NCSC Annual Review 2024
Pages
Page 12 of 16
Realising a more secure and prosperous cyber future
The UK has one of the world’s most advanced digital economies which relies on having a secure digital infrastructure. Our reliance on the technology that underpins much of society comes with a growing threat from nation states, cyber criminals and other malicious actors. Hostile activity in UK cyberspace has grown in frequency, sophistication and intensity.
The NCSC believes that the severity of state-led threats is underestimated, and that the cyber security of critical infrastructure, supply chains and the public sector must improve. There is a growing disparity between the resilience of our infrastructure and the threat we face. The gap between the threat and the cyber resilience of the UK needs to close as a matter of urgency.
Not a technical challenge
The majority of cyber attacks rely on techniques and vulnerabilities that are well known to us. We have the knowledge and the capability to defend against them. For example, we know that the five technical controls defined in the NCSC’s Cyber Essentials Scheme – the minimum standard of security we advise organisations to achieve – can stop the vast majority of commodity cyber attacks.
However, too many organisations are not implementing the most basic protective measures. Schemes like Cyber Essentials are effective; the evidence described in this Annual Review is clear, and it is corroborated by similar data from a range of industry partners. However, the NCSC only issued 30,000 Cyber Essentials certificates last year, which means millions of organisations are leaving themselves open to cyber attacks that we know how to prevent.
So improving the cyber resilience of the organisations, at scale, is not a technical challenge.
The UK needs to wake up to the severity of the cyber threat. We need all organisations, public and private, to see cyber security as both an essential part of operational resilience, and a driver for business growth. To view cyber security not just as a ‘necessary evil’ or compliance function, but as a business investment and catalyst for innovation. Safeguarding systems and preventing data breaches, but at the same protecting reputation and building customer trust and retention.
This challenge is exacerbated by a technology market that does not incentivise organisations to develop secure products (which is discussed in depth in Chapter 03 - Market incentives and the future of technology security). To re-emphasise, the barriers we need to overcome are not technical in nature. Defective and flawed software, sometimes rushed to market, is often at the heart of cyber incidents. We have the expertise and know-how to build a future where products are secure, private, resilient, and accessible to all. The technology to achieve this exists, but the commercial incentives to encourage adoption are flawed. We need to ensure there are market incentives to make this happen.
The NCSC advocates that immediate action is required to enhance the cyber security practices across the whole of society so we can:
- build a national infrastructure that is better prepared to withstand all but the most advanced cyber threats
- create an environment that imposes higher costs on adversaries targeting the UK and its interests
- foster the development of a market for secure technology and services
This is our aspiration for a more secure and prosperous future.
Protecting our digital way of life: the role of legislation
The NCSC raises awareness of the cyber threat and clearly guides citizens and organisations towards trusted cyber security advice, tools and services, promoting best practice, preparedness and mitigation. As the national technical authority for cyber security and critically, an integral part of GCHQ, the NCSC will continue to benefit from and leverage its unique insights to carry out this work. But this will not be enough. There is more to do.
One of the strategic levers that we can use to improve cyber security outcomes is legislation. The Network and Information Systems Regulations 2018 (NIS Regulations) went some way to enhancing the security of critical network and information systems in the UK, covering both ‘operators of essential services’ (OES) and ‘relevant digital service providers’ (RDSPs).
As the UK’s only cross-sector cyber legislation, NIS regulations boost cyber and physical resilience. However, more could be done to build greater resilience into the UK’s critical national infrastructure, to better withstand or recover from attacks by the most sophisticated state-level cyber threats. This government has committed to introducing the Cyber Security and Resilience Bill (CSRB) in this year’s King’s Speech, and we believe it’s a crucial step towards hardening the UK’s cyber defences. The UK government are using this opportunity to broaden the scope of current regulations to protect more digital services and supply chains, to put regulators on a stronger footing, and to strengthen reporting requirements to build a better picture across government of cyber threats to the UK.
The new legislation won’t be an end in itself. First, the implementation of the legislation – across government, across regulators, and across the economy – is a collective challenge. This may not be the only time we need new legislation to protect our infrastructure and economy. We need to listen to organisations working in the sector, to learn from our international partners, and ensure we have the legislation we need to give the nation the tools it needs to contest the threats we face. The scope stretches beyond the confines of our most critical infrastructure, with the Minister for Security recently committing to reviewing the 1990 Computer Misuse Act to combat cyber crime.
As well as strengthening regulation, policy and legislation to accelerate progress on raising resilience, the NCSC is planning to work across government to develop new capabilities to harden defences around our highest priority systems in response to changes in the geopolitical environment. This work will help us to prepare for crises and ensure that our national posture can keep up with what’s going on in the real world. This will include how we communicate the threat, and what is expected of operators to prepare for, respond to, and recover from a cyber incident.
The UK cannot underestimate the severity of state-led threats, or the volume of the threat posed by criminals. The resilience of critical infrastructure, supply chains and the public sector must improve. But so must our wider economy.
We believe that cyber security legislation and regulation in the UK needs to be comprehensive, forward-looking, and responsive to an increasingly dangerous and diffuse threat landscape. Globally pioneering work done in the context of the Telecommunications Security Act has shown how effective legislation can be. We are bringing our technical expertise to bear in shaping and enabling these outcomes.
The NCSC has always believed that cyber security is a team sport, and right now, our collective efforts are not enough. Only when we are clear about what needs to be done, and then together are committed to actually doing it, will we succeed.