Go back

Cyber Essentials

0m 0s

Cyber Essentials

The discussion centers on Cyber Essentials, a UK certification program designed to help organizations implement five basic cybersecurity controls to mitigate common threats. Initially developed from GCHQ's "10 steps" and attack analysis, it emphasizes practical measures like patching and access control. While small businesses find it straightforward, large organizations face challenges due to complex IT estates but benefit from risk reduction, such as an eightfold decrease in vulnerabilities. The certification is not just for compliance; it fosters a security culture, supports supply chain assurance, and demonstrates due diligence to regulators. Cyber Essentials Plus adds rigorous testing. Success requires leadership commitment, integrating controls into business operations, and viewing certification as part of ongoing risk management rather than a one-time exercise. Adoption is growing across sectors, driven by both contractual requirements and the tangible security improvements it delivers.

Transcription

7980 Words, 43612 Characters

English
Hello, and welcome back to Cyber Series, the NCSE's podcast series. I'm Dara, and today we're talking about Cyber Essentials getting the basics right. Whether it is small business or a charity or part of a larger organization, Cyber Essentials is designed to help protect against most carbon cyber threats. Joining me today are Mary Hague, Director of Digital Delivery and Deputy Global CIO at BAE Systems, Emma Philpott, CEO of IASME Consortium, and Chris Hensor, Deputy Director of Cyber Growth here at the National Cyber Security Centre. All three have been closely involved with helping organizations implement Cyber Essentials across the UK and is lovely to have you all here. To kick us off, could you tell us a bit about yourself and how you got into this field? Mary, shall we start with you? Slightly by accident about 16 years ago, I went into looking at the cross-domain solutions, bringing business experience into the cyber world and then discovered that cyber was fascinating, had a really important mission and didn't want to leave, so it stayed in that. Up until, in a sort of pure cyber role, and my final role in that was four years as CISO at BAE Systems and then very recently, my new role, which is digital data on cyber, so definitely not leaving cyber behind, layering in cyber from the beginning in digital systems. Marvelous, thank you very much, and Emma, what's your roots to where you are today? Well, again, a little bit by accident, so I'm actually a material scientist, and I used to specialise in helping small companies commercialise nanotechnology, and then I moved to Melbourne from outside the UK, and didn't have any particular job to do, and everyone I met was working in cyber security. But I noticed that there were loads and loads and loads of little tiny small companies that didn't know each other, and were just working for one big prime. So I set up this group of small companies to work in cyber security, and that kind of fed through to small companies, cyber security, into ISME and cyber essentials, so yeah, that's how I got hit. Hopefully, thank you. And Chris, you've worked with both Mary and Emma in the past, so, and how have you arrived to where you are today? Oh gosh, long journey, 35 years worse, started before we even called it cyber security. We had computer security, information security, information assurance, and then we got cyber security. So for me, it's always been, how do we defend ourselves against attacks? And that's where my career has been for 35 years in GCHQ and NTSA and CSG before it. Super. Chris, stay with you. We're talking about it today, but we've got cyber essentials. Can you tell us what's the core idea behind it for those who aren't familiar? So cyber science is quite simple, really. It's, do five things, do them consistently across an organisation and then go and get them assessed. I mean, the history behind some of this was, can go back about 13 years to about the time that the UK hosted the Olympics. So if GCHQ produced something called the 10 steps to cyber security, it was really at the request of a load of footsie companies who said, "Oh GCHQ, you know about this cyber stuff, don't you? Can you tell us what we should be doing?" So I got involved in producing the 10 steps. It was, if I may say, it's a slightly hand-wavy document because it, underneath it, is like do 74 things. If you count them individually, it's not quite 10 steps. But we produced it and it was well received by industry. But not long after, people then came back to us and said, "Yes, it's all great, but what do we actually need to do? What is the minimum set of things we need to do?" And this came at the same time that we'd been investigating a number of attacks against some rather, some quite big organisations. And there was a real common theme started to come up that, within each of these organisations, if they put one of these five controls in, then that attack would have been stopped, or at least it would have been slowed down. It was not to say they wouldn't have found a way in eventually. But basically, one of these controls was the thing that emerged that they should have been doing. We put the two things together. We have industry saying, "Tell us what we should be doing." We had the evidence that said, "If you do these things, actually you'll make a lot harder for a cyber attack to be successful." So we kind of brought those together. It's a slightly longer process than that, and I worked with Emma for quite a lot of work to get there. It was about two or three years worth of work to get there. But in the end, that was the core of cyber essentials. Doing these five controls makes such a big difference. Getting them independently checked is important. And then you've got to get the end of it, that's cyber essentials. And I mean, there's a common myth that cyber essentials just for small logs. I mean, what's your response to that? Well, I mean, I think it's easiest for small logs. So the small company, which is less than 50 people, is the absolute perfect place for cyber essentials. They love it, they know what to do, and it's relatively easy. For the large organizations, it can be quite hard because of things like the YOD and the legacy software. But we