The NCSC Annual Review 2025 provides a useful snapshot of Britain’s national cyber capability. We examine what its programmes and priorities mean for businesses, skills, innovation and regional resilience.
Contents
- Contents
- The NCSC Annual Review 2025: What It Reveals About UK Cyber Resilience
- Key Takeaways
- Incident Severity Is Rising Faster Than Incident Volume
- Ransomware Is an Industrial Resilience Problem
- Legacy Technology Remains a Structural Source of Exposure
- Central Capability Cannot Produce Resilience on Its Own
- The NCSC’s Expanding Role Creates a Boundary Question
- Assurance Needs to Measure Outcomes Rather Than Participation
- AI Expands the NCSC’s Technical Authority into a New Domain
- The Regional Question Is About Reach, Not Replication
- Regional Evidence Should Flow Back into the National System
- The NCSC’s Success Should Increase the Ambition for the Wider System
The NCSC Annual Review 2025: What It Reveals About UK Cyber Resilience
The National Cyber Security Centre’s Annual Review 2025 presents two pictures of UK cyber security at the same time. The first is of a national technical authority with substantial operational capability: responding to serious incidents, disrupting malicious infrastructure, developing assurance mechanisms, improving guidance and working across government, industry and critical national infrastructure. The second is less comfortable. The severity of incidents is increasing, organisational resilience remains uneven, and the mechanisms through which national capability reaches businesses and supply chains are still incomplete.
The most striking evidence concerns incidents. During the year to 31 August 2025, the NCSC received 1,727 incident tips and provided direct support in 429 cases, almost unchanged from the 430 incidents handled the previous year. Yet the composition of that workload changed markedly. The number classified as nationally significant rose from 89 to 204, while highly significant incidents increased from 12 to 18. In other words, the volume of incidents requiring NCSC support was broadly stable while the proportion carrying serious national consequences increased substantially.
The originating analysis, The NCSC Annual Review 2025: Between Capability and Stasis, used that tension to ask a broader question about the UK’s cyber system. The issue is not whether the NCSC is technically capable; the evidence strongly suggests that it is. The more difficult question is whether the wider national model can translate that central capability into sufficiently consistent resilience across businesses, public services, infrastructure and supply chains.
For the West Midlands, this distinction matters. Manufacturing and engineering were among the sectors reporting ransomware activity to the NCSC during the year, while the regional economy depends extensively on interconnected suppliers, operational technology and digital services. The Annual Review should therefore be read not simply as a record of national activity, but as evidence about where regional cyber capability needs to connect more effectively with the national system.
Key Takeaways
- The number of incidents requiring NCSC support remained almost unchanged at 429, but nationally significant incidents increased from 89 to 204 and highly significant incidents from 12 to 18, indicating a material shift in severity rather than simply volume.
- The NCSC remains the UK’s technical authority for cyber security, but its growing portfolio raises an important question about where central government capability should end and commercial, sectoral and regional delivery should begin.
- Ransomware remains a cross-economy resilience problem, with manufacturing and engineering among the sectors reporting activity to the NCSC during 2024/25.
- National programmes can establish guidance, assurance and common services, but they cannot substitute for organisational capability to assess risk, prepare for incidents and manage technology dependencies.
- For the West Midlands, the strongest regional role is not to reproduce NCSC functions, but to improve the route from national expertise into industrial organisations, SMEs and supply chains.
Incident Severity Is Rising Faster Than Incident Volume
The headline incident statistics require careful interpretation.
The NCSC handled 429 incidents during 2024/25, compared with 430 in the previous reporting year. Viewed only through total volume, this could suggest relative stability. The severity data shows something quite different.
Of those 429 incidents, 204 were nationally significant, representing 48% of the cases handled by the NCSC. The previous year recorded 89 such incidents. Highly significant incidents increased from 12 to 18, following 4 in 2022/23 and only 1 in 2021/22.
The comparison matters because cyber risk cannot be understood simply by counting attacks or incidents. Consequence matters.
A large number of low-impact phishing attempts and a single ransomware incident capable of interrupting an important service are not economically or operationally equivalent. An organisation can therefore experience no dramatic increase in the frequency of hostile activity while facing a substantially more serious risk environment.
