Site navigation

UK Gov Unveils New Cyber Defence Code for Firms

Tom Quinn

,

Uk cybersecurity code of practice
“A successful cyber attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line,” said Feryal Clark, Cyber Security Minister.

Directors and company boards are being urged to shore up their cyber defences using guidance published today by the UK Government, in a bid to protect organisations from the growing tide of online threats.

The new Code of Practice is being launched by the UK’s Cyber Security Minister, Feryal Clark, and sets out how business leaders can protect their day-to-day operations, and bolster the Government’s plans for growth.

One of the actions included in the Plan is having a cyber strategy in place to ensure effective risk management that supports business resilience, while other key actions include promoting a ‘cyber secure’ culture, so employees know what to look out for, and putting incident response plans in place, allowing organisations to quickly respond to incidents.

The Government said that the Code provides direction for business leaders to take control of cyber risks which could quickly overwhelm unprepared firms. Research shows that a third of large businesses lack a formal cyber strategy, while nearly half of medium-sized firms are operating without an incident response plan in place.  

“A successful cyber attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line,” said Clark.

“If we want to drive the economic growth which is fundamental to our Plan for Change, then we need to stand side-by-side with British business leaders as they face down that threat.”

The Code has already received backing from across UK industry, including from the Institute of Directors, EY and consulting firm Wavestone, and forms the backbone of a new support package, developed in partnership with the National Cyber Security Centre and industry, which sets out actions boards should take to strengthen accountability and reduce risk.

The support package includes online training to help implement the new Code, along with a Board Toolkit designed to help businesses identify risks, protect critical assets and engage with supply chain partners.

Smaller businesses are also encouraged to engage with the NCSC’s Small Business Guide, and seek support in bolstering their defences through the Cyber Local scheme.

“In today’s digital world, where organisations increasingly rely on data and technology, cybersecurity is not just an IT concern – it is a business-critical risk, on a par with financial and legal challenges,” said Richard Horne, NCSC CEO.

“I urge all board members to engage with the new Cyber Governance resources unveiled today and make cyber security an integral part of their governance. Cybersecurity is a leadership imperative.”

Improving cybersecurity among business and industry has become a central part of the Government’s plans to drive growth across the country, with cyber threats costing the UK economy almost £22 billion a year between 2015 and 2019.


Recommended reading


Three-quarters (74%) of large businesses and 70% of medium-sized firms have reported experiencing cyber-attacks and breaches in the past year, with figures from Vodafone Business finding that inadequate cybersecurity measures are costing small and medium-sized enterprises in the UK £3.4 billion.

Last week, the Government unveiled the most significant cybersecurity legislative reform in years with the Cyber Security and Resilience Bill, designed to harden the nation’s defences against increasingly sophisticated digital threats.

The policy blueprint, released by Science and Technology Secretary Peter Kyle, contains three broad pillars of reform – expanding the regulatory safety net, new powers for security watchdogs, and measures for the Government to work outside the bounds of the normal legislative process to meet emerging threats.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data