Helping banish malicious adverts – and drive a secure advertising ecosystem
If your brand uses digital advertising, the NCSC has new guidance to help you choose a security-minded partner.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

Online advertising is a key and growing component of the global digital economy. According to an industry review, the UK is expected to spend a projected £37 billion on advertising in 2024, and roughly three quarters of that will be digital content. This makes digital advertising a huge contributor to the UK economy, but public and commercial trust in the cyber security of the sector is essential if this is to remain the case.
Put simply, the harm comes from ‘malvertising’, when an attacker uses online advertising to deliver malicious activity. It's particularly insidious because it often doesn't require any user interaction, such as choosing to run downloaded files, to cause problems. A web user can become a victim of malvertising simply by visiting a website.
It's a popular attack method because a single malicious advertisement could be distributed to many publishers and then on to many websites, causing widespread attacks. Advertising networks allow advertisers to target online advertisements on features like location and device types, and attackers can use this to launch targeted malvertising campaigns.
Research shows that of the 1.1 trillion ads delivered globally in 2023, what equates to 0.26% were classed as a ‘security violation’. In other words, this means that 2.86 billion individual advert views were classed as security threats. The percentage in the UK was 0.56%, more than twice the global average.
While the majority of organisations and individuals in the advertising industry act responsibly to build trust with consumers, this good work can be undone by a minority of scammers and fraudsters whose activity undermines the reputation of the wider industry.
The presence of malvertising puts a duty on the advertising industry and hosting platforms to squeeze out those with malign intent. This is best done with a defence-in-depth approach, where each defensive measure provides a layer of security which, when deployed collectively, makes a cyber attack much less likely – and helps remove malicious advertisers from the ecosystem.
The government has committed in its online advertising programme to tackle illegal advertising, which includes malvertising, and has convened a minister-led industry taskforce to bring industry and government together.
And more can happen now, by making use of the vast amounts of ad spend flowing through the ecosystem to incentivise better practices. Many companies in the ad-tech industry spend large sums on user safety or security awareness campaigns. This goes some way, but ultimately it puts the burden back on the user, and user awareness training is no substitute for building systems that are secure by design.
We’ve already seen how market forces have led to the adoption of technology that allows ‘buy side’ (advertisers) to verify transaction partners, through sellers.json. If you are in charge of a marketing budget, your choices about where you spend that budget can significantly influence online security. Making the right choice here can also improve public trust in the digital advertising economy . . . which in turn reduces the impact of malvertising and leads to longer-term reputational benefit for the industry, ultimately making ad campaigns more effective.
It's for these reasons that the NCSC has published new guidance which lays out a set of principles that brands can use to check a potential partner has security front and foremost. It can also help your brand demonstrate positive your own security practices, while protecting revenue and reputation at the same time.
We hope this new guidance will stimulate discussion and lead to improved dialogue and stronger enforcement in the industry.


