National Cyber Security Centre Annual Review for 2025
Recommends for businesses to prioritise Cyber Essentials certification as a minimum
+ Cyber risk is no longer just an IT issue — it’s a boardroom priority!

Dr. Richard Horne, CEO of the NCSC, stated that it is crucial for all businesses and organisations to act now. Both the UK government and the NCSC emphasize that cyber risk is no longer just an IT issue; it has become a priority for the boardroom!
“For too long, cyber security has been viewed primarily as a concern for technical staff. This needs to change. Business leaders must take responsibility for their organisation’s cyber resilience.”
Cyber incidents can disrupt operations, damage a company’s reputation, and lead to serious financial and legal consequences. For today’s business leaders, cyber resilience means having the strategic foresight to prepare for, respond to, and recover from cyberattacks.
Cyber security is a matter of business survival that demands action.
“Don’t be an easy target; prioritise cyber risk management, embed it into your governance, and lead from the top.’ Anne Keast-Butler — Director GCHQ
Recommendations of the Annual Review
Embracing Cyber Essentials is a crucial step toward securing a business’s digital landscape and enhancing overall resilience against potential cyber risks.
Report Highlights
- Chapter 1 focuses on understanding and countering cyber threats around the following topics:
- State actors and the global cyber security threats from China, Russia, Iran and the Democratic People’s Republic of Korea.
- Ransomware which continues to remain one of the most acute and pervasive cyber threats to UK businesses highlighted by high profile attacks on Marks and Spencer and The Co-Op.
- AI and the threat actors of all types continue to use AI to increase the efficiency, effectiveness, and frequency of their cyber intrusions.
- Chapter 2 discusses how to build cyber resilience at scale to support economic growth and help organisations of all sizes prepare for, protect against, detect, and respond to cyber threats.
- It recommends that all businesses implement at least the Cyber Essentials certification as a minimum standard. This certification will not only equips businesses with essential tools to safeguard against cyber threats but also lays the groundwork for robust and effective defences.
- Additionally, it highlights the importance of Cyber Essentials in ensuring supply chain security. Alarmingly, only 14% of UK businesses reviewed the cyber risks associated with their immediate suppliers in the past 12 months. This lack of review is often due to insufficient capacity, capability, and tools within purchasing organisations. As a response, the government is urging large businesses to better address supply chain cyber security risks by developing strategies to enhance the adoption of Cyber Essentials within their supply chains.
- Chapter 3 examines how the National Cyber Security Centre (NCSC) is adapting to evolving technologies to ensure that our defences remain agile, adaptable, and prepared for the future. As emerging technologies like post-quantum cryptography (PQC), artificial intelligence (AI), and passkeys redefine the threats we face and the tools available to enhance cyber resilience, the NCSC is actively involved in shaping the development of these foundational technologies.
Click here to read the report in full.
What is Cyber Essentials Certification?

Obtaining a Cyber Essentials certification can significantly enhance a businesses defences and reduce cyber threats by approx. 80%.
By implementing five key controls, a business can significantly reduce risk, enhance protection, and provide stakeholders with verified assurance that their organisation prioritises cybersecurity and meets the UK’s minimum cybersecurity standards.
An independent impact evaluation report of businesses that have implemented Cyber Essentials reveals the following findings:
- 85% of Cyber Essentials users believe the scheme has directly enhanced their understanding of cyber security risks.
- 88% feels it has improved their knowledge of the steps they can take to mitigate those risks.
- 91% state that the scheme has directly boosted their confidence in consistently implementing measures to reduce cyber security risks.
- 79% believe the scheme positively impacts the confidence of their own clients and customers.
- 69% think that Cyber Essentials has increased their market competitiveness.
Among the organisations that achieved Cyber Essentials certification in the last year, the key benefits identified were:
- It enabled them to bid for new projects.
- It increased confidence among customers and partners.
- It allowed them to promote their commitment to cybersecurity.
TecSec Services Is A Licensed Certification Body

Our team of certified Cyber Essentials Assessors brings a wealth of expertise to the table, guaranteeing the highest level of service and support. Accredited by the National Cyber Security Centre, we provide comprehensive solutions that not only help companies navigate the certification process but also assist them in implementing and rigorously evaluating their application.
All Business Should Take Action Now: Cyber threats are not slowing down, and businesses must act now to fortify their defences. Don’t wait until an attack disrupts your operations – contact TecSec Services today to safeguard your business against cybercriminals.









