academia to address the growing need for specialists in the cyber security profession.
The service sets the standard for UK cyber security professionals and is at the heart of efforts to build a community of recognised professionals.
Benefits of being in the scheme include:
- professional expertise and competence are independently assessed and verified by Certification Bodies (CBs) approved by the NCSC
- a growing community of recognised professionals whose specialisms stand apart from other practitioners
- Cyber Professionals can act as Head Consultants in an NCSC Certified Cyber Security Consultancy
Assuring Products and Services - increasing the NCSC’s reach by harnessing the UK’s Cyber Security Industry
As well as redefining what ‘good’ looks like for the cyber security profession, the NCSC has continued this year to set the standard for industry products and services. Through its Commercial Assurance schemes, the NCSC assessed industry offerings against these standards, and - if they were met – allowed these products and services to use the NCSC brand.
NCSC assesses and assures products and services across several areas:
- Security Verification Services: which includes CHECK, the penetration testing scheme run on behalf of the government.
- Certified Cyber Security Consultancy: including Risk Management, Security Architecture and Audit & Review – mirroring areas assessed by CCP specialisms
- Cyber Incident Response: to help companies respond to and recover from attacks, such as ransomware
- Product Assurance: all Smart Meters and recognised smart metering products in the UK must be assured by NCSC licensed labs
By creating a trusted marketplace that helps UK consumers improve their security, the NCSC continued to raise standards and assure the market. This work continued to support the UK economy by helping to open up opportunities to sell UK cyber security products and services to foreign markets.
UK Cyber Security Council
To support the government’s wider work on improving cyber security skills and driving professionalisation, NCSC has also supported industry efforts to establish the new UK Cyber Security Council, funded through DCMS. This new organisation will be responsible for developing and embedding professional standards and career pathways across the wider cyber profession, and will look to build on the momentum of NCSC, government and wider industry work in this space to date.
Key achievements this year
-
Certified Professional
Launch of a new Risk Specialism. Now running a pilot for Security Architecture
-
Certified Training
Mapping of Cyber security training modules to CyBoK means applicants can now decide between similar certified courses on the basis of the knowledge taught.
-
Incident Response
Brokerage offering launched to help critical organisations get the right level of support quicker, with NCSC sharing knowledge with the supporting company for a more efficient approach. 10 victims have already been offered help.
-
Cyber Essentials
198 Covid-19 support packages were delivered to 170 health sector organisations. More than 50% said they will now continue investing in cyber security. Added benefit of supporting 21 small certification bodies through the pandemic.
-
Cyber Essentials Readiness Tool
Launched at CYBERUK. In the last 12 months we have sponsored 1,689 pen tests and currently have 26 companies recognised under the scheme.
-
Certified Consultancy
Now has 27 companies with 35 service offerings and 37 Head Consultants recognised under the scheme.
Participating in the i100 programme challenged my way of thinking and allowed my firm to help the NCSC with their objectives in a really beneficial way. We all gained from the insight and relationships which developed through working together.
It gave me the opportunity to collaborate with peers from the legal profession and to talk about the challenges we faced as an industry with more than a little sensitive data to manage. It also provided an open channel for the NCSC to provide feedback on events in the legal sector and ensured their guidance reached the desired audience.
The Information Security and Compliance Manager at a large European Law Firm and a member of the i100 Legal group
Sharing best practice – and people
Having nurtured talent, supported startups, and set, certified and assured industry standards the NCSC has continued to welcome those from the sector it has helped to develop and grow through its Industry 100 (i100) scheme.
This initiative has continued to facilitate close collaboration between the public and private sector to challenge thinking, test innovative ideas and enable greater understanding on cyber security. Industry 100 secondees work across a wide range of short-term placements within the NCSC, normally on a part-time basis. This year contributors included representatives from the sectors of legal, finance, aerospace, telecoms, academia, oil and gas, nuclear and engineering.
Equality, Diversity and Inclusion
The NCSC continued its drive to improve the diversity of the cyber security sector. In addition to initiatives like the CyberFirst girls competition, the NCSC launched a second survey for those in the sector. The new assessment, conducted in partnership with the accounting firm KPMG UK was expanded to capture new benchmarks on disability, neurodiversity, location of workplace, employer size, and seniority.
It will build on the results of the inaugural report which revealed that the sector does not benefit from the breadth of talent of the UK’s rich and diverse communities, particularly with regards to a lack of inclusivity across gender, sexual orientation, social mobility, and ethnicity. It urged leaders to become accountable for diversity and inclusion within their organisations and for the industry to improve how it could learn from best practice within and outside the sector.
The NCSC accepted all of the recommendations from the first report and took a range of actions as a result, including the introduction of an Outreach Officer role designed to encourage people from under-represented communities to begin a career in the cyber security profession. The NCSC agreed that evidence suggested that a more welcoming community would lead to greater diversity, increased innovation, and better outcomes, which would help to provide greater security for the UK.
Data from the new survey will be used to identify areas needing further improvement as part of the NCSC’s objective to transform the industry into an exemplar of best practice for diversity and inclusion, and to encourage a wide range of individuals to choose a career in cyber security.