NCC Group - Experts & Thought Leaders

Latest NCC Group news & announcements

Enhance Cyber Defense With NCC Group's PAM

NCC Group, a people-powered, tech-enabled global cyber resilience business, has partnered with Delinea, a pioneering provider of solutions for securing human and machine identities through centralized authorization, to deliver its cloud-native identity security solutions. The partnership leverages Delinea’s privileged access management (PAM) capabilities to help organizations defend their critical systems against cyber-attacks and insider threats. As organizations continue to adopt AI and evolve PAM services to satisfy compliance requirements, strong and robust identity security controls are essential to protect critical accounts and mitigate risks from credential theft, privilege escalation, covering both insider and external threats. The Delinea Platform enables organizations to discover all identities, assign appropriate access levels, and respond to threats in real-time, forming a key pillar of Zero Trust Architecture. Modern hybrid environments NCC Group’s partnership with Delinea delivers a high quality PAM service, forming a critical component of NCC Group’s Unified Digital Identity Framework: Leading capabilities: A comprehensive PAM platform designed for modern hybrid environments, featuring secure credential vaulting, privileged session management, and just-in-time access controls aimed at minimizing risk and enforcing Zero Standing Privilege. Rapid, scalable deployment: cloud-native architecture and intuitive interface, enabling fast implementation and seamless integration, and reducing the time before value for NCC Group clients. Optimized Total Cost of Ownership: automation and flexible licensing models can help to lower operational overheads whilst maintaining enterprise-grade security. Accessible for all: enterprise-class PAM delivered as a cost-effective entry point, making advanced identity security attainable for organizations of every size. Access management strategy PAM enforces guardrails by managing credentials centrally, controlling access and governing privileged interactions, and helping organizations to defend against one of the most common attack vectors - credential theft followed by privilege escalation to critical systems. NCC Group operates on the frontline of cyber defense, providing customers with deep insight into attack paths and adversary tactics. PAM is a foundational pillar of NCC Group’s Unified Digital Identity Framework and should form part of any robust identity and access management strategy. Enhancing user experience By combining Delinea’s advanced PAM technology with NCC Group’s people powered expertise, we deliver a high quality managed service for securing critical systems. NCC Group’s unified framework enables organizations to run PAM effectively, mitigating risks, supporting compliance, and enhancing user experience, all while supporting Zero Trust Architecture design principles and operational resilience. Derek Gordon, Digital Identity Practice Lead, commented: “We’re on the frontline of cyber defense, providing deep insight into attack paths and adversary strategies. Our unified digital identity framework offers fully managed and integrated Cyber services, including PAM, that aim to mitigate risk, support compliance, and enhance user experience.” Continuous identity discovery “Securing identity doesn’t stop at the point of entry. With Delinea’s software and NCC Group’s expertise, we’re delivering real-time PAM services, empowering our clients to implement Zero Trust and secure AI usage.” Chris Kelly, President at Delinea, added: “As AI-driven identity-based threats and attacks continue to evolve, businesses are seeking partners that can help them stay ahead, protect their critical assets, and realize the value of their cybersecurity investments more efficiently. By selecting Delinea as its strategic provider of PAM solutions, NCC Group is leading the way in helping our joint customers deploy quickly, augment staff, and offer managed service options to allow for continuous identity discovery, protection, and governance.”

