NCSC Annual Review 2024
Pages
Page 11 of 16
Chapter 02: Building the UK’s cyber resilience
From critical national infrastructure to emerging technology, cyber resilience underpins the UK’s economic future and safety.
The speed at which new technologies – such as artificial intelligence – are being used to facilitate cyber attacks continues to rise, as does the volume and sophistication of cyber threats from a range of capable adversaries.
The NCSC is prioritising the cyber resilience of the UK’s critical systems against the most advanced and sophisticated threats. At the same time, we’re raising our national resilience to commodity cyber attacks across the whole of the UK’s economy, using the unique insights we get from being a part of GCHQ, and by working with partners across government, industry, and academia.
More specifically, the NCSC is building UK cyber resilience by:
-
delivering transformational active cyber defence services and interventions
-
supporting legislative and regulatory reform
-
growing the UK’s cyber ecosystem
-
influencing the security standards for new and emerging technologies
This year the NCSC, working with the Cabinet Office Election Cell and alongside policing, central and local government and private sector organisations, helped to deliver safe and secure elections. We worked with the NPSA to provide dedicated support and services to high-risk individuals and organisations targeted by nation-state actors wishing to disrupt the democratic process. The general election was delivered smoothly and securely. No major information operations, cyber or concurrent incidents that caused a notable impact on the election and its outcome were observed.
Securing government
The NCSC has continued to strengthen cyber resilience across government, by supporting the establishment of the Government Cyber Coordination Centre (GC3) in September 2023. GC3 is a joint venture between the Government Security Group, the Central Digital and Data Office and the NCSC. It is the coordination point for operational cyber security efforts across the government sector relating to vulnerabilities, threats and incidents, enhancing government’s resilience and ability to ‘Defend as One’, meaning that government cyber defence is far greater than the sum of its parts.
2024 also saw the first set of annual GovAssure returns from government departments, which provide an assessment of the cyber security of critical systems underpinning government’s essential services. GovAssure is run by the Cabinet Office and uses the NCSC’s Cyber Assessment Framework (CAF) as its assurance methodology.
The NCSC has piloted new approaches to collaborating with security researchers from across the public sector, and accessing operational cyber security event data, at scale. This included hosting a workshop with researchers from across the public sector to conduct threat hunting across shared datasets, and to develop new tradecraft for detecting threats.
The NCSC is driving a transformational journey, moving away from traditional, anecdotal, incomplete and slow approaches to cyber resilience and instead embracing data-driven methods where insights inform our decisions and enable us to respond more effectively and more efficiently to emerging threats. By applying the standard data science toolkit to the cyber resilience problem, the NCSC will have better situational awareness, prioritisation and agility. This transformation will enable us to minimise harm by avoiding or mitigating more incidents faster.
The NCSC have developed joint cyber security priorities with the Ministry of Defence to increase the cyber resilience of our armed services. We have also been working with international partners to ensure the cyber security of joint projects to deliver the next generation of defence capabilities including the Global Combat Air Programme (GCAP) and AUKUS submarines.
Sector resilience
Over the last year, we have evolved our approach to the NCSC’s sector-specific Trust Groups; industry-specific communities of Chief Information Security Officers (CISOs) in businesses and organisations. This has involved taking a more thematic approach to common risks and vulnerabilities such as supply chain resilience and the security of overseas travel.
Nearly 300 CISOs now actively participate in the NCSC’s sector-specific Trust Groups. As of 31 August 2024, over 70% of the UK organisations that are Trust Group members had signed up to the NCSC’s Early Warning service, which is designed to inform organisations of potential cyber attacks on their network.
We also provide bespoke support where required, including the creation of a suite of practical resources for schools which, this year, passed over half a million combined views on YouTube and downloads from our website. In addition, we also extended our 'Protective DNS’ offering into the school sector, which helps to prevent malware, ransomware, phishing attacks, and other online threats from reaching school networks. This will mean more schools – regardless of their resources – can now benefit from enhanced cyber resilience.
Defending democracy
The integrity of the general election is fundamental to our democracy. Securing the election was a top priority for the NCSC. We played a part in the UK’s Defending Democracy Taskforce, made up from representatives from across government, the UK Intelligence Community (UKIC) and the NPSA. The taskforce’s aim was to ensure protection of our democratic institutions, processes and civil society, which included establishing the constructs for free and transparent elections in 2024. The Defending Democracy Taskforce then established the Joint Election Security Preparedness unit (JESP), which took overall responsibility for coordinating electoral security and drove the government’s election preparedness. Looking beyond the election the NCSC will continue to support the Defending Democracy Taskforce’s priorities.
Before the election, the NCSC helped secure digital infrastructure, working with devolved governments and the Ministry of Housing, Communities and Local Government to ensure local authorities were resilient. We extended Active Cyber Defence (ACD) services and offered expert advice to political parties and electoral management service providers.
