The UK is now dealing with an average of four nationally significant cyber incidents every week. That figure, first put on the record by National Cyber Security Centre chief executive Dr Richard Horne in late 2025, was reiterated at the CYBERUK 2026 conference in Glasgow on 22 April. According to the NCSC, the volume has held roughly steady. What has shifted dramatically is where the attacks are coming from: the majority of these serious incidents now originate, directly or indirectly, from nation states including China, Iran and Russia.

For boards running data centres, financial sites, utilities and other critical national infrastructure, the headline is uncomfortable but the operational lesson is simple. Cyber risk has stopped being a problem the IT department can solve on its own. The most damaging breaches still tend to involve a physical element somewhere in the chain: a tailgated door, a stolen access card, a contractor with credentials they should not have, a USB plugged into the wrong machine. The front door, the loading bay and the comms cupboard remain part of your cyber attack surface.

What the NCSC is actually reporting

In its Annual Review for the year to August 2025, the NCSC said it had dealt with 204 nationally significant cyber attacks against the UK, more than double the 89 it handled the year before. Eighteen of those were rated “highly significant”, meaning they had the potential to cause serious impact on essential services. The four-a-week running rate Dr Horne cited at CYBERUK 2026 suggests that trajectory has not eased.

In his keynote, Dr Horne described what he called a “perfect storm” for UK cyber security: rapid technological change driven by artificial intelligence, sharpening geopolitical tensions, and an expanding pool of capable hostile actors. He noted that Russia is reportedly applying lessons learned on the battlefield in Ukraine to its cyber operations elsewhere, and that frontier AI is enabling the discovery and exploitation of vulnerabilities at scale.

The shift in origin matters. State-backed operations are patient, well-resourced, and not motivated purely by financial return. They have time to map a target site, understand its routines, identify weak points in its physical posture, and combine that information with their digital tradecraft.

Where physical security meets the cyber threat

The convergence is not theoretical. Public reporting from across the security community has long flagged the same recurring physical-attack vectors that sit alongside the headline-grabbing software exploits:

  • Tailgating and credential cloning at corporate receptions, data halls and back-of-house entrances.
  • Social engineering at the front desk: visitors posing as engineers, couriers, fire-safety inspectors or auditors to get past the lobby.
  • Unsupervised contractor access to server rooms, plant rooms and risers – often the path of least resistance for a hostile actor who needs a few minutes alone with a network port or USB slot.
  • Loading-bay and perimeter weaknesses where deliveries, waste collection and maintenance routines create predictable gaps.
  • Insider risk, where the easiest way to bypass an otherwise hardened network is a person who is already inside the building.

None of these are exotic. They are the everyday gaps that a well-resourced state-aligned operator can probe and exploit because the cost is low and detection is difficult. A SOC monitoring east-west traffic will not always see a person who walked in through the lobby on a borrowed badge.

What this means for data centres, finance and CNI operators

For sites in the most exposed categories, three practical shifts are worth considering now, rather than after the next nationally significant incident lands.

Treat the physical perimeter as part of the cyber control set. Access control, visitor management, CCTV coverage of comms rooms, and the procedures around contractor escorts should be reviewed alongside, not separately from, your cyber controls. If your incident response plan treats physical and cyber as different incidents managed by different people, you will lose time when the two converge in a real event.

Invest in trained, SIA-licensed people at the human checkpoints. Cameras and turnstiles do not stop a confident impostor at reception. A trained officer who knows what hostile reconnaissance and social engineering look like, who is comfortable challenging unexpected visitors, and who follows a written escalation path, is one of the most cost-effective controls available. Our team builds these procedures into corporate security deployments and adapts them for the higher-tempo environment of construction and infrastructure sites, where contractors and deliveries cycle in and out throughout the day.

Drill the joint scenario. Tabletop exercises that combine a physical breach with a network event give security, IT and facilities teams a shared language. They also expose the gaps no one notices in steady-state operation: who calls who at 03:00, who decides to lock the building down, who briefs the board.

Need a security review?

If your site sits in the data centre, finance, or critical infrastructure category, the convergence between cyber and physical risk is not a future problem. It is the working reality the NCSC is describing four times a week. Our team can carry out a focused review of your access control, contractor management and front-of-house procedures, and join up that picture with your existing cyber posture.

Call us on 020 3700 0967, email info@secureonsitesecurity.co.uk, or use our contact form to arrange a confidential conversation. We can also discuss longer-term corporate security and site security arrangements where the physical layer needs to keep pace with a changing threat picture.

Loading...
Share This