Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The UK Government Approach To Cyber Security
Articles

The UK Government Approach To Cyber Security

ISBuzz TeamBy ISBuzz TeamApril 1, 2017Updated:July 4, 20248 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following on from recent announcements, we thought it might be useful to summarise the general approach of HM Government to cyber security and highlight some of the resources that might be useful to UK-based (and possibly non UK-based) organizations. Cyber security was identified as one of four major threats to the UK in the Government’s National Security Strategy in 2015.

As a quick reminder, the UK government has allocated £1.9 billion towards the problem of cyber security and is approaching it from four angles:

DEFEND – try to stop it happening

DETER – hunt down those that do it

DEVELOP – nurture the talent for the future

INTERNATIONAL ACTION – get other countries to help

The strategy involves the creation of some new organizations, the merging of some old ones and the re-emphasis of a number of existing initiatives. At first sight it may appear to be a confusing mixture of loosely-connected resources so we’ll try to make some sense of how it all fits together.

Central Government Organizations

The central hub of UK cyber activity continues to be GCHQ (Government Communications Head Quarters) based in Cheltenham with regional hubs in Scarborough, Bude, Harrogate and Manchester. GCHQ works with MI5 and the Secret Intelligence Service (SIS, also known as MI6) to protect the UK from a variety of threats including cybercrime, terrorism and whichever foreign nations are causing trouble at the time. The current Director of GCHQ is a guy called Robert Hannigan who has a long track record in advising government on national security issues and according to the GCHQ website is a fan of “hurling and Gaelic football”.

The centrepiece of the new structure is the National Cyber Security Centre (NCSC), part of GCHQ, which brings together and replaces a number of existing organizations under one roof, including:

CERT-UK – used to deal with the handling of cyber incidents; this is now a role of the NCSC

CPNI – Centre for the Protection of National Infrastructure, still exists and is part of the NCSC; focussed on making sure the lights don’t go out amongst other high priority goals

CESG – previously the information security arm of GCHQ, now replaced by the NCSC

CiSP – Cyber Information Sharing Partnership, a platform to allow industry and the Government to share real-time information about current threats. This is now run by the NCSC.

The NCSC publishes a wide range of guidance on cyber security issues, informed by the experience of GCHQ. It also issues a weekly threat report detailing the kinds of malware currently being seen in cyberspace. Finally, the NCSC has responsibility for co-ordinating some forms of education and research in cyber security and runs a certification scheme covering people, products and services. A new conference, CyberUK has been launched in 2017, hosted by the NCSC and intended to inform both government agencies and industry.

In conjunction with the SANS Institute HM Government has launched a Cyber Retraining Academy, a ten week programme open to people with no previous exposure to cyber security and aimed at starting to address the current cyber security skills shortage.

Another useful Government resource is the Information Commissioner’s Office. Based in Wilmslow, Cheshire, the ICO is an independent public body that reports into the Department for Media, Culture and Sport. Elizabeth Denham was appointed UK Information Commissioner in July 2016, having previously held the position of Information and Privacy Commissioner for British Columbia, Canada. Appropriately given her role in Privacy, we were unable to find out via the Internet if Elizabeth also likes “hurling and Gaelic football” or anything else.

The ICO primarily deals with data protection and privacy issues and has the power to issue fines to organizations that breach relevant legislation such as the Data Protection Act and in future the EU General Data Protection Regulation (depending on Brexit, watch this space).

The ICO website has lots of useful guides for data security and also publishes its enforcement and penalty notices if you like to read about other companies’ pain.

Military

In these days of cyberwarfare you won’t be surprised to know that the UK military has its own capabilities in this area. The newly-formed Cyber Security Operations Centre at MOD Corsham (in the West Country, near Bath) is a dedicated facility focussed on defending military networks from attack. The offensive side of the UK’s cyber capability is mounted by the National Offensive Cyber Programme (NOCP), a partnership between GCHQ and the MoD. Supported by the recent Investigatory Powers Act 2016 this programme will consist of proactive state-sponsored hacking and cyber-attacks against whatever targets are deemed appropriate.

 Police and Law Enforcement

The battle against cyber-crime continues unabated and is led in the UK by the National Cyber Crime Unit, NCCU. This is part of the National Crime Agency, NCA (the UK equivalent of the FBI but, let’s face it, not as cool) and it deals with regional units across the country, including the Metropolitan Police Cyber Crime Unit. Each Regional Cyber Crime Unit (RCCU) has officers working to raise awareness amongst people and organizations in their area as well as investigating more serious cases of cybercrime. The NCA co-operates with GCHQ to investigate specific types of cyber crime via a Joint Operations Cell (JOC), mainly focussed on online child exploitation within the Dark Web.

At a more local level, each of the 43 Police Forces in the UK also have a responsibility to record and investigate cybercrime, with varying degrees of knowledge and success. They are helped by the guidance issued by the National Police Chiefs’ Council which co-ordinates best practices in cybercrime investigation via the Digital Policing Board led by the Chief Constable of Essex Police.

Government Initiatives

As well as getting involved directly in Cyberspace, HM Government also tries to encourage the private sector and members of the public to take steps to protect themselves from cybercrime via a number of initiatives.

GetSafeOnline is a privately-owned website supported and promoted by the government aimed at individuals and small businesses and provides a variety of best practice advice to avoid becoming a victim. CyberAware (formerly CyberStreetwise) is the official HM Government effort and uses a rather mean-looking ginger cat to encourage people and businesses to adopt basic precautions.

But the government’s flagship initiative to encourage better cyber security amongst UK businesses is the Cyber Essentials Scheme. This proposes security controls in five main areas:

  1. Boundary firewalls and Internet gateways
  2. Secure configuration
  3. Access control
  4. Malware protection
  5. Patch management

Organizations can become certified to Cyber Essentials at two levels – Basic, via a self-assessment questionnaire and Plus, which includes a basic penetration test by an approved organization. The scheme is effectively a cut-down version of the Ten Steps to Cyber Security, issued by GCHQ and there are some plans to require organizations dealing with the government to have Cyber Essentials certification in the future. But be in no doubt that Cyber Essentials is basic at best and represents an attempt to raise the standard of cyber security in UK businesses from bad to merely ok. The scheme also suffers from a lack of awareness amongst UK businesses; in the most recent government survey, only 6% of organizations had heard of Cyber Essentials versus 18% for the ISO/IEC 27001 standard.

In the event that the worst happens and a cybercrime is experienced, the main method for reporting these is via the Action Fraud website which is run by the City of London Police working alongside the National Fraud Intelligence Bureau. Logging a cybercrime on Action Fraud will allow a crime number to be obtained, possibly for insurance purposes, but the premise behind the website is more for building a bigger picture rather than expecting any direct action for your specific crime. This is useful is you need to keep an eye on the latest scams doing the rounds.

 In Summary

So what are the main points from this quick run-through of the UK government’s approach to cyber security? Well, certainly central government is getting its own act together in a big way and recognizing the need to build capability and develop skills for the future. Similarly, law enforcement is waking up to the fact that traditional methods of policing are no longer enough and they are putting things in place at least at the national and regional level to tackle the cybercrime problem.

Probably the main area of weakness remains the lack of awareness and engagement within industry, particularly at the SME level where the attitude of “security through obscurity” still seems to prevail. The government still has its work cut out to get the message across that effective cyber security is not optional but a must-have in the 21st century.

[su_box title=”About Ken Holmes” style=”noise” box_color=”#336588″][short_info id=’101426′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}