Skip to content
You can now search across every topic, entity and event.What's new
NCSC
OrganisationGB

NCSC

UK national cyber agency within GCHQ; advisories, attribution, and the GDPR Article 32 standard.

NCSC chief executive Dr Richard Horne told RUSI on 17 June 2026 that his agency handled over 200 cyber incidents against UK critical infrastructure in the past year, about 75% traced to Russia, China or Iran, as the Cyber Security and Resilience Bill that would put NCSC guidance on a statutory footing moved to the House of Lords.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Will the Cyber Security and Resilience Bill give NCSC guidance the force of statute on 10 June?

Timeline for NCSC

#12 29 Jul

Provided March 2024 connectivity guidance that CISA cited as a mitigation resource

Cybersecurity: Threats and Defences: The alert's citations predate the alert
#12 26 Jul
#11 23 Jul

Co-sealed the AA26-204A advisory

Cybersecurity: Threats and Defences: Zimbra preview leaks mail to Russia
#12 22 Jul
#10 9 Jul

Published a joint advisory naming FSB Centre 16

Cybersecurity: Threats and Defences: NCSC names FSB Centre 16 over routers
View full timeline →

Background

The National Cyber Security Centre is the UK's national cybersecurity authority, operating as part of GCHQ. It provides threat advisories, Incident Response support, and guidance to UK industry and government on cybersecurity standards. NCSC's advisory outputs are informed by GCHQ's signals intelligence collection, giving them a higher attribution-confidence basis than purely commercial threat intelligence. NCSC works in formal partnership with the Five Eyes CERTs and regularly co-issues advisories with the US CISA, FBI, and the Dutch AIVD.

NCSC guidance carries regulatory weight beyond best-practice status: the UK ICO has established in both the Capita (£14m) and Advanced Computer Software (£3.07m) monetary penalty notices that NCSC cyber hygiene guidance, specifically Active Directory tiering and Privileged Access Management, constitutes the GDPR Article 32 technical standard.

On 23 July, NCSC was one of fifteen co-sealing agencies on advisory AA26-204A, led by CISA and the NSA. Its own advisory role was translating the Coalition's Zimbra webmail finding, that the exploited chain hands an attacker a victim's last 90 days of mail from a single preview, into guidance for UK operators to patch or isolate exposed instances. A CISA alert on water and wastewater plant controllers, published 30 July, separately cited NCSC's Secure Connectivity Principles for Operational Technology; that guidance dates to March 2024, so the citation reuses an existing standard rather than reflecting new or newly coordinated NCSC action.

Key Issues
Statutory footing

Its guidance is becoming statutory law

The UK Cyber Security and Resilience Bill passed its third reading in the Commons on 10 June 2026 and advanced to the Lords, adding ransomware and attacker pre-positioning to the incidents organisations must report, with fines reaching £17 million or 4 per cent of global turnover; a proposed ransomware-payment disclosure requirement did not make the published text.

On the same day the Bill moved to the Lords, 17 June, NCSC chief executive Dr Richard Horne told the RUSI security conference his agency had handled over 200 cyber incidents against UK critical infrastructure in the past year, about 75 per cent traced to state actors in Russia, China or Iran, giving peers a concrete incident count to frame their scrutiny of a Bill that will convert NCSC's own guidance into a legal standard.

Router hijacking

It keeps naming Russian router hijackers

NCSC assessed with 'almost certain' confidence on 7 April 2026 that GRU Unit 26165 ran a SOHO router DNS-hijacking campaign harvesting Microsoft 365 OAuth tokens, an attribution it reached jointly with the FBI.

NCSC returned to router hijacking on 9 July, this time naming FSB Centre 16 as part of a Coalition of 18 partner agencies, over a separate campaign exploiting decades-old default settings rather than a new software flaw; NCSC's own advice to UK operators was to change default credentials and disable remote management immediately, since no patch closes a configuration weakness.

Common Questions
What has NCSC warned about in 2026?
In March-May 2026, NCSC issued advisories on CitrixBleed 3 (25 March), state-linked QR-code attacks on Signal and WhatsApp (31 March, co-issued with Dutch AIVD), and APT28's SOHO router DNS hijacking campaign targeting Microsoft 365 (7 April, co-issued with FBI).Source: NCSC
Does NCSC guidance have legal force in the UK?
NCSC guidance is not legislation, but the UK ICO has established in the Capita and Advanced Computer Software monetary penalty notices that NCSC guidance constitutes the GDPR Article 32 technical standard. Organisations that fail to follow published NCSC guidance in a covered category face documented enforcement risk after a breach.Source: ICO
What is the NCSC's role in the Cyber Security and Resilience Bill?
The UK Cyber Security and Resilience Bill, scheduled for Commons Report Stage and Third Reading on 10 June 2026, will expand NCSC's co-regulatory role alongside Ofcom and DSIT, placing NCSC technical guidance on a statutory footing for data-centre operators and critical national infrastructure providers. It carries a two-tier penalty regime up to 4 per cent of global turnover.Source: UK Parliament / DSIT
How is NCSC connected to GCHQ?
NCSC operates as part of GCHQ, the UK's signals intelligence agency. This gives NCSC advisories access to signals intelligence that commercial threat intelligence firms cannot replicate, enabling higher-confidence attribution assessments such as the APT28/GRU Unit 26165 designation.Source: NCSC
How many cyber attacks hit UK critical infrastructure in 2026?
NCSC managed over 200 cyber incidents against UK critical national infrastructure in the year to May 2026, with approximately 75 per cent linked to state actors in Russia, China, and Iran, according to NCSC CEO Dr Richard Horne at RUSI on 17 June 2026.Source: event
What is the FortiBleed Fortinet credential leak?
FortiBleed is a privately-held database of 86,644 Fortinet FortiGate firewall credentials from 194 countries, disclosed on 18 June 2026 by researcher Volodymyr Diachenko, built via credential reuse and traffic interception since at least February 2026 by a suspected Russian-speaking actor.Source: event
When does NCSC expect AI to enable large-scale cyber attacks?
NCSC CEO Dr Richard Horne said at RUSI on 17 June 2026 that AI-enabled exploitation of known vulnerabilities at scale is expected by 2028.Source: event
What did NCSC's July 2026 LAUNDRY BEAR advisory warn about?
On 23 July 2026 NCSC co-sealed a 15-nation advisory, AA26-204A, led by CISA and the NSA, naming Russian state-supported actor LAUNDRY BEAR behind a zero-click exploit chain against Zimbra Collaboration Suite webmail.Source: NCSC