Policymakers join forces through an All-Party Parliamentary Group to propel the UK’s Cyber innovation

Aims to bridge the gap between policymakers and industry, stimulate collaboration across sectors

The Cybersecurity Business Network (CBN), a UK coalition of cybersecurity organisations looking to support and promote the cyber sector, announces its role as the Secretariat for the newly launched Cyber Innovation All-Party Parliamentary Group (APPG). The APPG will aim to break down complex cyber issues for policymakers, bringing together parliamentarians, industry leaders, academia and civil society to spark fresh ideas and drive innovation. 

The APPG is chaired by Dan Aldridge MP, with officers from all three major political parties: Liberal Democrat MP Max Wilkinson, Labour MP Sarah Edwards, and Conservative MP John Glen. Aldridge said, “The UK’s global cyber leadership position needs Parliamentarians to intentionally and meaningfully take an interest in its future, and we will do just that. This will be a different type of APPG – we will engage with the UK’s highly innovative cyber sector and look at how we as a Parliamentary community can support and grow the cyber ecosystem in the national interest.”

As the Secretariat, CBN will support the Group through an active events programme, and provide insights for Parliamentary members in order to foster a productive dialogue with industry and third-sector stakeholders around topics such as supporting the UK cyber ecosystem to grow, and ensuring Parliament and experts work together to make upcoming cyber legislation fit for an increasingly digital world.

Andrew Kernahan, Strategic Advisor at CBN said, “We are excited to serve as the Secretariat for the Cyber Innovation APPG, which will play a vital role in bringing together diverse perspectives from across the cyber ecosystem with Parliamentarians and policymakers. We believe the APPG will champion the UK’s thriving cyber ecosystem and its critical role in enabling modern society and driving economic growth.”

About Cybersecurity Business Network

Rebranded in 2024, Cybersecurity Business Network  aims to bridge the gap between government initiatives and private sector innovation. CBN provides a collective voice for our members, enabling them to engage with key stakeholders, shape national government policy, network with peers across the sector and cultivate new trade opportunities. Its  members represent a diverse range of companies which are invested in improving resilience, innovation and enabling economic growth. 

For more information, please visit our website – https://cb-network.org/

For more information on the Cyber Innovation APPG, please visit the website – https://cb-network.org/appg-for-cyber-innovation/

Media contact

For any media queries, please contact secretariat@cb-network.org

Enhancing communication between security and business leaders

Author: Marco Bresciani, Cyber Risk Enthusiast – CBN Board Member

Security leaders experience a continual trade-off between what they want to achieve and the resources that the organisation is willing to give them, be it funding, tools, suppliers, or people. At the same time, their executives need to quantify the financial loss that the organisation will incur if that specific risk happens.

This is not trivial: Gartner at the London 2024 event pointed out the need to “mind the gap” when reporting cybersecurity to management, providing different stakeholders with information they can act upon. 

As someone who has worked in the cybersecurity industry since 1996, I have worked with banks and other regulated industries across EMEA, and realised many leaders avoid risk quantification due to misconceptions about data needs and complexity. 

In this article I will highlight why cyber risk quantification (CRQ) serves as a vital purpose for security leaders, fostering better discussions with executives. Also, I will explain how organisations can achieve significant improvements in decision-making and risk prioritisation by debunking the myths on data complexity.

It’s not quantify vs qualify

CRQ  has been the trusted method for actively communicating cyber exposure in an objective, well-grounded, and defensible manner for several years. It can be delivered in different ways. Most CRQ frameworks are based on the Value-at-Risk approach, developed in the Finance industry to measure the potential loss of investment portfolios.

A popular choice is the Open FAIR framework, an international, non-proprietary standard whose open nature and wealth of supporting documents helped increase its adoption by practitioners and consultants.

It’s important to remark that CRQ is not a replacement for a company’s risk management framework. The identification, analysis, evaluation, and treatment of risks are conducted as usual.

CRQ complements the qualitative output of common frameworks like COBIT or risk controls like ISO27000, by providing the “so what”, a means to compare losses deriving from risk scenarios, and the costs/benefits of mitigating actions.

The lessons learned from early adopters

Many organisations have tested CRQ in the past 5-8 years, often obtaining mixed results that made them question if introducing it in their risk management process was worth the effort. However, executives agree that when done right CRQ can foster confidence in security programs, by enabling informed decisions on cyber risk investments.

