{"id":38186,"date":"2022-07-05T04:00:00","date_gmt":"2022-07-05T04:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/38186"},"modified":"2022-07-05T04:00:00","modified_gmt":"2022-07-05T04:00:00","slug":"ncsc-ceo-why-we-should-run-towards-crises-to-elevate-cyber-security","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=38186","title":{"rendered":"NCSC CEO: Why we should run towards crises to elevate cyber security"},"content":{"rendered":"<p><a href=\"https:\/\/www.ncsc.gov.uk\/\">National Cyber Security Centre<\/a> (NCSC) CEO Lindy Cameron has spent her life running towards crisis after crisis. Growing up in Northern Ireland during the Troubles has, she says, \u201cprobably given me a slightly unhealthy interest in conflict and crisis\u201d.<\/p>\n<p>Healthy or not, this interest has served her well as a foundation for a career that has spanned the world of national security. In stints spent at what was then the Department for International Development, the Foreign Office and the Cabinet Office, Cameron worked both in Iraq and in Afghanistan, where she ran the Helmand Provincial Reconstruction Team.<\/p>\n<p>\u201cThe unifying theme above all has been <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/crisis-management\/\">crisis leadership<\/a>,\u201d she says. \u201cA lot of my international development career was focused on understanding conflicts and crises and leading through them.<\/p>\n<p>\u201cThe other theme I suppose has been systems leadership. I\u2019ve often been in a part of the system where you don\u2019t get to just assert your leadership and tell people what to do, but you have to bring people with you.<\/p>\n<p>\u201c[In Helmand] I had a wide international team, so there\u2019s been a theme of being able to pull people together across the system and get them to work as a team for the greater good of the organisation.<\/p>\n<p>\u201cThen the third bit has been the international perspective. Although this is a job which is very much focused on keeping the UK the safest place to live and work online, it is understanding that international context of how geopolitics changes that.\u201d<\/p>\n<p>Any cyber security leader will recognise this wealth of experience as highly relevant to their work, and it is fair to say it stood Cameron in good stead <a href=\"https:\/\/www.computerweekly.com\/news\/252486758\/NCSC-names-national-security-expert-Lindy-Cameron-as-new-CEO\">when she arrived at the NCSC in 2020<\/a>, right in the thick of the biggest public health crisis to hit the UK in living memory.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"The wake-up call\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>The wake-up call<\/h3>\n<p><a href=\"https:\/\/www.computerweekly.com\/news\/252480238\/Coronavirus-now-possibly-largest-ever-cyber-security-threat\">Covid was indeed a unique challenge<\/a> to face when taking up a new role, but perhaps not in the ways you might expect. Cameron explains: \u201cI am a crisis veteran. I have always tended to run towards crises rather than away from them. Not much keeps me awake at night, and it\u2019s not as if I was worried about Covid in terms of a professional challenge.\u201d<\/p>\n<p>The challenge was more of a personal one. Getting to know a new organisation during Covid required her to flex different muscles and adapt to a new style of learning.<\/p>\n<p>\u201cIt\u2019s been a real lesson in actually probably personal learning style,\u201d says Cameron. \u201cI\u2019ve really reflected, looking back, on how much I learned by just watching the context and understanding the conversations that were going on around me.\u201d<\/p>\n<p>In December 2020, shortly after taking charge of the NCSC, Cameron was faced with the ultimate on-the-job lesson when a Russian state-backed cyber attack <a href=\"https:\/\/www.computerweekly.com\/news\/252507279\/The-Security-Interviews-How-SolarWinds-came-through-its-darkest-hour\">exploiting SolarWinds\u2019 network management technology<\/a> compromised the systems of multiple organisations around the world.<\/p>\n<div class=\"imagecaption alignLeft\"> <img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/ncsc-ceo-why-we-should-run-towards-crises-to-elevate-cyber-security.jpg\" alt> <\/div>\n<blockquote>\n<p><span><strong>\u201cThe unifying theme above all has been crisis leadership\u201d<\/strong><\/span><br \/><span><em>Lindy Cameron, NCSC<\/em><\/span><\/p>\n<\/blockquote>\n<p>It has become a clich\u00e9 in the security world to talk of \u201cwake-up calls\u201d, but in a very real sense, this was exactly what SolarWinds provided.<\/p>\n<p>Cameron describes the attack as a very powerful reminder, both to governments and private sector organisations, that although we rightly treat ransomware as the most pressing threat, the role of state advanced persistent threat (APT) groups in large-scale cyber attacks is often overlooked.<\/p>\n<p>But because SolarWinds gave people cause to think about the wider threat landscape, their own exposure to it, and the nature of the risks they faced, in effect it elevated the cyber conversation, says Cameron.