26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreThe National Cyber Security Centre’s Annual Review 2025 has made one thing clear – cyber risk is now a board-level issue. With threats rising and the cost of inaction growing, organisations must embed cyber resilience into their digital strategy.
The report’s findings are unequivocal. Over the past year, the UK has seen a 50% rise in highly significant cyber incidents for the third consecutive year. These attacks are no longer just IT issues, they disrupt operations, damage reputations, and threaten economic security across every sector.
Cyber criminals and hostile states are targeting supply chains, critical infrastructure, and organisations of all sizes. The cost of inaction is rising, and the window for preparation is narrowing.
“All business leaders need to take responsibility for their organisation’s cyber resilience.”
— Richard Horne, CEO, NCSC (Annual Review 2025)
Ransomware remains the most acute and pervasive threat. Attackers are sector-agnostic, targeting organisations based on vulnerability and likelihood to pay. In 2024 alone, 50% of UK businesses experienced a cyber attack or breach, up from 39% just two years earlier. This is not a trend; it’s a trajectory.
The NCSC highlights that cyber attacks now have real-world impacts, from empty shelves in retail to service outages in healthcare. No sector is exempt.
2025 cyber threats at a glance
(Source: NCSC Annual Review 2025)
- Ransomware: Still the top threat, with attacks disrupting operations and targeting critical data.
- State-Backed Actors: China, Russia, Iran, and North Korea are actively targeting UK organisations for espionage, disruption, and financial gain.
- Supply Chain Attacks: Incidents like the MOVEit breach show vulnerabilities in third-party software can have global repercussions.
- AI-Enabled Attacks: Threat actors are using AI to automate phishing, enhance reconnaissance, and accelerate vulnerability discovery.
- Legacy System Vulnerabilities: Outdated systems and unpatched software remain a major entry point for attackers.
- Proliferation of Intrusion Tools: The global market for cyber intrusion products is expanding, enabling more actors to target a wider range of systems.
- Critical National Infrastructure Under Fire: Ransomware and disruptive attacks on energy, healthcare, and transport sectors have had real-world impacts.
- Human Factor: Social engineering and phishing remain common, exploiting gaps in cyber awareness and organisational culture.
We all need to recognise that there is a 50% year-on-year increase in ‘highly significant’ cyber incidents, the third consecutive annual rise. This is not currently showing signs of decline.
Cyber resilience isn’t just a technical challenge, it’s a strategic one. The NCSC and UK Government are urging boards to take ownership, supported by the new Cyber Governance Code of Practice and free board-level training.
At Bistech, we believe that all boards should:
While ensuring these key questions should be discussed at board level:
The NCSC offers clear, actionable guidance. Here’s how to get started:
1. Make cyber risk a boardroom priority
Proactive planning is essential. Boards should review cyber posture regularly and ensure cyber risk is embedded in strategy and culture.
2. Invest in foundational controls
Cyber Essentials is more than a compliance badge, it’s a framework for good practice, now updated for hybrid working and cloud adoption.
3. Leverage free NCSC resources
The Cyber Assessment Framework (CAF) and Early Warning service help identify vulnerabilities before attackers do.
4. Build a positive cyber culture
Security is about people as much as technology. Empower staff to make secure decisions, report concerns, and understand their role in resilience.
5. Engineer for resilience
Go beyond prevention – test your ability to recover from disruptive attacks through regular incident exercises and resilience engineering.
6. Assure your supply chain
Only 14% of UK businesses reviewed supplier cyber risk in the past year. Use NCSC’s supply chain guidance and encourage suppliers to achieve Cyber Essentials certification.
One of our customers, Corstorphine & Wright, a leading architectural practice, faced the challenge of securing sensitive project data while maintaining operational agility. We introduced a tailored cyber security solution aligned with their technical needs, budget, and long-term goals, which are incorporating Cyber Essentials, segmentation, and incident response planning.
Crucially, we considered the unique challenges of the architectural sector, ensuring resilience without compromising creativity or collaboration.
“Our board knows we’re covered 24/7. It’s given them – and me – real confidence in our security strategy.”
— Corstorphine & Wright
Earlier this year, a supply chain attack involving the MOVEit file transfer app affected thousands of businesses globally. This is a stark reminder that resilience isn’t just about your own systems – it’s about your partners, vendors, and third-party tools.
Having clear, actionable security policies, and ensuring they’re understood and lived across the organisation is essential. It’s not enough to have a document on the intranet; it needs to be embedded in daily practice.
Cyber resilience is economic resilience. It protects your people, your data, and your reputation. The NCSC’s message is clear: It’s time to act.
If you’re unsure where to start, start here or book a call with us and let’s talk about building a cyber strategy that’s bespoke for you.