Skip to main content

Strengthening national cyber resilience through observability and threat hunting

How organisations can improve their ability to both detect and discover cyber threats.

Eugene Mymrin via credit Getty images

Whether organisations manage their own digital estate and assets or work with external partners, the NCSC has found significant variation in organisations' ability to:

  • monitor their systems (their ‘observability’) and 
  • proactively hunt for threats

In the vital pursuit of raising the national ability to detect and discover cyber threat, this needs addressing. 

In this blog, we urge organisations and their external providers to develop and/or optimise both their observability and threat hunting capabilities, and set out how they can achieve this.





Organisations – or those who provide services to them – should not only ingest and detect IOCs but also be capable of consuming, creating, sharing, and detecting TTPs in their threat hunting. This dual approach enhances both reactive and proactive security capabilities, improving overall resilience against sophisticated adversaries.


Written by

Ollie Whitehouse Chief Technology Officer (CTO), NCSC

Published

Part of blog