UK tops Europe for state-backed cyber activity, Microsoft finds
Microsoft's 2026 report puts the UK top of Europe for state-linked cyber activity and fifth globally for customer impact — with real implications for banks' identity and supplier risk.
- Published

The UK recorded more observed nation-state and geopolitical cyber activity than any other country in Europe, according to Microsoft's 2026 Digital Defense Report, published on 1 October 2026. Secondary reporting of the launch material describes the UK as recording the highest number of such events of any European country during the report period, though the precise count and Microsoft's definition of an "observed event" could not be verified in the material reviewed for this article. In a separate measure within the same report, the UK ranked fifth worldwide for the frequency with which Microsoft customers were affected by cyber threats in the first half of 2026, accounting for 3.8% of activity Microsoft observed globally.
These are two different measurements, and the report should not be read as saying the UK is simply "the most attacked" country in Europe by every yardstick. The nation-state ranking concerns state-linked and geopolitical activity specifically. The customer-impact ranking is broader and, on that measure, Microsoft places Ukraine first in Europe and the UK second — a different order entirely. Anyone citing one ranking should say which one.
For UK banks, payment firms and fintech providers, the relevant question is not where the UK sits in a vendor's league table but what the underlying pattern means for the systems that move money and hold customer data. Microsoft's report, read alongside UK official sources, points to identity compromise and dependence on shared infrastructure as the routes through which a state-linked or geopolitically motivated attack could disrupt a bank account, a payment or another service that customers rely on. That risk sits inside operational-resilience duties that already apply to regulated firms, and inside a UK reporting regime that tightens further from 18 March 2027.
What Microsoft measured, and its limits
Microsoft says its findings are informed by more than 165 trillion security signals analysed each day across its own products and services. That scale is real, but it is also a boundary: the rankings reflect activity visible within Microsoft's ecosystem, shaped by how widely its products are used in a given country, not a complete census of every UK cyber attack. Microsoft's precise definition of an "observed event" and the exact window behind the UK's reported European ranking were not available in the material reviewed for this article, and nothing reviewed indicates the rankings were adjusted for population, internet use or Microsoft's own customer base in each market. Unless the full report's methodology says otherwise, the figures should be read as raw telemetry rather than a per-capita measure of national risk.
The official UK picture
UK government sources independently support the direction of Microsoft's finding, even if they cannot verify its specific European ranking. The National Cyber Security Centre (NCSC) said it managed more than 200 incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026, and assessed around 75% of them as linked to state actors. In an April 2026 speech at CYBERUK, the NCSC's chief executive said that while most organisations still faced criminal activity such as ransomware most frequently, most of the nationally significant incidents the agency was then handling originated directly or indirectly from nation states. That is a distinction between prevalence and severity, not a contradiction: ransomware remains the more common problem for most firms, while state-linked activity dominates the most serious incidents.
The NCSC's Annual Review 2025 recorded 429 incidents handled between 1 September 2024 and 31 August 2025, including 204 nationally significant incidents and 18 highly significant incidents — the latter an increase of almost 50% on the previous year.
These are different datasets, built on different definitions, and cannot verify each other's figures — but they corroborate the same direction: state-linked activity against the UK is material and, on the evidence available, rising.
Why finance is exposed
Financial firms hold data and infrastructure attractive to espionage, disruption and geopolitically motivated activity, as well as ordinary fraud. HM Treasury's July 2026 report on cyber resilience in financial services recorded that 82% of participants in the Bank of England's first-half 2026 Systemic Risk Survey — surveyed banks, insurers and asset managers — named cyber attacks as a top-five risk to the UK financial system, ten percentage points higher than in 2024. That reflects participants' own views rather than a Microsoft or NCSC measurement of actual attacks.
Identity as the main access route
Microsoft's report says 78% of the attack techniques it observed against critical infrastructure used cloud identity abuse — compromising an account, a privileged credential or an application's access rights rather than breaking through a technical perimeter. That figure is global, covering critical infrastructure generally; no Microsoft statistic isolates UK banks or payment firms. But it explains a mechanism UK regulators have separately flagged as a weakness. The Bank of England, PRA and FCA's 2025 CBEST thematic review, which tests systemic firms and financial market infrastructures, found foundational gaps and highlighted credential management, multi-factor authentication, secure configuration, network segmentation, monitoring and governed remediation. STAR-FS, introduced in 2024, extends similar threat-led testing to more financial-sector firms beyond the CBEST population.
A single compromised identity with the wrong privileges can reach well beyond the system it first unlocks — an account used for payments processing, a service account with access to several applications, or an administrator credential that spans a bank's cloud estate. That is why identity controls, not just perimeter defences, sit at the centre of the CBEST findings.
