According to a parliamentary committee the UK government is not doing enough to protect the nation against cyber attack.1
The UK Government periodically publishes a Cyber Security Strategy.3
Many of the stakeholders across all categories are engaged with that effort.
The overall responsibility for security within the UK rests with the National Security Council which is a cabinet committee chaired by the Prime Minister tasked with overseeing all issues related to national security, intelligence coordination, and defence strategy.
The internal protective security coordination role for UK government is led by the Government Chief Security Officer (GCSO) within the Cabinet Office, who since 2021 has been Vincent Devine.4
The central organisation supporting the GCSO is the Government Security Group (GSG), with a distributed Government Security Function / Government Security Profession across the departments and Arms Length Bodies (ALB), and three National Technical Authorities (NTA), all of which have a role in information and/or cyber security:
The role of Lead Government Department (LGD) for Cyber Security is currently fulfilled by the Department for Science, Innovation, and Technology (DSIT), having previously rested with:
All other government departments and ALBs will have staff in the government security function / government security profession, supporting both their internal staff, and their client communities.
Former bodies in this category include:
The Ministry of Defence has primacy for information and cyber security within both its civilian and military staffs (approximately 250,000 personnel), and for the Defence Supply Base (DSB - approximately 30,000 companies).
It has two main security organisations:
These organisation work collaboratively to publish not only the internal rules, but also Defence Standards and Industry Security Notices (ISN)7
In April 2016, the MOD announced the creation of the Cyber Security Operations Centre (CSOC) with a budget of over £40 million. It is located at MoD Corsham.89
MOD collaborates with the DSB over information and cyber security matters through a number of organisations, including:
The National Cyber Force consolidates offensive cyber capabilities from the Ministry of Defence and GCHQ.
The National Crime Agency (NCA) hosts the law enforcement cyber crime unit, incorporating the Child Exploitation and Online Protection Centre.
Within the WPS, there are a number of collaborative bodies, including:
Two regulatory bodies have a specific cyber security related function:
Most other regulatory bodies will have staff covering information and cyber security function for both their internal staff, and their client communities.
Current bodies that cover multiple sectors include:
cyber security companies in uk
UK 'wholly' unprepared to stop devastating cyber-attack, MPs warn The Guardian https://web.archive.org/web/20250523210712/https://www.theguardian.com/technology/2018/nov/19/uk-wholly-unprepared-to-stop-devastating-cyber-attack-mps-warn ↩
"EURIM". https://www.dpalliance.org.uk/publications/eurim-archive/ ↩
"UK Cyber Security Strategy". HMG. http://www.cabinetoffice.gov.uk/resource-library/cyber-security-strategy ↩
"GCSO". HMG. https://www.gov.uk/government/people/vincent-devine ↩
HM Government (1 November 2016). "National Cyber Security Strategy 2016-2021" (PDF). gov.uk. Retrieved 2 November 2016. https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/564268/national_cyber_security_strategy.pdf ↩
"OCSIA". Archived from the original on 2013-01-23. Retrieved 2013-01-14. https://web.archive.org/web/20130123174427/http://www.cabinetoffice.gov.uk/content/office-cyber-security-and-information-assurance-ocsia ↩
"ISN". HMG. 14 December 2023. https://www.gov.uk/government/publications/industry-security-notices-isns ↩
"Defence Secretary announces £40m Cyber Security Operations Centre". Ministry of Defence. 1 April 2016. Archived from the original on 25 April 2019. Retrieved 2 April 2016. https://www.gov.uk/government/news/defence-secretary-announces-40m-cyber-security-operations-centre ↩
Hammick, Murray (30 October 2018). "The Budget and Defence". The Military Times. London. Archived from the original on 22 October 2019. Retrieved 7 May 2020. https://web.archive.org/web/20191022115351/https://www.themilitarytimes.co.uk/uncategorised/the-budget-and-defence/ ↩
"DCPP". HMG. 23 November 2023. https://www.gov.uk/guidance/defence-cyber-protection-partnership ↩
"Cyber Technical Advisory Group". Retrieved 2023-12-24. https://www.ctag.gov.uk/ ↩
"ICO - About". 20 November 2023. Retrieved 2023-12-24. https://ico.org.uk/about-the-ico/ ↩
"ACFTI UK". https://www.acfti.org/ ↩
"BCS Security". http://www.bcs.org/category/11307 ↩
Kaye, David. (2008). Managing risk and resilience in the supply chain. London [England]: BSI Business Information. ISBN 978-1-62198-414-6. OCLC 849744629. 978-1-62198-414-6 ↩
"Home". crest-approved.org. https://crest-approved.org/ ↩
"ADS". https://www.adsgroup.org.uk/ ↩
"CDF". https://ukcdf.org/ ↩
"Home". tigerscheme.org. http://www.tigerscheme.org/ ↩
"BSI - NSB". www.bsigroup.com. Retrieved 2023-12-24. https://www.bsigroup.com/en-GB/about-bsi/national-standards-body/ ↩
"Trustworthy Software Foundation". Retrieved 2023-12-24. https://www.tsfdn.org/ ↩
Protecting and promoting the UK in a digital world: 2 years on – Government Press Release, retrieved 12 December 2013 https://www.gov.uk/government/news/protecting-and-promoting-the-uk-in-a-digital-world-2-years-on ↩
"UKCSC". Retrieved 2023-12-24. https://www.ukcybersecuritycouncil.org.uk/about-the-council/ ↩
"WARP". http://www.warp.gov.uk/index.html ↩
"IAAC". Archived from the original on 2018-04-10. Retrieved 2013-01-14. https://web.archive.org/web/20180410103034/http://www.iaac.org.uk/ ↩
"IAAC - Neville-Jones". http://www.computerweekly.com/news/2240083002/Burton-takes-over-from-Neville-Jones-at-IAAC ↩
"IAAC Sponsors". Archived from the original on 2017-06-07. Retrieved 2016-05-17. https://web.archive.org/web/20170607235623/http://www.iaac.org.uk/about/sponsors ↩
"Establishment of the IACG". National Archives. Archived from the original on 2008-03-05. http://webarchive.nationalarchives.gov.uk/20080305141506/http://www.cabinetoffice.gov.uk/csia/ia_technical_programme/stakeholders/industry.aspx ↩
"IACG Overview". https://www.scribd.com/doc/117496158/IACG-Overview ↩
"IA Community Map" (PDF). Archived from the original (PDF) on 2013-07-31. Retrieved 2013-01-14. https://web.archive.org/web/20130731001653/http://www.cesg.gov.uk/Publications/Documents/uk_ia_community.pdf ↩
EC2ND 2006 - Proceedings of the Second European Conference on Computer Network Defence, 2006 ↩
"NDI UK". Archived from the original on 2016-10-21. Retrieved 2013-08-21. https://web.archive.org/web/20161021183318/http://ndi.org.uk/ ↩