NCSC Annual Review 2023
Pages
Page 7 of 16
Threats and risks

Introduction
The global threat landscape is ever-changing, so it has never been more important for the NCSC, as the UK’s technical cyber security authority to continue to identify, monitor and analyse key cyber security threats, risks, and vulnerabilities. The NCSC enables and supports wider government and society to anticipate and respond to new and recurring challenges.
This year has seen the emergence of state-aligned actors as a new and emerging cyber threat to critical national infrastructure (CNI), the continuation of Russia’s illegal invasion of Ukraine, and the concerns around the potential risks from AI, all of which drive the need for NCSC interventions and support.
China
The rise of China as a technology super-power poses an epoch-defining challenge for UK security and, as NCSC CEO Lindy Cameron highlighted in her speech at this year’s CYBERUK, we risk China becoming the predominant power in cyberspace if our efforts to raise resilience and develop our capabilities do not keep pace.
With our partners, we continue to see evidence of China state-affiliated cyber actors deploying sophisticated capability to pursue strategic objectives which threaten the security and stability of UK interests.
In May, the NCSC and international partner agencies issued a joint advisory highlighting how recent China state-sponsored activity had targeted critical infrastructure networks in the US and could be applied worldwide. And in October, MI5 Director General Ken McCallum warned about the state threat to cutting-edge start-ups working on UK research and innovation.
The challenge is global and systemic, and close collaboration with allies and industry will be crucial in further developing our understanding of the cyber capabilities threatening the UK.
Russia
Since Russia’s further invasion of Ukraine in February 2022, the NCSC has helped Ukraine to develop its cyber resilience. We continue to see further cyber activity targeting Ukraine by Russia and Russia-aligned actors. Beginning in 2022, this included a wave of distributed-denial-of-service (DDoS) and data wiper attacks against Ukrainian government and industry. However, the impact on Ukraine has been less than expected, in part due to well-developed Ukrainian cyber security and support from industry and international partners, including the UK’s own cyber programme.
Iran
In January, the NCSC issued an advisory highlighting spear-phishing activity against targeted individuals in sectors of interest to Iran, including academia, defence, government organisations, NGOs, think tanks, as well as politicians, journalists and activists. In July, the UK government highlighted the rising threat from Iran including increased efforts to kill or kidnap individuals perceived to be enemies of the regime outside of Iran, including in the UK. Iran remains an aggressive and capable cyber actor and will almost certainly use cyber for its objectives. The NCSC continues to work closely with government and industry partners to understand and mitigate the cyber threat from Iran.
Democratic People’s Republic of Korea (DPRK)
Cyber is one of the means through which the DPRK aims to improve their poor economic situation through illicit revenue generation and sanctions evasion, to further consolidate the current regime, and to strengthen and maintain its ability to defend itself against perceived hostile actors. Raising funds via cyber thefts is widely reported, and cyber attacks against a variety of institutions, companies, and government organisations in search of information and credentials is also prolific.
Ransomware
Ransomware remains one of the most acute cyber threats facing the UK, and all domestic organisations should take action to protect themselves from this pervasive threat. The now-normal approach of stealing and encrypting data continues to be the primary tactic cyber criminals used to maximise profits. However, data extortion attacks, in which data is stolen but not encrypted are a growing trend in the threat landscape.
Between September 2022 and August 2023, we received 297 reports of ransomware activity (‘tips’), triaged into 28 NCSC-managed incidents, 18 of which were categorised as C3 and above. The top five sectors reporting into the NCSC were academia (50), manufacturing (28), IT (22), finance (19) and engineering (18). Although academia appears high in our statistics, we do not have any specific evidence of actual targeting of this sector.
Cyber proliferation
Commercial proliferation will almost certainly be transformational to the cyber threat landscape. Commercial cyber tools and services lower the barrier to entry to both state and non-state actors, enabling them to access cost-effective capability and intelligence they would not otherwise be able to acquire. This creates an opportunity for misuse in the absence of oversight or an understanding of how international norms apply. The NCSC continues to support government with the UK’s international response working with like-minded countries, to ensure advanced commercial cyber capabilities are developed, sold, and applied in a way that is legal, responsible, and proportionate as part of the UK government’s ambition to instil responsible behaviours in cyberspace.
Cyber-enabled fraud
Fraud continues to be one of the most significant threats facing UK businesses and citizens. In 2021, more than 80% of all reported UK fraud was cyber-enabled, but only 32% of UK citizens thought they were likely to become a victim. Over the past year, the UK government’s Cyber Aware campaign supported individuals and small businesses to significantly improve their cyber resilience with two simple steps:
- use a password based on three random words
- secure accounts by enabling two-step verification (2SV)
Critical national infrastructure (CNI)
2023 has seen the addition of state-aligned actors to the ongoing threat from state actors, as a new and emerging cyber threat to CNI. While the cyber activity of these groups often focuses on DDoS attacks, website defacements and/or the spread of misinformation, some have stated a desire to achieve a more disruptive and destructive impact against western CNI, including in the UK. The NCSC continues to prioritise the resilience of UK CNI.
Artificial intelligence / large language models
Our adversaries – hostile states and cyber criminals – will seek to exploit AI technology to enhance existing tradecraft. In the short term, AI technology is more likely to amplify existing cyber threats than create wholly new ones, but it will almost certainly sharply increase the speed and scale of some attacks. There is now a significant amount of activity across the NCSC and wider government to assess and respond to the potential threats and risk posed by AI.
Incident management
Within the NCSC, the Incident Management (IM) team deals with all the cyber attacks that are reported to us. focussing in particular on incidents of national significance for the UK.
This year we saw a jump in reports of cyber attacks coming into the NCSC, but the volumes that reached the threshold of national significance remained broadly stable. There were, however, more incidents at the top end of the scale, reflecting more high-level and damaging incidents against the UK.
This year we received 2,005 reports, an increase of almost 64% from last year's 1,226. 371 were deemed serious enough to be handled by the IM team (compared with 355 last year). Of these, 62 were nationally significant (63 last year) and four of them were among the most severe incidents the NCSC has had to manage (compared with one last year) due to the sustained disruption they caused and the victims’ links to critical infrastructure via supply chains.
The NCSC issued 24.48 million notifications informing subscribing organisations of potential malicious activity detected on their networks, or exposure to a vulnerability, through our automated Early Warning service. Of these, 258 notifications were considered serious enough for a bespoke service from the IM team.
The NCSC was made aware of 327 reports that involved the exfiltration/extortion of data, which is an increase on last year and is indicative of the value that both cyber criminals and nation state actors find in data. All types of data can be manipulated by these actors, meaning unsuspecting organisations could be considered targets.
The highest proportion of incidents handled by the NCSC resulted from the exploitation of public-facing applications. This involves an actor exploiting a vulnerability in a public-facing application to gain unauthorised access to a target network. Incidents resulting from these vulnerabilities can be some of the most widespread, for example in the Citrix vulnerability (CVE-2023-3519) the NCSC was required to deal with 13 separate nationally significant incidents involving the exploitation of this vulnerability. To aid the prevention of incidents such as this, caused by poor cyber hygiene, the NCSC sent over 16,000 notifications of vulnerable services via our Early Warning service.
This year we received an all-time high of 2005 reports*, an increase of almost 64% from last year's 1226.
The NCSC issued 24.48 million notifications, informing organisations that they were experiencing a cyber incident, through our automated Early Warning service.
327 incidents involving the exfiltration/extortion of data (18.5% increase on last year.)
* Increase in reports attributed to change in data collection and cannot be compared directly to previous years.