Guidance
Risk management
How to understand and manage the cyber security risks for your organisation.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 15

Our lives have been transformed by digital technologies but they are vulnerable to attack, misuse, and abuse. Attackers can exploit weaknesses which poses a risk to the systems, services and information on which we depend.
The NCSC has guidance to help you understand and manage the cyber security risks to your organisation.
This guidance is for cyber security risk practitioners who help their organisations understand and make decisions in this area. It will also be helpful to people who are setting up a cyber security risk management function in their organisation for the first time, or looking to improve existing functions.
The guidance introduces some core risk management concepts. It then provides a framework of high-level steps that can be used to form the basis of any cyber security risk management process.
To support this framework, more detailed guidance is provided to:
If you are new to cyber security risk management, or don’t know where to start, a basic risk assessment method is included, with clear guidance on its limitations.
More experienced practitioners will benefit from the sections on:
Improving business outcomes should be the primary driver for cyber security risk management. We advocate meaningful cyber security risk management that illuminates the real cyber risks that are applicable to your organisation and how it operates, rather than the use of techniques which just seek to satisfy compliance requirements.
For these reasons, this collection of guidance is not prescriptive. No single technique in this guidance will be useful in every situation. It is therefore important that you take care to understand why you have chosen the cyber security risk management techniques, methods and approaches you use, and how they can help you and your organisation better understand the cyber security risks you face.


