NCSC CEO urges fresh perspective on cyber security as a contest
Introduction
What’s it like to feel in control…
only to realise – suddenly – that you’re not?
I play tennis.
Now, clearly, I’m not Roger Federer!
A tennis match is not something I can control.
With enough skill, I might be confident in my abilities.
With enough practice, I might gain an advantage over my opponent.
But I’ll never go into a match expecting to control every point.
Instead, I know that every game is a contest between two opposing players.
And that’s the truth of cyber security:
It’s a contest.
And when we talk about transforming resilience and countering threats that is the mindset we need.
Welcome to Manchester
It is my huge privilege to welcome you to Manchester…a city that is propelling the innovation we need for Britain’s growth.
Less than a mile away is Heron House, the north-west base for the NCSC and GCHQ, offering us a collaborative home...from which we can tap into the thriving local technology sector and work with industry and academia to develop the skills we need for the contest ahead.
The contest
The businesses we run… the services we rely on… the societies we live in…
All exist in cyberspace.
And that space is always evolving.
Almost all organisations...from independent coffee shops to multinationals that keep our lights on...run on IT that isn’t their own.
Their supply chains span the globe. they rely on services from other firms... who in turn rely on technology that isn’t their own.
And in that context, the concept of control is completely false.
We live in a complicated and unpredictable world. And it’s outside our power to always stop the unwanted things from happening.
But it is within our gift to prepare for them. Every organisation must have a business and IT architecture that seeks to minimise the scale of any attack’s impact...and continuity and IT recovery capabilities ... engineered in advance ... to be able to continue and rebuild on those occasions when an attack gets through.
Whether that’s directly at their own door… or indirectly, way down the supply chain, way across the world.
That’s why, over the next couple of days here in Manchester… we are talking about transforming resilience.
Because the contest we are in requires us to control all the variables that are within our control and to be prepared for those that are not.
Controlling the controllable
‘Controlling the controllables’ is the critical foundation for countering the threat.
In theory, my tennis serve is completely under my control.
But in practice, it’s hard to get it right every time.
(As I’ve said, I am not Roger!)
That’s where schemes like Cyber Essentials come in,
Which is driving up resilience at scale... and should be used so much more throughout supply chains.
Equally, the Code of Practice for Cyber Security Governance that we produced with DSIT is designed to help boards and senior leaders... get the grip that’s needed over those things that are within their control.
Scale of threat
Now the threat is one of the things we can’t control.
In just the last few weeks we have seen the very real impacts that cyber attacks can have... and the kind of disruption they can cause for both businesses and individuals alike.
The threat picture is diverse and dramatic.
At the NCSC we’ve managed more than 200 incidents since September last year.
And that includes twice as many nationally significant incidents as the same period a year ago.
Behind those numbers are people, our adversaries...adversaries probing for weaknesses.
Grey zone
Hostile nation states have weaponised their cyber capabilities.
And while they might not be using them in pursuit or support of direct conflict... some are operating daily in the ‘Grey Zone’.
That murky space between peace and war where states and non-state actors engage in competitive activity.
Where plausible deniability means our adversaries are normalising the use of cyber in pursuit of their geopolitical objectives which may not align with our own.
China
So on our adversaries...
China remains the pacing threat in the cyber realm.
The Chinese Communist Party’s strategic approach to capability, legislation and data, means they have a whole – vast – ecosystem, entirely at their disposal.
And the continued activity that we’re seeing come from the Chinese system remains a cause for profound and profuse concern.
Russia
And as the Director General of MI5 has previously warned,
The Russian Intelligence Services have focused - amongst other activity -on waging acts of sabotage...often using criminal proxies in their plots.
With our partners in MI5, including the National Protective Security Authority, we see a direct connection between Russian cyber attacks and physical threats to our security.
These threats are manifesting on the streets of the UK...against our industries and our businesses…putting lives, critical services and national security at risk.
And so the role of our community is therefore not just about protecting systems…it’s about protecting our people - our economy – our society from harm.
Today, I can say for the first time, based on our assessments that as we move closer to the possibility of a ceasefire in the Ukraine conflict ....
it is almost certain that Russia will continue its wider cyber espionage activity ....against Ukraine and supporting countries ....to gain strategic advantage in its negotiation strategy.
