The NCSC is looking to build on its Active Cyber Defence programme by developing a new suite of services in line with the threat posed by modern commodity cyber-attacks, the pre-packaged malicious tools and services illegally sold online that includes ransomware, phishing bots, and command and control servers.
First launched in 2016, the ADC program was designed as a national response to the harm caused by commonly available malware tools on organisations unable to keep pace with the evolving threat. The initiative provides a number of free to use cybersecurity tools and services, to target these high-volume commodity attacks.
Those range from self-service checks that allow organisations to check and improve their own security, to so-called ‘Disrupt and Defend’ services, designed to trigger automatic responses and mitigate ongoing cyber-threats in real time.
With this refresh of the programme, the NCSC plans to take a step back from active development and work with the private sector to deliver solutions where it deems the market is not able to, utilising its ability to work at scale to broaden protections.
In a blog post, Ollie Whitehouse, chief technology officer at the NCSC, and Jonathon Ellison, director of national resilience, wrote: “It’s important that the UK’s National Cyber Security Centre focuses its efforts where we can make a uniquely valuable contribution – where we see a gap in the commercial market, or where being part of GCHQ presents a unique opportunity to drive up resilience at scale.”
Recommended reading
- What is the Current Data Telling Us About Cyberattacks?
- Strong Cybersecurity Key to AI Superpower Ambitions, Microsoft Says
- The Unique Cybersecurity Threats Facing Education Institutions
In line with this new approach, the NCSC plans to divest services within three years to another part of government or the private sector to run on an permanent basis.
The first step will be to look at building on the attack surface management suite currently on offer, including the Web Check, Mail Check and Early Warning systems. According to the NCSC it will run ‘experiments’ alongside private industry partners to develop these core systems further.
The goal is to enable organisations to understand and reduce their own attack surface and related vulnerabilities, considered by the organisation as the most efficient way to drive up external resilience.
The NCSC provided some indication of this new approach earlier this year, when it released guidance for CEOs to navigate cyber incidents in an effort to ensure organisations are better at managing breaches and cyber-attacks as the number of cybersecurity threats continues to rise.





