1.Since 2010 the Government has categorised major cyber attacks on the UK and its interests as a top-tier threat to national security. This means that such an attack is highly likely and/or would also have a high impact.1 The impact of technology, and especially of cyber threats, was identified as one of the four “particular challenges … likely to drive UK security priorities for the coming decade” in the 2015 National Security Strategy and Strategic Defence and Security Review 2015 (2015 NSS & SDSR).2 Its importance was reaffirmed by the Government’s National Security Capability Review in March 2018.3

2.The past year has seen cyber attacks on the health, telecommunications, energy and government sectors in the UK.4 And although the UK has yet to suffer the most severe form of cyber attack—which the Government defines as an attack leading to the sustained loss of essential services, severe economic or social consequences, or a loss of life5—the head of the National Cyber Security Centre (NCSC), Ciaran Martin, has said this is a matter of ‘when’, not ‘if’.6 The May 2017 WannaCry attack, which affected NHS services for several days, should serve as a stark warning of the implications of such an attack for national security.

3.There are also important implications for the UK’s future prosperity—one of the three strategic objectives of the 2015 NSS & SDSR.7 The effects of a major cyber attack on a just-in-time economy should not be underestimated.8 Furthermore, the UK’s ability to reap many of the economic benefits of future technology such as internet-connected devices (the ‘Internet of Things’), automation and robotics will depend on robust cyber security—and, as importantly, public confidence in that cyber security.

4.Given the Government’s emphasis on cyber threats in the 2015 NSS & SDSR, as well as the string of high-profile cyber attacks in 2016 and 2017, we decided to launch an inquiry into the cyber security of critical national infrastructure (CNI) as our first inquiry of the 2017 Parliament.9 The Government has identified thirteen national infrastructure sectors that are essential to the functioning of daily life: chemicals; civil nuclear; communications; defence; emergency services; energy; finance; food; government; health; space; transport; and water.10 We set out to examine:

We published these terms of reference and a call for evidence for our inquiry in December 2017.11 Reflecting the weight of the evidence we received, our inquiry has focused primarily on issues relating to continuity of critical services, rather than the cyber-enabled theft of personal data or threats to democratic processes (which have been addressed by other Committees),12 although we recognise their significance. We also acknowledge the Government’s work to develop ‘cyber weapons’ under the National Offensive Cyber Programme but this was not an area covered by our inquiry.13

5.In February 2018 we held a private roundtable discussion on the cyber security of CNI, facilitated by techUK and attended by representatives of its member organisations.14 We took oral evidence in public from UK CNI operators (from representatives of the energy, transport and health sectors) as well as CNI-sector regulators and a trade body (representatives of the financial services, energy and communications sectors and the water sector, respectively). Our third evidence session focused on the shortage of essential cyber security skills.15 In June 2018 we took oral evidence from the Chancellor of the Duchy of Lancaster, Rt Hon David Lidington MP—the Cabinet Office Minister responsible for the delivery of the National Cyber Security Strategy 2016–2021 (2016 NCSS)—and Ciaran Martin, Chief Executive Officer of the NCSC. These two witnesses also gave us a private briefing after their evidence session.

6.This Report is the second of our inquiry. In July we published Cyber Security Skills and the UK’s Critical National Infrastructure, in which we concluded that

there are not enough people in the UK who both possess [the required] specialisms and are also willing and able to work in the CNI sector.16

Immediate and longer-term solutions must be found to this challenge. We are not reassured in this regard by the Government’s response to our Report on cyber security skills. Although positive in tone, it does not commit the Government to sufficient concrete action in the short term, with most of the initiatives referred to seemingly set to bear fruit towards the end of the next decade.17 Without a concerted, wide-ranging and creative effort to close the skills gap, this shortage in specialist skills and deep technical expertise will severely hinder the Government and the private sector in improving the UK’s CNI resilience to cyber threats at the pace required. The findings set out in this Report on the cyber security of CNI should be seen in that light.

7.We are grateful to all those who have provided written and oral evidence to our inquiry and to that of our predecessor Committee. We also thank our Specialist Adviser for the inquiry, Ewan Lawson, and our standing Specialist Advisers, Professor Malcolm Chalmers, Professor Michael Clarke and Professor Sir Hew Strachan, for their input.18