Recognising that personal digital services (such as email) are seen as softer targets by our adversaries, the NCSC developed a comprehensive cyber offer for high-risk individuals including briefings and the development of innovative individual cyber defence services, which were made available to all parliamentary candidates. These services included ‘Account Registration’ (a service to provide rapid notifications if we become aware of a cyber incident affecting a registered account) and ‘Personal Internet Protection’ (a service which helps manage the risk of visiting malicious domains).
Post-election, the NCSC worked with parliamentary security and the Cabinet Office to deliver cyber security briefs and facilitated the adoption of individual cyber defence services.
The 2024 general election took place in a complex information environment. The NCSC partnered with colleagues across government to offer expert technical advice on how to protect against and respond to information-based incidents. This included using our expertise in exercising to test a number of scenarios and our collective readiness to respond to any incidents, as well as participating in JESP's Election Security Exercise Programme.
Defender communities
In support of the ‘Defend as One’ objectives, the NCSC has piloted new approaches to engage and collaborate with security practitioners across the public sector. Successful projects like NHS England’s Cyber Security Operations Centre (CSOC), Police Digital Service's National Management Centre (NMC), and CymruSOC (Security Operations Centre) have made expertise accessible to many organisations.
The NCSC’s work with these communities has identified opportunities to support experts by tailoring analytic products and engagements for wide distribution. Regular engagements have facilitated the sharing of actionable intelligence, encouraging proactive defences and knowledge sharing. Over half of all actionable insights come from external contributors.
Threat hunting workshops have developed and shared tradecraft for detecting threats, enabling coordinated threat hunting on critical systems. The NCSC has invested in developing subject matter expertise and technical innovation, working closely with Five Eyes partners.
Research and innovation
In early 2024, the NCSC set up a new team dedicated to enhancing the resilience of the UK’s research and innovation (R&I) sectors to state threats, in partnership with the NPSA. The work focuses on enhancing cyber resilience in critical emerging technologies including quantum, AI, engineering, biology and semiconductors. A new Emerging Technology Trust Group spans universities, incubators, spin-outs, funders, investors and larger tech companies. This provides us with direct, one-to-one engagement with the most significant and strategic R&I organisations, which helps us to:
- influence funders and investors in these critical sectors
- encourage them to incentivise or mandate cyber security best practice
The NCSC have also worked in partnership with the NPSA in continuing to promote the joint Secure Innovation and Trusted Research campaigns. These campaigns provide emerging technology companies and research institutions with cost-effective measures to protect their ideas, reputation and future success. The international launch of the Secure Innovation campaign highlights the join up across our 5 Eyes community.
Cyber Essentials
Cyber Essentials can help every organisation – from micro businesses to large corporations – guard against the most common cyber attacks whilst signalling to potential customers that they take the cyber threat seriously. The technical controls defined in the Cyber Essentials scheme continue to be the minimum standard of security that the NCSC advise all organisations strive for. In 2024, Cyber Essentials celebrated its tenth anniversary.
Research from insurers show that organisations implementing the Cyber Essentials controls are 92% less likely to make a claim on their cyber insurance than those which don’t have Cyber Essentials. We’ve also launched the Cyber Essentials Knowledge Hub, to provide a central, up-to-date source of authoritative information, and it’s already received great feedback from customers and certification bodies.
-
33,836
Cyber Essentials certificates awarded
(+20%)
-
10,939
Cyber Essentials Plus certificates awarded
(+20%)
-
358
Certification Bodies right across the UK
(+12%)
Certifications by business size | ||
|---|---|---|
| Cyber Essentials certificates | Cyber Essentials Plus certificates | |
| Micro | 35% | 33% |
| Small | 35% | 29% |
| Medium | 20% | 23% |
| Large | 10% | 15% |
Top 4 reasons given for certification | ||
|---|---|---|
| To generally improve cyber security | 33% | |
| To give confidence to our customers | 31% | |
| Required for government contract | 13% | |
| Required for commercial contract | 13% | |
As recommended by users
-
91% of customers would recertify to Cyber Essentials next year
-
89% would recommend certifying to other organisations like theirs
-
40% of smaller organisations implemented the controls for the first time
-
2% failure rate for Cyber Essentials, dropping for the third straight year
-
The estimated fail rate for Cyber Essentials across all organisation sizes has dropped from 2.45% to 2.0%.
-
This year saw an increase (of 6%) in renewals of CE certifications 72% compared to the previous year.
-
Of sole traders, micro and small organisations, around 40% told us it was the first time that they’d implemented the Cyber Essentials controls. This figure is an increase of 10% on last year.
-
The proportion of organisations that say they will recertify (91%) and those saying they would recommend the scheme (89%) have both increased.
-
Achieving Cyber Essentials Plus compliance across their partnership network has helped St James Place reduce cyber security incidents by approximately 80%.
