Opening Plenary - Ministerial Keynote
Dan Jarvis MP (Security Minister · UK Government)
CYBERUK 2026 · Day 1 · Main Plenary
Overview
In his opening plenary address at CYBERUK, Dan Jarvis MP, the UK's Security Minister, delivered a critical assessment of the nation's cybersecurity posture, emphasizing the profound technological crossroads presented by the convergence of cyber threats and artificial intelligence. The talk, delivered in Glasgow, a city celebrated for its history of innovation and resilience, framed the current security landscape as a direct challenge to national prosperity and safety. Minister Jarvis underscored the escalating volume, sophistication, and ambition of cyberattacks emanating from both criminal syndicates and hostile state actors, shifting the focus from traditional physical threats to a pervasive digital warfare that aims to "hollow us out" from within.

Key moments
- 0:00 Introduction: Glasgow's legacy of innovation and resilience
- 2:30 The evolving nature of cyber warfare and threats
- 4:50 Cybersecurity of British business is a national security matter
- 6:00 Announcing £90M investment and new Cyber Resilience Pledge
- 8:00 AI's profound impact on accelerating cyber threats
- 9:00 Urgent call for government-industry collaboration against AI threats
- 9:40 UK becoming a leading global hub for AI innovation
Opening Plenary - Ministerial Keynote
Speakers: Dan Jarvis MP, Security Minister, UK Government
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=u0sFgfR2jYg
Overview
In his opening plenary address at CYBERUK, Dan Jarvis MP, the UK's Security Minister, delivered a critical assessment of the nation's cybersecurity posture, emphasizing the profound technological crossroads presented by the convergence of cyber threats and artificial intelligence. The talk, delivered in Glasgow, a city celebrated for its history of innovation and resilience, framed the current security landscape as a direct challenge to national prosperity and safety. Minister Jarvis underscored the escalating volume, sophistication, and ambition of cyberattacks emanating from both criminal syndicates and hostile state actors, shifting the focus from traditional physical threats to a pervasive digital warfare that aims to "hollow us out" from within.
The core message of the keynote was a resounding call for a paradigm shift in national cyber defense, moving beyond reactive measures to proactive, resilient, and collaboratively built systems. Jarvis highlighted the imperative for every organization, regardless of size, to recognize its role in national security and adopt fundamental cyber hygiene practices as a non-negotiable baseline. Crucially, the speech unveiled new government initiatives, including a significant financial investment and a Cyber Resilience Pledge, designed to bolster the UK's collective defenses. The Minister also laid out an ambitious vision for leveraging cutting-edge AI capabilities to construct national-scale cyber defense systems, advocating for a direct partnership between the government and frontier AI companies to meet the challenges of a machine-speed threat landscape.
This talk is particularly significant as it articulates the UK government's strategic response to an increasingly complex and AI-accelerated threat environment. It signals a governmental commitment not just to policy and funding, but to a fundamental re-evaluation of how national cybersecurity is conceived, implemented, and sustained through public-private collaboration. By positioning cybersecurity as a matter of national security and integrating advanced AI into the defensive framework, Minister Jarvis outlined a forward-looking strategy designed to protect the UK's critical national infrastructure and economic growth against an evolving array of digital adversaries.
Background
▶ Watch: Introduction: Glasgow's legacy of innovation and resilience (0:00)
The historical backdrop of Glasgow, a city renowned for industrial innovation and engineering prowess, served as a powerful metaphor for the UK's current cybersecurity challenges. Minister Jarvis drew parallels between past breakthroughs—such as artificial refrigeration, antiseptic surgery, and resilient water systems—and the contemporary need for preventative, rather than merely reactive, security solutions. This historical context underscored a legacy of building resilient systems from the ground up, a spirit that the Minister argued must be rekindled in the digital age.
The talk then pivoted to the evolution of the UK's digital landscape, recalling the launch of the ZX Spectrum 44 years prior. This affordable mass-market home computer ignited a generation of "bedroom coders" and digital pioneers who would ultimately build the British digital economy. However, Jarvis lamented that the very digital world they created is now being "weaponized against us." This shift represents a profound change from the Minister's own military background, where threats were primarily physical and adversaries needed to "cross water." Today, the threat landscape is characterized by geopoliticized instability, where attacks on British systems are increasing "in volume, in sophistication, and in ambition."