Enhancing NCC Group's Cyber Defense with SentinelOne AI

NCC Group, a people-powered, tech-enabled global cyber resilience business, announces a partnership with SentinelOne with the addition of the SentinelOne AI-powered Singularity™ Platform to NCC Group’s Managed Services and Incident Response offering. This addition provides NCC Group’s clients with expanded options for tech-flexibility as well as robust protection against cyber threats through advanced threat detection and response. Expanded options for tech-flexibility Integration of the pioneer Endpoint Detection and Response technology to reinforce NCC Group’s Managed Services and Incident Response engagements. Customers benefit from the power of SentinelOne’s agentic AI security analyst Purple AI™, enabling NCC Group’s cyber experts to deliver more effective defense against evolving threats. Seamless integration with NCC Group’s Unified Cyber Platform (UCP) delivering faster, smarter threat detection and intelligence-driven insights. Benefits of the partnership This partnership delivers advanced, AI-driven protection to NCC Group’s services, enabling autonomous threat detection, response, and remediation. Leveraging both agentic AI and automation, the solution empowers analysts to identify and contain threats in real time by streamlining investigation workflows and delivers insights faster, reducing mean time to response (MTTR) and supporting more informed decision-making. NCC and SentinelOne technology SentinelOne’s technology enriches NCC Group’s Unified Cyber Platform SentinelOne’s technology enriches NCC Group’s Unified Cyber Platform, cross-correlating threat intelligence from both platforms to deliver actionable, data-backed insights. By combining NCC Group’s proprietary intelligence with SentinelOne’s autonomous capabilities, the collaboration empowers clients to stay ahead in a dynamic and complex threat landscape. Words from NCC Group SVP Graham Francis, SVP Global Managed Security Services, NCC Group comments: “We’re committed to offering our clients the most trusted, transparent and tech-flexible Managed Services and Incident Response offering on the market.” “The combination of our people-powered and insight driven expertise, with SentinelOne’s AI powered endpoint solution, adds greater depth to our offering and importantly, enables our team to respond to increasingly sophisticated threats with enhanced speed, accuracy, and confidence.” Words from SentinelOne AVP Tracy Ryan, AVP, Global MSSP/MSP, SentinelOne comments: "We are thrilled to partner with NCC Group as they integrate SentinelOne’s Singularity Platform with Purple AI into their managed services portfolio.” “By combining SentinelOne’s industry-leading, AI-powered platform with NCC Group’s expertise in managed and incident response services, we are empowering customers with a comprehensive and proactive security solution. This partnership demonstrates our commitment to delivering innovation and flexibility, helping organizations stay ahead of evolving cyber threats."

NCC Group Announce The Appointment Of Diji Akinwale To The Role Of Director Of Strategy And Transformation With Immediate Effect

NCC Group, an independent provider of global cyber security and resilience services, is pleased to announce the appointment of Diji Akinwale to the role of Director of Strategy and Transformation with immediate effect. This new role has been created as the Group looks to implement and execute the updated strategy announced on 2 February, and Diji will report directly to Chief Executive - Mike Maddison. Increasing recurring revenue Diji Akinwale joins the Group from The Guardian where he served as Group Strategy Director. In this role, Diji successfully supported the media group’s international growth, while increasing recurring revenue and accelerating the development of its digital offering and capabilities. Diji joins the Group from The Guardian where he served as Group Strategy Director During his time at The Guardian, Diji Akinwale was responsible for developing and delivering a plan to generate positive cashflow – a key objective and a milestone The Guardian achieved for the first time in many years in Diji’s final full year at the group. Before The Guardian, Diji spent several years at McKinsey where he led digital strategy and transformation projects for clients across sectors including technology, financial services and the public sector.  Global delivery model Mike Maddison commenced his role as Chief Executive of NCC Group on 7 July 2022, and on 2 February 2023 the Group announced the next chapter its strategy which will deliver revenue from a broader service portfolio, addressing the full cyber security lifecycle, with deeper presence across sectors. This will be supported by the activation of a global delivery model, including an offshore delivery and operations center, and investment in the go-to-market model and brand for Cyber. Core to Diji’s responsibilities will be establishing a transformation management office resourced to deliver this next chapter of the strategy at pace.  Enterprise-level transformation Core to Diji’s responsibilities will be establishing a transformation management office Mike Maddison, Chief Executive of NCC Group, commented: “Diji’s experience successfully developing and delivering enterprise-level transformation projects for some of the world’s most important organizations supports my confidence that he will be a great asset to our group.” He adds, “Diji has a grounding in client services and his sector experience means he understands both how we and our clients operate. I look forward to working closely with him as we pursue our strategy to create a more resilient business positioned to capitalize fully on opportunities to meet changing client needs in a dynamic Cyber market.” Secure digital future Diji Akinwale commented: “This a fantastic opportunity to lend my experience and transformation expertise to a global business at the cutting edge of an exciting, fast-moving industry and at a critical moment in the Group’s journey.” “Underpinned by a focus on insights, intelligence and innovation, NCC Group’s proposition and strategy mean it is well placed to deliver on its purpose of creating a more secure digital future, and I look forward to working with my new colleagues to contribute to this.”

