23 Section 3 STRATEGIC CONTEXT “Just under a fifth of businesses had their staff take part in cyber security training in the past year.” Cyber Security Breaches Survey 2016. 3.20. We also need to develop the specialist skills and capabilities that will allow us to keep pace with rapidly evolving technology and manage the associated cyber risks. This skills gap represents a national vulnerability that must be resolved. Legacy and unpatched systems 3.21. Many organisations in the UK will continue to use vulnerable legacy systems until their next IT upgrade. Software on these systems will often rely on older, unpatched versions. These older versions often suffer from vulnerabilities that attackers look for and have the tools to exploit. An additional issue is the use by some organisations of unsupported software, for which patching regimes do not exist. “We recently analysed 115,000 Cisco devices on the Internet and across customer environments as a way to bring attention to the security risks that aging infrastructure – and lack of attention to patching vulnerabilities present… We found that 106,000 of the 115,000 devices had known vulnerabilities in the software they were running.” Cisco 2016 Annual Security Report Availability of hacking resources 3.22. The ready availability of hacking information and user-friendly hacking tools on the Internet is enabling those who want to develop a hacking capability to do so. The information hackers need in order to compromise victims successfully is often openly accessible and can be harvested quickly. Everyone, from the living room to the boardroom, needs to be aware of the extent of exposure of their personal details and systems on the Internet, and the degree to which that could leave them vulnerable to malicious cyber exploitation. “99.9% of exploited vulnerabilities were compromised more than a year after the vulnerability was published.” Verizon 2015 Data Breach Investigations report CONCLUSIONS 3.23. The UK has pursued policies and established institutions that have enhanced our defences and mitigated some of the threat we face in cyberspace. 3.24. However, we are not yet ahead of the threat. The types of malicious cyber actors we must contend with, and their motivations, have largely endured, even as the volume of malware and the numbers of such malicious actors has grown rapidly. The capability of our most technically proficient adversaries, namely a select number of states and elite cyber criminals, has grown. Our collective challenge is to ensure our defences are evolved and agile enough to counter them, to reduce the ability of malicious actors to attack us and to address the root causes of the vulnerabilities outlined above. National Cyber Security Strategy 2016

Select target paragraph3