How BitLocker PINs help protect your data and devices
Using a PIN mitigates many BitLocker vulnerabilities. Make sure you’re ready for the next one…
Help shape the future of resilient private 5G
The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G
Water sector example added to the NCSC’s Secure connectivity principles
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.
NCSC statement in response to recent incidents resulting from frontier AI evaluations
Making forensic observability the norm for network devices
Progress is being made, but too many network devices still remain difficult to investigate after compromise
When cyber attacks happen: helping organisations recover
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
Post-quantum cryptography (PQC) migration workshop report
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
Helping small businesses with free, hands-on cyber consultancy
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Cyber Essentials Pathways: from proof of concept to cyber confidence
An alternate path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Cyber Shield: The path to an agentic AI future for cyber defence
Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
Building more resilient CNI: what industry pen testers told us
Pen testers suggest what organisations can do to make their job more difficult.
The AI shift in cyber risk: why leaders must act now
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
The ‘vibe coding spectrum’ approach to AI-assisted software development
Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Software supply chain attacks: check your dependencies
Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
Designing secure access with ZTNA
New guidance explains how to design Zero Trust Network Access architectures aligned with zero trust principles and not built on old trust assumptions.
Thinking carefully before adopting agentic AI
When it comes to using agentic AI, make sure you can walk before you run.
10 questions to ask when using AI models to find vulnerabilities
Using Artificial Intelligence to find vulnerabilities can bring added security considerations.
Preparing for a ‘vulnerability patch wave’
Organisations must act now to prepare for a wave of patches that will address decades of technical debt.
Could your choice of metrics be harming your SOC?
Poor metrics can render a well-intentioned security operation centre entirely ineffective.
Supporting AI adoption for UK cyber defence
Adopting AI will require time, the development of new capabilities and careful oversight.
Defending against China-nexus covert networks of compromised devices
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
International cyber agencies share fresh advice to defend against China-linked covert networks
New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.
Executive Summary: Defending against China-nexus covert networks of compromised devices
Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.
NCSC: Leave passwords in the past – passkeys are the future
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
Passkeys are more secure than traditional ways to log in
Passkeys and other FIDO2 credentials offer a more usable, secure replacement for passwords and are already supported by most modern devices.
World-first NCSC-engineered device secures vulnerable display links
SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.
Cyber chief: UK faces “perfect storm” for cyber security
As the technology landscape develops, the definition of cyber security is expanding with it.
New cross domain guidance for government, industry and the wider security community
Ensuring cross domain technologies are better understood – and more easily deployed – across sectors.
Preparing for severe cyber threat: Why leaders must act now
A call to action to collectively build UK resilience.
Strengthening cyber resilience across the NHS with collaboration and innovation
How the NCSC is reducing risk, improving detection, and helping to keep vital services running.
Retaining defensive advantage in the age of frontier AI cyber capabilities
A step change in frontier AI models’ capabilities to find vulnerabilities in code can ultimately be a good thing for our cyber security.
UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks
New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations.
APT28 exploit routers to enable DNS hijacking operations
Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.
NCSC warns of messaging app targeting
The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.
Vulnerability affecting F5 BIG-IP APM
The NCSC is encouraging UK organisations to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager.
Why cyber defenders need to be ready for frontier AI
Understanding the threats and staying ahead of the adversary
Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.
NCSC CEO: Seize ‘disruptive’ vibe coding opportunity to make software more secure
Dr Richard Horne delivered a keynote about cyber risks and opportunities at the RSA Conference in San Francisco
Vibe check: AI may replace SaaS (but not for a while)
If ‘vibe coding’ disrupts the software market like SaaS did 20 years ago, what does this mean for cyber security?
How to secure your online meetings
International security chiefs to convene in Glasgow for flagship CYBERUK conference
CYBERUK will be delivered by the NCSC and sponsors across four distinct tracks of activity: Resilience, Technology, Threat, and Ecosystem.
Alert: NCSC advises UK organisations to take action following conflict in the Middle East
In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture.
Exploitation of Cisco Catalyst SD-WAN
Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN.
Our Collaborations With