75% of attacks on UK critical infrastructure are state-linked. Here is what to do with that number.
In June 2026 the NCSC's chief executive told a RUSI audience that his agency had managed more than 200 cyber incidents affecting the UK's critical infrastructure in a single year, and that around three quarters of them were linked to state actors. Read that again if you work in energy, water or transport. The typical adversary in this sector is not a teenager with a scanner. It is a funded team with time, patience and a mission.
For years, OT security conversations treated threat actors as background noise: "attackers" in the abstract, defended against with generic controls. CAF v4.0 ended that comfort. Its new contributing outcome A2.b, Understanding Threat, asks a blunt question: do you actually know who is likely to come for your essential function, what they can do, and what their attack on your specific estate would look like?
What "understanding threat" means in practice
It does not mean subscribing to a feed and filing the PDFs. The outcome expects documented, repeatable analysis. In an OT context that looks like three things.
Knowing the adversary categories that target your sector. Groups tracked publicly under names like VOLTZITE have specifically targeted energy infrastructure, and pre-positioning on OT networks (gaining quiet access now for possible disruption later) is a documented state tactic.
Mapping realistic attack paths through your own architecture. Start where attacks actually start: a phished corporate account, a compromised vendor laptop, an exposed remote access service. Then trace the route across the IT/OT boundary to the systems that matter: your SCADA servers, engineering workstations and protection relays.
Feeding that picture into decisions. Threat understanding that never changes a firewall rule, a monitoring priority or an investment case is shelf-ware. The framework asks for the connection, not the binder.
A practical way to start
Pick your single most critical function. Run one structured exercise with the engineers who know the estate: who would want to disrupt this, what would they need to reach it, and where would we see them first? Write it down, date it, and note what it changed. That one artefact, honestly produced, is worth more against A2.b than any purchased threat report.
And if three quarters of the incidents hitting your sector are state-linked, the uncomfortable corollary is worth saying plainly: assessments that score your defences against casual attackers are answering last decade's question.
Sources