Speaking in June 2026, the chief executive of the National Cyber Security Centre, Dr Richard Horne, said that hostile state actors were linked to around 75% of the cyber attacks affecting the UK’s critical national infrastructure. The NCSC handled more than 200 incidents in the year to May 2026, and named Russia, China and Iran as the principal state actors targeting UK essential services.
Two things in the speech are worth dwelling on.
The first is the framing. Dr Horne described cyber conflict as being less like a series of discrete engagements and more like a game played continuously across a wide field – positioning, probing, establishing access that may not be used for years. His warning was blunt: the vulnerabilities organisations tolerate today are the ones that will be exploited in a future conflict.
The second is the diagnosis. The NCSC’s position is that too many significant incidents remain possible because basic controls are not in place. Not because attackers are unusually sophisticated – because patching is behind, privileged access has accumulated, segmentation is theoretical, and recovery has never been properly tested. The NCSC also expects AI-enabled attack capability to be meaningfully weaponised by around 2028, which shortens the window for getting the basics right.
Our take
It is tempting for organisations outside the obvious critical sectors to read this as somebody else’s problem. We would resist that. State-aligned activity rarely arrives through the front door of the intended target; it arrives through a supplier, a managed service, or a shared platform. If you provide services into energy, health, water, transport or digital infrastructure, you are part of that field of play whether or not you think of yourself that way.
The NCSC’s three asks – understand your exposure, build defences on proven fundamentals, and be able to keep operating and recover quickly – are a reasonable agenda for any board. The third is the one most often underfunded.