This is but one of the findings from the Centre’s sixth annual Active Cyber Defence (ACD) report. The ACD itself is an NCSC programme aiming to tackle high-volume cyber-attacks that affect people’s everyday lives through a number of interventions and services.
The Suspicious Email Report Service (SERS) is one of the publicly available services offered. The ACD report discovered that, between January and December last year, 7.1 million suspicious emails and URLs were flagged by organisations and members of the public via SERS. This equates to just under 20,000 reports per day, or one every five seconds, and marks a 33% increase compared to 2021.
The NCSC found that last year’s reports led to the removal of over 72,000 malicious URLs across 40,000 scam campaigns, with the malicious URLs reported being removed from the internet within six hours on average. Further, around 235,000 malicious URLs have been eliminated by the NCSC since SERS’ launch in April 2020.
The NCSC’s Takedown Service — the centrally-managed service for finding malicious sites and then notifying the host or owner for their removal — saw a drop in the number of takedowns, with the takedowns of URLs falling from 3.1 million in 2021 to 2.4 million in 2022. The NCSC points to a reduction in frequency of certain threats, such as cryptocurrency investment scams, as the reason behind this.
Despite its fall, cryptocurrency investment scams continue to be a high-volume attack type, while the fake shop, phishing URL, brute force attack, web shell, and malware infrastructure URL attack types similarly remain highly used.
The overall increased usage of the NCSC’s publicly available cyber tools by organisations across Britain was also underscored in the sixth annual ACD report. For example, organisations using Mail Check — the NCSC’s platform for assessing email security compliance — rose from 1,530 in 2021 to 2,452 in 2022, with universities, colleges, schools, and charities cited as the primary drivers in this uptick.
Additionally, the NCSC’s Exercise in a Box (EiaB) tool, which allows organisations to improve upon their responses to cybersecurity incidents in a virtual environment, had 18,500 users worldwide, marking an increase of around 40% over 2021.
Recommended
- 6th Edition of Scots Fintech Festival Coming in September
- Aberdeen to Aberdeen: Prism Energy Acquires Mandos Software
- Edinburgh Airport to Receive New 3D Security Scanners
On many business’ desire to be cyber secure and resilient — and their usage of NCSC tools such as SERS, Mail Check, and EiaB — Martin McTague, the National Chair of the Federation of Small Businesses (FSB), said: “We’ve long championed building cyber resilience among small firms, given the persistent risk of cybercrime.
“A fifth of small businesses see cybercrime as the most impactful crime in terms of both cost and disruption to their operations.
“NCSC is doing the right thing by making its services accessible to SMEs so that they can better protect themselves in the digital world.”
Meanwhile, Jonathon Ellison, NCSC Director for National Resilience and Future Technology, said the following on the results of the latest ACD report: “In a cyber threat environment that resembles the Hydra – cut down one attack, another springs up in its place – ACD is once again doing unparalleled work to keep the country safe.
“As this latest report shows, cyber security is not the sole preserve of tech specialists: businesses are increasingly alive to and eager to engage with the cyber risks they face, signing up in swathes to make the most of NCSC data and expertise.
“Small businesses have a key role to play in making it safer to work and live online, which is why we’re making it even easier for them to shore up their defences with accessible, free tools and soon, to manage these effortlessly via our integrated MyNCSC platform.”
To read the full version of the latest ACD report, click here.





