22
Section 3
STRATEGIC CONTEXT
VULNERABILITIES
An expanding range of devices
3.15. When the last National Cyber
Security Strategy was published in
2011, most people conceived of cyber
security through the prism of protecting
devices such as their desktop computer
or laptop. Since then the Internet has
become increasingly integrated into our
daily lives in ways we are largely oblivious
to. The ‘Internet of Things’ creates new
opportunities for exploitation and increases
the potential impact of attacks which have
the potential to cause physical damage,
injury to persons and, in a worst case
scenario, death.
3.16. The rapid implementation of
connectivity in industrial control processes
in critical systems, across a wide range
of industries such as energy, mining,
agriculture and aviation, has created
the Industrial Internet of Things. This is
simultaneously opening up the possibility of
devices and processes, which were never
vulnerable to such interference in the past,
being hacked and tampered with, with
potentially disastrous consequences.
3.17. Therefore, we are no longer just
vulnerable to cyber harms caused by the
lack of cyber security on our own devices
but by threats to the interconnected
systems that are fundamental to our
society, health and welfare.
Poor cyber hygiene and compliance
3.18. Awareness of technical
vulnerabilities in software and networks,
and the need for cyber hygiene in the UK,
has undoubtedly increased over the past
five years. This is in part a consequence
of initiatives like the Government’s
National Cyber Security Strategy 2016
‘10 Steps to Cyber Security’, but also due
to the increased public profile of major
cyber incidents affecting governments
and corporations. Cyber attacks are not
necessarily sophisticated or inevitable
and are often the result of exploited – but
easily rectifiable and, often, preventable –
vulnerabilities. In most cases, it continues
to be the vulnerability of the victim, rather
than the ingenuity of the attacker, that is
the deciding factor in the success of a
cyber attack. Businesses and organisations
decide on where and how to invest in
cyber security based on a cost-benefit
assessment, but they are ultimately liable
for the security of their data and systems.
Only by balancing the risk to their critical
systems and sensitive data from cyber
attacks, with sufficient investment in
people, technology and governance,
will businesses reduce their exposure to
potential cyber harm.
“There is no conceivable information
security system that can stop one
person out of a hundred opening a
phishing email, and that can be all
it takes.”
Ciaran Martin, Director General for
Cyber Security, GCHQ – June 2015
Insufficient training and skills
3.19. We lack the skills and
knowledge to meet our cyber security
needs across both the public and private
sector. In businesses, many staff
members are not cyber security
aware and do not understand their
responsibilities in this regard, partially
due to a lack of formal training. The public
is also insufficiently cyber aware.