NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 15 of 32
Active Cyber Defence: automated prevention, at scale

The NCSC’s Active Cyber Defence (ACD) initiatives harness automation and data to prevent attacks at scale.
The services described in this section effectively operate ‘behind the scenes’, and block cyber attacks before they reach their targets. Once organisations have registered with a service, they don’t need to interact directly with the service to benefit from protections, and are instead protected automatically.
Early Warning
For many organisations, the cost of continuous network monitoring is prohibitive, and the specialist skills needed to do it often aren’t available in-house. That’s why the NCSC developed Early Warning, a free NCSC service designed to inform organisations of potential cyber attacks on their network, as soon as possible, potentially giving invaluable time to detect and stop a cyber incident before it escalates. The NCSC’s Early Warning uses information feeds from NCSC, trusted public, commercial and closed sources, which includes several privileged feeds which are not available elsewhere. You can register for Early Warning and see the other free NCSC services on the MyNCSC website.
Early Warning at-a-glance
- As of the end of the year Early warning had 13,178 organisations signed up to it.
- In total, across the year, Early Warning sent out alerts for 316,343 IP addresses belonging to customers.
- Of those events, we sent reports for 131,000 IPs we suspect had signs of being compromised by malware or hacking to 1,350 organisations
- We sent reports of vulnerabilities on 187,000 IP addresses to 4,030 organisations.
Takedown Service
We are working tirelessly to disrupt cyber attacks (such as malware and phishing sites) before they can cause damage to UK citizens and organisations. The NCSC’s Takedown Service works with hosting providers to remove malicious websites from the internet - at scale and in near real time - and blocks any attack infrastructure to limit the harm that cyber criminals can cause. No registration is required for the Takedown Service. Central government organisations benefit automatically without having to sign up.
The Takedown Service at-a-glance
1.2
million cyber-enabled commodity campaigns removed
26k
Over 26,000 phishing campaigns targeting HMG departments disrupted
79%
of confirmed phishing attacks targeting HMG departments were resolved within 24 hours of detection
50%
of these attacks were taken down within less than 1 hour (a significant improvement from the previous year which was approximately 4 hours)
Share and defend
Data from the NCSC Takedown service is used by another NCSC service, Share and Defend. This service shares feeds of known malicious domains with internet service providers (ISPs) and others so that they can be blocked or taken down. Since March 2025, Share and Defend, has blocked millions of attempts to access known scam websites, significantly enhancing online safety for millions of UK citizens. This collaborative approach, in partnership with BT and other industry leaders, is disrupting cyber-enabled crime at scale, bolstering national resilience, and supporting the government's Plan for Change.
To complement these services, last year the NCSC published:
guidance for domain registrars and operators of DNS services to reduce the prevalence of malicious and abusive domain registrations
guidance for brands to help their advertising partners counter malvertising (malicious advertising) and reduce the risk of cyber-facilitated fraud
Mail Check
Mail Check is the NCSC’s platform for assessing email security compliance. It helps domain owners identify, understand and prevent abuse of their email domains.
- 13,193 organisations now using Mail Check (3,744 last year)
- 402,796 domains scanned by Mail Check (80,464 domains last year)
- 1,014,887 Urgent or Advisory alerts raised
Web Check
Web Check helps users find and fix common security vulnerabilities in their websites. It tells you what you need to worry about, when you need to worry about it and what you need to do about it.
- 4,624 organisations using Web Check (3,923 last year)
- 133,913 domains and URLs scanned (63,384 last year)
- 569,467 Urgent or Advisory alerts raised
Suspicious Email Reporting Service (SERS)
Since its inception in April 2020, the Suspicious Email Reporting Service (SERS) has been a successful way of enabling the public and businesses to report suspicious emails to the NCSC, leading to the removal of thousands of scams.
- Over 10.9 million reports received in the last year
- Total number of reports since April 2020 reached over 45 million
- 412,000 malicious URLs removed by the NCSC since 2020
PDNS for Schools
Protective Domain Name Service for Schools ('PDNS for Schools') is a free cyber security service, developed by the NCSC, that’s designed to protect schools from a variety of online threats. It helps prevent malware, ransomware, phishing attacks, and other online threats from reaching school networks. Since rolling out the scheme in England and Scotland, over 13,000 schools are already being protected.
By early 2025, all schools across the UK were able to benefit from PDNS for schools. It’s part of a wider cyber security offer of guidance and tools the NCSC has provided so schools can focus on what they do best: educating pupils. For more additional information about the service, please visit our PDNS web pages. We intend to extend the service to schools in Wales and Northern Ireland by the end of the year.
Prior to implementing PDNS for schools, we were reporting 24m allowed queries and 19k blocked queries; and post this event these numbers increased to 66m allowed queries and a staggering 10m blocked queries. Expanding the service to protect our schools highlighted to us how our schools were exposed to significant cyber related attacks.
Medway Council
PDNS for ‘high-risk’ individuals
Nearly 600 of the UK’s high-risk individuals1, including Cabinet Ministers, are registered with the NCSC services. PDNS, which prevents access to malicious domains, has been broadened to unmanaged personal devices providing unique data insights. In response to the ongoing cyber threat of spear-phishing against personal accounts, PDNS is now available as an app. Through bespoke agreements with Google and Microsoft, the NCSC has extended free enhanced protection to hundreds of personal accounts belonging to high-risk individuals, closing a critical vulnerability gap and enabling faster threat detection and response.
1You are considered a high-risk individual if your work or public status means you have access to, or influence over, sensitive information that could be of interest to nation state actors.
High-risk individuals include those working in political life (including elected representatives, candidates, activists and staffers), academia, journalism and the legal sector.