On 3 December 2024, Richard Horne, the newly appointed head of the UK National Cyber Security Centre (NCSC), warned that organizations were underestimating cyber risks from hostile states and criminal groups. His message was that public services, critical infrastructure, supply chains and businesses need stronger resilience—not that every incident was a state attack.
What did the NCSC chief warn about?
Horne’s warning accompanied the NCSC Annual Review. He said: “There is no room for complacency about the severity of state-led threats or the volume of the threat posed by cyber criminals.” He also called for better defence and resilience across “critical infrastructure, supply chains, the public sector, and our wider economy.” (IT Pro, 3 December 2024)
The point was broader than government networks: organizations across public and private sectors should treat cyber risk as an operational and economic concern, not just an IT problem. The warning was issued in 2024; the figures below describe the NCSC reporting period from 1 September 2023 to 31 August 2024, not current 2026 totals.
What do the incident figures show—and what do they not show?
Contemporary reporting of the NCSC review said the centre supported 430 incidents during the 2023–24 reporting period, up from 371 in the preceding 12 months. Twelve incidents were described as at the “top end of the scale,” compared with four in the prior year. The NCSC was also reported to have received 317 reports of ransomware activity, 13 of which were described as nationally significant. (The Guardian, 3 December 2024)
#1 Best Overall
These are different measures: the 430 figure covers incidents requiring NCSC support, while the ransomware figure counts reports of ransomware activity. Neither should be read as a count of hostile-state attacks. The Guardian noted that the review did not disclose how many incidents were carried out by states versus criminal gangs, so the figures do not establish the actor or motive behind each case.
How do state-linked operations differ from criminal activity?
The warning described a threat landscape involving both state-linked cyber operations and financially motivated crime. They can overlap in the techniques they use, but their objectives and the limits of attribution matter when interpreting the risk.
| Threat category | Reported objectives and examples | What the figures establish |
|---|---|---|
| State-linked activity | Reporting named Russia, China, Iran and North Korea. Examples included Russian destructive malware and espionage, Chinese state-affiliated activity including Volt Typhoon and targeting of UK democratic institutions, developing Iranian cyber capabilities, and North Korean activity linked to revenue generation and intelligence collection. (IT Pro, 3 December 2024; The Guardian, 3 December 2024) | The reported examples describe the threat landscape; they do not prove that any particular incident in the annual count was state-directed. |
| Criminal activity, including ransomware | Ransomware can be financially motivated while still causing disruption with public consequences. Reporting cited attacks on NHS supplier Synnovis and the British Library as examples of the harm cyber incidents can cause. (The Guardian, 3 December 2024) | The 317 ransomware reports were not a count of state attacks, and the cited review did not disclose a state-versus-criminal breakdown for all incidents. |
The distinction does not make either category harmless. State-linked operations can pursue espionage and information theft, while the wider threat also includes possible disruption to essential services. Horne said of the consequences: “What these and other incidents show is how entwined technology is with our lives and that cyber-attacks have human costs.” (The Guardian, 3 December 2024)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should organizations do to improve resilience?
Parliamentary evidence on government cyber resilience later discussed the shift from espionage and information theft toward the possibility of disruption to essential services. Officials described resilience as a combination of controls, the ability to detect and respond to attacks, and plans to recover; they also acknowledged that government resilience was not yet sufficient. (UK Parliament, Public Accounts Committee oral evidence, “Cyber resilience of government,” HC 676)
Rank #3
For an organization, that translates into a practical cycle rather than reliance on a single security measure:
- Apply layered controls. Use the NCSC’s guidance to strengthen defences across systems and the services and suppliers they depend on.
- Prepare to detect and respond. Make sure the organization can identify suspicious activity and act when an incident occurs, rather than assuming prevention alone will be enough.
- Plan for recovery. Decide how essential operations can be restored after an attack and maintain plans that can be used under pressure.
The parliamentary evidence supports these as resilience measures, not a guarantee against attack. For current practical recommendations, consult the NCSC guidance linked from IT Pro’s report.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

