Annual Review 2025 launch
CEO Richard Horne announces the NCSC's ninth Annual Review.

Introduction
Last year, I spoke to you about the widening gap between the rising pace of the cyber threat and the UK’s collective resilience in facing that threat.
This year, that gap continues to grow.
So today, my message is simple: the time to act is now.
Over the past few weeks and months we have seen household names impacted by cyber incidents across all sectors of the economy… from retail to manufacturing and transport.
And those are just the incidents that have made the headlines.
Statistics
While you may be able to recall a handful of specific stories... in the twelve months to the end of August this year, our Incident Management team was asked to support some 429 cyber incidents.
When we dig into those numbers, nearly half of all incidents that have crossed our desks have been of national significance.
Meaning that, on average, the NCSC has dealt with four nationally significant incidents a week.
And 18 were classed as ‘highly significant’,
Attacks which have a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.
That is a 50% increase on the previous year, and a marked increase for the third consecutive year.
The implications
Now it would be easy to look at these numbers, and think we’re under siege, that we should hold up our hands and admit defeat... but that is not the case.
We know that far, far more cyber attacks fail than succeed.
That is not by chance.
It’s because organisations have built good defences.
We are also seeing more organisations able to continue in the face of an attack that does break through because they were prepared.
It can be done.
But we do see our attackers improving their ability to cause real impact…to inflict pain on the organisations they have breached and those who rely on them.
They don’t care who they hit or how they hurt them
That is why we need all organisations to act.
Cyber attacks are not just a matter of computers and data.
They impact growth, prosperity, safety, national security, reputations, operations, bottom lines, lives and livelihoods.
The impacts of an incident
As Shirine Khoury-Haq – the CEO of the Co-Op – has said, there is nothing that can fully prepare you for the moment a cyber incident unfolds and you receive that phone call.
But worse than receiving that call is receiving it when you do not have a plan.
I’ve sat now in too many rooms with individuals who have been deeply affected by cyber attacks against their organisations.
I’ve seen the emotional impact written across their faces.
I know the impact the disruption has on their staff, suppliers and customers, the worry, the sleepless nights.
And the impact it has on the teams who work round the clock for weeks and months trying to put the pieces back together.
What action to take
So, the time to act is now.
Every leader, whether you’re one person at your kitchen table or the boss of thousands of people, you must have a plan to defend against criminal cyber attacks
And...you must have a plan for continuity.
You must know how to keep going should an attack get through.
If your IT infrastructure was crippled tomorrow and all your screens went blank, could you run your payroll systems? or keep your machinery working? or stock your shelves?
If the answer is no, or more likely ‘don’t know’ act now.
Because when an attack does break through it is the strength of these pre-engineered solutions that determines an organisation’s ability to endure, respond, rebuild, survive.
And confronting that challenge of continuity should make clear to every leader that cyber security is a risk to be managed by the whole organisation led by the board, not one to just be delegated to technical experts.
NCSC support
Now nine years in, the NCSC’s mission is the same as it has always been: To make the UK the safest place to live and work online.
And we are continuing to support organisations to act now to secure themselves.
As you heard from the Security Minister, the new Cyber Action Toolkit that we are launching today will equip sole traders and small businesses to take their first steps toward cyber protection.
The UK’s minimum standard for cyber security, Cyber Essentials, is making it easier for organisations of all sizes, across all sectors to get basic foundational defences right.
And that comes with free cyber insurance for small businesses who opt in.
For senior leaders and board members, our recently launched Cyber Governance Training provides the clarity and confidence needed to govern cyber risk effectively.
Partnerships
And we are not doing that alone.
We’re working with partners across industry to strengthen our collective resilience.
For example, our Share and Defend service is working with Internet Service Providers across the UK, to block millions of attempted connections all the time to malicious websites by consumers.
Stopping attacks and fraud before they cause harm.
We’re working with our partners in the UK’s intelligence community including colleagues in the National Protective Security Agency.
We know that our adversaries are combining cyber means with physical methods in order to further their aims.
And we’ll hear more about that from Ken McCallum, the Director General of MI5, later this week when he speaks about the threats facing the UK.
And we’re working ever more closely with our international partners and friends.
Many of whom, I’m delighted to say, are here with us in the room today.
Sovereign UK action alone can only take us so far in closing the widening gap.
Together, we are building strong coalitions...to stand united against hostile activity.
Just last month, agencies from thirteen nations came together to warn that three technology companies based in China have conducted a malicious global cyber campaign targeting critical networks… on behalf of their host nation.
Conclusion
And so, my question to every leader of every organisation is simple.
What is your plan?
How will you continue when your IT is gone?
Because that plan must be written by you.
No one can do it for you.
And it is also only by asking that question, that you will truly understand the urgency of investing in cyber defences.
And we in the NCSC, are here to support and empower you.
If we all act now, we can create a UK that thrives in our new digital world.
With businesses and a society that can weather the digital storms that are inevitable and the confidence to meet the challenges head on.
Thank you.

NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.