Introducing the NCSC's ‘Share and Defend’ capability
Join the community of service providers helping to protect the UK from cyber attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Join the community of service providers helping to protect the UK from cyber attacks.

bucur demir via Getty Images
‘Share and Defend’ is a new capability from the NCSC, designed to enable protection to the UK public and businesses from cyber attacks and cyber-enabled fraud.
The ‘Share and Defend' capability is enabled by the NCSC, working with internet service providers (ISPs) and other tech companies. The capability is designed to enable others to block access to malicious websites before they can be used to carry out cyber attacks, or to conduct cyber-enabled fraud. This approach aims to reduce the burden of cyber security on citizens.
‘Share and Defend’ is the latest capability from the NCSC, which is designed to disrupt, at scale, cyber crime and fraud, and in doing so, deliver on National Cyber Strategy objectives.
The capability enables protection by working with threat intelligence providers to consume datasets which contain malicious indicators (such as domains and URLs). ‘Share and Defend’ also uses data from the NCSC’s PDNS Service and Takedown Service.
The capability will share these datasets with our industry partners including Managed Service Providers (MSPs), Communication Service Providers (CSPs) and Internet Service Providers (ISPs). The malicious datasets will be filtered through our partners' DNS (Domain Name System) platforms, ultimately resulting in their customers (that is, UK citizens and businesses) being denied access to malicious content.
We also recently started working with the Cyber Defence Alliance (CDA) to share their data (predominantly in the financial sector) with our partners, which includes numerous malicious indicators, some of which have recently been associated with criminal gangs reported by various news outlets.
Our defending partners' role is to offer additional protection to their customers based on data shared with them, through Share and Defend.
We can confirm our defending partners to date include BT and Jisc, who have committed to helping us to make the UK a safer place to live and work online.
We are working closely with Vodafone and Talk Talk to develop their capabilities, allowing them to utilise the Share and Defend data and increase their customer protection in the near future.
If a defending partner is using our data to protect their customers, access to malicious content (such as a fake shop, a phishing site, or a malicious link in an email or text message) is automatically blocked. Although customers don’t need to do anything to benefit from this protection, we encourage all members of the public to remain vigilant when using online services, accounts and devices as the service can only offer protection against known malicious threats.
We also encourage members of the public to:
We are engaging with numerous potential partners, including internet service providers and aim to onboard them in the near future.
The larger our community, the greater the protection we can enable to UK citizens and businesses. We welcome discussions with MSPs, CSPs, any providers of browser, antivirus or operating systems. Additional dataset providers who are confident in providing further protection are also welcome for discussion. We ultimately require more defending partners and data contributors to engage with the capability, working towards making the UK a safer place to live and work online.
For more information, please refer to our new Share and Defend webpage.