Growing the cyber ecosystem
Cyber Essentials is also fuelling growth across the wider cyber security sector. Through our Delivery Partner, IASME, we support the UK’s cyber security industry by licensing the Cyber Essentials assessment process to ‘Certification Bodies’ across the UK. We now have 358 cyber security companies right across the UK (up 12% on last year), who are licenced to deliver Cyber Essentials.
Certification bodies by region (August 2024) | |
|---|---|
| Region | Certified bodies |
| North East | 13 |
| North West | 37 |
| Yorkshire and The Humber | 18 |
| East Midlands | 20 |
| West Midlands | 38 |
| East | 27 |
| London | 64 |
| South East | 58 |
| South West | 34 |
| Wales | 10 |
| Scotland | 28 |
| Northern Ireland | 5 |
| Jersey | 1 |
| Guernsey | 2 |
| Isle of Man | 2 |
| Ireland | 1 |
Certification bodies by size | ||
|---|---|---|
| Micro | 204 | 56% |
| Small | 102 | 29% |
| Medium | 36 | 10% |
| Large | 16 | 5% |
Cyber Essentials Plus
Cyber Essentials Plus offers a higher level of assurance of the standard Cyber Essentials scheme, as it includes a technical audit, carried out by an approved third party, to ensure the technical controls have been correctly implemented. This year, St James’s Place, one of the UK’s largest advice-led wealth management companies, asked its partnership network of over 2,800 independent business to certify to Cyber Essentials Plus. In such a large supply chain this had its challenges, but the decision is already showing a positive impact with an 80% reduction in cyber security incidents.
The Funded Cyber Essentials Programme
The NCSC has continued to deliver its three-year Funded Cyber Essentials Programme, by supporting small organisations that work in those sectors that are at greater risk of cyber attack than others. This may be because of sensitive information they deal with, or because they're seen as an ‘easy target’ for cyber criminals.
Since beginning the programme, 525 small organisations have benefitted from the opportunity to access free Cyber Essentials support. Initially targeting small organisations in the legal aid and charity sectors (that is, organisations handling sensitive data that would have significant impact if disrupted), we expanded in 2023 to the ‘emerging technology’ sector, widening our offering to small businesses working in AI, engineering biology, quantum engineering and semi-conductors.
Between September 23 and August 24, 204 applications were approved (29 charities, 99 legal aid and 76 emerging tech companies). Since its launch 90% of organisations responding to feedback feel more confident about cyber security after completing the process.
Cyber Advisor
The Cyber Advisor scheme provides small and medium-sized organisations with access to local, reliable and cost-effective cyber security advice and practical support, all based on the implementation of the Cyber Essentials technical controls. Every Cyber Advisor must work for a company which has met the NCSC’s standards, and pass an independent assessment that measures their:
- knowledge and understanding of the Cyber Essentials’ technical controls
- competence in providing practical, hands-on support
- ability to understand and work with small and medium-sized organisations
Launched in 2023, Cyber Advisor has continued to grow this year, with 100 individual Cyber Advisors now employed by 93 NCSC assured service providers.
Number of Cyber Advisors by month (since scheme was launched) | |
|---|---|
| February 2023 | 18 |
| March 2023 | 25 |
| April 2023 | 31 |
| May 2023 | 34 |
| June 2023 | 46 |
| July 2023 | 52 |
| August 2023 | 61 |
| September 2023 | 10 |
| October 2023 | 72 |
| November 2023 | 76 |
| December 2023 | 80 |
| January 2024 | 85 |
| February 2024 | 86 |
| March 2024 | 91 |
| April 2024 | 93 |
| May 2024 | 92 |
| June 2024 | 95 |
| July 2024 | 97 |
| August 2024 | 100 |
Industry assurance
The NCSC, working with partners, offer certified assurance that covers a range of products, services and organisations. We continue to develop our range of industry assurance schemes and have launched new services to help grow the cyber security industry, leveraging the NCSC brand so consumers can choose products and services they can trust. This all means that more organisations than ever before can have confidence in the cyber security solutions they rely on to grow their businesses.
Cyber Resilience Audit
In August 2024 we announced the opening of a new Cyber Resilience Audit (CRA) scheme. CRA will assure providers who can conduct independent CAF-based audits. These audits are primarily delivered to government departments, the wider public sector, and organisations operating in critical national infrastructure or specifically regulated sectors, although other organisations may also buy Cyber Resilience Audits for their own benefit.
Cyber Incident Exercising
Last year we made an effort to make our schemes more accessible to a wider range of organisations. This included the launch of a Cyber Incident Exercising (CIE) scheme. CIE allows organisations to test the effectiveness of their incident response plans in a safe environment and strengthen their incident management processes. CIE doesn’t test cyber defences, but helps organisations to explore and evaluate their response plans, understand what risks they are holding from a cyber perspective, and how they can be managed. There are now 28 providers assured by the NCSC under CIE.
