NCSC Annual Review 2021
Pages
Page 16 of 44
Key Advisories and Interventions
September 2020
The NCSC and its Five Eyes partners issued a joint advisory to help organisations stay safe from malicious cyber actors. It highlighted technical approaches for sectors – including those which protect critical national infrastructure – to uncover malicious activity and mitigation steps based on best practice.
October 2020
The NCSC published updated guidance for the UK health sector following a US advisory on Ryuk ransomware attacks against the US health sector as cyber criminals continued to exploit the pandemic.
December 2020
The NCSC confirmed it was working to assess the impact of the SolarWinds compromise and published guidance for Orion product users, urging them to follow advice in recently published FireEye and Microsoft blogs.
March 2021
Organisations were advised to install the latest Microsoft Exchange Server updates, as a matter of urgency, to avoid compromise by an increasing range of threat actors and to reduce the risk of future ransomware and other malware infections. This followed Microsoft’s warning of large-scale exploitation of unpatched vulnerabilities and issued multiple security updates for the affected servers.
March 2021
In her inaugural speech as CEO of the NCSC, Lindy Cameron warned against complacency in the boardroom while outlining future cyber risks. Cameron called on CEOs and boards to embed cyber security in their thinking and position digital literacy as non-negotiable as financial or legal literacy.
June 2021
Delivering the RUSI Annual Security Lecture, CEO Lindy Cameron warned that ransomware was now the key cyber threat facing the UK and allies and had brought real world impact in ways not seen before. Cameron called for a whole of society approach and partnerships to address this challenge and that all organisations now needed to take the ransomware threat seriously.
July 2021
The NCSC and US and Australian counterparts published a joint advisory to address the top 30 vulnerabilities routinely exploited by malicious actors in 2020 globally and shared details of Common Vulnerabilities and Exposures (CVEs) being widely exploited in 2021.