5 operational in 2016, the NCSC’s cyber security front line has helped to support with 1,167 cyber incidents – including 557 in the last full 12 month period (October 2017October 2018). The latest NCSC annual report reveals most attacks against the UK that are managed by the NCSC, are carried out by hostile states. Since January 2018, the UK’s cyber community has implemented a new incident categorisation framework. This new approach fully aligns the NCSC’s work with law enforcement agencies to defend against the growing threat, with incident responders now classifying attacks into six specific categories (C1-6) rather than the previous three. The new system ranges from attacks targeting the Government and critical national infrastructure through to individual citizens. The NCSC will produce an impartial assessment of the nature of the incident drawing upon and weighing up the evidence from a wide range of sources. Incident Assessment Reports usually answer the following questions: based on intent and past form, and who is most likely to be responsible, and is this incident part of a wider trend? The report will open with a set of key judgements, followed by a confidence statement, which is based on the certainty behind the source material used. Further commentary is provided to support and expand upon the key judgements. Based on this assessment, the UK will consider how to respond. The UK will use a range of options across diplomatic (including but not limited to attribution), economic and law enforcement to respond. Any decision to respond will take into account the wider context at the time and be in accordance with international law. On attribution specifically, the UK Government’s starting point is that attribution is a political decision and can be a powerful deterrence tool when deployed effectively. The UK will decide whether attribution – public or private – is in the UK’s national interest. We consider attribution a sovereign political decision on a case by case basis. Attributing is a first step and opens up further response options, in the UK national interest and under international law. When considering attribution, the UK Government will consider, alongside a technical assessment from the National Cyber Security Centre: a. Geopolitical and bilateral factors: our wider objectives towards the State in question, including national security objectives, regional stability, the sensitivities of our allies and the likelihood of counter-response. b. Impact on victim: the impact of UK attribution (especially public) on the victim(s) of a cyber-incident will be reviewed. c. Impact on law enforcement activity: the impact of UK attribution (especially public) on the law enforcement investigation of a cyber-incident; for instance the effect on our ability to arrest and prosecute. d. UK values and ability to operate: attribution should not limit the UK’s ability to carry out our own cyber operations in full adherence to domestic and

Select target paragraph3