NCSC Annual Review 2023
Pages
Page 9 of 16
Resilience

Introduction
The NCSC continues to support government, public and private sector critical national infrastructure (CNI), citizens, and organisations of all sizes across England, Wales, Scotland and Northern Ireland to raise awareness of cyber threats and improve resilience for the whole of society.
Cyber resilience is essential to the UK’s economic and national security interests. The NCSC’s services and interventions are working to enhance the UK’s ability to prepare, respond, recover, and learn from cyber attacks, to make the UK the safest place to live and work online.
August 2023 marked 18 months since the publication of the National Cyber Strategy 2022, and it remains at the heart of the government’s comprehensive plan to keep our country safe online and grow our cyber industry. As outlined by the Deputy Prime Minister Oliver Dowden, “since its publication, we have become more secure against cyber attacks, and we have taken decisive action against our adversaries”.
Central to these efforts are a whole of society approach, bringing together private and the public sectors, “defending as one so we can prosper as one ”. This is in line with the government's approach to resilience as set out in the government’s Resilience Framework
Trust groups
Central to our whole of society approach, the NCSC has ensured long-lasting and meaningful impact by building ‘trust groups’; industry-specific communities of Chief Information Security Officers (CISOs) in businesses and organisations. This is now an established model that sees us work in collaboration with the trust groups on raising the cyber resilience in their sectors for:
- those larger organisations that make up the groups
- the thousands of smaller organisations that sit within their supply chains
- those citizens that are their customer base
This approach ensures engagement and nuance, allowing businesses, large and small, to access guidance and information, while also participating in a supportive community.
Share and defend
When it comes to raising the resilience of citizens and small organisations, our programmes of work focus on securing citizens and small organisations online at scale, reducing the burden on them to act. Our Takedown Service in this programme is approaching 10 million takedown records for malicious infrastructure. By taking down malicious domains quickly, it reduces the number of people who fall victim to scams. To further strengthen those protections, the NCSC is building the Share and Defend capability. This capability will enable the sharing of government and industry data around malicious domains, at scale and in near real time, enabling the protection of citizens and small organisations upstream by their service providers. We are currently sharing data tactically with several major UK ISPs, whilst working collaboratively with industry to develop the capability, identify relevant datasets and place protections where they will have the most impact for users.
Cyber Essentials
Appetite for the NCSC’s Cyber Essentials scheme continues to grow. The number of Cyber Essentials certificates awarded in the past year has increased by 21% to 28,399 overall; while the total number of Cyber Essentials Plus certificates awarded was 9,037 – an increase of 55%. In total 141,712 Cyber Essentials certificates have been awarded since the scheme began. The scheme is proving its efficacy too, with data suggesting that 80% fewer cyber insurance claims are made when Cyber Essentials is in place.
Cyber Essentials
- 28,399 certificates awarded (+21%)
- 9,037 Cyber Essentials Plus certificates awarded (+55%)
- 321 Certification Bodies right across the UK (+6%)
- 80% fewer insurance claims with Cyber Essentials in place (Insurer's data)
| By business size | ||
|---|---|---|
| Cyber Essentials certificates | Cyber Essentials Plus certificates | |
| Micro | 35% | 36% |
| Small | 34% | 28% |
| Medium | 20% | 21% |
| Large | 11% | 15% |
Top 3 reasons given for certification
35%
To generally improve security
22%
Required for government contract
15%
Required for commercial contract
- The estimated fail rate for Cyber Essentials across all organisation sizes has dropped from 3.4% to 2.45%.
- This year saw an increase in the proportion of Cyber Essentials (increase of 4%) and Cyber Essentials Plus certificates (increase of 17%) issued to micro-organisations
- Of sole traders, micro and small organisations, around 30% told us it was the first time that they’d implemented the CE controls.
- The proportion of organisations that say they will recertify (89.2%) and those saying they would recommend the scheme (78.9%) have both increased.
- The proportion of smaller organisations (<50 staff) say that the scheme makes them feel more secure (+2.5%), gives them a trusted source of information (+12.1%), and that they feel more confident implementing cyber security controls themselves (1.7%) have all increased.
