NCSC Annual Review 2021
Pages
Page 17 of 44
Active Cyber Defence
Building resilience at scale
The Active Cyber Defence (ACD) programme is one of the NCSC’s most successful ways to help bring about a real-world, positive impact against threats. The programme seeks to reduce high-volume cyber attacks, such as malware, ever reaching UK citizens and aims to remove the burden of action from the user.
The ACD programme’s core services include Mail Check, Web Check, Protective DNS, Exercise in a Box, the Suspicious Email Reporting Service, and the Takedown Service.
Takedown Service

Finds malicious sites and sends notifications to the host or owner to get them removed from the internet before significant harm can be done. The NCSC centrally manages the service, so departments automatically benefit without having to sign up. This year, the UK’s share of global phishing has remained consistent at approximately 2% due to this service.
This year the Takedown Service enabled the NCSC to remove a total of 2.3 million cyber-enabled commodity campaigns, including:
- 13,000 phishing campaigns which were disguised as coming from the UK Government.
- 442 phishing campaigns which used NHS branding, compared to 105 in the same period in last year’s report.
- 80 instances of NHS apps (unofficial mirrors) hosted and available for download outside of the official Apple and Google app stores.
2.3m
cyber-enabled commodity campaigns removed thanks to the Takedown Service
Mail Check
Helps organisations secure their email, in particular standards that prevent criminals from spoofing their email domains (DMARC), encryption-in-transit (TLS and MTA-STS). This year the number of public sector domains using DMARC has increased by 38% (from 3,097 to 4,273).
Web Check
Helps owners of public sector websites to identify and fix common security issues, making sites in the UK a less attractive target to attackers. This year Web Check has resolved 8,746 distinct urgent issues.
Protective Domain Name Service (PDNS)

PDNS prevents users from accessing domains or IPs that are known to contain malicious content and stops malware already on a network from calling home. This year, the number of organisations using PDNS has risen 20% (from 766 to 925).
There was a significant increase in customer onboarding in March 2020, when we extended PDNS to Healthcare organisations, and vaccine development and supply chain organisations.
20%
increase in organisations using PDNS
Routing and Signalling
Fixing the underlying infrastructure protocols on which the internet and telephony systems are based: the Border Gateway Protocol (BGP) and the Signalling System No. 7 (SS7). This includes setting up initiatives such as the SMS SenderID Protective Registry, which helps organisations protect their brand from abuse in SMS phishing campaigns.
Host Based Capability

Advanced NCSC threat detection capability that can be deployed to detect threats on an organisation’s network. This year, there has been a 50% rise in organisations using this service (from 20 to 31).
Vulnerability Disclosure
Services based around making it easier to report, manage and remediate vulnerabilities in government and other key services. This year 13 Government departments launched dedicated vulnerability disclosure programs with the aid of our Vulnerability Disclosure Pilot. In addition, the Vulnerability Reporting Service helped to remediate over 400 vulnerabilities.
NCSC Observatory
Generating data-driven insights to underpin the NCSC’s research and strategy, which includes supporting the other ACD services. DNS Insights (DNSI), part of the the NCSC Observatory, now processes over 2.1 billion DNS requests per day, up from 1 billion in October 2020.
2.1b
DNS requests processed now by DNSI per day
Suspicious Email Reporting Service
Allows the public to report phishing or suspicious emails they receive in their inboxes. The service analyses the emails for links to malicious sites, and then seeks to remove those sites from the internet to prevent the harm from spreading. The service has now received more than 5,427,000 reports in the 12 months up to September 2021 leading to the removal of more than 50,500 scams and 90,100 malicious URLs.
50k
scams removed in the 12 months up to September 2021
Exercise in a Box

A toolkit of realistic scenarios that helps organisations practise and refine their response to cyber security incidents in a safe and private environment. This year, the number of users (multiple per organisation) using Exercise in a Box has risen by 56% (from 7,535 to 11,754).
Logging Made Easy
An open-source project that helps organisations to install a basic logging capability on their IT estate enabling routine end-to-end monitoring of Windows systems. This year, there were 1,063 unique clones of the LME code from the LME GitHub page for people to install it.