42 Section 5 DEFEND • our most important companies and organisations understand the level of threat and implement proportionate cyber security practices. 5.5. CHANGING PUBLIC AND BUSINESS BEHAVIOURS 5.5.1 A successful UK digital economy relies upon the confidence of businesses and the public in online services. The UK The Government has worked with industry and other parts of the public sector to increase awareness and understanding of the threat. The Government has also provided the public and business with access to some of the tools that they need to protect themselves. While there are many organisations that are doing an excellent job – in places, world-leading – of protecting themselves, and in providing services to others online, the majority of businesses and individuals are still not properly managing cyber risk. “Last year, the average cost of breaches to large businesses that had them was £36,500. For small firms the average cost of breaches was £3,100. 65% of large organisations reported they had suffered an information security breach in the past year, and 25% of these experienced a breach at least once a month. Nearly seven out of ten attacks involved viruses, spyware or malware that might have been prevented using the Government’s Cyber Essentials scheme.” 2016 Government Cyber Health Check and Cyber Security Breaches Survey National Cyber Security Strategy 2016 Objective 5.5.2. Our objective is to ensure that individuals and organisations, regardless of size or sector, are taking appropriate steps to protect themselves, and their customers, from the harm caused by cyber attacks. Our approach 5.5.3. The Government will provide the advice that the economy needs to protect itself. We will improve how this advice is delivered to maximise its effect. For the public, the Government will harness ‘trusted voices’ to increase the reach, credibility and relevance of our message. We will provide advice that is easy to act upon and relevant to individuals, at the point they are accessing services and exposing themselves to risk. We will involve the Devolved Administrations and other authorities as appropriate. 5.5.4. For businesses, we will work through organisations such as insurers, regulators and investors which can exert influence over companies to ensure they manage cyber risk. In doing so, we will highlight the clear business benefits and the pricing of cyber risk by market influencers. We will seek to understand better why many organisations still fail to protect themselves adequately and then work in partnership with organisations such as professional standards bodies, to move beyond raising awareness to persuade companies to take action. We will also make sure we have the right regulatory framework in place to manage those cyber risks the market fails to address. As part of this, we will seek to use levers, such as the GDPR, to drive up standards of cyber security and protect citizens. 5.5.5. Individuals and organisations and organisations in the UK will have access to the information, education, and tools they need to protect themselves. To ensure we deliver a step-change in public behaviour,

Select target paragraph3