Early Warning
Free malicious activity notifications from the NCSC for UK organisations.
In just 5 minutes, sign up to receive email alerts from the NCSC tailored to the cyber threats for your organisation's IP address.

Who is it for?
Any organisation based in the UK.
Early Warning can help provide you with a basic layer of cyber security. It’s a free and easy-to-use service from the NCSC.
Register for Early Warning
It's easy!
All you need are these basic details to sign up.
- A MyNCSC account (if you don't have an account, follow the link below to create a free account)
- Your organisation's name
- Your organisation's public IP addresses and domain names
- The details of the contacts you wish alerts to go to (at least name and email address)
Identify cyber threats before they escalate
Early Warning delivers an average of 2,000 alerts each month to our users, offering potentially invaluable time to detect and stop a cyber incident.

What Early Warning can do for you
-
Receive alerts to the presence of malware and vulnerabilities affecting your network*.
-
Boost your organisation’s security by being aware of the low-grade incidents which might become much bigger issues, so you can act on them before they become bigger problems.
-
Increase confidence in the security of your network.
* Early Warning will notify on all cyber attacks detected by our feed suppliers against your organisation. This should not be used as the only layer of defence for a network. Early Warning should complement your existing security controls.
Need some more advice about other security controls, check out these NCSC services.
43% of businesses and 30% of charities report having experienced some form of cyber security breach or attack in the last 12 months.
*2025 Cyber Breaches Survey

About Early Warning
Early Warning is a free NCSC service designed to inform your organisation of potential cyber attacks on your network, as soon as possible, potentially giving you the crucial time needed to combat it.
Cyber security researchers will often uncover malicious activity on the internet or discover weaknesses in organisations security controls, and release this information in information feeds. In addition, the NCSC or its partners may uncover information that is indicative of a cyber security compromise on a network.
The NCSC’s Early Warning uses information feeds from NCSC, trusted public, commercial and closed sources, which includes several privileged feeds which are not available elsewhere.
Two types of daily and weekly reports received directly to your email will alert your organisation about potential attacks on your network.
Organisations will receive the following high level types of alerts, tailored to the information they registered with:
-
Incident Notifications
- suggest an active compromise of your system.
For example: A host on your network has most likely been infected with a strain of malware.
-
Network Abuse Events
- Indicates that your assets have been associated with malicious or undesirable activity.
For example: A client on your network has been detected scanning the internet.
-
Vulnerability and Open Port Alerts
- Indicates vulnerable services running on your network, or potentially undesired applications are exposed to the internet.
For example: You have a vulnerable application, or you have an exposed Elasticsearch service.
Note: Early Warning does not conduct any active scanning of your networks itself but uses information from other similar networks.