Skip to main content

Lindy Cameron's speech to a virtual audience at Queen's University, Belfast

Lindy Cameron's first speech as CEO of the NCSC, as delivered, to a virtual audience at Queen's University, Belfast.

It's really lovely to be back home in Northern Ireland, if only virtually. And in particular to be here at Queen's University, Belfast, where both my parents met and studied. And a particular thank you to CSIT for hosting this event - they are a real role model for bringing academia, businesses and the community together, and creating jobs for the recovery. So thank you.

It's a huge honour to be here as CEO of the National Cyber Security Centre, which in only 5 short years since its launch has helped the UK become a global leader in cyber security.

Its creation showed real foresight, and is widely recognised as an example others want to emulate - as I've learned my introductory calls in this job.

So I'm going to talk about what we have achieved in those five years; about the challenges we face, and, most importantly, about what we need to do about them to sustain our leadership in cyber security - not just as the NCSC but as a country - over the coming decades.

Five years ago, the UK government announced that it would set up the National Cyber Security Centre which I now have the honour of leading.

That announcement was driven by the understanding that better cyber security was critical to our future prosperity.

The scale of incidents like TalkTalk had shaken public confidence. There was a need for a single focal point in government to make sense of the complexity and coordinate the response.

It was one part of a larger vision for better cyber security aiming to make the UK the safest place to live and work online.

And a huge amount has been achieved since then. My predecessor Professor Ciaran Martin (another Northern Irishman) and the team he assembled, should be extremely proud of what they've achieved and the reputation the NCSC now holds, five years since the centre was announced.

And since then, we've dealt with over 2,000 significant incidents ranging from high sophistication covert state-sponsored attacks to criminal ones with major public impact - everything from WannaCry to SolarWinds.

We've got information out quickly and services back up - often before the incident has even been noticed.

We've protected the UK at scale through Active Cyber Defence which in 2020 took down hundreds of thousands of malicious URLs, including over 5,000 web shell campaigns.

We've built resilience: we have worked with all sectors of Critical National Infrastructure to understand their vulnerabilities and enhance their resilience, helping design a framework to help both organisations and their regulators.

We’ve provided accessible, actionable advice to sectors across the economy, from the smallest business to the FTSE Board; from charities to schools, colleges and universities.

We've tracked the emergence of new technologies and advised government on how to adapt, advising on challenging issues like telecoms security, and the evolving risk and opportunity of smart cities.

We've made the internet automatically safer for real people across the UK - we haven't waited for the market to do this.

When we started more than 5% of malicious sites were hosted in the UK. That's now 2%.

And we are working with international partners to make it harder to host malicious sites anywhere in the world.

We've made the internet easy to use, challenging password culture and victim blaming.

And then over the last 12 months we have pivoted to support the UK’s response to the COVID pandemic.

We quickly provided clear guidance to people and businesses on how to work from home securely - including rolling out a new scenario for our Exercise in A Box tool to help with the challenges of remote working.

Four years ago, the NHS was a victim of WannaCry. We are now supporting the NHS to defend themselves at scale, supported by our Active Cyber Defence - including threat hunting support to NHS Digital covering 1.4 million NHS end points.

We have scanned over 1 million NHS IP addresses for vulnerabilities.

We've protected the vaccine supply chain including both academia and businesses.

And we've worked with the government on new technology, including the Covid tracking app.

But of course, this has not been a solo effort - and nor should it be.

Cyber security, as my predecessor drummed into me during our handover, is a team sport, and we in the UK play this team sport really well, both at home and beyond.

Internationally, we have hugely valued relationships with our Five Eyes partners, but also with key operational partners in Europe, the Middle East and Asia. We have hosted events in our London headquarters for national leaders and for NATO.

Across government we work with key departments – with devolved administrations, the Government Security Group, the Government Digital Service, and DCMS, with the wider public sector and local government.

And of course with our colleagues at GCHQ, the National Cyber Force and across the United Kingdom Intelligence Community.

We work on Critical National Infrastructure with the Bank of England, the Centre for the Protection of National Infrastructure, and regulators.

We work on cyber crime with law enforcement partners including the National Crime Agency and the City of London Police, with whom we have rolled out the Suspicious Email Reporting Service.

This has taken over 5 million reports from the British public so far, leading to the removal of 36,000 scams and 71,000 malicious URLs.

Collaboration is key to everything we do, and we work with business, both as potential victims of cyber crime, as partners in recovery and mitigation, and a key source of information in both directions to understand the problem better.