are beginning to find that more and more large organizations are achieving it. About 91% do for the whole organisation, which is, you know, which is really great. And we have about 300 large organisations certified to cyber essentials each month. So, you know, there are quite a few. We reckon about 37% of large organisations have cyber essentials now. And Mary, from your standpoint, we're a bigger organisation, but we're rather a large organisation. Where are you coming from when it comes to getting the basics right? And what's your view on why so many organisations are finally difficult to do so? Yeah. I mean, it isn't easy, but that doesn't mean you shouldn't put the effort into doing it. I mean, a big one, you know, it's, you've got a complex estate, but you do have more maneuverability in where you spend your money. If I can phrase it like that, and you've got typically quite a lot of skills around that you can point to it. And to me, the stakes are high on this, right? So, so there's a lot to lose if you don't get it right. And any organisation needs to know that they're doing the responsible things to manage the risk in their organisation. And when you look at cyber essentials and you go, you know, if you don't have that, could your board hold their heads up high? After a big cyber attack and go, we were responsible in what we dealt. I don't think they can. So that then pushes you to, well, I'm going to really put the effort in, put the money in, put the resource in to fixing it. And when you get that senior level buy-in for it, then the rest of it flows through. And I think there's a bit of a myth around cyber essentials that is an organisational standard. And that's kind of how it's been kind of promoted, but actually it's a system based standard. So where you've got some more organisations, I think I have one system. So therefore, the system almost equals the organisation, but for larger organisations they might have dozens of systems. And ultimately they can get, they can apply this to each system to gain confidence that that's the case. I mean, is that what, how you've approached it, Mary? Yeah, so we've got cyber essentials for our digital intelligence business, social online network, and another one for another network that serves the rest of our kind of core enterprise pieces. So they are the big chunky business systems across our different divisions, essentially. And that means you're both going in at the important systems where it's risky. But you're also, I suppose, not trying to go after every single, different system and every single lab everywhere. There's a bit of pragmatism and risk thinking that goes into the scope that you do around it. So as part of a very large organisation, I mean, it can be quite difficult and you probably need to invest in it. And I know quite a lot of large organisations, you know, they see another certification scheme. They expect to fill in a few forms and get it. So how did you actually get your company to agree to put in that effort? You can't look at certifications and go, that's doing one thing and here's my cyber strategy doing a different thing. They are feeding more than other. So again, you look at what cyber essentials are asking for and you go, yeah, that fits with sensible set of things and organisation should be doing. Now you use that certification as a lever, a bit of a stick within the organisation. So I went out with a very, very simple business case to all the exec committee and the business leaders and I said, if you don't update and invest in that system, then we'll fail cyber essentials. If we fail cyber essentials, we can't deliver government contracts because you have to have cyber essentials for government contracts. Are all your government contracts and worth more than the investment to fix that thing? If yes, we'll have a conversation about whether you fix it or not. None of them came for a conversation. When you put the business case like that, it is a no-brainer that you invest in, obsolescent that's you invest in having a vulnerability. That's because we're mainly government contracts. If I was in a company where we weren't mainly government contracts, I'd change it slightly. And I'd say, here is an externally validated, well-respected certification that's asking you to do sensible things, you get this board and in a cyber attack, you can pass the red face test for did you do roughly enough to try and protect yourself? And that's important, they've got to show responsibility. So I think you can phrase it either way. And of course, if there was a breach, the ICO will come in and having cyber essentials is a really good way to show that you have done stuff. That's right. You've been doing your best. That's right. One large organization was telling us that they justified the investment for cyber essentials because of the breaches that they were having and it was actually less expensive to go ahead and get cyber essentials. Definitely. So cyber essentials for us, when we push that through, means that now nobody debates obsolescence funding and we stood up vulnerability management in a much more professionalised way than they've been there previously. And over the four years that we've done that, we've seen an eightfold reduction in internet facing vulnerabilities. That's a really useful stat to share because that is straight up risk reduction. And it was last year, there was a serious vulnerability and one of our externally facing firewalls. It was a vendor, true for lots of people. Within 42 minutes, a nation state had tried to exploit that. Now, if we hadn't had that really good asset management and that really good vulnerability management would be dead in water, you wouldn't know where that firewall was, you wouldn't know how to go and patch it, who to tell to go and patch it. So the speed at which these things are now being exploited is such that you've got to have a really slick process, well practised in place and that's one of the things that cyber essentials us for. So it is interesting because cyber essentials says 14 days for patching. And this is always, you know, whenever people come up to me and talk about cyber essentials, 14 days, you know, that's so hard. Are you thinking of changing it? And I think what they want me to say is yeah, we're going to go to 30 days and I kind of