In a dramatic new project to secure UK organisations, the NCSC (National Cyber Security Centre) has started to scan all internet-connected devices for existing vulnerabilities.
These scans will be performed using tools hosted in a dedicated cloud-hosted environment from scanner.scanning.service.ncsc.gov.uk and two IP addresses (18.171.7.246 and 35.177.10.231)
The agency has stated that all vulnerability probes are tested within their own environment to detect any issues before scanning the UK internet.
Why are our devices being scanned?
As part of the NCSC’s mission to make the UK the safest place to live and do business online, they are building a data-driven view of “the vulnerability of the UK“.
This view will help them to:
- Better understand the vulnerability and security of the UK.
- Help device owners understand their security posture on a day-to-day basis.
- Respond to cyber-security shocks, such as a new and widely exploited zero-day vulnerability.
How is the scanning performed?
Scans will be carried out by the NCSC’s software interacting with selected devices, and then analysing the response received, much the same way that a web browser or other network client typically would. This serves to identify whether a vulnerability exists in a system, by identifying the existence of specific associated protocols and services.
This can be better explained using the following example:
The NCSC may be able to determine the existence of a vulnerability known to exist in version X of a type of commonly used web server software by making a web request to the URL “../login.html” and detecting a “version X” value in the content of the page that is returned. If the vulnerability is then remediated in a subsequent version Y, then the NCSC can identify this by similarly detecting the value “version Y” in the response.
By repeating these requests on a regular basis, the NCSC can maintain an up-to-date picture of vulnerabilities across the whole of the UK.
Which devices will be scanned?
The NCSC’s scans will cover any internet-accessible systems hosted within the UK and will seek to identify vulnerabilities that are common or particularly important due to their high impact.
What kind of data will be collected by the NCSC?
The NCSC will collect and store any data that a service (device or system) returns in response to a request.
For web servers, this includes the full HTTP response (including headers) to a valid HTTP request. For other devices and systems, this includes data that is sent by the server immediately after a connection has been established or a valid protocol handshake has been completed.
The NCSC will also record other useful information for each request and response, such as the time and date of the request and the IP addresses of the source and destination endpoints.
The NCSC will design their requests to collect the smallest amount of technical information required to validate the version and/or vulnerability of a piece of software. They will also design requests to limit the amount of personal data within the response.
In the unlikely event that the NCSC does discover information that is sensitive or personal, they have assured the public that it will take steps to remove the data and also prevent it from being captured again in the future.
How will the data collected be used?
The NCSC will use the data they collect to create an overview of the UK’s exposure to vulnerabilities following their disclosure and track their remediation over time.
What cyber security measures will the NCSC take when scanning?
The NCSC is committed to conducting scanning activities in a safe and responsible manner. As such, all their probes are verified by a senior technical professional and tested in their own environment before use.
The NCSC also limit how often they run scans to ensure they do not risk disrupting the normal operations of any devices they monitor.
Can I opt out of having devices I own or maintain being scanned?
It is within your legal rights to be able to request that your devices are not scanned.
Contact scanning@ncsc.gov.uk with a list of IP addresses that you wish to exclude from any future scan activity.







