22 Section 3 STRATEGIC CONTEXT VULNERABILITIES An expanding range of devices 3.15. When the last National Cyber Security Strategy was published in 2011, most people conceived of cyber security through the prism of protecting devices such as their desktop computer or laptop. Since then the Internet has become increasingly integrated into our daily lives in ways we are largely oblivious to. The ‘Internet of Things’ creates new opportunities for exploitation and increases the potential impact of attacks which have the potential to cause physical damage, injury to persons and, in a worst case scenario, death. 3.16. The rapid implementation of connectivity in industrial control processes in critical systems, across a wide range of industries such as energy, mining, agriculture and aviation, has created the Industrial Internet of Things. This is simultaneously opening up the possibility of devices and processes, which were never vulnerable to such interference in the past, being hacked and tampered with, with potentially disastrous consequences. 3.17. Therefore, we are no longer just vulnerable to cyber harms caused by the lack of cyber security on our own devices but by threats to the interconnected systems that are fundamental to our society, health and welfare. Poor cyber hygiene and compliance 3.18. Awareness of technical vulnerabilities in software and networks, and the need for cyber hygiene in the UK, has undoubtedly increased over the past five years. This is in part a consequence of initiatives like the Government’s National Cyber Security Strategy 2016 ‘10 Steps to Cyber Security’, but also due to the increased public profile of major cyber incidents affecting governments and corporations. Cyber attacks are not necessarily sophisticated or inevitable and are often the result of exploited – but easily rectifiable and, often, preventable – vulnerabilities. In most cases, it continues to be the vulnerability of the victim, rather than the ingenuity of the attacker, that is the deciding factor in the success of a cyber attack. Businesses and organisations decide on where and how to invest in cyber security based on a cost-benefit assessment, but they are ultimately liable for the security of their data and systems. Only by balancing the risk to their critical systems and sensitive data from cyber attacks, with sufficient investment in people, technology and governance, will businesses reduce their exposure to potential cyber harm. “There is no conceivable information security system that can stop one person out of a hundred opening a phishing email, and that can be all it takes.” Ciaran Martin, Director General for Cyber Security, GCHQ – June 2015 Insufficient training and skills 3.19. We lack the skills and knowledge to meet our cyber security needs across both the public and private sector. In businesses, many staff members are not cyber security aware and do not understand their responsibilities in this regard, partially due to a lack of formal training. The public is also insufficiently cyber aware.

Select target paragraph3