
Risk management
How to understand and manage the cyber security risks for your organisation.
Strengthen your organisation’s cyber resilience with trusted guidance from the NCSC—tailored for government bodies, local authorities, and public services across the UK.
Helping to improve the cyber resilience of the UK government and public sector is a core part of the NCSC mission. In our role as the national technical authority for cyber security, the NCSC works with the Department of Science, Innovation and Technology (DSIT) and the devolved administrations to provide cyber security leadership across the whole of the public sector.
Where the impact has national significance, we develop direct relationships with public sector organisations and provide bespoke cyber security intervention.
How to understand and manage the cyber security risks for your organisation.
Advice, guidance and other resources for managing vulnerabilities.
Understanding the cyber security risks from suppliers and other third parties .
Fifteen best-practice measures to protect digital bulk data.
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
If you have experienced a cyber incident, and you aren’t sure which organisations to contact, you can use the UK government signposting service to help you.
Advice on implementing strong methods of MFA for accessing corporate online services.
Guidance for organisations on how to choose, configure and use devices securely.
How to defend your organisation from email phishing attacks.
Designing, building and operating digital services to deter cyber attack.
Password strategies that can help your organisation remain secure.
How to choose, configure and use cloud services securely.
Resources for organisations in the UK who have experienced an online scam or cyber attack.
Free malicious activity notifications from the NCSC for UK organisations.
Designing a security monitoring capability proportionate to the threats faced (and resources available).
Design your systems to be able to detect and investigate incidents.
Active Cyber Defence (ACD) seeks to reduce the harm from commodity cyber attacks by providing tools and services that protect from a range of attacks.
How to effectively detect, respond to and resolve cyber incidents.
The NCSC's Cyber Incident Exercising (CIE) scheme gives customers confidence that CIE Assured Service Providers meet NCSC standards for high quality cyber incident exercising.
Resources for individuals and organisations who have experienced a cyber attack.
Members of this scheme offer NCSC assured Cyber Incident Response services to a wide range of organisations.
Set a strong foundation for your organisation’s cyber security with the Government-backed certification scheme.
Looking beyond technical expertise to create and promote a positive cyber security culture.


















