MyNCSC Help Centre
Pages
Page 21 of 22
Early Warning
What the service does
Early Warning is a free NCSC service designed to inform your organisation as soon as possible of potential cyber attacks on your network. The service uses a variety of information feeds from the NCSC and trusted public, commercial, and closed sources, which includes several privileged feeds not available elsewhere.
Early Warning within MyNCSC
- Use MyNCSC to add and organise your assets and their subscriptions to Early Warning
- When Early Warning detects a potential incident affecting an asset in your organisation's portfolio, it will be surfaced in two forms:
- A finding will be generated and immediately displayed within MyNCSC
- Emailed directly as an Early Warning alert (finding-related notifications will not be sent from MyNCSC)
- All findings detected by Early Warning have the ability for their status to be manually set to one of the following:
- Marked as fixed
- Risk accepted
| Updating an Early Warning finding status (‘Marked as fixed’ or ‘Risk accepted’) is only a feature available in MyNCSC and will not be reflected in any alerts directly emailed from the Early Warning service. |
How to manage Early Warning emails
Early Warning will send emails to:
- the administrators and members of the team the asset is shared with,
- or, if the asset is shared with the entire organisation, the administrators and members of the organisation.
You can configure Early Warning to include additional email recipients, such as team/group or system mailboxes on the Early Warning Settings page of the team or organisation in MyNCSC.
How it works
Early Warning filters the millions of events the NCSC receives every day and, using the IP and domain names you provide, correlates those relevant to your organisation into findings within MyNCSC and daily Early Warning email alerts.
Organisations will receive the following high level types of alerts:
- Incident Notifications (shown as 'Suspected compromise' in MyNCSC) – This is activity that suggests an active compromise of your system.
For example: A host on your network has most likely been infected with a strain of malware.
- Network Abuse Events (shown as 'Suspected compromise' in MyNCSC) – This may be indicators that your assets have been associated with malicious or undesirable activity.
For example: A client on your network has been detected scanning the internet.
- Vulnerability and Open Port Alerts (shown as 'Known vulnerability' in MyNCSC) – These are indications of vulnerable services running on your network, or potentially that undesired applications are exposed to the internet.
For example: You have a vulnerable application, or you have an exposed Elasticsearch service.
Early Warning does not conduct any active scanning of your networks itself, however some of the feeds may use scan derived data - for example, from commercial feeds.
Findings can be viewed in MyNCSC as soon as they are raised.
We then email alerts for Incident Notifications and Network Abuse Events daily, and for Vulnerability and Open Port alerts weekly. Emails are usually scheduled for between 8-10am. However, we may occasionally contact you outside of these hours (by email) for other issues including critical or one-off alerts.