The
United Kingdom
The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Northwestern Europe, off the coast of European mainland, the continental mainland. It comprises England, Scotlan ...
has a diverse cyber security community, interconnected in a complex network.
Public sector bodies
Legislative
According to a parliamentary committee the UK government is not doing enough to protect the nation against cyber attack.
*
EURIM, the Digital Policy Alliance
National strategy
The UK Government periodically publishes a Cyber Security Strategy.
Many of the stakeholders across all categories are engaged with that effort.
Capstone components
The overall responsibility for security within the UK rests with the
National Security Council
A national security council (NSC) is usually an executive branch governmental body responsible for coordinating policy on national security issues and advising chief executives on matters related to national security. An NSC is often headed by a n ...
which is a
cabinet committee chaired by the
Prime Minister
A prime minister or chief of cabinet is the head of the cabinet and the leader of the ministers in the executive branch of government, often in a parliamentary or semi-presidential system. A prime minister is not the head of state, but r ...
tasked with overseeing all issues related to
national security
National security, or national defence (national defense in American English), is the security and Defence (military), defence of a sovereign state, including its Citizenship, citizens, economy, and institutions, which is regarded as a duty of ...
, intelligence coordination, and defence strategy.
The internal protective security coordination role for UK government is led by the Government Chief Security Officer (GCSO) within the Cabinet Office, who since 2021 has been
Vincent Devine.
The central organisation supporting the GCSO is the Government Security Group (GSG), with a distributed Government Security Function / Government Security Profession across the departments and Arms Length Bodies (ALB), and three National Technical Authorities (NTA), all of which have a role in information and/or cyber security:
* The National Technical Authority for Cyber Security (NTA-C) is the
National Cyber Security Centre (NCSC) is the UK's authority on cyber security; its parent organisation is
GCHQ
Government Communications Headquarters (GCHQ) is an intelligence and security organisation responsible for providing signals intelligence (SIGINT) and information assurance (IA) to the government and armed forces of the United Kingdom. Primar ...
. It absorbed and replaced
CESG (the
information security
Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
arm of GCHQ) as well as the Centre for Cyber Assessment (CCA), Computer Emergency Response Team UK (CERT UK) and the cyber-related responsibilities of the former
Centre for the Protection of National Infrastructure (CPNI). NCSC provides advice and support for the public and private sector in how to avoid cyber threats. CESG (originally Communications-Electronics Security Group) was a branch of GCHQ which worked to secure the communications and information systems of the government and critical parts of UK national infrastructure. Th
NPSAprovided protective security advice to businesses and organisations across the national infrastructure.
* The National Technical Authority for Protective Security (NTA-P) is the
National Protective Security Authority (NPSA) is the successor organisation to CPNI, but retains some elements of information and cyber security that were not transferred to NCSC, including for Cyber Physical Systems (CPS), and for security containers, locks, and structures to protect assets
* The National Technical Authority for Technical Security (NTA-T) is the
UK National Technical Authority for Counter-Eavesdropping (UK NACE), which deals predominantly with countering technical surveillance
Civilian components
The role of Lead Government Department (LGD) for Cyber Security is currently fulfilled by the
Department for Science, Innovation, and Technology (DSIT), having previously rested with:
* The
Department for Culture, Media, and Sports (DCMS)
* The
Department for Business, Energy & Industrial Strategy
The Department for Business, Energy, and Industrial Strategy (BEIS) was a ministerial department of the United Kingdom Government, from July 2016 to February 2023.
The department was formed during a machinery of government change on 14 July ...
(BEIS)
* The Department for Business & Industrial Strategy (BIS)
* The Department for Trade and Industry (DTI)
All other government departments and ALBs will have staff in the government security function / government security profession, supporting both their internal staff, and their client communities.
Former bodies in this category include:
* The
Office of Cyber Security and Information Assurance (OCSIA) supports the Minister for the
Cabinet Office
The Cabinet Office is a Departments of the Government of the United Kingdom, ministerial department of the Government of the United Kingdom. It is responsible for supporting the Prime Minister of the United Kingdom, prime minister and Cabinet ...
, the Rt Hon
Francis Maude
Francis Anthony Aylmer Maude, Baron Maude of Horsham, (born 4 July 1953) is a British Conservative Party (UK), Conservative Party politician who served as Minister for the Cabinet Office and Paymaster General from 2010 to 2015. He also served ...