Insights & Opinions from thought leaders at NCC Group

Executive Order Provides New Tools To Shore Up Cybersecurity Of U.S. Ports

Fueled by mounting concerns about the cybersecurity vulnerability of U.S. ports, President Joe Biden has signed an Executive Order aimed at shoring up defenses against cyberattacks. Cybersecurity initiative The cybersecurity initiative marks a significant shift in policy, empowering key agencies and outlining concrete actions to bolster defenses.  By empowering agencies, establishing clear standards, and fostering collaboration, the initiative aims to strengthen U.S. ports against the evolving threat of cyberattacks, safeguarding the nation's maritime economy and national security.   Expanded authority for DHS  The proactive approach aims to prevent incidents before they occur The Executive Order grants expanded authority to the Department of Homeland Security (DHS) and the Coast Guard to address maritime cyber threats. DHS gains the power to directly tackle these challenges, while the Coast Guard receives specific tools. The Coast Guard can compel vessels and waterfront facilities to address cyber vulnerabilities that endanger safety. The proactive approach aims to prevent incidents before they occur.   Real-time information sharing Reporting any cyber threats or incidents targeting ports and harbors becomes mandatory. This real-time information sharing allows for swifter response and mitigation efforts. The Coast Guard also gains the authority to restrict the movement of vessels suspected of posing cyber threats. Inspections can be conducted on vessels and facilities deemed risky.  Mandatory cybersecurity standards  The standardization aims to eliminate weak links in the chain and prevent attackers from exploiting Beyond these broad powers, the Executive Order establishes foundational elements for improved cybersecurity. Mandatory cybersecurity standards will be implemented for U.S. ports' networks and systems, ensuring a baseline level of protection across the board. This standardization aims to eliminate weak links in the chain and prevent attackers from exploiting individual vulnerabilities.  Importance of collaboration and transparency Furthermore, the initiative emphasizes the importance of collaboration and information sharing. Mandatory reporting of cyber incidents fosters transparency and allows government agencies and private sector partners to work together in mitigating threats.  Additionally, the Executive Order encourages increased information sharing among all stakeholders, facilitating a unified response to potential attacks.  Maritime Security Directive The Executive Order encourages investment in research and development for innovative cybersecurity solutions To address specific concerns, the Coast Guard will issue a Maritime Security Directive targeting operators of Chinese-manufactured ship-to-shore cranes. This directive outlines risk management strategies to address identified vulnerabilities in these critical pieces of port infrastructure. The long-term success of this initiative hinges on effective implementation. The Executive Order encourages investment in research and development for innovative cybersecurity solutions, recognizing the need for continuous improvement and adaptation to evolving threats.  Recognizing the urgency of cyber threats  The initiative has been met with widespread support from port authorities, industry stakeholders, and cybersecurity experts who recognize the urgency of addressing cyber threats. However, some concerns exist regarding the potential burden of complying with new regulations for smaller port operators.  Effective communication, resource allocation, and collaboration among all stakeholders will be crucial to ensure the successful implementation of this comprehensive plan.  