Security Resources

A curated list of 20 trusted internet security resources. These cover passwords, phishing, data protection, and web security from recognised organisations including the UK NCSC, ICO, OWASP, and NIST.

UK government and public safety

UK NCSC Cyber Aware

Official UK government advice on staying secure online, covering passwords, software updates, and two-factor authentication.

NCSC Three random words

The NCSC's recommended approach to creating memorable but strong passwords using three random words.

NCSC Password managers

Guidance from the NCSC on why and how to use a password manager to keep your accounts secure.

NCSC Report a scam email

How to report suspicious emails to the NCSC. Forward phishing emails to report@phishing.gov.uk.

NCSC Report a scam website

Report fraudulent websites to the NCSC so they can be investigated and taken down.

GOV.UK Report phishing and suspicious messages

The official GOV.UK page for reporting phishing emails, text messages, and suspicious websites.

Action Fraud Report phishing

Report phishing attempts to Action Fraud, the UK's national reporting centre for fraud and cyber crime.

Get Safe Online (UK)

Free expert advice on online safety for individuals and small businesses in the UK.

Get Safe Online Passwords

Practical password advice from Get Safe Online, including tips on creating and managing strong passwords.

Get Safe Online Check a website

A tool to check whether a website is likely to be legitimate or potentially fraudulent.

Privacy and data protection

ICO Information security guidance

The UK Information Commissioner's Office guidance on information security under the UK GDPR.

ICO Practical security steps

Practical steps from the ICO to help small organisations keep their IT systems safe.

Developer and web security

OWASP Top 10

The most critical web application security risks, maintained by the Open Worldwide Application Security Project.

OWASP Password Storage Cheat Sheet

Best practices for securely storing passwords, including hashing algorithms and salting techniques.

OWASP Authentication Cheat Sheet

Guidance on implementing secure authentication in web applications.

NIST SP 800-63B-4 (Authentication)

The US National Institute of Standards and Technology guidelines on digital identity and authentication.

CISA Secure Our World, strong passwords

Password guidance from the US Cybersecurity and Infrastructure Security Agency.

Mozilla HTTP Observatory (headers scanner)

A free tool to scan your website's HTTP headers and check for security best practices.

Useful tools and standards

Google Safe Browsing transparency report

Google's data on unsafe websites, including phishing sites and malware distribution.

Have I Been Pwned, Pwned Passwords

Check whether a password has appeared in a known data breach. Created by security researcher Troy Hunt.

PIN risk map (interactive)

Visual check for common and predictable 4 digit PINs. Runs locally in your browser.

PINs and device security

Ministry of Justice – Passwords (Security Guidance)

UK government guidance on passwords and PIN advice.

Police.uk – Protect your phone

Advice on keeping your phone and PIN secure.

Lloyds Bank – Card safety

What to do if someone knows your PIN or you suspect fraud.

DataGenetics – PIN number analysis

Research background on how common certain 4 digit PINs are (Nick Berry).

External links are provided for convenience. We do not control third party sites.

Last updated: 14 February 2026