NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 17 of 32
Defending the UK’s critical national infrastructure

Closing the widening gap between the threat to critical systems, and our ability to defend them.
A step change in cyber resilience doesn’t happen overnight.
In last year’s annual review, we warned that the gap between the threat posed to critical national infrastructure (CNI) and the ability of owners and operators of CNI to defend against it was widening. Narrowing this gap became our top priority for the year, as we focused on raising the resilience of the UK’s most critical sectors to the most advanced cyber actors.
This has increased our knowledge of CNI cyber maturity in order to inform targeted interventions, giving them the tools to detect and evict sophisticated actors from their networks. With a better understanding of those organisations carrying the highest risk, we have continued developing the UK’s defensive capabilities to improve vulnerability detection and operational response.
We seek to ensure the UK has the capability to defend, hunt and evict threat actors to reduce the vulnerability and impose cost on adversaries operating against the most critical systems. This is being achieved through identifying and developing cyber security communities across the UK, alongside tradecraft and capability experimentation.
Interconnected threat to CNI
The increasingly complex and interconnected nature of our technology and systems across CNI delivers great benefits - but also risks. This means that cyber-initiated attacks could have physical consequences.
Working closely with our partners at NPSA we both recognise the importance of supporting CNI to address physical, personnel and cyber vulnerabilities. A key priority to should be to review the countering sabotage guidance, and to act on it.
'Preparedness For Crisis' project
The National Security Strategy 2025 described the UK as entering a new era “characterised by radical uncertainty”. The international order is being reshaped by an intensification of great power competition, authoritarian aggression and extremist ideologies. This uncertainty brings many challenges, including threats to our cyber resilience.
As we explain in the threat chapter, disruptive cyber attacks are now part of the playbook for aggressors. This means operators of essential services should understand what defensive actions they could take if there was a step change in threat, allowing them to continue to operate their services even in a crisis. They should be prepared to increase their situational awareness (for example with enhanced threat hunting) or harden defences (for example by isolating operational technology or reducing the attack surface).
Operators of essential services should be prepared to increase their situational awareness or harden defences.
The NCSC’s ‘Preparedness for Crisis Project’ continues to place emphasis on the importance of organisations testing and gaining assurance in advance, and integrating these processes into their resilience strategies. Over the next year, the NCSC will be focused on helping organisations to prepare for crises, with new advice, guidance and tools.
Threat sharing and threat hunting
We have also continued to arm the most critical systems with threat intelligence through the TiSP (Threat Intelligence Sharing Platform), having this year onboarded private sector CNI, government and international organisations. In spring 2025, the NCSC convened two of the largest threat hunting workshops to date, tailored for both public and private sector cyber defenders. These comprised 60 experienced analysts from 28 government organisations and 80 experienced analysts from 55 private sector CNI organisations. These events are part of a community to improve threat hunting, upskill organisations, and share detailed insights into real incidents experienced by attendees.
Sector-specific interventions
With the majority of the UK’s CNI privately owned, the NCSC continues to offer specialist, sector-specific technical advice to industry. Informed by the threat landscape, our offering to CNI sectors has continued to be enhanced to ensure private sector owners and operators are well informed and have prioritised cyber security. We have continued to treat the cyber security of CNI as a shared responsibility, promoting our advice and guidance and empowering organisations to take action using this.
The Cyber Security and Resilience Bill (CSRB) is critical to our objective of improving cyber resilience of the UK’s highest priority public and private sector CNI, including recovery planning against advanced threats. The CSRB will provide the baseline against which both the regulatory framework and regulator capabilities will be uplifted.
-
In the transport sector, alongside government and industry, we have used our role as the National Technical Authority for cyber security to consider cyber security risks related to critical emerging technologies, such as Connected and Autonomous Vehicles (CAVs); gaining insights from innovative projects such as the new self-driving shuttles in Milton Keynes city centre.
-
In the finance sector, a multi-year collaborative project between the NCSC and the Bank of England has concluded, resulting in an initiative to embed cyber security into the renewed banking system used across the country.
-
Following the designation of data centres as CNI, we’ve helped shape government understanding of the cyber risk to that sector and the critical interdependencies. We have continued to work closely with DSIT to prepare for the implementation of the Cyber Security and Resilience Bill (CSRB). If enacted, more organisations (such as managed service providers) would be brought into scope of the NIS Regulations , the UK's Network and Information Regulations that aim to ensure the security and reliability of digital infrastructure. The government would also have new executive powers to respond to evolving cyber threats.
-
Our work to assist the energy sector in protecting its infrastructure over the last year has been wide-ranging, including providing technical advice and guidance on the cyber security challenges associated with mitigating risks and collaborating directly with critical suppliers on cyber security projects and extended support to operators of renewable energy assets, helping them to manage cyber security risks as part of the drive to secure the UK's ambitions for a Net Zero future.
Cyber risks to UK defence
In light of the 2025 Strategic Defence Review’s recognition of intolerable cyber risks in UK defence, we’ve intensified collaboration with the Ministry of Defence (MOD) to boost cyber resilience across its supply chain. Adoption of Active Cyber Defence (ACD) services has grown, extending protective DNS and host-based tools - typically reserved for the public sector - to key suppliers. These tools block threats, gather metadata for NCSC analysis, and provide expert support.
We’ve also revitalised the Defence Technical Information Exchange (DTIE), a joint NCSC-industry forum for sharing threat intelligence and mitigation strategies among key defence suppliers. Additionally, we’ve supported the development and launch of MOD’s Defence Cyber Certification (DCC) scheme, which ensures supplier cyber resilience through independent certification – providing assurance of organisational cyber resilience in support of future Defence procurements.
The NCSC has also maintained its vital role in supporting complex defence programmes, providing expert technical advice to ensure the security and resilience of strategic projects and their supply chains. Notable collaborations include:
-
The Dreadnought programme, the replacement programme for the Royal Navy’s Trident missile Vanguard Class submarines which form the UK’s nuclear deterrent.
-
The Future Combat Air System, the UK’s requirement and programme of record to deliver a next generation combat air capability. FCAS forms part of The Global Combat Air Programme, an international partnership between the UK, Japan and Italy which will design, manufacture and deliver the next generation crewed combat aircraft.
-
AUKUS, the Australia-UK-US defence partnership. This includes supporting the design and development of the ASTUTE replacement nuclear powered submarines known as SSN-AUKUS.
-
Op Highmast the Carrier Strike Group 25, through support to MOD with cyber security advice as part of the Op Highmast planning process.
The UK health sector
Focusing on cyber security across the health sector is essential to ensure sensitive data is protected, critical services operate smoothly, and public trust is upheld. In August 2024, the NCSC responded to several cyber attacks in the health sector, including the ransomware attack on Synnovis. In the aftermath, the NCSC brought together senior health representatives from across the four nations to identify shared challenges.
Since then, a broad collaboration has been fostered between the NCSC, UK health organisations, and industry partners. Within this partnership new tools and services through the Active Cyber Defence (ACD) 2.0 programme have been piloted, including Attack Surface Management and Deception Technology. Other initiatives include:
-
Preparing for future threats by assessing quantum readiness
-
Managing vulnerability disclosures
-
Sharing threat intelligence and tradecraft
-
Supporting supply chain security through initiatives like the NCSC Early Warning service and Cyber Essentials scheme
The NCSC has also worked with the health sector to help develop the joint NCSC/DSIT Software Code of Practice , which promotes secure software development. The NHS is the first large organisation to build use of this product into their software procurement process.
Strengthening government cyber security
The NCSC is working closely with the Government Digital Service (GDS) to support the development of a more interventionist model for cyber security across government. Together, we are collaborating on a Target Operating Model that will set out how this approach will work in practice, including ensuring clear roles, responsibilities and processes for managing systemic risks.
Our collaboration is already delivering key initiatives such as:
- the GovAssure cyber assurance regime, which provides a consistent and rigorous framework for assessing departmental resilience
- the Government Cyber Coordination Centre (GC3), which strengthens threat intelligence sharing, vulnerability management and incident response across government
We are now expanding this joint working to other areas including how centralised cyber security services are delivered across the public sector. Our collective efforts aim to address long-standing challenges such as legacy IT vulnerabilities, improving collective preparedness, and ensuring that government services remain secure and resilient. By combining the NCSC’s technical expertise with GDS’s leadership on digital delivery, we are building a stronger, more proactive approach to cyber security across the public sector.
