We're still waiting for UK government to get strategic about cybersecurity

Government investment in cybersecurity is great, but what matters is where the money goes

The Queen has opened the new British National Cyber Security Centre (NCSC), and chief executive Ciaran Martin insisted it's the "perfect place to coordinate our cybersecurity and manage incidents across the UK".

He also said that "initiatives will disappoint" and "things will go wrong" which pretty much sums up the UK government's cybersecurity strategy thus far. Which you may think is an odd statement, given that Chancellor of the Exchequer, Philip Hammond MP, stated at the NCSC opening that it will cement our position as a "world leader in cybersecurity". This, frankly, is an odd statement.

Show us the money

Hammond also insisted that "Britain is transforming its capabilities in cyber defence and deterrence", which is good to know. Unfortunately, the government has been saying this for years but not actually doing much to any great effect.

Advertisement
Advertisement - Article continues below

Hammond's predecessor, George Osborne, was also good at talking about cybersecurity. In a 2015 speech announcing 1.9 billion of cybersecurity spending over five years, Osborne mentioned the word 'cyber' 134 times in 45 minutes. Given that there are only three years left of Osborne's original spending timeline, and the current government has made little by way of firm strategic commitments, it's worrying to say the least.

Show us the strategy

Forget 'world leader'; Parliament's Public Accounts Committee chair, Meg Hillier, said that Britain is ranked below Brazil, China and South Africa when it comes to securing smartphones and laptops. This is hardly surprising when the committee report says the government has "little oversight of the costs and performance of government information assurance projects and processes".

The big picture, the strategic problem, is that the government effectively does not have a consistent approach to security breaches and so is unable to make informed decisions when it comes to prioritising resources both financial and hands-on.

Addressing the skills shortage is a start

All that said, there are some promising moves coming from the government. These include initiatives such as GCHQ's CyberFirst programme, which offers the best graduates financial support through bursaries and employment placements which can help them get the hands-on experience needed to properly skill the UK cybersecurity sector.

Beyond that and the opening of the NCSC, the National Cyber Security Strategy (NCSS) seems to be treading water somewhat. It's asked security companies, two years on, to put forward ideas as to how the UK can become cyber secure. It's asking for submissions on such things as what threats we face (yes, seriously) and how the government can combat them (ditto).

Looking for leadership

Should we be that surprised at this apparent discordant response to the cybersecurity threat? If you look to the average enterprise and how cybersecurity is rarely a strategic, business process-led, boardroom level discussion, then the answer is: well no, not really.

That so many C-suite directors do not understand the threats they face when it comes to cyber attack, let alone how to approach defending the organisation, now is the time for the government to grasp the nettle and show some leadership. There are three years of the five-year strategy left, and time is fast running out for the UK government to finally decide what that strategy actually is...

Advertisement
Advertisement - Article continues below

Picture: Bigstock

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/government-it-strategy/28305/ir35-news
Policy & legislation

Businesses urged to continue IR35 preparations despite Conservative review pledge

3 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/careers/28219/it-manager-job-description-what-does-an-it-manager-do
Careers & training

IT manager job description: What does an IT manager do?

28 Oct 2019
Visit/strategy/28223/cio-job-description-what-does-a-cio-do
Business strategy

CIO job description: What does a CIO do?

1 Oct 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/operating-systems/microsoft-windows/354297/this-exploit-could-give-users-free-windows-7-updates
Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019