go, yeah, I'd like to make it two days because, because ultimately, you're quite right. That is the speed by which these vulnerabilities get exploited often. It's in public in public tools well before the patch comes out. So, you know, you've got no time at all. So for me, it's, you know, but 14 days is as good, you know, at the end of the day is good enough. Then we can dial up from there. If you haven't got it in place at all, there's nothing you do, if you've got 14 days in place and the chances are you can get in touch with that person as I do now. And I think it's having that target. I'd like to come back to this talking about, it's not a tick box. If you see there's a tick box exercise just to get a contract, you're not taking cyber security seriously. And I think that's a really, really good point. But I see, I mean, we see that in statistics where often companies will get it for the contract, but then they don't renew it because it's not being checked sometimes. So I think that's an area that we need to get a lot better on is making sure that you consistently keep it going because then you are beginning to get into that rhythm. So there is a consistency of messaging that I think you have to have across cyber security in general, but for sure with cyber essentials of you can't just sort of one month go in and say, I don't know, obviously, listen to matters and vulnerability management matters. And then next month, flick to something else. These are fundamental, I sometimes describe it, is it fruit and veg kind of stuck? You've got to do it every day all the time. And that means as a cyber professional, you've almost got to bore yourself in how often you repeat the messages that this stuff matters, can't be inconsistent with it. And when it does start to come through, it's mentally satisfying. So when teams tend to you and go, well, of course, obsolescence is in the budget. We're managing that because, of course, we can't not do that. She's signed a success. That's when you go, yes. And is that part of building up muscle memory? So when something does occur, as you were just talking at the speed of a first reason, exploiting those vulnerabilities, it's all very well to have cyber essentials in place. But you also have to have the added bonus of doing the work as well to make sure you can respond quickly. I mean, Emma, turn to you in relation to any examples that you've seen or any trends that you've spotted as passive, with your eyes me hat on. What do you see? Well, I mean, we're seeing a much wider variety of organisations that are turning to cyber essentials, which is really great. Obviously, it started with sort of defence and security and people working a lot with government. And it's expanding to financial services and the legal sector. And every time a new sector is introduced to cyber essentials, there's often lots of kicking and screaming. You know, oh, you can't be expecting us to do this. You're asking us what? And it usually takes about a year. And then, you know, it's actually very rewarding that after about a year, they start saying, oh, this is, you know, it's a very powerful, it's been very great for our organisation. And they start off by saying, but it's so basic. And in the same breath, we can't achieve it. So, you know, it's natural when you're asking somebody to do something quite difficult. And first of all, you try all the reasons why you can't happen. And then when you actually do it, then they see benefit to it. And that is beginning to happen sector by sector, I would say. And it's really rewarding. And of course, every sector has its own issues. So for example, the retail sector have a big issue with point of sale equipment, you know, and we don't really know about it until it goes into that sector. And then we realise, oh, there's this issue, what should we do about it? So it's been very interesting. And in terms of those different sectors, I suppose the commonality between it all is supply chains as well. Can we talk a bit about supply chains and what people are seeing there to open questions to anyone? I think, I think when we start talking about supply chains, we have to work out what we mean by supply chains. Because it's like it, it's a word used to cover lots and lots of different things. So cyber essentials will give you confidence in your suppliers, taking cyber security seriously and particularly managing the most common risk, either tactically internet. What you won't necessarily tell you is what they're delivering you is any good or is cyber secure because it could be completely a different product then. So it's being really clear. So cyber essentials is a really good way, particularly in many people who buy things in the procurement space, then also security experts. So how are they going to get easy confidence that the companies they're dealing with are putting some minimum things in place? Well, cyber sensors is ideal for that. And it's probably one of the only things that you get, which actually focuses on a particular risk. Looking for a certificate, and particularly cyber essentials plus certificate, which is tested to get that extra level of rigour, you're getting confidence in the things that they're doing. It's not the end of the story, but it's a really, really good start. It's so easy for them to do. It suggests, say, show us your certificate for the system I care about and you're done kind of thing. We ask it. Mars buyers. And they don't all have it, but the fact that we ask is important and one of the conversations we have internally is, is the voice of cyber strong enough in procurement such that when a supplier doesn't have it, are we really thinking about whether we want to go with them or not? That should be an important factor, their cyber risk, along with the rest of supply chain risk. Well, I think it's, I mean, sometimes it's thought about I will, if they're providing the IT services, then it's important we use cyber essentials, but actually dawned on me a couple of weeks ago that, you know, it doesn't matter what you're delivering, everything now is determined by IT. You know, if you're a, if you're a college company, then it's IT because that does all your logistics, you get, if you lose your IT system through ransomware, you can't deliver anything. So it doesn't really, I mean, people who make a joke, you