The initial stage of CRQ adoption highlighted some practical and some inherent problems:

Operationalising CRQ, even with a rigorous, well-structured, well-documented framework like FAIR, can be a real challenge. 

How could we keep a CRQ initiative on the right path? The  experience of early adopters suggest the following:

Conclusion

After the initial enthusiasm about a fresh new method and the sobering experience of delivering it, CRQ is maturing into a solid foundation to inform executive decisions about cyber risk.

More in general, CRQ is becoming an element of a broader data-driven approach to cyber risk management, where risk exposure is measured in quasi real-time, from within the organisation, across the third parties, and from the external threats.

Does it look too difficult? Remember that Lloyds made the first aviation insurance in 1911, when the “flying machine” industry was just 8 years old. Not much historical data was available to inform the decision, and possibly not many success stories too… Where there’s a will, there’s a way!

CBN Newsletter | November 2024

Our monthly update to bring you the relevant, high-level policy and business news from across the cyber sector. 

This month, we provide an update on two significant announcements from the UK government, an insights piece from out CBN comms lead, and our usual policy and business news. 

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch. 

never miss a thing

Sign up for news and upcoming events

Headline News

UK political update: the Budget and a “modern” Industrial Strategy
On Wednesday, 30th October, Chancellor Rachel Reeves presented the new Labour Government’s first annual Budget. With a reportedly dismal economic outlook yet a manifesto promise to bring growth, the Chancellor changed borrowing rules and increased the overall tax burden on the country by £40bn in order to increase investment in key sectors and public services. 

Skirting around controversy of whether Labour broke its election manifesto commitment, the Chancellor continued the Government’s messaging of boosting growth and productivity and utilising innovative tech – especially in health, energy, defence and digital.

Notably, the Strategic Defence Review (SDR) was mentioned, in which the Government is considering cyber and digital “as a next step” as they develop their plans in this area. Other than defence, cyber was only mentioned in terms of improving the security of the NHS. 

Ahead of the Budget, the Government had launched its “modern” Industrial Strategy and associated consultation, aiming to streamline funding into eight key sectors – manufacturing; clean energy; creative industries; defence; digital and technologies; financial services; life sciences; and professional and business service – in an aim to address challenges via a “cross-cutting” and “pro-business” approach. 

While cyber is not mentioned in the Industrial Strategy, the consultation nonetheless plans to “focus on a range of technologies and their commercialisation, with a portfolio approach that backs smaller, less proven, and more disruptive businesses alongside larger, well-established businesses in existing sectors” under the context of investing in digital technologies, which presents a key opportunity for the sector to engage and raise its profile within government. 

If you have any questions about what these updates mean for the cyber sector or your business, please get in contact with us at secretariat@cb-network.org.  


Enhancing supply chain cybersecurity: positive storytelling and clear communication

Recent disruptions caused by global IT outages have shed light on how a lack of IT supply chain diversification fundamentally undermines resilience by concentrating risk. Over the last few months, many organisations have been considering the makeup of their supply chains, and the strength of their incident management and response plans, accordingly.

In a key insights articleCBN Communications Lead, Liva Emmatty, outlines the communication challenges faced by cybersecurity leaders and organisations in this context, and the value that powerful storytelling and clear communications can bring to cyber firms looking to boost reputations when trust is low.

If you have questions about how you can better communicate your services to customers or wish to speak to government about future solutions, please get in touch with the CBN team.

Read the article here


Political and policy updates

Building partnerships to protect the UK from cyber crime
In a speech to the PREDICT 2024 Conference, Home Office Security Minister Dan Jarvis said that “cyber security is national security” and highlighted how national security is the “foundation” for the Government to achieve its five missions. 

He went on to say that the Government is considering reviewing the Computer Misuse Act (CMA), and in light of the spending review are reviewing several policy areas to enable and enhance security. 

Five Eyes launch shared security advice campaign for tech startups
Cybersecurity guidance designed for technology companies, Secure Innovation, has been launched across Five Eyes nations, in an effort to protect the sector from national security threats, particularly originating from other nation states. 

Originally a UK-only initiative from the National Cyber Security Centre (a part of GCHQ) and National Protective Security Authority (NPSA), tailored guidance is now available in Australia, Canada, New Zealand, the UK and the US. 

