ACD 2.0 exploration into attack surface management completed
We thank participants and look forward to sharing what we've learned
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

Andriy Onufriyenko
In August of last year we shared our plans for ACD, beginning with an exploration of attack surface management (ASM). As part of that blog post, we invited any providers of ASM products interested in collaborating with us to get in touch.
The response was incredible. Twenty commercial ASM providers submitted proposals detailing how they wanted to work with us – they are listed below, and we would like to thank all of them. We were able to progress ASM product trials with many of these providers, enrolling a variety of customer organisations who had also volunteered to work with us. This included everything from small local charities to large organisations that we’d consider part of critical national infrastructure.
In total we ran 35 product trials (including some organisations trialling multiple products), for an average of 25-30 days per product per customer, resulting in around 900 days’ worth of combined trial time.
A huge thank you to both the providers and users for engaging with these trials, and for giving up additional time to speak to us about their experiences and share expertise.
The experiment was fascinating. We’re working on the results and reports, including one for external publication in February. Even without the full results yet, we can safely say we’ve improved our understanding of industry offerings and customer needs, and have a better idea of where we need to go next. We see real value in what industry offers beyond what the NCSC can provide. However sometimes there is a mismatch between provider and customer views of technologies and the marketplace, which is where we believe we can add benefit.
In parallel, we conducted other experiments, exploring how our own guidance relates to ASM findings, the role of defender communities in mitigating attack surface risks at scale, different approaches to notifications, and understanding the various uses of ASM data within NCSC. We worked on understanding the language used around scanning, risk appetites, and where we can add clarification as the national technical authority.
We are also refining our approaches to these experiments and improving our ways of working. This includes how best to engage with a diverse set of external organisations, plus our own internal stakeholders. The willingness of cyber security companies and customer organisations to collaborate has been humbling, and we look forward to continuing this effort.