know, why should we have, why do we care about cyber security when it's toilet rolls, I kind of think. But actually, if you can't, you know, if you, you can't operate, because you haven't been delivered, because they, they've been hit by a ransomware attack, it's going to have a knock on effect. So people, I only really got to think about what do we mean by supply chain and what is it that we don't want to happen in the supply chain that will affect our ability to deliver business. Oh, we see that people are reporting far less instance because of having cyber essentials in their supply chain. So for example, St James's place, it wasn't really their supply chain, it was their network, they asked for cyber essentials plus and overnight, they saw an 80% reduction in cyber instance. And so even though we're a small company, we ask all our suppliers for cyber essentials. And in some cases, so we have a little tiny accountant, I'm sure she's not small, but a small accountancy firm. And we asked them for cyber essentials and they really didn't know where to start. So we paid for them to get some help so that they could get it because we, obviously, I mean, I'm dad, we do, but we really do totally believe in it. And so it's worth it to us that she has cyber essentials, she has the controls in place. So yeah, so we do practice it as well as preach it. Mary, Emma mentioned there are cyber essentials plus, you've overseen BAE getting cyber essentials plus certification. How was that? What the key challenge is, was it smoothly sailing or was it, did we get obstacles? It was a helpful ramping up in what we were trying to do again. But you know, you look at it and goes that the right direction for improving our cyber resilience has an organisation overall, yes, great. So do the work, none of this is easy, best things in life aren't always easy. Go after it anyway because it reduces the risk in the organisation, so it was a helpful another lever to push us to improve. And we mentioned earlier on about ransomware, it continues to dominate the headlines. It's discouraged on businesses, how do the cyber essentials, controls help combat, you know, reduce the risk and then rise resilience against ransomware, such a critical motivator for organisations. So we could constantly monitor the effectiveness of the cyber essentials controls. So they've been around since 2014 and we are constantly looking at, you know, the latest attacks to say, could cyber, would cyber essentials have stopped this or not? And we still see for the majority of times, it is the fact that, you know, it's to fall passwords, it is something hasn't been patched, you know, they're, or they're not using multi-factor authentication. So the same things we saw back in 2012 when we, when we first decided what the fire control should be, we continue to see. And it's often that it's not being, so they'll do really, an organisation maybe do really well in one place, but they haven't consistently applied though. And reality is, if you're a defender, you have to close all the doors. If you're a attacker, you only have to find one open. So the key thing is effectively and consistently applying it across the organisation, because if you don't, and I do laugh sometimes, because you'll see, you'll see charts with red amber green in terms of how patching has been applied, and it might say something like, your green if you're 95% patched, your amber if you're 80% patched and your red if you're 60% patched, which looks really good, so you could pat yourself on the head and go, well done, you know, we're 95% patched. But then you say, well, what's patched, I mean, where is it, you know, is it all your internet facing things? So I will know, not all of them, which at the end of the day, will be found by an attacker. They will find it. There's enough of them out there, and that's what they look for on a daily basis. So being consistent is really important. That's the scary bit. That's what I worry about in a big organisation. It's not just doing it well in one bit, doing it well in every single area. That's what makes it hard. But it comes down to, I don't think it is boring, but sometimes people think it's boring, that process and that governance, and being quite regose about it, and then, and then when you've got that articulated and you, you're checking it, it's then all, if you're not doing it over there, do it well, that please, because there's your example of excellence and rolling it out and having it scalable. Yeah, we find one of the biggest barriers for large companies is lack of asset management. So to get cyber essentials, you need to know all your assets, and it's surprising how many companies, I mean, it is difficult, but how many particularly big companies actually don't know what assets they've got, they don't know what endpoints they've got, and you can't get cyber essentials and you've got that. But also, you can't protect properly against this threat when you don't know what your assets you've got. I think there's, there's another interesting lesson that's come out as well in terms of the person who's been tasked with getting their cyber essentials certification, and the people who can actually make the investments in changing things, and often they are in, either in completely different bits of the organisation, or no influence of the put, the poor person who's required to get the certificate cannot make any changes to any of the systems. And I come back to your point about people's seed as a stamp, I'm just going to come along and I'm just going to get a cyber essential certificate, but actually there's work to be done, and if you can't have any influence over that work that's needed and the investment that's needed, I'm hiding to nothing, and I think that's a real challenge for them. Yeah, and in fact we've seen some people who've been tasked to get cyber essentials actually welcome a fail, because then they can go back to their board and say, look, this is the meant to be the basics, this is the bottom level of where we expect it to be, and we failed, and it is a good justification for a bit of, you know, investment. And can they ask, so just curiosity, would they be able to ask the certification body to give them, rather than just like you've failed, but give them some more detail to be able to say, actually these are