general
75% of UK Infrastructure Attacks Now Linked to Nation-States
2026-06-17

Britain's cyber chief used his annual lecture at RUSI this week to land a fairly blunt message. Of the 200-plus incidents the National Cyber Security Centre handled against critical national infrastructure and its suppliers in the year to May, around 75% are believed to be the work of nation-state actors. Not criminals chasing a ransom payment. Governments.
Richard Horne, the NCSC's chief executive, said hostile states are quietly "prepositioning" inside the systems that keep the country running, establishing footholds that could be triggered in a future conflict. He pointed to Volt Typhoon, the Chinese state-linked campaign uncovered inside US infrastructure, as the clearest published example of what that looks like in practice. "Kinetic targeting in any conflict tomorrow will be based on intelligence gathered today," he said.
From risk to contest
What made the speech unusual was the shift in language. For the past decade, British cyber guidance has been built around the vocabulary of risk: assess it, quantify it, set an appetite, manage it. Horne wants that reframed as a contest, with an adversary on the other side of the table who is actively trying to win.
That is a real departure. The NCSC's own flagship Cyber Assessment Framework still opens with "managing security risk", so the boss publicly nudging the agency away from its own house style is worth noting. It also brings the UK into line with how NATO and US Cyber Command have been describing cyberspace for a few years now.
Stop benchmarking against competitors
Horne also took aim at a familiar boardroom habit. The most common question from non-executive directors, he suggested, is some variation of "how do we compare to our peers?" His answer: the only benchmark worth anything is how you compare to the people actually trying to break in.
Peers are reassuring because everyone in the sector tends to be in a similar place. Attackers do not care where the average sits. They care where the gap is.
The 2028 problem
The NCSC judges it "highly likely" that by 2028, AI tools will be used to identify and exploit known weaknesses in ageing operational technology. Which is a polite way of saying the unpatched kit sitting in the back of the server room, the stuff nobody quite wants to touch, is going to get a lot easier for attackers to find at scale.
For operators of essential services, that horizon is not far away. Most OT refresh cycles are measured in decades, not years.
What's coming next
The speech lands as the Cyber Security and Resilience Bill makes its way through Parliament, with a new National Cyber Action Plan expected in early July. For anyone running essential services, or supplying someone who does, the direction of travel is fairly clear:
- Regulation is getting teeth. Expect duties that bite further down the supply chain than current rules do.
- Auditor and client questions are about to get sharper, particularly on segmentation, logging and recovery.
- The threat model boards are being asked to plan against is no longer the opportunistic criminal. It is a patient government with time, money and a long memory.
None of which makes for a comfortable quarterly board pack. But it does mean the conversation about cyber spending is finally being held in the right room, with the right framing, by people who are no longer pretending this is just an IT problem.