惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
I
InfoQ
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog
博客园_首页
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
C
Check Point Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Engineering at Meta
Engineering at Meta
B
Blog
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
F
Fortinet All Blogs
月光博客
月光博客
GbyAI
GbyAI

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Infosecurity Europe: How DSIT Protects Thousands of UK Or...
Danny Palmer · 2026-06-08 · via www.infosecurity-magazine.com

The UK's Department of Science, Innovation and Technology (DSIT) is responsible for securing over half a million domains across thousands of government organizations.

This ranges from the smallest Parish Councils to the behemoth that is the National Health Service (NHS) and its various sub-organizations.

That makes advising these organizations on what the latest cybersecurity vulnerabilities are and how to fix them a challenge, especially in an era when frontier AI Models are uncovering more vulnerabilities than ever before.

However, that does not mean each individual organization must fully understand the technical details of what vulnerabilities could be exploited. Rather, it is more important that they are provided with the correct information on what to fix and how to fix it, explained Nick Woodcraft service owner for vulnerability monitoring at DSIT.

“When you come with a problem, rather than talking about the technology, talk about the outcomes,” he said said,

Woodcraft was speaking at Infosecurity Europe 2026, in a session on the Resilience and Cyber Risk stage, titled From Months to Days: How DSIT Is Rethinking Remediation at Scale’.

Making Vulnerability Management Simple to Understand

For example, he detailed how DSIT has simplified discussion around DNS vulnerabilities. A local council does not need to know what exactly a DNS vulnerability is, but they are told that if the issue is not fixed, they may lose access to their website.

“Most of the people we talk to are extremely competent at what they are do, but they are not cybersecurity or vulnerability experts,” said Woodcraft.

Read More: What Fronter AI Models Like Mythos and GPT-Cyber Mean for Modern Cybersecurity

“But when you explain this is what it is, this is what it means – that you could lose access to your website - they understand and appropriately prioritize it. That’s been important, finding ways to help people understand,” he explained.

However, with over half a million domains across thousands of government organizations to help with managing security, it’s impossible for DSIT to be hands-on with every single one of those bodies.

How Technology Helps DSIT Manage Vulnerabilities

That is why DSIT has also invested in creating additional channels to analyse and pass on information, including Security Information and Event Management (SIEM) solutions and online resources where people can easily find the data.

“We can push everything we get into a SIEM, and they can prioritize it themselves,” Woodcraft explained.

“The National Cyber Security Centre (NCSC) has a portal with early warnings, so we started pushing our data into there, where people might expect to find it, they see the data and trust it. We’re trying to make it clear in ways they can understand,” he added.

In addition, DSIT stressed that it is important not to overwhelm other governmental departments and organizations with information about too many issues at once. Instead, organizations will respond more positively if the information is fed to them in stages.

“We quickly found that if you discover 15 issues within an organization and we said that we had found 15 things, it gets their backs ups and it’s too much information,” said Woodcraft.

“We started drip feeding stuff instead – we would gradually feed issues and help them fix it. We also have humans who were prepared to spend the time with them with the sole focus to get it fixed,” he added.

DSIT is already thinking about how it can help organizations stay secure in a post-Mythos world where new vulnerabilities could be uncovered faster than ever before.

According to Woodcraft, while it is a problem which will need to solved, what can go a long way to protecting organizations is by ensuring that they are doing the basics correctly.

“If we know to keep patching, to keep things up to date and to have the right processes in place, we’re not going to be in as much danger,” he said.