the areas if you were to invest in these sorts of things, because that helps that it's that independent justification that they can take. Yeah, so I mean, they always get a fail report. So even at the basic level, cyber essentials, anything that you're not compliant with, you get a little bit of a chat from the assessor, say why it was a compliant, and what they could do about it, with the cyber essentials plus obviously they get a more in-depth report. All our certification bodies are general cyber security organisations that would be very happy to give even more support, but there's definitely enough information there for anyone who fails to know why they fail and what they can do about it. And of course we've got the cyber adviser service now as well, where, so if they want some trusted advice on how to implement some of these controls, they know where to go. Yes, exactly. And they assess not just as much as how much cyber security they know, but also whether they can communicate. So they're really good in terms of consultants, they can we can you expand a bit more about the cyber adviser. Yeah, so the cyber adviser's primary market is in the smaller organisation, understanding the business. So a lot of cyber security consultants we found were very good at cyber security, but they probably didn't necessarily understand business and they were not necessarily very good communication in real person talk. So we developed with the cyber scheme an assessment to see not just do you know how to implement the technical controls, but can you actually relate to business people and can you explain it? So we've got about 120 of these wonderful cyber advisers now and they're great and we get such amazing feedback from people who would them. I suppose that's the whole thing of if you were a small organisation you're looking at keeping your customers happy, looking at your bottom line and then you know you need to protect your assets and your business, but it's just turning having their headspace in order to do that. I imagine this is what the cyber advisers do in a way just it's almost a personal trainer or someone like that saying telling them what these to be done is out of fair assessment. Yes, and also being able to give proportionate advice. So with a very large organisation of course you would need a mobile device management system, but if you're a little tiny startup and you've got two computers and one mobile phone you know don't advise that they go out and buy a mobile device management system. So it's just being aware and understanding cyber security enough that you can scale it to that organisation. Yeah, and they're really good at doing that. And in terms of the motivating factors I mean between you know large organisations and smaller and Mary you've talked a bit about the motivating factors for a bit of organisations like B but is there anything particular that you've noticed about what motivates an organisation to get a grip of its own security? I think it does come back to that business translation. I sometimes describe my career as a technical translator so taking it from a technical area to a business area and you have to tell it in the way that makes sense in the industry when. So if I give an example I fairly early on was talking to the exact committee and one of my briefings about the important of segmentation. So our networks weren't segmented enough and I could have called it network segmentation and I could have gone big and called it Zero Trust and all of that a lot and I didn't because they would have glazed over and I said well actually we started off with the next size of ransomware and it was a flipping doomsday horrendous one and they were all properly shaken by it but that demonstrated why it matters and I introduced the idea of blast zones were a defence company right so they kind of get blast zones and I said you want to limit the blast zone of this attack if it comes in here you know when it rippings through all of your divisions limit you cyber blast zone so there is a bit about the language you use and then it's not just about bad stuff could happen it's also about talking about our customers trust in us the importance of our mission and making sure we can keep doing that because we're cyber resilient that they trust us and their information their sense of information because we're cyber resilient so it's weaving it right the way through our business story and how we protect our brand our relationship so our customers our ability to serve our customers as well as financial and avoiding the embarrassment of an attack with so many different angles to it but they all have a really strong business thread to them there to be quite blunt how do we know cyber it's our essentials actually we're so that's a really good question I've been worked in cyber security and information and all the things it was called before for 35 years having evidence of impact is really really hard when it comes to to controls because what you don't know is whether the control you put in was effective or actually nobody even tried to to kind of get rounded so so that's always like the holy grail in cyber security how do you know that something is having having impact so cyber essentials you know we've we've we started off with academic research so we we let a couple of academic contracts to look at basically here's a bunch of attacks with the controls have stopped it so that that was our starting point and Lancaster University Bristol University both both did reports which were available that's great but it's very theoretical kind of thing it's not not practical Emma's mentioned St James's place and some really good data from there they're required all their ethical partners or franchise is to have cyber essentials plus 80% drop in incidents we've also got the insurance data because you know when you when you get your cyber essential certificate you know comes with under certain conditions you know insurance so we now have some really good data from insurance companies which basically says you know if you if you have cyber essentials then you're 92% less likely to make insurance claim you know even if that is is you know 90% 92% you know even if it was 10% less or whatever that's still massive in terms of the effect it can have the 80% st James's place 90% is massive in terms