Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 7 of 33

Threats, Risks and Vulnerabilities

An image of a globe with connecting red beams of light
Photo credit: iStock.com/imaginima
This chapter sets out the key threats, risks and vulnerabilities and the NCSC’s analysis and response.

The most significant threat facing citizens and small businesses continued to be from cyber crime, such as phishing, while hacking of social media accounts remained an issue. Official figures revealed there were 2.7m cyber-related frauds in the 12 months to March 2022.

Internationally, Russia's invasion of Ukraine brought the cyber security threat into sharper focus in the UK. During the invasion, Russia sought to use disruptive cyber operations to support their military campaign. However, like on the battlefield, Ukrainian authorities – assisted by the NCSC – created strong cyber defences, limiting the impact of Russian operations. Ukraine’s successful defensive operations was an exemplar to network defenders across the world.

While not as prominent as Russian operations in cyberspace, the Chinese state’s cyber capabilities continued to develop. China’s activity has become ever more sophisticated, with the state increasingly targeting third-party technology and service supply chains, as well as exploiting software vulnerabilities. This approach shows no sign of abating, with China’s technical evolution likely to be the single biggest factor affecting the UK’s cyber security in the future.

Evolving state threats were not the only cyber security challenges this year: the proliferation and commercial availability of cyber capabilities continued and is likely to expand the threat to the UK. It is expected that further malicious and disruptive cyber tools will be available to a wider range of state and non-state actors, and will be deployed with greater frequency and less predictability.

Threats to the global supply chain continued to be apparent where attackers accessed target victim organisation’s networks or systems via third-party vendors or suppliers. Meanwhile, the disclosure of the Log4j vulnerability highlighted the challenges where weaknesses in IT systems are exploited to deliver successful attacks.

In response to these notable threats the NCSC stepped up its automated notification service with the launch of Early Warning in May. One of the newest ACD services, Early Warning, which is free and open to any organisation, had, by the end of August 2022 sent 34 million notifications to its 7,500 and growing members to inform them of potential threats, risks, vulnerabilities or open ports in their networks. This included alerting them to over 500 unique malware variants.

While the NCSC sought to stop as many attacks as possible getting through – 2.1 million commodity campaigns were removed this year – it worked throughout 2022 with its partners to respond to incidents when they occurred, and helped victims to recover. This year the NCSC managed the response to hundreds of incidents, 63 of which were nationally significant.

This chapter sets out the key threats, risks and vulnerabilities in more detail and the NCSC’s analysis and response.

Reviewed

Version

1.0

Written for