The NCSC Recorded 204 Nationally Significant Cyber Attacks in a Single Year. Four a Week. Every Week

The NCSC Recorded 204 Nationally Significant Cyber Attacks in a Single Year. Four a Week. Every Week

In October 2025 the National Cyber Security Centre published its annual review covering the year to September 2025. The headline figure was 204 nationally significant cyber incidents reported and managed during the period. That is more than double the 89 recorded in the previous year. It works out to an average of four major attacks on UK interests every single week and it represents the highest annual total in the organisation’s nine-year history.

The attacks were not evenly distributed. Ransomware campaigns disrupted NHS services, encrypting patient records and forcing hospitals to divert emergency cases. Supply chain attacks compromised managed service providers serving local authorities and public sector bodies simultaneously. A breach of the Ministry of Defence’s payroll system via a third party contractor exposed personal data belonging to serving and former military personnel. The pattern is consistent with what security researchers have been warning about for years: the weakest link in any organisation’s security is increasingly a supplier, a contractor or a software vendor rather than a direct employee.

The NCSC’s annual review was published alongside a letter from the government to the top 350 UK businesses, urging board-level action on cyber risk. The letter asked organisations to rehearse their cyber response plans, follow the NCSC Cyber Governance Code of Practice and sign up to the NCSC’s early warning system. The tone was notably more urgent than in previous years.

What Is Driving the Increase

The NCSC and independent researchers identify three converging factors behind the dramatic increase. First, AI is being used by threat actors to make phishing and social engineering attacks more convincing and faster to execute at scale. Messages that previously required hours of research and writing to craft convincingly can now be generated in seconds and personalised to individual recipients using publicly available information. Deepfake audio and video are being used in voice and video phishing attacks against finance teams to authorise fraudulent transfers.

Second, geopolitical alignment has directed more state-linked activity toward the UK. Groups linked to Russia, China, Iran and North Korea have all been attributed to significant UK incidents in the past 18 months. The UK’s support for Ukraine and its position in international sanctions regimes has made it a consistent target for disruptive operations that fall below the threshold of armed conflict.

Third, and most structurally concerning, the supply chain attack surface has expanded faster than the security controls governing it. The 2025 breach of the Ministry of Defence payroll system via a managed service provider is emblematic of a pattern seen across the public and private sectors. Organisations that have significantly improved their direct security posture are discovering that their suppliers have not.

The Legislative Response: Cyber Security and Resilience Bill

Table 1: Key provisions of the UK Cyber Security and Resilience Bill and expected implementation timeline

ProvisionWhat It RequiresIn Force
24-hour early warningNotify sector regulator and NCSC within 24 hours of a significant incidentOn Royal Assent (expected late 2026)
72-hour full reportFull incident report to sector regulator and NCSC with mandatory customer notificationOn Royal Assent
Expanded scopeManaged service providers, data centres and designated critical suppliers now coveredPhased to 2028
Penalties for serious breachesUp to £17 million or 4 percent of global turnover whichever is greaterOn Royal Assent
Ransomware reportingAll organisations must report ransomware incidents; CNI and public sector banned from payingSubject to final passage

What Organisations Should Be Doing Now

The bill has not yet received Royal Assent but the direction of travel is clear and organisations that wait for the law to pass before acting will find themselves under pressure to compress years of compliance work into a very short window. The 24 and 72-hour reporting timelines in particular require incident response processes that many organisations do not currently have.

The most important immediate action is to determine whether your organisation falls within the bill’s expanded scope. Managed service providers and data centres are newly covered and many organisations in these categories have not historically treated themselves as regulated entities. Those that are in scope should begin mapping their incident classification processes against the new reporting thresholds now.

Leave a Reply

Your email address will not be published.