admin

Equities process

We have recently shared the United Kingdom’s methodology for addressing vulnerabilities discovered in various technological systems. To clarify, the UK intelligence community, including the National Cyber Security Centre (NCSC), conducts vulnerability research aimed at identifying security flaws across a range of technologies, from commonly used devices to highly specialized equipment. Upon identifying a security vulnerability,…

Read More

Introducing Active Cyber Defence 2.0

As the National Cyber Security Centre (NCSC), our goal is to create a comprehensive suite of services that assist organizations in safeguarding against cyber threats. Some services we provide directly, leveraging our unique position, while others are offered through industry partners under NCSC assurance. We continuously evaluate the services we provide and aim to transition…

Read More

Navigating the different cyber services from the NCSC

The annual DSIT workforce survey continues to highlight a significant cyber security skills gap within many organizations. While the government focuses on long-term strategies to close this gap, the NCSC provides a variety of digital and industry cyber services to assist organizations in safeguarding their data. In-House or Outsourced Cyber Security? Many organizations opt to…

Read More

Shopping and paying safely online

As online shopping becomes more prevalent, it is crucial to be aware of the rising threat of internet fraudsters looking to exploit our personal and financial information. The following guidelines will assist you in securely shopping for products and services online. Verify the Store’s Legitimacy Before making purchases from unfamiliar online retailers, take steps to…

Read More

Cyber insurance guidance

Introduction This document is intended for organizations, regardless of size, who are contemplating the purchase of cyber insurance. The focus here is not to serve as a complete guide for cyber insurance buyers, but rather to highlight the key cybersecurity considerations associated with cyber insurance. For those looking into cyber insurance options, the following questions…

Read More

Threats and key takeaways for the legal sector

A recent report highlights the vulnerabilities of the legal sector to cyber attacks, outlining the tactics employed by cybercriminals and offering strategies for organizations to enhance their defenses. The Cyber Threat Report: UK Legal Sector has been released by the National Cyber Security Centre (NCSC), with contributions from various entities including the Law Society, Bar…

Read More

Penetration testing

Overview of Penetration Testing Penetration testing serves as a fundamental approach to assess IT system security, though it should not be overestimated as a sole solution. This guidance aims to equip you with the knowledge necessary for the appropriate commissioning and application of penetration tests. It also assists in planning your ongoing security measures, enabling…

Read More

Not all types of MFA are created equal…

For several years, we have strongly advocated for the use of multi-factor authentication (MFA). MFA, also recognized as 2-step verification (2SV) or two-factor authentication (2FA), serves as a protective measure against various common threats aimed at user accounts. This is the reason our 2018 guidance delivered a straightforward message: organizations must begin implementing 2FA for…

Read More
Back To Top