We're still waiting for UK government to get strategic about cybersecurity

Government investment in cybersecurity is great, but what matters is where the money goes

The Queen has opened the new British National Cyber Security Centre (NCSC), and chief executive Ciaran Martin insisted it's the "perfect place to coordinate our cybersecurity and manage incidents across the UK".

He also said that "initiatives will disappoint" and "things will go wrong" which pretty much sums up the UK government's cybersecurity strategy thus far. Which you may think is an odd statement, given that Chancellor of the Exchequer, Philip Hammond MP, stated at the NCSC opening that it will cement our position as a "world leader in cybersecurity". This, frankly, is an odd statement.

Show us the money

Hammond also insisted that "Britain is transforming its capabilities in cyber defence and deterrence", which is good to know. Unfortunately, the government has been saying this for years but not actually doing much to any great effect.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Hammond's predecessor, George Osborne, was also good at talking about cybersecurity. In a 2015 speech announcing 1.9 billion of cybersecurity spending over five years, Osborne mentioned the word 'cyber' 134 times in 45 minutes. Given that there are only three years left of Osborne's original spending timeline, and the current government has made little by way of firm strategic commitments, it's worrying to say the least.

Show us the strategy

Forget 'world leader'; Parliament's Public Accounts Committee chair, Meg Hillier, said that Britain is ranked below Brazil, China and South Africa when it comes to securing smartphones and laptops. This is hardly surprising when the committee report says the government has "little oversight of the costs and performance of government information assurance projects and processes".

The big picture, the strategic problem, is that the government effectively does not have a consistent approach to security breaches and so is unable to make informed decisions when it comes to prioritising resources both financial and hands-on.

Addressing the skills shortage is a start

All that said, there are some promising moves coming from the government. These include initiatives such as GCHQ's CyberFirst programme, which offers the best graduates financial support through bursaries and employment placements which can help them get the hands-on experience needed to properly skill the UK cybersecurity sector.

Advertisement - Article continues below

Beyond that and the opening of the NCSC, the National Cyber Security Strategy (NCSS) seems to be treading water somewhat. It's asked security companies, two years on, to put forward ideas as to how the UK can become cyber secure. It's asking for submissions on such things as what threats we face (yes, seriously) and how the government can combat them (ditto).

Looking for leadership

Should we be that surprised at this apparent discordant response to the cybersecurity threat? If you look to the average enterprise and how cybersecurity is rarely a strategic, business process-led, boardroom level discussion, then the answer is: well no, not really.

That so many C-suite directors do not understand the threats they face when it comes to cyber attack, let alone how to approach defending the organisation, now is the time for the government to grasp the nettle and show some leadership. There are three years of the five-year strategy left, and time is fast running out for the UK government to finally decide what that strategy actually is...

Picture: Bigstock

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/business-strategy/chief-information-officer-cio/354564/cios-are-taking-their-seat-at-the-boardroom
chief information officer (CIO)

CIOs are taking their seat at the boardroom table

17 Jan 2020
Visit/government-it-strategy/28305/ir35-news
Policy & legislation

Government announces review of IR35 off-payroll changes

8 Jan 2020
Visit/strategy/28223/cio-job-description-what-does-a-cio-do
Business strategy

CIO job description: What does a CIO do?

7 Jan 2020
Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020