Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 14 of 32

Empowering organisations: NCSC tools and services

The services described in this section are designed to help organisations protect themselves, prepare for incidents, detect threats, and respond effectively.

The NCSC’s evolving suite of tools and services have been developed to help organisations stay ahead of the cyber criminals and hostile states that seek to do us harm. From foundational protections like Cyber Essentials to advanced frameworks such as the CAF and innovative initiatives like ACD 2.0, the NCSC continues to deliver targeted, evidence-based solutions that meet the diverse needs of UK organisations.


Cyber Governance Training

Co-created with industry leaders, this training ensures boards are equipped to meet their cyber security responsibilities with clarity and confidence. The Cyber Governance Training aligns with the five core principles from the Cyber Governance Code of Practice. These are:

  • Risk Management
  • Strategy
  • People
  • Incident Planning, Response & Recovery
  • Assurance & Oversight

Each module takes around 20 minutes to complete, and includes expected learning outcomes and links to relevant NCSC resources.

Learn more about Cyber Governance Training



10 years of Cyber Essentials

Since its launch in 2014, Cyber Essentials has steadily grown year-on-year in both take-up and recognition. In recent years this has accelerated, with certification rates increasing by over 17% in the last year. To coincide with the 10th anniversary, an independent impact evaluation report was published by the government, assessing the efficacy of the scheme.

Most Cyber Essentials users (85%) believe the scheme has directly improved their understanding of cyber security risks, while an even greater proportion (88%) believe it has improved their understanding of the steps they can take to reduce those risks.

  • 86% say it has directly strengthened their senior management’s understanding of the risks posed by cyber attacks. 
  • 91% say that the scheme has directly improved their confidence at being able to consistently implement steps to reduce cyber security risks.
  • 71% agree that the scheme has directly strengthened how seriously their organisation takes cyber security.
  • 79% believe that the scheme has a positive impact on the confidence of their own clients and customers.
  • 69% believe that Cyber Essentials has increased their market competitiveness.

78%

would recommend certifying to other organisations like theirs

1.1%

fail rate, dropping for the fourth straight year

75%

of Cyber Essentials certifications were renewals, an increase of 3% on the previous year

(Data from IASME's review of Cyber Essentials 2024-2025)


Published

Reviewed

Version

1.0