
Risk management
How to understand and manage the cyber security risks for your organisation.
Access advanced guidance, technical insights, and expert resources from the NCSC—designed to support cyber security professionals in protecting systems, networks, and national infrastructure.
The NCSC’s guidance helps UK government departments, agencies, the critical national infrastructure and its supply chains protect their information and systems. It also has relevance for local government and the wider public sector.
Our guidance provides an authoritative set of technical documents on the tools and techniques which underpin cyber security. There's advice on everything from securing end user devices to the design and implementation of identity management systems.
For professionals interested in working with the public sector, there's also a great deal of useful information on the standards and approaches we believe work best.
How to understand and manage the cyber security risks for your organisation.
Advice, guidance and other resources for managing vulnerabilities.
Understanding the cyber security risks from suppliers and other third parties .
Fifteen best-practice measures to protect digital bulk data.
Understanding the risks - and benefits - of using AI tools.
Guidance for organisations on how to choose, configure and use devices securely.
If you have experienced a cyber incident – and you aren't sure which organisations to contact – the UK government signposting service can help.
Advice on implementing strong methods of MFA for accessing corporate online services.
How to defend your organisation from email phishing attacks.
Password strategies that can help your organisation remain secure.
How to choose, configure and use cloud services securely.
We assure cyber security products and services against our rigorous standards so that you can rely on them.
Free malicious activity notifications from the NCSC for UK organisations.
Design your systems to be able to detect and investigate incidents.
Designing a security monitoring capability proportionate to the threats faced (and resources available).
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
How to effectively detect, respond to and resolve cyber incidents.
A free resource to help organisations rehearse their response to cyber attacks.
Resources for individuals and organisations who have experienced a cyber attack.
How to defend organisations against malware or ransomware attacks.
Members of this scheme offer NCSC assured Cyber Incident Response services to a wide range of organisations.
There are two levels of NCSC Assured Cyber Incident Response that can help organisations recover from an incident. NCSC Assured Service Providers operating at the technical standard required for CIR Enhanced Level will also be technically competent in providing the incident response services required by CIR Standard Level. If unsure of which level to select, see Information for buyers section.
The Cyber Assessment Framework is set of resources for operators of essential services, digital service providers and critical suppliers to manage and assess their cyber risk against the most advanced threats.
Browse or search our guidance for cyber security professionals.

















