The UK Government's Cabinet Office has received a broadside from The National Audit Office (NAO) which has sharply criticised it over failings in how it set up the National Cyber Security Programme that mean it may struggle to meet its goals
The NAO believes the Cabinet Office took its eye off the ball when it established the National Cyber Security Programme almost three years ago, and the government now does not know whether it will be able to meet the programme’s goals, or adequately protect UK citizens, businesses and infrastructure from cyber attacks after 2021.
The NAO said it was unclear whether or not the programme, which was designed to establish a “focal point” for cybersecurity activity across government, would achieve any of its wider strategic outcomes by 2021.
This was not only due to the difficulty of dealing with the ever-changing and complex cybersecurity landscape but also because the Cabinet Office had not properly assessed whether the £1.3bn of funding – out of £1.9bn of funding allocated to the National Cyber Security Strategy – set aside for the programme was sufficient.
The NAO said the programme’s work was delayed after a third of its planned funding was redirected to some of the UK’s wider national security needs, such as counter-terrorist work. This set back crucial work to understand cybersecurity issues.
“Improving cybersecurity is vital to ensuring that cyber attacks don’t undermine the UK’s ability to build a truly digital economy and transform public services. The government has demonstrated its commitment to improving cybersecurity,” said NAO chief Amyas Morse.
“However, it is unclear whether its approach will represent value for money in the short term and how it will prioritise and fund this activity after 2021. The government needs to learn from its mistakes and experiences to meet this growing threat.”
MP Meg Hillier, chair of the Public Accounts Committee (PAC), said the programme was another example of an important government initiative being launched without getting the basics right.
“There were serious weaknesses in its initial set up, undermining its contribution to government’s overall cybersecurity strategy,” she said.
“The increasing cyber threat faced by the UK, and events such as the 2017 WannaCry attack, make it even more critical that the Cabinet Office take immediate action to improve its current programme and plan for safeguarding our cybersecurity beyond 2021.” Cabinet Office over failings in how it set up the National Cyber Security Programme that mean it may struggle to meet its goals."
65000 GDPR Data Breaches In Europe To Date
European privacy authorities have received almost 65,000 data breach notifications since the EU's new privacy law went into full effect. In addition, regulators in 11 European countries have imposed $63 million in General Data Protection Regulation fines.read more
More than half of British firms 'report cyberattacks in 2019'
The proportion of UK firms reporting a cyberattack has jumped, despite most businesses admitting they are under-prepared for breaches, according to research from Hiscox reported by the BBC. The insurer found 55 per cent had faced an attack in 2019, up from 40 per cent last year.read more
Sloppy IT Processes Risk Cyberattacks - McAfee
McAfee this week published a report that turns familiar survey findings on their heads by reporting that most cybersecurity breaches are the result of lax IT processes rather than mistakes made by end users.read more
Cybercrime Soaring Reports MalwareBytes
Cybercrime is accelerating at a worrying rate, reports MalwareBytes in its Q1 2019 report. Every quarter that goes by shows more alarming data as to how much cybercrime activity is going on out there, with organizations and companies being called to face and deal with an increasing amount of threats, coming literally from everywhere.read more