Special Briefing — Russia Cyber Threat to UK Businesses & CNI

šŸŽ§ Listen to this episode  |  Subscribe to the podcast feed

A special advisory episode produced in response to Russia's warning to the UK following continued support for Ukraine, including the supply of drone systems.

The Threat Actors

Sandworm (GRU Unit 74455) — The most dangerous Russian state actor targeting critical infrastructure. Responsible for attacks on Ukraine's power grid, the NotPetya malware (~$10B global damage), and the most sophisticated OT/ICS attacks ever documented. Primary threat to energy, water, transport, and defence-adjacent manufacturing.

APT29 / Cozy Bear (SVR) — Long-term stealthy access and intelligence collection. Specialises in supply chain compromise (SolarWinds). Targets government, defence, and technology organisations.

APT28 / Fancy Bear (GRU Unit 26165) — Credential theft and spear phishing at scale. Previously targeted UK political organisations, think tanks, and defence contractors.

Killnet / NoName057(16) — Russian state-aligned hacktivist groups conducting DDoS against NATO countries. Less sophisticated but disruptive. Target public-facing infrastructure.

UK Sectors at Highest Risk

  • Energy — Gas distribution, electricity grid, renewable generation, and supply chain contractors with OT/remote access
  • Water & Wastewater — OT access is a low-sophistication, high-impact target
  • Telecoms — High-value for disruption and intelligence collection
  • Defence Supply Chain — Manufacturers, logistics, component suppliers, and software vendors supplying MoD or contractors
  • Finance — DDoS, fraud, and market disruption

Immediate Actions for UK Businesses & CNI Operators

  1. Patch perimeter devices now — Priority on VPN appliances, remote access tools, and network edge kit (Fortinet, Cisco, Palo Alto, Ivanti). Russian actors consistently exploit known perimeter vulnerabilities for initial access.
  2. Enforce MFA everywhere — On all remote access paths and privileged accounts. Credential theft is APT28's primary tool; MFA stops most of it.
  3. Segment OT from IT — If you operate OT or ICS systems, ensure they are network-segregated. Remote access to OT must be off by default, require explicit authorisation, and be monitored in real time.
  4. Run a tabletop exercise — Test your incident response against a scenario combining a disruptive cyber attack with a concurrent geopolitical or physical event. Know your playbook before the incident.
  5. Audit supply chain access — Identify suppliers with remote access to your systems. Ensure they meet the same security baseline you apply internally. APT29 uses weaker suppliers to reach hardened targets.
  6. Report to NCSC — Use the Early Warning Service and Suspicious Email Reporting Service. Both are free and actively monitored.

NCSC Resources

Show Comments