NCSC Annual Review 2021
Pages
Page 23 of 44
Engaging and Supporting Sectors

From Critical National Infrastructure to communities, from the CEO to the citizen, NCSC has informed and engaged, and developed guidance and tools to meet those varying needs and priorities.
Critical National Infrastructure
Strengthening the resilience of the UK’s CNI will always be a top priority for the NCSC, which is why it has continued to work with government departments, regulators, and private sector operators to ensure the latest threats, risks and vulnerabilities are understood and actions put in place to counter and mitigate them. The majority of this work is with sectors such as communications, finance, energy, water, transport and civil nuclear, but there is also work in several emerging sectors, notably Smart Cities, Smart Energy and Managed Service Providers.
This year the NCSC provided expert advice to the strategically important space sector – worth £16.4bn to the UK economy - to ensure future launch facilities were secure from outside interference and to improve the protection of those providing services, such as the decommissioning of old satellites and the removal of space debris from orbit.
The NCSC have collaborated with the UK Space Agency on industry training and government exercising and have taken a key role in the review of the National Security Risk Assessment where the NCSC’s input on the threat to the space sector has ensured that the right risks are being prioritised.
As part of its ongoing engagement with the oil sector, the NCSC led a cross-organisation exercise on a ransomware attack affecting oil supply. This became a reality in the week preceding the exercise with the compromise of the Colonial Pipeline Co. in the US. NCSC worked with BEIS, industry and other government departments to help build a community of more than 50 of the largest organisations in the sector which is now collaborating on improving its collective cyber security.
This same collaboration made a real-world impact within transport, ports and the food supply chain, where the NCSC has worked to protect these key sectors as they contended with supply chains issues from the pandemic and changes to border controls, as well as their central role to vaccine supplies. This year a series of penetration tests were run at UK ports and the vulnerabilities found were used to advise on the steps needed to ensure better protection.
Financial sector
Working alongside the financial sector authorities, industry, law enforcement and trade bodies, the NCSC continued its efforts to improve the security and resilience of the UK’s financial sector. The NCSC has provided support to the Financial Sector Cyber Collaboration Centre (FSCCC), an industry-led initiative which the NCSC helped to create two years ago.
The FSCCC exists to develop and share the latest understanding of threats to the sector. The FSCCC now consists of over 60 member organisations. This year FSCCC produced five threat awareness briefs, presenting the latest understanding of malicious activity against the sector. Four emergency calls have been held by the FSCCC this year, bringing potentially affected parts of the sector together to address imminent threats and serious vulnerabilities.
Armed Forces and National Security Assets
Working in collaboration with the Ministry of Defence, Armed Forces and defence industry partners, the NCSC continued to contribute to the protection of national security and defence assets this year.
The NCSC supported the development of the Digital Strategy for Defence, which set out plans for how the Armed Forces will use data to underpin technology; worked with the MOD on embedding secure-by-design principles and helped create a modern assurance and accreditation model. It established a team to maintain the highest levels of cyber security for the Continuous-At-Sea-Deterrent (CASD), including ongoing support to the Dreadnought Programme, which will replace the Vanguard-class submarine.
This year, the NCSC supported Carrier Strike Group 21 – the British-led naval force - as it began its first deployment to the Indo- Pacific. This included holding joint workshops with the Royal Navy and providing cyber threat intelligence and technical capabilities.
Working with HM Government
The NCSC works in close partnership with the Government Security Group (GSG) and the Central Digital and Data Office (CDDO) in Cabinet Office to provide cyber resilience leadership across HM Government, including establishing the priority of cyber resilience and understanding of the threat at the highest levels of Government. We also work in close partnership with Cabinet Office to help HM Government and the Public Sector respond where incidents or significant vulnerabilities which have the potential to affect Government broadly. In particular the NCSC helped HM Government understand the SolarWinds and Microsoft Exchange attacks, providing mitigating advice and ensuring Government addressed vulnerabilities as soon as practically possible. Due to the government adopting ACD services the NCSC was immediately able to identify those departments who had compromised versions of SolarWinds, and similarly those using Microsoft Exchange servers. This enabled swift mitigation advice to be given to those affected.
The NCSC provided specialist advice and guidance to many UK government projects, programmes and events this year.
We provided support to the G7 Summit in mid-June, advising on cyber security measures and exercising to ensure it was ready for any cyber incidents that might occur, from large scale Denial of Service attacks to ransomware incidents. Following on from G7 the NCSC turned its attention to support to the cyber security of COP26, taking place in November. We have created new guidance to support the cyber security of high profile to support these and similar kinds of events.
As well as working directly with HM Government Departments, the NCSC has developed guidance which address key shared cyber security related challenges. As the Covid-19 pandemic went through its second wave, we issued further guidance on managing risks associated with a Bring Your Own Device strategy and Working from Home. The NCSC also played a key role in the evolution of the new Government Security Centres (GSECs) to increase the provision and broad availability of cyber security services across departments.
Local Government
This year saw increased uptake of core ACD services - Web Check, Mail Check, PDNS and Early Warning - among local government organisation and councils. For example, the use of PDNS increased from 72% to 80%1 within local authorities.
With some local public services still affected months after cyber attacks taking place and recovery costs reaching millions of pounds – as confirmed by Hackney Borough Council - the NCSC continued to encourage more local authorities to take up these services to increase their cyber resilience.
Work continued on ensuring that cyber security formed part of incident response and civil contingency planning with local public services. The NCSC worked with the Ministry of Housing, Communities and Local Government2 and the Welsh Government to support their ongoing work with local resilience forums to enhance cyber preparedness. This included encouraging the use of the updated Exercise-in-a-Box package enabling users to practice their response to cyber security incidents.
Local authorities have increasingly adopted connected place (or ‘smart city’) technologies over the past year. The NCSC has published new Connected Places Cyber Security Principles to help ensure local authorities use these technologies in a secure and resilient way and is working with DCMS to provide advice and support to local government.
Supporting Small Business
At the start of 2020 there were 1.4 million small and medium-sized enterprises (SMEs3) in the UK employing 11.9 million people and turning over £1.95 trillion4. According to the DCMS Cyber Security Breaches Survey 2021, 42%5 of SMEs surveyed experienced a cyber breach or attack in the previous 12 months, in some cases losing thousands of pounds in income or recovery costs.
With so much at stake, the NCSC continued to place supporting businesses and boosting their resilience as a high priority. It worked to create and promote the use of tools and services for small and medium-sized enterprises, and in May launched an e-learning package for small businesses and charities to help reduce the risk of cyber attacks.
The NCSC launched the Cyber Essentials Readiness tool for organisations to apply basic cyber security principles as part of a joint certification scheme with DCMS. This annual review describes more about Cyber Essentials in chapter 4.
As part of the continued offer to protect and support start-ups the NCSC, in May, published new joint guidance (with the Centre for the Protection of National Infrastructure (CPNI)) to help fledging tech companies, and their innovations, keep secure. The ‘Secure Innovation’ guidance was developed in consultation with emerging technology companies and highlighted the importance of laying strong security foundations for startups, in a cost- effective and proportionate manner to protect their ideas, designs and intellectual property.
In October the NCSC revamped its Small Businesses Guide to help the sector operate more securely online. The new guidance arrived at a time when many organisations had moved their operations online due to the pandemic, and it highlighted accessible and affordable steps to take.
In October the NCSC supported the British Retail Consortium in its refreshed Cyber Resilience Toolkit for Retail. This contained an actionable guide designed for non-cyber experts, such as Board members, those in senior strategic roles, and start-up businesses.
Education
Over the course of the 20/21 academic year there were persistent attacks against academia, leading to the NCSC issuing a cyber security alert direct to the sector in March.
The alert was published following a spate of online attacks against UK schools, colleges and universities from late February. Accompanying bespoke advice was created with input from the sector, while education leaders were encouraged to take swift action.