<\/p>\n<p>\u201cIt wasn\u2019t so much a lightbulb moment, it was more a moment of realising it was an opportunity to really move this onto the mainstream agenda,\u201d she says.<\/p>\n<p>\u201cThat was followed quite closely by <a href=\"https:\/\/www.computerweekly.com\/news\/252500508\/Colonial-Pipeline-ransomware-attack-has-grave-consequences\">Colonial Pipeline about six months later<\/a> in a way that reminded governments that a major incident \u2013 in theory to a private sector company \u2013 in the critical national infrastructure [CNI] space, actually didn\u2019t remain private sector for long \u2013 it suddenly became an incident of national significance.<\/p>\n<p>\u201cFor me, that connected the cyber security world with the world I\u2019m very comfortable in, which is the world of understanding threats to the UK and understanding how we then respond and what we do about it.\u201d<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Cyber goes pop\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Cyber goes pop<\/h3>\n<p>Since Cameron took over at the NCSC, a series of incidents, from the continuing Covid pandemic to SolarWinds, from Colonial Pipeline <a href=\"https:\/\/www.computerweekly.com\/news\/252503600\/About-60-Kaseya-customers-hit-by-REvil\">and Kaseya<\/a> during the spring and summer of 2021 <a href=\"https:\/\/www.computerweekly.com\/news\/252510860\/What-is-Log4Shell-and-why-are-we-panicking-about-it\">to Log4Shell last Christmas<\/a>, and since February 2022, <a href=\"https:\/\/www.computerweekly.com\/news\/252516466\/Russia-plumbs-new-depths-in-cyber-war-on-Ukraine\">to Russia\u2019s war on Ukraine<\/a>, has elevated cyber in the minds of not just organisational leadership and security professionals, who have been tested in their approaches to risk and crisis management, but the wider public, too.<\/p>\n<p>Indeed, just hours after our conversation, Channel Four premiered the first episode of a new prime-time cyber drama, <em><a href=\"https:\/\/www.channel4.com\/programmes\/the-undeclared-war\">The Undeclared War<\/a><\/em>, which portrays a fictionalised version of an NCSC-like unit operating within GCHQ.<\/p>\n<p>However, Cameron says she is not particularly surprised to see security entering the public discourse. \u201cI suppose partly because, with the wider experience I\u2019ve got, I\u2019ve seen people get really interested in the security world, in different aspects, whether it\u2019s a humanitarian crisis or whether it\u2019s counter-terrorism and organised crime,\u201d she says.<\/p>\n<p>\u201cI think in some ways you have to take advantage of the fact that people want to have that conversation and use it to try to shape the debate. One of the great things about that drama is that people will be sitting there thinking: what would I do if that happened to me? Of course it\u2019s a drama, so it will be dramatised, but I think getting that conversation going really matters.\u201d<\/p>\n<p>The challenge now, says Cameron, is to break that conversation out of a technical space and make it accessible to everyone, from organisational leadership to the average consumer.<\/p>\n<p>\u201cThis should be no more challenging for CEOs than talking to their general counsel about the legal challenges the organisation faces or talking to their CFO about the financial risks the organisation faces,\u201d she says. \u201cWe would expect CEOs to have a general understanding of the kinds of risk, but not for this to be shrouded in a level of technical language that means they feel disconnected.\u201d<\/p>\n<p>There is some responsibility on both sides, both towards CEOs to run towards the problem and ask the right questions to ensure they can understand what a cyber attack will feel like and what is the worst day they can possibly have, but also towards the security community not to answer those questions with an inaccessible lecture.<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cSome of these crises are teachable moments, but the onus is on us to try to communicate effectively\u201d <\/figure><figcaption> <strong>Lindy Cameron, NCSC<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p>\u201cI think we could do with doing a bit more of that,\u201d says Cameron. \u201cSome of these crises are teachable moments, but the onus is on us to try to communicate effectively and one of the things I am incredibly proud about the NCSC having done is actually trying to have that conversation with every sector.<\/p>\n<p>\u201cFor example, some of the best advice we\u2019ve given has been to farmers worrying what to do when their <a href=\"https:\/\/www.gov.uk\/government\/collections\/basic-payment-scheme\">Single Farm Payment<\/a> comes through, making sure they are not vulnerable to cyber criminals who see them as a risk in that moment.<\/p>\n<p>\u201cWe target the guidance to people when they need it in a way that they can understand that and that is partly why we work with sectors to try to understand what it looks like from the sector\u2019s perspective, as well as what it looks like from the expert\u2019s perspective. Our advice is informed by deep understanding of the threat, brilliant technical guidance and what to do about it, but then actually understanding what the customer wants and needs that helps them fix it or respond to it.