MP and the
National Security Council
A national security council (NSC) is usually an executive branch governmental body responsible for coordinating policy on national security issues and advising chief executives on matters related to national security. An NSC is often headed by a n ...
in determining priorities in relation to securing cyberspace. The unit provided strategic direction and coordinates action relating to enhancing cyber security and information assurance in the UK. The OCSIA was headed by James Quinault., but the function has been subsumed into the Government Security Group.
Defence components
The
Ministry of Defence
A ministry of defence or defense (see American and British English spelling differences#-ce.2C -se, spelling differences), also known as a department of defence or defense, is the part of a government responsible for matters of defence and Mi ...
has primacy for information and cyber security within both its civilian and military staffs (approximately 250,000 personnel), and for the Defence Supply Base (DSB - approximately 30,000 companies).
It has two main security organisations:
* The Directorate of Security and Resilience (DSR), predominantly focused on physical and personnel security
* The Directorate of Cyber Defence and Risk (CyDR), predominantly focused on information and cyber security
These organisation work collaboratively to publish not only the internal rules, but also
Defence Standards
Defense or defence may refer to:
Tactical, martial, and political acts or groups
* Defense (military), forces primarily intended for warfare
* Civil defense, the organizing of civilians to deal with emergencies or enemy attacks
* Defense indust ...
and Industry Security Notices (ISN)
In April 2016, the MOD announced the creation of the Cyber Security Operations Centre (CSOC) with a budget of over £40 million. It is located at
MoD Corsham.
MOD collaborates with the DSB over information and cyber security matters through a number of organisations, including:
* Defence Cyber Protection Partnership (DCPP)
Former bodies in this category include:
* DIPCOG, the Defence Infosec Product Co-Operation Group
National Cyber Force (NCF)
The
National Cyber Force
The National Cyber Force (NCF) is intended to consolidate offensive cyber activity in the United Kingdom, by enabling an offensive capability to combat security threats, hostile states, terror groups, extremism, hackers, disinformation and elect ...
consolidates offensive cyber capabilities from the
Ministry of Defence
A ministry of defence or defense (see American and British English spelling differences#-ce.2C -se, spelling differences), also known as a department of defence or defense, is the part of a government responsible for matters of defence and Mi ...
and
GCHQ
Government Communications Headquarters (GCHQ) is an intelligence and security organisation responsible for providing signals intelligence (SIGINT) and information assurance (IA) to the government and armed forces of the United Kingdom. Primar ...
.
Law Enforcement
The
National Crime Agency
The National Crime Agency (NCA) is a Law enforcement agency#natlea, national law enforcement agency in the United Kingdom. It is the UK's lead agency against organised crime; Human trafficking, human, Arms trafficking, weapon and Illegal drug t ...
(NCA) hosts the law enforcement cyber crime unit, incorporating the
Child Exploitation and Online Protection Centre
A child () is a human being between the stages of birth and puberty, or between the developmental period of infancy and puberty. The term may also refer to an unborn human being. In English-speaking countries, the legal definition of ''child ...
.
Former bodies in this category include:
* National High Tech Crime Unit (NHTCU)
Wider Public Sector
Within the WPS, there are a number of collaborative bodies, including:
* Assurance Specialism Advisory Group (ASAG), which runs the
SUAC series of Conferences
* Cyber Technical Advisory Group (CTAG), formerly the Public Sector IA Coordination Group (PSIACG)
Regulatory bodies
Two regulatory bodies have a specific cyber security related function:
* The Information Commissioner's Office (
ICO
is a 2001 action-adventure game developed and published by Sony Computer Entertainment for the PlayStation 2. It was designed and directed by Fumito Ueda, who wanted to create a minimalist game based on a "boy meets girl" concept. Originally ...
), leading on Data Protection (DP) for Personally Identifiable Information (PII)
*
OFCOM
The Office of Communications, commonly known as Ofcom, is the government-approved regulatory and competition authority for the broadcasting, internet, telecommunications and mail, postal industries of the United Kingdom.
Ofcom has wide-rang ...
, leading on telecommunications and broadcast aspects of security
Most other regulatory bodies will have staff covering information and cyber security function for both their internal staff, and their client communities.