We work closely with trade associations and representative bodies to understand sector cyber maturity, and partner with local business support networks to deliver advice.

Our innovative i100 scheme has allowed us to embed the best of business expertise in the NCSC itself to facilitate the exchange of skills and knowledge and help us understand what business needs.

We've hosted a flagship CYBERUK conference every year until the pandemic, and will be running it virtually this year and then in Wales next year and Northern Ireland in 2023.

We've used our Cyber Accelerator programme to support start-ups.

We use our Academic Centres of Excellence programme in higher education, and CyberFirst schools awards that you’ve heard about to reward and recognise those institutions that are the future of cyber security in the UK.

And nowhere is a better example of this than Northern Ireland.

We have recognised five schools in Northern Ireland for their excellence in teaching computer science and cyber security.

Queen’s University, where I’m speaking today, was recently chosen as lead for a fourth Research Institute in Secure Hardware and Embedded Systems.

And we are delighted that Angoka - a Northern Ireland-based firm specialising in securing smart city technology - is still reaping the benefits of being welcomed into our Cyber Accelerator programme last June.

Without any favour – good luck to the Northern Ireland school that has reached the final of the CyberFirst Girls competition.

This success all built on the vision of making the UK the safest place to live and do business online.

The 2016 National Cyber Security Strategy really simplified the operational landscape, overhauled the UK's ability to deal with nationally significant cyber incidents, and signalled the government’s intent to intervene proactively to drive out cyber security risk through upstream interventions like Secure by Design and Active Cyber Defence.

This approach has delivered real benefit and the UK is widely recognised as a pioneer in its approach.

As Robert Hannigan, former head of GCHQ said: "the key insight and approach was that businesses needed help in seeing cyber as a manageable risk, parallel to many other risks. It emphasised cultural and behavioural changes as strongly as technical fixes, which is commonplace now but was rare at the time when cyber security was still seen as a problem for the IT department."

And in the creation of the National Cyber Security Centre, don't underestimate how radical a notion it was - and indeed how unusual it still is - to combine secret intelligence with a truly public facing body committed to openness and transparency, intent on delivering for business and citizens.

We can see today, in the debate playing out about how the new US administration chooses to organise itself on cyber security, the challenges others have in emulating this approach.

So the UK should be really proud, both of what has been achieved, and of how we've done it. A genuinely whole of nation approach to cyber security, with a competent national technical authority with brilliant intelligence insights, genuine technical expertise, deep relationships with industry, and focused on outcomes.

Who thought we’d be giving advice to farmers or early years providers, saying that yes - you can let your device or browser manage your passwords. Even recommending those passwords are made less complicated by making them a combination of three random words rather than an impossible-to-remember jumble that has to be changed every month.

And last week the government announced its new Integrated Review: Global Britain in a Competitive Age. It outlines the priority actions of the next Cyber Strategy, to be launched this year.

It would be easy to think, listening to what I have just said, that we are good at cyber security and therefore the next cyber strategy should simply be ‘more of the same’.

And indeed, much of what we need to do will be building on success to date.

But just because the UK is seen as world-leading, doesn't mean we can rest on our laurels.

If we genuinely want the UK to remain the safest place to live and work online, ahead of the game and emulated by others - and I think we do - we have to not only be proud of our achievements, but honest about what more remains to do and the challenges we face.

Where we are right now should not, in my view, feel comfortable - for two reasons.

Firstly, where we are isn't good enough.

And secondly, the context is becoming more challenging: the threat, the technology, the environment are all changing.

Let me explain what I mean.

Firstly, the cyber security landscape we see now in the UK reflects huge progress and relative strength - but it is not a position we can be complacent about.

Recent global cyber incidents involving SolarWinds and Microsoft Exchange have shown the range of cyber threats we currently face.

As our reliance on technology grows, it sadly also presents opportunities for those who want to do us harm online.

It shows us what more we all have to do.

Cyber security is still not taken as seriously as it should be, and simply is not embedded into the UK’s boardroom thinking.

The pace of change is no excuse - in boardrooms, digital literacy is as non-negotiable as financial or legal literacy.

Our CEOs should be as close to their CISO - their Chief Information Security Officer - as their Finance Director or their General Counsel.

And we want to help them to develop this knowledge, as we’re all too aware that cyber skills are not yet fundamental to our education - even though these are life skills like wiring a plug or changing a tyre, as well as skills for the future digital economy.

Security is not yet a key factor for business and consumer choice.

Businesses don’t have tools to help them pick secure products for their enterprise IT and there’s no way for consumers to judge security.