\u201d<\/p>\n<p>When it comes to threats to consumers, one of the things that sets the NCSC apart from many of its international peers is that it takes these just as seriously as high-end national security systems.<\/p>\n<p>This is partly because a thousand small cuts can be as harmful to the body of the country as one big one, but also because it is in the UK\u2019s best interests to make sure everyone can confidently engage with technology and get the best out of it. Not for nothing is the NCSC very keen on the government line \u201c<a href=\"https:\/\/www.ncsc.gov.uk\/cyberaware\/home\">making the UK the safest place in the world to live and work online<\/a>\u201d.<\/p>\n<p>Getting this right is very important because the things that we do and learn in our personal lives can have a very meaningful effect on our professional ones, something that is not lost on Cameron. \u201cMy dad was a personnel manager,\u201d she says, \u201cand so I was subjected to quite a lot of excellent health and safety advice as a child on wearing my seatbelt in the car because all the evidence showed you that you were safer at work if you also behave sensibly in your car.<\/p>\n<p>\u201cThe way we behave with our own personal tech affects the way we behave at work. Better-educated employees, frankly, look after their own personal tech vulnerabilities better, and similarly, if you are nudged to do the right thing in your Gmail account or your bank account, then you\u2019ll be a more responsible employee who is less likely to click on a dubious link.\u201d<\/p>\n<p>The good news is that the public does respond to <a href=\"https:\/\/www.computerweekly.com\/news\/252487589\/Ed-Sheeran-is-not-promoting-investment-opportunities-says-NCSC\">the kind of outreach the NCSC engages in<\/a>. Indeed, one of the more exciting parts of the job, says Cameron, has been watching how they do so, such as by using the Suspicious Email Reporting Service (SERS), <a href=\"https:\/\/www.computerweekly.com\/news\/252481850\/NCSC-launches-coronavirus-cyber-security-campaign\">launched at the height of the pandemic<\/a>, which allows people to pass on phishing, scam and spam emails to the NCSC for analysis and action.<\/p>\n<p>SERS has been a huge success, <a href=\"https:\/\/www.computerweekly.com\/news\/252514743\/NCSC-catches-10-million-phishes\">with millions of emails received<\/a>, and the NCSC is now considering how to do similar initiatives to tackle other online harms, such as fraud, with its government partners.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Running up that hill\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Running up that hill<\/h3>\n<p>With a constantly evolving threat landscape amid the most challenging geopolitical upheaval the UK has faced since the Second World War, any cyber professional worth their salt will always have an eye on the future.<\/p>\n<p>\u201cThis is definitely one of those big generational challenges,\u201d says Cameron. \u201cIf I was to think about things that kept me up at night, it\u2019s not so much the immediate nightmares, but more the long-term ones.\u201d<\/p>\n<p>Acknowledging that, ultimately, cyber is as much a human issue as a technological one, Cameron says one of her biggest priorities right now is to leave the security skills landscape in better condition than she found it. In 10 years\u2019 time, she wants her successor to look back and be able to say that the NCSC did the right thing today, not just to make sure it has the talent it needs within its ranks, but more widely, that the UK\u2019s burgeoning cyber industry <a href=\"https:\/\/www.computerweekly.com\/opinion\/We-must-target-a-broad-church-to-fill-vacant-cyber-roles\">has the talent it needs<\/a>, and that its citizens know how to keep themselves safe online.<\/p>\n<p>In terms of addressing the security skills gap, the NCSC has been at the forefront of investing in building careers in cyber today, through its support of startups such as retraining specialist <a href=\"https:\/\/capslock.ac\/\">Capslock<\/a>, or the work of organisations such as the <a href=\"https:\/\/www.ukcybersecuritycouncil.org.uk\/\">UK Cyber Security Council<\/a>, which seeks to raise standards across the security profession.<\/p>\n<p>Meanwhile, for the cyber pros of tomorrow, the NCSC\u2019s work with young people, <a href=\"https:\/\/www.computerweekly.com\/news\/252502983\/NCSC-recognises-cyber-degree-apprenticeships-for-the-first-time\">its support of cyber security degrees<\/a>, bursaries, summer holiday code camp programmes, and in particular the annual <a href=\"https:\/\/www.ncsc.gov.uk\/cyberfirst\/girls-competition\">CyberFirst Girls<\/a> contest, has set a gold standard that other tech sectors can learn from.<\/p>\n<p>\u201cI was very pleased to see that almost half <a href=\"https:\/\/www.computerweekly.com\/news\/252520853\/UKtech50-2022-Vote-for-the-most-influential-person-in-UK-technology\" target=\"_blank\" rel=\"noopener noreferrer\">the UKtech50 shortlist<\/a> was female this year,\u201d says Cameron. \u201cAnd I think there is something about not missing the amazing female talent out there, making sure that talent also reflects the society we live in.