Enhancing cybersecurity The more impactful and noteworthy piece is the associated NPRM from the U.S. Coast Guard (USCG) “This Executive Order is a positive move that will give the U.S. Coast Guard (USCG) additional authority to enhance cybersecurity within the marine transportation system and respond to cyber incidents,” comments Josh Kolleda, practice director, transport at NCC Group, a cybersecurity consulting firm.  The more impactful and noteworthy piece is the associated Notice of Proposed Rulemaking (NPRM) from the U.S. Coast Guard (USCG) on “Cybersecurity in the Marine Transportation System,” adds Kolleda. Portions of the notice of proposed rulemaking (NPRM) look similar to the Transportation Security Administration (TSA) Security Directive for the rail industry and the Emergency Amendment for the aviation industry.   Coordinating with TSA on lessons learned  The USCG should be coordinating with TSA on lessons learned and incorporating them into additional guidance to stakeholders and processes to review plans and overall compliance, says Kolleda. “At first glance, the NPRM provides a great roadmap to increase cybersecurity posture across the various stakeholders, but it underestimates the cost to private companies in meeting the requirements, particularly in areas such as penetration testing,” says Kolleda. Cyber espionage and threats The focus is on PRC because nearly 80% of cranes operated at U.S. ports are manufactured there “It is unclear if or how the federal government will provide support for compliance efforts. As this seems to be an unfunded mandate, many private companies will opt for the bare minimum in compliance.”  “Cyber espionage and threats have been reported by the Director of National Intelligence from multiple nation-states including China, Russia, and Iran,” adds Paul Kingsbury, principal security consultant & North America Maritime Lead at NCC Group. The focus here is on the People’s Republic of China (PRC) because nearly 80% of cranes operated at U.S. ports are manufactured there, he says.  Destructive malware “The state-sponsored cyber actors’ goal is to disrupt critical functions by deploying destructive malware resulting in disruption to the U.S. supply chain,” says Kingsbury. “These threat actors do not only originate in China or other nation-states but also include advanced persistent threats (APTs) operated by criminal syndicates seeking financial gain from such disruptions." "The threat actors don’t care where the crane was manufactured but rather seek targets with limited protections and defenses. The minimum cyber security requirements outlined within the NPRM should be adopted by all crane operators and all cranes, regardless of where they are manufactured.”  PRC-manufactured cranes Kingsbury adds, “The pioneering risk outlined in the briefing is that these cranes (PRC manufactured) are controlled, serviced, and programmed from remote locations in China." "While this is a valid concern and should be assessed, there are certainly instances where PRC-manufactured cranes do not have control systems manufactured in PRC. For example, there are situations in maritime transportation system facilities where older cranes have been retrofitted with control systems of European Union or Japanese origin.”  Monitoring wireless threats  “The Biden Administration’s recent Executive Order is a critical step forward in protecting U.S. ports from cyberattacks and securing America’s supply chains,” says Dr. Brett Walkenhorst, CTO at Bastille, a wireless threat intelligence technology company. “To ensure proper defense against malicious actors accessing port-side networks, attention must also be paid to common wireless vulnerabilities." "Attacks leveraging Wi-Fi, Bluetooth, and IoT protocols may be used to access authorized infrastructure including IT and OT systems. Monitoring such wireless threats is an important element in a comprehensive approach to upgrading the defenses of our nation’s critical infrastructure.”

