UK National Security in a Digital World – PA Consulting Group Written Evidence

 

About PA

1.              PA Consulting Group is an independent firm of over 2,600 people which operates with in the UK and globally from offices across the Americas, Europe, the Nordics, the Gulf and Asia Pacific. We are experts in consumer and manufacturing, defence and security, energy and utilities, financial services, government, healthcare, life sciences, and transport, travel and logistics.

Introduction

2.              Thank you for this opportunity to provide written evidence concerning the present state of cyber security within the UK. As our daily lives become more entwined with digital technology and we become increasingly reliant upon it to develop opportunities for growth, we also become more susceptible to the potential risks that it carries including its use for cyber-crime and state actor aggression[1].

3.              Challenging and overcoming these risks is not the sole responsibility of government but will require joint effort from national bodies, industry, academia and the general public. To this end, the evidence we present below looks at a number of areas where such joint effort could be applied:

Key areas for action

4.              We see the following as key areas requiring attention:

 

Response 1 - Lessons from the first National Cyber Security Strategy and fitness for purpose of the second

5.              Immediately following the release of the second NCSS, PA Consulting’s cyber security experts conducted a detailed review to assess its suitability for enabling the enhancement of the UK’s resilience to a range of cyber related threats over the next five years[2].

6.              Our view is that the second NCSS is more comprehensive than the first and is honest about the cyber challenges the UK faces. Its broader scope and intent to actively deliver national level solutions to defend the UK from high volume cyber-attacks are steps in the right direction, as is its recognition that more needs to be done to further develop and grow cyber talent and innovation within the UK.

7.              However, despite these positive steps, our analysis also indicated that the second NCSS, much like the first, risks failing to deliver upon all of its objectives at the pace anticipated unless a different approach to its implementation is taken, especially where this relies upon the market to deliver.

8.              Such an approach should focus on joint action and shared responsibility to successfully implement and embed the changes outlined in the second NCSS. This means both top down action, advice and incentives from government, and bottom-up pressure, innovation, and desire from industry, investors and the public for better and simpler cyber security controls.

 

9.              This could be achieved by focusing on three core elements:

 

 

Each is explored in more detail below.

 

Elevating the importance of cyber risk within UK industry

10.              Today 88% of FTSE 350 companies have cyber security on their risk registers[3]. Despite this, there is continuing evidence that this risk is not always managed appropriately until the inevitable failure happens, meaning that some business are only prompted to make changes after falling victim to a cyber-attack[4],[5].

11.              Whist some boards may believe that protecting their business from cyber-attack rests with others, including their own IT departments, this is clearly not the case and boards must proactively play their part in strengthening their organisations own defences. The second NCSS identifies a number of potential financial levers that can be used to support regulatory requirements (such as the EU General Data Protection Regulation) however, these will only go so far.

12.              Influencing the behaviours of investors to apply pressure on boards is potentially a more powerful driver of change. Given this, we were pleased to see a recent proposal from the Department of Culture, Media and Sport (DCMS) for the NCSC to help educate the investment community and to provide them with the tools to directly challenge board members around cyber security issues[6]. It will be important that such tools focus on the key drivers that make the case for greater investment in cyber. These include:

 

 

13.              Demonstrating the business value of good cyber security will be key to galvanising investors to exert pressure and encourage companies to change the way they perceive the risks and improve their approach.

 

Driving collective innovation

14.              The cyber threat is constantly changing with new attack vectors and vulnerabilities being exploited every day. The second NCSS recognises the importance of cyber innovation within the UK in order to stay ahead of these threats. Since its publication we have seen the creation of the first DCMS lead innovation centre which will engage with and support UK cyber start-ups[7].

15.              This, along with other initiatives such as the DCMS Boot Camps and cyber focused innovation clusters is providing helpful top-down direction and support from government to grow cyber innovation within the UK, but a bottom up demand will also be required in order to make such innovation sustainable.

16.              This must come from individuals and business alike who need to be informed of the dangers they face in a way they understand and then be provided with the tools they need to respond to them. Such tools, which must support existing solutions as well as new products, should include cost–effective means for protecting the services they use on a daily basis (such as online banking) and must be developed and adopted in an agile way which drives demand for their creation and development

17.              Making a compelling case for this will require tailoring the message to make it relevant to different stakeholders within industry and the general public.

Embedding cultural change

18.              The second NCSS indicates that an improving cyber security culture is an “indicative measure of success”. This recognises that people can be the weakest link in cyber security, but if they are educated and informed properly they can also be the strongest defence.

