UK adds cyberattacks on critical systems to National Risk Register

The UK government has added cyberattacks targeting data infrastructure, water systems and police networks to its 2026 National Risk Register, which outlines the most serious risks facing the country.

The updated register also includes “digital resilience failure” as a new risk, drawing on lessons from the July 2024 CrowdStrike outage. The government cited the increasing sophistication of artificial intelligence as one factor affecting the cyber threat landscape.

The UK plans to conduct its largest home defense exercise in decades in 2027, testing government and public-sector responses to hybrid threats including cyberattacks, disinformation and critical infrastructure sabotage.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Seven new risks on the UK’s National Risk Register. The one that undermines the rest is “interference in democratic processes.” Every other addition, cyberattacks on water operational technology (OT), police networks and colocation data centers, has an identifiable technical failure state and a technical remediation path. Democratic interference does not. Once the integrity of the information environment becomes a national security risk, someone in government must decide what constitutes manipulation, disinformation, or an unacceptable influence operation. Those are political judgments, and the standards will change with the government making them.

   “Operation Albiston Shadow, the UK’s largest home defense exercise in decades, is supposed to test readiness for cyberattacks and infrastructure sabotage. To the extent the scenario requires officials to adjudicate information quality, it stops being a purely technical drills.

   “The technical risks themselves are overdue, though I’d feel better if the UK’s follow-through matched the announcements. In just over a week, the government released Cyber Shield’s blueprint for autonomous AI defense at machine speed, the Risk Register update and Albiston Shadow. Three announcements centered on identifying, modeling, and exercising risk, with no funded remediation commensurate with the risks being announced. The National Audit Office (NAO) reported in January 2025 that departments were running at least 228 legacy IT systems and lacked fully funded remediation plans for 120 of them, 53%.

   “Discovery is the easy part. Critical infrastructure teams too often avoid testing production OT because they lack the tooling or the risk appetite to touch systems that can’t go down. The vulnerability scan runs on the IT side, the OT side gets a paper assessment, and the exercise report says “tested.” That’s how exercises become security theater. Albiston Shadow runs in 2027, and without funded remediation, it risks testing many of the same weaknesses the government already knows about.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “The most significant development in the UK’s National Risk Register isn’t simply the recognition of growing cyber threats, it’s the recognition that digital resilience is now a national resilience issue. The strategic question is not whether we can prevent every cyber attack, it is whether society can continue functioning when digital systems fail.”

   “This is part of a broader international shift. In the United States, initiatives such as the June AI Executive Order, the Gold Eagle public-private cybersecurity partnership, and increasingly realistic resilience exercises all point toward the same conclusion: cybersecurity must evolve to address cyber civil defense. Governments don’t own most critical infrastructure, so resilience must be built through trusted public-private partnerships, shared situational awareness, and a collective defense which measures and addresses the exposures before a real crisis reveals them. Plans don’t build resilience. Realistic adversarial emulation, quantitative performance metrics, and OODA loops do.”

   “Artificial intelligence is accelerating this transformation for both attackers and defenders. Human-speed defensive workflows will increasingly struggle to keep pace with machine-speed offensive operations. The limiting factor is no longer finding flaws, but the speed and effectiveness of coordinated response. Ultimately, success should be measured not simply by whether attackers gained access, but by whether essential services remained available and recovered quickly when disruption occurred, and whether the attack remains contained, or affects adjacent infrastructures.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “The UK government putting cyberattacks on the same list as floods and pandemics is a policy signal worth reading carefully.

   “What stands out to me about the UK’s approach is the inclusion of digital resilience failure as a distinct risk, because the CrowdStrike outage showed that the most disruptive events can originate inside your own trusted systems, not from an adversary at all.

   “The 2027 exercise is the right instinct, but the gap between planning for a scenario and actually being prepared for it is where most organizations need to focus on closing.”

The USA should copy the UK as clearly the UK are on the right side of history.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading