The year three report covers 2019 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme
The Active Cyber Defence (ACD) programme's aim is to ‘Protect the majority of people in the UK from the majority of harm caused by the majority of cyber attacks the majority of the time.’
This third annual report (covering the 2019 calendar year) aims to provide transparency on these efforts, and evidence on their effectiveness.
This report includes sections for each of the services present in the second year report, along with some introductions to newer work from 2019. To highlight just a small selection of the progress we’ve made in 2019:
the Takedown Service continued to result in a significant reduction in ‘badness’ on the internet, and adapted to the changing behaviour of bad actors
DMARC adoption continued, we developed a better understanding of how to coach organisations through adoption, and we are continuing to keep track of email security standards
we developed a prototype capability to detect subdomain hijack vulnerability at scale
The ACD programme seeks to stop a range of different attacks ever reaching UK citizens, institutions or businesses. Working in a relatively automated and scalable way, it removes the burden of action from the user and enables attacks to be taken down at scale.