š§ Listen to this episode | Subscribe to the podcast feed
A special advisory episode produced in response to Russia's warning to the UK following continued support for Ukraine, including the supply of drone systems.
The Threat Actors
Sandworm (GRU Unit 74455) ā The most dangerous Russian state actor targeting critical infrastructure. Responsible for attacks on Ukraine's power grid, the NotPetya malware (~$10B global damage), and the most sophisticated OT/ICS attacks ever documented. Primary threat to energy, water, transport, and defence-adjacent manufacturing.
APT29 / Cozy Bear (SVR) ā Long-term stealthy access and intelligence collection. Specialises in supply chain compromise (SolarWinds). Targets government, defence, and technology organisations.
APT28 / Fancy Bear (GRU Unit 26165) ā Credential theft and spear phishing at scale. Previously targeted UK political organisations, think tanks, and defence contractors.
Killnet / NoName057(16) ā Russian state-aligned hacktivist groups conducting DDoS against NATO countries. Less sophisticated but disruptive. Target public-facing infrastructure.
UK Sectors at Highest Risk
- Energy ā Gas distribution, electricity grid, renewable generation, and supply chain contractors with OT/remote access
- Water & Wastewater ā OT access is a low-sophistication, high-impact target
- Telecoms ā High-value for disruption and intelligence collection
- Defence Supply Chain ā Manufacturers, logistics, component suppliers, and software vendors supplying MoD or contractors
- Finance ā DDoS, fraud, and market disruption
Immediate Actions for UK Businesses & CNI Operators
- Patch perimeter devices now ā Priority on VPN appliances, remote access tools, and network edge kit (Fortinet, Cisco, Palo Alto, Ivanti). Russian actors consistently exploit known perimeter vulnerabilities for initial access.
- Enforce MFA everywhere ā On all remote access paths and privileged accounts. Credential theft is APT28's primary tool; MFA stops most of it.
- Segment OT from IT ā If you operate OT or ICS systems, ensure they are network-segregated. Remote access to OT must be off by default, require explicit authorisation, and be monitored in real time.
- Run a tabletop exercise ā Test your incident response against a scenario combining a disruptive cyber attack with a concurrent geopolitical or physical event. Know your playbook before the incident.
- Audit supply chain access ā Identify suppliers with remote access to your systems. Ensure they meet the same security baseline you apply internally. APT29 uses weaker suppliers to reach hardened targets.
- Report to NCSC ā Use the Early Warning Service and Suspicious Email Reporting Service. Both are free and actively monitored.