Cyber security risk profiles are dynamic, meaning those with malicious intent can quickly develop new ways of breaching cyber security. Prior to October 2019, the UK CAA cyber security audit used a prescribed questionnaire to assess compliance of the UK industry with the regulations. The regulated entities were subject to five to six audits, having their cyber security assessed under different operational activities, often duplicating tasks across operational functions.
The process was time-consuming for both the regulated entities and the regulator. The risk self-assessment did not reflect requirements specific to the entities and did not encourage proactive evaluation and preparation for potential threats. To keep pace with the changing threat landscape and promote awareness of direct and indirect cyber security threats, the UK CAA embarked on re-visioning its existing cyber security oversight.