Managing the cyber risk of agentic AI NCSC Feed 10 hours 17 minutes ago Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
How BitLocker PINs help protect your data and devices NCSC Feed 1 week ago Using a PIN mitigates many BitLocker vulnerabilities. Make sure you’re ready for the next one...
Help shape the future of resilient private 5G NCSC Feed 1 week 1 day ago The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G
Water sector example added to the NCSC’s Secure connectivity principles NCSC Feed 1 week 2 days ago New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.
NCSC statement in response to recent incidents resulting from frontier AI evaluations NCSC Feed 2 weeks 2 days ago A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
Making forensic observability the norm for network devices NCSC Feed 3 weeks 1 day ago Progress is being made, but too many network devices still remain difficult to investigate after compromise
When cyber attacks happen: helping organisations recover NCSC Feed 3 weeks 2 days ago A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations NCSC Feed 4 weeks ago GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
Post-quantum cryptography (PQC) migration workshop report NCSC Feed 4 weeks 1 day ago No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
Helping small businesses with free, hands-on cyber consultancy NCSC Feed 1 month ago Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting NCSC Feed 1 month 1 week ago New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Cyber Essentials Pathways: from proof of concept to cyber confidence NCSC Feed 1 month 1 week ago An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Cyber Shield: The path to an agentic AI future for cyber defence NCSC Feed 1 month 1 week ago Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
Building more resilient CNI: what industry pen testers told us NCSC Feed 1 month 2 weeks ago Pen testers suggest what organisations can do to make their job more difficult.
The AI shift in cyber risk: why leaders must act now NCSC Feed 1 month 4 weeks ago Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
The 'vibe coding spectrum' approach to AI-assisted software development NCSC Feed 2 months ago Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways NCSC Feed 2 months ago Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems NCSC Feed 2 months ago Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Software supply chain attacks: check your dependencies NCSC Feed 2 months 2 weeks ago Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
Designing secure access with ZTNA NCSC Feed 2 months 3 weeks ago New guidance explains how to design Zero Trust Network Access architectures aligned with zero trust principles and not built on old trust assumptions.