NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 10 of 33
Cyber incidents in the UK
Over the last year, businesses and organisations in the UK reported hundreds of cyber incidents to the NCSC, 63 of which were significant enough to require a national level response. The incidents included a range of malicious cyber activity such as ransomware, reconnaissance, malware and network intrusions, data exfiltration and disruption of services and systems.

While the NCSC sought to stop as many attacks as possible getting through – 2.1 million commodity campaigns were removed – it worked throughout the year with its partners, including with the NCA to form a whole system approach, to respond to incidents when they occurred, and helped victims to recover.
2.1m
commodity campaigns removed
Over the last year, the commercial cyber incident response sector has continued to mature. End to end support packages provided through cyber insurance policies, including legal assistance and technical response from cyber incident response companies, are becoming more common.
The NCSC’s Cyber Incident Response (CIR) Level 1 scheme assures companies which deal with sophisticated, targeted attacks against networks of national significance. In the coming year the NCSC is planning to widen this out to include a Level 2 scheme which will provide technical response for incidents affecting small to medium-sized enterprises who require more accessible CIR support.
Although ransomware disrupted critical national infrastructure organisations last year following a series of high-profile incidents, such as the attack against Colonial Pipeline in the US, it is apparent that the public outcry and heightened political interest has raised the stakes for cyber criminals. In response it became clear that some groups modified their techniques to avoid law enforcement, sanctions and other operational responses.