Skip to main content
Annual Review

NCSC Annual Review 2023

Looking back at the National Cyber Security Centre's seventh year and its key developments and highlights, between 1 September 2022 and 31 August 2023.

Page 9 of 16

Resilience





Cyber Essentials

  • 28,399 certificates awarded (+21%)
  • 9,037 Cyber Essentials Plus certificates awarded (+55%)
  • 321 Certification Bodies right across the UK (+6%) 
  • 80% fewer insurance claims with Cyber Essentials in place (Insurer's data)


By business size

Cyber Essentials certificatesCyber Essentials Plus certificates
Micro35%36%
Small34%28%
Medium20%21%
Large11%15%

Top 3 reasons given for certification

35%

To generally improve security

22%

Required for government contract

15%

Required for commercial contract

  • The estimated fail rate for Cyber Essentials across all organisation sizes has dropped from 3.4% to 2.45%.
  • This year saw an increase in the proportion of Cyber Essentials (increase of 4%) and Cyber Essentials Plus certificates (increase of 17%) issued to micro-organisations
  • Of sole traders, micro and small organisations, around 30% told us it was the first time that they’d implemented the CE controls.
  • The proportion of organisations that say they will recertify (89.2%) and those saying they would recommend the scheme (78.9%) have both increased.
  • The proportion of smaller organisations (<50 staff) say that the scheme makes them feel more secure (+2.5%), gives them a trusted source of information (+12.1%), and that they feel more confident implementing cyber security controls themselves (1.7%) have all increased.
  • A large proportion of Cyber Essentials customers (62.1%) report having learned something new about cyber security from implementing the controls, and many were repeat customers.

The Funded Cyber Essential Programme

  • 369 applications approved in first cohort.
  • 78% charities 22% legal aid firms
  • 80% of organisations who have completed the programme have stated an intention to renew the certification next year.
  • 91% of these organisations claimed that they feel more confident about cyber security after completing the process.

Industry Assurance

  • 26 companies assured to offer risk management and security architecture consultancy
  • 44 CHECK pen-test providers, responding to 4500+ requests
  • 56 brand new Cyber Advisors onboarded
  • 13 assured providers of Cyber Incident Response


Mail Check

Helps public and third sector assess and improve email security compliance to prevent criminals spoofing email domains.

  • over 2,700 organisations are now using Mail Check
  • over 24,000 domains, 60% of which are protected by DMARC

Email Security Check

Available to all UK organisations to help users check an email domain for two important areas of cyber security: email anti-spoofing and email privacy.

  • used to complete 90,000 checks across 34,000 unique domains

Takedown service

Works with hosts to remove malicious sites and infrastructure from the internet.

  • the known share of global phishing dropped to 1.19%, in 2016 the figure was over 5%
  • number of fake UK government phishing scams decreased from 6,300 the previous year to 5,300 in this reporting period
  • 1.8 million cyber-enabled commodity campaigns removed

Suspicious Email Reporting Service (SERS)

Allows the public to report potential scam messages for removal by the Takedown service.

  • over 10 million reports received into SERS during the review period
  • total number of reports reached over 23.9 million (since it launched in April 2020)
  • 86k scam URLs removed, bringing total takedowns attributed to SERS since it launched to 261k

Early Warning (EW)

A vulnerability, compromise and open attack surface notification service.

  • Has been integrated into MyNCSC this year and over 96% of organisations migrated
  • Notified about 323,000 unique IP address having a form of vulnerability and 10,200 unique IPs about a malware infection
  • The top five malware families notified on EW are Mirai, Andromeda, Conficker, Ramnit, and Pony
  • The top five vulnerabilities notified on EW are CVE-2022-41082 (Microsoft Exchange); Exposed RDP; Open Recursive DNS Resolver; Exposed HTTP Management Service; and CVE-2023-21529 (Microsoft Exchange)
  • We have 8,704 customers using EW at the end of the reporting period

Web Check

Helps users find and fix common security vulnerabilities in their websites.

  • Service now has 2,999 organisations using Web Check
  • 15% increase in unique URLs scanned using Web Check
  • 14% increase in active assets
  • 15% decrease* in urgent findings reported to users, along with remediation advice

* Web Check is now provided via MyNCSC

Check Your Cyber Security

A range of free tools available to all UK organisations to help users identify common vulnerabilities in their public-facing IT, which now includes Email Security Check which launched last year as a standalone service and has now been subsumed into Check Your Cyber Security.

  • 18,285 IP checks completed since product launch in March 23
  • 14,672 browser checks completed since product launch in March 23
  • 2,526 users received at least one finding
  • 2,876 users were using an out-of-date browser
  • Used for 90,000 checks across 34,000 unique domains

Exercise in a Box (EiaB)

A free toolkit providing scenarios for organisations to refine their response to cyber security incidents.

  • New users increased from 16,808 to 21,524 which sees an increase of over 4,500 users which is on par to the previous year, giving a 28% increase

Protective Domain Name Service (PDNS)

Prevents users from accessing malicious domains or IP addresses.

  • Organisations using PDNS rose 20% (from 1,140 to 1,363)

Reviewed

Version

1.0

Written for