<\/p>\n<p>\u201cBut as technology shapes the world we live in, we need the workforce working on that to be a diverse workforce that understands how that affects everybody. Because, as we said, this is about how humans interact with it as well. So if we are narrow-minded about the workforce, we are narrow-minded about the opportunity.\u201d<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cAs technology shapes the world we live in, we need the workforce working on that to be a diverse workforce that understands how that affects everybody\u201d <\/figure><figcaption> <strong>Lindy Cameron, NCSC<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p>She adds: \u201cOne of the nicest things I did this year was I was going to hand out the prizes at the CyberFirst Girls competition. It was kind of the first out-of-school activity they\u2019d had in two years of secondary school through Covid and so they were all disproportionately excited. But one of the really lovely things for me, a quite humbling thing, was there were a couple who were physically excited to see some senior women in the industry and there was a sense that they could imagine themselves there in the future in a way that, if they just look at an industry and see people who don\u2019t look like them, they won\u2019t have a chance to do.\u201d<\/p>\n<p>The second generational challenge, says Cameron, is how we still \u201cdo\u201d cyber security in the long run, particularly in the face of the changing geopolitical situation.<\/p>\n<p>One of the NCSC\u2019s clearly defined roles is to think about the problems that others do not, marrying its technical expertise with the intelligence expertise that being part of GCHQ brings, as well as <a href=\"https:\/\/www.computerweekly.com\/news\/252521308\/SolarWinds-CEO-offers-to-commit-staffers-to-government-cyber-agencies\">drawing on the security community itself.<\/a><\/p>\n<p>\u201cI don\u2019t think I\u2019ve ever seen government and the private sector working so well together as I\u2019ve seen in this organisation \u2013 it is absolutely world-leading,\u201d says Cameron. \u201cBut the question is, will that be enough to then understand the technology of the future and how that will shape cyber security and particularly the changing geopolitical context?<\/p>\n<p>\u201cA lot of the technology of the past has been developed on the West Coast of the US \u2013 that won\u2019t be the case as much in the future. The question is, will we understand it as well? Are we setting up the standards bodies? The governance? Are we helping to shape it in a way that means we will be able to give the UK public confidence?<\/p>\n<p>\u201cThat requires not only carrying on running towards the problems we understand now, but we also need to think about how the world will change in the next decade and what that will mean for cyber security.\u201d<\/p>\n<p>Happily, Cameron reckons the UK is in a good place here. With the NCSC acting as team captain, we started running up that hill much earlier and more effectively than others, she says, and this is evidenced by the emergence of more bodies that are running in the same direction \u2013 bodies such as the <a href=\"https:\/\/www.gov.uk\/government\/publications\/government-cyber-security-strategy-2022-to-2030\">Government Security Group<\/a>, spearheaded by national security adviser <a href=\"https:\/\/www.gov.uk\/government\/people\/stephen-lovegrove\">Stephen Lovegrove<\/a> and Civil Service COO <a href=\"https:\/\/www.gov.uk\/government\/people\/alex-chisholm\">Alex Chisholm<\/a>.<\/p>\n<p>\u201cWe need to make sure we are not just responding to the huge demand we get from everybody else \u2013 different sectors, telecoms, etc,\u201d she concludes. \u201cWe all need to be thinking about the issues that nobody else has thought about yet, and that, I think, is the big challenge going forward \u2013 but it\u2019s a really fascinating one. I wouldn\u2019t miss it for anything.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>National Cyber Security Centre (NCSC) CEO Lindy Cameron has spent her life running towards crisis after crisis. Growing up in Northern Ireland during the Troubles has, she says, \u201cprobably given me a slightly unhealthy interest in conflict and crisis\u201d. Healthy or not, this interest has served her well as a foundation for a career that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":38187,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-38186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/38186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=38186"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/38186\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/38187"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=38186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=38186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=38186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}