The NCSC itself cautions against treating its incident figures as a complete measurement of UK cyber activity. Reporting is not mandatory for many businesses, and the agency states explicitly that its data is therefore not a true reflection of the number of incidents affecting the country.
The appropriate conclusion is consequently narrower but more important. Among incidents serious enough to reach the NCSC and require its support, the proportion with national significance increased sharply.
That changes the resilience problem. Prevention remains important, but organisations also need to assume that some incidents will succeed and prepare for containment, continuity and recovery.
Ransomware Is an Industrial Resilience Problem
The sectors reporting ransomware activity to the NCSC during the year included academia, finance, engineering, retail, health and manufacturing. The agency’s conclusion was unambiguous: no sector and no organisation is exempt from the threat.
For the West Midlands, the presence of engineering and manufacturing in that list is particularly relevant.
Ransomware in an industrial environment is not simply an information-security problem. Disruption can affect production planning, logistics, engineering systems, supplier communications and the availability of operational processes. Where enterprise IT and production environments are interconnected, the consequences can extend beyond conventional office systems.
This makes recovery capability as important as protection.
An organisation may possess backups but still lack confidence about how long critical services would take to restore. It may have an incident-response plan that has never been exercised against a scenario involving unavailable production systems. It may understand its own infrastructure but lack equivalent visibility into managed service providers or technology suppliers on which recovery depends.
Those are resilience questions rather than purely defensive ones.
The NCSC’s incident experience reinforces the argument that industrial cyber security should be considered within business continuity and operational risk rather than delegated exclusively to IT security teams. A serious cyber incident can become a production incident, a customer-service incident and a supply-chain incident simultaneously.
For a manufacturing-intensive regional economy, that distinction should shape both business practice and the cyber services developed to support it.
Legacy Technology Remains a Structural Source of Exposure
The Annual Review also identifies exploitation of vulnerabilities in legacy systems as one factor contributing to severe incidents.
Legacy technology is sometimes discussed as though it were simply evidence of poor technology management. In many organisations, particularly those operating industrial or public-service environments, the problem is more complicated.
Systems can remain operational because replacement would require substantial capital expenditure, because specialist applications depend upon them or because equipment has a lifecycle measured in decades rather than the much shorter cycles familiar in enterprise IT. Some systems cannot be updated quickly without testing, vendor support or planned operational downtime.
The security problem therefore cannot always be solved by issuing a stronger instruction to patch.
Where vulnerabilities cannot be removed promptly, organisations need compensating controls: segmentation, restricted access, monitoring, controlled remote maintenance and clear plans for eventual replacement. They also need to understand which legacy systems create the greatest operational consequence.
This is another area in which national guidance needs translation into organisational context. The principle that unsupported and vulnerable technology creates risk is straightforward. Determining how to manage that risk without interrupting essential operations is an engineering and business decision.
The West Midlands’ industrial structure makes that capability particularly important. Cyber providers able to work credibly with production environments, rather than applying enterprise IT assumptions indiscriminately, address a genuine regional requirement.
Central Capability Cannot Produce Resilience on Its Own
The Annual Review demonstrates the breadth of NCSC activity. As part of GCHQ, the organisation remains the UK’s technical authority for cyber security, combining incident management, technical guidance, threat analysis, assurance and national programmes intended to improve resilience at scale.
That breadth is an institutional strength, but it also exposes the limits of central delivery.
The NCSC cannot conduct the risk assessment of every UK business, design every recovery plan, inspect every industrial network or determine which supplier is operationally critical to each organisation. Those decisions depend upon information and capability held locally within businesses, sectors and supply chains.
National cyber capability therefore operates through leverage.
Guidance provides organisations with methods they can implement. Assurance schemes create common ways of demonstrating controls. Active Cyber Defence services can address certain classes of threat at scale. Incident support concentrates specialist national capability where consequences justify intervention.
The model succeeds when those mechanisms improve what organisations themselves are capable of doing.
