
NCSC
UK national cyber agency within GCHQ; advisories, attribution, and the GDPR Article 32 standard.
NCSC chief executive Dr Richard Horne told RUSI on 17 June 2026 that his agency handled over 200 cyber incidents against UK critical infrastructure in the past year, about 75% traced to Russia, China or Iran, as the Cyber Security and Resilience Bill that would put NCSC guidance on a statutory footing moved to the House of Lords.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Will the Cyber Security and Resilience Bill give NCSC guidance the force of statute on 10 June?
Timeline for NCSC
Provided March 2024 connectivity guidance that CISA cited as a mitigation resource
Cybersecurity: Threats and Defences: The alert's citations predate the alertMentioned in: One firm hedged, heise online named APT28
Cybersecurity: Threats and DefencesCo-sealed the AA26-204A advisory
Cybersecurity: Threats and Defences: Zimbra preview leaks mail to RussiaMentioned in: Hotel WiFi steers guests to fake logins
Cybersecurity: Threats and DefencesPublished a joint advisory naming FSB Centre 16
Cybersecurity: Threats and Defences: NCSC names FSB Centre 16 over routersBackground
The National Cyber Security Centre is the UK's national cybersecurity authority, operating as part of GCHQ. It provides threat advisories, Incident Response support, and guidance to UK industry and government on cybersecurity standards. NCSC's advisory outputs are informed by GCHQ's signals intelligence collection, giving them a higher attribution-confidence basis than purely commercial threat intelligence. NCSC works in formal partnership with the Five Eyes CERTs and regularly co-issues advisories with the US CISA, FBI, and the Dutch AIVD.
NCSC guidance carries regulatory weight beyond best-practice status: the UK ICO has established in both the Capita (£14m) and Advanced Computer Software (£3.07m) monetary penalty notices that NCSC cyber hygiene guidance, specifically Active Directory tiering and Privileged Access Management, constitutes the GDPR Article 32 technical standard.
On 23 July, NCSC was one of fifteen co-sealing agencies on advisory AA26-204A, led by CISA and the NSA. Its own advisory role was translating the Coalition's Zimbra webmail finding, that the exploited chain hands an attacker a victim's last 90 days of mail from a single preview, into guidance for UK operators to patch or isolate exposed instances. A CISA alert on water and wastewater plant controllers, published 30 July, separately cited NCSC's Secure Connectivity Principles for Operational Technology; that guidance dates to March 2024, so the citation reuses an existing standard rather than reflecting new or newly coordinated NCSC action.
Its guidance is becoming statutory law
The UK Cyber Security and Resilience Bill passed its third reading in the Commons on 10 June 2026 and advanced to the Lords, adding ransomware and attacker pre-positioning to the incidents organisations must report, with fines reaching £17 million or 4 per cent of global turnover; a proposed ransomware-payment disclosure requirement did not make the published text.
On the same day the Bill moved to the Lords, 17 June, NCSC chief executive Dr Richard Horne told the RUSI security conference his agency had handled over 200 cyber incidents against UK critical infrastructure in the past year, about 75 per cent traced to state actors in Russia, China or Iran, giving peers a concrete incident count to frame their scrutiny of a Bill that will convert NCSC's own guidance into a legal standard.
It keeps naming Russian router hijackers
NCSC assessed with 'almost certain' confidence on 7 April 2026 that GRU Unit 26165 ran a SOHO router DNS-hijacking campaign harvesting Microsoft 365 OAuth tokens, an attribution it reached jointly with the FBI.
NCSC returned to router hijacking on 9 July, this time naming FSB Centre 16 as part of a Coalition of 18 partner agencies, over a separate campaign exploiting decades-old default settings rather than a new software flaw; NCSC's own advice to UK operators was to change default credentials and disable remote management immediately, since no patch closes a configuration weakness.