23
Section 3
STRATEGIC CONTEXT
“Just under a fifth of businesses had
their staff take part in cyber security
training in the past year.”
Cyber Security Breaches Survey 2016.
3.20. We also need to develop the
specialist skills and capabilities that will
allow us to keep pace with rapidly evolving
technology and manage the associated
cyber risks. This skills gap represents a
national vulnerability that must be resolved.
Legacy and unpatched systems
3.21. Many organisations in the UK will
continue to use vulnerable legacy systems
until their next IT upgrade. Software on
these systems will often rely on older,
unpatched versions. These older versions
often suffer from vulnerabilities that
attackers look for and have the tools to
exploit. An additional issue is the use
by some organisations of unsupported
software, for which patching regimes do
not exist.
“We recently analysed 115,000 Cisco
devices on the Internet and across
customer environments as a way to
bring attention to the security risks
that aging infrastructure – and lack
of attention to patching vulnerabilities
present… We found that 106,000
of the 115,000 devices had known
vulnerabilities in the software they
were running.”
Cisco 2016 Annual Security Report
Availability of hacking resources
3.22. The ready availability of hacking
information and user-friendly hacking tools
on the Internet is enabling those who want
to develop a hacking capability to do so.
The information hackers need in order to
compromise victims successfully is often
openly accessible and can be harvested
quickly. Everyone, from the living room
to the boardroom, needs to be aware of
the extent of exposure of their personal
details and systems on the Internet, and
the degree to which that could leave them
vulnerable to malicious cyber exploitation.
“99.9% of exploited vulnerabilities
were compromised more than a year
after the vulnerability was published.”
Verizon 2015 Data Breach
Investigations report
CONCLUSIONS
3.23. The UK has pursued policies and
established institutions that have enhanced
our defences and mitigated some of the
threat we face in cyberspace.
3.24. However, we are not yet ahead of the
threat. The types of malicious cyber actors
we must contend with, and their motivations,
have largely endured, even as the volume of
malware and the numbers of such malicious
actors has grown rapidly. The capability of
our most technically proficient adversaries,
namely a select number of states and elite
cyber criminals, has grown. Our collective
challenge is to ensure our defences are
evolved and agile enough to counter them,
to reduce the ability of malicious actors to
attack us and to address the root causes of
the vulnerabilities outlined above.
National Cyber Security Strategy 2016