38 Section 5 DEFEND attack. This means ensuring an accurate and up to date knowledge of all systems, data, and those who have access to them. The likelihood and impact of a cyber incident will be minimised by implementing best practice as set out by the NCSC. The Government will also ensure that it is able to respond effectively to cyber incidents through a programme of incident exercises and regular testing of government networks. We will invite Devolved Administrations and local authorities to participate in these exercises, as appropriate. Through automated scanning, we will ensure that we have a better knowledge of government’s online security status. 5.3.6. Cyber security is not just about technology. Almost all successful cyber attacks have a contributing human factor. We will therefore continue to invest in our people, to ensure that everyone who works in government has a sound awareness of cyber risk. We will develop specific cyber expertise in areas where the risks are heightened and ensure that we have the right processes in place to manage these risks effectively. 5.3.7. The NCSC will develop worldleading cyber security guidance which will keep pace with the threat and development of new technologies. We will take steps to make sure government organisations have easy access to threat information to inform their understanding of their own cyber risks and take appropriate action. 5.3.8. We will continue to improve our highest classification networks to safeguard the Government’s most sensitive communications. 5.3.9. Health and care systems pose unique challenges in the context of cyber security. The sector employs around 1.6 million people in over 40,000 organisations, each National Cyber Security Strategy 2016 with vastly differing information security resources and capability. The National Data Guardian for Health and Care has set new data security standards for the health and social care systems in England, alongside a new data consent/opt-out model for patients. The Government will work with health and social care organisations to implement these standards. “Britain is a world leader in cyber security, but with growing threats, this new Cyber Security Operations Centre will ensure our Armed forces continue to operate securely. Our increasing defence budget means that we can stay ahead of our adversaries in cyberspace while also investing in conventional capabilities” The Rt Hon Michael Fallon MP, Defence Secretary, April 2016 5.3.10. Cyber security is vital to our defence. Our Armed Forces depend on information and communications systems, both in the UK and on operations around the world. The infrastructure and personnel of the Ministry of Defence (MoD) are prominent targets. Defence systems are regularly targeted by criminals, foreign intelligence services and other malicious actors seeking to exploit personnel, disrupt business and operations, and corrupt and steal information. We will enhance cyber threat awareness, detection, and reaction functions, through the development of a Cyber Security Operations Centre (CSOC) that uses stateof-the-art defensive cyber capabilities to protect the MoD’s cyberspace and deal with threats. The CSOC will work closely with the NCSC to confront the MoD’s cyber security challenges and contribute to wider national cyber security.

Select target paragraph3