Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and ICO challenge myths around reporting cyber attacks

Security

NCSC and ICO challenge myths around reporting cyber attacks

In a new joint blog post, the UK's National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) have identified six misconceptions that can discourage organisations from reporting attacks - particularly ransomware attacks - and is setting out to dispel them.

Image copyright Shutterstock

The misconceptions include the mistaken belief that reporting cyber attacks to the authorities makes it more likely the incident will become public, and that paying a ransom automatically makes the incident go away.

With cyber attacks continuing to cause significant disruption, the NCSC and ICO are concerned about incidents which go unreported because every 'hushed up' case that isn't shared or fully investigated makes other attacks more likely as no one can learn from them.

Advertisement
ODU RT

However, being open with the authorities will give victims access to expert support and advice and will be taken into account favourably by the ICO when considering their regulatory response.

The six ‘myths’ which the NCSC and the ICO have identified as commonly held by organisations that have fallen victim to cyber incidents are:

  • If I cover up the attack, everything will be ok
  • Reporting to the authorities makes it more likely your incident will go public
  • Paying a ransom makes the incident go away
  • I’ve got good offline backups, I won’t need to pay a ransom
  • If there is no evidence of data theft, you don’t need to report to the ICO
  • You’ll only get a fine if your data is leaked

Eleanor Fairford, NCSC Deputy Director for Incident Management, said: “The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward.

“Keeping a cyber attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout.

Advertisement
Security & Policing Rectangle

“By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well break the cycle of crime to prevent others from falling victim.”

 

 

 

Advertisement
Cranfield University
Birmingham Airport switching to sustainable lights with high-mast upgrade

Aerospace Security

Birmingham Airport switching to sustainable lights with high-mast upgrade

28 October 2025

Birmingham Airport (BHX) has continued its switch to more energy-efficient lighting with a high-mast LED upgrade.

Ella Haapiainen appointed Head of Siemens Advanta, Great Britain & Ireland

Aerospace Defence Security

Ella Haapiainen appointed Head of Siemens Advanta, Great Britain & Ireland

27 October 2025

Siemens has appointed Ella Haapiainen to lead its consultancy arm, Siemens Advanta, in the UK and Ireland, with a mission to help organisations tackle key challenges including digitalisation, decarbonisation and operational efficiency.

UK issues safeguards against supply chain ransomware attacks

Security

UK issues safeguards against supply chain ransomware attacks

27 October 2025

Critical businesses and services will be better safeguarded from costly cyber-attacks under new international guidance issued by the UK and Singapore.

NPAS featured in BBC phone theft documentary

Aerospace Security

NPAS featured in BBC phone theft documentary

27 October 2025

The National Police Air Service (NPAS) has been featured in the BBC documentary On the Front Line: Fighting the Phone Snatchers, now available to stream on BBC iPlayer.

Advertisement
Security & Policing Rectangle
Darktrace enhances its ActiveAI Security Platform

Security

Darktrace enhances its ActiveAI Security Platform

24 October 2025

Darktrace has announced a wave of innovations across its ActiveAI Security Platform to protect organisations from increasingly complex, multivector and novel attacks, extending novel threat detection and autonomous investigations across email, network, OT, cloud and SaaS and consequently delivering deeper endpoint visibility than ever ...

UK CSOs warn of threat to executives

Security

UK CSOs warn of threat to executives

23 October 2025

More chief security officers (CSOs) in the UK than anywhere else in Europe are providing senior executives such as CEOs and CFOs with close protection officers, protection for executives’ family members, personal protective equipment, online threat monitoring and enhanced security procedures to mitigate the threats posed to executives.

Advertisement
ODU RT