‘Standard’ Cyber Incident Response
As part of our aim to support a wider range and larger number of organisations, last year a new ‘Standard’ service level was introduced to our Cyber Incident Response (CIR) scheme. The requirements of the Standard level are designed to support target organisations which are at risk of common cyber attack, and are likely to include most private sector organisations, charities, local authorities and smaller public sector organisations. There are now 36 providers assured across the CIR scheme.
CHECK
The NCSC's CHECK scheme sets standards for penetration testing that government departments, public sector bodies and the UK’s CNI organisations can trust. There are currently 53 companies assured, delivering CHECK penetration testing engagements.
Over the past 12 months our assured service providers have carried out over 2,700 tests. As well as ensuring the resilience of some of the most critical sectors, the information gathered through these penetration tests helps the NCSC identify and better understand common vulnerabilities across organisations. Meanwhile, CHECK has completed the first phase of a digital transformation programme, automating the management of the scheme and allowing service providers the ability to carry out many day-to-day business activities themselves, while fuelling the ability to further explore relevant datasets.
Cyber Resilience Test Facilities (CRTFs)
To further develop Principles Based Assurance (the NCSC’s evidence-based method for technology assurance), initial work to establish Cyber Resilience Test Facilities (CRTFs) was completed, being the mechanisms that will deliver assurance for a wide range of internet-connected products using the Principles Based Assurance methodology. The objective is to set up a network of commercially operated CRTFs across the UK to assure these products at scale. Not only will this raise the bar for cyber-resilient product development, it will also widen the range of products being assured whilst driving private sector growth.
The CRTF pilots are now complete, with the results being analysed to determine what the future assurance model will look like ahead of a small-scale CRTF operating capability launch planned for 2025. Opportunities to scale the capability further will then be considered and implemented where feasible.
Active Cyber Defence
Active Cyber Defence (ACD) – a collection of NCSC services designed to protect UK citizens and organisations from commodity cyber attacks – continues to play an important role in building resilience. This year we announced ACD 2.0, which aims to build the next generation of ACD services in partnership with industry and academia.
As we embark on ACD 2.0, our first step is to look at our attack surface management suite (currently Web Check, Mail Check and Early Warning) and apply evidence-based scrutiny to our existing ACD services. This will ensure we have ongoing justification for the continuation of a service, along with a responsibility to evidence impact and be transparent about whole life costs, driving them down where possible. As a result, the NCSC will look to divest most of our new successful services within three years for the private sector to run on an enduring basis.
Share and Defend
Share and Defend is a new ACD service that shares feeds of known malicious domains with internet service providers (ISPs) and others so that they can be blocked or taken down, protecting UK citizens in near real time from high volume cyber crime and cyber-enabled fraud. The platform is already enabling the protection of approximately 50% of the UK public by sharing these known malicious domains with ISPs.
Share and Defend works with threat intelligence providers and security vendors to consume data sets which contain malicious indicators (such as domains and URLs). Share and Defend also uses data from the PDNS and Takedown services.
ACD service highlights
Mail Check is the NCSC’s platform for assessing email security compliance. It helps domain owners identify, understand and prevent abuse of their email domains.
- Over 3,800 organisations are now using Mail Check
- Over 34,600 domains, 60% of which are protected by DMARC
Web Check helps users find and fix common security vulnerabilities in their websites.
- Service now has over 4,000 organisations utilising Web Check
- Over 64,000 assets subscribed
Check Your Cyber Security was launched in early 2023 as our first free service specifically for small organisations and sole traders. Check Your Cyber Security offers a range of tools to help users identify common vulnerabilities in their public-facing IT.
- Over 33,000 IP checks completed in review period (82% increase on previous year)
- Over 7,300 IP vulnerabilities detected
- Over 25,800 browser checks completed in review period (76% increase on previous year)
- 30% of checks detected an out-of-date browser
The Takedown service works with hosting providers to remove malicious sites and infrastructure from the internet.
- Share of global phishing has remained on average between 1-2% throughout the last year. In 2016 the figure was over 5%
- 2.2 million cyber-enabled commodity campaigns removed (up from 1.8m last year)
Suspicious Email Reporting Service (SERS) allows the public to report potential scam messages for removal.
- Over 10.5 million reports received in the past year
- Total number of reports since April 2020 reached over 34.4 million
- 351,000 scam URLs removed by the NCSC since April 2020
Early Warning allows system owners to receive email alerts from the NCSC tailored to the cyber threats for their organisation's IP address.
- Notified about 181,180 vulnerable systems on the internet
- Notified about malware infections on 117,700 IPs
- Notified about 47,739 hacked internet servers
- There were 11,190 organisations signed up at the end of the period, an increase of 29% on the previous year