Skip to main content
Guidance

NCSC Annual Review 2021

Making the UK the safest place to live and work online

Page 22 of 44

NCSC's response to Covid-19

In the Autumn of 2020, a range of UK academic and research institutions, critical to the strategic response to and recovery from the pandemic, were targeted in ransomware attacks. This included an attack on the University of Oxford while it was working on vaccine research crucial to the rollout of the national immunisation programme.

However, five months previously the NCSC had worked with universities, health and scientific institutions to review and improve their cyber resilience and implement services to prevent successful attacks getting through or mitigating their impact. This engagement was built on the shared experiences from the WannaCry ransomware attack in 2017.

Since the outbreak, tens of thousands of indicators of compromise were shared to enable mitigating action by IT leads across the health sector.

The NCSC issued guidance and threat assessments to over 80 companies and 14 universities, and promoted its services such as Early Warning, Web Check and Mail Check.

A key intervention was to expand the use of Protective Domain Name System (part of the Active Cyber Defence programme that limits malware delivery and communication) to NHS, healthcare and vaccine suppliers, helping to protect these critical sectors from attacks.

In 2020 we extended the service to over 1,000 additional organisations within the Health and Social Care sector via HSCN in addition to our support of vaccine development and supply chain organisations. 

Extension of PDNS to these critical sectors represents protection of 2-3 million additional employees, from essential workers providing and supporting front line care to those working to develop and deliver vaccines to citizens across the country. 

12m

blocks against Covid-19 phishing specific domains between January 2020 and July 2021

The NCSC also worked closely with NHS Digital to provide increased protection against cyber threats for health and care organisations during the pandemic.

The scope of the NCSC’s work to protect the UK’s response to Covid-19 went beyond traditional healthcare and supported sectors not previously seen as critical parts of the infrastructure, such as manufacturers of ventilators and PPE, care homes and supermarkets and their respective supply chains.

I‘m really proud of the way this organisation pivoted to protecting the health mission at a time when it, and vaccine research and supply, were under sustained attack from ransomware operators who were putting people’s lives at risk. We didn’t wilt under the pressure of helping, with others, to protect the country under the Covid-19 pandemic.

Dr Ian Levy, NCSC’s Technical Director

In total the NCSC engaged with approximately 5,000 organisations who were providing an essential service during the pandemic. These ranged from well-known brands through to small businesses vital to the response in supporting healthcare or to the public’s ability to function during Covid-19.

The legacy for this work has seen hundreds of additional businesses now receiving support from NCSC and access to its services and tools, such as Exercise in a Box, Cyber Essentials and alerts.

Published

Reviewed

Version

1.0

Written for