Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 11 of 32

‘Beyond detection’: why collaboration is vital to combatting the evolving threat

Our adversaries have the ability to innovate and evolve. As cyber defenders, we must do the same.

 

 

In last year’s Annual Review, we spoke about the cyber threat becoming “increasingly diffuse and dangerous”. 2025 has seen that trend intensify. We are in a period of sustained international competition, punctuated by multiple acute crises and increasing conflict. Cyber is being used by state and non-state actors to achieve their goals, and the overall cyber threat to the UK is growing from an already high level. The NCSC’s incident statistics underline this growing intensity, with nationally significant incidents up by 50%.

Understanding the world we are in, and the role that cyber now plays within crisis and conflict, means we must also shift how we respond. In the face of escalating threat, we must develop the ability to rapidly interpret intent, capability, and geopolitical context across multiple actors in complex environments.

The need for this is increased by the varied ways we see threat actors operate, for the differing purposes of espionage, destruction, influence and leverage. This ranges from core capability and differing intents, from tightly controlled elite units to generating ecosystems of private sector, hacktivism and proxies access.

Of course, not all threat actors are equal. In the application of technologies, for example, there is a huge difference between a state-linked actor using AI for vulnerability research and exploit development (VRED), and a low-skilled cyber criminal using a jailbroken LLM to create more convincing phishing messages.

Regardless of the technical capabilities, the cumulative effect on threat is significant, leading to increased diversification, intensification and frequency of cyber threats across every sector in the UK.

While the threat is intensifying, the activity that the NCSC has repeatedly called out is not radically new, whether that’s the targeting of western technology companies by the Russian GRU or the operational activities of hacking group Scattered Spider. It’s more ‘evolution than revolution’, with existing techniques, tactics and procedures (TTPs) exploiting the complexity of the connected systems, networks and data we increasingly rely on.

Taken together, it means that traditional modes of understanding and response based on steady, static threat actor groupings are outdated. We exist in a world now where no one actor can understand everything, where no one government can set rules alone, and where digital sovereignty does not exist. It is a world where the ability to compromise the fundamental infrastructure of our lives comes at relatively low-cost, with near-anonymity and little fear of repercussion.

All this makes cyberspace a unique environment with unique challenges.

What is needed to operate in this environment are strategies to respond, deter and counter that are informed, context-aware and flexible. Understanding threat today is not just about detection; it is about outcompeting adversaries in insight and agility. We must be able to make sense of a complex, broad technical landscape at pace, and link this to geopolitical context, not least in understanding the intent of actors and our global exposure to them.

Understanding threat is not just about detection, it is about outcompeting adversaries in insight and agility.

Recognising this places huge emphasis on collaboration. Not one of us holds a monopoly on information, though we each have unique data and insight. The ability to share what we can, understand and respond to an increasingly differentiated threat environment is what will give us a competitive and strategic advantage in a world that is increasingly trying to diminish that advantage. And that work should not just be in how we share insight and the data that underpins it, but also how we generate it too. In this world, as cyber security professionals we must be technically and politically literate, and able to collaborate rapidly, flex and respond to a level of threat that is beyond what we have seen before.

The question for all of us now is ‘What more can we do to understand threat collaboratively, and at the pace we need to in a conflictual environment?’ Our sharing communities need to be deeper, faster and more actionable, sharing data and insight at speed, driving quicker evidence-based decision making.

Together with our colleagues across government, industry and academia, the NCSC is seeking to develop a data-led, collaborative response to threat insight and sharing. Our initiatives range from our established i100 and Cyber League initiatives (which brings together a trusted community of NCSC and industry cyber experts to work on the biggest cyber threats facing the UK), to our Trust Groups, a sector-specific community of CISOs which are so integral to information and threat sharing. More recently, we’ve launched the LASR (Laboratory for AI Security Research), a UK public-private initiative conducting foundational and applied research on AI security, focused on government national security priorities. It means that industry data and expertise are part of the design, not just as passive contributors, but as strategic partners in shaping defences that are relevant to different threat types.

But we must all do more. Our adversaries have the ability to innovate and evolve TTPs against an increasingly volatile and uncertain geopolitical climate. As cyber defenders, we must ensure that we can do the same. As our collaborative work drives resilience and makes life harder for threat actors, we must turn our threat understanding and response into real competitive edge, helping us to get ahead of the threat in an increasingly contested and competitive online world.

Published

Reviewed

Version

1.0