Government’s cyber plan delivers ‘a complete revolution in how we provide assurance’

The recently published Government Cyber Security Strategy set out a range of ambitions to make the public sector safer. PublicTechnology gathered a panel of experts to find out more about how it will do so.

Credit: Pete Linforth/Pixabay

“We had just published an Integrated review that set out Britain’s stall to be a cyber power, so we were keen to emphasise that you cannot be viewed in that way on the world stage unless your public sector is resilient, and you are leading from the front.”

This was the background against which the Government Cyber Security Strategy was published earlier this year, according to David Lovell, cyber strategy and policy lead at the Cabinet Office’s Government Security Group.

The strategy set out the ambition that the public sector’s defences should be “significantly hardened” to cyberthreats by 2025, on the way to becoming fully “resilient to known vulnerabilities and attack methods” by the end of the decade.

There are two main strand to the plan to achieve this target, Lovell says. 

The first is a change in government’s approach to managing risk, including the introduction of Gov Assure – a new regime through which government entities will undergo independent audits of their cyber resilience.

“There is a tendency to say ‘legacy is bad, and we must eliminate it’. That is not a tenable position. We need to be clear that you can manage and mitigate legacy – as you would with all risk, including cyber risk. In the past we may have been guilty of having a bit of a maximalist approach.”
David Lovell, Cabinet Office

Supported by the National Cyber Security Centre, the “scale and common language” created by Gov Assure can deliver a complete a “complete revolution in how we provide assurance”, the strategy lead adds, during a recent webinar discussion hosted by PublicTechnology and Egress.

This universality will support the ambitious central tenet of the cyber plan: that the public sector should ‘defend as one’. This will be achieved by close coordination between agencies, including the sharing of information on vulnerabilities and threats.

Jack Chapman, vice president of threat intelligence at Egress, says that the current landscape facing public bodies remains dominated by familiar foes, including phishing, ransomware, and malware.

“The key thing that is changing in the threat landscape is the sophistication and automation of these attacks,” he says. “Especially through the rise of crime as a service, where attackers are collaborating like never before. You can go out and purchase pre-defined technical kits that reduce the barrier of entry for attackers. This worrying evolution what is really driving concerns from a defensive side.”

The Government Cyber Security Strategy will help public-sector entities take a “much more targeted” approach to understanding – and managing – the cyber risk created by this landscape, according to Lovell. 

Chapman agrees that organisations should take a focused approach, beginning with the identification of the people, platforms, or products that are most valuable.

“You need a culture of understanding key assets, and understanding the routes in [to those for attackers],” he says. “And, from there, you can start drawing it out: where do I need to invest in order to protect first and foremost? And then having a layered approach – including people, process, and technology – for every avenue into an organisation.”

Lasting legacy
The ongoing prevalence of legacy IT systems is something that is often picked out as a major endemic cyber risk for government. Lovell recognises the issue as a significant challenge that agrees needs to be tackled.

“But legacy technology shows that you cannot treat cybersecurity as discrete from broader DDaT challenges – and, indeed, broader business challenges. Security, and tech in general, is just another enabler for business,” he says. So, when modernise technology, you not only get the security benefits – you get the greater benefit… in efficiencies, and  inthe better outputs you get in, ultimately, delivering your business objectives.”

He adds: “There is a tendency to say ‘legacy is bad, and we must eliminate it’. That is not a tenable position. We need to be clear that you can manage and mitigate legacy – as you would with all risk, including cyber risk. In the past we may have been guilty of having a bit of a maximalist approach to legacy: which can be useful in making the argument. But, that said, we need to treat legacy as a component part of risk and manage it accordingly.”

Alongside legacy, the other big challenge facing those in charge of delivering the cyber strategy is the need for cyber skills across government. This can partly be met by looking to recruit from a broader talent pool, Lovell says, including more neurodiverse candidates, as well as people from other professional backgrounds or those arriving in the cyber world at a later stage of their career.

“The key thing that is changing in the threat landscape is the sophistication and automation of these attacks. Especially through the rise of crime as a service, where attackers are collaborating like never before.”
Jack Chapman, Egress

Steven Furnell, professor of cybersecurity at the University of Nottinham’s School of Computer Science, says that cyber skills are a big challenge for many UK organisations across both the public and private sectors.

It is also crucial that those outside cyber-specialised functions are aware of security issues and the role their implications, he adds/

“It starts at the top: you need to make sure that cybersecurity and risk is recognised from the very top of the organisation, and promoted from that level,” Furnell says. “You have then got to ensure that things are underpinned in a way that means staff can appreciate and understand how it relates to them. Having a policy is a good starting point – but that, in itself, is not going to be sufficient. You have got to accompany that, initially, with an appropriate level of awareness-raising, [addressing for staff]: ‘what is it? What is my role in it? What do I need to do about it and in what context?’

