NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 14 of 32
Empowering organisations: NCSC tools and services

The services described in this section are designed to help organisations protect themselves, prepare for incidents, detect threats, and respond effectively.
The NCSC’s evolving suite of tools and services have been developed to help organisations stay ahead of the cyber criminals and hostile states that seek to do us harm. From foundational protections like Cyber Essentials to advanced frameworks such as the CAF and innovative initiatives like ACD 2.0, the NCSC continues to deliver targeted, evidence-based solutions that meet the diverse needs of UK organisations.
Cyber Governance for Boards
In partnership with the Department of Science, Innovation and Technology (DSIT), the NCSC created a Cyber Governance Training programme designed to empower boards to confidently implement the Cyber Governance Code of Practice. This tailored support package outlines the essential steps boards must take to gain meaningful oversight and assurance that cyber risks are being effectively managed.
Cyber Governance Training
Co-created with industry leaders, this training ensures boards are equipped to meet their cyber security responsibilities with clarity and confidence. The Cyber Governance Training aligns with the five core principles from the Cyber Governance Code of Practice. These are:
- Risk Management
- Strategy
- People
- Incident Planning, Response & Recovery
- Assurance & Oversight
Each module takes around 20 minutes to complete, and includes expected learning outcomes and links to relevant NCSC resources.
Cyber Action Toolkit
Smaller organisations – such as the 5 million sole traders, micro and small businesses active in the UK – can feel overwhelmed by the range of cyber security resources and guidance offered by the NCSC. For this reason, the NCSC has produced the Cyber Action Toolkit, a new way of providing advice in a way that engages small businesses, and more importantly, encourages them to take action.
The Cyber Action Toolkit is designed to be a single destination for sole traders to small organisations who are new to cyber security, and believe that cyber security is too complex, too expensive, and not a priority for their business. It provides a starting point and turns cyber protection into simple, achievable steps for businesses, allowing them to track their progress.
The Cyber Action Toolkit has been positively received by the 2,500 users who’ve taken part in our research, which showed that interactive approaches like this encourage businesses to take action when compared to simply providing cyber security guidance. The Cyber Action Toolkit has now moved to Public Beta and is being rolled out to all sole traders, micro and small businesses across the UK.
Cyber Essentials
While the cyber threat evolves, one thing remains constant; cyber criminals continue to exploit basic weaknesses in systems. Despite this, many UK organisations still aren’t guarding against even the most basic cyber threats.
We need more organisations to take action now, to put in place the foundational cyber security controls that will raise both their resilience and that of the wider UK. Getting Cyber Essentials certified can help do this.
Over a decade ago, GCHQ was challenged by industry to identify the most essential cyber security protections for organisations. Drawing on our insights and understanding of the threat, we identified 5 technical controls that every organisation, regardless of size, should implement. And despite emerging technologies and new ways of working, those 5 controls are as relevant today as they were 10 years ago.
Even sophisticated attackers will exploit basic weaknesses, and implementing these 5 controls has been proven to work; data from the Cyber Essentials Insurance company tells us that organisations with Cyber Essentials are 92% less likely to make a claim on their insurance.
10 years of Cyber Essentials
Since its launch in 2014, Cyber Essentials has steadily grown year-on-year in both take-up and recognition. In recent years this has accelerated, with certification rates increasing by over 17% in the last year. To coincide with the 10th anniversary, an independent impact evaluation report was published by the government, assessing the efficacy of the scheme.
Most Cyber Essentials users (85%) believe the scheme has directly improved their understanding of cyber security risks, while an even greater proportion (88%) believe it has improved their understanding of the steps they can take to reduce those risks.
- 86% say it has directly strengthened their senior management’s understanding of the risks posed by cyber attacks.
- 91% say that the scheme has directly improved their confidence at being able to consistently implement steps to reduce cyber security risks.
- 71% agree that the scheme has directly strengthened how seriously their organisation takes cyber security.
- 79% believe that the scheme has a positive impact on the confidence of their own clients and customers.
- 69% believe that Cyber Essentials has increased their market competitiveness.
Cyber Essentials ‘at-a-glance'
- 39,790 Cyber Essentials certifications awarded (+17.5%)
- 12,850 Cyber Essentials Plus certifications awarded (+17.3%)
- 402 Cyber Essentials Certification Bodies across the UK (+12.3%)
The top three reasons given by organisations for getting Cyber Essentials were:
- to give confidence to our customers (39%)
- to generally improve our security (31%)
- required for a contract (24%)
Of organisations that gained certification this year, the top benefits were listed as:
- it has allowed us to bid for new work
- it has given confidence to our customers and partners
- it has allowed us to advertise that we care about cyber security
95%
of customers would certify to Cyber Essentials next year
78%
would recommend certifying to other organisations like theirs
1.1%
fail rate, dropping for the fourth straight year
75%
of Cyber Essentials certifications were renewals, an increase of 3% on the previous year
(Data from IASME's review of Cyber Essentials 2024-2025)
Funded Cyber Essentials Programme
In its third and final year, the Funded Cyber Essentials Programme (FCEP) continued to strengthen the cyber resilience of small organisations in high-risk sectors by providing funding and support to help them achieve Cyber Essentials certifications. Year 3 focused on emerging technology sectors (including AI, semiconductors, advanced robotics), and in February 2025, support was extended to barristers.
Since launching in December 2022, FCEP has helped over 850 small organisations.
- Year 1: packages funded for 369 organisations
- Year 2: packages funded for 251 organisations
- Year 3: packages funded for 233 organisations
- 93% of participants that gave feedback reported that this Cyber Essentials changed the importance of cyber security within their organisation
- 100% expressed confidence in maintaining the controls implemented
The success of the FCEP is largely due to Assured Cyber Advisors—experts who offer tailored, accessible support to small organisations. They bridge the gap between technical know-how and the challenges small businesses face, such as limited budgets and in-house IT knowledge. Their clear guidance and hands-on support were vital in helping organisations achieve certification. There are now 128 Cyber Advisors working across the UK.
Cyber Essentials for supply chain assurance

Despite an increasing trend in supplier-based breaches, just 14% of UK businesses reviewed the cyber risk of their immediate suppliers in the last 12 months. This is often down to lack of capacity, capability and tools within buying organisations. The government is calling on large organisations to better address supply chain cyber security risk by developing approaches to improve adoption of Cyber Essentials within their supply chain.
- Alongside DSIT, the NCSC teamed up with the UK’s leading banks – Barclays, Lloyds Banking Group, Nationwide, NatWest, Santander UK, and TSB – to issue a joint statement encouraging businesses to strengthen their cyber defences and adopt the Cyber Essentials scheme across their supply chains.
- Cyber Essentials Impact Evaluation found 48% of respondents reported saving time on cyber security due diligence where a potential supplier is Cyber Essentials certified.
- Suppliers also report increased efficiency as they can use their Cyber Essentials certificates as evidence across their customer base, reducing the time spent filling out duplicative questionnaires.
- A new tool has been developed by IASME that allows organisations to drop a large list of suppliers into a bespoke search function and find out which suppliers are certified to either Cyber Essentials or Cyber Essentials Plus.