Annual Review 2025 launchCEO Richard Horne announces the NCSC's ninth Annual Review.
https://www.ncsc.gov.uk/speech/annual-review-2025-richard-horne-speech
(742자)
글로서리
1. Incident Management team : 사고 대응팀
2. NCSC: 영국 국가사이버안보센터
3. Shirine Khoury-Haq – the CEO of the Co-Op: 코옵(Co-op Group) 최고경영자 시린 쿠리-하크
4. Security Minister: 안보부 장관
5. Cyber Action Toolkit: 사이버 대응 툴킷
6. Cyber Essentials: 사이버 에센셜 (영국 정부의 최소 사이버보안 기준)
Last year, I spoke to you about the widening gap between the rising pace of the cyber threat and the UK’s collective resilience in facing that threat.
This year, that gap continues to grow.
So today, my message is simple: the time to act is now.
Over the past few weeks and months we have seen household names impacted by cyber incidents across all sectors of the economy… from retail to manufacturing and transport.
And those are just the incidents that have made the headlines.
While you may be able to recall a handful of specific stories... in the twelve months to the end of August this year, our Incident Management team was asked to support some 429 cyber incidents.
When we dig into those numbers, nearly half of all incidents that have crossed our desks have been of national significance.
Meaning that, on average, the NCSC has dealt with four nationally significant incidents a week.
And 18 were classed as ‘highly significant’,
Attacks which have a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.
That is a 50% increase on the previous year, and a marked increase for the third consecutive year.
Now it would be easy to look at these numbers, and think we’re under siege, that we should hold up our hands and admit defeat... but that is not the case.
We know that far far more cyber attacks fail than succeed.
That is not by chance.
It’s because organisations have built good defences.
We are also seeing more organisations able to continue in the face of an attack that does break through because they were prepared.
It can be done.
But we do see our attackers improving their ability to cause real impact…to inflict pain on the organisations they have breached and those who rely on them.
They don’t care who they hit or how they hurt them
That is why we need all organisations to act.
Cyber attacks are not just a matter of computers and data.
They impact growth, prosperity, safety, national security, reputations, operations, bottom lines, lives and livelihoods.
As Shirine Khoury-Haq – the CEO of the Co-Op – has said, there is nothing that can fully prepare you for the moment a cyber incident unfolds and you receive that phone call.
But worse than receiving that call is receiving it when you do not have a plan.
I’ve sat now in too many rooms with individuals who have been deeply affected by cyber attacks against their organisations.
I’ve seen the emotional impact written across their faces.
I know the impact the disruption has on their staff, suppliers and customers, the worry, the sleepless nights.
And the impact it has on the teams who work round the clock for weeks and months trying to put the pieces back together.
So, the time to act is now.
Every leader, whether you’re one person at your kitchen table or the boss of thousands of people, you must have a plan to defend against criminal cyber attacks
And...you must have a plan for continuity.
You must know how to keep going should an attack get through.
If your IT infrastructure was crippled tomorrow and all your screens went blank, could you run your payroll systems? or keep your machinery working? or stock your shelves?
If the answer is no, or more likely ‘don’t know’ act now.
Because when an attack does break through it is the strength of these pre-engineered solutions that determines an organisation’s ability to endure, respond, rebuild, survive.
And confronting that challenge of continuity should make clear to every leader that cyber security is a risk to be managed by the whole organisation led by the board, not one to just be delegated to technical experts.
Now nine years in, the NCSC’s mission is the same as it has always been: To make the UK the safest place to live and work online.
And we are continuing to support organisations to act now to secure themselves.
As you heard from the Security Minister, the new Cyber Action Toolkit that we are launching today will equip sole traders and small businesses to take their first steps toward cyber protection.
The UK’s minimum standard for cyber security, Cyber Essentials, is making it easier for organisations of all sizes, across all sectors to get basic foundational defences right.