 always downloading the latest software updates. Experts agree adopting these behaviors will provide small businesses and individuals with protection against cybercrime. Cyber Awareness should be supported by all partners, including the police and businesses in the retail, leisure, travel and professional services sectors. 4.1.7 CYBER ESSENTIALS The Cyber Essentials scheme was developed to show organizations how to protect themselves against low-level “commodity threat”. It lists five technical controls (access control; boundary firewalls and Internet gateways; malware protection; patch management and secure configuration) that organizations should have in place. The vast majority of cyber-attacks use relatively simple methods which exploit basic vulnerabilities in software and computer systems. There are tools and techniques openly available on the Internet which enables even low-skill actors to exploit these vulnerabilities. Properly implementing the Cyber Essentials scheme will protect against the vast majority of common internet threats. 4.1.8 MANAGING INCIDENTS AND UNDERSTANDING THE THREAT The number and severity of cyber incidents affecting organizations across the public and private sector are likely to increase. We therefore need to define how both the private sector and the public engage with the Government during a cyber-incident. We will ensure that Government’s level of support for each sector – taking into account its cyber maturity – is clearly defined and understood. The Government’s collection and dissemination of information about the threat must be delivered in a manner and at a speed suitable for all types of organization. The private sector, government and the public can currently access multiple sources of information, guidance and assistance on cyber security. This must be simplified. We must ensure that the Government offering, both in responses to incidents, and in the provision of guidance, does not exist in isolation, but in partnership with the private sector. Our incident management processes should reflect a holistic approach to incidents, whereby we learn from partners and share mitigation techniques. We will also continue to use our relationships with other CIRTs allies as an integrated part of our incident management function. Current incident management remains somewhat fragmented across government departments and this strategy will create a unified approach. The CIRT-SL will deliver a streamlined and

Select target paragraph3