So, businesses seek to outsource their risk to service providers or sweat their IT assets longer than is sensible.

And consumers aren’t offered security as a differentiator, only speed, convenience, and branding.

But on top of this, we also face growing challenges in terms of the threat, the technology, and the digital environment.

On the threat, we must continue to counter the threat the UK faces in all its forms, from sophisticated state actors to low level criminal actors.

Since it was founded, the NCSC has supported the public attributions of four states – North Korea, Iran, China and Russia - for having undertaken hostile activity in cyberspace.

And we continue to be alert to the threat that these states - and others - pose to the UK.

In cyber - like in other areas of security - Russia poses the most acute and immediate threat to the UK.

But - as the Integrated Review makes clear - we must be clear-eyed about Chinese ambition in technological advancement.

And ransomware remains a serious - and growing - threat, both in terms of scale and severity.

You will have seen that earlier this week we published further practical guidance to the education sector after seeing a growth in ransomware attacks against schools, colleges and universities.

Ransomware is not just about fraud - and theft - of money or data, serious as both are. It's about the loss of key services and unenviable choices for unprepared businesses of paying off criminals.

Insurance can really help to cover costs, but cannot be a substitute for better basic cyber security - making ransomware attacks as hard as possible.

But the threat itself is also changing. Increased connectivity will mean unparalleled growth in the potential attack surface – by that I mean the numbers of people and devices available to target, and the volumes of code and digital content that could be exploited to the detriment of our interests.

As our reliance on technology grows, from the institutional level down to the individual, so to will the opportunities for those who would seek to compromise our services, our systems, and our data.

At the same time, the impact of any compromise will increase in severity as digital identity becomes ever more central to our daily lives.

And the threat is also becoming commoditised. The number of competent adversaries is increasing, through the creation and sale of high-end capability to anyone who can pay.

Thus it is harder for us to track them, and we cannot expect them to be able to control the direct and collateral impact of their activity.

This means more than ever, we need to design systems that are tolerant to failure - where one wrong click by a user is not the end of the world.

And then on technology, the global context is changing. We have grown up with a largely western internet, where most of the key hardware was made, most of the intellectual property owned, most of the software was designed, and most of the standards driven by Western values.

It assumes a level of influence we can no longer assume will protect our national security.

Alongside the shift to a more global and more diverse supplier base, we are beginning to see the consequences of infrastructure that is more interconnected than ever before, with our most critical, regulated industries, like energy or telecoms, being connected to wider, unregulated services and suppliers - like managed service providers or Smart City platforms.

Critical National Infrastructure will become more distributed and diffuse. This will affect how it is regulated and will affect products and services much more widely.

Data is a valuable commodity we need to protect - not just the systems it sits on, with population scale data a particular risk as it combines personal impact and national security.

Commoditisation of security and technology makes it easier to sell a new technology type or service, and we will need some way to validate the claims made by the manufacturer in a way that works for consumers.

And finally, the commercial and social environment in which technology is used is also changing.

We are also seeing population changes in the way services are consumed - just look at how dependent we have all become on internet services from video conferencing to online shopping, particularly during the pandemic. And we are all introducing more and more internet-connected products and devices into our homes. As I say, the pandemic has dramatically accelerated this trend, so we need to ask ourselves when does the failure of these services move from being an inconvenience to being a national resilience problem?

So what does this mean for the our cyber security?

Firstly it means we can't afford to sit comfortably with the status quo.

Consolidating the achievements of the past five years alone will not deliver a confident digital Britain, acting as a science and technology superpower.

We will need to further transform our approach to cyber security in order to secure that digital future.

We must be ambitious and specific about what good enough looks like.

To counter the future threat, we must build on one of the undoubted strengths of the UK model: sustained investment in world-class cyber detection and investigatory capabilities, and the ability to operate them alongside the UK’s core intelligence machinery, but also to get declassified, usable insights to people who can do something with them.

But the experience of the last five years has also taught us that this is not enough; we need to work still harder to share intelligence and insights across law enforcement with industry at scale and pace, and be prepared to take action ourselves to counter threats directly where necessary.

But - and I cannot stress this enough - we need to build communities at the national level that can act on that information to protect themselves and others.

That has to be the next phase for national cyber defence in the UK, and by definition it’s something that government cannot do by itself.

But government can - and should - lead by example: through proactive, impact-led risk management and removing legacy IT, rather than just moving everything to ever more classified systems.

We must strive to make government the hardest target possible, while still enabling government to function.

