79
Annex 3
HEADLINE IMPLEMENTATION PROGRAMME
Strategic outcomes
Indicative success measures (to 2021)
Contributes to
4. Our partnerships
with industry
on active cyber
defence mean
that large scale
phishing and
malware attacks
are no longer
effective.
• The UK is harder to “phish”, because we have large-scale
defences against the use of malicious domains, more
active anti-phishing protection at scale and it is much
harder to use other forms of communication, such as
‘vishing’ and SMS spoofing, to conduct social engineering
attacks.
• A far larger proportion of malware communications and
technical artefacts associated with cyber attacks and
exploitation are being blocked.
• The UK’s internet and telecommunications traffic is
significantly less vulnerable to rerouting by malicious
actors.
• GCHQ, Defence and NCA capabilities to respond to
serious state-sponsored and criminal threats have
significantly increased.
DEFEND
5. The UK is more
secure as a result
of technology
products and
services having
cyber security
designed into them
and activated by
default.
• The majority of commodity products and services available
in the UK in 2021 are making the UK more secure, because
they have their default security settings enabled by default
or have security integrated into their design.
• Government services are trusted by the UK public,
because they have been implemented as securely
as possible, and fraud levels against them are within
acceptable risk parameters.
DEFEND
6.
• Government has an in-depth understanding of the level of
cyber security risk across the whole of government and the
wider public sector.
• Individual government departments and other bodies
protect themselves in proportion to their level of risk and to
an agreed government minimum standard.
• Government departments and the wider public sector are
resilient and can respond effectively to cyber incidents,
maintaining functions and recovering quickly.
• New technologies and digital services deployed by
government will be cyber secure by default.
• We are aware of, and actively mitigating, all known
internet-facing vulnerabilities in government systems
and services;
• All government suppliers meet appropriate cyber security
standards.
DEFEND
Government
networks and
services will be as
secure as possible
from the moment
of their first
implementation.
The public will
be able to use
government digital
services with
confidence, and
trust that their
information is safe.
National Cyber Security Strategy 2016