Reporting this month suggests hostile states are behind roughly three-quarters of cyberattacks on the UK’s critical national infrastructure — energy, water, transport, health and the suppliers that serve them. The motive is increasingly strategic rather than purely criminal.
What it means for you
Most businesses aren’t “critical infrastructure” — but many are in the supply chains that feed it, and state-linked actors are happy to reach their target through a smaller, softer supplier. Being a trusted vendor to a larger organisation now comes with a security expectation attached.
If you supply the public sector or larger enterprises, expect to be asked to prove your security posture — Cyber Essentials, documented controls, incident response. We help clients get certified and audit-ready so those questions become an easy “yes” rather than a scramble.
You are probably in a supply chain
Most businesses are not themselves critical national infrastructure — but a great many sit somewhere in the supply chains that feed it, and that is enough to matter. State-linked actors are pragmatic: rather than assault a well-defended target head-on, they reach it through a smaller, softer supplier with a trusted connection inside. Being a valued vendor to a larger organisation or the public sector now comes with a security expectation attached, whether or not it is spelled out in the contract today.
Getting audit-ready
The practical implication is that you should expect to be asked to prove your security posture, and increasingly to lose work if you cannot. Achieving Cyber Essentials gives you a recognised, evidenced baseline; documenting your controls and having a tested incident-response plan turns a nervous questionnaire into a confident, quick response. Do this ahead of time and those buyer questions become an easy “yes” rather than a last-minute scramble that delays a deal. We help clients get certified and audit-ready so security becomes a reason they win work, not a reason they lose it.
Source: ITPro, June 2026.