Supporting democracy in a borderless cyber landscape
The 2024 Annual Review highlighted a pivotal year for global democracy, with elections taking place across numerous nations amid rising geopolitical tensions and rapid technological change. Throughout 2025, the NCSC has continued to reflect on lessons learned and monitor an evolving threat landscape, particularly as innovations in technology and election services reshape democratic processes.
Cyber threats know no borders. In response, we have strengthened collaboration with international partners, working closely with FCDO’s International Cyber Network, to share insights, build resilience, and promote best practice on election security.
As the threat landscape evolves, the NCSC remains committed to supporting both domestic and international partners. In the UK, we are working closely with the Electoral Commission and the Joint Election Security Preparedness Unit to assess and strengthen cyber risk controls ahead of major democratic events. The next UK general election, is expected to be the first to rely predominantly on cloud-based Electoral Management Systems, marking a significant shift in how elections are administered and secured.
To prepare for this transition, we are supporting the Ministry of Communities Housing and Local Government to ensure that security standards and resilience measures are future-proofed. This work forms part of a broader strategy to modernise and secure UK elections, as outlined in the government’s 2025 Elections and Democracy Bill. The Bill also includes proposals to lower the voting age to 16, expand digital voter ID options, and improve voter registration systems.
Organisations need to look at their security in the round to make the right choices.
Updating the Cyber Assessment Framework (CAF)
Since the last version of the NCSC Cyber Assessment Framework (CAF) was published in April 2024, its adoption has continued to spread. It is now used by nearly all UK cyber regulators and is established in the public sector via GovAssure, the cyber security assurance scheme for assessing the critical systems of government organisations.
The most significant amendments in version 4.0 reflect the changing threats that organisations face:
- 1
A new section on building a deeper understanding of attacker methods and motivations to inform better cyber risk decisions.
- 2
- 3
Updates to the section on security monitoring and threat hunting to improve the detection of cyber threats.
- 4
There is improved coverage of AI-related cyber risks throughout the CAF.
The NCSC is supporting the community of cyber regulators and oversight bodies that use the CAF so that their sectors can make a quick transition to CAF v4.0. The CAF forms part of a broader suite of tools we provide to regulators and operators to build confidence and resilience, including:
- Cyber Resilience Audit, a scheme that gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits. The Cyber Resilience Audit scheme members will undertake independent cyber audits on behalf of a Cyber Oversight Body.
- Cyber Adversary Simulation, a scheme that assures commercial organisations providing Cyber Adversary Simulation services which meet our CyAS Standard. We have designed the scheme so that buyers can use it independently as part of their own cyber resilience activities, or under the direction of their Cyber Oversight Body.
Secure Innovation
Operating a secure business is not just about cyber security; organisations need to look at their security in the round to make the right choices. The NCSC therefore works in partnership with NPSA, as the National Technical Authority for Physical and Personnel Security, to help organisations address the full range of security threats that they may face. The Secure Innovation campaign has had international impact, with its guidance adopted by Five Eyes countries in October 2024, helping protect innovation, reputation, and national security.
Building on the Secure Innovation campaign, the Secure Innovation Security Reviews Scheme is a joint initiative by the NCSC, NPSA, DSIT and Department of Business and Trade (DBT). It provides partial funding for up to 500 organisations in the UK emerging technology sector with direct support and guidance from an approved Security Reviewer to protect their ideas, technologies, reputation, and future success. Businesses must be registered and based in the UK, have under 250 staff and be working in one of the 17 sensitive areas of the economy set out in the National Security and Investment Act, or selected sectors from Invest 2035: the UK's modern industrial strategy.
Launched in July 2025 after a successful pilot, the scheme is delivered via InnovateUK and Business West, with most costs funded by DSIT. Reviews are conducted by vetted professionals and include a site visit, a report with recommendations, and a follow-up call.