The types and sources of cyber threats to Critical National Infrastructure (CNI) most critical to the function of the UK digital economy:
- Due to the changing geopolitical environment, including the ongoing war in Ukraine, the rise of state-aligned groups from around the globe, and an increase in aggressive cyber activity, it is highly likely the cyber threat to UK CNI has heightened in the last year.
- The National Cyber Security Centre (NCSC) is the UK’s technical authority on cyber security. NCSC still assesses that ransomware remains one of the greatest cyber threats to UK CNI sectors. This has been evidenced by international incidents, including attacks against Colonial Pipeline and the Irish Health Executive, and within the UK, against South Staffordshire Water, Royal Mail International and even one impacting NHS 111. Some of these attacks have also highlighted the possibility of disrupting CNI through attacks on key suppliers, who may have weaker security and thus present an attractive opportunity for adversaries.
- While criminality online is the most significant threat in terms of volume, the most advanced threats to CNI come from nation states, including Russia, China, Iran, and Democratic People’s Republic of Korea. In May, the NCSC issued a joint advisory revealing details of ‘Snake’, a sophisticated espionage malware used by Russian cyber actors against their targets. These targets included CNI operators, and the targets were in more than 50 countries across the world.
- There is sometimes a misconception that state activity is all about espionage. Or that it is only targeted at trying to steal government secrets. But that’s not the case. Another joint advisory issued by the NCSC earlier this year exposed China state-sponsored activity targeting networks across CNI sectors in the US and it carried a warning that the same malicious techniques could be applied worldwide. It detailed how the actors had been observed taking advantage of built-in network administration tools on targets’ systems to evade detection after an initial compromise. This type of latent threat activity demonstrates the interest that state-sponsored actors have not only in compromising CNI networks in the West but persisting there too.
- Jen Easterly, Director of Cybersecurity and Infrastructure Security Agency, noted that such targeting “…wasn’t for espionage or data theft… it was more likely for disruption and destruction” and CNI operators should be alert to this and follow the actions in the advisory to hunt down this activity and mitigate.
- Nation states and profit-oriented cyber criminals are not the whole picture, however. The Deputy Prime Minister, Oliver Dowden CBE MP, announced that NCSC published an alert to operators of the UK’s CNI in April about the emergence of state-aligned groups as an adversary, some of whom have stated a desire to achieve a more disruptive and destructive impact against western CNI. Without external assistance, NCSC considers it unlikely that these groups currently have the capability to deliberately cause a destructive, rather than disruptive, impact in the short term. But they may become more effective over time, and may be able to achieve effects against infrastructure which is poorly secured.
- While NCSC don’t believe it is likely, right now, that anyone has both the intent and capability to significantly disrupt infrastructure within the UK, NCSC knows that we can’t rely on that situation persisting indefinitely. State-aligned groups, hacktivists and groups partnering with capable nation states increasingly have the intent to interfere with operational technology and to disrupt CNI. Uplifting cyber resilience can take several years to achieve, so it’s therefore important to prioritise that uplift before the threat further materialises against our CNI or its key dependencies.
List of cyber threats to the UK
- Russia/Ukraine
We continue to see increased cyber activity targeting of Ukraine by Russia and Russia-aligned actors – this increase started in January 2022, including a wave of Distributed Denial of Service (DDoS) and data wiper attacks against Ukrainian government and industry. The impact on Ukraine has perhaps been less than expected, in part due to well-developed Ukrainian cyber security and support from industry and international partners. NCSC has helped Ukraine to develop its cyber resilience, including publishing a malware report on malicious Russian cyber activity against Ukraine.
- CNI
As well as the ongoing threat from state actors, 2023 has seen the emergence of state-aligned actors as a new and emerging cyber threat to CNI. While the cyber activity of these groups often focuses on Distributed Denial of Service attacks, website defacements and/or the spread of misinformation, some have stated a desire to achieve a more disruptive and destructive impact against western critical national infrastructure, including in the UK.
