79 Annex 3 HEADLINE IMPLEMENTATION PROGRAMME Strategic outcomes Indicative success measures (to 2021) Contributes to 4. Our partnerships with industry on active cyber defence mean that large scale phishing and malware attacks are no longer effective. • The UK is harder to “phish”, because we have large-scale defences against the use of malicious domains, more active anti-phishing protection at scale and it is much harder to use other forms of communication, such as ‘vishing’ and SMS spoofing, to conduct social engineering attacks. • A far larger proportion of malware communications and technical artefacts associated with cyber attacks and exploitation are being blocked. • The UK’s internet and telecommunications traffic is significantly less vulnerable to rerouting by malicious actors. • GCHQ, Defence and NCA capabilities to respond to serious state-sponsored and criminal threats have significantly increased. DEFEND 5. The UK is more secure as a result of technology products and services having cyber security designed into them and activated by default. • The majority of commodity products and services available in the UK in 2021 are making the UK more secure, because they have their default security settings enabled by default or have security integrated into their design. • Government services are trusted by the UK public, because they have been implemented as securely as possible, and fraud levels against them are within acceptable risk parameters. DEFEND 6. • Government has an in-depth understanding of the level of cyber security risk across the whole of government and the wider public sector. • Individual government departments and other bodies protect themselves in proportion to their level of risk and to an agreed government minimum standard. • Government departments and the wider public sector are resilient and can respond effectively to cyber incidents, maintaining functions and recovering quickly. • New technologies and digital services deployed by government will be cyber secure by default. • We are aware of, and actively mitigating, all known internet-facing vulnerabilities in government systems and services; • All government suppliers meet appropriate cyber security standards. DEFEND Government networks and services will be as secure as possible from the moment of their first implementation. The public will be able to use government digital services with confidence, and trust that their information is safe. National Cyber Security Strategy 2016

Select target paragraph3