Skip to main content
Annual Review

NCSC Annual Review 2024

Looking back at the National Cyber Security Centre's eighth year and its key developments and highlights, between 1 September 2023 and 31 August 2024.

Page 6 of 16

Timeline 2023-2024

Highlights covering the period 1 September 2023 to 31 August 2024.

Date

Event

 2023 


 


 
1 September

 NCSC announces new CTO 
 

NCSC announces Ollie Whitehouse as new Chief Technology Officer 

11 September

 Evolution of Cyber Crime 

Publication of a paper by the NCSC and NCA examining the rise of 'ransomware as a service' and extortion attacks

12 September

NCSC and ICO sign Memorandum of Understanding

Memorandum sets out how both organisations will cooperate in the future

28 September

 UK and US host international dialogue 

NCSC CEO and CISA Director lead talks with international partners to boost the cyber resilience of global democracies

11 October

Principles for ransomware-resistant cloud backups

NCSC publish best practice to ensure cloud backups are more resistant to ransomware

12 October

 Supply chain guidance published 
 

A new collection of resources for understanding the impact of supply chain cyber security risks

18 October

NCSC at Singapore Cyber Week

NCSC CEO delivers speech on ‘Reshaping cyber security in the era of generative AI’

23 October

Cisco advisory published

Organisations are encouraged to take action to mitigate vulnerabilities affecting Cisco IOS XE

26 October

 PDNS for schools launched 

The first phase rollout of a protective DNS (PDNS) service for schools

27 October

Logging Made Easy (LME) with CISA

LME relaunched by the Cybersecurity and Infrastructure Security Agency (CISA)

28 October

British Library cyber attack

Major ransomware attack compromises most of its online systems

1-2 November

 AI Safety Summit, Bletchley Park 

NCSC support first ever global AI safety summit

9 November

 Black Friday Cyber Aware campaign launched 

Aimed at helping shoppers protect themselves online in the run up to the festive period

23 November

 DPRK advisory 

UK and Republic of Korea issue warning about DPRK state-linked cyber actors attacking software supply chains

27 November

 Guidelines for secure AI system development 

NCSC publishes first global guidelines to ensure the secure development of AI technology

30 November

Unitronics statement

NCSC publish mitigation advice following exploitation of Unitronics programmable logic controllers

5 December

Launch of Cyber Incident Exercising (CIE) scheme

Providing organisations with access to NCSC assured CIE service providers able to create bespoke, structured cyber incident exercises

7 December

 Star Blizzard advisory 

Joint advisory to raise awareness of the spear-phishing techniques Russian FSB cyber actor Star Blizzard are using to target individuals and organisations

7 December

 Defending Democracy guidance 

A collection of guidance published to help counter the cyber threat

15 December

 Culture sector summit 

NCSC and DCMS met with representatives from the UK cultural sector to discuss what can be done to protect institutions’ digital collections

 2024 


 

 
11 January

Ivanti advisory

Advising organisations to take immediate action to mitigate vulnerabilities affecting Ivanti Connect Secure

24 January

  Cyber Threat Assessment 

How AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years

6 February

Pall Mall Process

UK and France host conference on proliferation and irresponsible use of commercial cyber intrusion capabilities and sign the Pall Mall Process declaration

7 February

 Living off the land advisory 

A joint advisory and guidance warning CNI operators about the threat from cyber attackers using sophisticated techniques to camouflage their activity on a victims’ network

20 February 

LockBit statement

NCSC statement on law enforcement’s disruption of LockBit ransomware operation

26 February

 Five Eyes joint SVR advisory 

Revealing evolving tactics used by Russian state-linked cyber actors as more organisations move to cloud-based infrastructure

1 March

Vulnerability Researchers event

NCSC Challenge Coins presented to researchers who have contributed to vulnerability disclosure programmes across government 

4 March

 CyberFirst Girls Competition awards ceremony 

Winning teams from across the UK recognised for their success at an awards ceremony hosted at the University of Oxford’s Robotics Institute

25 March

 APT31 advisory 

UK calls out China state-affiliated actors for malicious cyber targeting of UK democratic institutions and parliamentarians

17 April

PDNS partner announced

A three-year contract awarded to Cloudflare Inc

18 April

 NCSC podcast live 

NCSC Cyber Series went live with a total of 5 episodes

19 April

 NCSC announces new CEO 

Richard Horne appointed as new CEO of the NCSC and GCHQ Board Member

22 April

Palo Alto advisory

NCSC encourage organisations to take immediate action to mitigate a vulnerability affecting Palo Alto Global Protect Gateway

24 April

CISCO advisory

The NCSC advises organisations to take immediate action to mitigate vulnerabilities affecting Cisco firewall platforms

2 May

UK local and mayoral elections

NCSC worked with partners to ensure elections were resilient

6 May

Director for National Resilience and Future Technology attends RSA Conference

Roundtable with CISA to discuss joint ‘global guidelines for AI security’ 

13-15 May

 CYBERUK 2024 

The UK government's flagship cyber security event convened over 2,000 cyber security leaders, professionals and international delegations in Birmingham

14 May

 Cyber insurance guidance 

Joint guidance from the NCSC with ABI, BIBA, IAU to help organisations faced with ransomware demands minimise disruption and cost of an incident

14 May

 Share and Defend capability launched 

A capability designed to enable protection to the UK public and businesses from cyber attacks and cyber-enabled fraud 

15 May

 Launch of Personal Internet Protection service 

The service provides an extra layer of security on personal devices for high-risk individuals  

5 JuneCyber Essentials celebrates 10th anniversary
21 June

 Synnovis incident 

NCSC working with Synnovis, NHS and law enforcement to fully investigate reports of sensitive data being published online following cyber attack 

4 July

UK General Election

NCSC work with partners to help deliver a safe and secure election

9 July

 APT40 advisory 

Australian-led joint advisory exploring how China state-sponsored actors have evolved their techniques for launching cyber attacks

10 July

Carolyn Ainsworth recognition

NCSC’s Chief Engineer named as one of the top 50 women in engineering 

19 July

 CrowdStrike outage 

Following the global IT outage NCSC issued guidance and a warning of an increase in phishing

25 July

 DPRK advisory 

Joint advisory exposing a global cyber espionage campaign carried out by attackers sponsored by the DPRK to further the regime’s military and nuclear ambitions

2 August

 ACD 2.0 blog 

Introducing ACD 2.0 and the principles that have been set

7 August

 NCSC CEO attendance at BlackHat, USA 

NCSC CEO took part in CISA’s panel focused on election security

12 August

Building a nation-scale evidence base for cyber deception 

The NCSC invited UK organisations to contribute evidence of cyber deception use cases and efficacy to support our long-term research goals

14 August

 Post-quantum cryptography blog 

NIST published three algorithm standards: ML-KEM, ML-DSA, and SLH-DSA. The NCSC has updated its PQC white paper to reflect this milestone

Published

Reviewed

Version

1.0

Written for