35 Section 5 DEFEND • working towards the implementation of controls to secure the routing of internet traffic for government departments to ensure that it cannot be illegitimately re-routed by malicious actors; and • investing in programmes in the Ministry of Defence, the NCA and GCHQ that will enhance the capabilities of these organisations to respond to, and disrupt, serious state-sponsored and criminal cyber activity targeting UK networks. We will develop these technical interventions as threats evolve to ensure that UK citizens and businesses are protected by default from the majority of large-scale commodity cyber attacks. Measuring success 5.1.6. The Government will measure its success in establishing effective ACD by assessing progress towards the following outcomes: • the UK is harder to ‘phish’, because we have large-scale defences against the use of malicious domains, more active anti-phishing protection at scale and it is much harder to use other forms of communication, such as ‘vishing’ and SMS spoofing, to conduct social engineering attacks; • a far larger proportion of malware communications and technical artefacts associated with cyber attacks and exploitation are being blocked; • the UK’s internet and telecommunications traffic is significantly less vulnerable to rerouting by malicious actors; • GCHQ, the Armed Forces’ and NCA capabilities to respond to serious statesponsored and criminal threats have significantly increased. 5.2. BUILDING A MORE SECURE INTERNET 5.2.1. Changing technology provides us with the opportunity to significantly reduce the ability of our adversaries to conduct cyber crime in the UK by ensuring that future online products and services coming into use are ‘secure by default’. That means ensuring that the security controls built into the software and hardware we use are activated as a default setting by the manufacturer so that the user experiences the maximum security offered to them, unless they actively choose to turn it off. The challenge is to effect transformative change in a way that supports the end user and offers a commercially viable, but secure, product or service – all within the context of maintaining the free and open nature of the Internet. “Internet-connected things are multiplying rapidly. We saw many proof-of-concept and real world attacks in 2015, identifying serious vulnerabilities in cars, medical devices and more. Manufacturers need to prioritise security to reduce the risk of serious personal, economic and social consequences.” Symantec 2016 Internet Security Threat Report National Cyber Security Strategy 2016

Select target paragraph3