Site navigation

UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC

Tom Quinn

,

UK national cyber security
Ministers have urged company boards to prioritise cybersecurity after ‘nationally significant’ cyber incidents more than doubled in the past year.

UK Government ministers have written to the chief executives and chairs of leading businesses, urging them to bolster their cyber-defences as new figures show the country is experiencing four ‘nationally significant’ cyber-attacks every week.

In its latest Annual Review, the National Cyber Security Centre (NCSC) revealed it had dealt with 429 cyber incidents in the twelve months to August 2025, 204 of which were categorised as ‘nationally significant’, a dramatic rise from just 89 similar incidents the previous year.

The growing cyber sophistication of hostile states is partly to blame for the skyrocketing number of these top-tier attacks. 

The past year has seen the NCSC and its allies expose covert networks of botnets linked to Chinese firms, disrupt Russian military units carrying out cyber-attacks, and trace the fake IT worker scam back to North Korea.

The report warns that state actors present an ongoing threat to UK national cybersecurity, one that the NCSC predicts will become more acute over the next five years, as the commercial cyber intrusion sector expands to meet the demand for spyware and intrusion products coming from hostile regimes.     

Meanwhile, another eighteen of the cyber-attacks the NCSC dealt with last year were labelled as ‘highly significant’, the second-highest level categorisation, meaning that they had the potential to have a serious impact on essential services.

Most of these incidents were ransomware attacks, with the rise marking a nearly 50% increase compared to last year, and a jump in ‘highly significant’ attacks for the third consecutive year in a row. That, unfortunately, looks set to increase with threat actors’ growing reliance on AI tactics.

The report warns that AI ‘will almost certainly pose cyber resilience challenges to 2027 and beyond’, with the NCSC expecting Advanced Persistent Threat (APT) actors – either nation-state actors or highly capable criminal groups – to take advantage of the barrage of new security research that has identified new techniques AI is primed to exploit.

This will lead to an increased volume of attacks, and challenges for firms in managing an expanded attack surface and keeping pace with unpredictable advancements and the proliferation of AI capabilities.

“With over half the incidents handled by the NCSC deemed to be nationally significant, and a 50% rise in highly significant attacks on last year, our collective exposure to serious impacts is growing at an alarming pace,” said Dr Richard Horne, Chief Executive of the NCSC.

“The best way to defend against these attacks is for organisations to make themselves as hard a target as possible.”

To that end, government ministers have written to business leaders, including those of all FTSE350 companies, urging them to make cybersecurity a board responsibility.

The letter, signed by the Chancellor, Rachel Reeves, and tech secretary Liz Kendall, among others, calls on businesses to ‘take the necessary steps’ to protect themselves, and by extension the economy, from cyber-attack.

By taking three specific actions, namely using the government’s Cyber Governance Code of Practice, signing up to the NCSC’s Early Warning service, and ensuring the NCSC’s Cyber Essentials scheme is built into supply chains, the ministers said that major businesses would see an ‘immediate positive impact’ on their cyber resilience.

Smaller firms, meanwhile, can take advantage of the latest NCSC Cyber Action Toolkit, a free, personalised resource designed to help sole traders and small organisations put in place some of the basic cybersecurity measures that can help them modernise their defences against emerging threats.


Recommended reading


“Rather than continue with security models that are driving cyber incidents each year, as highlighted by the NCSC, organisations must rethink their approach,” said Barry Daniels, CEO of container-based security software firm, Droplet.

“Regaining ownership of the end-to-end stack – from the server to network estates – allows organisations to move beyond identity-based protection. The core argument: legacy Zero Trust strategies alone are insufficient. Therefore, organisations must proactively secure all entry points by isolating any critical infrastructure within secure boundaries that treat every access attempt as suspicious.

“With threat actors financially benefitting and with estimates that global cyber crime will cost economies $10.5 trillion in the coming years, organisations do not have the IT budgets large enough to be indifferent. But, instead of completely ripping out what has come before (which would come at an incredible cost to an organisation), that new security view that organisations must develop entails increasing the security layers,” added Daniels. 

“A layered defence strategy is the best one, and when combined with efforts from other security vendors, it will provide a much more robust, proactive defence for critical assets. This, in turn, will remove the risk of downtime and financial loss, as well as customer and stakeholder relationship and reputational risk.

“Recognising that identity is increasingly vulnerable, organisations must seize the opportunity to redesign their IT security around a ‘never trust’ strategy. This does not mean discarding all existing defences but rather reinforcing them with additional proactive layers. The main takeaway for organisations: only a robust, multi-layered defence—built from the inside out—can protect critical assets and ensure operational resilience against evolving threats.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data