NCSC expands incident response scheme to support smaller at-risk organizations
Charities, small public sector organizations, and local authorities will be covered by the expanded scheme


The UK’s National Cyber Security Centre (NCSC) has announced an expansion to its Cyber Incident Response (CIR) scheme in a move that has been welcomed by industry figures.
In a statement on Wednesday, the authority revealed that it plans to introduce a new level of coverage through the scheme, meaning that more companies will be able to provide incident response services to a “wider range and larger number” of organizations across the country.
The move is aimed specifically at providing support for charities, local authorities, smaller public sector organizations, and firms operating outside of critical national infrastructure, the NCSC said.
In its prior setup, the CIR scheme focused on providing incident response services to organizations “running networks of national significance”. This applied to central government departments, critical national infrastructure organizations, and regulated industries.
While this aimed to offer protection to organizations at high risk of targeted attacks by cyber criminals and nation-state-backed groups, many industry stakeholders were excluded from coverage due to their size.
Chris Ensor, deputy director of cyber growth at the NCSC, said the expansion of the CIR will give confidence to a wider range of organizations at risk of cyber attacks.
“Falling victim to a cyber attack is really stressful. Finding someone with the skills and knowledge to help can also be hard, if, like many, you are not familiar with the cyber security world,” he said. “For many years, we have Assured Cyber Incident Response services for organizations targeted by the most sophisticated threat actors.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“I am really pleased that we can now assure a similar service for any organizations affected by criminal threat actors, a service that will be good enough for the majority of incidents that smaller organizations face. The NCSC badge will give confidence that the company they use has the right expertise to help them.”
RELATED RESOURCE
Learn how to use threat intelligence to fight ransomware attacks and how data is used to give you an advantage.
DOWNLOAD FOR FREE
Joseph Carson, chief security scientist and advisory CISO at Delinea, welcomed the move, noting that the expansion of the scheme is a well-needed “refresh”.
“The new update is an important and needed refresh that will provide all organizations with a service that will be relevant for most cyber security incidents, rather than a focus on purely organizations running networks of significance, such as central government, critical national infrastructure, and regulated industries,” he said.
Growing cyber security threats
The move by the NCSC comes against a backdrop of heightened cyber security threats facing businesses across the UK.
Third-sector organizations in particular have become lucrative targets for threat actors in recent years, representing easier prey than their private-sector counterparts, according to the NCSC’s own analysis.
Statistics from the UK government’s data breach report, published in late 2022, found that 30% of UK charities were hit with a cyber attack across the year.
87% of those reported experiencing phishing attempts, while nearly one-quarter (23%) were subjected to ransomware attacks.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Two years on from its Series B round, Hack the Box is targeting further growth
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
Five Eyes cyber agencies issue guidance on edge device vulnerabilities
News Cybersecurity agencies including the NCSC and CISA have issued fresh guidance on edge device security.
By Emma Woollacott
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice
-
State-sponsored cyber crime is officially out of control
News North Korea is the most prolific attacker, but Russia and China account for the most disruptive and tightly-targeted campaigns
By Emma Woollacott
-
Modern enterprise cybersecurity
whitepaper Cultivating resilience with reduced detection and response times
By ITPro
-
IDC InfoBrief: How CIOs can achieve the promised benefits of sustainability
whitepaper CIOs are facing two conflicting strategic imperatives
By ITPro
-
The NCSC and FBI just issued a major alert over a state-backed hacker group – here’s what you need to know
News State-affiliated attackers are targeting individuals via spear-phishing techniques, according to the NCSC
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
The NCSC wants to know how your business is using honeypots to combat hackers
News The NCSC hopes to encourage the use of cyber deception techniques within the UK, across government and critical national infrastructure
By Emma Woollacott