Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 5 of 33

CEO Foreword

Lindy Cameron, CEO the National Cyber Security Centre

I am proud to present the NCSC’s Annual Review of 2022. As you will see, it has been a year of impressive achievement for the team I am really proud to lead, but also one in which the cyber security threat has evolved significantly.

The most profound change in the cyber security landscape over the past 12 months came with Russia’s invasion of Ukraine. The return of war to Europe presented a unique set of challenges in cyberspace for the NCSC, our partners and our allies. We have been part of a huge effort to ensure UK organisations, critical infrastructure and the whole of society are as resilient as they can be.

As well as keeping the UK safe, I am proud of the role the NCSC played, in conjunction with FCDO, in supporting the Ukrainian authorities’ staunch cyber defence in the face of Russian hostility. These efforts were shown to have been highly successful in protecting the Ukrainians against Russian cyber attacks and raising their general cyber resilience.

These new challenges were accompanied by other, more familiar threats. Ransomware remains the most acute threat that businesses and organisations in the UK face. These attacks have genuine real-world consequences and are a reminder to all organisations of the importance of taking the important mitigation measures set out in our guidance.

Low sophistication cyber crime also continues to be a scourge to the British public and organisations, but it is heartening to see a growing uptake in our services to protect against these threats. Sign-ups to our Early Warning service rose by over 90%, while the 6.5 million reports from the public to the Suspicious Email Reporting Service (SERS) shows that people are both becoming more cyber aware and contributing to our resilience. The NCSC, in conjunction with our law enforcement partners, is more resolute than ever in its determination to thwart cyber criminals.

We are making significant progress in bolstering the UK’s resilience, stopping hundreds of thousands of attacks upstream while bolstering preparedness and helping UK institutions and organisations better understand the nature of cyber threats, risks and vulnerabilities downstream. Despite this, there remain serious gaps in the nation’s defences, and the collective resilience-building effort must continue apace.

This Annual Review is as much about what lies ahead as it is about the current challenges. We highlight the threats on the horizon, including the growing commercial availability of offensive cyber tools and the risk of those falling into the wrong hands. This contrasts with the positive technological insight that NCSC experts provide in support of the UK’s values-driven approach to developing future technologies and the principles that underpin them. This work makes a global contribution and reflects the NCSC’s efforts to innovate and build capability to ensure that the technology on which our economy and society depends is secure, resilient and reliable.

We also look at the opportunities to grow a strong, healthy and diverse cyber security ecosystem, one of the pillars of the National Cyber Strategy. This is critical for national security, is essential to maintaining the UK’s global leadership in critical technologies and has a significant part to play in the growth of the UK economy. Working alongside government, academia and industry, the NCSC will continue building that ecosystem into the future.

Central to this is a diverse, talented workforce, and I am pleased to see that over the past 12 months initiatives such as CyberFirst have engaged thousands more bright, enthusiastic young people in cyber security. This is a source of great optimism as we move into 2023.

Lindy Cameron
CEO, the National Cyber Security Centre

Published

Reviewed

Version

1.0

Written for