Reporting this month suggests hostile states are behind roughly three-quarters of cyberattacks on the UK’s critical national infrastructure — energy, water, transport, health and the suppliers that serve them. The motive is increasingly strategic rather than purely criminal.

What it means for you

Most businesses aren’t “critical infrastructure” — but many are in the supply chains that feed it, and state-linked actors are happy to reach their target through a smaller, softer supplier. Being a trusted vendor to a larger organisation now comes with a security expectation attached.

If you supply the public sector or larger enterprises, expect to be asked to prove your security posture — Cyber Essentials, documented controls, incident response. We help clients get certified and audit-ready so those questions become an easy “yes” rather than a scramble.

Source: ITPro, June 2026.