Ollie Whitehouse
ollieatnowhere.bsky.social
Ollie Whitehouse
@ollieatnowhere.bsky.social
CTO at the UK's National Cyber Security Center
Pinned
We know more about what is in our sausages than our software.

SBOMs tell us that 3rd party libraries are patched but not that the 1st party code is 25 years old, in a memory unsafe language of which only 8% has been touched in the last 4 years.

Transparency has a way to go..
Reposted by Ollie Whitehouse
At @ncsc.gov.uk we have just launched the CyberUK tech talks call for papers across three topics

- Cyber applications of AI
- What works: approaches that reduce cyber harm
- The evolving threat

www.cyberuk.uk/2026/call-fo...
Tech Talks - Call for Papers
www.cyberuk.uk
November 6, 2025 at 8:12 PM
At @ncsc.gov.uk we have just launched the CyberUK tech talks call for papers across three topics

- Cyber applications of AI
- What works: approaches that reduce cyber harm
- The evolving threat

www.cyberuk.uk/2026/call-fo...
Tech Talks - Call for Papers
www.cyberuk.uk
November 6, 2025 at 8:12 PM
Zero Trust is not a product it is an approach - at @ncsc.gov.uk we have just released demystifying zero trust which addresses common misconceptions, and provides practical advice on when and how it should be adopted.

www.ncsc.gov.uk/collection/z...
Demystifying Zero Trust
Addressing common misconceptions, and providing practical advice on when and how it should be adopted.
www.ncsc.gov.uk
November 6, 2025 at 5:57 AM
At @ncsc.gov.uk we have just released guidance on using Privileged Access Workstations (PAWs) in Operational Technology (OT) environments..

www.ncsc.gov.uk/collection/o...
Using PAWs in OT environments
Considerations for the use of Privileged Access Workstations (PAWS) in OT environments.
www.ncsc.gov.uk
November 4, 2025 at 9:05 PM
Reposted by Ollie Whitehouse
‼️ Update: the MIT-linked “AI-powered ransomware” report appears to have been taken offline. We updated our article to include an Internet Archive link to the original paper.
November 1, 2025 at 4:00 AM
Reposted by Ollie Whitehouse
Well this is VERY exciting. For the last 6 months we've been making a brand new BBC podcast series all about Evil Corp - the OGs of Russian cyber crime. Preview here. Series drops Monday! www.bbc.co.uk/sounds/play/...
Cyber Hack - Evil Corp - Introducing Evil Corp - BBC Sounds
Accused of stealing hundreds of millions of dollars – Russia’s most wanted hackers
www.bbc.co.uk
October 18, 2025 at 7:46 AM
CTO at NCSC Summary: week ending October 19th..
Now is the time to act..
ctoatncsc.substack.com
October 18, 2025 at 9:07 AM
Once again all edge network device vendors are asked to read and implement our 'Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances'

Doing do will enable cyber defenders to know and hunt.

www.ncsc.gov.uk/guidance/gui...
Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances
Outlining the expectations for the minimum requirement for forensic visibility, to help network defenders secure organisational networks both before and after a compromise.
www.ncsc.gov.uk
October 15, 2025 at 7:46 PM
An alert from the @ncsc.gov.uk on the compromise of the F5 network - The NCSC is advising organisations to follow the guidance issued by F5 and to install the latest security updates.

www.ncsc.gov.uk/news/confirm...
Confirmed compromise of F5 network
The NCSC is advising organisations to follow the guidance issued by F5 and to install the latest security updates.
www.ncsc.gov.uk
October 15, 2025 at 7:26 PM
Our annual review is out covering technical highlights such as

- Engineering resilience against critical loss
- Passkeys
- The future of digital identity
- Post quantum crypt transition
- Our Initiate r&d program with industry
- Radical transparency in technology

.. and more
It’s time to act

Today we’ve published our 2025 Annual Review, revealing that cyber threats facing the UK are accelerating rapidly. We must take action.
October 14, 2025 at 6:23 AM
Reposted by Ollie Whitehouse
A call to arms on observability and threat hunting coupled with a marker of where we want to collectively get to..

www.ncsc.gov.uk/blog-post/st...
Strengthening national cyber resilience through observability and threat hunting
How organisations can improve their ability to both detect and discover cyber threats.
www.ncsc.gov.uk
October 8, 2025 at 2:22 PM
A call to arms on observability and threat hunting coupled with a marker of where we want to collectively get to..

www.ncsc.gov.uk/blog-post/st...
Strengthening national cyber resilience through observability and threat hunting
How organisations can improve their ability to both detect and discover cyber threats.
www.ncsc.gov.uk
October 8, 2025 at 2:22 PM
If you run Oracle E-Business ensure you patch..
October 6, 2025 at 9:49 AM
Reposted by Ollie Whitehouse
New Fellow: Ollie Whitehouse FREng @ollieatnowhere.bsky.social leads the @ncsc.gov.uk's technical mission to protect the nation. With over 27 years in cybersecurity, and nine patents, his work has had global impact across the public and private sectors.
raeng.org.uk/about-us/fel... #RAEngFellows
RAEng Fellow 2025: Ollie Whitehouse FREng
Ollie Whitehouse leads the National Cyber Security Centre's technical mission to protect the nation.
raeng.org.uk
October 2, 2025 at 2:58 PM
Reposted by Ollie Whitehouse
Many congratulations @ollieatnowhere.bsky.social well deserved recognition
I am honoured to have been elected a Fellow of the Royal Academy of Engineering - @raeng.org.uk

I join 73 other leading figures in the fields of engineering and technology to be elected this year: raeng.org.uk/new-fellows-...

#RAEngFellows
https://raeng.org.uk/new-fellows-20…
September 25, 2025 at 6:27 PM