always downloading the latest software updates.
Experts agree adopting these behaviors will provide small businesses and individuals with
protection against cybercrime. Cyber Awareness should be supported by all partners, including
the police and businesses in the retail, leisure, travel and professional services sectors.
4.1.7 CYBER ESSENTIALS
The Cyber Essentials scheme was developed to show organizations how to protect themselves
against low-level “commodity threat”. It lists five technical controls (access control; boundary
firewalls and Internet gateways; malware protection; patch management and secure
configuration) that organizations should have in place. The vast majority of cyber-attacks use
relatively simple methods which exploit basic vulnerabilities in software and computer systems.
There are tools and techniques openly available on the Internet which enables even low-skill
actors to exploit these vulnerabilities. Properly implementing the Cyber Essentials scheme will
protect against the vast majority of common internet threats.
4.1.8 MANAGING INCIDENTS AND UNDERSTANDING THE THREAT
The number and severity of cyber incidents affecting organizations across the public and private
sector are likely to increase. We therefore need to define how both the private sector and the
public engage with the Government during a cyber-incident. We will ensure that Government’s
level of support for each sector – taking into account its cyber maturity – is clearly defined and
understood. The Government’s collection and dissemination of information about the threat must
be delivered in a manner and at a speed suitable for all types of organization. The private sector,
government and the public can currently access multiple sources of information, guidance and
assistance on cyber security. This must be simplified.
We must ensure that the Government offering, both in responses to incidents, and in the
provision of guidance, does not exist in isolation, but in partnership with the private sector. Our
incident management processes should reflect a holistic approach to incidents, whereby we learn
from partners and share mitigation techniques. We will also continue to use our relationships
with other CIRTs allies as an integrated part of our incident management function.
Current incident management remains somewhat fragmented across government departments
and this strategy will create a unified approach. The CIRT-SL will deliver a streamlined and