41 Section 5 DEFEND Our approach 5.4.4. Organisations and company boards are responsible for ensuring their networks are secure. They must identify critical systems and regularly assess their vulnerability against an evolving technological landscape and threat. They must invest in technology and their staff to reduce vulnerabilities in current and future systems, and in their supply chain, to maintain a level of cyber security proportionate to the risk. They must also have tested capabilities in place to respond if an attack happens. For the CNI, they must do this with government bodies and regulators so we can be confident that cyber risk is being properly managed and – if it is not – intervene in the interests of national security. 5.4.5. The Government will, therefore, understand the level of cyber security across our CNI and have measures in place to intervene where necessary to drive improvements that are in the national interest. 5.4.6. The Government will: • share threat information with industry that only the Government can obtain so they know what they must protect themselves against; • produce advice and guidance on how to manage cyber risk and, working collaboratively with industry and academia, define what good cyber security looks like; • stimulate the introduction of the highend security needed to protect the CNI, such as training facilities, testing labs, security standards and consultancy services; and • conduct exercises with CNI companies to assist them in managing their cyber risks and vulnerabilities. 5.4.7. The NCSC will provide these services for the UK’s most important companies and organisations, including the CNI. It will do so in partnership with departments and regulators, who will assure whether cyber risk is being managed in their sectors to the level demanded by the national interest. 5.4.8. The Government will also make sure that the right regulatory framework for cyber security is in place, one that: • ensures industry acts to protect itself from the threat; • is outcome focused and sufficiently flexible so that it will not fall behind the threat, or lead to compliance rather than sound risk management; • is agile enough to foster growth and innovation, rather than lead it; • is harmonised with regimes in other jurisdictions so that UK companies do not suffer from a fragmented and burdensome approach; and • delivers, when combined with effective support from the Government, a competitive advantage for the UK. 5.4.9. Many of our industry sectors are already regulated for cyber security. Nonetheless, we must ensure the right steps are taken across the whole economy, including the CNI, to manage cyber security risks. Measuring success 5.4.10. The Government will measure its success in protecting our CNI and other priority sectors by assessing progress towards the following outcomes: • we understand the level of cyber security across the CNI, and have measures in place to intervene, where necessary, to drive improvements in the national interest; and National Cyber Security Strategy 2016

Select target paragraph3