19.              Given this, it is in the national interest for the public to care about cyber security in the same way as they care about environmental impact or health and safety. This means creating a culture of cyber security and providing simple and effective ways to respond to individual concerns as well as helping them protect themselves by embedding cyber security activities into their normal daily behaviour in the same way that they do other types of security.

20.              Raising public awareness will be key to achieving this and information initiatives such as the Cyber Aware Campaign, and the NCSC’s promotion of cyber security advice via social media, should be enhanced to ensure that that this can happen in a more compelling way to elicit a response from a wider range of individuals – both privately and within SMEs – to develop basic practical cyber skills for everyday use.

21.              Whist achieving this will be difficult, potential methods for beginning the process include:

 

22.              If this work is successful in raising public awareness of cyber risk, then this will put further pressure on the leadership of companies and organisations to make cyber security a priority at every level and to provide proof of their cyber credentials.

 

Response 2 - Ways in which the Government can work with the private sector to build cyber resilience and cyber skills

23.              It is widely acknowledged that the UK lacks the skills and knowledge to meet our cyber security needs across both the public and private sector. Recently published research indicates that the number of cyber security roles advertised in the UK was the third highest globally and that employer demand exceeded candidate interest by more than three times, resulting in the second biggest skills gap of any country in the world[8].

24.              The Develop strand of the second NCSS acknowledged that the UK requires more talented and qualified cyber security professionals and promised investment in education and training. It is vital that the UK develops the specialist skills and capabilities that will allow it to keep pace with rapidly evolving technology and manage the associated cyber risks. While there is no single solution, joint government and private sector collaboration on the following three areas would certainly go some way to addressing the problem.

Reaching the right audience

25.              In 2015/16, just 10% of pupils took computer science at GCSE while less than 1% took it at A-Level, highlighting the scale of the challenge faced by the UK in encouraging young people to enter the cyber profession[9],[10].

 

26.              Although the government has taken steps to address this both through initiatives such as the Cyber Security Challenge’s schools programme and a recent announcement to provide 5,700 GCSE aged pupils with cyber security lessons[11], more still needs to be done on a larger scale in order to address the UK’s cyber skills gap in the long term.

 

27.              At a minimum this will require further investment in the education system and in suitably qualified teachers to bring cyber and information security concepts to a larger audience of children as part of the core curriculum both before and during their GCSE years. At best, this should be accompanied by further initiatives which are more focused on inspiring children to become cyber security professionals.

 

Delivering the right skills for UK industry

28.              Universities will need to play an important role in developing the required skills and the Government has already started the process of identifying and supporting quality courses with the introduction of the GCHQ Certified Cyber Security Master's degrees. However, with only 20 Masters degrees currently certified, these remain only a small fraction of the cyber security degrees available. In addition, all too often university students graduate with little or no practical experience that can be utilised by industry and university processes mean that changes to courses as technology develops can be slow.

29.              Cyber security apprenticeship programmes which are not just based on academic achievement but on a natural aptitude for understanding technical information, good communication skills and a willingness to work and learn, are also key to bridging the skills gap. Greater promotion of this option continues to be required to encourage people to see this as an excellent way to enter the cyber security industry.

30.              The introduction of the GCHQ Certified Training (GCT) scheme is to be applauded as it allows purchasers to be assured of the quality of the courses they are buying from industry providers. However, knowledge of the scheme is limited outside government and the industry itself. Mandating government to only purchase courses certified under the scheme would be one way to develop the scheme further. This approach could also generate a rationalised set of nationally accredited qualifications (as required by other professions) which could be incorporated in to clear learning pathways agreed by the private and public sector.

Organisations need to re-evaluate the way and who they recruit

31.              If organisations are unable to recruit enough staff with the right skills or qualifications, they need to reconsider the way, and who, they recruit. Employers should look at internal and external candidates with some applicable experience, who are a cultural fit and who show willingness to learn – and invest in them by offering them the opportunity to gain specific qualifications on the job.

32.              In turn, government needs to establish a fund or provide grants to retrain candidates already in the workforce who show a high potential for the cyber security profession. This could be specifically targetted at SMEs.

 

Response 3 – Means to develop the impact of the strategic lead in relation to the NCSC

33.              Cyber attacks are ranked among the top four risks to UK national security. However, as the Commons Public Accounts Committee has said, ministers have taken too long to consolidate the ‘alphabet soup’ of agencies tasked with stopping attacks and that a skills shortage and chaotic handling of personal data breaches are undermining confidence in the government's ability to protect the UK from cyber -attacks[12].

34.              It is therefore a welcome development that the NCSS states that the UK Government intends to:

 

35.              The NCSC have access to privileged information on the threats and vulnerabilities to the UK and therefore understand the risks. Historically, NCSC (or rather its predecessors) have used their internal expertise to define ways to mitigate those cyber risks, and have developed policies, standards and guidance for sharing (predominantly with government) as a (fairly blunt) instrument to get government departments to manage their risks appropriately.

36.              However, the risks have since evolved, and the scope of NCSC responsibility has grown massively from government departments only to requiring the NCSC to support ‘the most critical organisations in the UK, across government and the private sector’[13]. This ambition to provide ‘bespoke advice and guidance, assist in the design and testing of networks, and help develop effective incident response plans’ looks challenging, and it will need work to develop a way to meet that aim in way that has the required impact across the increased NCSC scope and scale.

37.              The NCSC pledges to combine the best of government, industry and academic expertise, so that the NCSC has the ‘clearest possible picture of the threats, vulnerabilities and technology trends which define today’s digital environment’ and also looks to exchange talent with other organisations through secondments and interchanges. This reflects the need to improve the NCSC’s understanding of risks through collaboration, but does not appear to address the issues of engaging the wider UK population and business community with that knowledge, at an appropriate scale.

38.              We believe that the best approach to scaling up the NCSC’s impact on the UK’s cyber issues across the different, specialist sectors (in particular the CNI) is to bring together those that work day to day tackling cyber threats within each sector and who understand their operations, with those that work within the NCSC and best understand the national threats and vulnerabilities.

39.              This will require the NCSC to increase its trust in outside bodies, something which could be achieved through the selective engagement of organisations and individuals that already bridge the gap between the industry specialists and the covert, vetted world of the NCSC. This approach would enable engagement to both focus on specific sectors, and scale up through engaging the consultancies that operate within those sectors.

40.              There are already a number of UK headquartered companies with List X status engaged at a national level and who also operate across the UKs cyber landscape. Selecting the right people from those organisations to share a deeper understanding of the threats and vulnerabilities, would open up the opportunity for a few trusted individuals to understand whether the ‘best practice’ that their organisations deploy across the real world could be improved. This would also provide the opportunity for those individuals to bring current knowledge, and observations from across a much broader section of the UKs industries back into the NCSC to improve their understanding of the operational environment, and what works, and what doesn’t. This would refine advice and guidance so that it becomes more effective across each sector, and better trusted as it becomes more tailored to the individual operational environments.

41.              This approach could operate through a number of models including a periodic, industry or sector focused forum that brings together the consultants dealing with day to day cyber challenges, with the NCSC specialists to exchange information. Establishing a way to enable both closed and open groups of industry cyber specialists to share observations with the NCSC and each other could be highly effective. In this way the NCSC would increase its influence without being having to grow significantly, the UKs consultancies would improve the quality of the cyber advice that they give, and our critical industries would become better defended.

 

 


[1] http://www.bbc.co.uk/news/uk-38951172

[2] http://paconsulting.com/our-thinking/national-cyber-security-strategy/

[3] https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/516331/UK_Cyber_Security_Strategy_Annual_Report_2016.pdf

[4] https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/579440/Cyber_Essentials_process_evaluation_and_message_testing.pdf

[5] https://www.publications.parliament.uk/pa/cm201617/cmselect/cmcumeds/148/14802.htm

[6] https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/579442/Cyber_Security_Regulation_and_Incentives_Review.pdf

[7] https://www.gov.uk/government/news/groundbreaking-partnership-between-government-and-tech-start-ups-to-develop-world-leading-cyber-security-technology

[8] http://blog.indeed.com/2017/01/17/cybersecurity-skills-gap-report/

[9] https://www.gov.uk/government/statistics/revised-gcse-and-equivalent-results-in-england-2015-to-2016,

[10] https://www.gov.uk/government/collections/statistics-attainment-at-19-years

[11] http://www.bbc.co.uk/news/education-38938519

[12] https://www.parliament.uk/business/committees/committees-a-z/commons-select/public-accounts-committee/news-parliament-2015/protecting-information-across-government-report-published-16-17/

[13] https://www.ncsc.gov.uk/about-us