The UK National Cyber Security Centre (NCSC) has launched the Proactive Notifications Service, a new initiative designed to automatically alert companies and organizations about security vulnerabilities found in their systems.

Developed in partnership with UK-based internet services firm Netcraft, the service aims to reduce cyber risks across the private and public sectors. The NCSC and Netcraft analyze open-source intelligence, including publicly accessible software version data, to identify outdated or vulnerable security configurations.
When an issue is detected, system owners receive an email from a netcraft.com address with guidance on how to remediate the problem.
All notifications are sent in plain text, without attachments, minimizing the risk of phishing. Organizations can contact the NCSC for further advice or opt out of the service entirely.
According to the NCSC, the service fully complies with the Computer Misuse Act and does not involve direct scanning of corporate networks. It also provides alerts related to malware presence, network abuse, and open ports, but does not cover every possible system or vulnerability. The agency stresses that ultimate responsibility for cybersecurity remains with each organization.
The Proactive Notifications Service serves as an early warning mechanism rather than a complete security solution. It highlights how government-led cybersecurity initiatives can support businesses while respecting privacy and operational boundaries.