Professional bodies
*
Association of Cyber Forensics and Threat Investigators
Association may refer to:
*Club (organization), an association of two or more people united by a common interest or goal
*Trade association, an organization founded and funded by businesses that operate in a specific industry
*Voluntary associatio ...
(ACFTI).
*
British Computer Society
image:Maurice Vincent Wilkes 1980 (3).jpg, Sir Maurice Wilkes served as the first President of BCS in 1957.
The British Computer Society (BCS), branded BCS, The Chartered Institute for IT, since 2009, is a professional body and a learned ...
(BCS) is a professional body and a learned society that represents those working in information technology both in the United Kingdom and internationally. It has a security, data and privacy group.
*
Business Continuity Institute
The Business Continuity Institute (BCI) was established in 1994 by Andrew Hiles and others, evolving from the Survive Group - a network of disaster recovery and business continuity experts. The Institute's initial vision was to enable individual m ...
(BCI) was established in 1994 to enable individual members to obtain guidance and support from fellow business continuity practitioners. BCI has a six certification standards to ensure individual practitioners literacy in organizations, responses, and other strategies.
*
Council of Registered Ethical Security Testers (CREST) is a Not for profit accreditation and certification organization. CREST does not have its own study material and leverage on third party coursework so that the member can become certified. As of 24/8/2022, the cost of CREST membership is 5000GBP for membership of one country chapter and 25000GBP for a regional membership. On two occasions between 2012 and 2014, the examination-related activities of one of more NCC Group employees and candidates breached the CREST Code of Conduct and NCC Group was, as their employer, vicariously responsible for those individuals at the time
Industry groups
*
ADS is a trade organisation for companies operating in the UK aerospace, defence, security and space industries.
*
Asset Disposal & Information Security Alliance, ADISA
*
Crypto Developers Forum (CDF)
*
IT Security Forum
*
Law Society
*
Nominet
*
Tigerscheme is a commercial certification scheme for technical security specialists, backed by university standards and covering a wide range of expertise. Tigerscheme is CESG certified in the UK and candidates are subject to an independent rigorous academic assessment authority. Tigerscheme was founded in 2007 on the principle that a commercial certification scheme run on independent lines would give buyers of security testing services confidence that they were hiring a recognised and reputable company. In June 2014 the operational authority for Tigerscheme was transferred to USW Commercial Services Ltd.
*
UK Cloud Pooled Audit Group (UK CPAG) is a membership organisation consisting of the UK's largest banks. Established in 2020 with a mission to use the collective power of the banks to audit Cloud Service Providers such as Google, Amazon and Microsoft. The group is operated by the
Worshipful Company of Information Technologists
The Worshipful Company of Information Technologists, also known as the Information Technologists' Company, is one of the livery company, livery companies of the City of London. The company was granted livery status by the Court of Aldermen on ...
*
UK Cyber Security Forum is a social enterprise representing cyber SME's (Small and Medium Enterprise) in the UK. The forum is composed of 20 regional cyber clusters around the UK. Each cluster is run as a subsidiary of the UK Cyber Security Forum and all are operated by groups of volunteers. They provide events around the UK to engage the public in
cyber security
Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
and to provide continued professional development to cyber professionals. The official clusters are:
Cross-sector bodies
Current bodies that cover multiple sectors include:
*
British Standards Institution
The British Standards Institution (BSI) is the Standards organization, national standards body of the United Kingdom. BSI produces technical standards on a wide range of products and services and also supplies standards certification services ...
(BSI), the UK's National Standards Body (NSB), which not only produces British Standards (BS) and Publicly Available Specifications (PAS) in the areas of Information and Cyber Security, but also provides the UK interface into international Standards Development Organisations (SDO), including ISO, IEC, ITU-T, CEN, CENELEC, and ETSI. The main Expert Committees for BSI relevant to these topic are IST/33 (Information and Cyber Security) and ICT/003 (Trustworthy Systems)
*
Trustworthy Software Foundation (TSFdn) which is a UK public good activity aimed to encouraging good proactive in systems specification, realisation, and use, and providing related independent Organisational and Solution Conformity Assessments. It arose from the
Trustworthy Software Initiative (TSI), previously the Software Security, Dependability and Reliability Initiative (SSDRI), and the Secure Software Development Partnership (SSDP), which were sponsored
*
UK Cyber Security Council
* Warning, Advice and Reporting Points (
WARP
Warp, warped or warping may refer to:
Arts and entertainment Books and comics
* WaRP Graphics, an alternative comics publisher
* ''Warp'' (First Comics), comic book series published by First Comics based on the play ''Warp!''
