67
Section 9
METRICS
9.1.
Cyber security remains an area of
relative immaturity when it comes to the
measurement of outcomes and impacts
– normally referred to as metrics. Already
the science of cyber security has been
obscured by hyperbole and obstructed
by an absence of calibrated data. This is
a source of frustration for policy-makers
and businesses alike, who have struggled
to measure investment against outcomes.
The Government assesses that the effective
use of metrics is essential for delivering this
strategy and focussing the resources that
underpin it.
9.2.
We will ensure that this strategy
is founded upon a rigorous and
comprehensive set of metrics against
which we measure progress towards the
outcomes we need to achieve. As well
as being a major deliverable under the
Strategy in its own right, the NCSC will
play a crucial role in enabling other parts of
Government, industry and society to deliver
all of these strategic outcomes within this
strategy.
9.3.
Annex 3 sets out how the success
measures set out in the strategy will
contribute to the strategic outcomes,
which will be reviewed annually to ensure
they accurately reflect our national goals
and requirements. The headline, strategic
outcomes are as follows:
1. The UK has the capability effectively
to detect investigate and counter the
threat from the cyber activities of our
adversaries.
2. The impact of cybercrime on the
UK and its interests is significantly
reduced and cyber criminals are
deterred from targeting the UK.
3. The UK has the capability to manage
and respond effectively to cyber
incidents to reduce the harm they
cause to the UK and counter cyber
adversaries.
4. Our partnerships with industry on
active cyber defence mean that large
scale phishing and malware attacks
are no longer effective.
5. The UK is more secure as a result of
technology products and services
having cyber security designed into
them and activated by default.
6. Government networks and services
will be as secure as possible from the
moment of their first implementation.
The public will be able to use
government digital services with
confidence and trust that their
information is safe.
7. All organisations in the UK, large
and small, are effectively managing
their cyber risk and are supported by
high quality advice designed by the
NCSC, underpinned by the right mix
of regulation and incentives.
8. There is the right ecosystem in the
UK to develop and sustain a cyber
security sector that can meet our
national security demands.
National Cyber Security Strategy 2016