of the benefits it brings so you know talking to people about you know why should they do it with all the runs from we're going around you know we've got the data so and and we haven't had that data in many of the play in any other places as far as I'm aware so for once we can say do these five things do them well do them consistently get them checked and it will have a big impact on your organization in fact the data is almost too good because we say oh you're 92% less likely and people are like yeah really you know that sounds like a made up number and I I know because I have checked and check when we first got that number I was thinking I'm I've definitely made a calculation error it can't be that much but I've checked a lot and the NCSE clever people have checked a lot that that is correct and we've we found it by just looking so so the underwriter has a cyber insurance package which you get automatically through a micro small company and you get cybersexuals but they also sell exactly the same package to micro small companies that don't have cybersexuals obviously for a lot more money because the two packages are the same you can directly compare the the claims data and there's thousands in both of the buckets so just comparing those claims data that's where we get the 92% from and it is you know and I guess it might go down or might go up but even if it's 50% I mean that's incredible and it is just those five technical controls and that's the basic level that's not even the audited cyber central plus so it is very powerful and it really backs up the things that we hear you know they hear say stuff when we talk to our certification bodies they talk about the joy that they get from working with charities little tiny companies schools that they can put these things in place and that organization then feels more secure and the certification bodies absolutely fully believe in it as well so a lot of them get a lot of job satisfaction from putting those controls into small organizations like that and we sometimes find them in this five controls we do review it constantly to see whether we should add controls in but you know the evidence tells us they're effective so if we add another control in it'll cost organizations money and time to implement it will it move those stats to 93% 94% and is it worth the effort that that takes and those are the balances we we constantly have you know make judgments around within within the entity and talking to the community by adding these extra things in will it make really tangible benefits and as a cybersecurity person you know more security must be good security of course it is but then if you're talking to organizations who have limited you know limited time money effort whatever or skills you're the more you put in the more effort is on them goes on them and they have to divide their time so which is why you know we've always run with the mantra less is more so why add more in backups is a thing that keeps coming out people say our cyber essentials does not backup actually cyber essentials does have backups within it so you read the technical standard it's got backups there and we we always recommend organizations should should backup their data because 92% is not 100% and therefore there's always a gap you know there's always a gap there and you really want to do belt braces then then bringing backups what we don't require is you must have it to part get a certificate ultimately it's a risk decision on the business whether they have it or not and we feel comfortable with that we're not saying backups bad we say absolutely should have backups it's your decision because but if you implement the five controls what's the time you don't need them because they won't get in the start with therefore you don't need to spend the money in the backups but if you want to that's entitled to you and we would always encourage it so again it's we constantly review it to see whether we should be adjusting it and changing and we actually whenever there is a claim on insurance we can use that to say well how you know why was there a claim how did they get in was it some reason that means that we should add another control and one of the issues is we don't have that many claims you know that's good but also it means we don't have that much data but yeah the the technical teams meet literally weekly to review the technical controls so it is kept up to date and yeah and we use all the data we've got to try and make it better I think the minute that companies use it as the only list to follow in which to make decisions about what's doing cyber security that's looking at it the wrong way that's back to your tick box exercise this is an important set of things that you should have in place it is not necessarily the only set of things as an example for a big organisation like BIE I would be crazy to only have what is line by line written in cyber essentials plus that's not what it's designed for but we make risk-based decisions I think that's such a good point because cyber essentials was built to mitigate one risk which has attacked on the internet from what we call public tools and technique commodity techniques there are more sophisticated actors out there and so for a lot of organisations that will be you know where the return on investment on attacking them is quite high from a tackers perspective they need to do more and it comes back it's absolutely a risk decision you could decide I'm just going to put the foundations in five controls and that will be good enough and I'll accept the risk above it but for a lot of organisations you have to you have to do more and that's and I think that's what you get from the InfoH commissioners office as well which is yeah cyber essentials is a great foundation for a lot of organisations it'll be absolutely enough but for others they will be expecting more and I don't think it devalues or or puts a contradiction in it all I think I'm fine with that I think you know because because actually those the things that cyber essentials are asking for because they are the the freeing of edge sometimes people get bored of it and they want to do the spicy stuff and you have to go I get that but just make sure you're doing this really well day in day out and having that cyber essentials lever is helpful in that so I don't see