and build resilience. Businesses and organizations must also understand that, if they are the
victim of a cyber-attack, they are liable for the consequences.
3.2.3 Government
The primary duty of the Government is to defend the country from attacks by other states, to
protect citizens and the economy from harm, and to set the domestic and international framework
to protect our interests, safeguard fundamental rights, and bring criminals to justice.
As the holder of significant data and a provider of services, the Government takes stringent
measures to provide safeguards for its information assets. The Government also has an important
responsibility to advise and inform citizens and organizations what they need to do to protect
themselves online, and where necessary, set the standards we expect key companies and
organizations to meet.
3.2.4 Driving change
This Strategy seeks to derive outcomes and increase capacity in both the public and private
sector by looking to the market to drive the right behaviors. It is expected that commercial
pressures and government- incentives will drive adequate business investment to enhance
appropriate cyber security standards that will stimulate a flow of investment into our industry,
and to encourage an adequate pull of skills to the sector.
The Government is committed to bring about significant improvements in our national cyber
security over the next five years. This ambitious and transformational programme will focus on
the following three broad areas:
1. Expanded intelligence and law enforcement focus on the threats. The intelligence
agencies, the ONS, CISU, Ministry of Defense, the police and other National Crime
Agencies, in coordination with international partner agencies, will expand their efforts to
identify, anticipate and disrupt hostile cyber activities by foreign actors, cyber criminals
and terrorists. This will improve their intelligence collection and exploitation, with the
aim of obtaining pre-emptive intelligence on the intent and capabilities of our
adversaries.
2. Development and deployment of technology in partnership with industry, including
Active Cyber Defense measures, to deepen our understanding of the threats, to strengthen
the security of the public and private sector systems and networks in the face of these
threats, and to disrupt malicious activity.