This is why the distinction between national capability and national resilience matters. A country can possess an exceptionally capable national cyber authority while resilience remains uneven across the organisations that constitute its economy.
The NCSC’s own incident figures provide evidence of the consequences when serious compromise reaches that national layer. The more strategic question is what proportion of risk can be managed effectively before escalation becomes necessary.
The NCSC’s Expanding Role Creates a Boundary Question
The originating analysis raised a deliberately challenging question about institutional scope: what should the NCSC itself do, and what should it enable others to do?
That question becomes more important as the UK’s cyber system matures.
Some functions clearly benefit from central authority. National threat intelligence, authoritative technical guidance, coordination of nationally significant incidents and capabilities derived from the NCSC’s position within GCHQ cannot simply be reproduced through the commercial market or regional organisations.
Other activities operate closer to markets. Security tools, organisational assessments, implementation support, training and managed services are also provided commercially.
The boundary should not be determined through an assumption that government provision is inherently better or worse. It should be based on comparative advantage and market failure.
Where the NCSC possesses information, authority or national-scale capability unavailable elsewhere, central delivery can create substantial public value. Where a healthy commercial market can provide implementation services, the stronger national role may be to establish standards, provide evidence and create confidence rather than become the default provider.
This distinction matters economically because the UK simultaneously wants stronger national resilience and a growing cyber industry. Public provision designed to address gaps should therefore avoid unnecessarily suppressing the markets through which private capability develops.
For regional cyber clusters, the same discipline applies. The objective should be to connect businesses with appropriate capability, not to reproduce services already delivered effectively by national institutions or commercial providers.
Assurance Needs to Measure Outcomes Rather Than Participation
The Annual Review also illustrates a wider problem with national cyber programmes: activity is easier to measure than resilience.
Registrations, certifications, programme participants, guidance downloads and service users can all be counted. These measures are useful because they indicate reach. They do not necessarily establish whether the organisations involved are materially more resilient.
Cyber Essentials provides a useful example.
The scheme establishes a recognised baseline around five technical control areas and has become increasingly important within procurement and supply-chain assurance. Certification can demonstrate that an organisation has implemented those controls at a particular point in time.
The more demanding policy question is whether adoption is occurring where it creates the greatest reduction in systemic risk.
A thousand certifications distributed randomly across the economy have a different resilience effect from a thousand certifications concentrated among suppliers that support critical services or high-consequence industrial systems. Raw volume does not reveal topology.
This suggests a progression in how assurance should be evaluated. National programmes need measures of reach, but increasingly they also need evidence about where adoption occurs, what dependencies it protects and whether organisations progress beyond baseline controls where their risk requires it.
For the West Midlands, this is particularly relevant to industrial supply chains. The objective should not be certification for its own sake. It should be proportionate assurance across relationships where supplier compromise could materially affect customers, production or strategically important activity.
AI Expands the NCSC’s Technical Authority into a New Domain
Artificial intelligence is another area in which the NCSC’s role is evolving.
AI creates two distinct cyber problems. Attackers can use it to improve elements of reconnaissance, social engineering, vulnerability research and malicious automation, while organisations are simultaneously embedding AI systems into business processes that themselves require security.
The second problem is strategically important because it creates new assets and dependencies.
Models, training data, system prompts, APIs, AI agents and the infrastructure supporting them can become targets for manipulation or compromise. Organisations therefore need to think about AI security as part of system design rather than treating it exclusively as an ethical or governance issue.
The NCSC’s work on secure AI reflects its role as technical authority, but the implementation challenge remains distributed. Guidance can establish principles; individual organisations still need to determine how those principles apply to their systems, suppliers and risk.
This follows the same pattern visible elsewhere in the Annual Review. National expertise is developing rapidly, while organisational adoption remains the point at which strategic intent either becomes operational capability or stalls.
For the West Midlands, AI security should therefore be connected to the region’s wider technology-adoption agenda. Manufacturers, professional-services organisations, public bodies and technology companies adopting AI need security expertise at the point of implementation, not only national guidance explaining why the issue matters.
The Regional Question Is About Reach, Not Replication
The NCSC is a national institution, but the organisations whose resilience it seeks to improve are distributed throughout the UK.
