NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 14 of 33
Ransomware
The resilience story this year can be told through the “three Rs”: ransomware, Russia and renewal. While one of the most high-profile and concerning cyber risks came from Russian cyber aggression related to their invasion of Ukraine, it was another “R” that required much of the NCSC’s focus on resilience this year: ransomware.
With ransomware continuing to be a significant threat, the NCSC joined government, NCA, Regional Organised Crime Units, police forces and the cyber security sector to improve resilience by stopping attacks getting through, calling out threat actors, reviewing policies, fine-tuning practices and working internationally to tackle this global issue. The NCSC took a three-pronged approach:
- Alerting audiences to the latest threats, risks and vulnerabilities and updating and clarifying advice and guidance in how to respond to mitigate them
- Engaging directly with sectors, especially those at risk, to encourage take-up of services, tools and behaviours, including webinars, roundtables, site visits and briefings
- Widening the scope and refreshing its advice, guidance and services, including the renowned Active Cyber Defence programme
A government ransomware “sprint”, led by the Home Office, improved understanding of the scale and complexity of the threat, and helped it to better prioritise, focus resources, refine advice and be more targeted in its engagement.
As part of the NCSC’s contribution to the UK’s international cooperation on this threat, in September, senior UK and US cyber security leaders met to discuss shared threats and opportunities and reaffirm their commitment to tackling ransomware. In February the NCSC joined the US and Australia to reveal growing sophistication of ransomware and urged businesses to take protective action against increasingly professional criminal attacks.
To support organisations improve their own resilience, in March, the NCSC launched the new ransomware hub with refreshed advice and guidance, including practical resources to help users prevent, report, respond to and recover from attacks.

NCSC’s key actions to take to prepare for ransomware:
- make regular backups
- prevent malware from being delivered and spreading to devices
- prevent malware from running on devices
- prepare for an incident
More advice can be found on the ransomware hub.