Decoding the world of cybersecurity

Russian hostile activity costs UK at least £2bn a year, report estimates

A new study estimates that Russian hostile activity imposes at least £2bn to £2.5bn in annual costs on the UK, while acknowledging substantial limits in available evidence.

Russian hostile activity costs UK at least £2bn a year, report estimates
Summary
  • The study covers cyber attacks, sabotage and threats to critical infrastructure.
  • Authors Graeme Downie MP and Dr Dominic Reed describe £2bn to £2.5bn as a working minimum.
  • The analysis distinguishes Russia-linked cybercrime from activity directed by the Russian state.

Russian hostile activity imposes an estimated annual cost of at least £2 billion to £2.5 billion on the UK, according to a study examining cyber attacks, sabotage and threats to critical infrastructure.

The Putin Tax: Estimating the Economic Cost of Russian Hostile Activity Against the United Kingdom, produced by Labour MP Graeme Downie with Dr Dominic Reed, argues that Britain has developed extensive mechanisms for imposing economic costs on Russia without maintaining an equivalent assessment of the losses created by Russian activity against the UK.

The estimate is not an official government accounting and its authors acknowledge substantial limitations in the underlying evidence. The analysis combines public reporting, parliamentary information and industry data covering different periods, while some losses can only be modelled rather than directly observed.

RUSI’s Tom Keatinge, who contributed the report’s foreword and has also examined its findings, notes that the calculation draws partly on individual incidents including the Royal Mail cyber attack, the Leyton arson attack and the Jaguar Land Rover cyber incident. Publicly reported costs for those cases account for a substantial proportion of the proposed annual burden.

Attributing that burden to Russia becomes more difficult when cybercrime is included. The study uses industry data identifying more than 300 Russia-linked cyber incidents affecting UK headquartered companies since 2022, but activity carried out by Russian-speaking criminals or groups operating from Russian territory cannot automatically be treated as an operation directed by the Russian state.

That distinction is central to any economic calculation because hostile-state activity and criminal activity tolerated within a jurisdiction represent different forms of responsibility. Intelligence agencies may assess links between an actor and a government without publishing all the underlying evidence, while a victim organisation may have little visibility into whether the attacker received state direction.

Costs are also wider than the immediate loss created by a successful intrusion. A serious cyber incident can interrupt production, delay deliveries, require forensic investigation, consume management time and force technology replacement, while organisations may increase protective spending after an incident or in anticipation of future attacks.

Threats to physical infrastructure add another layer of uncertainty. Potential disruption to subsea cables and other critical systems can create economic exposure even when damage does not occur, because governments and operators spend money on surveillance, redundancy and resilience measures intended to reduce the consequence of an attack.

Britain and other European governments have repeatedly attributed cyber campaigns to Russian intelligence services and warned of sabotage, reconnaissance and disruptive activity linked to Moscow. Treating those activities as part of one economic problem can help inform national resilience policy, but it also risks giving a single headline number more precision than the component evidence allows.

Downie and Reed therefore describe their estimate as a floor rather than a comprehensive total. Unreported incidents, incomplete attribution and costs that cannot readily be isolated from wider security expenditure mean the true economic burden could be higher, while some Russia-linked activity included in supporting datasets cannot be definitively assigned to the state.

The absence of an official methodology is one of the study’s principal findings. Without consistent government reporting, policymakers have limited ability to compare the cost imposed by hostile activity with the expenditure required to prevent, absorb and recover from it.

The study calls for more systematic measurement, including recurring assessment of hostile-state cyber activity. A stronger evidence base would allow future estimates to separate confirmed state operations, Russia-linked criminal activity, direct economic damage and resilience spending rather than compressing each category into one aggregate figure.

×