The guidance helps companies to create a cost-effective, bespoke action plan which supports them to assess their levels of secure innovation and identify any necessary actions they need to take to protect their business. 

G7 Cyber Expert Group recommends action to combat cyber risks from quantum
The G7 Cyber Expert Group (CEG) – chaired by the U.S. Department of the Treasury and the Bank of England – has recommended organisations have regard for the initial set of quantum-resilient encryption standards was released by the National Institute of Standards and Technology (NIST) and work to build resilience, particularly for sectors which hold highly sensitive information, such as the financial sector.

Cyber Essentials 10 years on
In a speech at the 10 year anniversary event for the Cyber Essentials scheme, DSIT’s Cyber Minister Feryal Clark highlighted the impact of Cyber Essentials for UK businesses, which are detailed in a new impact evaluation.

Further, she announced a new joint statement from DSIT, the NCSC, and the UK’s largest banks and building societies which aims to raise the levels of cyber security in critical national supply chains by exploring ways to expand the role of Cyber Essentials within their supplier assurance processes. 

NCSC updates


Business and industry

Businesses struggle to manage supply chain cyber risk
Businesses are facing a growing challenge in managing supply chain cyber risks, according to a new report from cyber defence company Blue Voyant, in their fifth annual State of Supply Chain Defense report. 

Despite 95% experiencing incidents in the last year, over half don’t regularly assess vendors for cybersecurity issues, and a third have no way of knowing when an incident occurs. This largely stems from  a lack of resources and expertise, even though budgets for third-party cyber-risk management have increased.

Further, prioritisation of third-party cybersecurity risk management has decreased; key challenges include understanding how to penalise non-compliant vendors, meeting regulatory requirements, and ensuring compliance. On the other hand, UK businesses are more proactive than their global counterparts in briefing senior management on these risks, indicating an awareness of the issue at the highest levels. 

If you want to learn more about supply chain cybersecurity resilience, check out CBN’s recent webinar for more insights from cyber leaders. 

Bridging the gaps to cyber resilience
Significant gaps exist between perceptions of cyber resilience among top security executives and C-suite leadership, according to the 2025 Global Digital Trust Insights report from PwC. 

Based on a survey of more than 4,000 business and technology executives across 77 countries, over two-thirds of technology leaders see cybersecurity as their top risk for mitigation – compared with less than half of business leaders. Despite this, CISOs are less likely to be involved in strategic planning, leading to a gap between CISOs and top C-suite executives over the company’s ability to comply with regulations, particularly those involving AI and critical infrastructure.

The report goes on to recommend that, in order to better communicate the need for cyber resilience, CISOs “share tech-enabled insights” and explain cyber priorities in business terms (cost, opportunity, risk).

Global threat report indicates increase in CNI cyberattacks
Cyber attacks on key critical national infrastructure (CNI) and supply chains continue to increase across the globe, according to data in Blackberry’s Q2 Global Threat Intelligence report. 

Notably, the period of April – June 2024 was “one of the highest” quarterly percentage increases in unique malware samples per day since their reporting began. The United States received the highest number of attempted attacks, followed by Japan, South Korea, Australia and Canada.The report does not go into detail on why these countries have received the most attacks, and although mentioning that the attacks came from both state and non-state actors, did not clarify further. 

While organisations are implementing measures like data encryption, fewer than half verify their suppliers’ cybersecurity compliance. The report stresses the urgent need for improved visibility and monitoring of software supply chains to reduce vulnerabilities.

To note, this report is based only on data collected by Blackberry in its internal systems.   


About CBN

Our new mission is to bring together cybersecurity companies to network, learn and debate across three key pillars — trade and export, policy, and market insights. Our members will be enabled to promote their cybersecurity expertise and capabilities, strategically engage with key stakeholders and develop lasting relationships in key verticals, in a wider effort to influence government policy and promote innovation in the sector. 

The strategic direction of CBN is shaped by our Membership who benefit from increased brand exposure and engagement opportunities with key stakeholders in the cyber space, other key sector verticals, media, government and regulators.

Membership to CBN is free for all cybersecurity organisations. If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.


Founded by Clarity

Global digital marketing and communications agency, providing fearless marketing and consultancy to the world’s most progressive companies.

