The National Cyber Security Centre revealed this week that it managed more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026 — and around three-quarters of those are believed to be linked to hostile states, including Russia, China and Iran. The target isn’t just power stations and water companies. It’s the much wider “ecosystem” around them: the contractors, software vendors, professional services firms, and small suppliers that connect into bigger organisations.
That last part is the bit UK SMEs tend to miss. Most small businesses assume state-linked hacking is somebody else’s problem — a concern for energy giants and defence contractors, not a ten-person consultancy or a regional IT reseller. The NCSC’s own assessment says otherwise: attackers actively probe smaller, weaker-defended suppliers specifically because they offer a quieter route into a bigger, better-defended client.
Why your size makes you a target, not a shield
If your business holds a supplier contract, a maintenance agreement, or system access with a larger client — a hospital trust, a utility, a financial services firm, a local authority — you are part of that client’s attack surface, whether you think of yourself that way or not. A state-linked group doesn’t need to break into a well-defended enterprise directly if it can compromise a smaller partner’s remote access credentials first and walk in through the front door.
The NCSC’s advice for this kind of exposure is deliberately unglamorous: multi-factor authentication on every account, no shared admin logins, prompt patching of anything internet-facing, and a proper review of which third parties can reach your systems — and which of your systems can reach theirs. None of this requires a security team. It requires someone actually doing it, on a schedule, rather than assuming it’s already been handled.
The questions to ask this month
Who has standing access into your systems, and do they still need it? Old contractor logins, dormant integrations, and unused API keys are exactly the sort of long-forgotten access route this kind of attacker looks for.
If a client asked you to prove your security posture tomorrow, could you? Increasingly, larger organisations are pushing security questionnaires and Cyber Essentials requirements down onto their supply chain. Getting ahead of that now is far cheaper than scrambling when a contract renewal depends on it.
Would you know if something had already happened? State-linked intrusions are built to be quiet — the NCSC’s own figures on incident volumes only capture what’s been detected. Basic monitoring and logging, even lightweight versions, are what turns “we think we’re fine” into “we can actually tell.”
This is where a firm like KeepSafe earns its keep — ongoing cyber incident monitoring gives smaller businesses the same kind of early-warning visibility that larger organisations take for granted, without needing an in-house security operations centre.
Looking further ahead
The NCSC also flagged a longer-term concern worth filing away: it expects AI-enabled tools to let attackers exploit known vulnerabilities in legacy technology at scale by 2028. That’s a reminder that “we’ll patch it eventually” is a shrinking strategy — the gap between a vulnerability becoming known and it being exploited automatically at scale is only going to narrow. Businesses running older, unsupported systems because “they still work fine” are the ones most exposed once that shift arrives.
The takeaway
You don’t need to run national infrastructure to be caught up in an attack on it. If your business connects into a bigger organisation’s systems in any way — as a supplier, a contractor, or a service provider — this week’s NCSC warning is a prompt to check who can access what, close the gaps you find, and make sure you’d actually notice if something went wrong.