Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC marks 20th anniversary of first response to state-sponsored cyber attack

Security

NCSC marks 20th anniversary of first response to state-sponsored cyber attack

The National Cyber Security Centre (NCSC) has marked the 20th anniversary of GCHQ’s first response to a cyber attack perpetrated against the UK Government by another state, with the response acting as the forerunner to a capability that became the National Cyber Security Centre, a part of GCHQ.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simone Flamigni / copyright Shutterstock

In June 2003, GCHQ experts were involved in responding to a cyber attack against the UK Government for the first time. Unlike today, in 2003 there was no government agency set up to deal with cyber attacks, nor was there a dedicated national incident management function. This all changed in 2016 with the establishment of the National Cyber Security Centre (NCSC), a part of GCHQ.

Advertisement
PTC rectangle

The NCSC can reveal that in June 2003 cyber experts were called upon to investigate after a government employee detected suspicious activity on one of their workstations.

A suspected phishing email had been identified, so technical specialists sought help from the Communications-Electronics Security Group (CESG) – the information assurance arm of GCHQ at that time.

CESG’s analysis discovered that malware, designed to steal sensitive data and evade anti-virus products, had been installed, raising suspicions about the attacker’s intent and setting in motion a series of actions that was transformative to cyber incident investigations.

For the first time, GCHQ fused its signals intelligence capabilities with its cyber security function to investigate and identify the actor responsible.

The ground-breaking analysis, coupled with international engagement, led CESG to conclude the intent of the attack had been cyber espionage by a nation state, setting in train a mission that today is at the heart of NCSC operations; namely, understanding and responding to cyber threats to the UK.

Paul Chichester, Director of Operations at the National Cyber Security Centre, said: “Twenty years ago, we were just crossing the threshold of the cyber attack arena, and this incident marked the first time that GCHQ was involved in a response to an incident affecting the UK Government.

Advertisement
ODU RT

“It was also the first time that the UK and Europe started to understand the potential online risks we faced and our response transformed how we investigate and defend against such attacks.

“The NCSC and our allies have come such a long way since this incident, and it is reassuring to be at the forefront of efforts to develop tools and techniques to defend against cyber threats and keep our respective nations safe online.”

The National Cyber Security Centre, a part of GCHQ, was set up in October 2016 to help keep the UK safe online. It combined existing expertise from CESG, the Centre for Cyber Assessment, CERT-UK and the Centre for Protection of National Infrastructure (now the National Protective Security Authority).

The NCSC responds to cyber security incidents to help reduce the harm they cause to organisations and the wider UK, as well as working with other law enforcement, defence, the UK’s intelligence and security agencies and international partners.

 

Advertisement
General Atomics LB
Cranfield appoints Prof Mark Westwood as Director of Defence and Security

Defence Security

Cranfield appoints Prof Mark Westwood as Director of Defence and Security

13 February 2026

Professor Mark Westwood has been appointed the new Director of Theme for Defence and Security at Cranfield University, a post he will take up on 1st March 2026.

UK to lead multinational cyber defence exercise from Singapore

Defence Security Events

UK to lead multinational cyber defence exercise from Singapore

13 February 2026

The UK will lead the multinational defensive cyber exercise Defence Cyber Marvel (DCM) 2026, a multilateral cyber defence exercise conducted by the British Army Cyber Association.

AAIB appoints Robert Balls as Chief Inspector of Air Accidents

Aerospace Security

AAIB appoints Robert Balls as Chief Inspector of Air Accidents

12 February 2026

The Air Accidents Investigation Branch (AAIB) has announced the appointment of Robert Balls as Chief Inspector of Air Accidents following a fair and open competition.

British Transport Police launch LFR tech trial

Security

British Transport Police launch LFR tech trial

12 February 2026

British Transport Police (BTP) launched a trial of Live Facial Recognition (LFR) technology yesterday afternoon at London Bridge railway station.

Advertisement
Security & Policing Rectangle
Avon Protection launches EXOSKIN-S2 CBRN protective suit

Defence Security

Avon Protection launches EXOSKIN-S2 CBRN protective suit

11 February 2026

Avon Protection has expanded its EXOSKIN protective ensemble range with the EXOSKIN-S2 high-performance CBRN suit, designed for operators in the military, first responder and special forces segments.

Darktrace releases Darktrace / SECURE AI

Security

Darktrace releases Darktrace / SECURE AI

10 February 2026

Darktrace has introduced Darktrace / SECURE AI, a new behavioural AI security product designed to help enterprises deploy and scale artificial intelligence by understanding how AI systems behave, interact with other systems and humans and evolve over time.

Advertisement
Security & Policing Rectangle
Advertisement
ECS leaderboard banner