UK joins international partners to issue advice on latest Russian cyber threat
An overview of Russian cyber threats to critical infrastructure and mitigation guidance for all organisations.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The UK has today joined international partners to share updated mitigation advice against Russian state-sponsored and criminal cyber threats.
The advisory is published jointly by the National Cyber Security Centre (NCSC) – a part of GCHQ – alongside agencies in the US, Australia, Canada and New Zealand, as well as the UK’s National Crime Agency. It provides technical details on the threat to critical infrastructure from Russian state-sponsored and cyber criminals.
It complements recent NCSC advice on actions to take when the cyber threat is heightened, and aims to further improve the resilience of organisations in the event of heightened malicious cyber activity.
Several immediate actions for all organisations to take to protect their networks are set out in the advisory, which include:
Lindy Cameron, NCSC CEO, said:
“In this period of heightened cyber threat, it has never been more important to plan and invest in longer-lasting security measures.
“It is vital that all organisations accelerate plans to raise their overall cyber resilience, particularly those defending our most critical assets.
“The NCSC continues to collaborate with our international and law enforcement partners to provide organisations with timely actionable advice to give them the best chance of preventing cyber attacks, wherever they come from.”
The advisory also includes details on Russian-aligned cyber criminal groups, some of which have recently pledged support for the Russian state and have threatened to conduct malicious operations in retaliation against countries providing support to Ukraine.
The advisory is available to read in full on the Cybersecurity and Infrastructure Security Agency’s (CISA) website.
“Given recent intelligence indicating that the Russian government is exploring options for potential cyberattacks against US critical infrastructure, CISA along with our interagency and international partners are putting out this advisory to highlight the demonstrated threat and capability of Russian state-sponsored and Russian aligned cybercrime groups.
“We know that malicious cyber activity is part of the Russian playbook, which is why every organisation – large and small – should take action to protect themselves during this heightened threat environment. We urge all critical infrastructure owners and operators as well as all organisations to review the guidance in this advisory as well as visit www.cisa.gov/shields-up for regular updated information to protect yourself and your business.”
“Threats to critical infrastructure remain very real. The Russia situation means you must invest and take action.”
“The FBI is focused on exposing and disrupting malicious cyber activity by Russia against our allies and our own networks.
“We are working alongside our federal and international partners to quickly share information that helps private industry as well as the public to better protect and defend their systems from these threats. We will continue to investigate these malicious threat actors through our unique authorities and hold them accountable for their actions.”
“Recent intelligence and historic instances of destructive cyber attacks indicate now is the time for organisations to improve their cyber security posture. In particular, critical infrastructure organisations should act now to raise defences, not wait until being attacked.
“The ACSC stands ready to support its critical infrastructure partners in responding to the threats we face by raising their awareness of the threat, sharing indicators of compromise, and providing technical mitigation advice.”
“Russia has significant cyber capabilities and a demonstrated history of using them irresponsibly, and state-sponsored malicious cyber activity is a real risk to organisations around the world.
“By joining alongside our partners in releasing today’s joint advisory, the Communications Security Establishment and its Canadian Centre for Cyber Security continue to support making threat information more publicly available, while providing specific advice and guidance to help protect against these kinds of risks.”
“We are currently seeing an increased potential for cyber-attacks on critical infrastructures which may have a serious impact, even for countries and organisations not directly targeted.
“Organisations should take the opportunity to consider their security posture, understand their critical systems and risks – including across their supply chain – and exercise readiness. This joint advisory with our partners provides organisations with important information which will help them to build their cyber resilience by identifying and mitigating risks they face.”