Third parties as an impact multiplier
Financial firms do not run their important business services alone. HM Treasury's July 2026 report notes that reliance on third-party suppliers can increase the scale and complexity of disruption when something goes wrong, and Microsoft's report similarly warns that failures can spread across interconnected systems and software supply chains rather than staying contained to one organisation. A compromise at a cloud provider, managed service provider or payments processor can affect many client firms at once, turning a single intrusion into a sector-wide problem.
UK policy has moved to address this. The critical third-party regime took effect on 1 January 2025, though obligations apply to an individual supplier only once HM Treasury's designation order for that provider comes into force; regulatory oversight of the first designated critical third parties began on 13 July 2026. The Bank of England has said the regime complements, rather than replaces, firms' own responsibility for due diligence, risk management and contingency planning; designation does not transfer accountability away from the firm that relies on the supplier.
From cyber defence to operational resilience
FCA operational-resilience rules and guidance, in force since 31 March 2022, require in-scope firms — including banks, building societies, designated investment firms, insurers, recognised investment exchanges, enhanced-scope SMCR firms, payment institutions and electronic money institutions — to identify their important business services, set impact tolerances for each one, and map the people, processes, technology, facilities and information that support them. By 31 March 2025, in-scope firms had to have completed that mapping and testing and be able to demonstrate they could remain within impact tolerances during severe but plausible disruption. The FCA's review of the year since found firms should keep evolving scenario testing, recovery planning and supply-chain testing, not treat the deadline as an endpoint.
Microsoft's two UK rankings and the NCSC's state-linkage findings do not create a new legal duty. But they support treating a state-linked compromise of an identity system or a material supplier as a reasonable severe-but-plausible scenario for operational-resilience testing. Scenario selection remains each firm's own judgement; Microsoft's threat research and the NCSC's frontier-AI guidance are inputs to it, not binding rules.
The regulatory timetable
| Date | What applies |
|---|---|
| 31 March 2022 | FCA operational-resilience rules and guidance take effect |
| 1 January 2025 | UK critical-third-party rules take effect, applying to each supplier once HM Treasury designates it |
| 31 March 2025 | Deadline for in-scope firms to complete mapping, testing and ability to remain within impact tolerances |
| 18 March 2026 | FCA, PRA and Bank of England publish final operational-incident and material-third-party reporting policies |
| 13 July 2026 | Regulatory oversight begins for the first HM Treasury-designated critical third parties |
| 18 March 2027 | New harmonised reporting regime for qualifying operational incidents and material third-party arrangements takes effect |
Until 18 March 2027, payment service providers remain subject to existing major operational and security incident reporting duties under the Payment Services Regulations 2017, alongside duties such as Principle 11 and SUP 15 reporting to the FCA. From that date, covered firms must also notify new material third-party arrangements or significant changes, maintain and annually submit a register of those arrangements, and report operational incidents that meet specified consumer-harm, firm-safety or market thresholds.
What to watch next
Microsoft's full 2026 Digital Defense Report should resolve the methodological questions this article could not settle from secondary material. Readers wanting that detail should consult Microsoft's published report directly rather than secondary summaries of it.
On the UK regulatory side, the next fixed points are further HM Treasury designation orders bringing more suppliers into the critical-third-party regime, and the 18 March 2027 start date for the new operational-incident and material-third-party reporting rules, for which firms had a 12-month preparation window from the policies' publication on 18 March 2026. Firms with questions about scope or current reporting duties should consult the FCA's and Bank of England's own published material directly.
Sources
- 2026 Digital Defense Report (opens in a new tab)
Microsoft · · Accessed
- Microsoft Digital Defense Report 2026 (opens in a new tab)
Microsoft · · Accessed
- Switzerland ranks 13th among the countries most impacted by cyber activity in Europe (opens in a new tab)
Microsoft Source EMEA · · Accessed
- NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems (opens in a new tab)
National Cyber Security Centre · · Accessed
- NCSC CEO keynote speech, CYBERUK 2026 (opens in a new tab)
National Cyber Security Centre · · Accessed
- NCSC Annual Review 2025: Incident management (opens in a new tab)
National Cyber Security Centre · · Accessed
- The Value of Resilience: Cyber Resilience in Financial Services (opens in a new tab)
HM Treasury · · Accessed
- 2025 CBEST thematic (opens in a new tab)
Bank of England, Prudential Regulation Authority and Financial Conduct Authority · · Accessed
- Operational resilience (opens in a new tab)
Financial Conduct Authority · · Accessed
- Operational resilience: insights and observations one year on (opens in a new tab)
Financial Conduct Authority · · Accessed
- PS16/24 – Operational resilience: Critical third parties to the UK financial sector (opens in a new tab)
Bank of England and Prudential Regulation Authority · · Accessed
- UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury (opens in a new tab)
Bank of England · · Accessed
- PS26/2: Operational incident and third party reporting (opens in a new tab)
Financial Conduct Authority · · Accessed
- Reporting operational incidents (opens in a new tab)
Financial Conduct Authority · · Accessed


