admin

Passwords, passwords everywhere

Selecting an effective password can be challenging. The NCSC has emphasized through various blogs and guidance that it’s crucial to modify password policies to ensure users are encouraged to select secure passwords. One of the strategies includes the utilization of password deny lists, which prevent users from choosing passwords that are frequently exposed in data…

Read More

NCSC advice for Marriott International customers

Customers of Marriott International, a prominent hotel group, may find that their personal information has been compromised in connection with the guest reservation database managed by Starwood. Incident Overview Marriott has announced that an internal investigation revealed that unauthorized access to the Starwood guest reservation database began in 2014, potentially impacting approximately 500 million customers….

Read More

‘Krack’ Wi-Fi guidance

The National Cyber Security Centre (NCSC) is investigating the implications of a vulnerability in WPA2 Wi-Fi networks known as ‘Krack’, first reported on 16 October 2017. This page offers guidance to enterprise administrators, small business owners, and home users regarding the recently identified vulnerability in their Wi-Fi networks. This information will be revised as new…

Read More

Setting up 2-Step Verification (2SV)

Overview This guide details the steps for enabling 2-step verification (2SV) on your vital online accounts. Implementing this feature significantly reduces the likelihood of unauthorized access, even if your password has been compromised. For IT professionals seeking guidance on broader implementation of 2SV in larger organizations, please consult the NCSC’s dedicated resource on multi-factor authentication…

Read More

NCSC advice for Dixons Carphone plc customers

Intended Audience for This Guidance This information is directed towards customers of Dixons Carphone plc and its main brands in the UK, specifically Currys PC World and Carphone Warehouse, as the National Cyber Security Centre (NCSC) collaborates with them to investigate a data breach. Overview of the Incident On June 13, 2018, Dixons Carphone plc…

Read More

What does the NCSC think of password managers?

Individuals frequently approach the NCSC to inquire whether it is advisable to use password managers (also known as password vaults). They ask questions about which password managers are recommended, who should utilize them—be it private individuals, small businesses, or large corporations—and the appropriate methods for using them. Furthermore, many wonder if it is secure to…

Read More

What does the NCSC think of password managers?

Many individuals inquire with the NCSC about the appropriateness of utilizing password managers (also referred to as password vaults). They wonder whether password managers are suitable for everyone – private citizens, small businesses, or large enterprises. Additionally, questions often arise regarding the safest methods to use these tools. Is it secure to store all essential…

Read More

Three random words or #thinkrandom

When selecting a password, a reputable site typically doesn’t save it in a directly readable format. Instead, it undergoes a sophisticated mathematical transformation known as ‘hashing’. This process converts the plaintext password into an unreadable string referred to as a password hash, which the website securely retains. The remarkable aspect of hashing is its resistance…

Read More

Making the UK the safest place to live and do business online

Welcome to the newly established National Cyber Security Centre by GCHQ. What is our purpose? In recent years, GCHQ has made significant strides in the realm of cyber security. Collaborating with colleagues across the intelligence community, law enforcement, various governmental bodies, international partners, and the essential private sector, we have heightened awareness of cyber threats,…

Read More
Back To Top