We match data-driven science with human ingenuity to expand our full-funnel, specialist services and expertise. Our vision is to accelerate positive change and impact across the world. A firm believer of cybersecurity as an enabler of growth and resilience, we are proud to driving its prosperous impact forward. Get in touch with secretariat@cb-network.org to understand more on how Clarity can enhance reputation, create impact, and drive growth in your organisations.


Key insights from the Supply Chain Resilience Webinar 

The Cybersecurity Business Network (CBN) was delighted to host a webinar on supply chain resilience. Developed in response to the recent global IT outage, which exposed how reliance on only a few key suppliers can weaken critical systems, the webinar explored how businesses and policymakers can address the growing issue of how a lack of diversification in IT supply chains can increase the risk of major outages. The webinar brought together experts from cybersecurity, healthcare and academia to discuss ways to strengthen supply chain resilience and manage these risks. Below are some key takeaways from the event. 

Dr. Melanie Garson, Cyber and Tech Geopolitics Lead at the Tony Blair Institute, opened the discussion by examining the global geopolitical landscape’s impact on supply chains. She emphasised the rising uncertainty and the interconnectedness of these risks, describing the current state as “a geopolitical state of upheaval.” According to Garson, the world’s IT supply chains are more vulnerable than ever due to increased global tensions and organisations must better anticipate the disruptions arising from cyberattacks and broader geopolitical events.

Simon Newman, Director of the Cyber Resilience Centre for London, reinforced this perspective by highlighting how attackers are now focusing on smaller, more vulnerable entities in supply chains. Newman also stressed the importance of enhanced collaboration across sectors, including law enforcement, to address these increasing vulnerabilities.

“As larger organisations have boosted their cybersecurity significantly, criminals are now targeting weaker entry points”, he explained, noting that smaller organisations often lack the resources to defend themselves effectively.

Simon Newman, Director of the Cyber Resilience Centre for London,

The healthcare sector’s supply chain vulnerabilities were a particular focus, with Rachel Dean, Head of Cybersecurity at NHS Supply Chain, providing insights. Dean emphasised that a successful cyberattack on the NHS’s supply chain could directly affect patient care.

“A successful cyberattack and the resulting inability to deliver operations impacts directly on the NHS’s ability to deliver patient care, which can have critical outcomes,” she warned.

Rachel Dean, Head of Cybersecurity at NHS Supply Chain

With a supply chain of over 6,000 suppliers, Dean explained the significant challenges in ensuring that each supplier meets necessary cybersecurity standards while avoiding creating barriers for smaller, critical suppliers.

On the regulatory side, Tim Rawlins, Director and Senior Advisor at NCC Group, discussed how regulations are evolving to address supply chain vulnerabilities.

“Regulators are increasingly focusing on requiring organisations to escrow software from their suppliers to reduce risk.”

Tim Rawlins, Director and Senior Advisor at NCC Group

While regulation is a key driver of improvement, Rawlins stressed that organisations themselves must take proactive steps to manage third-party risks and understand how disruptions in one part of the supply chain can have wide-reaching consequences.

Building Resilience: How UK Cybersecurity Organisations Can Bolster IT Supply Chains

Watch the Cybersecurity Business Network (CBN)’s webinar on ‘Building Resilience: How UK Cybersecurity Organisations Can Bolster IT Supply Chains’.

The recent global outage – followed by a DDoS cyber attack on Microsoft Azure highlighted a major issue with contemporary IT supply chains: the lack of diversification and a concentration of risk undermining the resilience of critical IT systems.

The discussion explored:

– Factors that led to the recent disruption and outage – Inherent risks of failing to diversify a security supply chain – How organisations can better manage their supply chains to improve resilience
– How the healthcare and telecom sectors have been managing their supply chain
– Role that UK cybersecurity organisations could play in improving resilience and mitigating risks
– Support needed by the UK cybersecurity sector from government to capitalise on the role it can have in delivering resilience

Speakers include:
– Andrew Kernahan, Strategic Advisor, Cybersecurity Business Network.
– Tim Rawlins, Director & Senior Adviser at NCC Group
– Simon Newman, Director at Cyber Resilience Centre London
– Dr Melanie Garson, Technology & Cyber Geopolitics Lead at Tony Blair Institute
– Rachel Dean, Head of Cyber Security at NHS Supply Chain

CBN Newsletter – August 2024

Our monthly update to bring you the relevant, high-level policy and business news from across the cyber sector. 

