home.social

#ncsc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ncsc, aggregated by home.social.

  1. 3/14 · Post-Quantum Audit for Critical National Infrastructure

    An operator-side playbook for the NCSC 2031 and 2035 migration deadlines. 22 pages.

    mickai.co.uk/ebooks/post-quant

    #NCSC #PostQuantum #CNI

  2. NCSC Post-Quantum Cryptography pilot opens. Late spring 2026 to 31 March 2027 delivery window. UK PQC migration timeline: 2028 discovery, 2031 high-priority migration, 2035 full migration.

    The Mickai SIOS audit ledger is FIPS 204 ML-DSA-65 from inception. Not retrofitted. ML-DSA-87 migration is a parameter change, not a redesign.

    mickai.co.uk/articles/ncsc-pqc

    #PostQuantum #NCSC #FIPS204 #Mickai

  3. NCSC named the AI patch wave on 1 May 2026. The operators that hold ground through the forced correction will be the ones with a cryptographic position on what they patched, in what order, under whose key.

    The Mickai audit substrate is that position at the primitive layer: FIPS 204 ML-DSA-65, SHA-3-512 hash chain, browser-resident offline verifier.

    mickai.co.uk/articles/ncsc-nam

    #NCSC #AICyber #PostQuantum #Mickai

  4. Zahltag beim #Patch Management: Was jahrelang aufgeschoben wurde, rächt sich früher oder später.

    Die Tage hat das britische #NCSC vor einer bevorstehenden Flut von #Cybersecurity #Updates gewarnt. Der Auslöser: #KI ermöglicht es Angreifern zunehmend, jahrzehntelang angehäufte technische Schulden in #Software-Systemen systematisch und in einem bislang ungekannten Tempo auszunutzen.

    Die Folge: ein massives Aufkommen kritischer Patches quer durch alle Softwarekategorien:

    ncsc.gov.uk/blogs/prepare-for-

  5. Zahltag beim #Patch Management: Was jahrelang aufgeschoben wurde, rächt sich früher oder später.

    Die Tage hat das britische #NCSC vor einer bevorstehenden Flut von #Cybersecurity #Updates gewarnt. Der Auslöser: #KI ermöglicht es Angreifern zunehmend, jahrzehntelang angehäufte technische Schulden in #Software-Systemen systematisch und in einem bislang ungekannten Tempo auszunutzen.

    Die Folge: ein massives Aufkommen kritischer Patches quer durch alle Softwarekategorien:

    ncsc.gov.uk/blogs/prepare-for-

  6. Zahltag beim #Patch Management: Was jahrelang aufgeschoben wurde, rächt sich früher oder später.

    Die Tage hat das britische #NCSC vor einer bevorstehenden Flut von #Cybersecurity #Updates gewarnt. Der Auslöser: #KI ermöglicht es Angreifern zunehmend, jahrzehntelang angehäufte technische Schulden in #Software-Systemen systematisch und in einem bislang ungekannten Tempo auszunutzen.

    Die Folge: ein massives Aufkommen kritischer Patches quer durch alle Softwarekategorien:

    ncsc.gov.uk/blogs/prepare-for-

  7. Zahltag beim #Patch Management: Was jahrelang aufgeschoben wurde, rächt sich früher oder später.

    Die Tage hat das britische #NCSC vor einer bevorstehenden Flut von #Cybersecurity #Updates gewarnt. Der Auslöser: #KI ermöglicht es Angreifern zunehmend, jahrzehntelang angehäufte technische Schulden in #Software-Systemen systematisch und in einem bislang ungekannten Tempo auszunutzen.

    Die Folge: ein massives Aufkommen kritischer Patches quer durch alle Softwarekategorien:

    ncsc.gov.uk/blogs/prepare-for-

  8. Zahltag beim #Patch Management: Was jahrelang aufgeschoben wurde, rächt sich früher oder später.

    Die Tage hat das britische #NCSC vor einer bevorstehenden Flut von #Cybersecurity #Updates gewarnt. Der Auslöser: #KI ermöglicht es Angreifern zunehmend, jahrzehntelang angehäufte technische Schulden in #Software-Systemen systematisch und in einem bislang ungekannten Tempo auszunutzen.

    Die Folge: ein massives Aufkommen kritischer Patches quer durch alle Softwarekategorien:

    ncsc.gov.uk/blogs/prepare-for-

  9. **Post 2:**

    The guidance also admits prompt injection may never be solved -- and that the industry has no mature methods to evaluate whether agentic systems are behaving as intended.

    The phrase that matters: the agent might be lying to the governor.

    Not a critic. Six governments, in writing.

    haunted.lighthouse.co.im/articles/strong-governance-is-not-optional/?utm_source=mastodon

    #CyberSecurity #AgenticAI #NCSC #CISA #Governance #IsleOfMan

  10. **Post 2:**

    The guidance also admits prompt injection may never be solved -- and that the industry has no mature methods to evaluate whether agentic systems are behaving as intended.

    The phrase that matters: the agent might be lying to the governor.

    Not a critic. Six governments, in writing.

    haunted.lighthouse.co.im/articles/strong-governance-is-not-optional/?utm_source=mastodon

    #CyberSecurity #AgenticAI #NCSC #CISA #Governance #IsleOfMan

  11. **Post 2:**

    The guidance also admits prompt injection may never be solved -- and that the industry has no mature methods to evaluate whether agentic systems are behaving as intended.

    The phrase that matters: the agent might be lying to the governor.

    Not a critic. Six governments, in writing.

    haunted.lighthouse.co.im/articles/strong-governance-is-not-optional/?utm_source=mastodon

    #CyberSecurity #AgenticAI #NCSC #CISA #Governance #IsleOfMan

  12. **Post 2:**

    The guidance also admits prompt injection may never be solved -- and that the industry has no mature methods to evaluate whether agentic systems are behaving as intended.

    The phrase that matters: the agent might be lying to the governor.

    Not a critic. Six governments, in writing.

    haunted.lighthouse.co.im/articles/strong-governance-is-not-optional/?utm_source=mastodon

    #CyberSecurity #AgenticAI #NCSC #CISA #Governance #IsleOfMan

  13. UK Urges Adoption of Passkeys Over Passwords

    Say goodbye to password headaches! The UK is leading the charge towards a more secure and user-friendly login experience with passkeys, which offer stronger resilience and eliminate many common cyber threats.

    osintsights.com/uk-urges-adopt

    #Fido2 #Passkeys #PasswordManagement #NationalCyberSecurityCentre #Ncsc

  14. NCSC Warns of Flawed SOC Metrics

    The National Cyber Security Centre is warning that common security operations center metrics are fundamentally flawed, and that the only metric that truly matters is whether attacks are detected and responded to in a timely manner. By focusing on easily quantifiable but misleading metrics, organizations may inadvertently be encouraging their teams to prioritize…

    osintsights.com/ncsc-warns-of-

    #SocMetrics #SecurityOperations #Secops #NationalCyberSecurityCentre #Ncsc

  15. UK Cyber Agency Unveils Device to Secure Computer Monitors

    Meet SilentGlass, a game-changing plug-and-play device that easily secures computer monitors from cyber threats, protecting vulnerable IT infrastructure like never before. Developed by the UK's National Cyber Security Centre, this innovative gadget is set to revolutionize desktop security.

    osintsights.com/uk-cyber-agenc

    #Ncsc #Silentglass #Cyberuk #Gchq #UnitedKingdom

  16. UK Cyber Agency Unveils Anti-Malware Gadget for Display Devices

    Meet SilentGlass, a game-changing anti-malware device from the UK's National Cyber Security Centre that shields your display screens and monitors from cyber threats with unprecedented ease. This innovative gadget is now available for commercial use, protecting vulnerable IT infrastructure like never before.

    osintsights.com/uk-cyber-agenc

    #Ncsc #Silentglass #AntimalwareDevice #Uk #Gchq

  17. MI5 is briefing CNI operators. The Technology Secretary says firms have months to prepare. On the Isle of Man, the biggest unaudited risk isn't your firewall -- it's your IT provider. The Island has been here before. open.substack.com/pub/sovereig
    #CyberSecurity #IsleOfMan #Mythos #CyberEssentials #DataProtection #NCSC #SovereignAuditor

  18. For some days now I've seen a sustained attempt by #cybercriminals to exploit misconfigured / insecure #VOIP phone systems to make multiple #telephone calls to the #French #Embassy in #London (+44 20 7073 1000).

    They are not getting anywhere on two systems I run as the #security software knocks back the INVITE attempts along with all the other various #blighters , but this traffic stands out as all the attempts are to this number - it doesn't look like the perps are searching for an open trunk to misuse for spam calls or even reselling minutes on other peoples systems, but a deliberate attempt to overwhelm the switchboard at the Embassy.

    Not sure if I should report this somewhere, or its presumably already been noticed by #NCSC and #DGSE ?

  19. The Haunted Lighthouse Limited has achieved Cyber Essentials certification (whole organisation scope).

    Assessed under the IASME scheme, aligned with the UK National Cyber Security Centre baseline controls. Sensible fundamentals: patch management, MFA, least privilege, secure configuration, and disciplined backup practices.

    Not glamorous, just solid security hygiene.

    The lighthouse is officially audited.

    #CyberEssentials #IASME #NCSC #CyberSecurity #InfoSec #SmallBusiness #PrivacyFirst

  20. UK lawmakers are urging a shift toward software liability, arguing that the current model externalizes the cost of insecurity onto users and national infrastructure. Recommendations include developer liability, stronger cyber-resilience incentives, and mandatory incident reporting.

    💬 What impact would a liability regime have on secure development and supply-chain risk?

    Source: therecord.media/software-compa

    Follow @technadu for more InfoSec-focused updates.

    #InfoSec #CyberSecurity #SoftwareSecurity #TechPolicy #CyberResilience #RiskManagement #SecureDevelopment #NCSC #CyberAwareness

  21. UK lawmakers are urging a shift toward software liability, arguing that the current model externalizes the cost of insecurity onto users and national infrastructure. Recommendations include developer liability, stronger cyber-resilience incentives, and mandatory incident reporting.

    💬 What impact would a liability regime have on secure development and supply-chain risk?

    Source: therecord.media/software-compa

    Follow @technadu for more InfoSec-focused updates.

    #InfoSec #CyberSecurity #SoftwareSecurity #TechPolicy #CyberResilience #RiskManagement #SecureDevelopment #NCSC #CyberAwareness

  22. UK lawmakers are urging a shift toward software liability, arguing that the current model externalizes the cost of insecurity onto users and national infrastructure. Recommendations include developer liability, stronger cyber-resilience incentives, and mandatory incident reporting.

    💬 What impact would a liability regime have on secure development and supply-chain risk?

    Source: therecord.media/software-compa

    Follow @technadu for more InfoSec-focused updates.

    #InfoSec #CyberSecurity #SoftwareSecurity #TechPolicy #CyberResilience #RiskManagement #SecureDevelopment #NCSC #CyberAwareness

  23. ⚠️« Cybercriminalité : Le groupe AKIRA intensifie ses activités
    Berne, 16.10.2025 — Communiqué de presse commun MPC, fedpol, OFCS - Le groupe de pirates informatiques AKIRA a intensifié ses activités en Suisse ces derniers mois. Environ 200 entreprises ont été victimes d'attaques par rançongiciel. Le préjudice s'élève actuellement à plusieurs millions de francs suisses, et à plusieurs centaines de millions de dollars à l'échelle mondiale. Depuis avril 2024, le Ministère public de la Confédération (MPC) mène une procédure pénale. L’enquête est coordonnée par l'Office fédéral de la police (fedpol), en étroite collaboration avec l'Office fédéral de la cybersécurité (OFCS) et les autorités de plusieurs pays impliqués. Les autorités suisses rappellent l'importance de les contacter avant de prendre toute mesure et de déposer plainte. »
    👇

    news.admin.ch/fr/newnsb/W1jbOj

    #CyberVeille #Akira #Suisse #OFCS #NCSC #ransomware

  24. Security test of QGIS Server and QGIS Web Client: Switzerland’s National #Cyber Security Centre (#NCSC) and the National Test Institute for Cybersecurity (#NTC) have completed a pilot test assessing the #security of #QGISServer and the #QGIS Web Client. The test identified six vulnerabilities —...
    spatialists.ch/posts/2025/10/1 #GIS #GISchat #geospatial #SwissGIS

  25. Ik ben op zoek naar nieuwe collega's! Ben jij onze manager infrastructuurdiensten of digitale platformdiensten?

    Het NCSC staat voor schitterende uitdagingen en dit is jouw kans om een leidende bijdrage te leveren.

    werkenvoornederland.nl/vacatur

    werkenvoornederland.nl/vacatur

    #ncsc #werkenbijdeoverheid #vacatures

  26. "Comme prévu, des attaques DDoS ont été lancées contre plusieurs sites web suisses dans le cadre de l'Eurovision Song Contest (ESC). Jusqu'à présent, les attaques DDoS n'ont pas affecté les activités de l'ESC. Ces attaques visent à attirer l'attention des médias et n'entraînent aucune fuite de données."

    "Note à l’attention des représentants des médias
    Lors de telles attaques contre la disponibilité de sites web et de services, les auteurs souhaitent généralement attirer l'attention des médias afin de propager leur idéologie. L’OFCS demande aux journalistes donc que les rapports soient aussi sobres que possible afin que les attaquants reçoivent le moins d'attention possible."
    👇

    ncsc.admin.ch/ncsc/fr/home/akt

    #CyberVeille #Suisse #NCSC #OFCS

  27. The NCSC’s advisory deadline of 2035 for organisations to introduce quantum-safe algorithms is too late, according to some industry insiders.

    The NCSC’s advisory deadline of 2035 for organisations to introduce quantum-safe algorithms is too late, according to some industry insiders.

    computing.co.uk/news/2025/secu

    #ncsc #quantum #pqc #uk #qkd #technews #infosec #cybersecurity

  28. UK cybersecurity agency National Cyber Security Centre is recommending that organisations start replacing existing asymmetric public key cryptosystems with post-quantum cryptography (PQC) alternatives to defend themselves against quantum computers

    computing.co.uk/news/2025/secu

    #technews #quantum #quantumcomputing #cryptography #pqc #ncsc #uk #nvidia #qkd #infosec #cybersecurity