---
title: "NCSC Annual Review 2025: A Call for Leadership | Firevault"
description: "Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ncsc-annual-review-2025#webpage",
      "url": "https://fire-vault.com/news/ncsc-annual-review-2025",
      "name": "NCSC Annual Review 2025: A Call for Leadership",
      "description": "Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/ncsc-annual-review-2025#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/ncsc-annual-review-2025#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NCSC Annual Review 2025: A Call for Leadership",
          "item": "https://fire-vault.com/news/ncsc-annual-review-2025"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "NCSC Annual Review 2025: A Call for Leadership",
      "description": "Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…",
      "url": "https://fire-vault.com/news/ncsc-annual-review-2025",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2025-11-07T08:24:21+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/ncsc-annual-review-2025"
      },
      "inLanguage": "en-GB",
      "articleSection": "Opinion",
      "wordCount": 823,
      "keywords": "NCSC, Opinion, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads like a warning. It captures a year in which cyber attacks stopped being technical events and became operational crises. “For too long, cyber security has been regarded as an issue for technical staff. This must change.” Richard Horne , CEO, NCS",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What boards must now prioritise?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "These are no longer “CISO questions.” They’re leadership questions. Forward-thinking leaders are already taking tangible steps to separate their most sensitive information from connected systems and create\noffline recovery vaults for clean restart capability. In an environment where every network can be reached, the ability to isolate and control data has become a defining act of resilience."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Three truths every board should …More Resources

[Knowledge Vault](/learn/knowledge)/ [Opinion](/learn/knowledge?filter=opinion)

Opinion · 7 November 2025 

# NCSC Annual Review 2025: A Call for Leadership

Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-annual-review-2025)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-annual-review-2025&text=NCSC%20Annual%20Review%202025%3A%20A%20Call%20for%20Leadership%0A%0AStop%20talking%20about%20prevention.%20Start%20building%20resilience.%20The%20National%20Cyber%20Security%20Centre%20\(NCSC\)%20Annual%20Review%202025%20doesn%E2%80%99t%20read%20like%20a%20report%2C%20it%20reads%E2%80%A6)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-annual-review-2025)[](mailto:?subject=NCSC%20Annual%20Review%202025%3A%20A%20Call%20for%20Leadership&body=Stop%20talking%20about%20prevention.%20Start%20building%20resilience.%20The%20National%20Cyber%20Security%20Centre%20\(NCSC\)%20Annual%20Review%202025%20doesn%E2%80%99t%20read%20like%20a%20report%2C%20it%20reads%E2%80%A6%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fncsc-annual-review-2025)

![An official government building entrance at dusk with warm interior light visible through glass doors](/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg)

An official government building entrance at dusk with warm interior light visible through glass doors

Why it matters

## What this means for organisations holding critical data

Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…

In this analysis

**On this page**

### **Stop talking about** **prevention. Start building resilience.**

The [National Cyber Security Centre](https://www.linkedin.com/company/national-cyber-security-centre/) **(NCSC) Annual Review 2025** doesn’t read like a report, it reads like a warning. It captures a year in which cyber attacks stopped being technical events and became operational crises.

> “For too long, cyber security has been regarded as an issue for technical staff. This must change.”
> 
> [Richard Horne](https://www.linkedin.com/in/richard-horne-0405743/), _CEO, NCSC_

That single line sets the tone for the year ahead. Cyber resilience is no longer the job of IT, it’s the responsibility of leadership.

### A changed landscape

The NCSC handled almost **1,800 cyber incidents** over the past 12 months, with **204 classed as nationally significant,** a **130%** increase year over year. Nearly half of all incidents were significant enough to impact national services, supply chains, or the wider economy.

This is the **third consecutive year** of growth in severe incidents. The trendline is clear. Attacks are more targeted, more political, and more disruptive than ever before.

The Review notes that the **“new normal”** is a threat landscape in which cyber incidents can directly affect daily life, from delayed hospital appointments to empty supermarket shelves.

It’s no longer about data loss. It’s about economic stability and public trust.

[https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025](https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025)

### The failure of pure prevention

The scale of this challenge shows that prevention alone has reached its limits. Patching, monitoring, and firewalling will always reduce risk, but not remove it.

As the NCSC notes, the defining measure of success is no longer how well you defend, but how effectively you **recover**.

**Prevention is about technology.** **Resilience is about leadership.**

Boards must now accept that _some attacks will get through_. The real test is whether the organisation can still function when they do.

## Three truths every board should take from the Review

### The scale of disruption is now systemic

204 major attacks in one year is not a technical statistic, it’s an operational reality. Businesses must assume disruption, plan for continuity, and rehearse recovery.

Resilience means being able to absorb impact and maintain critical operations not just survive the headlines.

