Guidance
How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Act now to be ready to withstand and recover from severe cyber attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 9 of 26
Organisations need to accept that increased monitoring means there will be an increased volume of alerts and greater sensitivity within security appliances. It is useful to consider where you can uplift your resources to assist triage activities.
To limit security risks, you should ensure protocols used within and between your network environments feature data formats that enable simple validation of both the protocol and its data. Use schemas to inspect and verify protocols and data payloads at key trust boundaries. In addition, since introducing change within operational networks can raise concerns about possible effects on safety or availability, developing and testing this validation in advance helps minimise those risks and reassures stakeholders that the system will remain stable.
There are several ways you can increase your threat monitoring, and further guidance to consult:
| Activity to increase monitoring | How it helps |
|---|---|
| Use External Attack Surface Management (EASM) tools to help identify, monitor and reduce vulnerabilities within your assets. | To identify, monitor and reduce vulnerabilities.
|
| Undertake proactive (rather than reactive) threat hunting. | To identify cyber threats which have evaded your existing security controls:
|
| Monitor network traffic patterns in both on-premises infrastructure and cloud-hosted systems. | Logging and monitoring helps you identify patterns of activity, which in turn provide indicators of compromise (IOCs).
|
| For OT networks, implement additional monitoring. | This is important because OT traffic volumes are typically much lower and use specific protocols. Therefore anything outside of the expected traffic baselines could be an indicator of a possible OT network compromise. |


