← Back to Library
GCHQ 10 Steps

GCHQ 10 Steps to Cyber Security (2015)

Full Name:
Government Communications Headquarters (GCHQ) 10 Steps
Acronym:
GCHQ 10 Steps
Type:
Cyber Hygiene Standard
Organization:
Government Communications Headquarters (GCHQ)
Version:
2015 Update
Year Published:
2015
Popularity:
Moderate

Overview of GCHQ 10 Steps (2015)

The 2015 update to the GCHQ 10 Steps to Cyber Security reinforced the core message of the original 2012 guidance while significantly refining the technical advice to keep pace with a rapidly evolving threat landscape. Released alongside a UK government report showing a significant rise in cyber breaches, this version emphasized that cyber security had matured from an emerging issue to a critical risk that could threaten economic prosperity.

This update coincided with the maturation of the Cyber Essentials scheme, allowing the 10 Steps to position itself as the broader, holistic risk management framework for larger enterprises, while Cyber Essentials served as the technical baseline. Key conceptual shifts in 2015 included a move away from "perimeter defense" towards "defense in depth" and a new, urgent focus on supply chain security.

Detailed Refinements in the 2015 Update

While the top-level headlines of the ten steps remained consistent, the underlying guidance was overhauled to address new realities such as the "Bring Your Own Device" (BYOD) trend and the rise of ransomware.

1. Risk Management: Defining "Appetite"

The 2015 guidance moved beyond simple governance to emphasize Risk Appetite. It encouraged boards to explicitly define what risks they were willing to accept. This was a crucial maturation, acknowledging that "perfect security" is impossible and that trade-offs between security, usability, and cost must be made consciously at the executive level.

2. Network Security: Defense in Depth

The guidance acknowledged the erosion of the traditional network perimeter. It introduced the concept of Defense in Depth—ensuring that if one control fails (e.g., the firewall), others (e.g., internal segmentation, intrusion detection) are there to catch the attacker. This was a direct response to the increasing sophistication of Advanced Persistent Threats (APTs).

3. Malware Prevention: Beyond Antivirus

Reflecting the rise of polymorphic malware and ransomware, the 2015 update expanded "Malware Prevention" to suggest a layered approach. It recommended not just signature-based antivirus, but also heuristic analysis, sandboxing, and content filtering at the gateway to catch malicious code before it reached the endpoint.

4. Monitoring: Anomalous Activity

The focus shifted from simply "logging" events to actively monitoring for anomalies. The guidance encouraged organizations to establish a baseline of "normal" network behavior so that deviations (e.g., unexpected data flows, login attempts at odd hours) could be detected. This marked the beginning of the shift towards behavioral analytics.

5. Home and Mobile Working: The BYOD Challenge

The 2015 update tackled the "Bring Your Own Device" (BYOD) trend head-on. It provided nuanced advice on segregating corporate data from personal data on employee-owned devices, recommending the use of containerization and remote wiping capabilities to protect sensitive information without infringing on user privacy.

Key Addition: Supply Chain Risk

Although not renamed as a separate step until 2021, the 2015 guidance significantly expanded the "Information Risk Management" section to include Supply Chain Security. It warned that attackers were increasingly targeting smaller, less secure suppliers as a pathway into larger organizations. It advised companies to audit their suppliers' security arrangements and build security requirements into contracts.

Applicability and Adoption

The 2015 version became the gold standard for UK critical national infrastructure (CNI) and FTSE 350 companies. It was widely cited in government procurement contracts (especially in defense and nuclear sectors) and became a benchmark for internal audits.

Implementation Strategies

Cyber Essentials as a Foundation: The 2015 guidance strongly encouraged organizations to achieve Cyber Essentials certification first. This demonstrated that the "technical basics" (5 of the 10 steps) were in place, allowing the board to focus its energy on the more complex governance and risk management aspects of the framework.

Scenario-Based Planning: The update encouraged organizations to use "cyber attack scenarios" to test their resilience. This moved implementation from a theoretical checklist to practical war-gaming, ensuring that Incident Management plans (Step 6) actually worked in practice.

Relationship to Other Frameworks

  • Cyber Essentials Plus (2015): The technical verification standard that aligns with the technical controls of the 10 Steps.
  • NIST Cybersecurity Framework 1.0: Published in 2014, the NIST CSF and GCHQ 10 Steps (2015) became the two dominant western models for cyber risk management. They share roughly 90% alignment in principles, with the 10 Steps often seen as more accessible for non-technical boards.

Common Challenges

Supply Chain Visibility: While the 2015 update highlighted supplier risk, organizations struggled to actually audit their suppliers. Gaining visibility into 2nd and 3rd tier suppliers proved extremely difficult, a challenge that remains today.

Skill Shortage: As the guidance called for more sophisticated monitoring and behavioral analysis, the acute global shortage of skilled cybersecurity analysts became a major bottleneck. Many organizations bought tools they didn't have the staff to operate.

Frequently Asked Questions

What is the main difference between the 2012 and 2015 versions?

The 2015 version maintained the same 10 steps but updated the underlying advice to reflect new technologies (like cloud and BYOD) and new threats (like ransomware). It placed a heavier emphasis on "defense in depth" and incident recovery rather than just prevention.

Is GCHQ still the publisher?

Yes, the 2015 version was published by GCHQ (CESG). However, shortly after this release, the National Cyber Security Centre (NCSC) was formed in 2016 and took over ownership of the guidance.

Can I certify against the 10 Steps?

No, the 10 Steps is a guidance framework, not a certification standard. Organizations wishing to demonstrate compliance typically certify against Cyber Essentials (for the basics) or ISO 27001 (for the full management regime).