In pre-published comments before a speech to launch the annual National Cyber Security Centre (NCSC) Annual Review CEO Richard Horne warns that the cyber risks facing the UK are ‘widely underestimated’.
Mr. Horne urges organizations to collectively boost resilience by following NCSC advice amid signs of widening gap between the risks the UK faces and its ability to handle them.
“The NCSC, as the National Technical Authority, has been publishing advice, guidance and frameworks since our inception, in a bid to drive up the cyber security of the UK. The reality is that advice, that guidance, those frameworks need to be put into practice much more across the board,” says Mr. Horne. “We need all organizations, public and private, to see cyber security as both an essential foundation for their operations and a driver for growth. To view cyber security not just as a ‘necessary evil’ or compliance function, but as a business investment, a catalyst for innovation and an integral part of achieving their purpose.”
Key highlights from the NCSC Annual Review include:
State threats
- Characterising the 2024 cyber threat landscape as ‘diffuse and dangerous’, the Annual Review notes a rising frequency of cyber incidents and a growing severity in their impact.
- Over the past 12 months, the NCSC has observed how conflicts are fuelling a volatile threat landscape, including Russia’s deployment of destructive malware against Ukrainian targets, and routine attempts to interfere with the systems of NATO countries in support of its war effort.
- China is described as a highly sophisticated and capable actor targeting a wide range of sectors. In February 2024, the NCSC co-signed an advisory on observed compromises of U.S. Critical National Infrastructure (CNI) by Volt Typhoon, and in March 2024 the UK government called out China state-affiliated actors for targeting democratic institutions.
- Iran-based threat actors remain aggressive in cyberspace, and the Democratic People’s Republic of Korea (DPRK) continues to prioritise raising revenue to circumvent sanctions and collect intelligence in its cyber activity.
Criminal threats
- Ransomware is highlighted as the most pervasive cyber threat to UK organizations.
- Cyber criminals’ are using artificial intelligence to increase the volume and heighten the impact of cyber attacks. In January 2024, the NCSC published an assessment of the near-term impact of AI on the cyber threat, highlighting how it can be used for reconnaissance, social engineering and analysis of exfiltrated data.
- The Annual Review also notes an observation from the NCSC that the application of AI to cyber defence will exceed the uplift in any adversary capability or application.
Incidents
- This year, the NCSC’s Incident Management team handled 430 incidents, compared to 371 the previous year. Of these, 347 involved some level of data exfiltration and 20 incidents involved ransomware.
- The top sectors reporting ransomware activity into the NCSC this year were academia, manufacturing, IT, legal, charities, and construction.
- The Incident Management team issued 542 bespoke notifications informing organizations to a cyber incident impacting them and provided advice and guidance on how to mitigate it. This was more than double the 258 bespoke notifications issued last year.
- Almost half of the bespoke notifications sent this year related to pre-ransomware activity, enabling organizations to detect and remove precursor malware before ransomware was deployed.






