NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 3 of 32
Foreword

Over the last year, cyber attacks on household brands have brought the NCSC’s work to the forefront of public consciousness. Empty shelves and stalled production lines are a stark reminder that cyber attacks no longer just affect computers and data, but real business, real products, and real lives.
We've also seen how organisations that suffer a cyber attack can experience financial losses, lengthy service disruption with customers’ personal data often caught in the crossfire.
The recent cyber attacks must act as a wake-up call. The new normal is that cyber criminals will target organisations of all sizes, operating in any sector. From local coffee shops to providers of critical national infrastructure, every organisation must understand their exposure, build their defences and have a plan for how they would continue to operate without their IT (and rebuild that IT at pace) were an attack to get through.
In today’s volatile and technology-dependent world, online attacks can also be the outcome of geopolitics. As this year’s review illustrates, nearly half of all incidents handled by the NCSC over the last 12 months were of national significance. And 4% of these were categorised as ‘highly significant’ – attacks which we define as “having a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.” That marks a 50% increase in highly significant incidents for the third consecutive year.
These numbers clearly illustrate that the challenge we face is growing at an order of magnitude. We do see some organisations – ones with well-thought-through plans for continuity and recovery already in place – respond well to disruptive cyber attacks. This is what all organisations should aspire to, because almost every business depends on technology to function.
But for too long, cyber security has been regarded as an issue predominantly for technical staff. This must change. All business leaders need to take responsibility for their organisation’s cyber resilience.
Cyber security is now critical to business longevity and success.
It is time to act.