41
Section 5
DEFEND
Our approach
5.4.4. Organisations and company
boards are responsible for ensuring their
networks are secure. They must identify
critical systems and regularly assess
their vulnerability against an evolving
technological landscape and threat.
They must invest in technology and their
staff to reduce vulnerabilities in current
and future systems, and in their supply
chain, to maintain a level of cyber security
proportionate to the risk. They must also
have tested capabilities in place to respond
if an attack happens. For the CNI, they
must do this with government bodies and
regulators so we can be confident that
cyber risk is being properly managed and
– if it is not – intervene in the interests of
national security.
5.4.5. The Government will, therefore,
understand the level of cyber security
across our CNI and have measures in
place to intervene where necessary
to drive improvements that are in the
national interest.
5.4.6. The Government will:
• share threat information with industry
that only the Government can obtain
so they know what they must protect
themselves against;
• produce advice and guidance on how
to manage cyber risk and, working
collaboratively with industry and
academia, define what good cyber
security looks like;
• stimulate the introduction of the highend security needed to protect the CNI,
such as training facilities, testing labs,
security standards and consultancy
services; and
• conduct exercises with CNI companies
to assist them in managing their cyber
risks and vulnerabilities.
5.4.7. The NCSC will provide these services
for the UK’s most important companies
and organisations, including the CNI. It will
do so in partnership with departments and
regulators, who will assure whether cyber
risk is being managed in their sectors to the
level demanded by the national interest.
5.4.8. The Government will also make
sure that the right regulatory framework for
cyber security is in place, one that:
• ensures industry acts to protect itself
from the threat;
• is outcome focused and sufficiently
flexible so that it will not fall behind the
threat, or lead to compliance rather
than sound risk management;
• is agile enough to foster growth and
innovation, rather than lead it;
• is harmonised with regimes in other
jurisdictions so that UK companies
do not suffer from a fragmented and
burdensome approach; and
• delivers, when combined with
effective support from the Government,
a competitive advantage for the UK.
5.4.9. Many of our industry sectors
are already regulated for cyber security.
Nonetheless, we must ensure the right
steps are taken across the whole
economy, including the CNI, to manage
cyber security risks.
Measuring success
5.4.10. The Government will measure its
success in protecting our CNI and other
priority sectors by assessing progress
towards the following outcomes:
• we understand the level of cyber
security across the CNI, and have
measures in place to intervene, where
necessary, to drive improvements in
the national interest; and
National Cyber Security Strategy 2016