Welcome back. You have just practised judging how valuable an asset is by looking beyond direct financial loss: disruption, safety, privacy, trust, and competitive advantage can all make an incident severe.
This completes Week 1A’s focus on threats and organisational impact. You will now use a reputable cybersecurity advisory source to identify and summarise a current change in the threat landscape. This is more than repeating a news story: at distinction level, you need to explain what is changing, who is affected, why it matters, and how certain the advisory is.
What is a “change in the threat landscape”?
The threat landscape is the overall cyber-security environment an organisation faces. It includes:
- the threat actors involved, such as cyber criminals, hostile states, insiders, or hacktivists;
- their motives, capabilities, and business models;
- the methods they use to gain access, steal data, disrupt services, or demand payment;
- the types of organisations and assets they target;
- the likely volume, scale, and impact of attacks.
A change does not necessarily mean a completely new kind of cyber attack has appeared. It may mean that an existing threat is becoming:
- more frequent;
- easier for criminals to carry out;
- more convincing or difficult to detect;
- more automated;
- accessible to a wider range of threat actors;
- more harmful to organisations.
For this lesson, the current change is the increasing use of artificial intelligence (AI) by threat actors to make existing attacks—especially ransomware, phishing, reconnaissance, and vulnerability research—more efficient and effective.
It is important to use a source with authority. In the UK, the National Cyber Security Centre (NCSC) is a highly reputable advisory source because it is the UK’s national technical authority for cyber security and publishes evidence-based guidance and threat assessments.
Before writing any summary, read the advisory carefully enough to separate:
- what the source has observed;
- what it assesses is likely to happen;
- what the source does not claim.
Global ransomware threat expected to rise with AI, NCSC warns | National Cyber Security Centre
Read this NCSC advisory to identify its central assessment: AI is changing the scale and accessibility of existing cybercrime, particularly ransomware. The source is especially useful because it also gives an important limitation: the change is evolutionary rather than a complete transformation of cyber threats.
In the opening report summary, read the core assessment. Focus on the causal chain: AI lowers the barrier to entry, less-skilled actors can perform better access and information-gathering activity, and victim targeting can improve. Then find the section headed “NCSC CEO Lindy Cameron said”. Read the key qualification. This distinction prevents an exaggerated summary.
The main change: AI is strengthening existing attacks
A weak summary might state:
AI is now used by hackers, so cyber attacks are more dangerous.
This is broadly true but too vague. It does not explain how AI changes the threat, whether it is a new attack type, or what evidence supports the point.
The NCSC’s position is more precise:
AI is being used to enhance existing tactics, rather than instantly create entirely new types of attack.
This means AI can act as a multiplier. It can help attackers work faster, process more information, target more victims, and produce more believable content. For example, an attacker might use AI to:
- research an organisation and its employees;
- draft convincing phishing messages at scale;
- translate a scam into accurate English or another language;
- process stolen data after an initial breach;
- support research into software flaws that may be exploited;
- make parts of an attack campaign more automated.
This does not mean that every AI-generated message will bypass security controls, or that AI makes successful ransomware attacks inevitable. Security controls, trained staff, software patching, access controls, monitoring, backups, and incident response still make a substantial difference.
The distinction-level point is this:
The threat is changing because attacks can become more efficient, scalable, and accessible—not because ransomware or phishing has suddenly become a completely new technology.
Read a current advisory in context
The NCSC Annual Review 2025 gives a broader and more current picture. It places AI-enabled attacks alongside continued ransomware, state activity, and threats to critical national infrastructure.
NCSC Annual Review 2025 | Chapter 01
Read these parts of the NCSC Annual Review 2025 to see how a current advisory connects ransomware with AI-enabled activity. Notice that the report distinguishes between criminal motivations, state-linked activity, and the practical methods attackers use.
First, in the “Ransomware” section, read the ransomware context. Focus on why criminals may select organisations: likely payment, disruption caused by downtime, and sensitive data that can be used for extortion. Next, in the “Artificial intelligence (AI)” section, read how AI supports existing attacks. Then continue with the recent developments. Pay attention to the phrase “AI-assisted vulnerability research and exploit development”: this is identified as a particularly significant near-term development.
