Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 10 of 33

Cyber incidents in the UK

Over the last year, businesses and organisations in the UK reported hundreds of cyber incidents to the NCSC, 63 of which were significant enough to require a national level response. The incidents included a range of malicious cyber activity such as ransomware, reconnaissance, malware and network intrusions, data exfiltration and disruption of services and systems.

Commodity attacks: high-volume, low-sophistication attacks usually involving phishing and other scams often reaching citizens and small businesses.

While the NCSC sought to stop as many attacks as possible getting through – 2.1 million commodity campaigns were removed – it worked throughout the year with its partners, including with the NCA to form a whole system approach, to respond to incidents when they occurred, and helped victims to recover.

2.1m

commodity campaigns removed

Over the last year, the commercial cyber incident response sector has continued to mature. End to end support packages provided through cyber insurance policies, including legal assistance and technical response from cyber incident response companies, are becoming more common.

The NCSC’s Cyber Incident Response (CIR) Level 1 scheme assures companies which deal with sophisticated, targeted attacks against networks of national significance. In the coming year the NCSC is planning to widen this out to include a Level 2 scheme which will provide technical response for incidents affecting small to medium-sized enterprises who require more accessible CIR support.

Although ransomware disrupted critical national infrastructure organisations last year following a series of high-profile incidents, such as the attack against Colonial Pipeline in the US, it is apparent that the public outcry and heightened political interest has raised the stakes for cyber criminals. In response it became clear that some groups modified their techniques to avoid law enforcement, sanctions and other operational responses.

Published

Reviewed

Version

1.0

Written for