NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 7 of 33
Threats, Risks and Vulnerabilities

Introduction
One of the most important roles of the NCSC is to identify, monitor and analyse key cyber security threats, risks and vulnerabilities to inform how the organisation, wider government and the whole of society can keep ahead of and respond to these challenges.
Over the last year, the cyber security threat to the UK has evolved significantly. The threat from ransomware was ever present – and remains a major challenge to businesses and public services in the UK. This year, 18 ransomware incidents required a nationally co-ordinated response, including attacks on a supplier to NHS 111, and a water utility company, South Staffordshire Water.
2.7m
cyber-related frauds in the 12 months to March 2022
The most significant threat facing citizens and small businesses continued to be from cyber crime, such as phishing, while hacking of social media accounts remained an issue. Official figures revealed there were 2.7m cyber-related frauds in the 12 months to March 2022.
Internationally, Russia's invasion of Ukraine brought the cyber security threat into sharper focus in the UK. During the invasion, Russia sought to use disruptive cyber operations to support their military campaign. However, like on the battlefield, Ukrainian authorities – assisted by the NCSC – created strong cyber defences, limiting the impact of Russian operations. Ukraine’s successful defensive operations was an exemplar to network defenders across the world.
While not as prominent as Russian operations in cyberspace, the Chinese state’s cyber capabilities continued to develop. China’s activity has become ever more sophisticated, with the state increasingly targeting third-party technology and service supply chains, as well as exploiting software vulnerabilities. This approach shows no sign of abating, with China’s technical evolution likely to be the single biggest factor affecting the UK’s cyber security in the future.
Evolving state threats were not the only cyber security challenges this year: the proliferation and commercial availability of cyber capabilities continued and is likely to expand the threat to the UK. It is expected that further malicious and disruptive cyber tools will be available to a wider range of state and non-state actors, and will be deployed with greater frequency and less predictability.
Threats to the global supply chain continued to be apparent where attackers accessed target victim organisation’s networks or systems via third-party vendors or suppliers. Meanwhile, the disclosure of the Log4j vulnerability highlighted the challenges where weaknesses in IT systems are exploited to deliver successful attacks.
In response to these notable threats the NCSC stepped up its automated notification service with the launch of Early Warning in May. One of the newest ACD services, Early Warning, which is free and open to any organisation, had, by the end of August 2022 sent 34 million notifications to its 7,500 and growing members to inform them of potential threats, risks, vulnerabilities or open ports in their networks. This included alerting them to over 500 unique malware variants.
While the NCSC sought to stop as many attacks as possible getting through – 2.1 million commodity campaigns were removed this year – it worked throughout 2022 with its partners to respond to incidents when they occurred, and helped victims to recover. This year the NCSC managed the response to hundreds of incidents, 63 of which were nationally significant.
This chapter sets out the key threats, risks and vulnerabilities in more detail and the NCSC’s analysis and response.