- Ransomware
While data extortion attacks (where data is exfiltrated (stolen) but not encrypted) are not strictly ransomware incidents, they are becoming part of the ransomware threat landscape because they are often conducted by cyber criminals normally responsible for ransomware attacks. But the now-normal approach of stealing and encrypting data (‘double extortion’ ransomware) will continue to be a core tactic to increase pressure on victims to pay a ransom.
- Cyber Proliferation
Commercial cyber tools and services lower the barrier to entry to state and non-state actors for obtaining cost-effective capability and intelligence they would not otherwise be able to develop or acquire and, in the absence of international norms and oversight, create the opportunity for misuse. Commercial proliferation will be almost certainly transformational to the cyber threat landscape. NCSC continues to support the UK government in understanding and developing international responses to ensure cyber capabilities are developed, sold and used in a way that is legal, responsible and proportionate.
- China
We continue to see increased widespread evidence of cyber actors across industry and government sectors of China, deploying sophisticated capability to threaten the confidentiality and integrity of UK sovereign data. Close working with NCSC partner agencies facilitates the development of understanding of cyber capabilities threatening the UK.
- Iran
In the November 2022 MI5 annual threat update the rising threat from Iran was highlighted, including increased efforts to kill or kidnap individuals perceived to be enemies of the regime outside of Iran, including in the UK. Iran remains an aggressive and capable cyber actor and will almost certainly use cyber for its objectives. NCSC continues to work closely with government and industry partners to understand and mitigate the cyber threat from Iran.
- AI/Large Language Models (LLMs)
The UK’s adversaries – hostile states and cyber criminals – will seek to exploit AI technology to enhance existing tradecraft. Up to 2025, AI technology is more likely to amplify existing cyber threats than create wholly new ones but will almost certainly sharply increase the speed and scale of some attacks.
The strengths and weaknesses of the UK Government’s National Cyber Strategy 2022 and Government Cyber Security Strategy 2022-2030 in relation to CNI for the digital economy
National Cyber Strategy
- Technological advancements are revolutionising the way we live our lives and our approach to national security. The National Cyber Strategy 2022 aims to strengthen our position as a responsible and democratic cyber power, able to protect and promote our interests in and through cyberspace.
- The National Cyber Strategy 2022 strengthens UK cyber security so that the UK is able to pursue and promote our interests with confidence: it will keep us ahead of our adversaries in cyberspace and strengthen our ability to act in cyberspace, as well as our ability to influence and shape tomorrow’s technologies so they are safe, secure and open. It sets out a clear vision for building cyber expertise in all parts of the country, strengthening our offensive and defensive capabilities and ensuring the whole of society plays its part in the UK’s cyber future.
- Significant progress has been made in the last decade in improving our cyber resilience, with the formal establishment of the National Cyber Security Centre (NCSC) in 2017, the National Cyber Force (NCF) in 2020, increased availability of advice, guidance and other tools, and the implementation of legislation including the Network & Information Systems (NIS) Regulations, UK General Data Protection Regulation, and Data Protection Act 2018. The National Cyber Strategy builds on the foundations of the previous strategy, evolving the Government's approach and shifting the dial - with a particular emphasis on:
● scaling up work to make the internet automatically safer, preventing attacks, building in basic protections to benefit all UK businesses, organisations and citizens, and increasing support available to those least able to protect themselves online
● setting an ambition for government to act as an exemplar of best practice in cyber security
● embedding cyber security as a core part of good business through better use of regulation and other incentives, and harnessing the power of our threat insight to build communities that can defend themselves
● underpinning all of this with objectively-measurable standards, evidence and data and moving from gathering to acting on that data.
- In particular, while retaining a strong focus on outcomes for the broader government and public sector and wider economy, the National Cyber Strategy 2022 also set outcomes for CNI (in the private and public sector) to better i) understand and ii) manage cyber risk, and iii) minimise the impact of cyber incidents when they occur.
