Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

NCSC counts 200+ UK infrastructure hits

3 min read
12:09UTC

NCSC chief Richard Horne told RUSI on 17 June that the agency handled more than 200 cyber incidents against UK critical infrastructure in a year, about 75% state-linked.

TechnologyDeveloping
Key takeaway

Britain's cyber agency put a number on the state-backed threat to national infrastructure: 200-plus incidents, mostly hostile states.

Dr Richard Horne, chief executive of Britain's national cyber agency, the NCSC (National Cyber Security Centre), told the RUSI (Royal United Services Institute) annual security lecture on 17 June that NCSC managed more than 200 cyber incidents against UK critical national infrastructure in the year to May 1. RUSI is a London defence think tank; critical national infrastructure covers the energy, water, health, transport, and finance systems a country cannot function without. Around 75% of those incidents were linked to state actors in Russia, China, and Iran, Horne said 2. He warned that vulnerabilities tolerated today will be exploited in conflict tomorrow.

The number does work beyond the headline. It lands as the UK Cyber Security and Resilience Bill moves through Parliament, having cleared the Commons on 10 June without the ransomware-payment regime that fell out at report stage . A bill asking operators to report incidents and meet baseline standards is easier to defend with a named agency putting a count on the threat to the systems it covers. Horne's 200-plus figure, three-quarters of it traced to hostile states, is the evidence base ministers can cite at the Lords stage.

Horne also looked forward, putting AI-enabled exploitation of known flaws at scale by 2028 3. That horizon would be overtaken within days, when the wider Five Eyes alliance compressed the same timeline far harder in a joint statement of its own.

Deep Analysis

In plain English

The NCSC (National Cyber Security Centre) is the UK government body that defends the country's most important infrastructure: power grids, water systems, hospitals, financial networks, and communications. Dr Richard Horne, the NCSC's chief executive, told a security conference on 17 June that his agency dealt with more than 200 cyber incidents against these systems in the year to May 2026. Three-quarters of them were linked to state actors in Russia, China, and Iran. Horne also warned that by 2028, AI tools will allow adversaries to find and exploit weaknesses in critical systems far faster than today. The analogy is an attacker who currently takes weeks to find an unlocked door being replaced by one who tests every door in seconds. The UK's Cyber Security and Resilience Bill, which was heading to the House of Lords the same day, will require more organisations to report such attacks faster.

Deep Analysis
Root Causes

The 75 per cent state-actor rate against UK CNI reflects a structural feature of the current geopolitical environment: Russia, China, and Iran have each developed persistent access to CNI networks as a strategic hedge against conventional conflict escalation. Maintaining persistent access is cheaper and less provocative than developing kinetic CNI attack capability, making it a dominant strategy for states that want leverage without crossing a war-fighting threshold.

The 2028 AI exploitation warning reflects a specific technical development track: the June 2026 Five Eyes joint statement and GTIG's confirmation of the first large language model-written zero-day both compress the horizon for AI-assisted vulnerability discovery. The 2028 date represents NCSC's assessment of when AI-enabled discovery of previously unknown CNI vulnerabilities becomes operationally reliable for adversaries, not when first instances occur.

What could happen next?
  • Consequence

    The 200+ figure provides the UK Cyber Security and Resilience Bill with a quantified domestic evidence base ahead of Lords scrutiny; peers seeking to strengthen mandatory reporting or sector scope provisions now have NCSC-sourced incident data to cite.

  • Risk

    The 2028 AI exploitation warning compresses the security community's planning horizon: product security teams, CNI operators, and regulators must treat 2028 as a hard planning deadline for AI-resilient vulnerability management, not a horizon to monitor.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

NCSC· 24 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.