Posts

Showing posts with the label NCSC

What the UK Cyber Security & Resilience Bill Means for Security Practitioners

Image
The UK Cyber Security & Resilience Bill is progressing through Parliament Royal Assent expected later in 2026. The UK's Cyber Security and Resilience Bill is working its way through Parliament, and if you haven't started paying serious attention yet, now is the time. Introduced to the House of Commons in November 2025, the Bill represents the most significant overhaul of UK cyber regulation since the NIS Regulations in 2018, and its implications for security practitioners are immediate and practical. What's Actually Changing At its core, the Bill expands the existing Network and Information Systems regulatory framework. It brings more organisations into scope, imposes stricter incident notification requirements, and hands regulators substantially more enforcement power. Secondary legislation and statutory Codes of Practice will follow, but the primary architecture of what you'll be working within is already taking shape. One of the most significant shifts for prac...

NCSC Warns UK Organisations to Prepare for Potential Iran-Linked Cyber Activity

Image
Geopolitical conflict rarely stays confined to physical battlefields. Increasingly, it spills into the digital domain. The latest escalation of tensions in the Middle East has prompted the UK’s National Cyber Security Centre (NCSC) to issue a warning to organisations  to review their cyber security posture and prepare for possible cyber activity linked to Iran. While the NCSC has stressed that there is currently no confirmed significant increase in direct cyber threats to the UK, it has warned that the situation is fast-moving and organisations should remain alert. Rising Tensions and Cyber Spillover The warning follows a sharp escalation in the regional conflict involving Iran, the United States and Israel. Military developments have been accompanied by cyber activity targeting digital infrastructure and online services in the region, highlighting how modern conflicts now run across both physical and digital fronts. In response, the NCSC has advised UK organisations to review the...

10 Things You Might Not Know About Cyber Essentials

Image
  I ASME  del iv ers Cyber Essentials on behalf of UK  NCSC By Sam Jones | Cyber Tec Security  and Dave Whitelegg What is  Cyber Essentials?  If you are just hearing about the Cyber Essentials scheme, read on as we unpack 10 things you might not know about Cyber Essentials. 1. UK Gov Launched Cyber Essentials in 2014 The UK Government  National Cyber Security Centre (NCSC) published its ‘10 Steps to Cyber Security in 2012' , after the UK Government agencies recognised small-medium sized UK businesses require further cybersecurity guidance and support in order to protect the British digital dependant economy.  This led to the development of five critical 'cyber essentials' technical security controls which provides a minimum level of cybersecurity protection. Assurance of the adoption of these five security controls by an organisation provides a good degree of confidence an organisation is protected against the most common cyber threats, th...

The Key to Cybersecurity is an Educated Workforce

Image
The United Kingdom's National Cyber Security Centre (NCSC) handled a record number of cybersecurity incidents over the last year, a 20% increase in cases handled the year before. With the increasing number and more innovative nature of cyber attacks, businesses of all sizes must prioritise cybersecurity. However, the fundamental starting point of any organisation’s security infrastructure must be a trained and aware workforce, who understand their responsibility in keeping business data safe. Oliver Paterson, Product Expert, VIPRE Security Awareness Training and Safesend , explains. Business Size Doesn’t Matter Whether a business is a start-up or a larger corporate organisation, all companies are at risk of a cyber-attack. We often see million-pound enterprises on the news when they suffer from a data breach, such as Estée Lauder, Microsoft and Broadvoice . But, no organisation is too small to target, including small and medium-sized businesses (SMBs), who are the target for an es...

Cyber Security Roundup for May 2021

Image
   A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, April 2021. Think Before You LinkedIn! Business social media platform LinkedIn is being exploited by nation-state threat actors to target UK citizens.  The UK Security Service MI5 said 10,000 staff from every UK government department and from important UK industries have been lured by fake LinkedIn profiles. MI5 said the faked LinkedIn accounts are created and operation by nation-state spy agencies, with an intent to  recruit individuals or gather sensitive information. MI5 released a campaign video called "Think Before You Link" to raise awareness  of the threat. The personal information of 11 million UK Facebook profiles were been found on a hackers website , with the social media giant seemingly dismissing the significance of the data within a statement, " This is old data that was previously reported on in 2019...

Cyber Security Roundup for March 2021

Image
  A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, February 2021. Serious Linux Vulnerability Last month  a newly discovered critical vulnerability in 'sudo', a fundamental program present in all Linux and Unix operating systems caught my eye. The sudo vulnerability aka  CVE-2001-3156 , seemed to go under the radar after it was announced and patches were released on 26th January 2021. I  wrote a blog post  about my concerns given Linux is embedded everywhere, yet many of these systems are rarely, and even never updated with security updates. From IoT devices to internet-based services, the security of countless devices and web-based services' are dependant upon a secure Linux account privilege model. While these Linux operating systems remain unpatched to prevent exploitation of the CVE-2021-3156 vulnerability, there are waiting to be hacked. Npower App Hack Npowe...

Solorigate: SolarWinds Orion Compromise Overview

Image
On 13th December 2020, it came to light SolarWinds IT systems were compromised by hackers between March 2020 and June 2020. SolarWinds provides software to help organisations manage their IT networking infrastructure. The attackers exploited their SolarWinds IT access to covertly insert a vulnerability, coined 'Solorigate' or 'Sunburst', within the SolarWinds Orion platform software builds.  The following SolarWinds Orion versions are considered to be compromised.  Orion Platform 2019.4 HF5, version 2019.4.5200.9083 Orion Platform 2020.2 RC1, version 2020.2.100.12219 Orion Platform 2020.2 RC2, version 2020.2.5200.12394 Orion Platform 2020.2, 2020.2 HF1, version 2020.2.5300.12432 The vulnerability within these 'tainted' SolarWinds Orion versions permits an attacker to compromise the server on which the SolarWinds Orion product is installed and runs.  Given that SolarWinds is a popular network traffic monitoring product, thousands of organisations are said to be i...

Cyber Security Roundup for December 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, November 2020. Manchester United FC remains impacted by a seemly major cyber-attack, which I covered in a blog post titled  The Multi-Million Pound Manchester United Hack . At this point, United have provided few details about their cyber-attack which has been impacting club's IT systems for well over a week. However, the UK media are widely reporting United's leaky IT defences was unable to prevent a ransomware attack and data theft.   London's Hackney Borough Council have also been tight-lipped about what they describe as " a serious cyber-attack "  which has impacted its service delivery to Londoners. Like United, this attack has all the hallmarks of a mass ransomware outbreak. Both Manchester United and Hacknet Council said they are working UK's National Cyber Security Centre (NCSC). Man.Utd hit by ransomware, w...