New Vulnerability Monitoring Service (VMS) from GDS now available in MyNCSC
New Vulnerability Monitoring Service (VMS) from GDS now available in MyNCSC
What is the Vulnerability Monitoring Service (VMS) from GDS
VMS - from GDS, helps UK public sector organisations identify and respond to security vulnerabilities in their internet-facing digital services. VMS goes hand-in-hand with the monitoring already offered by DNS Check (also from GDS).
While VMS is an existing service already used by some organisations, what’s new is that GDS and NCSC have partnered to scale access to all eligible organisations via the MyNCSC platform.
What type of scanning is provided?
The service can find internet-facing vulnerabilities including:
- certificate issues
- web based vulnerabilities
- exposed files, storage buckets and admin panels
- misconfigurations
- phishing domains
- new and existing CVEs in applications like Microsoft Exchange and ServiceNow
- software vulnerabilities like XSS and RCE
- exposed API keys and passwords
- IP addresses in untrusted locations
Checks will continue to be added based on user feedback, with care taken to avoid any service disruption. This service includes some active scanning. It queries each service by host and IP address and each open port found. It can generate a substantial amount of traffic but is within the volumes a modern service should be able to tolerate.
Is there a charge for the service?
No. The service is centrally funded with no cost to your organisation.
Is your organisation eligible to use the service?
VMS is available through MyNCSC to organisations responsible for securing UK public sector domains and digital services. This includes central government departments and arms-length bodies, local government, devolved administrations, NHS organisations in devolved administrations, law enforcement and emergency services. The service is not currently available to academic institutions.
NHS England organisations are eligible but should make use of the NHS Vulnerability Monitoring Service in the first instance.
How do you set up the service in MyNCSC?
- Ensure your domains are added to your asset portfolio in MyNCSC
- Domains must be verified before they can be monitored - How to verify assets
- Subscribe any existing assets you would like monitored by VMS to VMS - How to edit assets
- For existing VMS customers, your domains will be subscribed to VMS checks automatically
- You must ensure access is allowed to the following VMS scanning sources to receive findings for VMS when it is made available:
- scanner.detectify.com
- IP addresses 52.17.9.21 and 52.17.98.131
- Ensure your organisation’s appropriate security and operations people are informed about the monitoring before it is set up. This makes sure they understand where the extra traffic is coming from and do not block it
- Ensure your service providers are informed about the monitoring to make sure you are contractually allowed to include the VMS
Note: This is an active scanning service that requires asset verification
To receive security findings from VMS in MyNCSC you need to:
- Verify your domains in MyNCSC using the MyNCSC verification tools to prove ownership of your domains.
- Allow scanner IP access. Traffic will originate from scanner.detectify.com using the IP address 52.17.9.21 and 52.17.98.131. Please ensure you have notified the relevant people (security and operations teams or relevant suppliers) that these scans will take place.
Feel your organisation should be eligible?
If you feel you should be eligible for VMS in MyNCSC but your organisation is showing as ineligible, please contact us.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.