Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC marks 20th anniversary of first response to state-sponsored cyber attack

Security

NCSC marks 20th anniversary of first response to state-sponsored cyber attack

The National Cyber Security Centre (NCSC) has marked the 20th anniversary of GCHQ’s first response to a cyber attack perpetrated against the UK Government by another state, with the response acting as the forerunner to a capability that became the National Cyber Security Centre, a part of GCHQ.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simone Flamigni / copyright Shutterstock

In June 2003, GCHQ experts were involved in responding to a cyber attack against the UK Government for the first time. Unlike today, in 2003 there was no government agency set up to deal with cyber attacks, nor was there a dedicated national incident management function. This all changed in 2016 with the establishment of the National Cyber Security Centre (NCSC), a part of GCHQ.

Advertisement
Security & Policing Rectangle

The NCSC can reveal that in June 2003 cyber experts were called upon to investigate after a government employee detected suspicious activity on one of their workstations.

A suspected phishing email had been identified, so technical specialists sought help from the Communications-Electronics Security Group (CESG) – the information assurance arm of GCHQ at that time.

CESG’s analysis discovered that malware, designed to steal sensitive data and evade anti-virus products, had been installed, raising suspicions about the attacker’s intent and setting in motion a series of actions that was transformative to cyber incident investigations.

For the first time, GCHQ fused its signals intelligence capabilities with its cyber security function to investigate and identify the actor responsible.

The ground-breaking analysis, coupled with international engagement, led CESG to conclude the intent of the attack had been cyber espionage by a nation state, setting in train a mission that today is at the heart of NCSC operations; namely, understanding and responding to cyber threats to the UK.

Paul Chichester, Director of Operations at the National Cyber Security Centre, said: “Twenty years ago, we were just crossing the threshold of the cyber attack arena, and this incident marked the first time that GCHQ was involved in a response to an incident affecting the UK Government.

Advertisement
ODU RT

“It was also the first time that the UK and Europe started to understand the potential online risks we faced and our response transformed how we investigate and defend against such attacks.

“The NCSC and our allies have come such a long way since this incident, and it is reassuring to be at the forefront of efforts to develop tools and techniques to defend against cyber threats and keep our respective nations safe online.”

The National Cyber Security Centre, a part of GCHQ, was set up in October 2016 to help keep the UK safe online. It combined existing expertise from CESG, the Centre for Cyber Assessment, CERT-UK and the Centre for Protection of National Infrastructure (now the National Protective Security Authority).

The NCSC responds to cyber security incidents to help reduce the harm they cause to organisations and the wider UK, as well as working with other law enforcement, defence, the UK’s intelligence and security agencies and international partners.

 

Advertisement
Babcock LB Babcock LB
Navantia UK targets  500 apprentices by 2030

Defence Security

Navantia UK targets  500 apprentices by 2030

5 February 2026

Navantia UK has set a target of hiring 500 apprentices by 2030 to support the business’s expansion in shipbuilding, engineering and in supplying the offshore energy industry. 

NCA and NatWest partner to address Invoice Fraud

Security

NCA and NatWest partner to address Invoice Fraud

4 February 2026

The National Crime Agency (NCA) and NatWest Group have launched a joint campaign aimed at accounts payable professionals and finance personnel that highlights the risks of Invoice Fraud, a crime that costs businesses millions each year.

Returning to STEM after career break becomes harder than ever

Aerospace Defence Security Space

Returning to STEM after career break becomes harder than ever

4 February 2026

Returning to STEM industries after a career break is now harder than ever, according to new research by STEM Returners, with bias against gender, age, ethnicity and a lack of recent experience penalising highly qualified people from getting a job.

UK-Japan partnerships advance quantum and future connectivity tech

Aerospace Defence Security Space

UK-Japan partnerships advance quantum and future connectivity tech

4 February 2026

Joint investments will advance quantum technology, boost digital connectivity and strengthen network resilience against cyber threats.

Advertisement
PTC rectangle
Blighter boosts stealth of e-scan radars

Defence Security

Blighter boosts stealth of e-scan radars

4 February 2026

Blighter Surveillance Systems has further boosted the stealth characteristics of its e-scan radars to better serve the growing number of developers of crewed and autonomous multisensor surveillance vehicles and platforms.

Defence personnel to gain greater powers to defeat drones

Defence Security

Defence personnel to gain greater powers to defeat drones

3 February 2026

The security of key military sites will be strengthened as Defence personnel will be given stronger powers to defeat drones near bases as part of new measures being introduced in the Armed Forces Bill.

Advertisement
PTC rectangle
Advertisement
ECS leaderboard banner