In its latest Annual Review, the UK’s National Cyber Security Centre (NCSC) reveals that it dealt with 204 ‘nationally significant’ cyber attacks against the UK in the 12 months to August 2025 – a substantial rise from 89 in the previous year.
Of a total of 429 incidents handled, 18 were categorised as ‘highly significant’, meaning that they had the potential to cause serious impact to essential services. This represents an almost 50% increase in incidents at this second-highest level of categorisation compared with the previous year, marking the third consecutive annual increase.
A substantial proportion of all incidents handled by the NCSC last year were linked to Advanced Persistent Threat (APT) actors – either nation-state actors or highly capable criminal groups.
Dr Richard Horne, Chief Executive of the NCSC, said: “Cyber security is now a matter of business survival and national resilience. The best way to defend against these attacks is for organizations to make themselves as hard a target as possible. That demands urgency from every business leader: hesitation is a vulnerability, and the future of their business depends on the action they take today. The time to act is now.”
NCSC’s definitions:
Nationally significant incidents have a substantial impact on the UK’s national security, economy or critical infrastructure, including threats to essential services, sensitive data, or key government functions.
Highly significant incidents represent an even more serious threat, often requiring a coordinated cross-government response due to their potential to cause widespread disruption or long-term damage to national interests.






