Opening Plenary - NCSC Keynote

Richard Horne (Chief Executive Officer · National Cyber Security Centre (NCSC))

CYBERUK 2026 · Day 1 · Main Plenary

Overview

Richard Horne, Chief Executive Officer of the National Cyber Security Centre (NCSC), delivered the opening plenary keynote at CYBERUK, presenting a compelling vision of the current and future cybersecurity landscape. Titled "Opening Plenary - NCSC Keynote," Horne's address framed the challenges and opportunities ahead as a "perfect storm," driven by the twin forces of rapid technological advancement and escalating geopolitical tensions. He emphasized that cybersecurity is no longer an isolated technical discipline but a fundamental, shared mission integral to national prosperity and security.

Watch on YouTube

Visual summary for Opening Plenary - NCSC Keynote by Richard Horne
Visual summary for Opening Plenary - NCSC Keynote by Richard Horne

Key moments

  1. 0:00 Introduction: The 'perfect storm' of cyber challenges
  2. 2:30 AI: Opportunity for defense, challenge from adversaries
  3. 4:50 Geopolitical shift: Cyberspace as a contested domain
  4. 6:00 Rising nation-state cyber threats: China, Iran, Russia
  5. 8:00 Cybersecurity as the home front in modern conflict
  6. 9:20 Organizational resilience: Embed cyber, build defense in depth

Opening Plenary - NCSC Keynote

Speakers: Richard Horne, Chief Executive Officer, National Cyber Security Centre (NCSC)

Conference: CYBERUK

YouTube: https://www.youtube.com/watch?v=kPsjBD1TLn8

Overview

Richard Horne, Chief Executive Officer of the National Cyber Security Centre (NCSC), delivered the opening plenary keynote at CYBERUK, presenting a compelling vision of the current and future cybersecurity landscape. Titled "Opening Plenary - NCSC Keynote," Horne's address framed the challenges and opportunities ahead as a "perfect storm," driven by the twin forces of rapid technological advancement and escalating geopolitical tensions. He emphasized that cybersecurity is no longer an isolated technical discipline but a fundamental, shared mission integral to national prosperity and security.

The talk served as a strategic call to action for the cybersecurity community, urging a proactive and adaptive approach to securing the digital realm. Horne highlighted the NCSC's role in navigating this complex environment, from providing guidance on emerging technologies like AI and quantum computing to countering sophisticated nation-state threats. He underscored the critical need for organizations to embed cybersecurity into their core corporate missions, fostering a cultural shift where resilience is viewed as a strategic investment rather than a mere cost.

Horne's address is particularly significant given the NCSC's position at the forefront of the UK's cyber defense efforts. It provides a high-level strategic outlook that aims to galvanize both public and private sectors, outlining the essential steps required to maintain a secure and prosperous digital future amidst unprecedented global uncertainty. The keynote sets the tone for the entire conference, emphasizing collaboration, innovation, and a collective responsibility in the face of evolving cyber threats.

Background

▶ Watch: Introduction: The 'perfect storm' of cyber challenges (0:00)

The NCSC keynote at CYBERUK, delivered by CEO Richard Horne, positions the current cybersecurity landscape within a decade of profound transformation, reflecting on the inaugural Cyber UK conference ten years prior. This historical context serves to highlight the dramatic evolution of technology and geopolitical dynamics that have reshaped the operational environment. A decade ago, the concept of driverless taxis roaming city streets, the ubiquitous influence of artificial intelligence (AI), or the looming threat of quantum computing breaking modern encryption were largely theoretical or nascent. Today, these are realities, fundamentally altering the attack surface and defense paradigms.

Horne articulates that the world is experiencing "the most seismic geopolitical shift in modern history," echoing sentiments from figures like MI6 Chief Blaze Metcalfe, who described the current global state as "more dangerous and contested now than it has been for decades." This shift is characterized by a "space between peace and war," where cyberspace has become an undeniable domain of conflict. The NCSC's experience, handling an average of four nationally significant incidents a week, demonstrates the persistent and escalating nature of these threats. While criminal activity, particularly ransomware, remains a prevalent threat for many organizations, the NCSC observes a significant shift in the origin of nationally significant incidents, with a majority now tracing back "directly or indirectly from nation-states."

This background establishes the "perfect storm" metaphor central to Horne's address: the confluence of rapid technological advancement—creating new vulnerabilities and attack vectors—and rising geopolitical tensions—driving sophisticated, state-sponsored cyber operations. The problem, therefore, is not merely one of technical defense but of national resilience, requiring a comprehensive, whole-of-society approach to cybersecurity that transcends traditional boundaries and adapts to an ever-expanding definition of cyber risk.

