Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 28 of 32

From Bletchley to the battlefield: Crypt-Key and the evolution of UK cyber defence

In an era defined by geopolitical uncertainty and relentless cyber threats, Crypt-Key has quietly but decisively shaped the UK's national security posture.

Often operating behind the scenes, Crypt-Key is the cryptographic engine that secures the UK’s most sensitive information across defence, government, and international operations. It’s not just a tool – it’s a strategic capability. And in 2025, it is as important as ever that this work continues to evolve and keep pace with changing threats and emerging technologies.

This important capability is built on a legacy of excellence. Throughout its history, GCHQ has attracted and developed world-class expertise in information assurance and security, notably in cryptography. From its origins in 1919, through the legendary work at Bletchley Park, to the pioneering creation of public key cryptography by James Ellis and colleagues in the 1960s, the UK has consistently been at the forefront of cryptographic innovation. Crypt-Key is built on that legacy, and we must continue to evolve, operationalise and deploy to meet today’s most complex security challenges.

Crypt-Key predates the internet, yet it remains at the forefront of cyber defence. Designed to withstand the most advanced and persistent threats, it operates in highly contested environments, from battlefield networks to government communications. Its ubiquity across military platforms and civil infrastructure speaks to its enduring relevance.

But Crypt-Key is not standing still. Under the leadership of the NCSC, it is evolving to meet new challenges. In 2025 alone, the NCSC approved a dozen new Crypt-Key products and variants for operational use, each one reflecting the UK’s commitment to staying ahead of the threat curve.






(1) A method of distributing authentication keys over the network to encryption devices, removing the need for central key generation and physical key distribution / installation.

Published

Reviewed

Version

1.0