“But even that raising of awareness does not tell someone how they are supposed to do it. You then have to take that further, and go from awareness through to training and education, and engaging with the staff… this step seems to be slightly under-represented in terms of what organisations are doing in practice.”

Register here for free to watch the full webinar discussion, including lots more insights on the aims of the Government Cyber Security Strategy and the plan to realise them over the coming years

 

Sam Trendall

Learn More →

66 thoughts on “Government’s cyber plan delivers ‘a complete revolution in how we provide assurance’

  1. 신림동콜걸출장섹스마사지 December 9, 2024 at 5:18 am

    대전호박나이트

  2. 섹스노리야동코리아 January 17, 2025 at 1:11 am

    https://dday.tistory.com/468

  3. Jorgedak January 22, 2025 at 8:44 am

    Mexican Easy Pharm: Mexican Easy Pharm – Mexican Easy Pharm

  4. Rodneyicems January 23, 2025 at 3:26 pm

    mexican pharmaceuticals online https://mexicaneasypharm.com/# Mexican Easy Pharm
    п»їbest mexican online pharmacies

  5. Albertruith January 24, 2025 at 3:43 pm

    https://predpharm.shop/# mail order prednisone
    prednisone nz

  6. Albertruith January 24, 2025 at 8:46 pm

    https://predpharm.shop/# 5 mg prednisone daily
    prednisone medication

  7. Albertruith January 25, 2025 at 1:56 am

    https://dappharm.com/# buy priligy
    prednisone brand name in usa

  8. Albertruith January 25, 2025 at 9:07 am

    https://dappharm.shop/# dapoxetine price
    medicine prednisone 10mg

  9. Albertruith January 25, 2025 at 5:08 pm

    http://dappharm.com/# priligy
    buy prednisone no prescription

  10. Albertruith January 26, 2025 at 1:15 am

    https://predpharm.com/# PredPharm
    prednisone pills for sale

  11. Albertruith January 26, 2025 at 8:51 am

    http://predpharm.com/# purchase prednisone canada
    buy prednisone online from canada

  12. Albertruith January 26, 2025 at 4:13 pm

    https://cytpharm.com/# Cyt Pharm
    buy prednisone without a prescription

  13. Albertruith January 26, 2025 at 11:39 pm

    https://predpharm.com/# PredPharm
    400 mg prednisone

  14. Albertruith January 27, 2025 at 6:30 am

    https://kamapharm.com/# Kama Pharm
    generic prednisone otc

  15. Albertruith January 27, 2025 at 1:53 pm

    https://cytpharm.com/# buy cytotec
    buy prednisone 10mg

  16. Albertruith January 27, 2025 at 7:27 pm

    https://predpharm.shop/# Pred Pharm
    prednisone cream brand name

  17. Albertruith January 28, 2025 at 12:47 am

    https://kamapharm.com/# Kama Pharm
    50 mg prednisone canada pharmacy

  18. MichaelVon January 28, 2025 at 9:53 am

    https://farmaprodotti.com/# farmacie online affidabili
    acquistare farmaci senza ricetta

  19. MichaelVon January 28, 2025 at 2:44 pm

    https://farmabrufen.com/# Ibuprofene 600 prezzo senza ricetta
    farmacia online senza ricetta

  20. MichaelVon January 28, 2025 at 7:35 pm

    https://farmasilditaly.shop/# viagra acquisto in contrassegno in italia
    Farmacie online sicure

  21. MichaelVon January 29, 2025 at 12:20 am

    https://farmaprodotti.shop/# comprare farmaci online con ricetta
    farmacia online piГ№ conveniente

  22. MichaelVon January 29, 2025 at 4:56 am

    https://farmasilditaly.shop/# kamagra senza ricetta in farmacia
    comprare farmaci online all’estero

  23. Edwardvep January 31, 2025 at 3:37 am

    acquistare farmaci senza ricetta: Farma Prodotti – migliori farmacie online 2024

  24. Patrickbeisa January 31, 2025 at 8:23 am

    Las experiencias son Гєnicas en cada visita.: jugabet – jugabet

  25. Josephbycle January 31, 2025 at 9:00 am

    taya777 taya777 Promotions are advertised through social media channels.

  26. 섹스노리야동코리아 January 31, 2025 at 10:07 am

    https://tiptravel.tistory.com/32

  27. LannyRinly January 31, 2025 at 10:37 am

    Hay reglas especГ­ficas para cada juego.: jugabet – jugabet casino

  28. 섹스노리야동코리아 January 31, 2025 at 10:39 am

    https://bestkkultip.tistory.com/11

  29. Patrickbeisa January 31, 2025 at 1:25 pm

    Responsible gaming initiatives are promoted actively.: taya365 – taya365

  30. LannyRinly January 31, 2025 at 3:30 pm

    Los bonos de bienvenida son generosos.: jugabet.xyz – jugabet casino

  31. Josephbycle January 31, 2025 at 5:32 pm

    jugabet casino jugabet casino Las apuestas deportivas tambiГ©n son populares.

