Key Takeaways
- The UK’s National Cyber Security Centre (NCSC) warns that the most serious cyber threats now come from hostile nation‑states—primarily Russia, Iran, and China—rather than solely from criminal ransomware gangs.
- NCSC handles about four “nationally significant” cyber incidents each week; while ransomware remains common, state‑sponsored attacks pose the greatest risk to national security and critical infrastructure.
- British intelligence leaders describe the current era as the most seismic geopolitical shift in modern history, with cyberspace firmly part of the global contest between peace and war.
- China’s cyber operations exhibit “eye‑watering” sophistication; Iran uses cyber tools to repress British individuals deemed threats to the regime; Russia repurposes tactics honed in Ukraine for broader hybrid attacks on the UK and Europe.
- Recent incidents in Sweden, Poland, Denmark, and Norway—including attacks on heating plants, power facilities, water utilities, and dams—illustrate a pattern of Russian‑linked hybrid activity that has generated over 155 disruption events tracked since the 2022 invasion of Ukraine.
- Additional European threats involve German air‑traffic control, attempts to hijack Signal and WhatsApp accounts of officials and journalists, and exploitation of router vulnerabilities to steal sensitive data.
- UK businesses must prepare for large‑scale cyberattacks that cannot be resolved by paying ransoms; understanding the full extent of risk and strengthening defenses before a crisis hits is essential.
Introduction and Warning from NCSC Chief
Richard Horne, the head of the United Kingdom’s National Cyber Security Centre (NCSC)—a component of GCHQ—will tell delegates at the CyberUK conference in Glasgow that the country is living through “the most seismic geopolitical shift in modern history.” He will argue that British businesses can no longer view cyber threats as isolated criminal nuisances; instead, they must anticipate the possibility of being targeted “at scale” should the UK become embroiled in an international conflict. Horne’s preview, shared with reporters, stresses that the NCSC’s daily workload now includes a steady stream of sophisticated, state‑backed incursions that demand urgent attention from both government and private‑sector leaders.
Volume and Nature of NCSC‑Handled Incidents
According to Horne, the NCSC currently manages roughly four “nationally significant” cyber incidents each week. While high‑volume, low‑impact criminal activity—especially ransomware campaigns—remains the most frequently encountered problem, the most serious danger emanates from cyberattacks planned or sponsored by foreign states. This distinction is crucial: ransomware victims often have the (controversial) option to pay for decryption keys, whereas state‑sponsored attacks are typically designed to disrupt, destroy, or exfiltrate data without offering a monetary escape route, leaving organizations with far fewer recovery options.
MI6 Perspective and the Contested Cyberspace
Echoing Horne’s warning, Blaise Metreweli, the chief of Britain’s Secret Intelligence Service (MI6), recently described the global environment as more dangerous and contested than it has been for decades, asserting that the UK operates in a “space between peace and war.” Horne will reinforce this view by stating unequivocally, “Let’s be clear, cyberspace is part of that contest.” In other words, the digital domain is no longer a neutral backdrop but an active theatre where states project power, gather intelligence, and seek to undermine adversaries without crossing traditional kinetic thresholds.
Specific Threats from China, Iran, and Russia
Horne will detail the distinct capabilities of the three nations identified as primary concerns. He will characterize China’s intelligence and military cyber units as displaying an “eye‑watering level of sophistication” in their operations, suggesting a capacity for prolonged, stealthy espionage and potential disruption of critical systems. Regarding Iran, he will assert that Tehran is “almost certainly using cyber activity to support the repression of British individuals on our streets who are seen as a threat to the regime,” indicating a blend of domestic surveillance and intimidation exercised through digital means. On Russia, Horne will point out that Moscow is repurposing tactics honed during its war in Ukraine—such as coordinated disinformation, sabotage of infrastructure, and hybrid influence campaigns—and is “moving them beyond the battlefield” to target the UK and wider Europe.
Nordic Examples of Russian‑Linked Infrastructure Attacks
Recent disclosures from Scandinavian authorities underscore the reality of Russian‑linked cyber aggression. Swedish officials announced that a pro‑Russian group with ties to Russia’s security and intelligence services was responsible for a cyberattack on a heating plant last year. Similar patterns emerged in Poland, where December 2024 saw coordinated hits on combined heat and power plants serving roughly half a million customers, as well as on wind and solar farms; Polish investigators later concluded the perpetrators were “directly linked to the Russian services.” Norwegian officials warned that an April 2025 intrusion affecting water flows from a dam was traced to Russia, while Danish authorities reported a 2024 attack on a water utility that left some households without water. These four cases are part of a larger tally: Western officials have logged more than 155 incidents of disruption—including arson, sabotage, and espionage—linked to Russia or its proxies since the full‑scale invasion of Ukraine began in February 2022.
Additional European Incidents Attributed to Russia
Beyond the Nordic examples, European investigators have connected a range of other malign activities to Russian state actors. These include an attempted intrusion into German air‑traffic control systems, repeated efforts to gain unauthorized access to Signal and WhatsApp accounts belonging to government officials, journalists, and activists, and campaigns by hackers tied to Russian military intelligence that exploit vulnerabilities in widely used internet routers to siphon sensitive data. Collectively, these episodes demonstrate a broad, multi‑vector strategy aimed at eroding confidence in essential services, compromising communications, and harvesting intelligence that could be leveraged in future confrontations.
Implications for UK Businesses and the Need for Proactive Defense
Horne’s message to the UK’s corporate sector is clear: organizations must prepare for the prospect of large‑scale cyberattacks that cannot be resolved by paying a ransom. Unlike ransomware incidents—where payment may restore access to encrypted data—state‑sponsored operations often aim for persistent disruption, data theft, or physical damage, leaving firms with limited remedial options. Consequently, every organization needs to grasp the “full extent” of the risk it faces, invest in robust cyber‑hygiene, adopt incident‑response plans that assume‑the‑worst, and continuously test defenses against realistic adversary scenarios. Learning from how cyber operations have been employed in actual conflict zones—such as Ukraine—can inform resilience‑building measures, from network segmentation and supply‑chain security to employee awareness and threat‑intelligence sharing.
Conclusion: A Call to Vigilance at CyberUK and Beyond
Speaking at the CyberUK conference in Glasgow, Horne will wrap up his address by urging both public and private entities to treat cybersecurity not as an IT afterthought but as a core component of national security strategy. He will echo the sentiment that the UK’s current geopolitical climate demands constant vigilance, cross‑sector collaboration, and a willingness to invest now rather than regret later. By heeding these warnings, British businesses can better shield themselves against the evolving tide of nation‑state cyber threats and help ensure that the UK remains resilient in an era where the boundary between peace and war is increasingly defined in the digital realm.

