Infrastructure Security
Hostile state actors account for 75% of cyber attacks on UK critical infrastructure – In-depth interpretation of the NCSC annual report
A recent report by the UK National Cyber Security Centre (NCSC) shows that 75% of cyber attacks against UK critical infrastructure over the past year were linked to hostile state actors. In his annual speech, NCSC Chief Executive Richard Horne warned that cyber security should be seen as a continuous contest rather than a static risk, and emphasized that AI will accelerate the exploitation of legacy vulnerabilities. This article provides an in-depth analysis of the incident background, attack methods, corporate impact, and defense recommendations.
Event Overview
On June 17, 2026, Richard Horne, CEO of the UK's National Cyber Security Centre (NCSC), disclosed at the Royal United Services Institute (RUSI) Annual Security Lecture that over the past year (June 2025 to May 2026), the NCSC handled 200 cyber incidents affecting Critical National Infrastructure (CNI). Approximately 75% of these originated from or were linked to hostile state actors such as Russia, China, and Iran. While this figure represents a slight decrease from the 204 "nationally significant" incidents reported in the previous annual report, the dominance of hostile state actors has become even more pronounced.
- Horne categorized cyber threats into three "contested spaces":
- Far Space: The adversaries' own territory, where the UK applies pressure through intelligence gathering, sanctions, law enforcement, and offensive cyber operations.
- Middle Space: The digital infrastructure shared by legitimate and malicious actors, where attackers leverage cloud services and open-source supply chains to spread malicious code and achieve scaled impact.
- Near Space: The internal systems of target organizations. Horne urged boards to prioritize fundamental capabilities: understanding the attack surface, defense, and response.
Technical and Risk Analysis
Attack Vectors and Exploitation Chains Horne noted that state actors widely adopt prepositioning strategies. For example, the China-linked group Volt Typhoon has established persistent access points within US digital infrastructure. These pre-positioned "hidden footholds" can be rapidly activated during a conflict to cause widespread disruption. Attackers are also heavily exploiting cloud services, open-source components, and third-party supply chains to propagate malicious code, leveraging the "middle space" for amplification effects.
AI was characterized as an "accelerant." The NCSC assesses that advanced AI models can now effectively identify long-standing vulnerabilities in code and that it is "highly likely" that by 2028, attackers will use AI to automate exploitation of known legacy vulnerabilities in UK critical infrastructure. Horne warned: "Many vulnerabilities tolerated by organizations today will be exploited in a conflict tomorrow."
Affected Assets and Industries Andrew Lintell, EMEA General Manager at Claroty, noted that OT-intensive industries (manufacturing, water utilities, power generation) account for over 40% of observed attacks in the CNI sector, as their compromise can cause the greatest disruption and panic. James Neilson, Global Senior Vice President at OPSWAT, emphasized that critical infrastructure environments contain a mix of IT and OT assets, but very few personnel possess deep expertise in both, creating a knowledge gap in threat assessment and defense development.
Enterprise Impact Analysis
Operational and Financial Risks Attacks by state actors typically aim for long-term persistence, data theft, and destructive disruption, potentially leading to core industrial process interruptions, production halts, and data loss. Recovery costs are often extremely high, including incident response, system rebuilding, regulatory fines, and reputational damage.### Compliance and Brand Risk The UK has strengthened CNI regulation through the Cyber Security and Resilience Bill. Organizations that fail to demonstrate appropriate cybersecurity measures may face severe penalties. Additionally, attacks involving state actors are often accompanied by espionage activities and geopolitical connections, triggering brand reputation crises.
Data Risk Attackers may steal industrial designs, operational data, customer information, and more, even exacerbating negative impacts through ransomware. Even without ransomware, the data breach itself constitutes a national security risk.
Industry Trend Observations
Cybersecurity is a "Race" not a "Risk" Horne strongly criticizes the traditional mindset of treating cybersecurity as an "item to be managed" on a risk register, advocating for its reframing as a continuous "capability and performance race". Graeme Stewart, Head of Public Sector at Check Point, echoed that the NCSC CEO is absolutely correct, and organizations that merely treat cybersecurity as a compliance checkbox will face dangerous exposure.
AI-driven Attacks Will Soon Become the Norm The NCSC predicts that AI will be used to exploit legacy vulnerabilities at scale within the next two years. This means organizations must accelerate their patching processes and deploy AI-driven defense tools. At the same time, cloud and AI-as-a-service may be leveraged by adversaries, increasing supply chain complexity.
Legacy Systems Become a Critical Weakness Many critical infrastructures still run unsupported legacy systems, which will become primary targets in conflicts. Horne emphasized: "In cyberspace, we are, to some extent, already fighting tomorrow's battles."
Defense and Response Recommendations
Enterprise Level - Identity and Access Management: Implement multi-factor authentication (MFA) and the principle of least privilege to prevent lateral movement after credential leakage. - Zero Trust Architecture: Verify all internal and external traffic; do not trust any default "secure" zones. - Vulnerability Management: Prioritize patching known exploited vulnerabilities, especially focusing on legacy systems in OT/ICS.
Technical Level - Deploy EDR/XDR: Achieve real-time monitoring and behavioral analysis of endpoints and networks. - Threat Intelligence Integration: Subscribe to official and commercial intelligence sources such as NCSC and CISA to get early warnings of targeted attacks. - OT Security Isolation: Implement strong logical or physical isolation between IT and OT networks, and deploy dedicated intrusion detection systems.
Management Level - Incident Response Drills: Regularly simulate attack scenarios by state actors to test cross-departmental coordination and recovery processes. - Supply Chain Risk Assessment: Conduct security audits of key suppliers to ensure the reliability of upstream code and cloud services. - Board Security Awareness: Ensure management understands the "continuous race" concept and allocate sufficient resources to the security team.
SecurityPost InsightThe NCSC's warning is by no means an exaggeration. The 75% attribution rate to state actors marks the complete mapping of geopolitical tensions into cyberspace, and critical infrastructure is shifting from an "indirect target" to a "frontline battlefield." Horne's "three-dimensional" framework—deterrence in the far space, structural hardening in the middle space, and foundational defense in the near space—provides organizations with a clear strategic stratification. However, most enterprises remain trapped in compliance-oriented "risk checklist" thinking, overlooking that adversaries are pre-positioning attack capabilities in the middle space (cloud, supply chain, AI services).
The most severe challenge lies in the time window: the NCSC predicts that AI will be used for large-scale vulnerability exploitation by 2028, yet many organizations have not begun to phase out legacy systems that have been running for more than two decades. For those critical infrastructure entities relying on mixed OT and IT environments, the urgent priority is to bridge cross-domain knowledge gaps and build a resilient system capable of responding to both physical and digital threats.
This race has no finish line, but organizations that begin investing in continuous capacity building—rather than one-time compliance projects—will take the initiative in this prolonged struggle.
--- *Source: Infosecurity Magazine report 'Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns'*
Evidence route · securitypost
securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.