Cyber risk facing UK being ‘widely underestimated’, security chief warns

3 December 2024, 00:04

Hands on a keyboard with code on a computer screen
Most people happy to share health data to develop artificial intelligence. Picture: PA

National Cyber Security Centre chief Richard Horne will warn of the dangers posed by countries including Russia and China as well as online criminals.

The UK needs to wake up to Russia’s online “aggression and recklessness” and the risks posed by “highly sophisticated” Chinese hackers, the cyber security chief will warn.

In his first major speech, Richard Horne, head of GCHQ’s National Cyber Security Centre (NCSC), will highlight the “widening gap” between the threats facing the UK – from both state-backed hackers and online criminals – and the defences in place to protect businesses and public services.

The NCSC’s annual report shows a threefold increase in the most serious cyber incidents affecting the UK in 2023-24, but Mr Horne will warn the danger is still being “widely underestimated” by both public and private sector organisations.

Mr Horne, who took over as the cyber security agency’s chief in October, will say on Tuesday: “What has struck me more forcefully than anything else since taking the helm at the NCSC is the clearly widening gap between the exposure and threat we face, and the defences that are in place to protect us.

“And what is equally clear to me is that we all need to increase the pace we are working at to keep ahead of our adversaries.”

Mr Horne will warn of “the aggression and recklessness of cyber activity we see coming from Russia”, both from organisations linked to Vladimir Putin’s government and groups operating without direct Kremlin control.

He will say: “We can see how cyber attacks are increasingly important to Russian actors, along with sabotage threats to physical security, which the director general of MI5 spoke about recently.

“All the while, China remains a highly sophisticated cyber actor, with increasing ambition to project its influence beyond its borders.

“And yet, despite all this, we believe the severity of the risk facing the UK is being widely underestimated.”

Speaking at the NCSC’s headquarters in London, he will say: “There is no room for complacency about the severity of state-led threats or the volume of the threat posed by cyber criminals.

“The defence and resilience of critical infrastructure, supply chains, the public sector and our wider economy must improve.”

The NCSC’s report described Russia as a “capable, motivated and irresponsible threat actor in cyberspace” and through its actions in Ukraine Mr Putin’s government is also inspiring “non-state threat actors” not officially linked to the Kremlin to carry out cyber attacks against critical national infrastructure.

Chinese hackers such as the Volt Typhoon group had targeted US infrastructure and “could be laying the groundwork for future disruptive and destructive cyber attacks” while in the UK Beijing-linked groups are believed to have targeted MPs’ emails and the Electoral Commission’s database.

The report also warns that Iran “is developing its cyber capabilities and is willing to target the UK to fulfil its disruptive and destructive objectives” while North Korean hackers were targeting cryptocurrency to raise revenue and attempting to steal defence data to improve Pyongyang’s internal security and military capabilities.

The NCSC also believes that UK firms are almost certainly being targeted by workers from North Korea “disguised as freelance third-country IT staff to generate revenue for the DPRK regime”.

The report highlights major incidents including the British Library hack in October 2023 and the Synnovis incident in June 2024, which saw a Russian gang carry out a ransomware attack which disrupted health services.

Mr Horne will say: “The attack against Synnovis showed us how dependent we are on technology for accessing our health services. And the attack against the British Library reminded us that we’re reliant on technology for our access to knowledge.

“What these and other incidents show is how entwined technology is with our lives and that cyber attacks have human costs.”

In all, 2023-24 saw the NCSC receive 1,957 reports of cyber attacks, 430 of which needed support from the centre’s incident management team, up from 371 the previous year.

Of these incidents, 89 were nationally significant, 12 of which were at the top end of the scale and more severe in nature, a threefold increase on last year.

The NCSC said: “The UK needs to wake up to the severity of the cyber threat.”

The report added: “The UK cannot underestimate the severity of state-led threats, or the volume of the threat posed by criminals.

“The resilience of critical infrastructure, supply chains and the public sector must improve. But so must our wider economy.”

The increasing availability of artificial intelligence (AI) can “increase the volume and heighten the impact of cyber attacks”, the report said.

Cabinet Office minister Pat McFadden said: “As this report shows, while AI presents huge opportunities, it is also transforming the cyber threat.

“Cyber criminals are adapting their business models to embrace this rapidly developing technology – using AI to increase the volume and impact of cyber attacks against citizens and businesses, at a huge cost.”

By Press Association

More Technology News

See more More Technology News

Exclusive
Ministers are looking at relaxing the Tory government's TikTok ban in a bid to woo younger voters online, LBC understands.

Ministers eye TikTok comeback to reach younger voters despite security concerns

Telegram Messenger stock

Telegram to work with internet watchdog on child sexual abuse material crackdown

The GCHQ building in Cheltenham (GCHQ)

‘Broader and deeper’ online risk to UK from criminals and state-backed hackers

Riot police at a demonstration outside a hotel in Rotherham (

Oversight Board to examine Facebook posts about summer riots

The Microsoft logo

Microsoft facing £1 billion legal claim from UK businesses

A rendering of a computer chip with a human brain image superimposed on it

Most people happy to share health data to develop artificial intelligence – poll

Ms Barkworth-Nanton, from Swindon was honoured for services to people affected by domestic abuse and homicide at Buckingham Palace on Thursday (Aaron Chown/PA)

Social media ban for children ‘brilliant idea’ for tackling abuse – charity boss

Baroness Cass sounded the note of caution as she made her maiden speech in the House of Lords (Yui Mok/PA)

Mobiles in schools could become like ‘smoking behind the bike shed’

A young girl looks at social media apps, including TikTok, Instagram, Snapchat and WhatsApp, on a smartphone.

Australian social media ban for under-16s a ‘retrograde step’, UK charity says

Australia will ban social media for under-16s.

Australia passes world-first law banning under-16s from social media

Pacific 24 rigid inflatable boat

‘Robot Rib’ drone boat tested by Royal Navy in UK waters for first time

A child using a laptop

Girls to learn AI skills as part of new Girlguiding activities

A young girl using a mobile phone in the dark

Women spend more time online than men, but worry more about online harms – Ofcom

A person using the Uber app on a smartphone

Uber launches teen accounts, giving parents option to track children’s journeys

A woman using her mobile phone

O2 launches AI-powered scam call detection tool

Google's homepage

Google needs ‘right conditions’ to build more AI infrastructure in UK