NCSC Early Warning: What It Does and How to Use It

Cyber incidents affecting UK organisations are becoming more frequent and more disruptive. The National Cyber Security Centre (NCSC) handled 204 nationally significant cyber attacks in the 12 months to August 2025, an average of four each week.

Not every organisation can operate a dedicated security operations centre, but every UK organisation can take advantage of one useful source of government-backed threat information. NCSC Early Warning is a free service that alerts organisations when trusted information feeds suggest malicious activity, vulnerabilities or exposed services associated with their public IP addresses and domain names.

Early Warning is not a complete security service and does not actively scan your network. Used alongside monitoring, vulnerability management, secure configuration and an incident-response plan, it can provide valuable time to investigate a potential problem before it becomes a more serious incident.

What is NCSC Early Warning?

Early Warning is part of the NCSC’s Active Cyber Defence programme. It compares the public IP addresses and domain names registered by an organisation against information received from the NCSC and trusted public, commercial and closed sources.

When the service identifies information relevant to a registered asset, it presents findings through MyNCSC and sends reports to the organisation’s nominated contacts. The NCSC states that Early Warning delivers an average of around 2,000 alerts each month across its users.

The service is available to UK organisations and is free to use. To register, an organisation needs:

  • A MyNCSC account.
  • Its organisation name.
  • Its public IP addresses and domain names.
  • The names and email addresses of the contacts who should receive alerts.

Any UK organisation with a static public IP address or domain name can use the service. This includes businesses, charities, public bodies, education providers and other eligible organisations.

What alerts does Early Warning provide?

Early Warning provides three main categories of finding.

Incident notifications

An incident notification suggests that a system may already be compromised. For example, a host associated with your network may have been observed communicating in a way that indicates malware infection.

This type of alert should be investigated promptly. The organisation may need to identify and isolate the affected device, review endpoint and network telemetry, reset exposed credentials and preserve evidence for a wider incident investigation.

Network abuse events

A network abuse event indicates that an asset associated with your organisation has been linked to malicious or undesirable activity. One example is a device on your network being observed scanning other systems on the internet.

This can indicate malware, an exposed service, an incorrectly configured system or a legitimate activity that needs to be confirmed. The finding should not be dismissed until the source and reason are understood.

Vulnerability and open-port alerts

These alerts indicate that a vulnerable service or potentially unwanted application may be exposed to the internet. This could include an unpatched application, an administration interface or an open database service.

The response should consider whether the service is genuinely required, whether it is supported and up to date, and whether access can be restricted. Internet-facing and actively exploited vulnerabilities may require emergency remediation rather than waiting for the next scheduled maintenance window.

What Early Warning does not do

Understanding the limits of the service is important. Early Warning:

  • Does not actively scan your network. It uses information already gathered by the NCSC and its feed providers.
  • Does not see every attack. An absence of alerts does not prove that the environment is secure.
  • Does not monitor internal systems directly. It is based on registered public IP addresses, domains and the activity visible in its information feeds.
  • Does not remediate findings. The organisation still needs people, processes and tools to investigate and resolve the issue.
  • Does not replace endpoint, identity, network or cloud monitoring. It should complement existing security controls.
  • Does not replace vulnerability management. Findings must be combined with asset, exposure, exploitability and business-impact information.
  • Does not provide a complete incident-response service. Organisations still need defined escalation routes, decision-makers and recovery plans.

Early Warning should be treated as an additional source of relevant threat information, not as evidence that all risks are covered.

Why UK organisations should register in 2026

It provides access to information that may not be available elsewhere

The service uses NCSC, public, commercial and closed information feeds, including privileged sources that are not generally available to individual organisations. This may identify an issue that has not yet been detected by internal tools.

It is free and straightforward to introduce

The NCSC describes registration as a process that can be completed in around five minutes once the required organisation, asset and contact details are available. There is no licence fee, although the organisation must still allocate time to maintain the registered assets and act on findings.

It can shorten the time between exposure and investigation

A useful alert can bring malware, abuse or an exposed service to the organisation’s attention earlier. Faster awareness does not guarantee a better outcome, but it gives the team more time to contain the issue before it spreads or is exploited further.

