NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 12 of 33
NCSC View: Future Threat Challenges

Proliferation of cyber capabilities
In the coming years, the NCSC anticipates that the proliferation and commercial availability of cyber capabilities will expand the cyber security threat to the UK. In the future, malicious and disruptive cyber tools will be available to a wider range of state and non-state actors and will be deployed with greater frequency and with less predictability.

This wide and complicated landscape includes the provision of off-the-shelf cyber surveillance products and supporting services, the vulnerability and exploit marketplace, hackers-for-hire offering bespoke hacking services and the use of commercially or publicly available malware.
The growing grey market for cyber tools lowers the barrier to entry to states in obtaining capability – some of which will be highly advanced and sophisticated – and therefore the intelligence that they would not otherwise develop or acquire. Demand for these products and services is such that we expect the sector to continue to grow.
Hackers-for-hire and ‘As-a-Service’ models are also lowering the barrier to entry for non-state actors. Ransomware as a Service (RaaS) is an example of how this proliferation is allowing less sophisticated criminal actors to extort organisations. We are also seeing emerging use of hacking services in corporate espionage.
In June 2022, Lindy Cameron highlighted the challenge that proliferation of cyber capabilities presents in a speech during Tel Aviv Cyber Week, stating:
If we are going to maintain a cyberspace which is a safe and prosperous place for everyone, it is vital that such capabilities are produced and used in a way that is legal, responsible and proportionate.
In addition, the geopolitical landscape has also spurred on the actions of non-state actors; cyber criminals, and 'hacktivists' with economic or political motivations. We saw this following the Russian invasion of Ukraine and while we cannot predict the long-term impact of these actors, the impact of their actions will continue to shape the cyber landscape.
Supply chain attacks

The technology ecosystem that we all rely on is continuing to grow rapidly – and becoming increasingly complex. This size and complexity create increased opportunities for criminals and states to achieve their ambitions.
Supply chain attacks are an example of how this increasingly complex technology ecosystem can be exploited. Where organisations cannot directly be compromised, an adversary can take advantage of lax security somewhere in that organisation’s digital supply chain.
This came to prominence with the 2020 compromise of SolarWinds by the SVR However, the threat to technology supply chains is much broader than this isolated case.
Over the last year, the threat to global IT infrastructure from foreign states and cyber criminals has almost certainly grown as both continued to develop their capabilities against the IT sector. While foreign states target entities for intelligence gain, cyber criminals targeted them largely to carry out ransomware or data extortion attacks for profit.