Modern technology has revolutionised how we conduct business. Itβs opened up a world of opportunities and efficiencies. And also vulnerabilities.
Our growing reliance on technology has given rise to a host of cyber security threats. Criminals are exploiting network weaknesses and our own blind spots to access sensitive information and systems.
This guide exposes the most common cyber security threats. By understanding these threats, you can plan how to protect against them. Preventing attacks is less costly than recovering from them.
Reading this guide will help you:
- Recognise common cyber security threats
- Identify vulnerabilities in your organisation
- Plan protections against cyber security threats
The term cyber security threat sounds sophisticated. The methods criminals use to attack computers, networks and smart devices can be sophisticated, but theyβre also commonplace.
Simply put, a cyber security threat is a potential malicious act that could compromise a computer system, service or data. Cyber criminals often seek financial gain, but threat actors may also pursue espionage, disruption or influence. Attacks can steal information, misuse accounts, interrupt operations or deploy ransomware.
Cyber threat actors can be individuals, criminal groups or state-linked operators with the expertise and resources to exploit weaknesses in digital systems. They may target technical vulnerabilities as well as the people who receive messages, visit websites or install updates that appear legitimate.
Cyber attacks can be categorised into two types: targeted and untargeted.
Targeted attacks are planned and executed against a specific individual, organisation or system. Cyber criminals conducting these attacks have a clear objective and select their targets based on perceived vulnerabilities or the value of the information accessible. Such attacks often involve lengthy research to find specific weaknesses within the targetβs systems. Spear phishing is one example of a targeted cyber security attack where attackers send fraudulent messages designed to trick specific people into revealing sensitive information.
Untargeted attacks are indiscriminate. Criminals launch these attacks against as many systems, devices and users as possible rather than one specific target. Theyβre usually automated and used to find multiple weaknesses simultaneously. Distributing malicious software through mass email campaigns is a typical example of an untargeted attack. Criminals reason that sending emails to a long list of recipients will entrap at least a handful of unsuspecting users.
The Cyber Security Breaches Survey 2025/2026found that 43% of UK businesses and 28% of charities identified a cyber security breach or attack in the previous 12 months. This equates to approximately 612,000 businesses and 57,000 charities. The survey also estimated that 19% of businesses and 14% of charities had experienced at least one cyber crime during that period.
The figures cover incidents organisations detected and were willing to report, so they may underestimate the true prevalence. Phishing remained the most commonly identified type of breach or attack, affecting 38% of businesses and 25% of charities.
Costs varied sharply. The median perceived cost of the most disruptive breach or attack was Β£0 across all businesses, but the cost at the 95th percentile was Β£4,000, rising to Β£10,000 for medium and large businesses. These figures reflect organisationsβ estimates for identified incidents, not the total economic cost of cyber crime.
The NCSCβs 2025 Annual Review recorded 429 incidents requiring NCSC support between 1 September 2024 and 31 August 2025. Of these, 204 were nationally significant and 18 were highly significant. These are incidents handled by the NCSC, rather than an estimate of every attack affecting UK organisations.
Current NCSC risk-management guidance recommends an organisation-wide approach that considers people, processes and technology. Awareness is important, but it must work alongside proportionate technical controls, secure procedures and incident planning.
Below, weβve outlined seven common types of cyber security threats organisations face. They will help you conduct a risk assessment for your IT systems and plan appropriate safeguards.
Social engineering means manipulating people into revealing sensitive information, transferring money or bypassing security procedures. It may be used on its own or alongside technical methods that compromise accounts and systems.
Cyber criminals use various tactics to trick individuals into providing confidential information or access. These tactics play on human emotions, such as fear, curiosity or the desire to help, making them remarkably effective.
For instance, an attacker might impersonate a senior figure in an email to persuade an employee to disclose sensitive company data, as in the βCEO scamβ. In this scam, an employee receives an email that appears to be from their CEO. The message urgently requests a transfer of funds or sensitive information. Mistaking the request as legitimate, the employee complies, only to later find out theyβve been duped.
Generative AI can help attackers create polished, personalised messages quickly and at scale. The NCSCβs 2025 assessment of AI-enabled cyber threats states that AI is already supporting reconnaissance, social engineering, basic malware generation and vulnerability research. The NCSC expects AI to make existing attack methods more effective and efficient rather than immediately creating entirely new types of attack.
Deepfakes add convincing synthetic audio, images or video to impersonation attempts. A message may appear to come from a senior colleague, while a phone or video call may reproduce a familiar voice or face. These cues should not be treated as proof of identity.
The Report Fraud Annual Assessment 2025/26 found that reports in which victims identified AI as a factor rose from 193 in 2024/25 to 956 in 2025/26, an increase of 395%. Reported losses linked to AI-enabled crime also increased from Β£1.2 million to Β£9.6 million. Victims described AI-generated endorsement videos, cloned voices, manipulated images, fake websites and chatbots used to make fraud attempts appear authentic.
Organisations should require unusual payment, access and data-sharing requests to be verified through an established second channel. Staff should use contact details already held in company records and follow the normal approval process, even when a request appears to come from a familiar person.
Phishing is a common cyber attack that uses social engineering tactics. In these attacks, criminals impersonate trusted people or organisations in emails or other communication channels to obtain sensitive data, money or access. Phishing can also be the first step in a more complex cyber attack.
As a form of social engineering, phishing attempts are designed to prey on peopleβs expectations and emotions. Malicious messages are made to appear legitimate, making them difficult to separate from genuine communications. Attackers also often use urgent language to trick victims into hastily clicking on suspicious links or attachments.