Key Findings

▶ Watch: Geopolitical shift: Cyberspace as a contested domain (4:50)

Richard Horne's keynote outlines several critical findings regarding the contemporary and future state of cybersecurity, framed by the "perfect storm" of technological revolution and geopolitical upheaval.

Firstly, the technological revolution presents both immense opportunity and significant risk. Artificial intelligence (AI) is identified as a potential "net positive for cyber defense," offering unprecedented capabilities for detection and response. However, adversaries are also rapidly adopting AI tooling, enabling the "discovery and exploitation of existing vulnerabilities at scale." This highlights a critical finding: AI will quickly expose fundamental cybersecurity weaknesses, such as vulnerable code shipped by tech producers, incomplete or urgent patching, and the failure to replace legacy systems. The NCSC acknowledges that while significant new AI-driven attacks may not yet be prevalent, the success of defenders hinges on embracing AI for defense at least as quickly as attackers leverage it.

Secondly, the looming threat of quantum computing breaking widely used cryptography is a definite future challenge. While the exact timeline is uncertain, the NCSC emphasizes that readiness is "in our gift," highlighting the proactive steps organizations must take to migrate to post-quantum cryptography. This finding underscores the need for forward-looking strategic planning that anticipates disruptive technological shifts long before they manifest as immediate threats.

Thirdly, the rising geopolitical tensions have fundamentally reshaped the threat landscape, with nation-state cyber operations escalating in sophistication and prevalence. Horne explicitly states that the majority of nationally significant incidents handled by the NCSC now originate from nation-states. Specific examples include:

  • China's intelligence and military agencies displaying an "eye-watering level of sophistication" and employing a "whole-of-state approach," positioning them as a "peer competitor in cyberspace."
  • Iran almost certainly using cyber activity to support repression, even targeting British individuals.
  • Russia applying "cyber lessons learned in a theater of war" beyond the battlefield, directing tactics and techniques honed in conflict at states it considers hostile, as evidenced by "sustained Russian hybrid activity" targeting assets across the UK and Europe, including the attacks on the Polish energy sector in December.

A crucial finding from this geopolitical context is that cyber operations are now integral to conflict, as much a reality of modern warfare as drones and missiles. The scope of targeting is widening, making cybersecurity the "home front." Furthermore, the UK must prepare for potential hacktivist attacks at scale during conflict situations, which could mirror the destructive nature of ransomware but without the option to pay a ransom for recovery. This signifies a shift towards a more existential threat where resilience, rather than negotiation, is paramount.

Finally, the definition of cybersecurity itself is expanding. It now encompasses securing operational technology (OT) controlling energy systems and production lines, robotics, space-based communications, autonomous systems and agents, and even technology "physically integrated with human bodies." This broadens the scope of responsibility far beyond traditional IT security, demanding a continuous reimagining of defensive strategies.

Technical Deep Dive

▶ Watch: Rising nation-state cyber threats: China, Iran, Russia (6:00)

Richard Horne's keynote delves into several technical and strategic areas, providing a nuanced understanding of the evolving cyber threat landscape and the necessary defensive responses. The discussion spans emerging technologies, the sophisticated tactics of nation-state actors, and the fundamental shifts required in organizational cybersecurity posture.

On the front of Artificial Intelligence (AI), Horne highlights its dual nature. From a defensive standpoint, AI offers the potential for significant positive impact, enabling faster detection, analysis, and response to threats. However, adversaries are already leveraging AI tooling to accelerate the "discovery and exploitation of existing vulnerabilities at scale." This capability underscores the critical need for organizations to address fundamental security hygiene issues, such as vulnerable code in products from tech producers, patching deficiencies, and the persistence of legacy systems. To counter adversarial AI, the NCSC advocates for embracing AI for defense "at least as quickly as adversaries embrace it to attack." Furthermore, ensuring the security of the AI systems themselves is paramount, with Horne referencing the newly published international standard for AI security as a crucial benchmark to enforce trust and resilience in AI deployments. The NCSC also aims to "shape the new normal of AI-generated code" to improve code quality and reduce vulnerabilities from the outset.

