Guidance
How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Act now to be ready to withstand and recover from severe cyber attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 14 of 26
Activities undertaken to enhance your situational awareness, such as external attack surface management, will have helped identify vulnerabilities within your internet-facing assets. Ensure you disable any unnecessary services and enforce strict access controls.
Refer to the following NCSC guidance to identify and tackle areas of weakness in your organisation’s cyber defences:
| NCSC guidance | How it helps |
|---|---|
| NCSC vulnerability management | Helps you identify and remediate weaknesses quickly, reducing exposure to known exploits. |
| Device security guidance | Ensures your enterprise networks and devices are well configured to reduce the opportunities for an attacker to gain a foothold in your organisation. |
| Multi-factor authentication for your corporate online services | Adds an extra layer of protection against credential compromise and account takeover. |
| Secure system administration | Protects administrative accounts and processes, reducing the risk of privileged access abuse. |
| Principles for secure privileged access workstations (PAWs) | Provides a hardened environment for administrative tasks, preventing compromise of critical systems. |
| Demystifying zero trust | Helps organisations understand where different security approaches can help in designing systems, such as zero trust being an approach, not a product that can 'fix' security. |
| Secure connectivity principles for Operational Technology | For OT systems. Principle 5 of the Secure connectivity principles for Operational Technology – Harden your OT boundary explains why and how to harden the boundary by using segmentation, secure connectivity patterns and layered security controls to reduce exposure and maintain resilience against evolving cyber threats. |


