Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

NCSC counts 200+ UK infrastructure hits

3 min read
16:08UTC

NCSC chief Richard Horne told RUSI on 17 June that the agency handled more than 200 cyber incidents against UK critical infrastructure in a year, about 75% state-linked.

TechnologyDeveloping
Key takeaway

Britain's cyber agency put a number on the state-backed threat to national infrastructure: 200-plus incidents, mostly hostile states.

Dr Richard Horne, chief executive of Britain's national cyber agency, the NCSC (National Cyber Security Centre), told the RUSI (Royal United Services Institute) annual security lecture on 17 June that NCSC managed more than 200 cyber incidents against UK critical national infrastructure in the year to May 1. RUSI is a London defence think tank; critical national infrastructure covers the energy, water, health, transport, and finance systems a country cannot function without. Around 75% of those incidents were linked to state actors in Russia, China, and Iran, Horne said 2. He warned that vulnerabilities tolerated today will be exploited in conflict tomorrow.

The number does work beyond the headline. It lands as the UK Cyber Security and Resilience Bill moves through Parliament, having cleared the Commons on 10 June without the ransomware-payment regime that fell out at report stage . A bill asking operators to report incidents and meet baseline standards is easier to defend with a named agency putting a count on the threat to the systems it covers. Horne's 200-plus figure, three-quarters of it traced to hostile states, is the evidence base ministers can cite at the Lords stage.

Horne also looked forward, putting AI-enabled exploitation of known flaws at scale by 2028 3. That horizon would be overtaken within days, when the wider Five Eyes alliance compressed the same timeline far harder in a joint statement of its own.

Deep Analysis

In plain English

The NCSC (National Cyber Security Centre) is the UK government body that defends the country's most important infrastructure: power grids, water systems, hospitals, financial networks, and communications. Dr Richard Horne, the NCSC's chief executive, told a security conference on 17 June that his agency dealt with more than 200 cyber incidents against these systems in the year to May 2026. Three-quarters of them were linked to state actors in Russia, China, and Iran. Horne also warned that by 2028, AI tools will allow adversaries to find and exploit weaknesses in critical systems far faster than today. The analogy is an attacker who currently takes weeks to find an unlocked door being replaced by one who tests every door in seconds. The UK's Cyber Security and Resilience Bill, which was heading to the House of Lords the same day, will require more organisations to report such attacks faster.

Deep Analysis
Root Causes

The 75 per cent state-actor rate against UK CNI reflects a structural feature of the current geopolitical environment: Russia, China, and Iran have each developed persistent access to CNI networks as a strategic hedge against conventional conflict escalation. Maintaining persistent access is cheaper and less provocative than developing kinetic CNI attack capability, making it a dominant strategy for states that want leverage without crossing a war-fighting threshold.

The 2028 AI exploitation warning reflects a specific technical development track: the June 2026 Five Eyes joint statement and GTIG's confirmation of the first large language model-written zero-day both compress the horizon for AI-assisted vulnerability discovery. The 2028 date represents NCSC's assessment of when AI-enabled discovery of previously unknown CNI vulnerabilities becomes operationally reliable for adversaries, not when first instances occur.

What could happen next?
  • Consequence

    The 200+ figure provides the UK Cyber Security and Resilience Bill with a quantified domestic evidence base ahead of Lords scrutiny; peers seeking to strengthen mandatory reporting or sector scope provisions now have NCSC-sourced incident data to cite.

  • Risk

    The 2028 AI exploitation warning compresses the security community's planning horizon: product security teams, CNI operators, and regulators must treat 2028 as a hard planning deadline for AI-resilient vulnerability management, not a horizon to monitor.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

NCSC· 24 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.