The threat of quantum computing is presented as a long-term, yet inevitable, technical challenge. The ability of a sufficiently powerful quantum computer to "break the widely used cryptography" that underpins global digital security is a known future risk. While the exact timing is uncertain, the NCSC emphasizes proactive preparation. They have published guidance outlining the steps organizations need to take "over coming years" for a successful migration to post-quantum cryptography (PQC). This involves inventorying cryptographic assets, understanding dependencies, and planning for the transition to new, quantum-resistant algorithms. Major technology companies are already taking initial steps in this direction, signaling the industry-wide recognition of this impending cryptographic shift.

Regarding nation-state cyber operations, the technical sophistication and strategic intent are detailed. Horne points to China's intelligence and military agencies exhibiting an "eye-watering level of sophistication" and a "whole-of-state approach," indicating deep integration of cyber capabilities across government and military objectives. This makes China a "peer competitor in cyberspace," implying a breadth and depth of technical capability that rivals leading Western nations. Iran is noted for using cyber activity to support repression, suggesting targeted surveillance, disruption, and data exfiltration operations against perceived threats to its regime, even impacting individuals in the UK.

Russia's cyber operations are described as evolving, with tactics and techniques "honed in conflict" now being directed at states considered hostile beyond traditional battlefields. The NCSC, in collaboration with partners like the National Protective Security Authority, observes "sustained Russian hybrid activity" targeting critical assets across the UK and Europe. The attack on the Polish energy sector in December is cited as a stark example of this reality, demonstrating the willingness to target critical national infrastructure as part of broader geopolitical objectives. This highlights the technical capacity for disruptive and destructive attacks on operational technology (OT) and industrial control systems (ICS).

From a defensive perspective, Horne outlines key technical and architectural principles. Organizations must build defense in depth, ensuring that an "initial foothold by an attacker" does not lead to "catastrophic impact." This involves layered security controls, robust segmentation, and resilient architectures designed to contain breaches. The ability to "respond to remain operational and rebuild following a successful attack" is paramount, moving beyond simple prevention to comprehensive cyber resilience. A particularly strong stance is taken on ransomware: organizations "should already be at the point where paying ransoms in the face of destructive attacks simply doesn't happen." This implies the technical and procedural capability to restore from backups, recover systems, and maintain continuity without capitulating to attacker demands, preparing for scenarios where "paying their way out just isn't an option," such as during large-scale hacktivist attacks in a conflict scenario.

Finally, the expanding definition of cybersecurity itself presents significant technical challenges. Securing operational technology (OT) in energy systems and production lines, robotics, space-based communications, autonomous systems and agents, and even "technology physically integrated with human bodies" (e.g., medical devices, implants) requires specialized technical expertise and tailored security frameworks. These domains often involve unique protocols, hardware, and lifecycle management considerations that differ significantly from traditional IT, demanding a continuous "reimagining of our work" and the development of new security paradigms.

Demo / Proof of Concept

▶ Watch: Cybersecurity as the home front in modern conflict (8:00)

As an opening plenary keynote address, the format of Richard Horne's speech at CYBERUK was primarily strategic and informational, focusing on high-level analysis and policy direction. Therefore, no live demonstration or technical proof of concept was presented during this session. The content concentrated on outlining the current threat landscape, emerging technological challenges, and strategic defensive imperatives rather than showcasing specific tools or attack vectors.

Defensive Implications

▶ Watch: Organizational resilience: Embed cyber, build defense in depth (9:20)

Richard Horne's keynote provides a robust framework for defensive action, stressing that cybersecurity must evolve from a reactive technical problem to a proactive, organization-wide strategic imperative. The defensive implications span technological adoption, strategic planning, and cultural transformation.

Firstly, organizations must embrace AI for defense with urgency. This means actively exploring and integrating AI-powered solutions for threat detection, anomaly analysis, and automated response to counteract adversaries' increasing use of AI. Crucially, this adoption must be paired with ensuring the security of the AI systems themselves, adhering to established benchmarks like the international standard for AI security. This proactive approach extends to shaping the development of AI-generated code to ensure it contributes to higher code quality and fewer vulnerabilities from the outset.

Secondly, a strategic and long-term defensive posture is required for post-quantum cryptography (PQC) migration. Organizations must follow NCSC guidance to identify critical cryptographic assets, assess their dependencies, and develop a comprehensive roadmap for transitioning to quantum-resistant algorithms over the coming years. This is a non-negotiable step to prepare for the eventual breaking of current encryption standards by quantum computers.

Thirdly, in the face of escalating nation-state threats and the integration of cyber operations into modern conflict, organizations must shore up their resilience. This involves a granular understanding of the specific risks posed by sophisticated actors like China, Iran, and Russia, and adapting defenses accordingly. The NCSC's observation of "sustained Russian hybrid activity" and attacks on critical infrastructure like the Polish energy sector underscores the need for robust protections for operational technology (OT) and critical national infrastructure.