- In August 2023, the Government published the first annual progress report[1] on the National Cyber Strategy. The report reflects on key achievements and the increasing strength of UK cybersecurity since the inception of the strategy; highlighting the progress the government has made alongside industry, academia and wider society, as well as looking ahead to future priorities and challenges.
- Russia’s illegal invasion of Ukraine, rapid advancements in AI, and emerging technologies have altered the current state of global cyberspace, with significant implications for our national security, our prosperity and our cyber power. These developments have often posed challenges which the government is quick to assess, manage, and mitigate the impacts of.
Government Cyber Security Strategy
- The Government Cyber Security Strategy was published in January 2022. This sets out how the government will build and maintain its cyber defences - by building greater cyber resilience across all government organisations and working together to ‘defend as one’ which enables a greater defensive force.
- The strategy sets a clear target for government’s most critical functions to be appropriately resilient by 2025, with all government organisations being resilient to known vulnerabilities and common attack methods by 2030. This reflects the ambitions set out in the Integrated Review and the National Cyber Strategy to establish the UK as a democratic and responsible “Cyber Power”.
- In April 2023, GovAssure, a transformational cyber assurance regime for the whole of the government was formally launched. The scheme provides a clear and objective view of government cyber resilience and enables us to measure progress towards strategic targets. GovAssure has been designed with the NCSC around their Cyber Assessment Framework (CAF) to align with best practice in management of wider UK CNI sectors.
The effectiveness of the strategic lead provided by the National Security Council, Government Departments and agencies, and the National Cyber Security Centre, and the coherence of cross-government activity
- The resilience of our CNI to cyber threats sits naturally at the confluence of both resilience and cyber governance structures which come together under the Deputy Prime Minister who chairs both the National Security Council (Resilience) (NSC(R)) and the Ministerial Cyber Board (see below). The NSC(R) is a Cabinet sub-Committee which takes collective decisions across the Resilience landscape, and the Ministerial Cyber Board drives the specific cyber agenda. Where collective agreement is needed, the Cyber Board will refer papers to the NSC(R).
- Given that the levers and mechanisms that are available to reduce the impact of cyber threat sit across government, oversight and decision-making also sits with Ministers across government. Extensive cross-government working takes place through multiple levels to ensure government approach is coherent and joined up to provide maximum impact and effectiveness.
NSC, NSC sub-committees, and ministerial responsibilities
National Security Council (NSC) and subcommittees
- The National Security Council (NSC) is the main forum for collective discussion of the government’s objectives for national security and about how best to deliver them. Chaired by the Prime Minister, the NSC exercises ministerial oversight of these strategies, monitoring implementation and considering the overall balance and direction of UK strategy. The NSC is supported by a number of sub-committees.
- The NSC(Resilience) is a sub-committee of the National Security Council chaired by the Deputy Prime Minister. Its purpose is to drive progress and unblock challenges on strategic issues relating to the resilience system. It ensures that preparations are being made for risks on the horizon, and takes strategic choices to prevent, mitigate or absorb those shocks and risks. Where required, the NSC(R) will refer up to the NSC for decisions. This ensures that a common approach is agreed at all levels of government.
Ministerial Cyber Board
- The Ministerial Cyber Board considers the latest evidence on the cyber threat, oversees the delivery of the National Cyber Strategy and the Government Cyber Security Strategy, resolves critical policy issues, and drives progress on the cyber resilience agenda. Chaired by the Deputy Prime Minister, the core membership includes the Chancellor, Foreign Secretary, Home Secretary, Defence Secretary and Science & Technology Secretary, with other Secretaries of State invited depending on the agenda.
Ministerial Responsibilities
- The Deputy Prime Minister has overall responsibility for cross-sector policy and coordination of the cyber security and resilience of the UK’s CNI. He provides overall leadership across departments to ensure an effective government response to cyber threats. This includes the development and implementation of the National Cyber Strategy, the supporting programme of investment and coordination of the government’s efforts on cyber resilience. The Deputy Prime Minister is the default chair for ministerial COBR meetings on cyber incidents, when necessary.