  32. Patrickbeisa January 31, 2025 at 6:19 pm

    La mayorГ­a acepta monedas locales y extranjeras.: winchile casino – winchile casino

  33. Daviddof January 31, 2025 at 8:00 pm

    http://winchile.pro/# La Г©tica del juego es esencial.
    Many casinos have beautiful ocean views.

  34. LannyRinly January 31, 2025 at 8:23 pm

    Slot machines feature various exciting themes.: taya365.art – taya365 com login

  35. WilliamTraix January 31, 2025 at 11:01 pm

    The poker community is very active here. http://phtaya.tech/# Players enjoy a variety of table games.

  36. Patrickbeisa January 31, 2025 at 11:03 pm

    Slot tournaments create friendly competitions among players.: taya777 – taya777 login

  37. LannyRinly February 1, 2025 at 12:57 am

    Many casinos have beautiful ocean views.: phtaya login – phtaya

  38. Josephbycle February 1, 2025 at 1:43 am

    phtaya casino phtaya The ambiance is designed to excite players.

  39. Patrickbeisa February 1, 2025 at 3:42 am

    Live music events often accompany gaming nights.: taya777 register login – taya777 register login

  40. LannyRinly February 1, 2025 at 5:34 am

    Promotions are advertised through social media channels.: phmacao casino – phmacao casino

  41. Patrickbeisa February 1, 2025 at 8:23 am

    Los croupiers son amables y profesionales.: jugabet casino – jugabet

  42. Josephbycle February 1, 2025 at 9:47 am

    jugabet jugabet Los jugadores disfrutan del pГіker en lГ­nea.

  43. LannyRinly February 1, 2025 at 10:12 am

    Live music events often accompany gaming nights.: taya777.icu – taya777.icu

  44. Patrickbeisa February 1, 2025 at 1:09 pm

    Online gaming is also growing in popularity.: phmacao casino – phmacao com

  45. LannyRinly February 1, 2025 at 2:55 pm

    Many casinos have beautiful ocean views.: phmacao com – phmacao club

  46. Josephbycle February 1, 2025 at 5:53 pm

    jugabet jugabet.xyz Hay casinos en Santiago y ViГ±a del Mar.

  47. Patrickbeisa February 1, 2025 at 5:56 pm

    La pasiГіn por el juego une a personas.: winchile – win chile

  48. LannyRinly February 1, 2025 at 7:41 pm

    The casino experience is memorable and unique.: taya777.icu – taya777 app

  49. Patrickbeisa February 1, 2025 at 10:45 pm

    The Philippines has several world-class integrated resorts.: phmacao com login – phmacao.life

  50. LannyRinly February 2, 2025 at 12:30 am

    The casino scene is constantly evolving.: taya365.art – taya365

  51. Josephbycle February 2, 2025 at 2:01 am

    winchile winchile casino La Г©tica del juego es esencial.

  52. Patrickbeisa February 2, 2025 at 3:50 am

    Gaming regulations are overseen by PAGCOR.: taya777 – taya777

  53. LannyRinly February 2, 2025 at 5:44 am

    Resorts provide both gaming and relaxation options.: phmacao com login – phmacao casino

  54. Patrickbeisa February 2, 2025 at 9:21 am

    Live music events often accompany gaming nights.: phmacao com login – phmacao casino

  55. LannyRinly February 2, 2025 at 10:41 am

    Muchos casinos tienen salas de bingo.: jugabet – jugabet.xyz

  56. Josephbycle February 2, 2025 at 12:23 pm

    win chile winchile La competencia entre casinos beneficia a los jugadores.

  57. Daviddof February 2, 2025 at 1:56 pm

    https://phtaya.tech/# The Philippines offers a rich gaming culture.
    The thrill of winning keeps players engaged.

  58. 섹스노리야동코리아 February 2, 2025 at 2:14 pm

    양산시술출장마사지

  59. Patrickbeisa February 2, 2025 at 2:41 pm

    Slot machines attract players with big jackpots.: taya365 com login – taya365 login

  60. LannyRinly February 2, 2025 at 3:34 pm

    п»їCasinos in the Philippines are highly popular.: phtaya login – phtaya casino

  61. Patrickbeisa February 2, 2025 at 7:59 pm

    Los casinos reciben turistas de todo el mundo.: jugabet.xyz – jugabet chile

  62. LannyRinly February 2, 2025 at 8:32 pm

    Los jugadores pueden disfrutar desde casa.: jugabet – jugabet

  63. Patrickbeisa February 3, 2025 at 1:27 am

    Gambling can be a social activity here.: phmacao – phmacao casino

  64. LannyRinly February 3, 2025 at 1:33 am

    A variety of gaming options cater to everyone.: phmacao club – phmacao com login

Leave a Reply