There is an increasing need to provide evidence of cyber capability to provide confidence to regulators, boards, shareholder and other interested parties. In addition to providing confidence, there is also a requirement to provide evidence following a cyber security breach.

In order to provide this evidence we must develop international standards to allow business to provide the it in a consistent manner. The supplier industry must help to promote these standards with the support from governments and regulators.

No all of the requirements for security are the same, there is therefore a need to create a process providing this evidence from basic cyber hygiene through to Critical National Infrastructure. The companies must be suitably accredited and the individuals must have appropriate credentials and experience.

Importantly the cyber security industry must move from simply being providers of advice to providing opinions. This will mean the industry must move to being accountable. This will in turn help to professionalise the industry.

Key takeaways: Need to provide evidence of cyber capability to regulators, boards, shareholder and other interested parties. Evidence following a cyber security breach is essential, but unstructured International standards developed by supplier industry with support from governments and regulators. Evidence required from basic cyber hygiene through to Critical National Infrastructure is different. *Cyber security industry must move from advisory to accountability, this is a massive change!