33
Section 5
DEFEND
5.0.1. The DEFEND elements of this
strategy aim to ensure that UK networks,
data and systems in the public, commercial
and private spheres are resilient to and
protected from cyber attack. It will never
be possible to stop every cyber attack, just
as it is not possible to stop every crime.
However, together with citizens, education
providers, academia, businesses and other
governments, the UK can build layers of
defence that will significantly reduce our
exposure to cyber incidents, protect our
most precious assets, and allow us all to
operate successfully and prosperously in
cyberspace. Acting to promote cooperation
between states and good cyber security
practice is also in the interest of our
collective security.
5.0.2. The Government will implement
measures to ensure that citizens,
businesses, public and private sector
organisations and institutions have
access to the right information to defend
themselves. The National Cyber Security
Centre provides a unified source of advice
in government for threat intelligence
and information assurance, ensuring
that we can offer tailored guidance for
cyber defence and respond quickly and
effectively to major incidents in cyberspace.
The Government will work with industry
and international partners to define what
good cyber security looks like for public
and private sectors, for our most important
systems and services, and for the economy
as a whole. We will build security by
default into all new government and critical
systems. Law enforcement agencies will
collaborate closely with industry and the
National Cyber Security Centre to provide
dynamic criminal threat intelligence with
which industry can better defend itself,
and to promote protective security advice
and standards.
5.1.
ACTIVE CYBER DEFENCE
5.1.1. Active Cyber Defence (ACD) is the
principle of implementing security measures
to strengthen a network or system to
make it more robust against attack. In a
commercial context, Active Cyber Defence
normally refers to cyber security analysts
developing an understanding of the threats
to their networks, and then devising and
implementing measures to proactively
combat, or defend, against those threats. In
the context of this strategy, the Government
has chosen to apply the same principle on
a larger scale: the Government will use its
unique expertise, capabilities and influence
to bring about a step-change in national
cyber security to respond to cyber threats.
The ‘network’ we are attempting to defend
is the entire UK cyberspace. The activities
proposed represent a defensive action plan,
drawing on the expertise of NCSC as the
National Technical Authority to respond to
cyber threats to the UK at a macro level.
Objectives
5.1.2. In undertaking ACD, the Government
aims to:
• make the UK a much harder target
for state sponsored actors and cyber
criminals by increasing the resilience of
UK networks;
• defeat the vast majority of highvolume/low-sophistication malware
activity on UK networks by blocking
malware communications between
hackers and their victims;
• evolve and increase the scope and
scale of Government’s capabilities to
disrupt serious state sponsored and
cyber criminal threats;
• secure our internet and
telecommunications traffic from
hijacking by malicious actors;
National Cyber Security Strategy 2016