As the threat becomes more complex, we also need to challenge ourselves to ensure we have the right people delivering the nation’s cyber security.

That doesn’t just mean the right skills - it also means the diversity of thought and background that is necessary to respond to a diverse threat, and fully reflect the whole country with its diverse population.

CyberFirst Girls competition is one way that the NCSC is trying to do this – running a competition which helps to increase the number of women in cyber security - but we need to go much further.

And at the NCSC, I am determined that we play our part in delivering this urgently needed change.

On technology, the last five years gives us confidence that the right expertise and partnerships, channelled in the right way, can help remove the burden of poor cyber security from organisations and individuals.

We will keep on doing this where we can, to fix the problems that are with us already. But I’ve said, shifting trends makes that harder for us to do directly, even as technology becomes ever more important to our national interest and daily lives.

So the Integrated Review lays out in some detail our approach to becoming a great science and technology power.

It sets out the UK’s stall to both support our own growing industrial base, working within an “own-collaborate-access” framework to build advantage in critical technologies, pursue economic interests, and, where needed, to mitigate the risks of dependence on non-allied sources of supply.

But given the key inflection point we see on global technology, international engagement will be key.

We must work internationally to make sure technology standards embody good security, for global as well as UK benefit.

We will also play our part in building the capability of key partners to improve their own cyber security. 

I firmly believe that this is key to a more secure future: the NCSC’s role in it will be to provide the threat-informed, expert technical advice so the implementation lives up to the vision from a security perspective.

And then on the environment

We have been saying since 2016 that we need to improve the UK's cyber resilience across the board, so that the majority of attacks against the UK, and vulnerabilities within it, are managed at the national level. With individuals, families and businesses equipped to deal with the remainder.

Since then, we have introduced legislation for critical systems, defined what ‘good’ looks like with objective measures, and developed new capabilities to help identify, understand, and manage cyber risks.

But now we need to go further: challenging ourselves to get the incentive model right, so that - for the public and private sector - secure technology and practices are indivisible from good business practice - full stop.

A good organisation is not just one that can defend itself, it is one that is resilient, can recover, and deliver its service, even when having fallen a victim to an attack.

As the NCSC, we must get the right intelligence, out to the right people, at the right time, to take the right action and prevent harm.

We will continue to support regulators to ensure they understand the threat their industries face, and enable them to make best use of the rules and tools that we already have. And we will support government departments to make better policy to drive up basic standards, across government and the wider economy and society.

And as a national centre, we should continue to develop services and guidance to help those who cannot easily help themselves.

So in conclusion, on each of these, the UK's approach must be both ambitious and innovative.

It must be underpinned by action across government, industry and academia.

We must continue our interventionist approach, not just in the UK, but now more widely in the global context in which we operate.

But in doing so, we must stick to the principles that have served us so well until now. Cyber security as a whole of UK team sport.

Technical excellence and evidence-based interventions.

Cultural and behavioural insights that facilitate change not blame.

Automation and scale.

The combination of secret intelligence and industry insight.

The National Cyber Security Centre - launched five years ago - is now a firmly embedded part of the UK cyber security landscape, and here to stay.

We no longer need to prove the concept - but in what will be a challenging period of economic recovery, we need to change the dial on the outcomes we seek, and look much further ahead to the generational change that is needed.

Because the central premise of UK thinking remains true - that the nation will derive huge benefit from being at the forefront of connectivity and of digital technology, as long as we can effectively identify and manage the associated risks.

The new national strategy will be key to coalescing this activity and ensuring our response is scaled to the challenge.

So we need to ensure that the fantastic science and technology envisioned in the Integrated Review is protected from theft or acquisition by hostile states.

We need to ensure that our Critical Infrastructure, which keeps the country working through thick and thin, is a hard target for those that would seek to disrupt it.

We need to ensure that the ever-increasing amounts of data generated and processed by the internet services we use every day are properly protected, and our privacy appropriately managed.

We need to ensure that the next generation of commodity technologies don’t repeat the security mistakes of the past. We need to ensure that our adversaries - be they state or criminal, traditional or new - think twice before attacking UK targets.

And we need to ensure that future generations are better equipped to deal with – and this complexity - than any of their predecessors.

This is how cyber security can contribute to our economic recovery and tackle the long term strategic challenges of the Competitive Age outlined in the Integrated Review.

And we in the National Cyber Security Centre will be proud to play our part. Thank you.
 

Published

Date of speech

Location

Queen's University, Belfast (virtual)