In the 16+ years Arcanum has been operating, we have done all sorts of cyber security jobs for all sorts of clients. Some have been large organisations, some small. Some have been in the Public Sector, some in the Private Sector. Some have been very profitable businesses, and some have been very small charities and not-for profit organisations. What did they have in common and why did they come to us? In a series of posts, we will explore the question ‘Why hire a cyber security consultancy?’ Looking back at our records, we’ve worked out that, although there is no single reason, there are some common themes; specialist expertise required, fear, incident response, frameworks, training, compliance and risk management. In this post, cyber consultant Chris Kirkham shares his experience using the NCSC Cyber Assessment Framework.
I have worked with the NCSC’s Cyber Assessment Framework (CAF) across a number of sectors. Still a relatively new framework, many organisations are now just beginning to get to grips with it. For some sectors, such as critical national infrastructure or government departments the CAF process is mandatory. Others choose to adopt it in preparation for probable future regulatory requirements, or as a useful way of holistically understanding their own cyber resilience and where improvements should be applied. In 2022 I was lucky enough to support the Welsh Government in a pilot project to explore implementing the CAF for 15 local authorities and 3 regional emergency services. This was a unique opportunity to demonstrate the utility of the CAF process to a forward-looking sector, who had a range of diverse systems and challenges. Establishing the scope is a key element of the CAF. This is to ensure the businesses critical functions are effectively protected. With local authorities I quickly found out that all services were critical, if it isn’t important then they simply no longer had the capacity to do it. Some of those involved in the CAF pilot project were immediately keen to engage. Others were more reluctant, as they tentatively viewed it as just another regulatory process to go through. However, by the end all participants readily agreed that it had been an exceptionally useful process, which had helped clearly articulate their strengths and formed clear routes to improvement. The CAF contains what I like to refer to as ‘golden threads’. These are those key principles and themes such as governance, risk management, asset management or supply chain, that run throughout the framework. I focused how addressing gaps here would build firm foundations on which to develop targeted advancement and tangible improvements across many corresponding principles. By providing a mix of onsite step-by-step guided CAF completions and virtual CAF workshops, I was able to empower participants (who held that essential expert knowledge of their own organisations) to identify not only how they could reach attainment of the desired CAF profile, but also ensure continual improvement and ongoing independent gap analysis activity. Where I encountered a range of individuals taking part in the CAF from across the organisation (from senior management to technical support) this ensured the most effective approach. In many instances it was surprising to find that relevant and important conversations about risks being held had not previously been discussed in this way. Participants quickly identified gaps in their resilience measures and the candid conversations supported routes to more effective risk management. With some guidance participants were able to soon develop suitable and detailed justifications to support self-assessed contributing outcome attainments. This understanding of what is required prior to an assessment occurring placed those organisations in a much stronger position, allowing the time and resources required to address issues before an audit. I provided feedback on the results of the CAF submissions to both the individual local authorities and anonymised pan-sector findings to government. Thereby supporting the strengthening of cyber security at both local and national levels. It was rewarding to hear feedback in which the CAF had been successfully used to support internal business cases, targeted to improve organisational cyber security. Many participants told us that it was the most useful framework they had used to date, and that it had helped articulate their current security posture holistically across the organisation. Sometimes the breadth of challenges in improving an organisations cyber resilience can seem daunting. I firmly believe that for medium-to-large businesses, the CAF is one of the best processes available to focus efforts and establish a pathway to cyber security excellence.
— Arcanum is a Cyber Security Consultancy, a team of cyber security professionals who, although many have a deep specialisation in one area or another, like incident response, operational technology or security testing, all have a core of extremely competent knowledge of cyber risk management. If you’d like to talk to us about any aspect of managing your cyber risks, please get in touch. Read more from this series: Incident response planning Expertise and specialisation Employee training