67 Section 9 METRICS 9.1. Cyber security remains an area of relative immaturity when it comes to the measurement of outcomes and impacts – normally referred to as metrics. Already the science of cyber security has been obscured by hyperbole and obstructed by an absence of calibrated data. This is a source of frustration for policy-makers and businesses alike, who have struggled to measure investment against outcomes. The Government assesses that the effective use of metrics is essential for delivering this strategy and focussing the resources that underpin it. 9.2. We will ensure that this strategy is founded upon a rigorous and comprehensive set of metrics against which we measure progress towards the outcomes we need to achieve. As well as being a major deliverable under the Strategy in its own right, the NCSC will play a crucial role in enabling other parts of Government, industry and society to deliver all of these strategic outcomes within this strategy. 9.3. Annex 3 sets out how the success measures set out in the strategy will contribute to the strategic outcomes, which will be reviewed annually to ensure they accurately reflect our national goals and requirements. The headline, strategic outcomes are as follows: 1. The UK has the capability effectively to detect investigate and counter the threat from the cyber activities of our adversaries. 2. The impact of cybercrime on the UK and its interests is significantly reduced and cyber criminals are deterred from targeting the UK. 3. The UK has the capability to manage and respond effectively to cyber incidents to reduce the harm they cause to the UK and counter cyber adversaries. 4. Our partnerships with industry on active cyber defence mean that large scale phishing and malware attacks are no longer effective. 5. The UK is more secure as a result of technology products and services having cyber security designed into them and activated by default. 6. Government networks and services will be as secure as possible from the moment of their first implementation. The public will be able to use government digital services with confidence and trust that their information is safe. 7. All organisations in the UK, large and small, are effectively managing their cyber risk and are supported by high quality advice designed by the NCSC, underpinned by the right mix of regulation and incentives. 8. There is the right ecosystem in the UK to develop and sustain a cyber security sector that can meet our national security demands. National Cyber Security Strategy 2016

Select target paragraph3