This guidance is aimed at medium to large organisations that have someone dedicated to managing the organisation's cyber security. For smaller organisations our Cyber Action Toolkit might be a better place to start, though the principles here in the 10 Steps are applicable to all organisations.
This collection is designed for security professionals and technical staff as a summary of NCSC advice, and provides links to more detailed guidance where applicable. It can also be used alongside our Cyber Security Toolkit for Boards, which contains questions to help frame discussions between you and your Board, and further resources you can point your Board towards. Cyber security is central to the health and resilience of any organisation reliant on digital technology to function, and this places it firmly within the responsibility of the Board.
How can this guidance help me?
This guidance aims to help organisations manage their cyber security risks by breaking down the task of protecting the organisation into 10 components. Adopting security measures covered by the 10 Steps reduces the likelihood of cyber attacks occurring, and minimises the impact to your organisation when incidents do occur.
Understanding what you are trying to protect against is essential to managing cyber security risk. The video below talks about the common threat actors behind cyber attacks, and to keep up to date with cyber security matters affecting the UK see our latest reports and advisories.