← Back to Library
GCHQ 10 Steps

GCHQ 10 Steps to Cyber Security (2012)

Full Name:
Government Communications Headquarters (GCHQ) 10 Steps
Acronym:
GCHQ 10 Steps
Type:
Cyber Hygiene Standard
Organization:
Government Communications Headquarters (GCHQ)
Version:
2012 (Original)
Year Published:
2012
Popularity:
High (Historic Significance)

Overview of GCHQ 10 Steps (2012)

Published in 2012 by the UK Government's Communications Headquarters (GCHQ) through its CESG arm, the "10 Steps to Cyber Security" marked a pivotal shift in information security governance. Before this release, cybersecurity was largely treated as a technical IT problem. The 2012 guidance was one of the first global frameworks to explicitly target the board room, positioning cyber risk as a strategic business issue that required executive oversight.

The guidance was grounded in the finding that approximately 80% of known cyber attacks could be prevented by implementing basic cyber hygiene. By distilling complex technical security concepts into ten digestible, actionable areas, GCHQ empowered non-technical executives to ask the right questions, allocate appropriate budgets, and hold their technical teams accountable. This framework laid the groundwork for the UK's National Cyber Security Strategy and eventually led to the creation of the Cyber Essentials scheme.

The 10 Steps Framework Components

The framework is structured hierarchically: it establishes an overarching "Information Risk Management" regime which then governs nine specific technical and operational domains.

1. Information Risk Management Regime

This is the central pillar of the framework. It mandates that security cannot be achieved through technology alone but requires governance.

  • Board-Level Ownership: Establishing a governance structure where a board member is directly accountable for cyber risk.
  • Risk Appetite: Defining clear risk appetite statements to guide decision-making (e.g., what data must never be lost vs. what systems can tolerate downtime).
  • Policy Enforcement: Ensuring security policies are not just written but communicated and enforced throughout the organization.

2. Secure Configuration

Focuses on reducing the attack surface by hardening systems against vulnerabilities.

  • Baseline Builds: Developing and maintaining standard, secure images for all laptops, servers, and network devices.
  • Patch Management: Ensuring security patches are applied promptly to known vulnerabilities.
  • Removal of Unnecessary Functionality: Disabling unnecessary user accounts, software, and services (e.g., removing default games or disabling unused ports).

3. Network Security

Protecting the connections between the organization's internal systems and the internet.

  • Perimeter Defense: Using firewalls and gateways to filter traffic at the network boundary.
  • Internal Segmentation: Monitoring and controlling traffic moving within the network to prevent lateral movement by attackers.
  • Testing: Regularly testing security controls through penetration testing and vulnerability scanning.

4. Managing User Privileges

Restricting access rights to the minimum necessary (Least Privilege) to limit the impact of a compromised account.

  • Privileged Access Control: Strictly limiting the number of "admin" or "root" accounts.
  • Process Management: Ensuring formal processes for granting and revoking privileges, especially when staff change roles or leave.
  • Monitoring: heightened auditing of privileged user activity.

5. User Education and Awareness

Addressing the "human factor" in cybersecurity.

  • Policy Awareness: Ensuring all staff understand the Acceptable Use Policy (AUP).
  • Training Programs: Regular training on identifying social engineering, phishing, and secure working practices.
  • Reporting Culture: Encouraging staff to report incidents without fear of blame.

6. Incident Management

Preparing for the inevitable breach to minimize impact and recovery time.

  • Response Plans: Establishing clear plans for incident response and disaster recovery (DR).
  • Specialist Training: Ensuring the incident response team has the necessary skills and tools.
  • Reporting: Establishing channels to report criminal incidents to law enforcement (e.g., Action Fraud).

7. Malware Prevention

Defending against malicious software including viruses, worms, and spyware.

  • Anti-Malware Tools: Deploying antivirus software across all endpoints and keeping signatures updated.
  • Scanning: Scanning all incoming data (email, web traffic, removable media) for malicious content.
  • Policy: Restricting the installation of unapproved software.

8. Monitoring

Establishing visibility into network and system activity to detect attacks.

  • Logging: collecting logs from critical systems (firewalls, servers, proxies).
  • Analysis: Analyzing logs for "unusual" activity that could indicate a breach (e.g., massive data transfers at 3 AM).
  • Synchronization: Ensuring system clocks are synchronized (NTP) so logs can be correlated accurately.

9. Removable Media Controls

Managing the risk of data loss or malware introduction via USB drives and discs.

  • Policy Restrictions: Limiting the use of removable media to approved business cases.
  • Scanning: Automatically scanning any media connected to the corporate network.
  • Encryption: Ensuring data stored on removable media is encrypted to protect it if lost or stolen.

10. Home and Mobile Working

Securing data when it leaves the physical office, a domain that was nascent in 2012 but critical.

  • Data in Transit: Using VPNs and encryption to protect data moving over public networks.
  • Device Security: Ensuring mobile devices have the same "Secure Configuration" (Step 2) as office desktops.
  • Remote Wiping: Capability to erase lost or stolen devices remotely.

Applicability and Legacy

The 2012 guidance was universally applicable, designed to scale from small businesses to large multinational corporations. Its greatest legacy is the Cyber Essentials scheme launched in 2014, which codified five of these steps (Secure Configuration, Firewalls, Access Control, Malware Protection, Patch Management) into a verifiable standard.

While specific technical recommendations (such as password complexity rules) have evolved, the categorization of domains defined in 2012 remains the standard structure for UK cybersecurity guidance today, proving the foresight of the original authors.

Implementation Strategies

For organizations looking to understand the foundational logic of the 10 Steps:

Start with Governance: The primary lesson from 2012 is that without a risk management regime (Step 1), technical controls (Steps 2-10) are disjointed and less effective. Executive buy-in drives the budget and authority needed for the other 9 steps.

Focus on the "Basic 80%": The guidance emphasized that basic hygiene blocks the majority of opportunistic attacks. Prioritize patching, passwords, and malware protection before investing in advanced threat detection tools. This remains true today.

Relationship to Other Frameworks

  • Cyber Essentials: Derived directly from a subset of the 10 Steps. It focuses on the technical controls that mitigate the most common internet-based threats.
  • ISO 27001/27002: The 10 Steps provided a simplified, executive-friendly view of the comprehensive controls found in ISO standards, making them accessible to non-practitioners.

Common Challenges (2012 Context)

Board Engagement: In 2012, the biggest challenge was convincing boards that cyber was their responsibility. The guide was specifically written to bridge this gap, but cultural change was slow.

BYOD and Mobile: The "Home and Mobile Working" step was challenging as the iPhone and Android revolution brought consumer devices into the workplace faster than IT could secure them. Organizations struggled to balance security with the explosion of "Shadow IT."

Frequently Asked Questions

Is the 2012 version still valid for use today?

While the core principles remain sound, specific technical advice (especially regarding passwords, cloud security, and BYOD) has been superseded by later versions (2015, 2021). Organizations should use the latest NCSC 10 Steps (2021) for current implementation guidance.

Who authored the 10 Steps?

It was originally authored by CESG, the Information Security arm of GCHQ (Government Communications Headquarters). Responsibility for the guidance transferred to the National Cyber Security Centre (NCSC) upon its formation in 2016.

What was the main goal of the 2012 release?

The primary goal was to mainstream cybersecurity, moving it out of the server room and onto the boardroom agenda. It aimed to demonstrate that good security protects business value, intellectual property, and reputation, rather than just being a cost center.