- The Home Secretary leads the government’s work to detect, disrupt, and deter our adversaries, and in the response to cyber incidents in line with their responsibilities for homeland security. They also have specific responsibility to counter cyber crime, and have statutory responsibility for the National Protective Security Authority (NPSA).
- The Secretary of State for Foreign, Commonwealth and Development Office (FCDO) leads the government’s work to advance UK global leadership on cyber. They also have statutory responsibility for GCHQ and thus, for NCSC.
- The Secretary of State for Defence has joint responsibility for the National Cyber Force (NCF) with the Secretary of State for FCDO, as a joint endeavour between defence and intelligence.
- The Secretary of State for Science, Innovation, and Technology has the responsibility for the government’s work to strengthen the UK’s cyber ecosystem and to take the lead in technologies vital to cyber power, and on interventions to support effective organisational cyber risk management.
- The UK Government oversees a sector-led model of CNI. Each sector is overseen by the relevant Lead Government Department (LGD). Ministers of all Lead Government Departments (LGDs) for CNI have responsibility for the security and resilience policy for their sectors, including cyber.
Cross-government working (official level)
- There are associated cross-government senior official groups that support and inform these ministerial level structures.
- The Deputy National Security Adviser (DNSA) for Intelligence, Security and Resilience is the Senior Responsible Owner for the National Cyber Strategy and leads its delivery across government at official level, supported by the relevant senior officials across departments.
- The DNSA and the Director General of the Economic and Domestic Secretariat (EDS) co-chair an Official level NSC(R), which provides oversight and assurance of work to improve the security and resilience of the UK, including its CNI, taking an ‘all risks’ (i.e. threats and hazards) perspective to better inform efforts and prioritise resources. The Resilience Directorate (RD) in EDS, supported by National Security Secretariat (NSS), administers the NSC(R) meetings, providing coordination on cyber security and CNI issues across Government.
- Many parts of the Government contribute to improving CNI cyber security. RD has overall policy and coordination responsibility for CNI resilience policy and assurance, including the management of cyber policy for CNI. This is alongside wider CNI and resilience policy and assurance. Being situated in EDS allows government officials to seamlessly link cyber resilience considerations to wider economic and domestic policy areas including the infrastructure portfolio.
- The National Security Secretariat (NSS) manages the National Cyber Programme, which funds a wide range of activity in support of the National Cyber Strategy, including initiatives to build the cyber security of CNI.
- RD collaborates closely with NSS colleagues through multiple forums, such as the cross-departmental Resilience Steering Board, chaired by the Director of Resilience, which will take items about CNI and cyber as part of its overall programme of resilience, and the cross-departmental Directors Cyber Board which drives the overarching Cyber strategy and programme specifically, with items relevant to Resilience.
Responsibilities of the National Cyber Security Centre
- The National Cyber Security Centre (NCSC), a part of GCHQ, is the UK’s technical authority for cyber security. It works to make the UK the safest place to live and work online and bring clarity and insight to an increasingly complex online world – this includes working to identify, monitor and analyse key cyber security threats, risks and vulnerabilities affecting CNI. Using these insights, the NCSC helps UK institutions and organisations to take actions to secure the systems and services that society depends on; to stop attacks upstream and bolster preparedness for when incidents occur; and to minimise the impact and recover more effectively.
- The NCSC’s broader responsibilities under the cyber strategy, of relevance to CNI, also include:
● Providing technical input to HMG policy and regulation on the issues of most importance for cyber security by providing policy leads across Whitehall with authoritative technical input and threat assessment derived from the NCSC’s core capabilities, supporting development and implementation of policies and regulations to keep the UK’s citizens, organisations and interests digitally secure.
● Taking direct action to reduce cyber harms to the UK by providing protection at scale through the Active Cyber Defence programme (a range of free cyber security tools and services provided by the NCSC to eligible organisations), managing the response to nationally significant cyber incidents, and, with the NCF, countering threats which undermine the confidentiality, integrity and availability of data, and effective use of systems by users.
