The United Kingdom is facing an unprecedented cyber security crisis, as the National Cyber Security Centre (NCSC) reports that it handles on average four «nationally significant» cyber attacks per week. This alarming escalation represents a dangerous shift in the threat landscape, with the NCSC handling 204 nationally significant incidents over the twelve months that ended in August 2025, more than doubling the 89 attacks recorded the previous year.
See also: CISA: Requires Cisco to patch zero-day vulnerabilities

The threat landscape has reached critical proportions, with 18 incidents classified as ‘high significance’ during the reporting period. These attacks had the potential to cause serious disruption to essential services and infrastructure, marking an increase of almost 50% on the previous year and continuing a three-year upward trend. The NCSC’s latest Annual Review reveals that over half of the 429 incidents it handled required national coordination, underlining the systematic nature of these threats to UK interests.
See also: NCSC: UMBRELLA STAND malware targets FortiGate firewalls

A significant proportion of these attacks originated from Advanced Persistent Threats (APT), including both state operational and sophisticated criminal organizations. NCSC analysts noted the increasing complexity and persistence of these threat actors, who demonstrate advanced capabilities in targeting critical infrastructure, government systems, and private sector networks. The attacks have shown a significant potential impact on the United Kingdom's national security system, financial systems, and essential service providers.
Dr Richard Horne, Chief Executive of the NCSC, said: “Cybersecurity has become a matter of business survival and national resilience. The escalating threat requires immediate action from business leaders, as hesitancy represents a fundamental vulnerability that attackers are easily exploiting. The severity of the situation has prompted immediate government intervention, with formal letters being sent to CEOs and chairmen of major UK businesses, including all FTSE350.
See also: NCSC: Security guidance following attacks on M&S, Harrods, Co-op

This coordinated approach aims to establish cyber resilience as a board-level responsibility, while promoting collaboration between government and private sector actors. The NCSC has also launched the Cyber Action Toolkit, specifically designed to help small organisations implement key security controls against common threats. The initiative includes the promotion of the Cyber Essentials, which provides automatic cyber liability insurance for eligible UK organisations with an annual turnover of less than £20 million, creating financial incentives for the proper implementation of security in the business landscape.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
