A new alert from the NCSC highlights the risk to CNI from state-aligned groups -particularly threats from those sympathetic to Russia’s invasion of Ukraine.
The NCSC – a part of GCHQ – warned in the alert that some groups have stated an intent to launch ‘destructive and disruptive attacks’ and that CNI organisations should ensure they have taken steps outlined in the NCSC’s heightened threat guidance to strengthen their defences.
Over the last 18 months, threats have emerged from groups which are sympathetic to the Russian invasion of Ukraine.
These groups appear to not be motivated by financial gain nor subject to control by the state, according to the NCSC. This only makes their actions less predictable and their targeting broader than traditional cyber crime actors.
While in the short term, any activity from the groups is likely to take the form of Distribute Denial of Service (DDoS) attacks, website defacements or the spread of misinformation, some groups have stated a desire to achieve a more destructive impact against western infrastructure, the alert said.
The alert was issued on the first day of the NCSC’s CYBERUK conference in Belfast, where experts have gathered to consider topics under the theme of ‘securing an open and resilient digital future.’
Dr Marsha Quallo-Wright, NCSC Deputy Director for Critical National Infrastructure, said: “It has become clear that certain state-aligned groups have the intent to cause damage to CNI organisations, and it is important that the sector is aware of this.
“In the wake of this emerging threat, our message to CNI sectors is to take sensible, proportionate steps now to protect themselves.
“The NCSC has produced advice for organisations on steps to take when the cyber threat is heightened, and I would strongly encourage all CNI organisations to follow this now.”
The NCSC’s heightened threat guidance was published shortly before Russia’s invasion of Ukraine last year, and organisations are encouraged to continue to follow it.
Recommended
- Critical Vulnerabilities Found in Microsoft Message Queuing
- Scots Rural Small Businesses Struggling Due to Poor Broadband
- Scottish Games Week to Return Later This Year
Cyber resilience in the context of Russia’s invasion of Ukraine will feature in a session on day two of CYBERUK entitled The Three Rs of Cyber Security: Russia, Ransomware and Resilience.
Achi Lewis, Area VP EMEA for Absolute Software, a zero trust and endpoint security firm, commented: “It is crucial that organisations remain prepared at all times to face cyber-attacks, ensuring they have resilient cyber policies in place with the necessary preventative and reactive measures.
“Cyber-attacks are a case of when, not if, and without a resilient cyber posture, organisations susceptible to malicious threats – particularly when they escalate to attack types such as ransomware.”





