Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and ICO challenge myths around reporting cyber attacks

Security

NCSC and ICO challenge myths around reporting cyber attacks

In a new joint blog post, the UK's National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) have identified six misconceptions that can discourage organisations from reporting attacks - particularly ransomware attacks - and is setting out to dispel them.

Image copyright Shutterstock

The misconceptions include the mistaken belief that reporting cyber attacks to the authorities makes it more likely the incident will become public, and that paying a ransom automatically makes the incident go away.

With cyber attacks continuing to cause significant disruption, the NCSC and ICO are concerned about incidents which go unreported because every 'hushed up' case that isn't shared or fully investigated makes other attacks more likely as no one can learn from them.

Advertisement
ODU RT

However, being open with the authorities will give victims access to expert support and advice and will be taken into account favourably by the ICO when considering their regulatory response.

The six ‘myths’ which the NCSC and the ICO have identified as commonly held by organisations that have fallen victim to cyber incidents are:

  • If I cover up the attack, everything will be ok
  • Reporting to the authorities makes it more likely your incident will go public
  • Paying a ransom makes the incident go away
  • I’ve got good offline backups, I won’t need to pay a ransom
  • If there is no evidence of data theft, you don’t need to report to the ICO
  • You’ll only get a fine if your data is leaked

Eleanor Fairford, NCSC Deputy Director for Incident Management, said: “The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward.

“Keeping a cyber attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout.

Advertisement
ODU RT

“By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well break the cycle of crime to prevent others from falling victim.”

 

 

 

Advertisement
Gulfstream banner
MGI conducts first TigerShark flights with Auterion

Aerospace Defence Security

MGI conducts first TigerShark flights with Auterion

2 April 2026

MGI Engineering Ltd (MGI) has announced the successful first flights of its TigerShark uncrewed deep strike platform, in partnership with Auterion.

Logiq acquires Savient

Security

Logiq acquires Savient

1 April 2026

Logiq has acquired Savient Ltd, a technology and data specialist focused on delivery in highly regulated environments, strengthening its capability and further expanding its presence in the South-West.

SIA introduces changes for close protection operatives

Security

SIA introduces changes for close protection operatives

1 April 2026

Today, the Security Industry Authority (SIA) have introduced changes to training for those holding, or applying for, a close protection licence.

NCSC warns of messaging app targeting

Security

NCSC warns of messaging app targeting

1 April 2026

Alongside international partners, the National Cyber Security Centre (NCSC) has issued actions for individuals at risk of attacks against messaging apps, as a result of growing malicious activity from Russia-based actors using messaging apps - such as WhatsApp, Messenger and Signal - to target high-risk individuals.

Advertisement
ODU RT
LexisNexis Risk Solutions releases Cybercrime Report

Security

LexisNexis Risk Solutions releases Cybercrime Report

31 March 2026

LexisNexis Risk Solutions has released its latest Cybercrime Report which reveals rapid growth in synthetic identity fraud, bot-driven attacks and account takeover activity across global markets, whilst first-party fraud remains the most reported fraud type.

Getac launches CommandCore

Defence Security

Getac launches CommandCore

27 March 2026

Getac has announced the launch of its CommandCore rugged drone control solution.

Advertisement
ODU RT
Advertisement
FIA2026 animated banner