There are a number of subcategories of phishing attacks:
- Spear Phishing takes the deception further by targeting specific individuals or organisations. These attacks are highly personalised, with the attacker having done their homework to make the scam more convincing. For example, they might use information gathered from social media profiles to craft a believable email asking for sensitive information, supposedly from a colleague or a known contact.
- Whaling targets the βbig fishβ β senior executives or other high-profile targets within an organisation. These attacks are sophisticated and meticulously planned, often involving fake legal documents or other high-stakes communications designed to pressure the target to respond.
- Smishing uses text messages or messaging apps to deliver fraudulent links, request information or pressure the recipient to act.
- Vishing uses phone calls or voice messages. Attackers may spoof caller ID or use AI-generated audio to impersonate a trusted person.
Malware (a contraction of βmalicious softwareβ) is harmful software designed to infiltrate, damage or disable computers, systems and networks. It represents one of the most common and destructive cyber threats facing organisations today.
There are numerous types of malware, each with its own method of attack and malicious intent. These include:
- Viruses, which attach themselves to clean files and spread throughout a system
- Worms, which replicate and spread across networks
- Ransomware, which encrypts data or locks access to systems and demands payment, sometimes after data has also been stolen
- Spyware, which monitors and collects information from unaware targets
A recent UK example shows the operational impact a cyber attack can cause. In April 2025, Marks & Spencer reported that a cyber incident had disrupted contactless payments and Click & Collect, delayed some online orders and led the retailer to move some processes offline. The NCSCβs 2025 Annual Review later highlighted attacks on Marks & Spencer, the Co-op and Jaguar Land Rover as examples of cyber threats with real-world costs.
These incidents underline the need for layered controls, including prompt security updates, restricted privileges, protected and tested backups, monitoring and a rehearsed response plan. No single safeguard can prevent every malware infection.
In the context of cyber security, spoofing refers to attacks in which a criminal βspoofsβ a legitimate site or source of communication. Users believe theyβre exchanging messages with a known person or accessing a trustworthy site, but theyβre actually feeding criminals critical information.
There are various forms of spoofing, including email spoofing, website spoofing and IP address spoofing, each with its unique method and purpose.
- Email spoofing sees attackers falsely replicate sender email addresses, making their messages appear to come from a trusted contact. This method is often used with phishing scams to trick recipients into divulging sensitive information or downloading malware.
- Website spoofing requires creating a malicious website that reproduces the look and feel of a legitimate one. Users are tricked into entering their login details, which the attackers steal.
- IP address spoofing involves falsifying the source address in internet traffic so that it appears to come from another address. It is often used in denial-of-service attacks and can exploit systems that rely too heavily on source addresses as proof of trust.
Denial-of-service (DoS) attacks are a formidable cyber threat. They shut down a machine or network by overwhelming the target with a flood of useless traffic, making it inaccessible to genuine users.
When these attacks come from multiple sources simultaneously, they are referred to as Distributed Denial-of-Service (DDoS) attacks. DDoS attacks are more complex and difficult to prevent because the attack traffic is spread across multiple points of origin.
DDoS attacks paralyse websites, online services and networks by saturating them with more requests than they can handle. This denies service to legitimate users and can also lead to longer-term impacts on a businessβs reputation and financial health.
Identity and access attacks exploit credentials, authentication processes or trusted communications to gain information or unauthorised access.
Some attacks use stolen usernames and passwords to impersonate legitimate users. Others intercept communications or automate repeated login attempts. Strong authentication, restricted privileges and monitoring can reduce the risk and limit the impact of a compromised account.
Three specific types of identity-based attacks include:
- Man-in-the-middle (MitM) attacks: These occur when an attacker intercepts communications to gather or alter the information being exchanged.
- Brute force attacks: In this approach, attackers use automated trial and error to make repeated password guesses. The attack relies on the volume of attempts rather than exploiting a specific software vulnerability.
- Password spraying: Instead of targeting one account with thousands of password attempts, password spraying targets many accounts with a few commonly used ones. This method exploits the probability that a fraction of accounts will have weak passwords.
People can make mistakes that contribute to security incidents, but describing employees as the weakest link oversimplifies the problem. Attackers exploit working conditions, unclear procedures and technical weaknesses as well as individual judgement.
The NCSCβs phishing guidance warns that no training package can teach users to identify every phishing attempt. It recommends layered defences that make attacks harder to deliver, help users report suspicious messages, limit the effects of a successful attempt and support a rapid response.
Employees still need relevant awareness and a clear, supportive way to report mistakes or suspicious activity. This should sit alongside email filtering, secure authentication, access controls, patching, monitoring and tested incident-response procedures.
Organisations should follow a prepared incident-response plan to contain an attack, preserve evidence, restore services and meet any reporting duties. Significant cyber incidents can be reported to theNCSC. Fraud and cyber crime should be reported through Report Fraud, which replaced Action Fraud in December 2025. In Scotland, reports should be made to Police Scotland by calling 101.
If an incident involves personal data, organisations must assess their duties under the UK GDPR and Data Protection Act 2018. The ICOβs current guidance states that a notifiable personal data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of awareness. All personal data breaches must be recorded, and affected individuals must be informed without undue delay when a breach is likely to result in a high risk to their rights and freedoms.
Cyber security awareness helps employees recognise suspicious activity, follow verification procedures and report concerns promptly. It is one part of a wider system of technical, procedural and organisational controls.
Our online Cyber Security Awareness Training is designed to help trainees recognise a range of cyber threats and follow appropriate steps to protect sensitive information and report concerns.
Trainees learn to identify different types of cyber threats, from malware to phishing attacks, and understand the methods behind them. This awareness can help staff recognise and respond to social engineering attempts. The course also explores cyber hygiene and routine measures that support protection against common threats.