Working From Home Creates New Security Concerns for Companies

The global pandemic caused by the novel coronavirus is changing work environments to an unprecedented degree. More employees than ever are being asked to work remotely from home. Along with the new work practices comes a variety of security challenges. Without the proper precautions, working from home could become a cybersecurity nightmare, says Purdue University professor Marcus Rogers. “Criminals will use the crisis to scam people for money, account information and more,” he says. “With more people working from home, people need to make sure they are practicing good cybersecurity hygiene, just like they would at work. There is also a big risk that infrastructures will become overwhelmed, resulting in communication outages, both internet and cell.” Covid-19 concerns  Concerns about the coronavirus have increased the business world’s dependence on teleworking. According to Cisco Systems, WebEx meeting traffic connecting Chinese users to global workplaces has increased by a factor of 22 since the outbreak began. Traffic in other countries is up 400% or more, and specialist video conferencing businesses have seen a near doubling in share value (as the rest of the stock market shrinks). Basic email security has remained unchanged for 30 years Email is a core element of business communications, yet basic email security has remained unchanged for 30 years. Many smaller businesses are likely to still be using outdated Simple Mail Transfer Protocol (SMTP) when sending and receiving email. “The default state of all email services is unencrypted, unsecure and open to attack, putting crucial information at risk,” says Paul Holland, CEO of secure email systems provider Beyond Encryption. “With remote working a likely outcome for many of us in the coming weeks, the security and reliability of our electronic communication will be a high priority,” says Holland. The company’s Mailock system allows employees to work from any device at home or in the office without concerns about data compromise or cybersecurity issues. Acting quickly and effectively  As the virus spreads, businesses and organizations will need to act quickly to establish relevant communication with their employees, partners and customers surrounding key coronavirus messages, says Heinan Landa, CEO and Founder of IT services firm Optimal Networks. Employers should also enact proper security training to make sure everyone is up to speed with what’s happening and can report any suspicious online activity. Reviewing and updating telework policies to allow people to work from home will also provide flexibility for medical care for employees and their families as needed. Scammers, phishing, and fraud  An additional factor in the confusing environment created by the coronavirus is growth in phishing emails and creation of domains for fraud. Phishing is an attempt to fraudulently obtain sensitive information such as passwords or credit card information by disguising oneself as a trusted entity. Landa says homebound workers should understand that phishing can come from a text, a phone call, or an email. “Be wary of any form of communication that requires you to click on a link, download an attachment, or provide any kind of personal information,” says Landa. Homebound workers should understand that phishing can come from a text, a phone call, or an email Email scammers often try to elicit a sense of fear and urgency in their victims – emotions that are more common in the climate of a global pandemic. Attackers may disseminate malicious links and PDFs that claim to contain information on how to protect oneself from the spread of the disease, says Landa.  Ron Culler, Senior Director of Technology and Solutions at ADT Cybersecurity, offers some cyber and home security tips for remote workers and their employers: When working from home, workers should treat their home security just as they would if working from the office. This includes arming their home security system and leveraging smart home devices such as outdoor and doorbell cameras and motion detectors. More than 88% of burglaries happen in residential areas. When possible, it’s best to use work laptops instead of personal equipment, which may not have adequate antivirus software and monitoring systems in place. Workers should adhere to corporate-approved protocols, hardware and software, from firewalls to VPNs. Keep data on corporate systems and channels, whether it’s over email or in the cloud. The cyber-protections that employees depended on in the office might not carry over to an at-home work environment. Schedule more video conferences to keep communication flowing in a controlled, private environment. Avoid public WiFi networks, which are not secure and run the risk of remote eavesdropping and hacking by third parties. In addition to work-from-home strategies, companies should consider ways to ensure business cyber-resilience and continuity, says Tim Rawlins, Director and Senior Adviser for risk mitigation firm NCC Group. “Given that cyber-resilience always relies on people, process and technology, you really need to consider these three elements,” he says. “And your plan will need to be adaptable as the situation can change very quickly.” Employees and their employers Self-isolation and enforced quarantine can impact both office staff and business travelers Self-isolation and enforced quarantine can impact both office staff and business travelers, and the situation can change rapidly as the virus spreads, says Rawlins. Employees should be cautious about being overseen or overheard outside of work environments when working on sensitive matters. The physical security of a laptop or other equipment is paramount. “It’s also important to look at how material is going to be backed up if it’s not connected to the office network while working offline,” says Rawlins. It’s also a good time to test the internal contact plan or “call tree” to ensure messages get through to everyone at the right time, he adds.