Navigating the different cyber services from the NCSC
If you don’t have the inhouse expertise to keep your organisation cyber secure, the NCSC offers services and tools to help organisations guard against commodity threats.

Abstract Aerial Art via Getty Images
The annual DSIT workforce survey continues to show there is a cyber security skills gap in many organisations. While the government’s longer-term work focuses on closing that gap, the NCSC offers a range of digital and industry provided cyber services to help organisations protect themselves.
To grow or to buy?
It’s normal practice for some organisations to 'buy in' services in areas such as accounting and legal, rather than employ their own specialists directly.
But buying services is costly and I regularly hear the challenge that “cyber security is too expensive.” Ultimately, this is a risk decision for organisations to make. Does the cost outweigh the benefits of having confidence that its own data, and its customer data, is secure? Shouldn’t buying cyber security services be seen as the cost of doing business, the same way as legal or accountancy services?
If you are buying in services, how do you know what a good cyber security practitioner looks like? The UK Cyber Security Council is setting the standards for these practitioners, overseeing assessments and holding a register of practitioners. That’s a great start, particularly when you want to buy in a particular skillset. But if you need a more complete service, the NCSC’s recognition of quality service offerings from industry and its provision of free-to-use digital services can help.
One size doesn’t fit all
Different organisations have different cyber security needs, based on what they do and the threats they face, as well as the capacity, expertise and means they have available. For this reason, the NCSC services on offer can be divided into two categories:
-
We have services to support organisations that may be targeted by the most capable actors using the most sophisticated tooling and techniques – for example, risk and security architecture consultancy, exercising, penetration testing and incident response to name a few.
-
We also have services for organisations targeted by what we call ‘commodity capability’ – attacks using publicly known tools and techniques which over time, can have a cumulative impact. This includes Cyber Essentials advice and assessment services.
Finding the right service for your organisation
The NCSC has been recognising quality industry services for many years, as a way of scaling the impact and today we have over 450 companies offering services that meet our standards.
I want to make it as easy as possible for organisations to navigate these services, recognising that if an organisation doesn’t have the skills internally, they may find it difficult to understand what they need in the first place.
Here we look a bit more closely at the commodity-level services that apply to most organisations, including some of the free-to-use services from the NCSC.
There are many ways you can present cyber security activities within an organisation, I like to group them in terms of how an organisation:
- protects itself from attack
- prepares itself for a potential attack
- detects an attack that manages to penetrate its protections
- responds to an attack once detected
Services that help protect
This is about putting in place measures that make an organisation more resilient to cyber attack, as data shows that organisations implementing the Cyber Essentials controls are 92% less likely to make an insurance claim. That’s not to say organisations shouldn’t do more, but if you are going to do anything, do these controls consistently.
We say these are ‘basic controls’ but, actually, some of them can be quite complicated to implement. Organisations can use the NCSC Cyber Advisor service to help.
The NCSC also provides a number of free-to-use digital tools that will help you build confidence, including Check Your Cyber Security.
But the best way to gain confidence is to get a Cyber Essentials Certification Body to check the controls are correctly implemented correctly. There are two options here:
- the Cyber Essentials Certification service is an independent audit of the information provided, with a certificate issued if controls have been met.
- the Cyber Essentials Plus Certification service, includes a technical assessment
Services that help prepare
If the worst happens, being prepared is vital for a fast recovery. To help with this, the NCSC offers:
- Exercise in a Box to help organisations step through different incident scenarios
- the Cyber Incident Exercising service offered by a number of NCSC assured companies helps organisations test incident response plans in a safe environment and strengthen incident management processes
Services that help detect
For many organisations, the cost of monitoring a network is prohibitive, and the skills to do it not available internally. Signing up to the NCSC Early Warning service can help here. Early Warning is a free NCSC service to inform an organisation of potential threats to a network. The service uses a variety of information feeds from the NCSC, trusted public, commercial and closed sources, and includes several privileged feeds which are not available elsewhere.
Services that help respond
Many organisations with a Cyber Essentials certificate may have access to incident response expertise through the included cyber liability insurance. But for those that can’t make use of this, there is an option to use our Level 2 Cyber Incident Response Service to find an industry partner to help with incident recovery.
Missing anything? Get in touch!
I believe this is a pretty comprehensive offering, but we are always interested to hear what else organisations would find useful, so if you have spotted a gap, please get in touch.
Chris Ensor
Deputy Director Cyber Skills and Growth
Share and print this article
Written by
Deputy Director National Resilience Capabilities, NCSC