It adds an independent source of evidence

Internal monitoring may have blind spots or may have been disabled during an attack. An external notification provides another source of information that can support investigation and challenge assumptions about the current security posture.

It supports supplier and group-wide resilience

Large organisations can encourage subsidiaries and suppliers to register their own assets. This does not replace supplier assurance, but it gives more organisations access to a practical government service and may help surface compromises that could affect the wider supply chain.

It now forms part of the Government Cyber Resilience Pledge

In April 2026, the Government Cyber Resilience Pledge identified three practical actions for organisations: make cyber security a Board responsibility, sign up to NCSC Early Warning and require Cyber Essentials across supply chains.

This reinforces an important point: signing up is worthwhile, but it should sit within a broader resilience programme supported by accountable leadership and basic security controls.

How to register for NCSC Early Warning

  1. Create or access a MyNCSC account. The first person joining an organisation may need to be approved before becoming its initial organisation administrator.
  2. Set up or join the correct organisation. Avoid creating duplicate organisations where colleagues already use MyNCSC.
  3. Compile the public asset list. Include the static public IP addresses and domain names owned or managed by the organisation.
  4. Add nominated contacts. Use contacts who can understand the alert or route it quickly to the right operational team.
  5. Enable Early Warning for the relevant assets. Check that newly added assets are included in the service.
  6. Review the MyNCSC findings and email reports. Early Warning provides daily and weekly reporting, depending on the type and status of the findings.

Register through the official NCSC Early Warning page.

Prepare before the first alert arrives

Registering the assets is only the beginning. The organisation needs a workable response process.

Maintain an accurate public-asset inventory

Record each public IP address and domain, the service it supports, the technical owner, the hosting provider and the business impact if it is compromised or unavailable. Update MyNCSC when services are introduced, moved or retired.

Compare the registered assets with firewall, DNS, cloud, hosting and supplier records. An unknown public service is a bigger concern than an alerting gap alone.

Use a monitored team mailbox

Do not rely on one individual receiving the alert. A monitored security or IT operations mailbox reduces the risk of warnings being missed during annual leave, staff changes or out-of-hours periods.

The mailbox should have clear ownership and forwarding rules, without creating a chain in which everybody assumes somebody else has acted.

Define severity and escalation rules

Write a short runbook for each alert category. It should explain:

  • Who performs the initial check.
  • What information must be collected.
  • When the event becomes a security incident.
  • Who can isolate a device or restrict a public service.
  • When senior management, customers, insurers or regulators may need to be involved.
  • How actions and evidence will be recorded.

Incident notifications should normally receive faster attention than a low-risk exposed service, but every finding needs a recorded disposition.

Connect alerts to the existing workflow

Where possible, route findings into the organisation’s service-management or security-operations process. Create a ticket, assign an owner, set a response target and track the work through to closure.

This avoids alerts remaining in a mailbox without a record of what was checked or changed.

Confirm access to the tools needed for investigation

The responder may need endpoint detection, firewall, DNS, proxy, identity, cloud, server and vulnerability data. Make sure the correct team can access these systems without waiting for emergency permissions during an incident.

Exercise the response

Use a tabletop scenario to test what happens when Early Warning reports malware on a public-facing system or a compromised device scanning the internet. Confirm that contacts, permissions and decision-making work under pressure.

How to handle an Early Warning alert

1. Validate the asset and alert

Confirm that the IP address or domain still belongs to the organisation and identify the system, service or supplier responsible for it. Check the date, time, alert category and any technical indicators supplied.

2. Investigate related activity

Review endpoint, identity, firewall, DNS, proxy, application and cloud logs around the relevant period. Look for unusual authentication, outbound connections, new accounts, suspicious processes, policy changes and attempts to move to other systems.

3. Contain confirmed or likely compromise

Isolation may involve removing a device from the network, restricting an exposed service, blocking indicators, disabling an account or rotating credentials. Containment should reduce harm without destroying evidence needed for the investigation.

4. Remediate the underlying cause

Patch the vulnerability, remove malware, correct the configuration, revoke access and rebuild affected systems where necessary. Do not close the finding simply because the original alert is no longer visible.

5. Check for wider exposure

A finding on one host may indicate a broader issue. Search for the same software, account, configuration, indicator or attack path across the rest of the environment.

