Cyber Incident Response

What is the NCSC assured Cyber Incident Response scheme?
The NCSC assured Cyber Incident Response (CIR) scheme gives clients confidence in companies which meet the NCSC’s rigorous standards for high quality cyber incident response.
CIR companies help organisations which have been the victim of a cyber attack.
Cyber attacks can take many forms such as denial of service, malware, ransomware or phishing attacks and is defined by the NCSC as:
- A breach of a system’s security policy in order to affect its integrity or availability
- The unauthorised access or attempted access to a system
How does the scheme work?
The NCSC has assessed that scheme members, referred to as CIR Assured Service Providers (ASP), can provide incident response services which conform to our CIR Technical Standards.
CIR Assured Service Providers help organisations to recover from cyber incidents and deliver a full investigation of the incident along with recommendations on how to prevent it happening again.
If your organisation has been the victim of a cyber attack, we recommend that you check gov.uk/report-cyber to identify where you should report your incident, and go to our Find an Assured CIR Provider section to select a CIR company to help you to recover from your cyber attack.
Who is it for?
The NCSC recommends that all UK organisations should use an NCSC-assured Cyber Incident Response provider when dealing with cyber incidents. This includes, but is not limited to, businesses from small, local companies to large, multi-national organisations, central and local government, and charities.
The NCSC assures Cyber Incident Response companies at two levels. Assured Service Providers from either Cyber Incident Response - Enhanced Level or Standard Level will be able to assist with most cyber incidents.