CYBER UK 2026: Accelerating Our Cyber Defence for the Next Decade
- May 12
- 5 min read
Updated: 5 days ago

CYBERUK 2026 arrived at a moment of clear‑eyed reflection. Rather than focusing on celebration alone, the National Cyber Security Centre’s tenth anniversary offered an opportunity to take stock of a cyber landscape that has become more complex and fast‑moving over time. Against this backdrop, the conference theme, The Next Decade: Accelerating Our Cyber Defence, felt purposeful and timely, highlighting a shared focus on building stronger resilience and capability for the years ahead.
From the opening plenary in Glasgow, the tone was set by a clear recognition that the cyber domain now sits firmly in the space between peace and war. Nation state activity, criminal ransomware operations, and economic coercion are increasingly blurred together, creating an environment where cyber security is inseparable from national resilience, business continuity, and public trust. As NCSC CEO Richard Horne observed, we are not preparing for a distant future threat. We are already living through it, and the decisions we take now will shape our competitiveness and security for the decade ahead.
A dominant theme throughout day one was the accelerating convergence of emerging technologies and systemic risk. Artificial intelligence featured prominently, not as a distant theoretical risk but as a present operational reality. Speakers highlighted how AI-generated code is already being deployed at scale, often without corresponding advances in secure-by-design practices or assurance. The concern is no longer simply about vulnerable software, but about the speed at which insecure code is produced, shipped and embedded into critical systems that underpin our way of life. This has been amplified in the last few weeks since the conference with additional comments from the IMF stating ‘that artificial intelligence (AI)-powered cyber attacks could create a worldwide financial crisis’.
This challenge is compounded by persistent failures in patching and legacy replacement. Technology producers continue to release complex systems into environments that were never designed to absorb them safely, leaving defenders exposed to inherited weaknesses. The consensus from the plenary was stark: success over the next decade depends on defenders embracing AI at least as quickly as adversaries do. We cannot hope to counter machine-speed attacks with human-speed decision making.
That argument was reinforced by the discussion on standards and governance. The emergence of ISO/IEC 42001 as a global benchmark for AI management and security was cited as an important step towards shaping norms around AI-generated systems, but speakers were clear that attaining certification to standards alone will not close the gap. Without strong adoption, regulatory alignment and board-level accountability, they risk becoming afterthoughts rather than accelerants of resilience.https://www.techuk.org/resource/government-reinforces-its-message-that-there-s-no-excuse-for-failing-to-address-cyber-risk.html
Quantum computing added another layer of urgency. While large-scale quantum attacks may still be years away, the impact on cryptography is already a present concern. The NCSC’s updated guidance on post-quantum cryptography, and early migration efforts by major technology companies, were framed as essential first moves rather than optional future planning. Attackers do not need quantum capability today to create risk; they only need to harvest encrypted data now and wait.
Geopolitics hung heavy over the conference. The threat landscape sessions made clear that ransomware remains the most prevalent cyber threat to UK organisations, but that the majority of nationally significant incidents now involve direct or indirect nation state activity. China’s cyber operations were described as displaying an “eye-watering” level of sophistication, not as a theoretical adversary but as a peer competitor operating at scale. Russia’s sustained hybrid activity across the UK and Europe, shaped by lessons learned from recent conflicts, continues to evolve, while Iranian operations grow in confidence and reach.
Real-world examples grounded these concerns. Attacks on Polish energy infrastructure in late 2025 were cited as evidence that adversaries are broadening their targeting beyond symbolic disruption to sustained pressure on critical national infrastructure. The implication was clear: organisations can no longer assume they are collateral. They must assume relevance.
Across multiple sessions, one message stood out with uncomfortable clarity. Organisations must prepare for a future in which paying a ransom is no longer an option. Whether constrained by regulation, disrupted payment channels or simple adversary escalation, ransomware recovery will increasingly depend on resilience rather than negotiation. That means tested business continuity plans, rehearsed incident response, proactive detection, ransomware focused defences and a realistic understanding of operational dependencies. The days of treating cyber incidents as isolated IT problems are over.
Richard Horne’s closing message on day one captured the mood of the room. “Strengthen by the storm,” he urged, arguing that resilience is forged not by avoiding disruption, but by designing systems that can absorb and recover from it.
That call to arms was echoed and sharpened by the Security Minister’s keynote. Dan Jarvis framed cyber security not as a technical discipline, but as an economic and national security imperative. “The cyber security of British business is a matter of national security,” he stated plainly, stressing that no government can substitute for the decisions individual organisations choose to make every day.
Jarvis announced a new £90 million investment to provide targeted, practical support to small and medium-sized businesses, particularly to help them achieve the Cyber Essentials certification. He also signalled the launch of a new Cyber Resilience Pledge, due in Summer 2026, which will ask major organisations to make public commitments to cyber maturity, including Cyber Essentials certification and participation in early warning services. Organisations meeting the pledge will be listed publicly as exemplars of good practice, introducing a deliberate market signal around resilience.
Perhaps the most resonant line of the week followed shortly afterwards. “We cannot fight a machine-speed threat with human-speed bureaucracy,” Jarvis warned. It was not a criticism of regulation, but a challenge to how organisations design decision-making, escalation and response in an era of automated attack.
Day two shifted the focus from threat to resilience in practice. The opening plenary, led by the CEO of Scottish Power, reinforced that resilience is a shared, whole-of-society effort. Energy infrastructure, like many modern systems, depends on deep and often opaque supply chains. Building resilience half-way through delivery, after systems have already gone live, is not viable. Resilience must grow alongside investment, not trail behind it.
Scottish Power’s four priorities over the next decade reflected issues many organisations are grappling with today. Strengthening sector-wide resilience is about enabling sustainable growth, not slowing it down. Securing national networks increasingly depends on collaboration across partners and suppliers, with Cyber Essentials Plus positioned as a practical baseline rather than a compliance exercise. Innovation through data-driven operations and AI must be matched with governance that understands new risk rather than assuming existing controls will suffice. Above all, resilience is about people. Technology does not recover systems; trained, empowered teams do.
Jonathan Ellison, Director of National Resilience at the NCSC, reinforced this perspective. Legislative requirements, he argued, are becoming the primary influence on security programmes across sectors, from energy and transport to digital services. Cyber security is no longer a specialist annex to resilience planning. It is foundational to it, shaping how organisations design, operate and invest over the long term.
Across panels and workshops, a consistent message emerged. Accelerating our cyber defence over the next decade will not be achieved through isolated technical breakthroughs or one-off funding injections. It will come from collective effort, shared standards, cultural change and the willingness to act before incidents force our hand. Cyber security must be treated as strategic infrastructure, not a cost to be minimised or deferred.
CYBERUK 2026 did not offer easy answers, but it did offer clarity. The next decade will reward organisations that invest early, collaborate openly and design for resilience rather than perfection. The shared responsibility to tackle the cyber challenges of today and tomorrow was a clear theme running throughout the conference, with organisations who do so able to thrive in the coming years. The threat landscape will continue to evolve, but so too can our defences if we choose pace over complacency.
Acceleration, after all, is a choice. And as this year’s conference made abundantly clear, it is one we must make together.





