10 questions to ask when using AI models to find vulnerabilities
Using Artificial Intelligence to find vulnerabilities can bring added security considerations.
Preparing for a âvulnerability patch waveâ
Organisations must act now to prepare for a wave of patches that will address decades of technical debt.
Could your choice of metrics be harming your SOC?
Poor metrics can render a well-intentioned security operation centre entirely ineffective.
Supporting AI adoption for UK cyber defence
Adopting AI will require time, the development of new capabilities and careful oversight.
Defending against China-nexus covert networks of compromised devices
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
International cyber agencies share fresh advice to defend against China-linked covert networks
New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.
Executive Summary: Defending against China-nexus covert networks of compromised devices
Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.
NCSC: Leave passwords in the past – passkeys are the future
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
Passkeys are more secure than traditional ways to log in
Passkeys and other FIDO2 credentials offer a more usable, secure replacement for passwords and are already supported by most modern devices.
World-first NCSC-engineered device secures vulnerable display links
SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.
Cyber chief: UK faces “perfect storm” for cyber security
As the technology landscape develops, the definition of cyber security is expanding with it.
New cross domain guidance for government, industry and the wider security community
Ensuring cross domain technologies are better understood – and more easily deployed – across sectors.
Preparing for severe cyber threat: Why leaders must act now
A call to action to collectively build UK resilience.
Strengthening cyber resilience across the NHS with collaboration and innovation
How the NCSC is reducing risk, improving detection, and helping to keep vital services running.
Retaining defensive advantage in the age of frontier AI cyber capabilitiesÂ
A step change in frontier AI modelsâ capabilities to find vulnerabilities in codeâŻcan ultimately be a good thing for our cyber security.
UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks
New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations.
APT28 exploit routers to enable DNS hijacking operations
Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversaryâinâtheâmiddle attacks and theft of passwords and authentication tokens.
NCSC warns of messaging app targeting
The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.
Vulnerability affecting F5 BIG-IP APM
The NCSC is encouraging UK organisations to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager.
Why cyber defenders need to be ready for frontier AI
Understanding the threats and staying ahead of the adversary
Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.
NCSC CEO: Seize ‘disruptive’ vibe coding opportunity to make software more secure
Dr Richard Horne delivered a keynote about cyber risks and opportunities at the RSA Conference in San Francisco
Vibe check: AI may replace SaaS (but not for a while)
If âvibe codingâ disrupts the software market like SaaS did 20 years ago, what does this mean for cyber security?
How to secure your online meetings
International security chiefs to convene in Glasgow for flagship CYBERUK conference
CYBERUK will be delivered by the NCSC and sponsors across four distinct tracks of activity: Resilience, Technology, Threat, and Ecosystem.
Alert: NCSC advises UK organisations to take action following conflict in the Middle East
In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture.
Exploitation of Cisco Catalyst SD-WAN
Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN.
Can you help the NCSC with the next phase of EASM research?
Organisations with experience in external attack surface management can help us shape future ACD 2.0 services.
Improving your response to vulnerability management
How to ensure the âorganisational memoryâ of past vulnerabilities is not lost.
Eradicating trivial vulnerabilities, at scale
A new NCSC research paper aims to reduce the presence of âunforgivableâ vulnerabilities.
Thanking the vulnerability research community with NCSC Challenge Coins
Reflecting on the positive impact of the Vulnerability Reporting Service â and introducing something new for selected contributors.
Cloud Security Posture Management: silver bullet or another piece in the cloud puzzle?
CSPM tools are big business. Could they be the answer to your cloud configuration problems?
One small step for Cyber Resilience Test Facilities, one giant leap for technology assurance
CRTFs are helping organisations to make informed, risk-based decisions on the adoption of technology products.
Products on your perimeter considered harmful (until proven otherwise)
As attackers’ tactics change, so must network defenders’.
The Cyber Assessment Framework 3.1
Latest version of the CAF focusses on clarification and consistency between areas of the CAF.
Watch all the plenaries from CYBERUK 2024 live, and for free
Key talks from the UK governmentâs flagship cyber security event will be livestreamed from Birminghamâs ICC.
