Britain’s cyber defense agency says hostile states were behind roughly three-quarters of the cyber incidents it handled affecting critical infrastructure over the past year. NCSC chief Richard Horne said the agency responded to more than 200 incidents affecting critical national infrastructure and its supporting ecosystem in the year to May 2026, and warned adversaries are 'prepositioning' inside infrastructure for possible later disruption, citing tactics similar to the China-linked Volt Typhoon campaign.
Why it matters: This is a high-signal warning that government, utilities, telecom, transport and other essential-service operators may already be dealing with state-backed intrusions designed for future disruption. UK critical-infrastructure defenders should review monitoring, segmentation, access controls and incident-response readiness now rather than treating this as a distant risk.
2026.06.17
100% relevant
This article establishes a distinct UK-focused story by adding new official incident numbers and a direct public warning from the NCSC that nation-state actors are already embedded across British critical infrastructure.
← Back to all stories