Annual Review 2022 launch

Introduction
Good morning and welcome to the NCSC’s sixth Annual Review launch.
It gives me great pride to be here and to celebrate the dedicated work from right across the NCSC that this Annual Review is based on. And I wanted to say a huge personal thank you to my team who work incredibly hard – as I think all of our cyber security experts across the UK have done in what has been quite a year – but in particular a big thank you for the work you’ve done, you’re an amazing bunch and I’m very proud of you.
It is also an important moment to pay tribute to the really invaluable support that we have received from a much wider community, whether that is our colleagues in wider GCHQ, our partners across the intelligence services as a whole, across Government departments, law enforcement, and very fundamentally our partners in the cyber security industry and private sector in the last year. Thank you very much indeed.
It has also been a year of impressive achievement for all of you and I’m incredibly proud of the work we do together. One of the most consistent questions I get from my international partners is about how the UK has been able to mobilise a genuine whole-of-society effort which goes beyond the public sector and government to work together for the greater good for the UK and make us the safest place to live and work online.
State threats
Because it has been a year of quite profound change in the cyber security landscape. In some ways, for me, it was the year that the private sector took state threats seriously as we began to prepare for – and then see in reality – the horrific invasion of Ukraine by Russia.
The return of war to Europe presented a unique set of challenges in cyberspace for the NCSC, our partners and our allies.
We have of course been part of a huge effort to ensure UK organisations, critical infrastructure and the whole of society are as resilient as they can be to those threats – and thank you for all you have done to make that the case. The preparation was genuinely impressive and I think a real team effort.
Of course, as well as keeping the UK safe, I am really proud of the role the NCSC played, in conjunction with FCDO, in supporting the Ukrainians’ staunch cyber defence in the face of Russian hostility.
One of the key messages I’ve taken away from the last year is the fundamental importance of being prepared for the threats you can see and building that resilience. And the Ukrainians have demonstrated what is possible and I think we can all take a lesson from that. Those efforts were shown to have been really critical in protecting themselves against Russian cyber attacks but also raising their general cyber resilience.
But while the threat from Russia has been particularly obvious over the last year, it’s important not to forget that China’s technical development and evolution – the scale and pace of what they are able to do – is still likely to be the single biggest factor affecting our cyber security in the years to come.
That ‘future look’ at cyber security will be part of the theme at CYBERUK which we will be proud to host in Belfast in April 2023.
Cyber crime
Of course, as Jeremy said, the last year also saw many threats that we were – unfortunately – all too familiar with. Ransomware remains one of the most acute threats that both businesses and organisations more widely in the UK face.
It is a threat to not just our security but also our prosperity. Ransomware attacks have genuine real-world consequences and are a reminder to organisations – of all shapes and sizes – of taking the important mitigation measures set out in our guidance.
As I have said repeatedly, it is vital that organisations treat cyber security as a genuine, board-level risk to be managed – not one to be delegated to technical experts.
This is a risk issue that CEOs need to take seriously and in the past year, in particular in the face of the geostrategic changes we saw with Russia’s invasion of Ukraine, we really saw that conversation escalate to board level. And I think non-executive directors have helped to encourage that as well.
Alongside ransomware, we have also seen low-sophistication cyber crime continue to be a scourge for the British public and organisations. We saw 2.7 million cyber-enabled frauds last year.
But at the same time, we also saw a growing uptake in the services we provide to prevent and to protect against these threats. In particular, I am proud of the 6.5 million reports we received in the last year from the public to the Suspicious Email Reporting Service (SERS) showing that people are becoming more cyber aware and contributing to our resilience.
It is really important that the public understand those reports genuinely help us take down threats that people face. I hope it gives them some comfort that we are doing something about that. That was a 20% increase on last year and we are keen to see that trend continue.
The NCSC, in conjunction with our law enforcement partners, is more resolute than ever in our determination to thwart cyber criminals and make the UK a tough environment for them to operate in.
Resilience
I am pleased to see that in the last year the UK’s resilience has continued to improve – albeit we still have more to do – stopping hundreds of thousands of attacks upstream while bolstering preparedness and helping UK institutions and organisations better understand the nature of cyber threats, risks and vulnerabilities downstream.
Despite that, there remain serious gaps in the nation’s defences, and so the collective resilience-building effort we are all making really must continue apace – a key lesson from the Ukraine experience.
Future threats
This year, what we have tried to do is not just focus on what we’ve seen in the last year. We wanted to focus also on what lies ahead. We have highlighted the threats we see on the horizon.
In particular, we have called out the growing commercial availability of malicious and disruptive cyber tools and the risk of those falling into the wrong hands. Cyber surveillance products and hackers-for-hire offering bespoke services are among the capabilities likely to become more advanced and more available and could be used with greater frequency and potentially less predictability.
As a leading responsible and democratic Cyber Power, the UK is at the forefront of understanding and responding to this increasing threat and calling it out where we see it.
That contrasts with the positive technological insight that NCSC experts provide in support of the UK’s values-driven principles and approach to developing future technologies and the principles that underpin them.
I’m really proud that this work makes a global contribution and reflects the NCSC’s efforts to innovate and build capability to ensure that the technology on which our economy and society depends is secure, resilient and reliable.
Ecosystem
Building a strong cyber security ecosystem has always been vital to our nation’s cyber security – and this work has also continued over the last year.
This is critical for national security, but it is also essential to maintaining the UK’s global leadership in critical technologies and has a significant part to play in the growth of the UK economy as well. The sector is now worth £10bn to the economy and employs 53,000 people.
However, there are 14,000 vacancies and skills shortages continue to hold back further growth in the ecosystem – something we are really focused on. Working with government, academia and industry, the NCSC will continue to build and nurture that ecosystem into the future.
Central to that is a diverse as well as a talented workforce, and I am delighted to see that over the past 12 months initiatives such as CyberFirst have continued to engage thousands of bright, enthusiastic young people in cyber security, while fledgling businesses supported by the NCSC have helped generate hundreds of millions of pounds’ worth of investment.
It is a great source of optimism as we move into 2023. I think my favourite part of the whole year was when I was presenting the prizes at the CyberFirst Girls Competition at the Bradford Science Museum. One of the teams of thirteen-year-old girls sidled up to me and said: ‘Are you really the CEO of the NCSC?’. I said: ‘yes’ and they said: ‘that’s such a cool job’.
I wanted to say ‘yes, it is a really cool job, but it is dependent on a fantastic team, a fantastic collaboration across government, the private sector and we all have a part to play’.
Thank you for what you’ve done, there is still a lot of work to do.