In April the NCSC launched a free online training resource for the education sector to improve cyber resilience in the face of the increasing threat and the resulting impact, with schools losing money, coursework and access to essential work systems for weeks.
A further alert was published as ransomware attacks against the sector escalated. It was recommended that schools take a ‘defence in depth’ strategy to prevent and mitigate attacks.
Engineering Processes
The NCSC identified that Cyber risks can be introduced by security not always being fully considered in the engineering processes used to develop products used in critical national infrastructure (CNI). This is why, in October, the organisation teamed up with the Institution of Engineering and Technology to produce its first ever Code of Practice for Cyber Security and Safety in Engineering. The code of practice set out a series of principles designed to ensure safety and cyber security teams work together effectively to address the threat of cyber attacks.
Farming
In another first, the NCSC joined forces with the National Farmers’ Union in December to issue a cyber security guide for the agricultural sector. With more farmers relying on and benefitting from digital systems and devices to monitor and manage their operations it was important these were kept secure from online threats.

Sport
In January the NCSC held its first security summit with professional sports clubs and organisations to help protect them against online threats. Over 180 representatives, including from 11 Premier League and 35 English Football League teams, rugby and cricket clubs and a range of national governing bodies, took part in coaching sessions with NCSC’s experts to better understand the threat and the actions to reduce the risk of falling victim to cyber criminals. The sports industry contributes £37 billion to the economy each year and was seen as a high-value target by cyber criminals, with at least 70% of clubs and bodies suffering a breach every 12 months - double the average for UK businesses.6
Construction and Manufacturing
The Department for Business, Energy and Industrial Strategy (BEIS) have been working closely with NCSC to improve cyber resilience in two key sectors, manufacturing and construction. To raise understanding of cyber threats within the manufacturing sector, BEIS commissioned NCSC Assessment to produce a strategic threat paper on cyber threats to the manufacturing sector for release to industry, which was promoted in presentations at the Digital Manufacturing Week industry conference in November. In the construction sector, NCSC have worked closely with CPNI and BEIS to support major construction companies in developing tailored information security best practice for companies engaged in Joint Ventures.
Early Years
Like most other work environments, nurseries and pre-schools became increasingly reliant on technology during the pandemic. As teachers and childminders often work with sensitive information, such as children’s personal and medical data, the NCSC published its first-ever guidance for Early Years practitioners, giving advice on how to keep data and devices secure, and how to communicate with staff and families safely.
1 On 31/08/2020, 291 of 404 local authorities were using PDNS (72%). On 31/08/2021, 318 of 398 local authorities were using PDNS (80%). Note: on 01/04/2021 the number of local authorities decreased from 404 to 398.
2 Later changed to Department for Levelling Up, Housing and Communities
3 1-249 employees
4 According to the GOV.UK National Statistics Business population estimates for the UK and regions 2020
5 Calculated using a weighted mean