Protecting SMS messages used in critical business processes
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
Security advice for organisations using text messages to communicate with end users
Adapted edition
- Document type
- Reference Guide
- Format
- DOCX
- Pages
- 6
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-16
- Category
- Information security
- Licence
- Open Government Licence v3.0
Description
Security advice for organisations using text messages to communicate with end users for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.
Contents
- Introduction
- Advice
- Audience
- Why SMS is popular
- General threat protection advice
- 1. Know your estate
- Suggested Controls
- 2. Consider alternatives to SMS
- 3. Protect the integrity of customer phone numbers
- SMS attacks and compensating controls
- 1. Defend against SIM Swaps
- Points to note
- 2. Defend against SS7 attacks
- 3. Defend against Malware attacks
- General purpose SMS protection techniques
- 1. Use data from the device to make risk-based decisions on the 'safety' of SMS
- Source links
Source and licence
National Cyber Security Centre
AttributionNational Cyber Security Centre, “Protecting SMS messages used in critical business processes” (6 November 2019), reused under the Open Government Licence v3.0.
ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.
Version history
- v1.016/09/2026