UK faces surge in major cyber attacks, NCSC warns
John E. Kaye
- Published
- News

The UK’s cyber threat level has reached unprecedented intensity, with the National Cyber Security Centre reporting 204 “nationally significant” incidents in the past year — the equivalent of four major attacks every week
Britain is now facing an average of four “nationally significant” cyber incidents every week, according to new figures from the National Cyber Security Centre (NCSC).
In its latest annual review, the agency said it handled 204 major incidents in the 12 months to September 2025, more than double the 89 recorded the previous year, underscoring what it described as an “alarming” escalation in both scale and severity.
The NCSC defines “nationally significant” incidents as those with the potential to disrupt critical services, compromise sensitive data, or affect large sections of the public or economy. Officials said the trend reflected the increasing sophistication and persistence of threat actors targeting UK networks.
Dr Richard Horne, Chief Executive of the NCSC, said: “Cyber security is now a matter of business survival and national resilience. With over half the incidents handled by the NCSC deemed nationally significant, our collective exposure to serious impacts is growing at an alarming pace.”
Industry experts said the findings should prompt a step change in how organisations approach security.
Tim Hemsley, DFIR Operations Director at cyber firm Zensec, said: “The NCSC’s data underlines what we’re seeing across our client base — a steady escalation in both the frequency and impact of serious cyber incidents. Threat actors are adapting faster than many organisations’ defences. The key isn’t just to prevent attacks, but to build operational resilience so that when — not if — a breach occurs, the organisation can absorb the shock and continue operating.”
Zensec said the data showed that disruption is now a probability rather than a risk, urging firms to treat cyber resilience as a board-level issue. The company advised that governance, investment, and preparedness — including incident simulation — should form part of every organisation’s core strategy.
The NCSC’s findings come amid heightened concern over the security of public infrastructure and private-sector supply chains, with officials warning that both state-sponsored and criminal groups are targeting UK institutions more aggressively.
According to Zensec, “cyber resilience is now a business imperative” and must be embedded across every layer of corporate governance as Britain adapts to what the NCSC describes as an “unprecedented” threat environment.
READ MORE: ‘ISF warns of a ‘corporate model’ of cybercrime as criminals outpace business defences‘. Cybercrime has matured into an industry that mirrors legitimate enterprise, complete with supply chains and customer service. The industrialisation of hacking, amplified by artificial intelligence, demands a total rethink of how organisations manage people, technology and risk, warns Steve Durbin of the Information Security Forum.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
TOP STORIES
-
Scotland’s £19bn food and drink industry faces ‘cliff edge’ as costs squeeze businesses -
Lidl owner plans €5.6bn data centre as Germany pushes digital independence -
AI could make it easier for citizens to have their say, study finds -
Hidden workplace chemical risks come under spotlight as experts turn to skin exposure -
Cyber attack hits Manchester, Stansted and East Midlands airports as customer data stolen -
New global map reveals 800 businesses trying to cut plastic waste -
LEGO sales soar 22% amid World Cup, F1 and Star Wars push -
Japan switches on its first full-stack neutral-atom quantum computer -
Britons flock to Greece as tourist numbers jump 15% -
Sudan’s children get $22m education lifeline ahead of Geneva funding conference -
Robot beats Usain Bolt’s 100m record at Beijing games -
Royal Mail posts another target miss -
New AI master’s aims to turn non-tech graduates into business leaders -
New direct flights from Paris and Athens open easier route to Alaska -
Robots that work, play and even tackle the laundry go on show in Beijing -
Six young sea eagles released on Exmoor after 200-year absence -
More than half of US travellers now use AI to plan holidays -
Could wild swimming and camping help reverse Britain’s outdoor play decline? -
Israeli genomics firm opens easier route to AI system for NHS labs -
European investors can now trade thousands of US stocks through Kraken -
Healthcare AI plans hampered by spreadsheets and legacy systems -
Women form tighter workplace friendships than men, study finds -
Children now nearly 11 before being allowed to play outside alone -
Ex-Lenovo executive Sabine Hammer to lead Infinigate’s DACH business -
Ferrari’s first electric car sells for record US$40m




