Cyber insurance guidance
Cyber security considerations for organisations thinking about taking out cyber insurance.
Designing safer links: secure connectivity for operational technology
New principles help organisations to design, review, and secure connectivity to (and within) OT systems.
New interactive video – and related downloads – to help secondary school kids stay safe online
A new initiative, aimed at 11 to 14-year-olds, that helps them navigate the risks of online life.
The Government Cyber Action Plan: strengthening resilience across the UK
With GCAP, the UK government is taking decisive steps towards a safer, more resilient future.
Home working: preparing your organisation and staff
How to make sure your organisation is prepared for home working.
Drawing good architecture diagrams
Some tips on good diagram drafting and pitfalls to avoid when trying to understand a system in order to secure it.
Updating our guidance on security certificates, TLS and IPsec
The NCSC has updated 3 key pieces of cryptographic guidance. Here, we explain the changes.
Using IPsec to protect data
Guidance for organisations wishing to deploy products that use IPsec.
Provisioning and managing certificates in the Web PKI
How service owners should securely provision and manage certificates in the Web PKI.
Using TLS to protect data
Recommended profiles to securely configure TLS for the most common versions and scenarios, with additional guidance for managing older versions.
Pattern: Safely Importing Data
An architecture pattern for safely importing data into a system from an external source.
Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking
Technical report on best practice use of this fundamental data routing protocol.
What makes a responsible cyber actor: introducing the Pall Mall industry consultation on good practice
Calling vulnerability researchers, exploit developers and others in the offensive cyber industry to share their views.
Zero trust 1.0
Zero trust architecture design principles 1.0 launched.
Sextortion emails: how to protect yourself
Advice in response to the increase in sextortion scams
Shopping and paying safely online
Tips to help you purchase items safely and avoid fraudulent websites.
How to recover an infected device
Advice for those concerned a device has been infected.
Recovering a hacked account
A step by step guide to recovering online accounts.
Data breaches: guidance for individuals and families
How to protect yourself from the impact of data breaches
How to spot scammers claiming to be from the NCSC
Check that you’re talking to a genuine NCSC employee, and not a criminal.
A method to assess ‘forgivable’ vs ‘unforgivable’ vulnerabilities
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
Prompt injection is not SQL injection (it may be worse)
There are crucial differences between prompt and SQL injection which â if not considered â can undermine mitigations.
Building trust in the digital age: a collaborative approach to content provenance technologies
Joint NCSC and Canadian Centre for Cyber Security primer helps organisations understand emerging technologies that can help maintain trust in their public-facing information.
What makes a responsible cyber actor: introducing the Pall Mall industry consultation on good practice
Calling vulnerability researchers, exploit developers and others in the offensive cyber industry to share their views.
It’s time for all small businesses to act
The NCSCâs Cyber Action Toolkit helps you to protect your business from online attacks.
NCSC handing over the baton of smart meter security: a decade of progress
Why transferring the Commercial Product Assurance scheme to industry ownership marks an important milestone.
Choosing a managed service provider (MSP)
An SMEâs guide to selecting and working with managed service providers.
Advanced Mobile Solutions (AMS) guidance trailer
Chris P explains how AMS will enable high-threat organisations to stay connected âon the go’.
Vulnerability Scanning: Keeping on top of the most common threats
Vulnerability Scanning solutions offer a cost-effective way to discover and manage common security issues.
Cyber Security and Resilience Policy Statement to strengthen regulation of critical sectors
New proposals will combat the growing threat to UK critical national infrastructure (CNI).
NCSC to retire Web Check and Mail Check
By 31 March 2026, organisations should have alternatives to Mail Check and Web Check in place.
Strengthening national cyber resilience through observability and threat hunting
How organisations can improve their ability to both detect and discover cyber threats.
Creating the right organisational culture for cyber security
Calling cyber security professionals, culture specialists and leaders to drive uptake of new Cyber security culture principles.
Software Code of Practice: building a secure digital future
New voluntary code of practice for technology providers defines a market baseline for cyber security.