● Supporting growth in cyber skills and investment by providing the technical underpinning for cyber education and catalysing investment into the cyber sector.
- More specifically NCSC provides support to critical national infrastructure operators through:
● Advice, support and guidance: publishing technical guidance relevant to CNI; engagement at technical and executive levels to help CNI operators to progress cyber security improvements; using deep technical expertise to solve novel or complex cyber security challenges in CNI; support with exercising and testing.
● Threat intelligence: sharing both strategic and actionable threat intelligence and advisories.
● Technical policy input: technical support to regulators to help them deliver their CNI cyber security responsibilities, including by developing the Cyber Assessment Framework, supporting government with policy development in relation to cyber security and resilience of CNI.
● Engagement: input to industry groups on CNI cyber security; convening organisations, including at our annual CyberUK conference.
● Incident management: managing the national response to significant cyber incidents affecting CNI.
National Protective Security Authority (NPSA)
- The National Protective Security Authority (NPSA) is the UK government's National Technical Authority for physical and personnel protective security, maintaining its expertise in counter terrorism as well as state threats. NPSA is part of MI5, the Security Service, which exists to protect the UK against national security threats.
- NPSA works to keep UK citizens safe, protects the economy and our science and technological advantage, as well as the infrastructure upon which daily life depends. NPSA helps organisations understand the range of threats they and the UK face and importantly what they can do to minimise their risk through how they operate day to day.
The effectiveness of the Government's relationships with private sector operators and regulators in protecting and preparing CNI organisations of most critical to the UK digital economy from cyber-attacks
- Effective protection of CNI from cyber-attacks is a priority for the Government and must be a partnership between Government, regulators and private-sector operators. Engagement with private-sector operators is fundamental to the delivery of this and the aim of achieving more cyber resilient critical infrastructure and systems.
- Owners and operators are responsible for understanding and managing the risks to their systems and ensuring that they invest in security and resilience to the standard required.
- The Government guides owners and operators by setting out the framework of security and risk assessment and provides support to owners and operators through engagement, advice and tools. Relationships between the government, operators, and regulators are assessed to be effective through regular feedback from regulators and Lead Government Departments (LGDs), including on the outcomes being achieved. The government will continue to improve the way it works with sectors to ensure proper information exchange and joined up working. Specific examples of effective relationships in the sectors outlined in the call for evidence are found in Annex A.
- LGDs are responsible for identifying those parts of infrastructure in their sectors that are most critical and prioritising interventions accordingly. This also includes working with regulators to ensure the regulatory framework for cyber resilience is effective, and with operators to implement the necessary measures to ensure cyber resilience and security. They must do this in collaboration with the relevant technical authorities. For cyber security, this is the National Cyber Security Centre (NCSC).
- LGDs are required to complete CNI self-assurance, commissioned by the Resilience Directorate in the Cabinet Office. The assurance process asks a broad set of structured questions around the Risk Management Cycle to reduce assumptions and enable better comparison across sectors which enable Government, to understand baseline security and resilience for each CNI sector, and importantly, identify whether there are issues which we may wish LGDs to prioritise due to the cross-cutting impact. This subsequently supports the process of understanding, managing, and mitigation of cyber risk to CNI across the sectors.
- NCSC supports private sector operators of CNI by providing advice (including threat information) to help them increase the cyber security and resilience of their networks. Groups of companies are engaged in trusted subject- or sector-specific fora, creating effective channels for information sharing, often in collaboration with the National Protective Security Authority (NPSA).
- These engagements are supported and supplemented by the NCSC’s online Cyber Information Sharing Platform (CiSP), and by annual conferences like CYBERUK.
- The NCSC works in partnership with NPSA to support LGDs, as a holistic approach (a combination of physical, personnel and cyber security) is necessary for the private sector operators of CNI to best manage their security risks.
