Science & Technology

Government Cyber Profession Arrives, and Passwords Seek Promotion

A new Government Cyber Profession promises faster public sector fixes, while Britain’s security patches begin preparing for promotion.

One laughing adult cyber analyst is seen from above at a curved desk in a modern public-sector operations room with generic, unreadable dashboards.
A photorealistic overhead satirical scene of a cyber analyst enjoying an unusually prompt security fix.

The Government Cyber Profession has launched to protect public services, giving Britain’s security patches what they have long lacked: a career structure, professional standards and the faint possibility of being taken seriously at appraisal time.

The new vulnerability monitoring service scans public sector internet facing systems and alerts organisations when it finds trouble. The official announcement says the median time to fix domain related vulnerabilities has fallen from 50 days to eight. At last, a security weakness can enjoy a shorter wait before someone decides it belongs to another team.

The service covers around 6,000 public sector bodies and detects roughly 1,000 types of cyber vulnerability. It also tracks issues until they are resolved, which is the digital equivalent of standing beside a colleague’s desk until they finally read the message marked urgent.

The announcement says the backlog of critical open domain related vulnerabilities has fallen by 75 per cent. This does not mean every public computer has become invincible. It means one important category of weakness is being dealt with faster, leaving fewer opportunities for attackers to redirect users, steal data or interrupt services.

That distinction will be preserved with the care usually reserved for a ministerial footnote. Britain has not defeated cybercrime. It has improved the national ability to notice a hole in the wall before appointing a panel to consider whether the hole supports the wall’s strategic objectives.

The new Cyber Profession is intended to recruit and retain skilled staff through a career framework, a resourcing hub, an academy, apprenticeships and structured progression. The North West will serve as a primary hub, giving cyber specialists a place to develop their talents while government develops the campus, the pathway and presumably the meeting about the pathway.

This should help public bodies find people who understand DNS, vulnerabilities and the difference between a warning and a decorative red light. It may even persuade experts to remain in government rather than join a company whose security policy is not naming the shared folder EVERYTHING.

The service still depends on organisations acting when an alert arrives. A scanner can identify a weakness, explain the repair and monitor progress. Then responsibility returns to humans, the only known technology capable of placing an urgent cyber problem in a spreadsheet called to review later.

So the state has built a faster way to find danger, a profession to manage it and a system to track the repair. The remaining vulnerability is the person who receives all three and schedules a meeting to discuss opening the email.

Source: Department for Science, Innovation and Technology and National Cyber Security Centre.

Topics

The Lawn newsletter

Get The Weekly Cut

Three sharp stories. One gem from the archive. Delivered every Friday.

Free. Unsubscribe any time. Read the Privacy Statement

Illustrative edition of The Weekly Cut
Illustrative edition

Read next