Broadly yes—but only with an important qualification. The UK’s National Cyber Security Centre (NCSC) handled 204 nationally significant cyber incidents during its latest 12-month review period, compared with 89 in the previous year. Dividing 204 by roughly 52 weeks gives 3.92, which the NCSC rounded to four a week. This is an annual average of cases reaching the NCSC’s incident-management operation, not a live count of every cyberattack in Britain or proof that four critical services were knocked offline each week.
The announcement was published on 14 October 2025, so it should not be presented as a verified weekly rate for August 2026.
The numbers behind the headline
| Measure | Previous period | Latest period |
|---|---|---|
| Nationally significant incidents handled by the NCSC | 89 | 204 |
| All incidents requiring NCSC incident-management support | Not stated | 429 |
| Highly significant incidents | About 12 | 18 |
The NCSC’s announcement gives the rounded “four per week” figure: 204 nationally significant incidents over approximately one year. Its annual-review data says those 204 cases were 48% of the 429 incidents requiring support from the Incident Management team, up from 89 the year before: NCSC Annual Review 2025.
“Four a week” is therefore a rounded average, not a schedule. Incidents can cluster in one period and be absent in another.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
What “nationally significant” means
The NCSC uses the category for an incident that either has a serious impact on a large organisation or wider/local government, or poses considerable risk to central government or UK essential services. It is a technical severity classification, not a synonym for every large or successful cyberattack.
A smaller but more serious category is “highly significant”. It can involve central government, UK essential services, a large proportion of the UK population or the UK economy. Only 18 incidents received that classification in the review period. The NCSC’s definition and figures are set out in its incident-management review.
What the statistic does—and does not—tell us
It does tell us
- 204 serious cases reached the NCSC’s incident-management threshold during the review year.
- The number of nationally significant cases handled by the NCSC was more than twice the previous year’s 89.
- The cases concerned UK interests and organisations, rather than constituting a census of attacks physically occurring inside the UK.
It does not tell us
- That exactly four attacks happen in every calendar week.
- That four attacks successfully shut down critical infrastructure each week.
- That four separate organisations were attacked each week.
- How many attacks were attempted, blocked, reported to police or handled by regulators without NCSC involvement.
- That attacker activity increased by exactly the same proportion as NCSC-handled cases.
An incident may involve an attempted intrusion, compromise, disruption, data theft or serious risk that is contained before a prolonged outage. In a speech accompanying the annual review, NCSC chief executive Richard Horne stressed that many attacks fail and that preparation can allow an organisation to continue operating when an intrusion gets through: NCSC Annual Review 2025 speech.
Why the number rose from 89 to 204
The increase is substantial, but the figures alone cannot establish a single cause. More severe attacks may be occurring, while improved visibility, reporting, triage, changes in the severity mix or more organisations seeking government assistance may also affect the total. It is accurate to say that NCSC-handled nationally significant incidents rose from 89 to 204; it is not accurate to turn that into a precise percentage increase in all UK cybercrime.
Rank #3
Who is behind the incidents?
The NCSC says a substantial proportion of the incidents it handled were linked to advanced persistent threat actors, including nation-state operators and highly capable criminal groups. The four-a-week announcement does not provide a complete numerical breakdown by country, so claims that most incidents came from Russia, China, Iran or another specific state would require separate evidence.
Which organisations are exposed?
The category covers large businesses, central and local government and essential services. Relevant exposure extends across healthcare, energy, transport, financial services, retail, manufacturing, technology and telecommunications. Suppliers can also be affected indirectly when an attacker reaches a customer through a cloud provider, outsourced IT service or connected system.
Rank #4
That does not mean every organisation faces the same likelihood or impact. In the government’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, 65% of medium businesses and 69% of large businesses reported a breach or attack, compared with 42% of micro businesses and 46% of small businesses. Smaller firms are not safe by default: limited security staffing, weaker recovery capability and supply-chain connections can increase the consequences of an incident.
How this compares with everyday cybercrime
The NCSC figure measures the high-severity end of the threat landscape. The government survey measures self-reported experience among businesses, so the datasets should not be combined as if they were one national incident count.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
| Survey measure | 2025/2026 result |
|---|---|
| Businesses observing a breach or attack in the previous 12 months | 43% (about 612,000 UK businesses) |
| Businesses reporting phishing | 38% |
| Businesses with a formal cyber-incident response plan | 25% |
| Businesses reporting ransomware | About 1% |
Phishing is therefore far more common than incidents reaching the “nationally significant” threshold. The survey’s ransomware figure is self-reported and should not be treated as a complete measure of ransomware activity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organisations should do now
Small organisations
- Turn on phishing-resistant or app-based multi-factor authentication, starting with email, administrator and cloud accounts.
- Apply security updates promptly, prioritising internet-facing systems.
- Keep offline or otherwise isolated backups and test that they can be restored.
- Separate administrator accounts from everyday user accounts.
- Use the NCSC’s small-organisation toolkit and consider Cyber Essentials as a baseline, not a complete defence.
Growing and larger businesses
- Monitor privileged accounts, unusual logins and suspicious email-forwarding rules.
- Identify critical suppliers and check their recovery arrangements.
- Define recovery-point and recovery-time objectives for essential systems.
- Rehearse an incident-response plan with senior leadership, IT, legal, communications and insurance contacts.
- Consider whether 24/7 managed detection and response is justified by the organisation’s systems, exposure and regulatory obligations.
Boards and public-sector leaders
- Know which services must continue if identity, data or cloud systems become unavailable.
- Require evidence that backups and restoration procedures have been tested.
- Set a clear escalation route and decision authority before an incident.
- Review supplier concentration and the consequences of a provider-wide outage.
What to do after a suspected breach
- Isolate affected devices or network segments while preserving evidence.
- Save logs, suspicious emails, ransom notes and relevant timestamps.
- Contact the incident-response provider, insurer and legal advisers.
- Reset compromised credentials, prioritising privileged and cloud accounts.
- Assess whether data was accessed or exfiltrated.
- Notify regulators, customers or law enforcement where required, and use the UK’s cyber-incident reporting route linked from the NCSC’s incident-management guidance.
- Do not assume that restoring a backup removes the attacker’s access.
- Do not pay a ransom without legal, insurance and law-enforcement advice.
Bottom line
The “four major cyberattacks a week” headline is rooted in a real NCSC statistic, but the precise claim is that the agency handled an average of four nationally significant incidents a week during the year covered by its 2025 review. It is a warning about serious cases reaching the national cyber authority—not a complete count of UK cybercrime or evidence of four weekly critical-infrastructure outages.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




