A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’
NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
Iran, Russia, China and other nation states represent the most serious cybersecurity threats to the UK today, according to Richard Horne, the CEO of the National Cyber Security Centre (NCSC).
Speaking at the CyberUK conference in Glasgow, Horne said that technological change and geopolitical tensions make for 'tumultuous uncertainty', with the agency already handling an average of four nationally significant incidents a week.
"Criminal activity such as ransomware remains the most prevalent threat to the vast majority of organizations, but the majority of the nationally significant incidents that my teams are handling now originate directly or indirectly from nation states," he said.
Horne warned that China’s intelligence and military agencies in particular now display an 'eye-watering' level of sophistication in their cyber operations, while Iran is almost certainly using cyber activity to support the repression of British individuals.
Russia, meanwhile, is using the tactics and techniques that it's honed in conflict against states it considers hostile, making cyber security the new 'home front'.
"We know that, were we to be in, or near, a conflict situation, the UK would likely face hacktivist attacks at scale. With similar effects and sophistication to the ransomware attacks we see today but no option to pay a ransom to help recover," he said.
These threats are combining with others to create a 'perfect storm', with frontier AI capabilities now rapidly enabling discovery and exploitation of existing vulnerabilities at scale.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Attackers are exposing gaps in the fundamentals of cybersecurity, such as code shipped by tech producers with significant vulnerabilities, organizations' failure to patch with the completeness or urgency they should, and a failure to replace legacy systems.
NCSC sounds alarm on quantum threats
Meanwhile, quantum is a looming threat, Horne told attendees. The warning comes amid rising concerns about ‘Q-Day’, the point at which quantum computers can crack traditional encryption methods.
Google, for example, recently revised its timeline for this tipping point to within just three years. Predictions on this front vary wildly, however, ranging from within a few years to decades.
"We don’t know when a quantum computer will be able to break the widely used cryptography that we rely on in everything we do. But we do know it is in our gift to be ready for that point," he said.
He advised organizations to refer to NCSC guidance setting out what they need to do over the coming years to ensure successful migration to post-quantum cryptography.
More broadly, as the technology landscape develops the definition of cybersecurity expands with it. Efforts to shore up protections across a wider array of areas are being made globally, such as in operational technology (OT), typically used to control energy systems and production lines – both key targets for state-backed threat groups and hacktivists.
Ric Derbyshire, principal security researcher at Orange Cyberdefense, echoed Horne's concerns about politically-motivated hacktivist groups.
"Escalatory hacktivism is a phenomenon we are seeing in which groups align with state-backed narratives and contribute to their host state’s hybrid warfare efforts. This trend is set to become more pervasive and more impactful," he said.
"This is about societal resilience as much as cyber resilience. It will require stronger global collaboration, closer public-private coordination, and sustained legislative action, such as the Cyber Security and Resilience Bill, with a focus on protecting critical services and maintaining continuity in the face of disruption.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
Cisco sounds alarm over new Russian malware campaign hitting firms in US and EuropeNews UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims
-
NCSC issues warning over Russian intelligence-backed threat groupNews The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations”
-
UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilitiesNews The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks
-
‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worseNews Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk
-
US offers $10m bounty for info on Russia-linked hackers behind Signal and WhatsApp attacksNews UNC5792 and UNC4221 have been targeting government officials through their Signal and WhatsApp accounts
-
Hostile states behind three-quarters of UK critical infrastructure attacksNews NCSC CEO warns that with the rise of AI, the danger is only set to get worse
-
Security experts sound alarm over 'expanded' China-linked botnet used to target US critical infrastructure and military assetsNews The China-linked botnet highlights risk of leaving routers and IoT devices unpatched

