Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 16 of 33

Resilience renewed

While ransomware and Russia attracted a particular focus this year, the NCSC ensured a “threat-informed” approach in its continued resilience-building across a wide range of sectors in the face of a sustained threat and risk to businesses and organisations.

Earlier this year it was revealed that 39% of businesses in the UK had suffered a cyber attack over the previous 12 months, 20% of which faced a material outcome, such as loss of money or data.

39%

of businesses in the UK had suffered a cyber attack over the previous 12 months

As well as threats and risks, the NCSC continued to observe the impact and potential harm from critical vulnerabilities in the global IT system. One of the most serious this year was linked to the Log4j logging system that was present in millions of computers around the world.

The vulnerability, if left unfixed, meant that attackers could break into systems, steal passwords and logins, extract data, and infect networks with malicious software. As countries and institutions raced to patch the vulnerability, the NCSC took a leading role in alerting UK citizens, organisations and businesses, and providing them with advice and services, such as Early Warning, which notifies users about attacks, risks and vulnerabilities on their systems.

The NCSC’s general resilience efforts included a continual cycle of engagement and support in the form of webinars, briefings, bulletins and workshops, to inform and alert sectors of threats, risks and vulnerabilities, while showcasing and signposting them to advice, guidance, tools and services, giving them agency to apply these resources to help improve their resilience.


Published

Reviewed

Version

1.0

Written for