What are the interventions that are required from Government, and CNI organisations most critical to the UK digital economy to ensure the Government’s cyber resilience targets by 2025 are achieved
- Close working with industry and other organisations will underpin our continued commitment to a whole of society approach to developing cyber resilience policy. There is much further to go to achieve suitably robust levels of cyber resilience, and in the year ahead, the government will continue to press for progress, particularly for the government and CNI. The government will continue working with partners to shape a cyberspace that reflects UK democratic values, and to use the UK’s world-class cyber capabilities to influence the behaviour of adversaries.
- Ensuring CNI is secure and resilient against cyber-attacks is a priority for the Government. Under the National Cyber Strategy 2022 the Government is committed to taking a number of steps to achieve this, including through three outcomes:
A more sophisticated understanding of cyber risk across the CNI
- In order to be able to take the most effective actions to protect our CNI, the government must first have an understanding of the risk from cyber-attacks, including the nature of the threat, what is critical and the level of resilience or vulnerability. This links closely with the Government’s principal tool for identifying and assessing risks to the UK and its overseas interests, the official-sensitive National Security Risk Assessment (updated in 2022). The government has prioritised work to complete criticality reviews and map dependencies within CNI and its supply chains.
- Over the past year, the UK government has significantly improved its strategic understanding of the current cyber resilience of the CNI and set targets for improvement by 2025, including in the assurance processes required to drive improvement. In 2018, the NCSC launched the Cyber Assessment Framework to aid Regulators in assessing the cyber resilience of operators of essential services.
- Adoption of the Cyber Assessment Framework or other recognised frameworks for assessing CNI resilience more broadly, continues to increase and NCSC have worked to map other cyber security assessments and standards to improve our understanding of comparability.
- Since 2018, more than a hundred assessments or tests by regulators have been carried out across CNI. More recently work has focused around steps to increase the robustness of assessment through introducing technical validation independent of the operator, such as through assurance schemes launched in Government and aviation, the ‘CBEST’ framework[2] for testing in the finance sector or other regulatory inspections. The Telecommunications (Security) Act implements a significantly improved assurance regime. Complementary to this, NCSC are also developing a scheme for Cyber Adversary Simulation.
- The government is working to understand new risks or where new CNI is emerging as a consequence of digitalisation and new technologies, including as part of broader priorities such as the transition to Net Zero.
Cyber risks to UK critical national infrastructure are more effectively managed
- The government has set targets to achieve resilience against common attack methods as quickly as possible and to put in place more advanced protections where appropriate, as announced by the Deputy Prime Minister at CYBERUK 2023.
- In support of this outcome, the government needs the ability to hold CNI operators to account to ensure they invest in the cyber security of critical systems and effectively manage their risk, including from their supply chains.
- The government is strengthening the regulatory framework, to improve its coverage, powers, and agility to adapt, within the context of broader national security risk and rapidly changing threat and technology. We are implementing a new security framework for UK telecommunications providers and we have consulted on reforms to strengthen the Network and Information Systems Regulations 2018 (NIS) regulations. In energy, we are developing the regulatory framework to ensure that the future smart and flexible energy system the UK requires to deliver Net Zero will be secure and resilient to cyber threats. Some gaps remain and we are looking at targeted options to bring all private sector CNI operators within the scope of cyber regulation to ensure that the government has the necessary levers to ensure operators manage risk in the national interest.
- Alongside this, the government will enhance the capability of regulators and invest in skills to improve CNI operators’ ability to attract, develop, and retain cyber professionals.
- The Ecosystem Pillar of the National Cyber Strategy sets out the objective to enhance and expand the nation’s cyber skills at every level. This includes increasing the number of people entering the cyber workforce, building the cyber security profession, improving diversity and the flow of highly skilled people coming through our education system. The Government Cyber Security Strategy recognises that attracting and retaining skilled cyber professionals is critical to our cyber resilience. This includes attracting early talent, such as through the Cyber Fast Stream and Cyber Apprenticeship programmes, and developing a sustainable talent pipeline through to mid-career and senior cyber roles.
