exploitation and increases the potential impact of attacks which have the potential to cause physical damage, injury to persons and, in a worst case scenario, death. The rapid implementation of connectivity in industrial control processes in critical systems, across a wide range of industries such as energy, mining, agriculture and aviation, has created the Industrial Internet of Things. This is simultaneously opens up the possibility of devices and processes, which were never vulnerable to such interference in the past, being hacked and tampered with, with potentially disastrous consequences. 2.2.2 Poor cyber hygiene and compliance Awareness of technical vulnerabilities in software and networks, and the need for cyber hygiene, has undoubtedly been ignored due to lack of awareness and initiatives to promote cyber safety, Cyber-attacks are not necessarily sophisticated or inevitable and are often the result of exploited – but easily rectifiable and, often, preventable – vulnerabilities. In most cases, it continues to be the vulnerability of the victim, rather than the ingenuity of the attacker, that is the deciding factor in the success of a cyber-attack. Businesses and organizations decide on where and how to invest in cyber security based on a cost-benefit assessment, but they are ultimately liable for the security of their data and systems. Only by balancing the risk to their critical systems and sensitive data from cyber-attacks, with sufficient investment in people, technology and governance, will businesses reduce their exposure to potential cyber harm. 2.2.3 Insufficient training and skills The lack of skills and knowledge to meet our cyber security needs across both the public and private sector is a cause for concern. In businesses, many staff members are not cyber security aware and do not understand their responsibilities in this regard, partially due to a lack of formal training. The public is also insufficiently cyber aware. We also need to develop the specialist skills and capabilities that will allow us to keep pace with rapidly evolving technology and manage the associated cyber risks. This skills gap represents a national vulnerability that must be resolved. 2.2.4 Legacy and unpatched systems Many networks continue to use vulnerable legacy systems until their next IT upgrades. Software on these systems will often rely on older, unpatched versions. These older versions often suffer

Select target paragraph3