NCSC Annual Review 2021
Pages
Page 20 of 44
10 Steps to Cyber Resilience
One of the NCSC’s most popular pieces of guidance, 10 Steps to Cyber Security, was refreshed this year to reflect the changes in the way organisations and employees worked due to Covid-19, and the related cyber risks this posed.
Since the original advice was issued nearly ten years ago, there has been a growth of cloud services, the shift to home and hybrid working, and changes in the threats, such as the rise of ransomware and supply chain vulnerabilities.
This updated guidance aimed to help organisations manage their cyber security risks by breaking down protection into ten components. The guidance, which saw over 45,000 unique page views and 5,100 downloads this year, continues to be targeted at security professionals, and provides a route into more detailed guidance on specific topics.
| Step | Description |
|---|---|
| Risk management | Take a risk-based approach to securing your data and systems. |
| Engagement and training | Collaboratively build security that works for people in your organisation. |
| Asset management | Know what data and systems you have and what business need they support. |
| Architecture and configuration | Design, build, maintain and manage systems securely. |
| Vulnerability management | Keep your systems protected throughout their lifecycle. |
| Identity and access management | Control who and what can access your systems and data. |
| Data security | Protect data where it is vulnerable. |
| Logging and monitoring | Design your systems to be able to detect and investigate incidents. |
| Incident management | Plan your response to cyber incidents in advance. |
| Supply chain security | Collaborate with your suppliers and partners. |
I heard from a senior industry contact that a great many people look at our website as being the perfect version of giving information on what you should do in order to be secure as possible.
Paul Maddinson, NCSC’s Director for National Resilience & Strategy