Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 17 of 32

Defending the UK’s critical national infrastructure

Closing the widening gap between the threat to critical systems, and our ability to defend them.

A step change in cyber resilience doesn’t happen overnight.

In last year’s annual review, we warned that the gap between the threat posed to critical national infrastructure (CNI) and the ability of owners and operators of CNI to defend against it was widening. Narrowing this gap became our top priority for the year, as we focused on raising the resilience of the UK’s most critical sectors to the most advanced cyber actors.

This has increased our knowledge of CNI cyber maturity in order to inform targeted interventions, giving them the tools to detect and evict sophisticated actors from their networks. With a better understanding of those organisations carrying the highest risk, we have continued developing the UK’s defensive capabilities to improve vulnerability detection and operational response.

We seek to ensure the UK has the capability to defend, hunt and evict threat actors to reduce the vulnerability and impose cost on adversaries operating against the most critical systems. This is being achieved through identifying and developing cyber security communities across the UK, alongside tradecraft and capability experimentation.

Interconnected threat to CNI

The increasingly complex and interconnected nature of our technology and systems across CNI delivers great benefits - but also risks. This means that cyber-initiated attacks could have physical consequences.

Working closely with our partners at NPSA we both recognise the importance of supporting CNI to address physical, personnel and cyber vulnerabilities. A key priority to should be to review the countering sabotage guidance, and to act on it.

'Preparedness For Crisis' project

The National Security Strategy 2025 described the UK as entering a new era “characterised by radical uncertainty”. The international order is being reshaped by an intensification of great power competition, authoritarian aggression and extremist ideologies. This uncertainty brings many challenges, including threats to our cyber resilience.

As we explain in the threat chapter, disruptive cyber attacks are now part of the playbook for aggressors. This means operators of essential services should understand what defensive actions they could take if there was a step change in threat, allowing them to continue to operate their services even in a crisis. They should be prepared to increase their situational awareness (for example with enhanced threat hunting) or harden defences (for example by isolating operational technology or reducing the attack surface).

Operators of essential services should be prepared to increase their situational awareness or harden defences.

The NCSC’s ‘Preparedness for Crisis Project’ continues to place emphasis on the importance of organisations testing and gaining assurance in advance, and integrating these processes into their resilience strategies. Over the next year, the NCSC will be focused on helping organisations to prepare for crises, with new advice, guidance and tools.

Threat sharing and threat hunting

We have also continued to arm the most critical systems with threat intelligence through the TiSP (Threat Intelligence Sharing Platform), having this year onboarded private sector CNI, government and international organisations. In spring 2025, the NCSC convened two of the largest threat hunting workshops to date, tailored for both public and private sector cyber defenders. These comprised 60 experienced analysts from 28 government organisations and 80 experienced analysts from 55 private sector CNI organisations. These events are part of a community to improve threat hunting, upskill organisations, and share detailed insights into real incidents experienced by attendees.


Cyber risks to UK defence

In light of the 2025 Strategic Defence Review’s recognition of intolerable cyber risks in UK defence, we’ve intensified collaboration with the Ministry of Defence (MOD) to boost cyber resilience across its supply chain. Adoption of Active Cyber Defence (ACD) services has grown, extending protective DNS and host-based tools - typically reserved for the public sector - to key suppliers. These tools block threats, gather metadata for NCSC analysis, and provide expert support.

We’ve also revitalised the Defence Technical Information Exchange (DTIE), a joint NCSC-industry forum for sharing threat intelligence and mitigation strategies among key defence suppliers. Additionally, we’ve supported the development and launch of MOD’s Defence Cyber Certification (DCC) scheme, which ensures supplier cyber resilience through independent certification – providing assurance of organisational cyber resilience in support of future Defence procurements.

The NCSC has also maintained its vital role in supporting complex defence programmes, providing expert technical advice to ensure the security and resilience of strategic projects and their supply chains. Notable collaborations include:

  • The Dreadnought programme, the replacement programme for the Royal Navy’s Trident missile Vanguard Class submarines which form the UK’s nuclear deterrent.

  • The Future Combat Air System, the UK’s requirement and programme of record to deliver a next generation combat air capability. FCAS forms part of The Global Combat Air Programme, an international partnership between the UK, Japan and Italy which will design, manufacture and deliver the next generation crewed combat aircraft.

  • AUKUS, the Australia-UK-US defence partnership. This includes supporting the design and development of the ASTUTE replacement nuclear powered submarines known as SSN-AUKUS.

  • Op Highmast the Carrier Strike Group 25, through support to MOD with cyber security advice as part of the Op Highmast planning process.

The UK health sector

Focusing on cyber security across the health sector is essential to ensure sensitive data is protected, critical services operate smoothly, and public trust is upheld. In August 2024, the NCSC responded to several cyber attacks in the health sector, including the ransomware attack on Synnovis. In the aftermath, the NCSC brought together senior health representatives from across the four nations to identify shared challenges.

Since then, a broad collaboration has been fostered between the NCSC, UK health organisations, and industry partners. Within this partnership new tools and services through the Active Cyber Defence (ACD) 2.0 programme have been piloted, including Attack Surface Management and Deception Technology. Other initiatives include:

  • Preparing for future threats by assessing quantum readiness

  • Managing vulnerability disclosures

  • Sharing threat intelligence and tradecraft

  • Supporting supply chain security through initiatives like the NCSC Early Warning service and Cyber Essentials scheme

The NCSC has also worked with the health sector to help develop the joint NCSC/DSIT Software Code of Practice , which promotes secure software development. The NHS is the first large organisation to build use of this product into their software procurement process.




The NCSC is supporting the community of cyber regulators and oversight bodies that use the CAF so that their sectors can make a quick transition to CAF v4.0. The CAF forms part of a broader suite of tools we provide to regulators and operators to build confidence and resilience, including:

  • Cyber Resilience Audit, a scheme that gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits. The Cyber Resilience Audit scheme members will undertake independent cyber audits on behalf of a Cyber Oversight Body. 
  • Cyber Adversary Simulation, a scheme that assures commercial organisations providing Cyber Adversary Simulation services which meet our CyAS Standard. We have designed the scheme so that buyers can use it independently as part of their own cyber resilience activities, or under the direction of their Cyber Oversight Body.

Published

Reviewed

Version

1.0