This month, we provide an update on the new Labour government’s priorities, and highlight what the CrowdStrike incident could mean for cyber businesses.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch. 

never miss a thing

Sign up for news and upcoming events

Headline news

New government sets out priorities
The Labour Party swept into power on 5th July, winning a near-historic 411* seats, while the Conservative share collapsed for its worst-ever result. Over the past weeks, Keir Starmer’s government has wasted no time in setting a new tone for the country; however, while the cyber sector has largely welcomed the new government’s focus on cyber security national resilience, its impact is largely yet to be felt as Parliament breaks for recess, returning 2nd September. 

King’s Speech: legislative priorities 
In July, King Charles addressed the nation during the State Opening of Parliament, to set out the Government’s policy priorities and legislative programme for the coming year. In line with previous promises, Prime Minister Keir Starmer placed a primary focus on driving economic growth.

With 40 new(ish) bills, it is an ambitious programme which promises to “take the brakes off” the economy and reaffirm financial stability. Measures include boosting construction, reforming energy production, re-nationalising the railways, developing UK skills, and increasing and improving the use of data and digital technologies in the economy.

Chancellor’s financial statement
On 29th July, Chancellor Rachel Reeves declared a £22bn “hole” in the country’s finances. Although disputed by former Chancellor Jeremy Hunt, Reeves has been backed up by the Office for Budget Responsibility (OBR), which has formally launched a review of the Spring Budget forecasts. 

Reeves then announced a number of areas where the government intends to save money – including selling off “surplus” government property, a reduction in the use of external consultants in Whitehall and a pause on certain infrastructure projects. Tax rises are now expected in the October 30th Budget, alongside the outcome of a formal spending review for 2025-2026. 

A cyber lens
Notably, a Cyber Security and Resilience (CS&R) Bill will be introduced to ensure the security of critical infrastructure and digital services, building on Security of Network & Information Systems Regulations (NIS Regulations) 2018. DSIT Minister Feryal Clark also recently said that the CS&R Bill will be designed to strengthen the UK’s defences and ensure the services – private and public – that companies rely on are protected.

Further, Science, Innovation and Technology Secretary Peter Kyle said that national resilience – particularly in relation to cyber security – “suffered terribly” under the Conservatives due to division within the party. He claimed that he only became aware of the significance of the threat upon taking office, but concern led him to “put forward a request” for the new CS&R Bill, which had “national security priority”. 

Separately, the Government has launched a “root and branch” Strategic Defence Review which, led by three external experts, will consider the threats Britain faces, the capabilities (including digital and cyber) needed to meet them, the state of UK armed forces and the resources available. The Review is expected to be delivered “at pace”, with submissions invited until the end of September and the report delivered in the first half of 2025.

*Now 404 following the temporary suspension of seven MPs

If you have any questions about what the election and policy developments means for the cyber sector or your business, please get in contact with us at secretariat@cb-network.org.  

How resilient is our global IT infrastructure? 

On Friday, 19th July, 8.5 million Microsoft Windows computers around the world crashed, causing chaos and disruption for businesses and services including airlines, banks and hospitals.

While cyber security firm Crowdstrike quickly confirmed the outage was caused by a defective software update for its Windows hosts and worked to resolve the issue, the incident nonetheless called attention to the precariousness of IT infrastructure – and what could happen if an attack was carried out by malicious actors, as was then seen last week with the Microsoft Azure DDoS attack and subsequent software failure.

Businesses across the world are now asking themselves two questions – firstly, their place within the global supply chain and the strength of their incident management and response plans, as highlighted by the NCSC. And secondly – how can they prevent future incidents from affecting them?

Although some companies may look to bring their IT security functions in-house, this is not an option for all organisations, who may start seeking to diversify their software and other security application suppliers.

In light of the government’s upcoming CS&R Bill, the sector will be watching closely for strategic direction from officials on how they will look to improve resilience and “insulate” society and the economy from future attacks.

At the same time, the cyber sector as a whole has the responsibility and opportunity to not only highlight the importance of having a robust cyber resilience programme, but also to ask questions about the concentration of risk – given 62% of the global external attack surface is covered by 15 companies – and the long-term viability of this landscape. 

In light of this, keep an eye out for an upcoming CBN webinar which will bring together policymakers and key supply chain sector leaders to provide insights for members on what this means for the sector, and how we can make improvements going forward. 

