---
title: "UK critical infrastructure hit by 200 cyber inc… | Firevault"
description: "NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double#webpage",
      "url": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double",
      "name": "UK critical infrastructure hit by 200 cyber inc…",
      "description": "NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns",
          "item": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns",
      "description": "NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.",
      "url": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-06-20T05:14:36.940418+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Analysis",
      "wordCount": 819,
      "keywords": "Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The UK's critical national infrastructure absorbed more than 200 cyber incidents in the year to May 2026, and about three-quarters of them are believed to be the work of state actors. That is the headline from a speech by Richard Horne, chief executive of the National Cyber Security Centre, delivered at the Royal United Services Institute and reported by [The Guardian](https://www.theguardian.com/",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What did the NCSC report?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "NCSC chief executive Richard Horne told an audience at RUSI that the National Cyber Security Centre responded to more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026, with about 75 per cent believed to be linked to state actors."
          }
        },
        {
          "@type": "Question",
          "name": "Why does critical national infrastructure matter so much?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Critical national infrastructure covers the systems behind power, water, health, transport, telecoms and the nuclear deterrent. A successful attack on any of these does not just cause data loss, it removes services that people depend on in daily life. That is why hostile states target it."
          }
        },
        {
          "@type": "Question",
          "name": "How does offline secure storage help?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "NCSC tells operators to concentrate on the fundamentals, including being able to recover quickly from attacks. A backup of last resort that sits physically disconnected at OSI Layer 1, accessed only through scheduled identity-verified windows, cannot be reached by an attacker who has compromised the production estate. That is the role Firevault is built for."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What the NCSC actually saidWhy this is a backup problem as …The Firevault viewWhat CNI operators should do thi…More Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Analysis · 20 June 2026 

# UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-uk-critical-infrastructure-incidents-double)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-uk-critical-infrastructure-incidents-double&text=UK%20critical%20infrastructure%20hit%20by%20200%20cyber%20incidents%20in%20a%20year%2C%20NCSC%20warns%0A%0ANCSC%20chief%20Richard%20Horne%20says%20the%20UK%20faced%20more%20than%20200%20nationally%20significant%20cyber%20incidents%20against%20critical%20infrastructure%20in%20a%20year%2C%20with%20about%20three-quarters%20tied%20to%20state%20actors.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-uk-critical-infrastructure-incidents-double)[](mailto:?subject=UK%20critical%20infrastructure%20hit%20by%20200%20cyber%20incidents%20in%20a%20year%2C%20NCSC%20warns&body=NCSC%20chief%20Richard%20Horne%20says%20the%20UK%20faced%20more%20than%20200%20nationally%20significant%20cyber%20incidents%20against%20critical%20infrastructure%20in%20a%20year%2C%20with%20about%20three-quarters%20tied%20to%20state%20actors.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-uk-critical-infrastructure-incidents-double)

![Twilight UK electricity substation behind a chain-link perimeter fence with magenta and teal accent lighting](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg)

Twilight UK electricity substation behind a chain-link perimeter fence with magenta and teal accent lighting

Why it matters

## What this means for organisations holding critical data

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

In this analysis

1.  01 [What the NCSC actually said](#section-0)
2.  02 [Why this is a backup problem as …](#section-1)
3.  03 [The Firevault view](#section-2)

**On this page**[What the NCSC actually said](#section-0)[Why this is a backup problem as …](#section-1)[The Firevault view](#section-2)

The UK's critical national infrastructure absorbed more than 200 cyber incidents in the year to May 2026, and about three-quarters of them are believed to be the work of state actors. That is the headline from a speech by Richard Horne, chief executive of the National Cyber Security Centre, delivered at the Royal United Services Institute and reported by [The Guardian](https://www.theguardian.com/uk-news/2026/jun/17/uk-critical-infrastructure-cyber-incidents-ncsc).

For an island that runs on a tightly coupled mesh of energy, water, health, transport, telecoms and finance, that number is not a statistic. It is a forecast.

## What the NCSC actually said

Horne framed the threat as an "ongoing contest with capable adversaries", naming Russia, China and Iran as the states most actively probing the systems behind the United Kingdom's key services. He compared it not to a wrestling match in a defined ring but to a football or basketball game played across the entire pitch, with success depending on how well you operate across the whole field.