- Risk from digital supply chains is a key challenge, which the government is tackling through the ongoing work on criticalities to map areas of vulnerability in critical supply chains. The government supports operators with guidance on how to manage these risks and supply chain risk management is a requirement under the Cyber Assessment Framework. In addition, we have undertaken work to address systemic risks. Providers of some digital services are in scope of the Network and Information Systems regulations and we have consulted on broadening this to include managed IT services and a new regime for critical dependencies. We have also legislated for a new critical third-party regime in the Finance sector that protects the functioning of the sector and prevents significant disruption.
CNI is more prepared to respond to and recover from incidents, including through better incident planning and regular exercising
- NCSC will provide the UK government and CNI operators with the cyber exercising and incident management services they need from the marketplace by expanding the NCSC’s accredited scheme for Cyber Incident Response and introducing a new scheme for exercising. To improve the breadth of, and access to, quality incident response services in the aftermath of an incident, the NCSC expanded their accredited scheme for Cyber Incident Response companies which launched on 15 August.
- The NCSC has also launched its Cyber Incident Exercising (CIE) Assurance Scheme that will assure industry providers of particular types of cyber exercising services against a related NCSC standard. The scheme will be run by delivery partners on behalf of the NCSC, the first assured CIE service providers expected to come on board by winter 2023.
- The government will set out clear requirements for exercising and testing or adversary simulation across CNI operators, and stimulate innovation and collaboration in incident response and exercising, considering application of models such as the Financial Sector Cyber Collaboration Centre.
- The government and NCSC have increased the advice and guidance offering, including a refresh of the NCSC’s supply chain cyber security guidance to boards, the launch of new supply chain cyber security guidance and expanded sector-specific guidance.
- Underpinning the UK's approach to strengthening cyber resilience across CNI is a focus on skills and increasing the size, diversity, and quality of the cyber workforce. There are a range of activities intended to inspire and support young people towards pursuing a career in cyber security, including the NCSC CyberFirst Bursaries Scheme. Alongside this is further support to upskill and retrain individuals in the UK's existing workforce, with an interest in entering the cyber security field. The Department for Science, Innovation, and Technology (DSIT) funds Upskill in Cyber, which recently attracted over 5,000 applications from across the UK, for 200 places on a reskilling course delivered by SANS, a recognised industry provider.
- In addition to these efforts, there is a clear government focus to professionalise cyber security and make it easier to enter and navigate a career in the relatively nascent field. This is why DSIT has funded the creation and development of the UK Cyber Security Council - the new professional authority for cyber security. We are working closely with regulators across the UK to make sure that the public sector consistently points to this body and its definitions of quality for practitioners. This will give confidence to organisations, who know exactly the individuals they are recruiting, and to the cyber professionals, who have a clear professional infrastructure for cyber security. In October 2023, the first cohort of 100 professionals assessed against the first-ever Chartered Standard for cyber security were recognised. Building on this momentum, and embedding this practice across UK CNI, is key towards a quality assured cyber workforce going forward and supporting cyber resilience objectives.
What role will ‘secure by design’ and emerging technologies play in the cyber resilience of CNI most critical to the UK digital economy and their supply chains
- ‘Secure by Design’ ensures that both systems and networks, and the devices used by everyone (particularly Internet of Things (IoT) devices) have security built in at the design stage rather than as an afterthought or by retrofitting.
- Work surrounding ‘Secure by Design’ falls under the Technology Pillar of the National Cyber Strategy which is led by DSIT. DSIT is collaborating with the NCSC, and will aim to improve UK CNI resilience in operational technology and industrial control systems.
Secure by design systems
- Adding cyber security into existing systems and processes is costly and can prove extremely challenging where those systems are well established, functional and complex, such as legacy IT systems. The government encourages organisations, particularly those in CNI sectors, to consider and design security, including cyber security, into systems and programmes from the outset. Engagement and thinking about security at an earlier start-up or innovation stage is crucial. Secure by design principles are core to building new and developing, secure companies and therefore the Government is working to instil this as security norms through all our engagement with industry.
