Making forensic observability the norm for network devices NCSC Feed 3 hours 13 minutes ago Progress is being made, but too many network devices still remain difficult to investigate after compromise
When cyber attacks happen: helping organisations recover NCSC Feed 1 day 3 hours ago A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations NCSC Feed 6 days 3 hours ago GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
Post-quantum cryptography (PQC) migration workshop report NCSC Feed 1 week ago No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
Helping small businesses with free, hands-on cyber consultancy NCSC Feed 2 weeks ago Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting NCSC Feed 2 weeks 2 days ago New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Cyber Essentials Pathways: from proof of concept to cyber confidence NCSC Feed 2 weeks 6 days ago An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Cyber Shield: The path to an agentic AI future for cyber defence NCSC Feed 3 weeks 1 day ago Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
Building more resilient CNI: what industry pen testers told us NCSC Feed 4 weeks ago Pen testers suggest what organisations can do to make their job more difficult.
The AI shift in cyber risk: why leaders must act now NCSC Feed 1 month 1 week ago Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
The 'vibe coding spectrum' approach to AI-assisted software development NCSC Feed 1 month 1 week ago Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways NCSC Feed 1 month 1 week ago Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems NCSC Feed 1 month 1 week ago Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Software supply chain attacks: check your dependencies NCSC Feed 1 month 3 weeks ago Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
Designing secure access with ZTNA NCSC Feed 2 months ago New guidance explains how to design Zero Trust Network Access architectures aligned with zero trust principles and not built on old trust assumptions.
Thinking carefully before adopting agentic AI NCSC Feed 2 months 2 weeks ago When it comes to using agentic AI, make sure you can walk before you run.
10 questions to ask when using AI models to find vulnerabilities NCSC Feed 2 months 2 weeks ago Using Artificial Intelligence to find vulnerabilities can bring added security considerations.
Preparing for a ‘vulnerability patch wave’ NCSC Feed 2 months 4 weeks ago Organisations must act now to prepare for a wave of patches that will address decades of technical debt.
Could your choice of metrics be harming your SOC? NCSC Feed 3 months ago Poor metrics can render a well-intentioned security operation centre entirely ineffective.
International cyber agencies share fresh advice to defend against China-linked covert networks NCSC Feed 3 months ago New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.