it as a sort of failure that I have to do more than it's just this cyber risk is a complex thing and even in the supply chain it's the same isn't it so in your supply chain you can say I expect you to have cyber essentials and other things so it doesn't have to be just cyber essentials we don't say in the supply chain we're expecting to just ask for cyber essentials but it's a really good basic to ask for and also for small companies that work for multiple large companies at the moment they have many many different spreadsheets to fin in more or less the same but taking hours for each one if they could all just ask for cyber essentials and then anything else that would save so much time from small companies and we actually get this plea from small companies saying please make large companies standardize what they ask from us yeah I think this thing about less is more there is a danger we could do one of two things we could put more into cyber essentials so that you don't have to ask for it in procurement so make procurement job easy but it makes it a lot harder than for people to implement always say no cyber essentials is the basics that's the starting point for any procurement but if you if you want more then put it in your contract and ask them separately to provide it that's that's the thing it's let keep it as a basic let's keep it as the minimum people need to do and if you need more ask for it but it that's part your business risk and how you decide how you manage your risk and one thing for me I mean we've been hearing about how you're certainly not static or the teas behind cyber essentials are not static and they are constantly reviewing the controls that required how is cyber essentials how can it ever keep pace with the new threats and technologies that we're facing these days so again you know we came up with the controls nearly 15 years ago based on attacks you know as we see attacks today they're still the save attacks you know if you think about vulnerabilities in code buffer overflows being around since the 70s where's the evolution there kind of thing it's the same kind of attacks the same kind of bugs that go in the then that then get exploited so whilst there may be more attackers there's more proliferation of tools they're still exploiting the same vulnerabilities what we do tweak and what we do change is the technology that will help implement the controls so for example past keys so we you know we've we started talking about having good passwords then we started talking about the need for multi-factor authentication now we see past keys as kind of the next evolution so it's more about adding more controls it's about how can we make it so much easier to implement those controls using the technology that comes out of the box so that's really where we put a lot of our effort because I just say I mean we often say the threat is evolving but I think that that sometimes scares people into the threat getting to the point I can't do anything about it but that's on the case you know they still exploit the basic things let's get rid of the basic things and let's make it hard as the return on investment isn't there and maybe they'll go somewhere else I think a lot of the time it's um about doing what you've always had to do but doing it faster and better so my example of the you know 42 minutes one effect we might see with AI is even more efficient exploitation of vulnerabilities so get on it and get really good yeah vulnerability management 20 minutes trials and 14 days quite now turning to final thoughts Emma what message would you leave with our listeners today so at some last thoughts really cyber essentials can often seem very difficult for large organizations and I think part of that is the fact that you do need to invest in time and effort to be able to do things like asset management but it seems to really have such a positive effect and things like supply chain if you can ask for something like cyber essentials in your supply chain not only does it standardise the ask of your from your suppliers but it makes it easy for your procurement officials because they can go by the certificate they don't have to make the judgment themselves so yeah we're seeing an offtake in it on that side Chris anything any last thoughts from you I think it's just time these sorts of things take to embed and it's the creating the muscle memory I think you mentioned earlier you know we've been we've just celebrated 10 years for cyber essentials and it just takes time to embed these sorts of things and people say oh you know you've not got enough you know there's not enough organisation certified you know as it succeeded it's like that's not what I measure it by my measurement is how effective it is at stopping attacks getting more and more organisations to realise how effective it is in a time of you know constant ransomware is the key thing that we know need to do you know it works we've got data on it we know how impactful it can be if you want to stop ransomware implement the five controls get yourself certified because that's an independent check so for me that that's the key thing but it's patient you have to have patience because it takes time to get these things embedded Mary do you have any final views for our listeners well I think in my own organisation we've seen it work with the eightfold reduction in vulnerabilities and in the way that people are now bedding in their budget requests some managed-opt lessons on a way that I never saw before so from a very personal perspective I've seen it be very effective as part of our cyber strategy don't don't view it as some separate tick forks thing view it as a lever as part of parcel of kind of really pushing that message of why cyber security was a little bit so important and how to enact it thank you for those pills a wisdom to finish our conversation we've heard that when it comes to sub-scouting sometimes less is more than maximum impact can be achieved by applying cyber essentials effectively and consistently across your organisation and that leaves me just to say thank you to Mary Emma and Chris for joining us and sharing their insights if you'd like to learn more about cyber essentials including how to get certified or support others in doing so please do visit the NCSU website on ncsc.gov.uk for full guidance