- A large proportion of Cyber Essentials customers (62.1%) report having learned something new about cyber security from implementing the controls, and many were repeat customers.
The Funded Cyber Essentials Programme
The Funded Cyber Essentials Programme was launched to provide support to some of the most vulnerable small organisations in the UK. Initially targeting legal aid and charity sub-sectors, the programme provided funding and technical support to gain Cyber Essentials Plus certification. 369 applications were approved in the first cohort (78% charities and 22% legal aid), with over 90% of organisations claiming that they feel more confident about cyber security after completing the process. The Programme is currently expanding to support small organisations and start-ups working on emerging and advancing technologies.
91%
of organisations say they feel more confident about cyber security after completing the Funded Cyber Essentials Programme
The Funded Cyber Essential Programme
- 369 applications approved in first cohort.
- 78% charities 22% legal aid firms
- 80% of organisations who have completed the programme have stated an intention to renew the certification next year.
- 91% of these organisations claimed that they feel more confident about cyber security after completing the process.
Cyber Advisor scheme
This year, the new Cyber Advisor scheme was launched to consumers, offering small organisations a network of 56 NCSC-assured providers (as of August 2023), to help with reliable, cost-effective cyber security advice and practical support. This work aims to improve basic cyber security in small organisations and reduce the likelihood of the most common cyber attacks.
Existing schemes continue to grow. Following an update that puts industry at the heart of the scheme, Assured Cyber Security Consultancy now has 26 providers offering risk management and security architecture consultancy. While the CHECK scheme now has 44 assured pen-test providers, who responded to over 4500 requests last year.
In August, a new Level 2 service was introduced to our assured Cyber Incident Response (CIR) scheme. Its aim is to support a wider range and larger number of victim organisations, by providing access to high quality, assured incident response services. With 13 providers assured across Levels 1 and 2, now more organisations can have confidence that the company they use has the right expertise to help them.
Industry Assurance
- 26 companies assured to offer risk management and security architecture consultancy
- 44 CHECK pen-test providers, responding to 4500+ requests
- 56 brand new Cyber Advisors onboarded
- 13 assured providers of Cyber Incident Response
Active Cyber Defence (ACD)
Now in its sixth year, the Active Cyber Defence collection of products and services continues to make the UK measurably safer from cyber attacks. Threat actors come and go, and the types of vulnerabilities being introduced and exploited continue to evolve. However, most of our ACD initiatives address enduring cyber security challenges: sharing knowledge of threats, closing down vulnerabilities, and responding to breaches. We believe that automation is the best way of generating the scale and reach required to tackle these challenges of today and tomorrow.
For all these reasons, we see ACD as a core part of how the NCSC will improve the UK’s cyber resilience over the coming years, as we continue to build services designed to protect UK citizens and organisations.
When ACD was launched in 2016, we developed services with the protection of government organisations specifically in mind. However, at the core of the UK’s National Cyber Strategy is a ‘whole of society’ approach, which is why we’ve broadened the utility of ACD products and services to a wider range of users, from small business owners to the education and charity sectors to citizens being able to report scam emails to the NCSC’s Suspicious Email Reporting Service (SERS). This conscious shift to designing and developing ‘radically simple' digital services, (with accessibility and ease of use as core design principles) can help provide the benefits of vulnerability checking to those individuals and organisations that do not have a dedicated security function.
We also want to make it simple for users to find, sign up to and manage our services, whilst reducing duplication and providing a smoother, more integrated user experience. We built the MyNCSC platform to turn that vision into reality. The platform brings several ACD products and services together into a single, coherent experience tailored to show the content, vulnerabilities, and alerts most pertinent to each user. These are currently Mail Check and Web Check. We plan to gradually increase the number of ACD products and services integrated with MyNCSC and have started migrating our customer organisations’ use of Early Warning to the platform.
This year’s ACD report noted the challenges of developing new services, which included improvements in levels of defensive capability, the need for a more dynamic commercial cyber security services market , and the growing sophistication of commodity threats. This has meant embracing different ways of ‘getting things done’, whether that’s building services ourselves, contracting with market-leading UK companies, or engaging with collaborative projects.
