NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 10 of 32
Incident management

The NCSC Incident Management Team (NCSC IM) work with industry to respond to cyber incidents impacting UK organisations. We play a core role in minimising harm, restoring operations and helping victims to get back on their feet.
The team is responsible for triaging incidents, supporting affected organisations and - for nationally significant incidents - serves as the central coordination hub for the cross-government response. This ensures there’s a rapid, unified effort to protect UK citizens and critical services.
NCSC IM works closely with the National Crime Agency and wider law enforcement partners who play a pivotal role in tackling cyber threats. By bringing together the operational, technical, and strategic capabilities of government, NCSC IM enhances our collective ability to detect, deter, and mitigate cyber threats. This coordinated approach not only reduces harm to the UK but also strengthens our national cyber resilience.
We also work closely with the UK’s Cyber Incident Response companies, law enforcement, UK and international intelligence partners and wider industry, to protect UK interests.
Incidents of national significance
This year NCSC IM received 1,727 incident tips from a combination of our own information flows and reports from partners and victims. These were triaged into 429 incidents requiring support from the NCSC IM team. This represents a similar total trend from the previous year.
However, nationally significant incidents represent 48% (204) of all incidents, a significant increase from last year (89). A nationally significant incident covers incidents in the upper three categories in the NCSC and UK law enforcement categorisation model. Amongst this year's incidents, 4% (18) were categorised as highly significant in nature. This marks an almost 50% increase in highly significant incidents, an increase for the third consecutive year.
NCSC IM treats all reports in confidence. We encourage all affected organisations to report incidents to regulatory bodies who in turn view engagement with NCSC IM positively. However, for many businesses, reporting a breach is not mandatory. Since many chose not to do this, our data is not a true reflection of the number of cyber incidents that impact the UK.
Categorising UK cyber incidents
The UK government cyber attack categorisation is designed to improve response to incidents. The top 3 categories deal with nationally significant incidents.
A cyber attack which causes sustained disruption of UK essential services or affects UK national security, leading to severe economic or social consequences or to loss of life.
A cyber attack which has a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.
A cyber attack which has a serious impact on a large organisation or on wider/local government, or which poses a considerable risk to central government or UK essential services.
The top sectors reporting ransomware activity to the NCSC this year were academia, finance, engineering, retail, health and manufacturing. However, no sector (and no organisation) is exempt from this threat.
Table shows yearly totals for tips, incidents handled and highly significant and significant incidents. Number of highly significant incidents is shown in brackets.
| Year (Sep - Aug) | Total tips | Incidents handled | Highly significant and significant incidents |
|---|---|---|---|
| 2024 - 2025 | 1727 | 429 | 204 (18) |
| 2023 - 2024 | 1957 | 430 | 89 (12) |
| 2022 - 2023 | 2005* | 371 | 62 (4) |
| 2021 - 2022 | 1226 | 355 | 63 (1) |
*Increase in reports attributed to change in data collection and cannot be compared directly to previous year
Vulnerabilities in legacy systems
A contributing factor to the increase in the volume of severe incidents is the exploitation of vulnerabilities by a small number of cyber actors. For example, NCSC IM published alerts for CVE-2025-0282 (Ivanti Connect Secure, Policy Secure & ZTA Gateways), CVE-2024-47575 (Fortinet FortiManager) and CVE-2025-53770 (Microsoft SharePoint Server products), signposting organisations to the respective vendors' security advisories. These three CVEs alone were associated with 29 incidents managed by the NCSC.
Report an incident
Organisations can find out where to report a cyber incident in the UK using the signposting service at gov.uk/report-cyber.
You may need to report your incident to the Information Commissioner's Office (ICO) if there has been a breach of personal data. You can find out more by using the ICO’s self assessment tool.
If you’re an individual and you’ve lost money, tell your bank straight away and report it to Action Fraud or in Scotland, contact CyberScotland.