Between September 2024 and August 2025, the NCSC dealt with 429 cyber incidents. 204 NCSC threats were classed as nationally significant, which is more than double the 89 recorded the year before. Attacks on Marks & Spencer, the Co-op and Harrods earlier this year proved what happens when things go wrong in the real world, with empty shelves and stolen customer data splashed across every front page in the country.
- Nationally significant cyber incidents doubled recently, driven by rising AI-powered threats.
- Cybercriminals now use large language models to create highly convincing spear-phishing emails.
- Ransomware remains the top cyber threat across all sectors, severely impacting smaller businesses with fewer defences.
- Software vulnerabilities in third-party suppliers regularly expose dependent businesses to cyberattacks.
- Businesses must quickly patch software, limit user access, and test recovery plans to stay protected.
Since then, the warnings have only ramped up. In June 2026, the Five Eyes cybersecurity agencies put out a joint statement telling business leaders to treat AI-driven cyber risk as something that needs attention now. So what’s actually changed, and what should smaller businesses be doing about it?
AI Is Making Phishing Harder To Spot
Phishing emails used to give themselves away. Bad grammar, dodgy formatting, a sender address that looked slightly off. You could train staff to spot them in an afternoon. That era is over. The NCSC’s 2025 Annual Review confirmed that threat actors now use large language models to run fully automated spear-phishing campaigns, and these aren’t your typical spam blasts sent to thousands of inboxes at once. They’re targeted messages written for specific people in specific roles, and they read like something a real colleague might send.
ALSO READ: What Makes a Successful Startup? 10 Key Factors for Long-Term Success
If your business doesn’t have a dedicated security team, that’s a genuinely difficult thing to defend against. Training from two years ago won’t prepare anyone for emails that sound completely legitimate and reference actual internal projects or conversations. Some firms are now tempted to plug that gap with an AI agent instead of hiring dedicated security staff. The NCSC’s updates page is one of the better resources for keeping track of how these tactics keep changing.
Ransomware Isn’t Slowing Down
The NCSC hasn’t minced words here. Ransomware remains the most immediate cyber threat facing UK organisations, and it keeps spreading into new sectors despite ongoing law enforcement crackdowns. The DragonForce attacks on major retailers showed that even companies with big security budgets can get caught out.
Budgets like these are usually shaped by the same asset-valuation exercises that inform wider business planning. Academia, finance, engineering, retail, health and manufacturing all appeared among the top sectors reporting ransomware incidents last year. Nobody’s exempt.
Smaller companies face a tougher version of this problem because they typically have fewer defences and less capacity to bounce back quickly after an attack. A proper Cyber Essentials certification covers the five technical controls the government considers baseline security, everything from firewall configuration to access management. It won’t make you bulletproof, but it closes the exact gaps that most opportunistic criminals look for first.
Supply Chain Weak Points
Here’s something that doesn’t get talked about enough. The NCSC flagged that a small number of known vulnerabilities in widely used software were behind dozens of the incidents it responded to last year.
That means if your business depends on third-party platforms or managed IT providers, their weaknesses become yours the moment something gets exploited. Ask your suppliers about their own certifications and patching schedules. This kind of outsourcing is increasingly common as businesses look to scale without expanding headcount. It’s not paranoia. It’s the bare minimum you should be doing.
What This Means If You Run A Small Business
One thing the NCSC keeps repeating is that attackers go after vulnerabilities, not specific industries. A ten-person consultancy running outdated software looks just as attractive to a criminal as a large retailer with a known gap in its defences.
Patch quickly, limit user access to only what people actually need, and test your recovery plan before a crisis forces you to find out whether it works. The businesses that treat cyber security as someone else’s responsibility will always be the ones caught off guard when something goes wrong.
ALSO READ: UK Business Insurance: What Coverage Does Your Small Business Really Need?
FAQs
Q1. How Are Cyber Attacks Impacting UK Businesses Recently?
Nationally significant cyber incidents in the UK have more than doubled year-on-year, severely affecting major retailers and smaller companies alike.
Q2. Why Is AI Making Phishing Attacks Harder To Spot?
Cybercriminals now use large language models to automate highly realistic spear-phishing campaigns that lack traditional spelling errors and dodgy formatting.
Q3. What Is The Most Immediate Cyber Security NCSC Threat Facing UK Organisations?
Ransomware remains the most immediate cyber threat facing UK organisations across every sector, regardless of their size or budget.
Q4. How Do Supply Chain Weaknesses Put Businesses At Risk?
Attackers routinely exploit known software vulnerabilities in third-party platforms and IT service providers to compromise connected client businesses.
Q5. What Can Small Businesses Do To Protect Themselves From Cyber Attacks?
Small firms should obtain Cyber Essentials certification, patch software promptly, restrict user access, and routinely test their incident recovery plans.
Sources & References
- National Cyber Security Centre. (2026, June 22). Five Eyes cyber security agencies statement: The AI shift in cyber risk, why leaders must act now. National Cyber Security Centre (NCSC).
- Cybersecurity and Infrastructure Security Agency. (2026, June 22). Five Eyes cyber security agencies statement. U.S. Department of Homeland Security, CISA.
- UK Government, Department for Science, Innovation and Technology, & Home Office. (2026, April 30). Cyber security breaches survey 2025/2026. GOV.UK.
- UK Government. (2026, March 13). Cyber Essentials scheme: Overview. GOV.UK.
- National Cyber Security Centre. (2026). Cyber Essentials: Protect your business against the most common cyber threats. NCSC.
- Heiding, F., Lermen, S., Kao, A., Schneier, B., & Vishwanath, A. (2026). Evaluating large language models’ ability to automate spear phishing. Expert Systems with Applications. Harvard Kennedy School.
- Wikipedia Contributors. (2026). Ransomware. In Wikipedia.
- National Cyber Security Centre. (2025, October). NCSC Annual Review 2025. NCSC, GCHQ.
- National Cyber Security Centre. (2025). Chapter 1: Countering the cyber threat and incident management. In NCSC Annual Review 2025.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute technical, legal, or professional security advice, nor is it intended for promotional purposes. Cybersecurity threats and official regulatory standards evolve rapidly, so readers should independently verify all facts and consult qualified professionals before implementing specific security practices.




