Skip to main content
Annual Review

NCSC Annual Review 2024

Looking back at the National Cyber Security Centre's eighth year and its key developments and highlights, between 1 September 2023 and 31 August 2024.

Page 11 of 16

Chapter 02: Building the UK’s cyber resilience

From critical national infrastructure to emerging technology, cyber resilience underpins the UK’s economic future and safety.

The speed at which new technologies  – such as artificial intelligence – are being used to facilitate cyber attacks continues to rise, as does the volume and sophistication of cyber threats from a range of capable adversaries.

The NCSC is prioritising the cyber resilience of the UK’s critical systems against the most advanced and sophisticated threats. At the same time, we’re raising our national resilience to commodity cyber attacks across the whole of the UK’s economy, using the unique insights we get from being a part of GCHQ, and by working with partners across government, industry, and academia.

More specifically, the NCSC is building UK cyber resilience by:

  • delivering transformational active cyber defence services and interventions
     

  • supporting legislative and regulatory reform
     

  • growing the UK’s cyber ecosystem

  • influencing the security standards for new and emerging technologies

This year the NCSC, working with the Cabinet Office Election Cell and alongside policing, central and local government and private sector organisations, helped to deliver safe and secure elections. We worked with the NPSA to provide dedicated support and services to high-risk individuals and organisations targeted by nation-state actors wishing to disrupt the democratic process. The general election was delivered smoothly and securely. No major information operations, cyber or concurrent incidents that caused a notable impact on the election and its outcome were observed.







Certifications by business size

 Cyber Essentials certificates Cyber Essentials Plus certificates 
Micro35%33%
Small35%29% 
Medium20%23%
Large10%15%

 

Top 4 reasons given for certification

To generally improve cyber security33%
To give confidence to our customers31%
Required for government contract13%
Required for commercial contract13%

As recommended by users

  • Decorative image

    91% of customers would recertify to Cyber Essentials next year

  • Decorative image

    89% would recommend certifying to other organisations like theirs

  • Decorative image

    40% of smaller organisations implemented the controls for the first time

  • Decorative image

    2% failure rate for Cyber Essentials, dropping for the third straight year

  • Decorative image

    The estimated fail rate for Cyber Essentials across all organisation sizes has dropped from 2.45% to 2.0%.

  • Decorative image

    This year saw an increase (of 6%) in renewals of CE certifications 72% compared to the previous year.

  • Decorative image

    Of sole traders, micro and small organisations, around 40% told us it was the first time that they’d implemented the Cyber Essentials controls. This figure is an increase of 10% on last year.

  • Decorative image

    The proportion of organisations that say they will recertify (91%) and those saying they would recommend the scheme (89%) have both increased.

  • Decorative image

    Achieving Cyber Essentials Plus compliance across their partnership network has helped St James Place reduce cyber security incidents by approximately 80%.


Cyber Essentials Plus

Cyber Essentials Plus offers a higher level of assurance of the standard Cyber Essentials scheme, as it includes a technical audit, carried out by an approved third party, to ensure the technical controls have been correctly implemented. This year, St James’s Place, one of the UK’s largest advice-led wealth management companies, asked its partnership network of over 2,800 independent business to certify to Cyber Essentials Plus. In such a large supply chain this had its challenges, but the decision is already showing a positive impact with an 80% reduction in cyber security incidents.

The Funded Cyber Essentials Programme

The NCSC has continued to deliver its three-year Funded Cyber Essentials Programme, by supporting small  organisations that work in those sectors that are at greater risk of cyber attack than others. This may be because of sensitive information they deal with, or because they're seen as an ‘easy target’ for cyber criminals. 

Since beginning the programme, 525 small organisations have benefitted from the opportunity to access free Cyber Essentials support. Initially targeting small organisations in the legal aid and charity sectors (that is, organisations handling sensitive data that would have significant impact if disrupted), we expanded in 2023 to the ‘emerging technology’ sector, widening our offering to small businesses working in AI, engineering biology, quantum engineering and semi-conductors.  

Between September 23 and August 24, 204 applications were approved (29 charities, 99 legal aid and 76 emerging tech companies). Since its launch 90% of organisations responding to feedback feel more confident about cyber security after completing the process.

Cyber Advisor

The Cyber Advisor scheme provides small and medium-sized organisations with access to local, reliable and cost-effective cyber security advice and practical support, all based on the implementation of the Cyber Essentials technical controls. Every Cyber Advisor must work for a company which has met the NCSC’s standards, and pass an independent assessment that measures their:

  • knowledge and understanding of the Cyber Essentials’ technical controls
  • competence in providing practical, hands-on support
  • ability to understand and work with small and medium-sized organisations

Launched in 2023, Cyber Advisor has continued to grow this year, with 100 individual Cyber Advisors now employed by 93 NCSC assured service providers.  

Number of Cyber Advisors by month (since scheme was launched)

February 202318
March 202325
April 202331
May 202334
June 202346
July 202352
August 202361
September 202310
October 202372
November 202376
December 202380
January 202485
February 202486
March 202491
April 202493
May 202492
June 202495
July 202497
August 2024100


Reviewed

Version

1.0

Written for