Extracting evidence without overclaiming
Cybersecurity advisories use careful language. Words such as likely, highly likely, almost certainly, and expected are not empty phrases: they show the confidence of the assessment.
Compare these statements:
| Statement | Quality | Why |
|---|---|---|
| “AI has made all cyber attacks fully automatic.” | Poor | This is an unsupported exaggeration. |
| “The NCSC says AI is used by criminals.” | Basic | It identifies a source but does not explain the change or impact. |
| “The NCSC assesses that AI is increasing the efficiency, effectiveness, and frequency of existing cyber intrusion methods.” | Strong | It accurately describes the assessment. |
| “The NCSC reports that AI is enhancing existing tactics rather than creating wholly novel attacks; this may increase the volume of phishing, ransomware, and vulnerability exploitation attempts.” | Distinction-level | It uses the source precisely, explains the change, and avoids claiming certainty beyond the evidence. |
A useful rule is:
Report the source’s level of certainty; do not turn a forecast into a proven fact.
For example, the NCSC states that AI-assisted vulnerability research and exploit development is likely to be a significant near-term development. A careful summary should say:
The NCSC assesses that AI-assisted vulnerability research may make it easier to discover and exploit weaknesses in code or configuration.
It should not say:
AI has already found every vulnerability and removed the need for human attackers.
The first statement is supported and proportionate. The second is not.
Link the change to threats, vulnerabilities, and impact
A strong threat-landscape summary does not stop after describing the technology. It explains the organisational significance.
Consider this chain:
For example:
| Part of the analysis | Example |
|---|---|
| Change | Threat actors use AI to enhance phishing and reconnaissance. |
| Why it changes the threat | Messages may be produced faster, tailored to more victims, and written more convincingly. |
| Relevant vulnerability | Staff may trust a realistic email, use weak verification procedures, or disclose credentials. |
| Possible attack | An attacker gains access to an account, steals data, or deploys ransomware. |
| Organisational impact | Services may be unavailable, sensitive information may be copied, and trust may be damaged. |
| Appropriate judgement | The organisation should treat phishing resistance and account protection as continuing priorities, not assume old awareness training is enough. |
This links directly to the work you have done in earlier lessons:
- Threat actors may be financially motivated criminals seeking ransomware payments or data for extortion.
- A vulnerability might be weak passwords, insufficient staff training, unpatched software, or excessive access rights.
- An attack vector could be a phishing email, stolen credentials, or an exposed internet-facing system.
- The impact could include downtime, loss of confidentiality, reputational damage, and loss of trust.
At this stage, you do not need to explain every technical detail of phishing, ransomware, or vulnerability exploitation. The important skill is showing how a current development changes the likelihood or scale of an existing threat.
A reliable structure for an advisory summary
In an exam, coursework task, or revision answer, use this five-part structure.
1. Name and evaluate the source
State who produced it and why it is reliable.
The National Cyber Security Centre is a reputable UK cybersecurity advisory source because it is the national technical authority for cyber security and publishes threat assessments for organisations and the public.
You do not need to claim that every statement from an official source is permanently true. Cyber threats change quickly. Instead, show that you have considered the source’s authority, date, and purpose.
2. State the change clearly
Write one focused sentence.
A current change in the threat landscape is the increasing use of AI by cyber criminals and state-linked actors to improve existing attack methods.
3. Explain the mechanism
Show how the change affects attacks.
AI can lower the skill barrier for some attackers and increase the speed and scale of reconnaissance, social engineering, data processing, and vulnerability research.
4. Explain why it matters
Connect it to an organisation’s vulnerabilities and possible impacts.
This matters because a larger number of more convincing phishing attempts may increase the chance that a staff member reveals credentials or performs an unsafe action. Attackers could then access sensitive systems or data, potentially leading to ransomware, data theft, operational disruption, and reputational damage.
5. Add a balanced judgement
Show that you understand the limits of the evidence.
However, the NCSC describes this as an evolutionary change rather than a completely new form of cyber threat. Organisations should strengthen established controls rather than assume that traditional security measures are no longer useful.
