Guidance for brands to help advertising partners counter malvertising

On this page
- Make sure that strong ‘know your customer’ checks are in place
- Employ strong cyber security practices
- Use data from reputable sources
- Implement industry standards
- Employ effective malvertising detection and removal services
- Collaborate to share threat intelligence
- Put in place reliable reporting mechanisms
- Demonstrate a transparent approach
Who is this guidance for?
This guidance helps brands that use in-house and third-party digital advertising services choose digital advertising partners that prioritise security.
Asking your digital advertising partners to follow the principles outlined in this document and publicly show their compliance can help raise standards across the digital advertising industry and ultimately make UK cyberspace a safer place.
Your partners can demonstrate compliance with several of these principles through independent industry-recognised certifications.
Context to this guidance
Digital advertising is fundamental to the digital economy and depends on the interactions between those selling advertising space and those buying it, often in real time. But this can be abused and result in malicious advertising, or malvertising, which can include malware. This can lead to fraud and undermines trust in the digital advertising industry.
But by putting in place defence-in-depth measures, digital advertising partners can help reduce the presence of malvertising. These actions are transparent to the user and are consistent with the NCSC principles of secure by design, as each measure provides a layer of security which when deployed collectively, reduces harm to the end user.
This guidance lays out the actions that brands should expect of their digital advertising partners, in the form of principles. Digital advertising companies may wish to publish their response to this guidance to make it easier for potential customers to evaluate the service.
Make sure that strong ‘know your customer’ checks are in place
Implementing robust ‘know your customer’ (KYC) checks makes it more difficult for malicious actors to use the services of digital advertisers and to co-exist with your own ad campaigns. While these checks can add onboarding friction, there are benefits to strong verification of customers. These checks also mean that more information is available if an incident does happen.
KYC checks should be proportionate to the potential risk, but it is often the case that they don’t go far enough. You should expect your suppliers to:
- identify and verify customer identities
- identify and verify identities of beneficial owners (anyone who owns 25% or more of the company)
- verify any claimed ownership of domains, assets, images or brands
- continuously monitor customers and transactions to identify things such as:
- activity spikes that can’t be explained
- activity in regions known for money laundering and other financial crimes
- whether customers or individuals with controlling stakes appear on sanctions or adverse media lists
Employ strong cyber security practices
You should have confidence that your provider is taking appropriate steps to secure the whole digital advertising operations infrastructure to manage the risk of a cyber attack.
They should be able to explain how they design, build, manage and maintain their whole advertising operations infrastructure. This includes securing both:
- hardware, such as ad servers and bidders
- the integrity of code and information passed through the advertising supply chain, such as markup like JavaScript
The NCSC has guidance for organisations on designing, building, maintaining and managing systems securely to support this.
Your provider should also be able to describe where they have outsourced services, such as ad servers or serving third-party code, and what due diligence they have carried out to make sure these entities meet high security standards.
Use data from reputable sources
The advertising-technology industry facilitates a large real-time exchange of data. This can attract unscrupulous data brokers to operate in this space, that collect, process and sell data illegally.
While many organisations uphold high standards to protect data that deliver online advertising, it's important to recognise when special categories of personal data are in use, and to make sure they are processed lawfully, fairly and transparently under UK General Data Protection Regulation (GDPR) legislation.
The Information Commissioner’s Office provides guidance on planning online marketing campaigns that are compliant with UK GDPR. You can ask your supplier to demonstrate how they are protecting personal data. This may also apply to your own organisation.
Your organisation can also choose to buy inventory only through verified channels, namely channels that are certified as meeting published standards. You should consider asking all prospective partners to demonstrate they are meeting your requirements.
Implement industry standards
As a brand advertiser, it is reasonable for you to expect clarity about where your money is spent in the value chain. You should check that your suppliers are clear about whether they are enforcing industry-recognised initiatives such as:
- ads.txt – a method for publishers and distributors to declare who is authorised to sell their inventory, improving transparency for programmatic buyers. app-ads.txt aims to achieve the same thing as ads.txt but for mobile and over-the-top applications.
- buyers.json and DemandChain Object – provide transparency around all the entities involved in the bid response for a particular impression, and support defenders to trace the source of malicious ads across platforms, so they can take action to stop them.
Independent industry-recognised certifications, such as those offered by TAG or IAB UK, provide a comprehensive baseline of good practice.
It is also reasonable to expect that an organisation responsible for delivering your campaign is screening adverts to check for signs of malicious behaviour, and to make sure they are in line with regulations. For example, any financial promotions in the UK relating to financial services must be approved by a person authorised by the Financial Conduct Authority (FCA). UK organisations and individuals offering financial services must also be authorised or registered by the FCA to carry out certain activities.
Employ effective malvertising detection and removal services
The organisations helping to deliver your campaigns should be taking action to prevent harm to users. You also want assurance that the adverts appearing on the same sites and pages as your own are reputable and trustworthy.
You can support the wider effort here by demanding effective malvertising detection and removal services across an intermediary’s advertising assets and publisher’s landing pages. This is a continuous process, which should apply before and throughout an advertising campaign.
You should expect your partners to be able to provide information about:
- how they handle malvertising detection and removal services
- the vendor they use, if any, to detect and remove malvertising, and whether this includes ‘cloaking’, where the harmful nature or destination of an advert is hidden
- the scope of their assets where scanning, detection and removal are in place
- how they monitor for any changes during the lifecycle of an ad campaign
- how an attack, if one happens, is escalated and investigated
Collaborate to share threat intelligence
Advertisers, publishers and advert networks should collaborate to share threat intelligence. By pooling information about emerging threats, it is possible to respond faster to new attacks and proactively prevent an attack that is detected on one platform also appearing on others.
Partners should be able to explain their policy for sharing with the wider community and also how they use third-party data to protect their services.
Industry partners run mechanisms for sharing and receiving threat intelligence across the digital advertising industry, for example, the registered Information Sharing and Analysis Organisation (ISAO).
Put in place reliable reporting mechanisms
A reputable partner should have an intuitive and reliable mechanism to receive reports of malicious or suspicious activity. Reports may come from a variety of sources, such as advertisers, publishers or even consumers and the reporting mechanism should be tailored to who is receiving it.
It is reasonable to expect that when you report security issues to your supplier, you receive timely acknowledgement, a clear explanation of what will happen next, and a summary of findings and actions at the end of the investigation. Your supplier should be able to explain:
- how to report abuse – is this intuitive and practical for the user reporting individual instances, or does it allow for reporting at scale (such as via an API) in the case of an industry partner?
- their process for assessing malvertising events, and determining whether an event is an incident
- their process for escalating malvertising incidents within their organisation, and with their partners, to enable appropriate and timely resolution
- what response you can expect in terms of timescales and possible interventions
- whether you will have a dedicated point of contact
- what your options are if you need to appeal a decision
- how your brand will be protected by reports received from other parties, such as publishers, consumers, threat intelligence collaborators or internal findings
Demonstrate a transparent approach
You should expect your partners to be willing to demonstrate how they reduce user harm and to openly signal their commitment to securing end users and your advertising spend.
You can ask current and prospective partners to provide comprehensive answers against these principles. Options here are to publish their answers publicly, or achieve certification through independent industry-recognised schemes.
The measures above will go a long way to help reduce harm to users, protect your brand and improve trust in digital advertising.