Advanced Cryptography: new approaches to data privacy
A new NCSC paper discusses the suitability of emerging Advanced Cryptography techniques.
Cyber Resilience Audit scheme open to applications
A new NCSC scheme assuring providers of CAF-based audits is now open for potential members.
Watch all the plenaries from CYBERUK 2024 live, and for free
Key talks from the UK governmentâs flagship cyber security event will be livestreamed from Birminghamâs ICC.
Interactive administration in the cloud: managing the risks
Tips to help you secure and reduce interactive access to your cloud infrastructure.
Cyber security is business survival
The NCSC co-signs Ministerial letter to major British businesses including FTSE 350 companies.
There’s a hole in my bucket
…or ‘Why do people leave sensitive data in unprotected AWS S3 buckets?’
Moving your business from the physical to the digital
Security questions to ask your IT service providers when considering a digital transition
Strengthening national cyber resilience through observability and threat hunting
How organisations can improve their ability to both detect and discover cyber threats.
Phishing attacks: defending your organisation
How to defend your organisation from email phishing attacks.
Maintaining a sustainable strengthened cyber security posture
How organisations can avoid staff burnout during an extended period of heightened cyber threat.
RFC 9794: a new standard for post-quantum terminology
The NCSCâs contribution to the Internet Engineering Task Force will help to make the internet more secure.
Putting staff welfare at the heart of incident response
Guidance for staff responsible for managing a cyber incident response within their organisation.
Understanding your OT environment: the first step to stronger cyber security
If you canât see your entire operational technology environment, you canât defend it. New guidance from the NCSC will help you gain that visibility.
Early Years practitioners: using cyber security to protect your settings
How to protect sensitive information about your setting and the children in your care from accidental damage and online criminals.
Products on your perimeter considered harmful (until proven otherwise)
As attackers’ tactics change, so must network defenders’.
New online training helps board members to govern cyber risk
The NCSCâs CEO, Richard Horne on the new cyber governance resources giving Boards the tools they need to govern cyber security risks.
Setting direction for the UK’s migration to post-quantum cryptography
Why the key milestones for PQC migration are part of building and maintaining good cyber security practice.
Navigating the different cyber services from the NCSC
If you donât have the inhouse expertise to keep your organisation cyber secure, the NCSC offers services and tools to help organisations guard against commodity threats.
RITICS: Securing cyber-physical systems
Discover the Research Institute in Trustworthy Inter-connected Cyber-physical Systems.
NCSCâs Cyber Advisor scheme milestone
Cyber Advisor scheme for small organisations welcomes its 100th advisor, but more still needed!
EASM buyer’s guide now available
How to choose an external attack surface management (EASM) tool thatâs right for your organisation.
External attack surface management (EASM) buyer’s guide
A guide to choosing the right EASM product for your organisation, and the security features you need to consider.
Buying, selling and donating second-hand devices
How to erase the personal data from your phone, tablets, and other devices (and why it’s important when you’re buying and selling them).
Cyber resilience matters as much as cyber defence
Why planning and rehearsing your recovery from an incident is as vital as building your defences
“If you have knowledge, let others light their candles in it.”
Why sharing lessons learned from cyber security incidents and ânear missesâ will help everyone to improve
The future of telecoms in the UK
NCSC Technical Director Dr Ian Levy explains how the security analysis behind the DCMS supply chain review will ensure the UKâs telecoms networks are secure â regardless of the vendors used.
Protecting internet-facing services on public service CNI
How operators of critical national infrastructure (CNI) can use NCSC guidance and blogs to secure their internet-facing services.
ACD 2.0: Insights from the external attack surface management trials
We publish the results of our ACD 2.0 external attack surface management (EASM) trials
Cyber Essentials Plus is for charities too!
Sara Ward, the CEO of Black Country Women’s Aid, discusses her organisation’s experience of gaining Cyber Essentials Plus certification.
From bugs to bypasses: adapting vulnerability disclosure for AI safeguards
Exploring how far cyber security approaches can help mitigate risks in generative AI systems
âOur Collaborations With