Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 10 of 32

Incident management

The NCSC Incident Management Team (NCSC IM) work with industry to respond to cyber incidents impacting UK organisations. We play a core role in minimising harm, restoring operations and helping victims to get back on their feet.

The team is responsible for triaging incidents, supporting affected organisations and - for nationally significant incidents - serves as the central coordination hub for the cross-government response. This ensures there’s a rapid, unified effort to protect UK citizens and critical services.

NCSC IM works closely with the National Crime Agency and wider law enforcement partners who play a pivotal role in tackling cyber threats. By bringing together the operational, technical, and strategic capabilities of government, NCSC IM enhances our collective ability to detect, deter, and mitigate cyber threats. This coordinated approach not only reduces harm to the UK but also strengthens our national cyber resilience.

We also work closely with the UK’s Cyber Incident Response companies, law enforcement, UK and international intelligence partners and wider industry, to protect UK interests.


The top sectors reporting ransomware activity to the NCSC this year were academia, finance, engineering, retail, health and manufacturing. However, no sector (and no organisation) is exempt from this threat.

Table shows yearly totals for tips, incidents handled and highly significant and significant incidents. Number of highly significant incidents is shown in brackets.
Year (Sep - Aug) Total tipsIncidents handledHighly significant and significant incidents
2024 - 20251727429204 (18)
2023 - 2024195743089 (12)
2022 - 20232005*37162 (4)
2021 - 2022122635563 (1)

*Increase in reports attributed to change in data collection and cannot be compared directly to previous year


Report an incident

Organisations can find out where to report a cyber incident in the UK using the signposting service at gov.uk/report-cyber.

You may need to report your incident to the Information Commissioner's Office (ICO) if there has been a breach of personal data. You can find out more by using the ICO’s self assessment tool.

If you’re an individual and you’ve lost money, tell your bank straight away and report it to Action Fraud or in Scotland, contact CyberScotland.

Published

Reviewed

Version

1.0