I.AM Intern

A Case Study


In a world where cyber threats move faster than most organisations can detect them, early visibility is everything.
The UK’s National Cyber Security Centre (NCSC) offers one of the most underrated tools in the national defence ecosystem…the Early Warning Service (EWS)


This is now mentioned when completing the cyber essentials (CE) paperwork and I personally cant see why anybody WOULDN’T sign up for it.

It’s free, simple to set up, and it gives organisations access to threat intelligence they would never normally see.


This isn’t just another alert feed.
Early Warning provides a blend of public, private, and closed‑source intelligence, including insights from government‑level sensors, trusted partners, and classified threat‑intelligence channels.
For many organisations, it’s the only way to gain visibility into threats that are already forming around their infrastructure.


Early Warning doesn’t wait for a breach.
It tells you when your organisation is starting to appear in attacker data, leaked credentials, scanning activity, botnet targeting, malware indicators, or suspicious traffic hitting your perimeter.
It’s an early signal that something is happening, long before it becomes a crisis.

And because it’s free, it’s one of the most accessible tools in the UK’s cyber defence kit today.


What Early Warning Provides

Once signed up, organisations receive three types of actionable intelligence:

1. Attack Surface Alerts

Notifications when your infrastructure is being scanned, probed, or targeted by known malicious actors.

2. Compromise Indicators

Signals that your systems, credentials, or services appear in threat‑intelligence feeds including closed sources you would never normally access.

3. Malware & Botnet Activity

Alerts when your IPs or domains are linked to malware distribution, botnet traffic, or command‑and‑control behaviour.

This combination gives organisations a level of visibility that typically requires expensive commercial tooling.


Why This Matters: Early Warning means Early Action

Cyber incidents rarely begin with a breach.

They begin with reconnaissance, scanning, credential harvesting, and exposure.

Early Warning detects these early behaviours.

It’s the difference between discovering a fire when the smoke alarm goes off, versus when the building is already burning.


I’ve been doing some research into previous attacks and looking into how the presence of the Early Warning Service could well have prevented or at the very least mitigated the risk of an attack being successful. Partularly, WannaCry in 2017, Jaguar Land Rover (JLR) in 2023 and Marks & Spencer’s (M&S) in 2024

From what ive researched, the Early Warning Service would not have prevented attacks outright however it could have given organisations early visibility into the behaviours that led to those attacks.

And early visibility changes everything.


WannaCry (2017)

WannaCry spread using EternalBlue, a vulnerability in SMB that Microsoft had already patched months earlier. This greatly affected many large organisations, one of which was the NHS (where I was working at the time). No computer systems worked AT ALL.

How Early Warning could have helped

Early Warning detects:

Before WannaCry detonated globally, attackers were already scanning the internet for SMBv1 hosts.



Early Warning would have flagged:

“Your IPs are being scanned by known malicious actors targeting SMB.”

That signal alone could have prompted:

Would the Early Warning Service have stopped WannaCry?

Not universally, but for many organisations, it could have prevented compromise by prompting earlier action.


JLR Ransomware Attack (2023)

The JLR incident involved ransomware deployment through compromised third‑party systems, likely via credential exposure, remote access exploitation, or lateral movement.
This caused the factories within the JLR group to stop working.
Costing millions in halting production and massive reputational damage to the companies within the group.

How Early Warning could have helped?

Early Warning provides:

In supply‑chain ransomware attacks, the earliest signs are usually:


Early Warning would have surfaced these behaviours before the ransomware payload was deployed, giving JLR:

Not prevention in the absolute sense but meaningful early detection.


Marks & Spencer Ransomware Attack (2024)

The M&S incident reportedly involved compromised credentials and unauthorised access, consistent with modern ransomware tradecraft.
This resulted in the online sales platform crashing and again a long lasting effect is reputational damage to the company.

How Early Warning could have helped

Early Warning detects:


In identity‑driven ransomware attacks, the earliest signals are:


Early Warning would have flagged these signals, enabling:

Again it doesn’t guaranteed prevention, but early visibility that materially reduces risk.


The NCSC’s Early Warning Doesn’t Replace Cybersecurity rather it amplifies it

Early Warning is not a firewall, an EDR, or a SOC. It’s a national‑level intelligence feed that tells you:

“You are appearing in attacker data…act now.”


For WannaCry, JLR, M&S, and countless other incidents, that kind of early signal could have:


And in cyber defence, time is everything.

This is especially powerful when combined with identity‑exposure intelligence platforms like Orbital.


Why Every UK Organisation SHOULD Use It


Early Warning doesn’t replace commercial tools, it strengthens them.
It adds a layer of national‑level visibility that no SIEM, EDR, or vulnerability scanner can replicate.

Cyber threats evolve quickly, but they rarely appear without warning.
The organisations that detect early signals via scanning, exposure, botnet interest and credential leaks are the ones that prevent incidents rather than respond to them.

The NCSC Early Warning Service gives every UK organisation the ability to see those signals.

It’s free.

It’s powerful.

And it’s one of the simplest ways to strengthen your cyber defence posture today.