Supply Chain Cyber Resilience: Act Now - Bistech

“Cyber risk is now a board-level issue”

The National Cyber Security Centre’s Annual Review 2025 has made one thing clear – cyber risk is now a board-level issue. With threats rising and the cost of inaction growing, organisations must embed cyber resilience into their digital strategy.

Why now? 

The report’s findings are unequivocal. Over the past year, the UK has seen a 50% rise in highly significant cyber incidents for the third consecutive year. These attacks are no longer just IT issues, they disrupt operations, damage reputations, and threaten economic security across every sector. 

Cyber criminals and hostile states are targeting supply chains, critical infrastructure, and organisations of all sizes. The cost of inaction is rising, and the window for preparation is narrowing.

 

All business leaders need to take responsibility for their organisation’s cyber resilience.”
— Richard Horne, CEO, NCSC (Annual Review 2025) 

 

Cyber threats are business threats 

Ransomware remains the most acute and pervasive threat. Attackers are sector-agnostic, targeting organisations based on vulnerability and likelihood to pay. In 2024 alone, 50% of UK businesses experienced a cyber attack or breach, up from 39% just two years earlier. This is not a trend; it’s a trajectory. 

The NCSC highlights that cyber attacks now have real-world impacts, from empty shelves in retail to service outages in healthcare. No sector is exempt.

 

2025 cyber threats at a glance
(Source: NCSC Annual Review 2025) 

  • Ransomware: Still the top threat, with attacks disrupting operations and targeting critical data. 
  • State-Backed Actors: China, Russia, Iran, and North Korea are actively targeting UK organisations for espionage, disruption, and financial gain. 
  • Supply Chain Attacks: Incidents like the MOVEit breach show vulnerabilities in third-party software can have global repercussions. 
  • AI-Enabled Attacks: Threat actors are using AI to automate phishing, enhance reconnaissance, and accelerate vulnerability discovery. 
  • Legacy System Vulnerabilities: Outdated systems and unpatched software remain a major entry point for attackers. 
  • Proliferation of Intrusion Tools: The global market for cyber intrusion products is expanding, enabling more actors to target a wider range of systems. 
  • Critical National Infrastructure Under Fire: Ransomware and disruptive attacks on energy, healthcare, and transport sectors have had real-world impacts.
  • Human Factor: Social engineering and phishing remain common, exploiting gaps in cyber awareness and organisational culture. 

 

50% year-on-year increase

We all need to recognise that there is a 50% year-on-year increase in ‘highly significant’ cyber incidents, the third consecutive annual rise. This is not currently showing signs of decline. 

The board’s role: Leadership must take the reins 

Cyber resilience isn’t just a technical challenge, it’s a strategic one. The NCSC and UK Government are urging boards to take ownership, supported by the new Cyber Governance Code of Practice and free board-level training.

At Bistech, we believe that all boards should:  

  1. make cyber risk a standing agenda item
  2. use NCSC guidance to translate technical risk into business risk
  3. regularly review cyber posture, not just reactively after incidents. 

While ensuring these key questions should be discussed at board level: 

  • are we investing in the right controls? 
  • do we have visibility across our digital estate? 
  • are our people empowered to act securely?

Practical steps to build resilience 

The NCSC offers clear, actionable guidance. Here’s how to get started: 

1. Make cyber risk a boardroom priority
Proactive planning is essential. Boards should review cyber posture regularly and ensure cyber risk is embedded in strategy and culture.

2. Invest in foundational controls
Cyber Essentials is more than a compliance badge, it’s a framework for good practice, now updated for hybrid working and cloud adoption.

3. Leverage free NCSC resources
The Cyber Assessment Framework (CAF) and Early Warning service help identify vulnerabilities before attackers do.

4. Build a positive cyber culture
Security is about people as much as technology. Empower staff to make secure decisions, report concerns, and understand their role in resilience. 

5. Engineer for resilience
Go beyond prevention – test your ability to recover from disruptive attacks through regular incident exercises and resilience engineering.

6. Assure your supply chain
Only 14% of UK businesses reviewed supplier cyber risk in the past year. Use NCSC’s supply chain guidance and encourage suppliers to achieve Cyber Essentials certification. 

Cyber resilience in action 

One of our customers, Corstorphine & Wright, a leading architectural practice, faced the challenge of securing sensitive project data while maintaining operational agility. We introduced a tailored cyber security solution aligned with their technical needs, budget, and long-term goals, which are incorporating Cyber Essentials, segmentation, and incident response planning. 

Crucially, we considered the unique challenges of the architectural sector, ensuring resilience without compromising creativity or collaboration. 

“Our board knows we’re covered 24/7. It’s given them – and me – real confidence in our security strategy.”
— Corstorphine & Wright 

The power of policy and planning 

Earlier this year, a supply chain attack involving the MOVEit file transfer app affected thousands of businesses globally. This is a stark reminder that resilience isn’t just about your own systems – it’s about your partners, vendors, and third-party tools. 

Having clear, actionable security policies, and ensuring they’re understood and lived across the organisation is essential. It’s not enough to have a document on the intranet; it needs to be embedded in daily practice. 

Don’t wait for the breach 

Cyber resilience is economic resilience. It protects your people, your data, and your reputation. The NCSC’s message is clear: It’s time to act.
 


If you’re unsure where to start, start here or book a call with us and let’s talk about building a cyber strategy that’s bespoke for you. 

 

Book a call today

 


Andy Allison, Principal Innovation Architect

Andy Allison leads infrastructure and cyber security at Bistech, defining the strategy that underpins secure, scalable and commercially aligned platforms. He is responsible for security governance, platform resilience and ensuring technology investment supports both internal operations and customer-facing services. With over 20 years of experience across infrastructure, networking, cloud and cyber security, Andy brings a broad and practical understanding of modern IT environments. He focuses on enabling the business to scale securely, operate efficiently and maintain trust with customers and partners.