* Warp (comics), a D ...
s) provide a trusted environment where members of a community can share problems and solutions.
Former bodies in this category include:
* Cyber Security Knowledge Transfer Network (CS KTN), as sponsored by Innovate UK (formerly the Technology Strategy Board)
*
Information Assurance Advisory Council (IAAC) worked across industry, government and academia towards ensuring the UK's information society has a robust, resilient and secure foundation. The IAAC was set up by
Baroness Neville-Jones who chaired the organisation until 2007, handing over to the current chairman Sir
Edmund Burton
Lieutenant-General Sir Edmund Fortescue Gerard Burton KBE (born 20 October 1943) is a former British Army officer who became Deputy Chief of the Defence Staff (Systems).
Military career
Educated at Cheltenham College and Trinity Hall, Cambrid ...
. Affiliates include
BT Group
BT Group plc (formerly British Telecom) is a British Multinational corporation, multinational telecommunications holding company headquartered in London, England. It has operations in around 180 countries and is the largest provider of fixed-li ...
,
Northrop Grumman
Northrop Grumman Corporation is an American multinational Aerospace manufacturer, aerospace and Arms industry, defense company. With 97,000 employees and an annual revenue in excess of $40 billion, it is one of the world's largest Arms industry ...
,
QinetiQ
QinetiQ ( as in '' kinetic'') is a British defence technology company headquartered in Farnborough, Hampshire. It operates primarily in the defence, security and critical national infrastructure markets and run testing and evaluation capabili ...
,
Raytheon
Raytheon is a business unit of RTX Corporation and is a major U.S. defense contractor and industrial corporation with manufacturing concentrations in weapons and military and commercial electronics. Founded in 1922, it merged in 2020 with Unite ...
,
PwC
PricewaterhouseCoopers, also known as PwC, is a Multinational corporation, multinational professional services network based in London, United Kingdom.
It is the second-largest professional services network in the world and is one of the Big Fo ...
,
O2 UK
Telefonica UK Limited, trading as O2 UK (stylised as O2), is a British List of telephone operating companies#United Kingdom, telecommunications services provider. It is the List of mobile network operators of Europe#United Kingdom, largest mobi ...
,
Ultra Electronics
Ultra Electronics Holdings is a British defence and security company. It was listed on the London Stock Exchange and was a constituent of the FTSE 250 Index until it was acquired by Cobham, which is itself owned by Advent International.
The ...
and
GlaxoSmithKline
GSK plc (an acronym from its former name GlaxoSmithKline plc) is a British Multinational corporation, multinational Pharmaceutics, pharmaceutical and biotechnology company with headquarters in London. It was established in 2000 by a Mergers an ...
. The 2012/13 work programme focused on
consumerisation and its effects on information assurance.
* The
Information Assuarnce Coordination Group (IACG) was formed following the UK's national IA conference in 2006. The IACG encourages greater collaboration between the commercial supply base for
information assurance
Information assurance (IA) is the practice of assuring information and managing risks related to the use, processing, storage, and data transmission, transmission of information. Information assurance includes protection of the data integrity, inte ...
products and services operating within the UK public sector. The group maintained the UK information assurance community map, hosted on the CESG's web site. It has two co-chairs:
Colin Robbins of
Nexor
Nexor Limited is a privately held company based in Nottingham, providing products and services to safeguard government, defence and critical national infrastructure computer systems. It was originally known as X-Tel Services Limited.
History
N ...
and Ross Parsell of Thales. The IACG ceased operation in 2014.
* General IA Products and Service Initiative (GIPSI), which was largely replaced by NIAF
*
ITSafe (IT Security Awareness for Everyone) was a former government-funded organisation that provided alerts, which was subsumed into GetSafeOnline
*
NDI was a former government-funded organisation building supply chains for the MOD and manufacturers using SMEs in the United Kingdom.
See also
*
British intelligence agencies
The Government of the United Kingdom maintains several intelligence agencies that deal with secret intelligence. These agencies are responsible for collecting, analysing and exploiting foreign and domestic intelligence, providing military intell ...
br>
cyber security companies in uk
References
{{reflist, 25em
Computer security in the United Kingdom
Computer security organizations
Internet in the United Kingdom