Podcast Summary

Key Points:

  1. Cyber Essentials is a UK certification focusing on five fundamental security controls to protect against common cyber threats, applicable to organizations of all sizes.
  2. Implementation challenges vary by organization size, with large entities facing complexities like legacy systems, but certification drives risk reduction and operational improvements.
  3. The scheme is increasingly adopted across sectors, aids supply chain security, and helps demonstrate due diligence, with Cyber Essentials Plus offering enhanced verification.
  4. Senior leadership buy-in and integrating certification with business strategy are crucial for successful adoption and maintaining consistent security practices.

Summary:

The discussion centers on Cyber Essentials, a UK certification program designed to help organizations implement five basic cybersecurity controls to mitigate common threats. Initially developed from GCHQ's "10 steps" and attack analysis, it emphasizes practical measures like patching and access control. While small businesses find it straightforward, large organizations face challenges due to complex IT estates but benefit from risk reduction, such as an eightfold decrease in vulnerabilities.

The certification is not just for compliance; it fosters a security culture, supports supply chain assurance, and demonstrates due diligence to regulators. Cyber Essentials Plus adds rigorous testing. Success requires leadership commitment, integrating controls into business operations, and viewing certification as part of ongoing risk management rather than a one-time exercise.

Adoption is growing across sectors, driven by both contractual requirements and the tangible security improvements it delivers.

FAQs

Cyber Essentials is a UK certification scheme designed to help organizations protect against common cyber threats by implementing five key security controls. It focuses on basic but essential measures to significantly reduce the risk of cyber attacks.

No, Cyber Essentials is beneficial for organizations of all sizes. While it is particularly accessible for small businesses, many large organizations also achieve certification to enhance their security posture and meet contractual requirements.

Large organizations often face challenges due to complex IT estates, legacy systems, and the scale of implementation. However, with senior-level buy-in and a risk-based approach to scoping, they can successfully apply the controls to critical systems.

Cyber Essentials provides confidence that suppliers are implementing basic cyber security measures, reducing risks in the supply chain. It is often used in procurement to ensure partners meet minimum security standards, helping prevent disruptions from cyber incidents.

Cyber Essentials involves a self-assessment questionnaire, while Cyber Essentials Plus includes independent testing by an assessor for added rigor. The Plus version offers higher assurance that controls are effectively implemented.

Patching within 14 days is a key requirement because vulnerabilities are often exploited quickly by attackers. This timeframe establishes a baseline for timely updates, helping organizations reduce exposure to common threats.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.