UK National Cyber Security Centre CEO Richard Horne said the agency handled more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem between June 2025 and May 2026, with about 75% assessed as linked to hostile states including Russia, China and Iran. Speaking at the RUSI Annual Security Lecture, Horne said cyber security must be treated as a continuous contest rather than a static risk-management problem, warning that adversaries are already pre-positioning in infrastructure for possible future disruption and citing Volt Typhoon as a prominent example.
Horne described the threat across "far," "mid" and "near" digital spaces, arguing that governments and allies must combine intelligence, sanctions, law enforcement and offensive cyber operations while industry and government work together to secure cloud, telecoms and open-source ecosystems. He warned that AI will accelerate vulnerability discovery and attack scaling, with attackers likely to apply AI-enabled capabilities against known weaknesses in legacy critical infrastructure technology, and urged organizations to strengthen foundational controls, improve resilience and recovery, and replace unsupported systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-17, NCSC CEO Richard Horne delivered the RUSI Annual Security Lecture in London and argued that cyber security should be treated as a continuous contest rather than a manageable static risk. He outlined threats across far, mid, and near spaces and warned about AI acceleration and adversary pre-positioning in critical infrastructure.
Between June 2025 and May 2026, the NCSC managed more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem. Horne said about 75% of these incidents were believed to be linked to state actors or hostile states.
Richard Horne cited Volt Typhoon as a high-profile campaign against largely US critical national infrastructure that was attributed in 2024, using it as an example of adversary pre-positioning for potential future conflict.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.