NCSC
UK National Cyber Security Centre — guidance and assurance schemes · National Cyber Security Centre (United Kingdom) · Official site
Guidance and assurance schemes from the UK's national cyber authority: Cyber Essentials, the Cyber Assessment Framework used by regulators of essential services, and the topic guidance the UK public sector holds its suppliers to. Not statute in itself — but the yardstick UK procurement and sector regulators reach for when they need one.
Timeline
NCSC blog post discussing the security challenges posed by staff using unapproved AI tools, focusing on understanding why such tools are adopted and how to manage the associated risks.
NCSC guidance encouraging owners of operational technology to address avoidable vulnerabilities and build long-term cyber resilience following disruptive cyber activity incidents related to internet-…
NCSC guidance on managing cyber risks associated with agentic AI systems. The guidance recommends using safeguards, sandboxing, and active oversight to enable autonomous systems while limiting uninte…
NCSC blog post providing guidance on using BitLocker PINs to mitigate vulnerabilities and protect data and devices. The excerpt suggests recommendations for PIN usage but lacks detail on specific req…
NCSC inviting organisations to collaborate on development of technologies and approaches for secure, resilient and deployable private 5G networks.
New guidance on secure connectivity principles featuring a water sector example has been published by the NCSC. This is the first content authored by the Industrial Control System COI (Community of I…
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents resulting from frontier AI evaluations. The statement appears to be an informational…
NCSC blog post discussing the state of forensic observability in network devices. The post notes that while progress is being made, many network devices remain difficult to investigate after a securi…
NCSC has published new guidance providing a framework for response and recovery from disruptive cyber incidents.
GCHQ's National Cyber Security Centre and international partners issue warning regarding 'LAUNDRY BEAR' cyber threat group conducting targeted phishing campaign. This is an informational alert about …
NCSC has published a report on their first post-quantum cryptography (PQC) migration workshop, highlighting key takeaways about navigating PQC migration. The workshop focused on collective insights a…
NCSC advisory highlights Russian state cyber actors' global exploitation of poorly configured routers and urges critical sectors to strengthen their defences against Russian intelligence targeting. T…
NCSC published guidance on alternative pathways to Cyber Essentials Plus certification. The article discusses pathways from proof of concept to achieving cyber confidence without compromising the int…
NCSC blog post featuring insights from industry penetration testers on recommendations and best practices for organisations to improve their security posture and make attacks more difficult.
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. This is a guidance publication addressing the evolving landscape of AI-related cyber threats and risks.
NCSC issued guidance advising organisations using Fortinet services to take action following a global campaign targeting Fortinet firewalls and VPN gateways.
NCSC blog post providing guidance on calibrating oversight levels for AI-assisted software development code based on different risk profiles and code characteristics. The post recommends a spectrum-b…
NCSC CEO Dr Richard Horne highlighted the scale of cyber threats against the UK's critical infrastructure at RUSI's Annual Security Lecture. The statement indicates that hostile states are linked to …
Sources we monitor
- NCSC UK — all content checked 3 hours, 27 minutes ago