- For example, the UK Space Agency is in the process of building mandatory engagement and cyber security planning into the requirements of receipt of UK Space Agency funding, to improve mitigation measures and overall resilience. The UK Space Agency is also engaged in various international collaborative groups designing cyber security technical standards for space systems. Mandatory cyber security standards are being considered; however, this needs to be balanced with the commercial space growth agenda, the need to avoid stifling innovation, and team resources available.
Secure by design devices
- Connected or smart technology provides opportunities to transform many areas of society - from the home and office, to industry, public spaces and CNI. Whilst beneficial, this increase in technology also brings its own set of risks. DSIT is working to minimise the risks that connected technology can introduce to the economy by looking at the design, deployment, and management of technology across CNI, the economy, and wider society.
- This government has taken a ‘Secure by Design’ approach to introduce interventions to secure connected technology at the design and deployment stage, through legislation, non-binding standards, codes of practice, engagement, and guidance. These interventions take a holistic approach; securing consumer connected devices through legislation; securing apps that are used and downloaded on these devices through a Code of Practice for the apps and app store; and ensuring cyber security principles for enterprise IoT products that are used in almost every business today.
Emerging Technologies
- The role of emerging technologies is becoming increasingly important to the cyber resilience of CNI most critical to the UK digital economy and their supply chains. Technologies such as AI will continue to have a profound impact on societal function. Wider policy work regarding the cyber security of AI is underway and the government is advocating for a secure by design approach.
- Cybersecurity is also an essential precondition for the safety of AI systems. The recent AI Safety Summit on 1-2 November saw world leaders, businesses, academia and civil society come together to discuss the most significant risks created or significantly exacerbated by the most powerful frontier AI systems, and how it can change the face of global security.
- As AI becomes increasingly integrated into our economy and society, this work is not just a crucial step for the UK to fully realise the benefits of an AI-enabled economy, but vital if the government is to protect UK citizens and the economy from the risks posed by this convergence.
- The Technology Pillar of the National Cyber Strategy 2022 outlines how the government will ensure that, wherever possible, the next generation of technologies are designed, developed and deployed with security and resilience in mind and as part of a concerted effort to embrace a ‘secure by design’ approach. The global nature of technology means the UK government uses all available levers to actively manage the risks of technological dependence. Where possible, we seek to ensure that security is built in; where we cannot do this, we implement robust measures to mitigate risk, including domestic regulation and international collaboration on standards.
- This work includes anticipating, assessing and acting on science and technology developments to build and sustain a competitive edge in technologies. DSIT works with research and technical experts within government and academia to draw in insights and proactively influence the secure development of the next generation of technologies. The government’s National AI Strategy 2021 states that cyber security should be considered early in the development and deployment of AI systems to prevent harms from arising, by adopting a ‘secure by design’ approach to mitigate against cyber security becoming an afterthought. The National Cyber Strategy is the Government's plan to continue the drive for securing emerging technologies to support the UK’s growth and resilience, including building security into the development of AI.
- A good example of this approach is the civil nuclear sector, which has a framework in place which supports Secure by Design and responds to security considerations for emerging technology. For example, the Generic Design Assessment (GDA) process ensures effective cyber security standards are embedded in the design stage of new reactor development and the Office for Nuclear Regulation (ONR) works with the NCSC to ensure this process remains fit-for-purpose. Also, ONR’s outcome-based regulatory approach can support the adoption of innovative solutions that are consistent with safety and security expectations. This ensures technology risk (including from emerging technologies) is balanced with regulatory requirements and innovation is not stifled. Furthermore, from a voluntary perspective, existing cyber governance forums facilitate a collaborative approach through knowledge sharing across the sector on emerging technologies such as AI.
14 November 2023
19