Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and ICO challenge myths around reporting cyber attacks

Security

NCSC and ICO challenge myths around reporting cyber attacks

In a new joint blog post, the UK's National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) have identified six misconceptions that can discourage organisations from reporting attacks - particularly ransomware attacks - and is setting out to dispel them.

Image copyright Shutterstock

The misconceptions include the mistaken belief that reporting cyber attacks to the authorities makes it more likely the incident will become public, and that paying a ransom automatically makes the incident go away.

With cyber attacks continuing to cause significant disruption, the NCSC and ICO are concerned about incidents which go unreported because every 'hushed up' case that isn't shared or fully investigated makes other attacks more likely as no one can learn from them.

Advertisement
ODU RT

However, being open with the authorities will give victims access to expert support and advice and will be taken into account favourably by the ICO when considering their regulatory response.

The six ‘myths’ which the NCSC and the ICO have identified as commonly held by organisations that have fallen victim to cyber incidents are:

  • If I cover up the attack, everything will be ok
  • Reporting to the authorities makes it more likely your incident will go public
  • Paying a ransom makes the incident go away
  • I’ve got good offline backups, I won’t need to pay a ransom
  • If there is no evidence of data theft, you don’t need to report to the ICO
  • You’ll only get a fine if your data is leaked

Eleanor Fairford, NCSC Deputy Director for Incident Management, said: “The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward.

“Keeping a cyber attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout.

Advertisement
ODU RT

“By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well break the cycle of crime to prevent others from falling victim.”

 

 

 

Advertisement
General Atomics LB
NATS, DroneCloud and Network Rail complete CNI drone trial

Aerospace Security

NATS, DroneCloud and Network Rail complete CNI drone trial

3 June 2026

NATS, DroneCloud and Network Rail have completed a major project exploring how drones could be safely used at scale around Critical National Infrastructure (CNI), including for rail inspections and incident response.

DSEI Germany adds fourth exhibition hall

Defence Security Space Events

DSEI Germany adds fourth exhibition hall

3 June 2026

The organisers of DSEI Germany have announced that, due to unprecedented industry demand, they will be opening a fourth exhibition hall ahead of its debut in March 2027.

Getac launches rugged ZX80W and ZX80W-EX tablets

Aerospace Defence Security

Getac launches rugged ZX80W and ZX80W-EX tablets

3 June 2026

Getac today announced the expansion of its ZX80 range of eight inch fully rugged tablets with the launch of the new ZX80W and ZX80W-EX, which are two lightweight, highly mobile Windows 11 devices built on ARM architecture.

Greater protection given for whistleblowing to the SIA

Security

Greater protection given for whistleblowing to the SIA

2 June 2026

The Security Industry Authority (SIA) has today been given prescribed person status under the Public Interest Disclosure Act 1998 (PIDA), following the commencement of a Statutory Instrument that was laid before Parliament on 1st May 2026.

Advertisement
ODU RT
Omnisense and 42T partner on resilient drone landing system

Aerospace Defence Security

Omnisense and 42T partner on resilient drone landing system

1 June 2026

Omnisense, which specialises in terrestrial positioning technology, has partnered with 42 Technology (42T) to demonstrate a safer autonomous drone landing system when satellite navigation signals are unreliable.

Fivecast gains UK public sector approval for police social media screening solution

Security

Fivecast gains UK public sector approval for police social media screening solution

28 May 2026

BlueLight Commercial OSINT Social Media Screening Capabilities Framework appointment gives police forces and public bodies easier access to AI-powered OSINT screening capabilities.

Advertisement
ODU RT
Advertisement
FIA2026 animated banner