6. Record the outcome

Document whether the finding was confirmed, what evidence was reviewed, the action taken and any follow-up work. False positives should still be recorded so recurring alerts can be handled consistently.

7. Escalate serious incidents

Use the organisation’s incident-response plan and consider reporting significant incidents through the appropriate NCSC, Action Fraud, insurer, customer or regulatory routes. Legal and data-protection advice may be needed where personal data, contractual commitments or regulated services are affected.

Early Warning, MyNCSC and the 2026 service changes

Early Warning is now accessed through MyNCSC, which allows organisations to manage assets, users and findings through one account.

The NCSC retired its separate Web Check and Mail Check services on 31 March 2026. Early Warning and DNS Check continue to provide findings through MyNCSC. Organisations that previously relied on Web Check or Mail Check should not assume that Early Warning provides the same coverage.

The NCSC recommends using commercial External Attack Surface Management where organisations need ongoing discovery and assessment of internet-facing assets. Its free Check your Cyber Security service can also check important email-domain protections and certain public-facing weaknesses.

A sensible 2026 model may therefore combine:

  • NCSC Early Warning for relevant government-backed threat notifications.
  • External Attack Surface Management for active discovery and assessment.
  • Continuous vulnerability management for prioritised remediation.
  • Endpoint, identity, cloud and network detection for internal visibility.
  • An incident-response process that turns alerts into action.

How CloudCoCo can support the process

Organisations do not need CloudCoCo to register for Early Warning. The service is free and available directly from the NCSC. The challenge often comes after registration: maintaining the assets, interpreting findings, investigating activity and fixing the underlying weakness.

CloudCoCo can support that operating work through:

  • Cyber Security – 24/7 managed detection and response from a UK SOC, external attack-surface management, exploitability-led vulnerability prioritisation, identity-led defence, penetration testing and incident-response support.
  • Managed IT Services – defined ownership across service desk, endpoint, identity, network and observability, with alerts routed into established incident and change processes.
  • IT Consulting – Cyber Maturity Assessments aligned with NCSC CAF, NIST CSF 2.0, ISO 27001 or Cyber Essentials, producing a prioritised remediation backlog and board-level readout.
  • Connectivity – managed network visibility, SASE, Zero Trust Network Access and AIOps across internet-facing and hybrid environments.

The purpose is not to replace the NCSC service. It is to ensure that an alert reaches people who can investigate it, make a decision and complete the remediation.

NCSC Early Warning FAQs

Is NCSC Early Warning free?

Yes. It is a free service for eligible UK organisations. The organisation still needs to provide and maintain its asset and contact details and allocate people to review and act on findings.

Who can register?

Any UK organisation with a static public IP address or domain name can register. The organisation needs a MyNCSC account and nominated contacts for alerts.

Does Early Warning scan our systems?

No. Early Warning does not actively scan your network. It compares registered assets against information received from NCSC and trusted external feeds.

How are alerts delivered?

Findings are available through MyNCSC, with daily and weekly reports sent to nominated email contacts.

Does it replace a SOC or managed detection and response service?

No. Early Warning provides an additional source of alerts, but it does not continuously monitor internal endpoints, identities, cloud applications or network traffic, and it does not investigate or remediate incidents for the organisation.

Does it replace vulnerability scanning?

No. Some findings may identify vulnerabilities or exposed services, but the service is not an active vulnerability scanner. Organisations still need asset discovery, vulnerability assessment, prioritisation and remediation tracking.

What happened to NCSC Web Check and Mail Check?

Web Check and Mail Check were retired on 31 March 2026. Early Warning and DNS Check continue through MyNCSC. The NCSC recommends suitable commercial External Attack Surface Management tools where organisations need the broader active checks those retired services provided.

What should we do if an alert suggests an active compromise?

Follow the organisation’s incident-response process immediately. Identify and contain the affected asset, preserve evidence, investigate related activity and escalate according to the potential impact. Do not wait for another alert before acting.

Register for NCSC Early Warning through the official service.

Talk to CloudCoCo if you need help investigating alerts, managing vulnerabilities or improving incident response.


Leave a comment!

Your email address will not be published. Required fields are marked *