
The National Cyber Security Centre has updated its '10 Steps to Cyber Security' guidance to address evolving technology and threats, focusing on risk management, training, asset management, and more, aimed at security professionals in medium to large organizations.
The '10 Steps to Cyber Security' guidance, originally crafted in 2012 by CESG, the predecessor of the National Cyber Security Centre (NCSC), has undergone significant updates to remain relevant in today's rapidly changing technological landscape. With the rise of cloud services and the shift towards remote work, the nature of cyber threats has also evolved, necessitating a fresh look at how organizations can protect themselves.
Since its inception, the guidance has seen a dramatic shift in the types of threats organizations face. Ransomware attacks, which can impact any sector regardless of size, have become increasingly prevalent. As our understanding of technology and human behavior has advanced over the past nine years, the NCSC recognized the importance of refreshing the '10 Steps to Cyber Security' guidance ahead of its 10th anniversary.
While the core structure of the guidance remains intact with ten steps, several updates have been made to ensure its relevance:
The revised '10 Steps to Cyber Security' is specifically aimed at security professionals and technical staff working for or supporting medium to large organizations. This guidance allows technical staff to delve deeper into specific areas by following links to more detailed NCSC resources. Additionally, it can be used in conjunction with the NCSC's 'Cyber Security Toolkit for Boards', published in 2019, which assists board members in discussions with technical experts about cyber security.
The updated guidance outlines the following ten steps:
The NCSC welcomes feedback on the updated guidance to ensure it remains relevant and useful for organizations. As we look forward to another decade of cyber security advancements, it is crucial for organizations to stay informed and proactive in their security measures. By following these ten steps, organizations can better protect themselves against the evolving landscape of cyber threats.