Skip to main content

Products & services

Prepare for potential cyber security attacks

Learn about the range of products, tools and services available to help your organisation find and fix vulnerabilities and minimise the risk of a successful cyber attack.

All organisations should regularly assess their IT infrastructure to make sure it is secured against cyber attack.

There are a variety of activities you can undertake to test the resilience of your organisation to a range of different types of cyber attack. These include tests of your IT systems, people and processes. Each plays a different role in protecting organisations from cyber attack.

This section describes the types of assessments and services that are available to help you make informed choices to prepare your organisation.

Exercising

Exercising is when your organisation plays out one or more scenarios that may occur as part of a cyber attack to assess how resilient your organisation is, practice your response and identify any fixes needed to make your organisation more resilient.

The scenarios can range in scale and threat level to suit different types of organisations, from an employee’s mobile device being stolen to the threat of sensitive data link in your national supply chain.

Exercise in a Box

A free resource which helps organisations find out how resilient they are to cyber attacks and practise their response.

Discover Exercise in a Box

Pen Testing

A penetration test is an authorised simulated cyber attack on your computer system, or custom software, to attempt to breach that system to evaluate its security.

Penetration testing is often completed using the same tools and techniques that an adversary might.

Cyber Security Consultancy

Cyber security consultancy supports your organisation through a range of services that will help you improve your cyber security processes. This might include offering support on risk management; help with the design of IT systems or even in the compliance with security policies, standards and regulatory requirements. Or, for less cyber-mature organisations, it might offer basic advice and practical support to help you get started.

Cyber Resilience Audit

Cyber Resilience Audit (CRA) assesses and evaluates security measures to identify vulnerabilities, ensure compliance and protect sensitive information. This can help oversight bodies understand the level of cyber resilience of individual organisations in their sector, building a more accurate picture of resilience at both a sector and national level.