38
Section 5
DEFEND
attack. This means ensuring an accurate
and up to date knowledge of all systems,
data, and those who have access to them.
The likelihood and impact of a cyber
incident will be minimised by implementing
best practice as set out by the NCSC.
The Government will also ensure that it
is able to respond effectively to cyber
incidents through a programme of incident
exercises and regular testing of government
networks. We will invite Devolved
Administrations and local authorities
to participate in these exercises, as
appropriate. Through automated scanning,
we will ensure that we have a better
knowledge of government’s online security
status.
5.3.6. Cyber security is not just about
technology. Almost all successful cyber
attacks have a contributing human factor.
We will therefore continue to invest in our
people, to ensure that everyone who works
in government has a sound awareness of
cyber risk. We will develop specific cyber
expertise in areas where the risks are
heightened and ensure that we have the
right processes in place to manage these
risks effectively.
5.3.7. The NCSC will develop worldleading cyber security guidance which will
keep pace with the threat and development
of new technologies. We will take steps to
make sure government organisations have
easy access to threat information to inform
their understanding of their own cyber risks
and take appropriate action.
5.3.8. We will continue to improve
our highest classification networks to
safeguard the Government’s most sensitive
communications.
5.3.9. Health and care systems pose unique
challenges in the context of cyber security.
The sector employs around 1.6 million
people in over 40,000 organisations, each
National Cyber Security Strategy 2016
with vastly differing information security
resources and capability. The National Data
Guardian for Health and Care has set new
data security standards for the health and
social care systems in England, alongside
a new data consent/opt-out model for
patients. The Government will work with
health and social care organisations to
implement these standards.
“Britain is a world leader in cyber
security, but with growing threats,
this new Cyber Security Operations
Centre will ensure our Armed forces
continue to operate securely. Our
increasing defence budget means that
we can stay ahead of our adversaries
in cyberspace while also investing in
conventional capabilities”
The Rt Hon Michael Fallon MP,
Defence Secretary, April 2016
5.3.10. Cyber security is vital to our defence.
Our Armed Forces depend on information
and communications systems, both in the
UK and on operations around the world. The
infrastructure and personnel of the Ministry
of Defence (MoD) are prominent targets.
Defence systems are regularly targeted by
criminals, foreign intelligence services and
other malicious actors seeking to exploit
personnel, disrupt business and operations,
and corrupt and steal information. We
will enhance cyber threat awareness,
detection, and reaction functions, through
the development of a Cyber Security
Operations Centre (CSOC) that uses stateof-the-art defensive cyber capabilities to
protect the MoD’s cyberspace and deal with
threats. The CSOC will work closely with the
NCSC to confront the MoD’s cyber security
challenges and contribute to wider national
cyber security.