36
Section 5
DEFEND
5.2.2. The Government is well-placed
to take a lead role in exploring those
new technologies that will better protect
our own systems, help industry build
greater security into the supply chain,
secure the software ecosystem and
provide automated protections to citizens
accessing government services online.
The Government must test and implement
new technologies that provide automated
protection for government online products
and services. Where possible, similar
technologies should be offered to the
private sector and the citizen.
Objective
5.2.3. The majority of online products
and services coming into use become
‘secure by default’ by 2021. Consumers
will be empowered to choose products
and services that have built-in security as
a default setting. Individuals can switch off
these settings if they choose to do so but
those consumers who wish to engage in
cyberspace in the most secure way will be
automatically protected.
Our approach
5.2.4. We will pursue the following actions:
• the Government will lead by example
by running secure services on the
Internet that do not rely on the Internet
itself being secure;
• the Government will explore options for
collaboration with industry to develop
cutting-edge ways to make hardware and
software more ‘secure by default’; and
• we will adopt challenging new cyber
security technologies in government,
encouraging Devolved Administrations
to do likewise, in order to reduce
perceived risks of adoption. This
will provide proof of concept and
demonstrate the security benefits of
new technologies and approaches.
National Cyber Security Strategy 2016
It will also put security at the heart of
new product development, eliminate
opportunities for criminal exploitation
and thereby protect the end user.
5.2.5. To do this we will:
• continue to encourage hardware and
software providers to sell products with
security settings activated as default,
requiring the user to actively disable
these settings to make them insecure.
Some vendors are already doing this,
but some are not yet taking these
necessary steps;
• continue to develop an Internet
Protocol (IP) reputation service to
protect government digital services
(this would allow online services to
get information about an IP address
connecting to them, helping the service
make more informed risk management
decisions in real time);
• seek to install products on government
networks that will provide assurance
that software is running correctly, and
not being maliciously interfered with;
• look to expand beyond the GOV.UK
domain into other digital services
measures that notify users who are
running out-of-date browsers; and
• invest in technologies like Trusted
Platform Modules (TPM) and emerging
industry standards such as Fast
Identity Online (FIDO), which do not rely
on passwords for user authentication,
but use the machine and other
devices in the user’s possession to
authenticate. The Government will test
innovative authentication mechanisms
to demonstrate what they can offer,
both in terms of security and overall
user experience.
5.2.6. The Government will also explore
how to encourage the market by providing
security ratings for new products, so that
consumers have clear information on