This final step is often what moves an answer beyond description. You are evaluating the meaning of the advisory rather than simply copying it.
Worked distinction-level summary
Here is a model answer based on the NCSC Annual Review 2025.
The NCSC Annual Review 2025 identifies the increasing use of AI by threat actors as a current change in the cyber threat landscape. The NCSC reports that criminals and state-linked actors are using AI to enhance existing tactics, techniques, and procedures rather than creating entirely new forms of attack. AI can support reconnaissance, social engineering, processing of stolen data, and research into vulnerabilities in software or system configurations. This could increase the efficiency, frequency, and effectiveness of attacks, including phishing and ransomware. For organisations, more convincing and scalable attacks may exploit staff mistakes, weak account security, or unpatched systems, leading to data theft, service disruption, or extortion. However, the NCSC describes the change as evolutionary rather than revolutionary, so established controls such as staff verification procedures, access controls, patching, monitoring, and secure backups remain important.
Why this is strong:
- It identifies a named, reputable source.
- It accurately describes a current change.
- It explains the technical and human mechanism.
- It links the change to vulnerabilities and organisational impact.
- It avoids claiming that AI has replaced all older attacks.
- It reaches a reasoned, balanced conclusion.
Common mistakes to avoid
Treating “current” as a vague word
A current advisory should have a recognisable publication period, named organisation, and specific assessment. Do not write only:
I saw on social media that AI scams are increasing.
Instead, identify the advisory and summarise what it actually says.
Confusing AI with the attack itself
AI is not automatically the attack. It may help attackers carry out an existing attack, such as phishing, credential theft, ransomware, or data exfiltration.
Claiming that all organisations face identical risk
The NCSC notes that ransomware criminals are often sector agnostic: they may target any organisation they think is vulnerable, likely to pay, or likely to suffer from downtime. However, the impact is still different for different organisations.
For example:
- a retailer may suffer lost sales and disruption to stock or payment systems;
- a college may face risks to student personal data, learning systems, and safeguarding information;
- a healthcare provider may face disruption that affects safe care;
- a manufacturer may lose production time or confidential designs.
The broad threat may apply to many sectors, but the specific assets and consequences still need scenario-based analysis.
Repeating advice without connecting it to the change
“Use strong passwords” is not enough on its own. Explain the connection:
Because AI may enable more convincing credential-theft attempts, multi-factor authentication can reduce the damage if a password is disclosed, as an attacker would need an additional authentication factor.
You will study authentication methods and technical controls in more depth later. For now, focus on making each recommendation follow logically from the reported threat.
A quick revision template
Use this as a planning frame before writing:
| Prompt | Notes to include |
|---|---|
| Source | NCSC Annual Review 2025 |
| Current change | AI is enhancing existing cyber attacks. |
| Threat actors | Cyber criminals and state-linked actors. |
| Methods affected | Reconnaissance, phishing, data processing, vulnerability research, exploit development. |
| Why the change matters | Increased speed, scale, targeting, and potential effectiveness of attacks. |
| Relevant vulnerabilities | Weak staff verification, poor account security, unpatched systems, excessive privileges. |
| Potential impact | Ransomware, data theft, downtime, privacy harm, reputational damage. |
| Balanced conclusion | Evolutionary change; established controls still matter. |
Key takeaways
- A threat-landscape change can be an increase in the capability, scale, accessibility, or effectiveness of an existing threat—not only the appearance of a new attack type.
- The NCSC is a reputable UK cybersecurity advisory source, and its Annual Review 2025 reports that threat actors are using AI to enhance existing attack methods.
- AI can support reconnaissance, social engineering, post-breach activity, data processing, and vulnerability research.
- Avoid overclaiming: the NCSC characterises the near-term impact as evolutionary, not revolutionary.
- A distinction-level summary identifies the source, states the change, explains its mechanism, links it to vulnerabilities and organisational impacts, and gives a balanced judgement.
Next, you will begin Week 1B by distinguishing spyware, adware, and ransomware according to what each one does and the harm it is intended to cause.
Can't find a good explanation? Sign up and we'll make it for you
Sign up