Ransomware: ‘WannaCry’ guidance for enterprise administrators

Ransomware: ‘WannaCry’ guidance for enterprise administrators Summary The UK National Cyber Security Centre (NCSC) provides pragmatic, actionable guidance for enterprise administrators to reduce the risk of being hit by the WannaCry ransomware (and similar threats). Core advice centres on applying Microsoft’s MS17-010 patch, disabling SMBv1 where patching is not possible, isolating legacy systems, and ensuring […]

Read More →

Mitigating malware and ransomware attacks

Mitigating malware and ransomware attacks Summary This NCSC guidance explains how organisations can reduce the likelihood, spread and impact of malware — including ransomware. It outlines a defence-in-depth approach with layered mitigations, practical actions to prepare (backups, patching, filtering and hardening), and clear steps to follow if an infection occurs. The guidance emphasises backups, limiting […]

Read More →

Cyber security for high profile conferences

Cyber security for high profile conferences Summary This NCSC guidance extends its Major Events advice to cover cyber security for high-profile conferences, addressing both physical and virtual risks. It explains how to assess threats based on event topic and attendees, and recommends controls for identity and access, denial of service resilience, supplier assurance, website protection, […]

Read More →

Macau operators’ significant investment in entertainment to pay dividends even beyond Golden Week | AGB

Macau operators’ significant investment in entertainment to pay dividends even beyond Golden Week | AGB Summary Macau’s casino operators have been doubling down on entertainment — booking sports fixtures, NBA games and major concerts — to broaden appeal and drive both gaming and non-gaming revenue. The strategy is already showing results: Golden Week is expected […]

Read More →

Cyber resilience matters as much as cyber defence

Cyber resilience matters as much as cyber defence Summary The NCSC argues that planning and rehearsing recovery is as vital as building strong defences. Recent disruptions to UK retailers and manufacturers show why medium and large organisations must prepare not only to prevent attacks but also to keep services running and recover quickly when incidents […]

Read More →

From bugs to bypasses: adapting vulnerability disclosure for AI safeguards

From bugs to bypasses: adapting vulnerability disclosure for AI safeguards Summary This NCSC blog (co-authored with the AI Security Institute) examines how established cyber security practices — especially vulnerability disclosure and bug-bounty approaches — can be adapted to help find and mitigate “safeguard bypasses” in frontier AI systems (general-purpose models such as ChatGPT, Gemini, Llama […]

Read More →