Hello, Mauven Here. The NCSC Just Confirmed the Attacks Aren't Slowing Down

News & Analysis

Hello, Mauven Here. The NCSC Just Confirmed the Attacks Aren't Slowing Down

Hello, Mauven here.

Let’s start with the figure that the NCSC itself put on the record, because it deserves more attention than it usually gets outside industry circles. In its Annual Review, published on 14 October, the National Cyber Security Centre confirmed it dealt with 204 nationally significant cyber incidents in the twelve months to August 2025. The previous year’s figure was 89. That’s more than a doubling.

Eighteen of those 204 were classed as highly significant, meaning they carried the potential for serious impact on essential services. That’s up from 12 the year before, a rise of nearly 50%.

The Number Behind the Number

Total incident tips received by the NCSC across the period: 1,727. Of those, 429 were escalated to formal incident status requiring the agency’s support. The 204 nationally significant incidents sit within that larger figure as the ones judged to have a substantial impact on the UK, whether that’s a medium-sized organisation directly affected or a considerable risk to something larger.

At CyberUK 2026 in Glasgow this April, NCSC chief executive Richard Horne gave an update on that trajectory. The number, he said, has remained “fairly steady” since the Annual Review was published. Four nationally significant attacks a week, on average, is the NCSC’s own phrase, not industry hyperbole.

Not Abstract “Threat Actors”

The Annual Review’s introduction, written by GCHQ director Anne Keast-Butler, named specific attacks as illustrative examples: Marks & Spencer, the Co-op Group, and Jaguar Land Rover. These aren’t obscure incidents. They’re the ones that made front pages in 2025, and per the NCSC’s own account, they represent the visible tip of a much larger, largely invisible pattern.

At CyberUK, Horne went further on attribution. A substantial proportion of the incidents the NCSC handled were linked to Advanced Persistent Threat actors, meaning nation-state groups or highly capable criminal organisations operating with nation-state-level resourcing. He described a “perfect storm”: rapid technological change driven by AI, sharpening geopolitical tension, and an expanding pool of capable hostile actors, with Russia in particular applying battlefield lessons from Ukraine to cyber operations elsewhere.

Why This Belongs Next to the Compliance Numbers

Put this next to what we covered on Tuesday from the Cyber Security Breaches Survey 2025/2026. Only 25% of UK businesses have a formal incident response plan. Just 31% have board-level cyber ownership. Five per cent hold Cyber Essentials.

The NCSC isn’t describing a risk that might materialise eventually. It’s describing an operating environment that already exists, right now, at a rate of four significant incidents a week, aimed disproportionately at organisations that supply, service, or sit adjacent to the large businesses making headlines. Jaguar Land Rover’s disruption alone was modelled by the Cyber Monitoring Centre at a £1.9 billion economic impact, cascading across more than 5,000 supply chain organisations. Most of those 5,000 will be small and medium businesses.

What Boards Consistently Get Wrong

The pattern in the qualitative interviews behind the government survey is worth reading directly. Board members describe increased awareness driven by media coverage of high-profile breaches, not by any systematic review of their own exposure. One IT manager’s quoted concern, “will he understand what I’m telling him, probably not”, captures something the NCSC’s incident count can’t: the gap between headline awareness and operational readiness is often generational, cultural, and entirely unaddressed by a single news cycle of concern.

Reading the news about M&S is not the same as reviewing your own supply chain exposure. The NCSC’s figures exist precisely to close that gap, and most boards still haven’t opened the document.

What This Means for Your Business

  1. Read the NCSC’s actual incident figures, not just the retailer headlines. The Annual Review and the CyberUK follow-up remarks are both public and take fifteen minutes to absorb.

  2. Ask specifically whether your board discussion of cyber risk references any primary source. “We saw the M&S thing on the news” is not the same conversation as “the NCSC handled 204 nationally significant incidents last year, and here’s our exposure.”

  3. If you supply, service, or sell to larger organisations, treat supply chain risk as immediate, not theoretical. The Jaguar Land Rover disruption alone touched more than 5,000 organisations in its supply chain.

  4. Revisit your incident response plan against the NCSC’s guidance, not just your own assumptions. If you don’t have one, that’s the gap this week’s Thursday guide will help close.

SourceArticle
NCSCUK experiencing four nationally significant cyber attacks weekly
Infosecurity MagazineUK Faces a Cyber Perfect Storm
Infosecurity MagazineUK: 130% Spike in Nationally Significant Cyber Incidents
PrivacyEngineCybersecurity Statistics UK 2026

Filed under

  • smb-security
  • uk-business
  • nation-state-attacks
  • business-risk
  • compliance-failure