Iran, DPRK
Iran continues to pose a threat to the UK and our allies…with the UK facing a heightened threat of cyber espionage from Iranian cyber actors.
And UK firms are being targeted by IT workers in the North Korean system… to generate revenue for their regime ... by disguising themselves as freelance third-country IT workers.
Ransomware
And of course, cyber criminals continue their activity...with ransomware remaining a persistent threat.
We must see a future together where paying ransoms is no longer considered an option... where the business model for the attackers no longer works.
The recent Home Office consultation on ransomware...was an important step on that journey.
But we all have a critical role in building the resilience that’s needed to ensure recovery can happen without the payment of a ransom.
AI
One thing that is changing the contest is AI.
As we begin to properly integrate AI into our lives we make ourselves more dependent on technology, and so, we become more exposed to the impact of cyber attacks.
AI will cause us to be vulnerable in new ways... and it will cause the threat to accelerate and change as our adversaries adopt AI.
But...
AI also provides huge promise for our cyber defences.
The prospect of AI tooling used in code generation... can help make Secure by Design a reality.
While AI tooling in defence operations enables threats to be identified and eliminated at machine speed.
And so, to be fit for the contest, we must embrace the technology.
Because we see there will eventually come a digital divide... between those who integrate AI into their cyber security and those who don’t.
Partnerships
But we must remember in the face of these challenges...that the contest for cyber security is not about any of us working in isolation.
Our adversaries see us as an interconnected system.
And so, we need to respond not as individuals, but as a movement, working in synergy to defend ourselves – and our way of life.
The NCSC has a vital role in this movement…
With the mission of making the UK the safest place to live and work online.
And three main areas of focus:
First...to raise defences and resilience across the UK...
For example, since announcing the next stage of our Active Cyber Defence services, we’ve carried out trials to gain better market understanding.
Working closely with partners to build capabilities including Share and Defend, which is sharing known malicious domains with internet service provider partners in almost real time, enabling them to block millions of attempted connections from their customers, intervening at scale to defend our society.
Our second area of focus is leading the UK’s defence against the most sophisticated cyber adversaries.
This is where our position within GCHQ is so important.
We're able to generate the intelligence about what our adversaries are doing... and can act on it at pace.
Working hand-in-glove with the National Cyber Force, who are at the forefront of cyber effects operations, disrupting our adversaries' capabilities...
And with our colleagues at the National Crime Agency...to combat cyber crime... by taking action against those responsible...because in this contest, offence is a vital part of defence.
Likewise with the National Protective Security Authority, raising defences against complex hybrid threats.
Then...as the National Technical Authority for cyber security we have a responsibility to provide guidance that can be relied on.
In March, we published a roadmap for the migration to post-quantum cryptography...
A key milestone in helping organisations safeguard their systems from the threat of quantum computing.
We know in the NCSC we can’t double our impact by doubling our size or our effort.
That is why we work so closely with so many of you who live the contest every day.
We also know that being fit for the contest requires diversity.
Historically, our industry has not been a beacon of diversity and inclusion.
Thankfully, that is beginning to change.
I’m proud of the 85,000 girls who have participated in CyberFirst...taking the first step in their cyber security career.
And I’m proud to have the first female director of GCHQ, Anne Keast-Butler, as my boss.
But we have a long way to go.
Genuine diversity is not yet part of the DNA of our industry... and that must change.
Finally, in cyberspace the UK is not an island.
The movement we need to build for the contest ahead must be international.
That is why we work tirelessly with our Five Eyes partners and our close allies - many of whom are here today - to disrupt the threats that require our intervention and join up our approaches.
Conclusion
So no matter what your mission is, whether you’re the coffee shop down the road, or a vital part of our critical infrastructure, cyber security must be part of that mission.
CYBERUK is about what we all need to do together to ensure our collective success.
To truly counter threats...transform our resilience...and be fit for the contest ...together.
We cannot control everything.
But we must control the things that we can... and be prepared for the things we can’t.
Thank you.
With that, I am delighted to welcome to the stage...
The Minister responsible for Cyber Security who continues to champion our effort in bolstering the cyber security of our nation...the Chancellor of the Duchy of Lancaster and Secretary of State for the Cabinet Office, Often referred to as CDL Pat McFadden