Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

NCSC counts 200+ UK infrastructure hits

3 min read
18:20UTC

NCSC chief Richard Horne told RUSI on 17 June that the agency handled more than 200 cyber incidents against UK critical infrastructure in a year, about 75% state-linked.

TechnologyDeveloping
Key takeaway

Britain's cyber agency put a number on the state-backed threat to national infrastructure: 200-plus incidents, mostly hostile states.

Dr Richard Horne, chief executive of Britain's national cyber agency, the NCSC (National Cyber Security Centre), told the RUSI (Royal United Services Institute) annual security lecture on 17 June that NCSC managed more than 200 cyber incidents against UK critical national infrastructure in the year to May 1. RUSI is a London defence think tank; critical national infrastructure covers the energy, water, health, transport, and finance systems a country cannot function without. Around 75% of those incidents were linked to state actors in Russia, China, and Iran, Horne said 2. He warned that vulnerabilities tolerated today will be exploited in conflict tomorrow.

The number does work beyond the headline. It lands as the UK Cyber Security and Resilience Bill moves through Parliament, having cleared the Commons on 10 June without the ransomware-payment regime that fell out at report stage . A bill asking operators to report incidents and meet baseline standards is easier to defend with a named agency putting a count on the threat to the systems it covers. Horne's 200-plus figure, three-quarters of it traced to hostile states, is the evidence base ministers can cite at the Lords stage.

Horne also looked forward, putting AI-enabled exploitation of known flaws at scale by 2028 3. That horizon would be overtaken within days, when the wider Five Eyes alliance compressed the same timeline far harder in a joint statement of its own.

Deep Analysis

In plain English

The NCSC (National Cyber Security Centre) is the UK government body that defends the country's most important infrastructure: power grids, water systems, hospitals, financial networks, and communications. Dr Richard Horne, the NCSC's chief executive, told a security conference on 17 June that his agency dealt with more than 200 cyber incidents against these systems in the year to May 2026. Three-quarters of them were linked to state actors in Russia, China, and Iran. Horne also warned that by 2028, AI tools will allow adversaries to find and exploit weaknesses in critical systems far faster than today. The analogy is an attacker who currently takes weeks to find an unlocked door being replaced by one who tests every door in seconds. The UK's Cyber Security and Resilience Bill, which was heading to the House of Lords the same day, will require more organisations to report such attacks faster.

Deep Analysis
Root Causes

The 75 per cent state-actor rate against UK CNI reflects a structural feature of the current geopolitical environment: Russia, China, and Iran have each developed persistent access to CNI networks as a strategic hedge against conventional conflict escalation. Maintaining persistent access is cheaper and less provocative than developing kinetic CNI attack capability, making it a dominant strategy for states that want leverage without crossing a war-fighting threshold.

The 2028 AI exploitation warning reflects a specific technical development track: the June 2026 Five Eyes joint statement and GTIG's confirmation of the first large language model-written zero-day both compress the horizon for AI-assisted vulnerability discovery. The 2028 date represents NCSC's assessment of when AI-enabled discovery of previously unknown CNI vulnerabilities becomes operationally reliable for adversaries, not when first instances occur.

What could happen next?
  • Consequence

    The 200+ figure provides the UK Cyber Security and Resilience Bill with a quantified domestic evidence base ahead of Lords scrutiny; peers seeking to strengthen mandatory reporting or sector scope provisions now have NCSC-sourced incident data to cite.

  • Risk

    The 2028 AI exploitation warning compresses the security community's planning horizon: product security teams, CNI operators, and regulators must treat 2028 as a hard planning deadline for AI-resilient vulnerability management, not a horizon to monitor.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

NCSC· 24 Jun 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.