The UK’s new cybersecurity chief will use his first major speech today to issue a rallying call for collective action against an increasingly complex threat landscape.
Speaking at the National Cyber Security Centre’s (NCSC) London headquarters for the launch of its Annual Review, Richard Horne will describe the cyber risks facing the nation as “widely underestimated”, and warn that the UK and its allies are competing in an increasingly aggressive cyber-space .
According to the NCSC, Horne will discuss the growing gap between the UK’s exposure to cyber threats and the defences in place to protect the nation, warning that the country needs to ‘increase the pace’ in order to keep ahead of adversaries.
“We need all organisations, public and private, to see cybersecurity as both an essential foundation for their operations and a driver for growth,” Horne will say.
“To view cybersecurity not just as a ‘necessary evil’ or compliance function, but as a business investment, a catalyst for innovation and an integral part of achieving their purpose.”
To meet the rising threat, the new cyber chief is set to emphasise the importance of NCSC guidance, advice, and security frameworks for UK citizens and businesses, and suggest that these should be put into practice ‘much more across the board’.
Turning to the changing threat landscape, Horne will highlight a combination of the UK’s growing dependency on technology and adversaries who are conspiring to use it against the country, saying: “Hostile activity in UK cyber-space has increased in frequency, sophistication and intensity.
“Actors are increasingly using our technology dependence against us, seeking to cause maximum disruption and destruction.”
With specific mention of rising cyber aggression and evolving sophistication seen from nations such as Russia and China, Horne will caution that the UK is underestimating the global threat landscape, leaving the ambitions of hostile nations in the cyber sphere unchecked.
He will also highlight the real-world impact of cyber-attacks, drawing on recent examples that have disrupted lives, jeopardised safety, and eroded trust in our online world, saying: “In the past year, we have seen crippling attacks against institutions that have brought home the true price tag of cyber incidents.
“The attack against Synnovis showed us how dependent we are on technology for accessing our health services. And the attack against the British Library reminded us that we’re reliant on technology for our access to knowledge.
“What these and other incidents show is how entwined technology is with our lives and that cyber-attacks have human costs.”
Recommended reading
- NCSC Warns of Surge in Zero-day Exploits
- NCSC Releases Guidance to Prevent Malvertising
- Google Report Reveals 50% Surge in Zero-Day Vulnerabilities
The new cybersecurity chief will make his comments to coincide with the NCSC’s annual review, which will detail the increasingly challenging online environment that the UK and its allies are navigating.
Characterising the 2024 cyber threat landscape as “diffuse and dangerous”, the Annual Review notes a rising frequency of cyber incidents and a growing severity in their impact, including NCSC observations that physical conflicts are fuelling the threat landscape, such as Russia’s deployment of malware against Ukrainian targets, as well as attempts to interfere with the systems of NATO countries in support of the war effort.
The report also notes the growing threat from both China and Iran, following advisory notices and warnings from the NCSC about the cyber activities of these countries earlier this year.
As well as state level threats, the Review will examine observed trends by cyber-criminals over the year, with ransomware noted as the most pervasive cyber threat to the UK, and the financially motivated attack on Synnovis standing out as having a significant impact.
This year, the NCSC said its Incident Management team handled 430 incidents, compared to 371 last year. Of these, 347 involved some level of data exfiltration and 20 incidents involved ransomware.
Cyber-criminals’ increasing use of AI is also examined, however the Review notes an observation from the NCSC that the application of AI to cyber defence will exceed the uplift in any adversary capability or application.





