Skip to main content

Guidance for brands to help advertising partners counter malvertising

Advice to make it harder for cyber criminals to deliver malicious advertising, and reduce the risk of cyber-facilitated fraud.
Mykyta Dolmatov via Getty Images

Who is this guidance for?

This guidance helps brands that use in-house and third-party digital advertising services choose digital advertising partners that prioritise security. 

Asking your digital advertising partners to follow the principles outlined in this document and publicly show their compliance can help raise standards across the digital advertising industry and ultimately make UK cyberspace a safer place.

Your partners can demonstrate compliance with several of these principles through independent industry-recognised certifications. 

Context to this guidance

Digital advertising is fundamental to the digital economy and depends on the interactions between those selling advertising space and those buying it, often in real time. But this can be abused and result in malicious advertising, or malvertising, which can include malware. This can lead to fraud and undermines trust in the digital advertising industry.

But by putting in place defence-in-depth measures, digital advertising partners can help reduce the presence of malvertising. These actions are transparent to the user and are consistent with the NCSC principles of secure by design, as each measure provides a layer of security which when deployed collectively, reduces harm to the end user.

This guidance lays out the actions that brands should expect of their digital advertising partners, in the form of principles. Digital advertising companies may wish to publish their response to this guidance to make it easier for potential customers to evaluate the service.









Published

Reviewed

Version

1.0