### The battleground has shifted

The Review highlights how attackers are moving up the chain. Cloud identity, authentication, and trusted integrations are now the preferred routes in. The perimeter has disappeared, and trust has become the new target.

Boards must understand where their critical assets really live and who has the power to reach them.

### Resilience is the new definition of leadership

The UK government has written directly to CEOs and Chairs, making cyber resilience a **board-level duty**. Neglecting it is no longer an operational weakness; it’s a governance failure.

Boards must take ownership, allocate accountability, and demand evidence that continuity plans work.

> “The buck stops with us as senior leaders. Please continue to consider the best route to protecting your business, but also the best means to defend against an attack, including supporting customers and colleagues, at every possible stage.”
> 
> [Shirine Khoury-Haq](https://www.linkedin.com/in/shirine-khoury-haq-92b5a11/), _CEO,_ [Co-op](https://www.linkedin.com/company/the-co-op-group/)

The Co-op’s open letter to business leaders is one of the most honest reflections of what a cyber event feels like inside the boardroom. It echoes the NCSC’s message that resilience isn’t theory, it’s a responsibility.

### What boards must now prioritise?

-   **Continuity:** Can your organisation operate for 24 hours without IT?
-   **Recovery:** Do you have a clean, trusted recovery source?
-   **Governance:** Who owns resilience in your board structure?
-   **Evidence:** When did you last test and time your recovery plan?

These are no longer “CISO questions.” They’re leadership questions.

Forward-thinking leaders are already taking tangible steps **to separate their most sensitive information from connected systems and create** **offline recovery vaults** for clean restart capability. In an environment where every network can be reached, the ability to isolate and control data has become a defining act of resilience.

### From national guidance to board action

The **NCSC Annual Review 2025** isn’t just an assessment of risk, it’s a blueprint for change. It pushes resilience up the chain of command and embeds it as part of responsible governance.

Resilience is now the measure of leadership in a connected world.

Boards that plan for failure, rehearse continuity, and manage recovery will define the next era of responsible business. Those that don’t will learn the hard way that **cyber is no longer a technical risk, it’s an existential one.**

At [Firevault Limited](https://www.linkedin.com/company/firevault-limited/) , We share the NCSC’s belief that resilience must be built, tested, and evidenced. Our work with business leaders focuses on continuity and control ensuring that when the worst happens, critical data and decisions are protected inside [**Vault**](/vault), the offline safety deposit box for the information that keeps organisations moving.

Because when everything is connected, the ability to disconnect safely becomes leadership in practice.

### Our reflection

The NCSC has done its part. It has given business leaders clarity, urgency, and direction. The next step belongs to the boardroom.

**Defence reduces risk. Resilience ensures survival. Leadership delivers both.**

👉 Read the NCSC Annual Review 2025: [www.ncsc.gov.uk](http://www.ncsc.gov.uk/) #CyberResilience #Leadership #NCSC #Governance #BoardResponsibility #Coop #Firevault #Vault

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Zero-Copy Cloud is Not the End of Lock-In. It is the Start of a New One](/__l5e/assets-v1/13d1c397-693e-44a7-b9e6-67b730df160d/zero-copy-cloud-lock-in-2026-2x.jpg)

Opinion 

### Zero-Copy Cloud is Not the End of Lock-In. It is the Start of a New One

SAP and Google Cloud have made data migration quietly optional. The data stays put. The operating judgment built above it does not. That is the lock-in the architecture diagram will never show.

29 Jul 2026 4 min 







](/news/zero-copy-cloud-lock-in-opinion-2026)[

![World Backup Day 2026: Backups Are Not Enough](/__l5e/assets-v1/d7a77b5b-74d6-4c42-88b9-4e64057bbe9f/world-backup-day-2026-2x.jpg)

Opinion 

### World Backup Day 2026: Backups Are Not Enough

Every 31 March, World Backup Day reminds organisations to protect their data. But in 2026, the real question is not whether you back up. It is whether your backups can survive the attack that is coming for them.

31 Mar 2026 5 min 







](/news/world-backup-day-2026-why-backups-alone-are-not-enough)[

![Offline by Default: UK 2025 Breaches Survey](/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg)

Opinion 

### Offline by Default: UK 2025 Breaches Survey

The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…

7 Nov 2025 4 min 







](/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders)[

![Retail Exposure Crisis: Policy Pressure and Breach Wave](/__l5e/assets-v1/2b8767ec-6dad-4df5-86ba-14ee23170188/retail-exposure-crisis-1771248346427-2x.jpg)

Opinion 

### Retail Exposure Crisis: Policy Pressure and Breach Wave

2025: When Cybersecurity Became a Political Issue Parliament is asking a blunt question: “Why are UK retailers still leaking customer data?” Major breaches…

23 May 2025 3 min 







](/news/retails-exposure-crisis-policy-pressure-political-fallout-and-the-breach-wave-only-firevault-can-halt)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)