Check Your Cyber Security
In March 2023, we launched Check Your Cyber Security (CYCS), our first free active service specifically for small organisations and sole traders. Through IP and browser checks, CYCS identifies and provides advice on common vulnerabilities. To date, approx. 24% of CYCS users have an out-of-date browser and the most common browser used is Google Chrome. FTP and MySQL have been identified as the most common IP vulnerabilities reported to users. The NCSC is investigating repeat users to track effectiveness of mitigation advice and additional support required. Currently, 4% of users have subscribed to reminders, signalling a desire by users to utilise the tool on a regular basis to monitor their cyber security enduring usage.
Mail Check
Helps public and third sector assess and improve email security compliance to prevent criminals spoofing email domains.
- over 2,700 organisations are now using Mail Check
- over 24,000 domains, 60% of which are protected by DMARC
Email Security Check
Available to all UK organisations to help users check an email domain for two important areas of cyber security: email anti-spoofing and email privacy.
- used to complete 90,000 checks across 34,000 unique domains
Takedown service
Works with hosts to remove malicious sites and infrastructure from the internet.
- the known share of global phishing dropped to 1.19%, in 2016 the figure was over 5%
- number of fake UK government phishing scams decreased from 6,300 the previous year to 5,300 in this reporting period
- 1.8 million cyber-enabled commodity campaigns removed
Suspicious Email Reporting Service (SERS)
Allows the public to report potential scam messages for removal by the Takedown service.
- over 10 million reports received into SERS during the review period
- total number of reports reached over 23.9 million (since it launched in April 2020)
- 86k scam URLs removed, bringing total takedowns attributed to SERS since it launched to 261k
Early Warning (EW)
A vulnerability, compromise and open attack surface notification service.
- Has been integrated into MyNCSC this year and over 96% of organisations migrated
- Notified about 323,000 unique IP address having a form of vulnerability and 10,200 unique IPs about a malware infection
- The top five malware families notified on EW are Mirai, Andromeda, Conficker, Ramnit, and Pony
- The top five vulnerabilities notified on EW are CVE-2022-41082 (Microsoft Exchange); Exposed RDP; Open Recursive DNS Resolver; Exposed HTTP Management Service; and CVE-2023-21529 (Microsoft Exchange)
- We have 8,704 customers using EW at the end of the reporting period
Web Check
Helps users find and fix common security vulnerabilities in their websites.
- Service now has 2,999 organisations using Web Check
- 15% increase in unique URLs scanned using Web Check
- 14% increase in active assets
- 15% decrease* in urgent findings reported to users, along with remediation advice
* Web Check is now provided via MyNCSC
Check Your Cyber Security
A range of free tools available to all UK organisations to help users identify common vulnerabilities in their public-facing IT, which now includes Email Security Check which launched last year as a standalone service and has now been subsumed into Check Your Cyber Security.
- 18,285 IP checks completed since product launch in March 23
- 14,672 browser checks completed since product launch in March 23
- 2,526 users received at least one finding
- 2,876 users were using an out-of-date browser
- Used for 90,000 checks across 34,000 unique domains
Exercise in a Box (EiaB)
A free toolkit providing scenarios for organisations to refine their response to cyber security incidents.
- New users increased from 16,808 to 21,524 which sees an increase of over 4,500 users which is on par to the previous year, giving a 28% increase
Protective Domain Name Service (PDNS)
Prevents users from accessing malicious domains or IP addresses.
- Organisations using PDNS rose 20% (from 1,140 to 1,363)
Assured Services
Looking beyond ACD, we’ve also ‘badged’ certain assured industry services to help organisations that don’t have the necessary skills differentiate quality. We’ll keep investing in proven delivery models but stay attuned to new approaches as the consumption of IT services shifts (for example, through cloud provision). However, whilst we can identify quality, we can’t drive quantity; that comes from market demand. Ensuring there are enough providers offering quality services needs the full range of government and industry levers to be used. For example, larger organisations asking for Cyber Essentials in their supply chain will not only improve resilience, but will incentivise more providers to offer the service, upskilling their staff in the process. This will help build a thriving cyber sector, discussed further in this report.