36 Section 5 DEFEND 5.2.2. The Government is well-placed to take a lead role in exploring those new technologies that will better protect our own systems, help industry build greater security into the supply chain, secure the software ecosystem and provide automated protections to citizens accessing government services online. The Government must test and implement new technologies that provide automated protection for government online products and services. Where possible, similar technologies should be offered to the private sector and the citizen. Objective 5.2.3. The majority of online products and services coming into use become ‘secure by default’ by 2021. Consumers will be empowered to choose products and services that have built-in security as a default setting. Individuals can switch off these settings if they choose to do so but those consumers who wish to engage in cyberspace in the most secure way will be automatically protected. Our approach 5.2.4. We will pursue the following actions: • the Government will lead by example by running secure services on the Internet that do not rely on the Internet itself being secure; • the Government will explore options for collaboration with industry to develop cutting-edge ways to make hardware and software more ‘secure by default’; and • we will adopt challenging new cyber security technologies in government, encouraging Devolved Administrations to do likewise, in order to reduce perceived risks of adoption. This will provide proof of concept and demonstrate the security benefits of new technologies and approaches. National Cyber Security Strategy 2016 It will also put security at the heart of new product development, eliminate opportunities for criminal exploitation and thereby protect the end user. 5.2.5. To do this we will: • continue to encourage hardware and software providers to sell products with security settings activated as default, requiring the user to actively disable these settings to make them insecure. Some vendors are already doing this, but some are not yet taking these necessary steps; • continue to develop an Internet Protocol (IP) reputation service to protect government digital services (this would allow online services to get information about an IP address connecting to them, helping the service make more informed risk management decisions in real time); • seek to install products on government networks that will provide assurance that software is running correctly, and not being maliciously interfered with; • look to expand beyond the GOV.UK domain into other digital services measures that notify users who are running out-of-date browsers; and • invest in technologies like Trusted Platform Modules (TPM) and emerging industry standards such as Fast Identity Online (FIDO), which do not rely on passwords for user authentication, but use the machine and other devices in the user’s possession to authenticate. The Government will test innovative authentication mechanisms to demonstrate what they can offer, both in terms of security and overall user experience. 5.2.6. The Government will also explore how to encourage the market by providing security ratings for new products, so that consumers have clear information on

Select target paragraph3