A fundamental defensive implication is the absolute necessity of building defense in depth. This architectural principle ensures that initial compromises do not lead to catastrophic impacts. It requires layered security, robust network segmentation, strong access controls, and comprehensive incident response capabilities that allow organizations to "respond to remain operational and rebuild following a successful attack." The NCSC's firm stance that organizations "should already be at the point where paying ransoms in the face of destructive attacks simply doesn't happen" highlights the need for mature backup and recovery strategies, implying that the technical capability to restore systems without reliance on attacker decryption keys is paramount. This readiness is particularly critical when facing hacktivist attacks at scale in conflict situations, where paying a ransom may not be an option.

Furthermore, Horne calls for a profound cultural shift within organizations. Cybersecurity must be embedded into the corporate mission, moving beyond the sole responsibility of IT departments to become a shared mission across all levels, "whether they sit on the board or the IT help desk." This demands greater diversity of skills, minds, and backgrounds within the cybersecurity community. Defenders must advocate for cybersecurity and resilience as a strategic investment, not a cost to be minimized. Organizations that fail to prioritize their "technology base, new and old, as core to their prosperity and security" are not merely naive but "failing to grasp the reality of today's world."

Finally, the expanding definition of cybersecurity means defenders must continually reimagine their work. Securing domains such as robotics, space-based communications, autonomous systems, and human-integrated technologies requires new expertise, specialized tools, and adapted frameworks. This implies continuous learning, cross-sector collaboration, and a willingness to innovate defensive strategies beyond traditional IT boundaries.

Key Takeaways

  • The cybersecurity landscape is defined by a "perfect storm" of rapid technological change, particularly AI and quantum computing, and escalating geopolitical tensions, with cyberspace now an integral domain of conflict.
  • Organizations must proactively embrace and secure AI for defensive purposes, leveraging its potential for threat detection while ensuring the security of AI systems themselves and shaping AI-generated code for quality.
  • Preparation for post-quantum cryptography migration is critical, requiring strategic planning and adherence to NCSC guidance to secure against future quantum threats to current encryption standards.
  • Nation-state cyber threats, exemplified by the "eye-watering sophistication" of China, Iran's repressive cyber activities, and Russia's conflict-honed tactics against critical infrastructure, demand heightened resilience and a robust defense-in-depth approach.
  • Cybersecurity must transition from a technical cost center to a strategic investment and a shared corporate mission, fostering a cultural shift across all organizational levels to build resilience against destructive attacks where ransom payment is not an option.
  • The definition of cybersecurity is expanding rapidly to include operational technology (OT), robotics, autonomous systems, and space-based communications, necessitating continuous adaptation and innovation in defensive strategies.

About the Speaker(s)

Richard Horne is the Chief Executive Officer of the National Cyber Security Centre (NCSC), a component of GCHQ that provides a unified national voice for cybersecurity. In his role, Horne is responsible for leading the UK's efforts to make the country the safest place to live and work online. His keynote at CYBERUK reflects the NCSC's strategic priorities and its commitment to guiding both government and industry through the complex challenges of the digital age. As CEO, he is at the forefront of defining the UK's approach to emerging cyber threats, technological advancements like AI and quantum computing, and the geopolitical dimensions of cyberspace.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Richard Horne's opening plenary at CYBERUK is a competent strategic keynote from someone who genuinely holds the seat he's describing. It's not hollow — the NCSC handles real incidents, and Horne lands a few punches that a corporate keynote speaker couldn't: the explicit nation-state attribution framing, the 'four nationally significant incidents a week' number, the direct call-out of China as a 'peer competitor in cyberspace,' and the unusually firm stance that organizations should already be past the point of paying ransoms. Graded as a strategic/executive keynote, it earns its place on the program. The problem is that almost none of this is new signal. The 'perfect storm' of AI plus…

Heather Calloway (CISO) — SOLID

Richard Horne delivers a competent and credible opening keynote that correctly names the structural forces shaping the threat environment — nation-state escalation, AI duality, quantum migration timelines, and the expanding attack surface into OT and autonomous systems. The framing is serious and the threat characterizations are accurate. But the talk stops consistently at the diagnosis. It identifies what is true without telling organizations what to do with that truth at the institutional level. For a CISO audience that already understands the 'perfect storm' framing, this lands as confirmation rather than direction. It sets a conference tone, which is the job — but it does not move the…

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026