That creates a persistent delivery problem.
Businesses encounter cyber risk through their own technology, employees, customers and suppliers. Their requirements vary according to sector, size and operational context. National guidance necessarily abstracts from some of those differences so that it can remain authoritative and widely applicable.
Regional capability can help close that distance.
For the West Midlands, this could mean connecting manufacturers with appropriate OT specialists, helping SMEs understand assurance requirements imposed by larger customers, linking cyber providers with industrial demand, and ensuring that regional experience informs national policy discussions.
None of those functions requires a regional NCSC.
Indeed, attempting to reproduce national technical authority locally would create unnecessary duplication and potentially inconsistent advice. The regional role is better understood as an interface between national capability and organisational implementation.
This also provides a more useful way to assess regional cyber organisations. Their contribution should not be measured principally by how many activities they undertake, but by whether they make national resources easier to use and regional capability easier to access.
A business that moves from generic awareness to an exercised incident plan represents progress. A manufacturer that identifies a critical digital dependency and mitigates it represents progress. A supplier that reaches the assurance level required to retain a major customer represents progress.
Those outcomes are more meaningful than institutional visibility alone.
Regional Evidence Should Flow Back into the National System
The relationship should also work in the opposite direction.
National organisations possess visibility that individual regions cannot replicate, particularly concerning threats and incidents affecting multiple sectors. Regional ecosystems possess different information: the practical difficulties organisations encounter when applying national guidance, shortages of particular specialist skills, recurring procurement barriers and sector-specific patterns of demand.
That evidence has policy value.
If manufacturers repeatedly struggle to obtain specialist OT expertise, the issue may indicate a capability shortage rather than an awareness problem. If SMEs repeatedly encounter incompatible supplier-assurance requirements, the constraint may lie in procurement architecture. If organisations understand incident-response guidance but lack access to realistic exercises, implementation infrastructure may be the missing component.
Regional organisations are well placed to identify such patterns because they operate close enough to businesses to see where abstract requirements encounter practical constraints.
A mature national cyber system should therefore contain feedback loops through which regional evidence can influence programme design and policy.
This is more substantive than regional representation. The purpose is not simply to ensure that different parts of the country are present in national discussions, but to improve the evidence on which national interventions are based.
The NCSC’s Success Should Increase the Ambition for the Wider System
The most important conclusion from the Annual Review is not that the NCSC is failing. Its operational record demonstrates substantial technical capability, and the sharp rise in serious incidents makes that capability increasingly important.
The more difficult conclusion is that national technical excellence is not sufficient evidence of national resilience.
The UK cyber system increasingly needs to be judged by what happens outside its strongest institutions: whether businesses understand their critical dependencies, whether supply chains can demonstrate appropriate assurance, whether organisations can recover from ransomware, whether industrial systems are protected according to their operational consequences and whether emerging technologies are adopted securely.
The NCSC can influence all of those outcomes. It cannot produce them alone.
For the West Midlands, this provides a clearer definition of regional responsibility. The region does not need to recreate national threat intelligence, duplicate NCSC guidance or establish parallel technical authorities. It needs the connective infrastructure through which national expertise becomes usable within an economy characterised by advanced manufacturing, engineering, technology companies and extensive SME supply chains.
That requires capable providers, informed customers, realistic exercises, stronger assurance pathways and institutions able to connect national policy with sector-specific implementation.
The Annual Review’s incident statistics make the urgency difficult to ignore. A broadly stable number of NCSC-supported incidents accompanied by a rise from 89 to 204 nationally significant cases is not evidence of a threat environment standing still. It suggests that consequence is becoming more concentrated even where headline volume appears stable.
The appropriate response is not to expect the national technical authority to absorb an ever-larger share of the problem. It is to increase the capability of the wider system around it.
For the West Midlands, that means treating the NCSC’s national capability as an asset to be connected with regional execution. The measure of success will not be how closely regional institutions resemble the NCSC, but whether fewer organisations remain dependent on national intervention because stronger resilience has been built into businesses, industrial systems and supply chains before serious incidents occur.