Wednesday, 30 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Whitehall’s Russia briefings must not stop at the boardroom door

Dan Jarvis will brief critical infrastructure chief executives on Russian cyberattacks, sabotage and disinformation. But the threat arrives through operational technology, remote access and suppliers, and only 15% of UK businesses review the risks their immediate suppliers pose

VETTDD Cybersecurity section card
Image: VETTDD
In brief
  • The Cabinet Office and Ministry of Defence announced closed-door Russia threat briefings on 25 September for industry bodies representing CNI providers and defense firms, chaired by Dan Jarvis and Louise Sandher-Jones.
  • The NCSC handled 429 incidents in the year to August 2025 and rated 204 of them nationally significant, more than double the 89 of the year before, according to its Annual Review 2025.
  • CNI security leaders should decide now how the briefing content reaches their own teams and the suppliers that hold their credentials, and hold those suppliers to the duties in the Cyber Security and Resilience Bill.

On 25 September the Cabinet Office and the Ministry of Defence announced closed-door briefings on the threat from Russia. Security minister Dan Jarvis will chair a session with the industry bodies that represent critical national infrastructure (CNI) providers. Louise Sandher-Jones, minister for the armed forces, will chair a second for the bodies that represent defense firms. The release lists the tactics at issue as cyberattacks, sabotage and disinformation, and says the sessions will sit alongside the support the National Cyber Security Centre (NCSC), the National Protective Security Authority (NPSA) and the Civil Nuclear Constabulary already provide.

“Strong defences are built on a clear understanding of the threat,” Jarvis, security minister since July 2026 across the Home Office and the Cabinet Office, says in the release. The sessions, he says, will focus on the actions organizations can take in partnership with government. Sandher-Jones says Russia “is actively seeking to disrupt the organisations that form the bedrock of our national security”. No date is given and the release carries no figures.

The invitees are industry bodies; the audience is chief executives. The release does not mention the security teams, or the managed service providers and managed security service providers (MSSPs), that run those operators’ service desks, security operations centers, remote access and firewalls. Those are the people who would act on the intelligence first, and the release says nothing about how it reaches them.

That gap matters because the government’s own paperwork says attacks through managed service providers are increasing. Security leaders and boards in energy, water, transport, health and defense should decide now how what their chief executive hears reaches the people who run operational technology (OT) and remote access, and the suppliers who hold the credentials, and hold those suppliers to the duties the Cyber Security and Resilience Bill would place on them.

The weak link Whitehall already knows about

The factsheets the Department for Science, Innovation and Technology (DSIT) published for the bill, updated in June 2026, say MSPs often hold wide and trusted access to clients’ systems, and that a single compromise can have a ‘one to many’ effect. They cite the May 2024 incident in which an attack through an MSP reached the Ministry of Defence’s payroll and put the personal data of around 270,000 serving personnel, reservists and veterans at high risk. That is the department that wrote the bill explaining why MSPs have become an increasingly attractive target.

The NCSC added its own warning on 27 August, in an alert on internet-exposed systems and edge devices. It says it has seen increased targeting of OT across multiple sectors, including in the UK, and assesses that the threat from state use of offensive cyber, including outside of conflict, “has almost certainly increased”. Its eight priority actions – an inventory of OT assets, no direct internet exposure, replaced default credentials, segmented networks and tested backups among them – are work for the engineers, in-house or contracted, who run those systems, not for the chief executive who will hear the briefing.

The figures the release left out

The release gives no numbers, so here are the government’s. The NCSC’s Annual Review 2025, published in October 2025, says its incident management team handled 429 incidents between September 2024 and August 2025, of which 204 – 48% – were nationally significant, up from 89 the year before.

DSIT’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 from Ipsos fieldwork between August and December 2025, found that 43% of UK businesses identified a breach or attack in the previous 12 months, about 612,000 businesses, rising to 69% of large businesses. The same survey found that only 15% of businesses reviewed the risks posed by their immediate suppliers and 6% looked at their wider supply chain. For a CNI operator, the MSP with remote access is one of them.

Three things to do now

The first is to decide who receives the intelligence. Where a CNI operator uses an MSP or MSSP to run its service desk or security operations center, the contract between them is the place to start. Put in writing, before the briefing, how what the chief executive hears will reach the security team and those suppliers. An operator that kept the briefing from the firm running its security operations center would struggle to explain that after an incident.

The second is the bill itself, which was still before the House of Lords in September. Its factsheets say medium and large MSPs that meet the definition of a relevant managed service provider will come under the Network and Information Systems (NIS) Regulations 2018, with duties to manage the risks to the systems their service relies on and to report significant incidents. Regulators could also designate critical suppliers, small MSPs included. Operators need not wait for the bill to ask their suppliers the same: which systems the service relies on, how their risks are managed and how an incident would be reported. Suppliers with access across many customers face that question at scale.

The third needs no invitation. The NCSC alert of 27 August is public, specific and written for the organizations that run OT. A water company or a hospital trust can put its eight actions to its own engineers and to the MSSP that runs its firewalls, ask for evidence against each one, and register for the Early Warning service, as the NCSC asks.

A briefing for chief executives is the right start. But the threat the ministers describe does not arrive in the boardroom. It arrives through a remote-access tool, a service desk ticket or a firewall nobody inventoried, and the people who own those are nowhere in the release. Boards that hear the briefing should treat passing it on – to their own security teams and to every supplier that holds their credentials – as its first action.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Cabinet Office and Ministry of Defence, “CEOs from sensitive sectors to receive briefings on Russia threats”, press release, 25 September 2026. https://www.gov.uk/government/news/ceos-from-sensitive-sectors-to-receive-briefings-on-russia-threats
  2. GOV.UK, “Dan Jarvis”, ministerial profile (Minister of State (Security Minister), Home Office and Cabinet Office, appointed 21 July 2026). https://www.gov.uk/government/people/dan-jarvis
  3. National Cyber Security Centre, “Disruptive cyber activity highlights risk from internet-exposed systems and edge devices”, alert, 27 August 2026. https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices
  4. National Cyber Security Centre, “NCSC Annual Review 2025: Incident management”, 14 October 2025. https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025/chapter-01-cyber-threat-to-the-uk/incident-management
  5. Department for Science, Innovation and Technology, “Cyber Security Breaches Survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
  6. Department for Science, Innovation and Technology, “Cyber Security and Resilience (Network and Information Systems) Bill: factsheets – Relevant managed service providers”, updated 30 June 2026. https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/relevant-managed-service-providers
  7. Department for Science, Innovation and Technology, “Cyber Security and Resilience (Network and Information Systems) Bill: factsheets – Designating critical suppliers”, updated 30 June 2026. https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/designating-critical-suppliers
  8. UK Parliament, “Cyber Security and Resilience (Network and Information Systems) Bill”, bill page (current house: Lords, last updated 16 September 2026). https://bills.parliament.uk/bills/4035
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →