Site navigation

New Gov Cyber Tool Cuts Attack Fix Times by 84%

Tom Quinn

,

UK gov cyber tool
“As our public services continue to innovate, it is vital that they remain resilient to evolving threats and vulnerabilities are being effectively managed to reduce the chances of disruption,” said Richard Horne, NCSC.

The UK Government has launched a new vulnerability monitoring service (VMS), which it claims can identify and fix critical cyber weaknesses across the public sector six times faster than before.

Following cyber-attacks against essential public service organisations, including the Legal Aid Agency and branches of the NHS, the government’s specialist monitoring service aims to slash average incident‑response times from almost two months to barely a week.

The new service targets vulnerabilities in the Domain Name System (DNS), essentially the internet’s address book, flaws which can allow attackers to redirect users to fraudulent sites, steal sensitive data, or take services offline entirely, resulting in potentially serious consequences for those relying on public services. 

Before this VMS was in place, the government said that these exploitable gaps in DNS records could go unnoticed for nearly two months, long enough for a hostile actor to redirect access from a government service to a malicious site.

According to the government, the vulnerability monitoring service has managed to close this window down to 8 days and produces alerts with clear, practical guidance for admins on how to fix the problem. When a weakness is identified, the service alerts the relevant organisation with specific, actionable guidance and tracks progress until the issue is resolved.

The VMS continuously scans 6,000 UK public sector bodies, detecting around 1,000 different types of cyber vulnerabilities, and has so far processed and resolved around 400 confirmed vulnerabilities each month.

By automating detection and streamlining remediation, the government claims the service has produced an 84% improvement in the time to fix domain-related vulnerabilities, reduced median time to fix other cyber vulnerabilities from 53 days to 32 days, and cut the backlog of critical open domain-related vulnerabilities by 75%.

“Cybersecurity is more consequential than ever today, with attacks in the headlines showing the profound impacts they can have on people’s everyday lives and livelihoods,” said Dr Richard Horne, CEO of the National Cyber Security Centre.

“As our public services continue to innovate, it is vital that they remain resilient to evolving threats and vulnerabilities are being effectively managed to reduce the chances of disruption.”

Along with the VMS, the government has also launched a dedicated “Cyber Profession” programme, which will work to recruit and train top-tier cyber experts needed to secure public services against advanced threats.


Recommended reading


Spearheaded by the Department for Science, Innovation and Technology alongside the NCSC, the initiative will introduce a competitive offer for top cyber talent, establish a dedicated Cyber Resourcing Hub to streamline recruitment, and create a career framework aligned with UK Cyber Security Council professional standards. 

It will also include a government Cyber Academy for training and development, a new apprenticeship scheme to build future talent, and structured career pathways to strengthen long-term capability across the public sector. 

The North West will serve as a primary hub for the profession, building on Manchester’s growing digital ecosystem and the forthcoming government Digital Campus.

“The government Cyber Action Plan is a crucial step in building stronger cyber defences across our public services, and the launch of the government Cyber Profession today will help attract and retain the most talented professionals with the top-tier skills needed to keep the UK safe online,” continued Horne.

 


Join the Conversation at ITSX Summit

How is customer service and IT support evolving in the age of AI, automation, and digital transformation?

Join us at the ITSX Summit in Edinburgh on 5th March, to unpack the future of ITSM, ESM, Self Service, and User Experience.

The event will bring together senior leaders from IT, Service Management, and UX, providing an ideal forum for shared learning, collaboration, and high-level networking.

Register now to secure your free place at ITSX Summit.

 

Image designed by katemangostar / Freepik

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data