To progress this work, the Government has been reassessing the current risk landscape in light of the Covid-19 crisis and the increasingly rapid digitisation of the economy. Coronavirus has fundamentally altered our lives and the role that tech plays within it. Tech plays a central role in enabling the UK’s economic, social and health recovery - from analysing data to creating new jobs to ensuring education can continue and people remain connected. In this context, of particular interest is ensuring small and medium-sized businesses (SMEs) are well supported to embark on this transition in a way that both stimulates their economy recovery and growth whilst ensuring their security risks are mitigated. Likewise, supporting procurement professionals and those managing supplier risks to undertake their roles effectively is of utmost priority to ensuring any organisation is resilient in the current context. The Department for Digital, Culture, Media and Sport (DCMS) will be working with industry over the coming months to develop policy proposals which seek to address some of these barriers, as highlighted through our evidence gathering efforts. Further details are outlined in the Next Steps section. Summary of the call for evidence findings The Call for Evidence was a key first step in testing our understanding of the barriers that many organisations face in managing their risks. These barriers were outlined as: e arange of inabilities that organisations may have, from not knowing what to do, to not having the right skills and resources; e alack of commercial rationale or business drivers that stimulate the prioritisation of and investment in cyber risk management; and ¢ acomplex and insecure digital environment within which organisations base many business operations in this digital era. The majority of respondents agreed with the three barriers that were presented in the Call for Evidence. Over 70% of respondents agreed that each presented a moderate or severe barrier to organisations managing their risk effectively, providing validation for DCMS’ understanding of the main barriers to organisations undertaking effective cyber risk management. Respondents also highlighted two further barriers of: 1. a lack of incentives to support organisations to protect their organisation online; and 2. insufficient regulation to compel organisations to better manage cyber risks. While we believe that Government initiatives to date have had a positive impact on cyber security, these efforts have tended to focus on improving organisational capability, and more recently on addressing insecurities in the design and provision of products or services. Less explicit focus has been placed on exploring and addressing commercial rationales for investment in cyber security. The Call for Evidence focused more extensively on the underlying reasons for the apparent lack of commercial drivers (barrier 3/27

Select target paragraph3