GCHQ 10 Steps to Cyber Security (2021)
Overview of NCSC 10 Steps (2021)
In 2021, the National Cyber Security Centre (NCSC)—the public-facing arm of GCHQ—released the first major structural overhaul of the "10 Steps to Cyber Security" guidance since its inception. While the previous versions served the industry well for nearly a decade, the 2021 update acknowledges that the technology landscape has fundamentally changed: the traditional network perimeter has dissolved, almost every organization now relies on cloud services, and remote working has become the norm.
The 2021 update breaks the original 10 steps structure to introduce new, distinct categories for Cloud Security (integrated throughout), Supply Chain Security, and Asset Management. It represents a shift from "perimeter security" to "data security," recognizing that data must be protected wherever it lives, whether on-premise, in the cloud, or on a user's mobile device.
The 10 Steps: 2021 Edition
The updated framework reflects modern best practices, zero-trust principles, and a more empathetic approach to user security.
1. Risk Management
Take a risk-based approach to securing your data and systems. This step emphasizes that cyber security risks should be governed at the same level as other business risks (financial, legal, operational). It calls for active Board participation and the integration of cyber risk into the wider organizational risk register.
2. Engagement and Training
A significant shift from "User Education," this step focuses on building a positive security culture. It encourages organizations to move away from "blame" and "compliance" toward collaboration. Training should be tailored to specific roles, and security controls should be designed to be usable, reducing the friction that causes users to find workarounds.
3. Asset Management
New distinct category. You cannot secure what you don't know exists. This step mandates establishing a comprehensive inventory of all data, systems, and software. It specifically addresses the challenge of "Shadow IT"—services spun up by business units without IT oversight—and emphasizes the need to know the physical and logical location of your data.
4. Architecture and Configuration
Replacing "Secure Configuration," this broader category focuses on designing systems securely from the ground up. It covers the maintenance of secure baselines, the removal of unnecessary functionality, and the importance of keeping systems up to date (patching). It explicitly includes cloud architecture and the principle of "secure by design."
5. Vulnerability Management
Manage vulnerabilities throughout the lifecycle of your systems. This goes beyond just patching; it includes regular scanning, risk-based prioritization of remediation, and a plan for retiring end-of-life (EOL) systems that can no longer be secured.
6. Identity and Access Management
Control who and what can access your systems and data. Reflecting Zero Trust principles, this step emphasizes strong authentication (MFA), the principle of Least Privilege, and the robust management of the identity lifecycle (joiners, movers, and leavers).
7. Data Security
Protect data where it lives, in transit, and at rest. This step covers encryption, data rights management, and backups. It emphasizes that data is the asset, not the server it sits on, and security must travel with the data.
8. Logging and Monitoring
Design your systems to be able to detect and investigate incidents. This step highlights the need for visibility into both traditional networks and cloud environments (e.g., SaaS logs). It stresses that logs are useless unless they are actively analyzed and stored securely.
9. Incident Management
Plan your response to a cyber incident in advance. This step requires organizations to have a tested incident response plan that covers not just technical recovery, but also communications, legal, and PR. It emphasizes the speed of response as a critical factor in minimizing impact.
10. Supply Chain Security
New distinct category. Collaborate with your suppliers and partners. This step addresses the growing risk of third-party compromise. It requires organizations to map their supply chain, assess the security of their vendors, and build security requirements into contracts.
Applicability and Adoption
The NCSC 10 Steps serves as the de facto cybersecurity standard for UK businesses, particularly medium to large enterprises. While small businesses are encouraged to start with Cyber Essentials, the 10 Steps provides the strategic framework for organizations that have outgrown the basics.
Implementation Strategies
Embrace Cloud Security: Unlike previous versions which treated cloud as an "outsourced" risk, the 2021 guidance integrates cloud security into every step. Organizations should leverage cloud-native security tools (e.g., Cloud Identity, Cloud Logging) rather than trying to force-fit legacy on-premise tools into the cloud.
Zero Trust Mindset: The move away from "Network Security" (boundary protection) to "Identity and Access Management" reflects a shift toward Zero Trust architectures. Implementation should focus on verifying identity for every request, rather than just trusting devices because they are on the corporate network.
Relationship to Other Frameworks
- NCSC Cyber Assessment Framework (CAF): The 10 Steps provides the "what to do" (guidance), while the CAF provides the mechanism for assessing "how well you are doing it" (assurance), particularly for Critical National Infrastructure (CNI).
- NIST Cybersecurity Framework 2.0: The 2021 update aligns closely with NIST CSF 2.0's addition of "Govern" (Risk Management) and its focus on Supply Chain Risk Management (C-SCRM).
Common Challenges
Shadow IT and Asset Visibility: The Asset Management step is increasingly difficult in cloud-first organizations where business units can spin up SaaS applications with a credit card. Organizations struggle to discover and govern these assets without blocking innovation.
Supply Chain Complexity: Mapping and securing the entire supply chain (Step 10) is often the most difficult step for large enterprises due to the depth of sub-contractors. Gaining visibility beyond "Tier 1" suppliers remains a significant industry challenge.
Frequently Asked Questions
Why did the names of the steps change in 2021?
The NCSC updated the names to better reflect modern security practices. For example, "Network Security" became "Architecture and Configuration" to acknowledge that security is about system design and cloud architecture, not just network perimeter firewalls.
Is this framework relevant for non-UK companies?
Yes. While published by the UK government, the 10 Steps are technology-agnostic and universally recognized as best practice. They are widely used by multinational corporations as a balanced, readable alternative to more complex standards like ISO 27001.
Does this replace Cyber Essentials?
No. Cyber Essentials is a specific subset of technical controls designed for basic hygiene and certification. The 10 Steps is a broader, holistic risk management framework that includes Cyber Essentials controls but adds governance, supply chain, and incident management dimensions.