The NCSC defines a cyber incident as any attempt to damage, disrupt or gain unauthorised access to computer systems, networks or devices. More than 200 of those, in a single year, touched the operators of national infrastructure or the suppliers that hold them up. Hospitals, power plants, airports and the nuclear deterrent are all in scope.

Horne also warned that advances in artificial intelligence are likely to accelerate the threat, exposing cyber flaws in national infrastructure. He pointed to 2028 as the moment when that pressure is likely to crystallise. His message to organisations was unromantic: concentrate on the fundamentals, and make sure you can recover quickly from an attack.

## Why this is a backup problem as much as a defence problem

No operator of [critical infrastructure](/control-for-critical-infrastructure) expects to keep adversaries out forever. The realistic objective is to limit the blast radius and to come back online before a service outage becomes a national event.

That is precisely where most estates are weakest. Modern ransomware and destructive intrusion sets target backups first, because attackers know that an operator with a clean, reachable backup is an operator who will not pay. "Immutable" object storage and hardened backup appliances raise the bar, but they remain reachable across the network through identity systems, APIs and management consoles. A sufficiently determined attacker who reaches domain admin reaches the backup plane too.

NCSC has already published its own [Principles for ransomware-resistant cloud backups](/compliance/ncsc-ransomware-resistant-backups) describing exactly this risk: backups must be resilient to destructive actions, the system must not be possible to lock customers out of, and there must be a backup of last resort that can be restored from. Those principles are unforgiving, and they are the right standard for critical infrastructure.

## The Firevault view

Firevault was built to be the backup of last resort. The gold copy sits in a [physically air-gapped](/learn/physical-vs-logical-air-gap) module, disconnected at Layer 1 of the OSI model. While offline there is no IP address, no API, no console and no identity path into the data. It is brought online only inside a scheduled, identity-verified connection window managed from a separate plane, and every event is recorded on a tamper-evident audit trail that auditors, insurers and regulators can read.

For a CNI operator that already has hot, warm and immutable backups, Firevault is the layer that survives the day those fail. It will not stop the intrusion. It is the reason the lights, the water or the trains come back on the day after.

## What CNI operators should do this week

-   **Test a restore from a truly offline copy.** Not a snapshot, not a vendor-managed immutable tier — a copy that is physically disconnected from the production estate and identity system.
-   **Separate the management plane.** The console that controls your backups should not share identity, network or operators with the systems they back up.
-   **Schedule identity-verified connection windows.** Treat access to the backup of last resort as a distinct workflow, not a continuation of day-to-day admin.
-   **Keep the evidence pack ready.** Regulators (Ofgem, Ofwat, the ICO, sector CAs under NIS Regulations) will increasingly ask to see proof that a restore is possible. Tamper-evident logs are the easiest answer.

Horne's closing line at RUSI is worth keeping on the wall: "The many vulnerabilities that organisations tolerate today will be exploited in conflict tomorrow. If they are too expensive or hard to fix in peacetime, then they certainly will be in war."

Source: [The Guardian — UK critical infrastructure hit by 200 cyber incidents in a year, agency says](https://www.theguardian.com/uk-news/2026/jun/17/uk-critical-infrastructure-cyber-incidents-ncsc).

_Mark Fermor is a co-founder of Firevault._

**How Firevault helps**

-   **[Offline Secure Storage](/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
-   **[Control](/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.

_Talk to Firevault about [Disconnect to Protect®](/about) for your organisation._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.theguardian.com/uk-news/2026/jun/17/uk-critical-infrastructure-cyber-incidents-ncsc)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Threat Analysis 

### Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

22 Jun 2026 4 min 







](/news/scattered-spider-tfl-guilty-plea-offline-recovery)[

![24 billion credentials exposed in record infostealer leak](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg)

Threat Analysis 

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min 







](/news/24-billion-credentials-infostealer-leak)[

![FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials](/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg)

Threat Analysis 

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min 







](/news/fortibleed-74000-fortinet-firewalls-credentials-exposed)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)