If you have questions about how you can better communicate your services to customers or wish to speak to government about future solutions, please get in touch with the CBN team at secretariat@cb-network.org

News & Updates

Policy and political

Government extends call for views on the Cyber Security of AI
Originally published in May, before the General Election, the closing date for the government’s call for views on the Cyber Security of AI has been extended to this Friday, 9th August. 

The call for views sets out specific interventions to help secure AI, so that the benefits of AI can be realised, and asks for input as to whether industry would support the gov creating a global standard for AI cyber security. To note, a “call for views” is often an initial information-gathering exercise which will go on to determine formal proposals and policy.

If you have any questions about responding to this or other a government consultations, please get in touch with the CBN team. 

G7 countries to establish operational tech cybersecurity framework
In a statement following a summit in Italy, the Group of Seven (G7) countries acknowledged the rising cyber threat to critical infrastructure, particularly energy, and agreed to “explore avenues towards establishing mutual recognition of schemes for reliable cyber-safe products.” 

The potential collective framework would apply to both manufacturers and operators, as the statement signals an intention to incentivise tech companies to build more secure Internet of Things (IoT) products. This move was in conjunction with the United States’ recent Supply Chain Cybersecurity Principles, as indicated by a statement from the White House national security advisor. 

UK statement at the UN Security Council
UK Permanent Representative to the UN, Ambassador Barbara Woodward, gave a statement at the UN Security Council regarding the importance of addressing cyber threats to protecting global security. She highlighted four “trends” – the prevalence of ransomware, expansion of artificial intelligence, malicious activities on the global stage, and the risk of disinformation – going on to indicate the UK’s work in this area.

NCSC updates

Business and industry

ICO officially “reprimands” Electoral Commission
The Electoral Commission, which oversees UK elections, has been formally reprimanded by the Information Commissioner’s Office (ICO) over the security lapse which left millions of UK voters’ personal details “vulnerable to hackers”.

Following the 2021 breach, hackers had access to the Electoral Register for just over a year, until they were detected and “booted out” in 2022. The ICO’s investigation found the Electoral Commission did not have appropriate security measures – including secure passwords and up-to-date patches – in place to protect the personal information it held, which led to the breach.

UK faces significant cyber funding and skills gap
A new report, Underfunded and Under Reported: Threats, Breaches, and Budgets, reveals the CISOs face significant problems from a lack of funding, exacerbated by a lack of talent, tools, and time. Notably, 83% of respondents feel their organisation has a gap in its cyber skills, yet they struggle to access adequate talent. 

NCA leads international operation to crack down on unlicensed pen testing 
The National Crime Agency (NCA) worked with international partners to coordinate global action against unlicensed versions of Cobalt Strike.

CyberThreat 2024
The NCSC and SANS Institute announced that CyberThreat 2024, an event designed for security practitioners with a strong technical emphasis, will take place on 9th-10th December. 

Discover new opportunities by becoming a member of CBN today!

Through proactive engagement, deep collaboration, and expert consultation, we convene leaders from across the cybersecurity industry.

CBN Newsletter – June 2024

Our monthly update to bring you the relevant, high-level policy and business news from across the cyber sector.

This month we take a look back at our relaunch event at the end of April, update you on the latest election developments and give you a breakdown of the recent McPartland review into ‘Cyber Security and Economic Growth’ .

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch. 

Prime Minister calls surprise General Election
On the 4th July UK voters will head to the ballot box to vote in the 2024 General Election. Labour is currently polling strongly with an estimated 45% vote share and expected to win a significant majority after nearly fifteen years of Conservative government.

The campaign will focus on bread and butter issues like the economy and security with cyber unlikely to be front and centre, but a week and a half in to the campaign and cyber has been raised by both Conservatives and Labour – the former as part of a new National Service policy, the latter as part of their defence review as Labour commit to a strategic defence review in the first year of government. Aside from the parties, the Joint Committee on the National Security Strategy called for the PM to defend UK democracy, raising several concerns about the potential threats posed by foreign nations that may undermine the outcome of the election. The NCSC also recently launched a personal protection service for election candidates and officials, as part of a wider package of cyber support.

McPartland Review into Cyber Security and Economic Growth
Stephen McPartland MP published his final report and recommendations, the McPartland Review of Cyber Security and Economic Growth.

