Skip to main content
Annual Review

NCSC Annual Review 2023

Looking back at the National Cyber Security Centre's seventh year and its key developments and highlights, between 1 September 2022 and 31 August 2023.

Page 7 of 16

Threats and risks







Between September 2022 and August 2023, we received 297 reports of ransomware activity (‘tips’), triaged into 28 NCSC-managed incidents, 18 of which were categorised as C3 and above. The top five sectors reporting into the NCSC were academia (50), manufacturing (28), IT (22), finance (19) and engineering (18). Although academia appears high in our statistics, we do not have any specific evidence of actual targeting of this sector.






This year we received an all-time high of 2005 reports*, an increase of almost 64% from last year's 1226.

The NCSC issued 24.48 million notifications, informing organisations that they were experiencing a cyber incident, through our automated Early Warning service.

327 incidents involving the exfiltration/extortion of data (18.5% increase on last year.)

* Increase in reports attributed to change in data collection and cannot be compared directly to previous years.

Reviewed

Version

1.0

Written for