Skip to main content

Active Cyber Defence: Sixth annual report now available

New ACD services developed to help protect SMEs from the harms caused by cyber attacks.
A birds-eye view of people walking on a white floor connected by orange beams of light
Photo credit: iStock.com/gremlin

This is the sixth time that we’ve published a retrospective summary of the work carried out as part of the NCSC’s Active Cyber Defence (ACD) programme.

Our rationale for producing the report has remained constant during this time; a commitment to transparency, and basing our interventions on unbiased data and evidence to better understand the reality of cyber attacks, as well as the efficacy of our products and services.

Whilst the specifics change over time (and the types of vulnerabilities exploited continue to evolve), most of our ACD initiatives address enduring cyber security challenges: sharing knowledge of threats, closing down vulnerabilities, and responding to breaches. The need to tackle these challenges through automation will persist, because that’s the only realistic way of generating the scale and reach required.

At the outset, we concentrated on building the cyber resilience of the public sector. However, at the core of the UK’s National Cyber Strategy is a ‘whole of society’ approach, which is why we’re extending the reach of existing ACD services, and developing new ones. For example, the Early Warning service can now be accessed by all organisations, not just those working in the public sector. And throughout 2022, we’ve continued to develop services (such as Check Your Cyber Security) which are ‘radically simple', and can be used by organisations that perhaps don’t have access to cyber security expertise.

As with previous reports, we have tried to focus on key findings and important trends. We highlight the successes but we’re honest about the gaps in the evidence base that still make it hard to be definitive about impact. The underpinning message is that ‘cyber security is a team sport’, involving the public sector, commercial and international partners (without whom we would not be able to implement these national-scale cyber security defences).

We welcome feedback on this report, particularly ideas for improved approaches, data that would be useful in future reports, and comparisons or pointers to similar efforts. Please contact us at [email protected], or via our social media channels.


Dave W
NCSC Active Cyber Defence