The report identifies 16 high-level “non-legislative” recommendations which span investment, skills, resilience and governance, crime and net zero.” Some recommendations include: 

Although “warmly welcomed” by Government, it cannot be officially published until after the election due to the dissolution of Parliament and the purdah period, and there are questions around its implementation under a new government.

Discover new opportunities by becoming a member of CBN today!

Through proactive engagement, deep collaboration, and expert consultation, we convene leaders from across the cybersecurity industry.

Cyber UK 2024
CyberUK, the UK government’s “flagship” cyber security event, took place in Birmingham last week. Notably, the DSIT Minister for Tech and the Digital Economy, Sadiq Bhatti MP, made a range of announcements, including a call for views on the new Code of Practice on the Cyber Security of AI & Software Vendors; the future direction of CyberFirst; and figures of growth in the UK cyber security sector.  

The figures, which constitute a cyber security sectoral analysis, find that the total annual revenue within the sector has increased by 13% in the past year – considerably higher than the slower growth in the previous study (3%) – and that the sector has grown by 5%, adding 2,700 new jobs. In addition, they estimate total GVA for the sector has reached c. £6.5 bn, reflecting an increase of 4% since last year’s study.  

Other speeches:  

Note: due to the election, the announcements made by the Minister may not be carried through by the next Parliament. We will share an update when possible, but please get in touch if you have any questions. 

Statement from HM Government on the adoption of UK Cyber Security Council standards
The government committed to strengthening standards by embedding UK Cyber Security Council standards across its cyber workforce by 2025. This includes defining necessary competencies, introducing training programs, and encouraging skill improvement. Critical National Infrastructure (CNI) regulators will recognise these standards and collaborate with the government. The Cyber Growth Partnership (CGP) will support the Council with industry backing.

Cybersecurity of elections
briefing from the Parliamentary Office of Science and Technology (POST) examines the impacts of cyber threats on election outcomes and mitigation strategies. It highlights the evolving nature of these threats, including misinformation and AI-generated content, and identifies risks such as ransomware, data leaks, and attacks on high-profile individuals. The briefing also outlines relevant cybersecurity policies, challenges in addressing these risks, and suggestions for preventing cyber attacks.

NCSC updates – May 2024

UK not heeding warning over China threat, says ex-cybersecurity chief.

Ciaran Martin, former head of the NCSC, warned that the UK isn’t taking the threat of Chinese cyber-spying seriously enough, citing US warnings about Chinese hackers targeting critical infrastructure. He urged the UK to declare attacks on civilian infrastructure as unacceptable and called for stronger government action. Martin supports proposed measures for mandatory ransomware attack reporting and regulating ransom payments, emphasising increased vigilance against this threat.

Founded by Clarity

Global digital marketing and communications agency, providing fearless marketing and consultancy to the world’s most progressive companies.

We match data-driven science with human ingenuity to expand our full-funnel, specialist services and expertise. Our vision is to accelerate positive change and impact across the world. A firm believer of cybersecurity as an enabler of growth and resilience, we are proud to driving its prosperous impact forward.

NCC Group: Digital Dawn: Cyber Security Policy in the Wake of Political Change
The NCC Group released a new cyber policy report for incoming (and existing) governments and policymakers across the world their roles in securing cyberspace, highlighting challenges and opportunities. 

Opportunities include cross-party agreement on cybersecurity’s importance, strong existing regulations, and a “whole-of-society” approach. Challenges involve limited resources, lack of specific responsibility, keeping up with emerging technology, and protecting smaller organisations.

One in three organisations looking to improve cybersecurity 
According to research from Daisy Corporate Services, while almost two-thirds of UK organisations are likely to be looking to reduce costs over the course of this year, leaders are prepared to invest in services such as cloud and cybersecurity, as they look to unlock operational performance improvements and streamline their current technology supply chain. 

70% of CISOs concerned about material cyber attack
Chief information security officers around the globe “are nervously looking over the horizon,” according to a survey of 1,600 CISOs with more than two thirds (70 percent) concerned their organisation is at risk of a material cyber attack over the next 12 months. 

These figures are striking. highlighting an increase from 48% in 2022, with those in South Korea, Canada and the US most concerned. 43% of those surveyed said their organisation is not prepared for a cyber attack.