The National Cyber Security Centre has launched a free service that does something most small businesses have never had: an early warning that their own systems are visibly vulnerable, sent before anyone exploits them. The Proactive Notifications Service (PNS), built with Netcraft as part of the NCSC’s Active Cyber Defence programme, scans publicly visible internet data — things like software version numbers exposed on open ports — and emails the organisation running that system with specific, practical advice on what to patch.
It matters because most breaches at small firms don’t start with anything exotic. They start with a piece of software nobody remembered was public-facing, running a version with a known, published flaw. Attackers scan for exactly this constantly and automatically. Until now, the only people doing the same scan on your behalf, for free, were the criminals.
What the emails actually look like
If you’re contacted, the message will come from a Netcraft.com address, will be plain text, will contain no attachments, and will never ask for payment or personal details. That’s worth memorising, because the format is also a near-perfect template for a scam. Expect copycat phishing emails dressed up as “official NCSC vulnerability alerts” within weeks of this getting coverage — that’s the pattern every time a legitimate government security service gets press. If a message claiming to be from the NCSC or Netcraft asks you to click a link, log in, or pay for anything, it isn’t genuine. Verify directly with acdenquiries@ncsc.gov.uk if you’re unsure.
Don’t wait to be contacted — check yourself first
The service is still in pilot, scans what’s publicly visible rather than everything, and won’t catch every exposed system. Don’t treat “no email yet” as a clean bill of health. If you run anything customer-facing — a booking portal, a WiFi login page, an old admin panel — it’s worth an afternoon confirming the software behind it is current and that nothing was left exposed by a supplier or a previous developer. This is exactly the kind of quiet, unglamorous gap that turns into the next headline breach: a car park booking system, a WiFi sign-up form, an unpatched login page nobody thought to check.
For businesses without an internal IT function to run that audit, this is a sensible moment to bring in outside help rather than guess. CoolCoding can review what’s actually exposed on your public-facing systems and get anything out of date patched before it becomes someone else’s opportunity, and KeepSafe can help set up the ongoing monitoring so you’re not relying on a government pilot scheme catching it for you.
Why a free government scan is still not enough on its own
The PNS is a genuinely useful safety net, but it’s reactive by design — it tells you about a problem it happened to spot, not everything that could go wrong. It won’t catch a weak password, a phishing email that gets past your team, or a supplier with poor security practices holding your customer data. Treat it as one layer, not the whole strategy. Pair it with basic hygiene that costs nothing: multi-factor authentication on anything important, a named person responsible for applying security updates, and a plan for who does what in the first hour if something does go wrong.
The takeaway
A free government alert service is a good thing to have watching your back, but it only tells you about what it can already see from the outside — and so can everyone else, including the people looking for an easy target. Don’t wait for an email that might never come. Check what your business exposes to the public internet this month, patch what’s out of date, and treat any “urgent security alert” that lands in your inbox with a healthy dose of suspicion until you’ve verified it through an official channel.