These attacks, originating from criminal syndicates and ransomware gangs (even targeting "children's nurseries"), as well as hostile states, seek to "quietly hollow us out." The Minister cited the recent attack on Jaguar Land Rover as a stark example, equating its impact to hundreds of physical criminals smashing dealerships. This analogy served to bridge the perceived gap between physical and digital criminality, asserting that there is "no significant difference" in their brazen nature and damaging consequences. The National Cyber Security Centre (NCSC) handled over 200 nationally significant incidents last year, "more than double the year before," a statistic that Jarvis used to declare unequivocally that the "frontline isn't coming, it's already here." This alarming increase in incidents, coupled with the changing nature of warfare, establishes the urgent need for a robust and adaptive national cyber strategy, highlighting why the cybersecurity of British business is now firmly a matter of national security.
Key Findings
▶ Watch: Cybersecurity of British business is a national security matter (4:50)
The ministerial keynote, while not presenting traditional research findings, articulated several critical observations and strategic pronouncements that serve as the foundation of the UK's evolving cyber strategy. These "key findings" reflect the government's current understanding of the threat landscape and its intended responses.
Firstly, Minister Jarvis unequivocally declared that the cybersecurity of British business is a matter of national security. This elevates the importance of corporate cyber resilience from a mere operational concern to a strategic imperative for the entire nation. It implies that economic stability and societal function are directly intertwined with the digital defenses of individual organizations.
Secondly, the talk highlighted the alarming rate at which the threat landscape is evolving, particularly with the advent of Artificial Intelligence (AI). Jarvis noted that AI is "lowering the barrier to entry for our adversaries," "automating attacks," and "finding vulnerabilities in critical systems faster than any human team can patch them." This observation underscores a fundamental shift in the pace and scale of cyber warfare, demanding an equally rapid and scalable defensive response.
A pivotal "finding" presented by the Minister was the revelation concerning Anthropic's new Claude Mythos AI model. In testing, this AI model "autonomously found thousands of zero-day vulnerabilities across major operating systems," uncovering "critical flaws that had gone unnoticed by human experts and automated tools for over two decades." This specific example served as compelling evidence of AI's unprecedented capability in vulnerability discovery, validating the urgent need for AI-powered defenses.
Thirdly, the Minister identified a critical gap: "We cannot fight a machine-speed threat with human-speed bureaucracy." This emphasizes the challenge of traditional governmental and industrial response mechanisms being outpaced by AI-driven threats. It highlights the need for a new model of collaboration that combines sovereign classified intelligence from government with the "speed of the market, commercial agility, and the engineering talent" of the private sector.
Finally, the address announced concrete governmental actions: a new £90 million investment to strengthen cyber resilience, particularly for Small and Medium-sized Businesses (SMBs), and the launch of a new Cyber Resilience Pledge. This pledge, to be introduced in the summer, calls on major organizations to make public commitments to board-level cybersecurity responsibility, NCSC Early Warning service adoption, and demanding Cyber Essentials certification from suppliers. These initiatives represent a clear strategic direction for enhancing collective national cyber resilience through both direct support and incentivized best practices.
Technical Deep Dive
▶ Watch: Announcing £90M investment and new Cyber Resilience Pledge (6:00)
The technical implications of Minister Jarvis's keynote, while presented from a policy perspective, are profound, particularly concerning the transformative role of Artificial Intelligence (AI) in both offense and defense. The Minister explicitly detailed how AI is reshaping the technical landscape of cybersecurity, presenting challenges that necessitate equally advanced technical solutions.
The primary technical shift identified is AI's capacity to "lower the barrier to entry for our adversaries" and "automat[e] attacks." This implies that sophisticated attack methodologies, once requiring specialized human expertise, can now be executed with greater ease and at an unprecedented scale by AI systems. Technically, this could involve AI-driven fuzzing for vulnerability discovery, automated exploit generation based on discovered flaws, and intelligent phishing campaign orchestration tailored to individual targets. The automation extends to the reconnaissance phase, where AI can rapidly map network topologies, identify vulnerable services, and even predict human behaviors to optimize attack vectors.
A critical technical demonstration of AI's capabilities was highlighted with Anthropic's Claude Mythos AI model. This model, in testing, reportedly "autonomously found thousands of zero-day vulnerabilities across major operating systems" and "uncovered critical flaws that had gone unnoticed by human experts and automated tools for over two decades." The technical significance here is multi-faceted:
- Autonomous Vulnerability Discovery: Mythos demonstrates an AI's ability to identify previously unknown security flaws (zero-days) without explicit human guidance or prior knowledge of the vulnerability's signature. This likely involves advanced techniques like static and dynamic code analysis, symbolic execution, or machine learning models trained on vast datasets of code and vulnerability patterns.
- Scale and Speed: Finding "thousands" of vulnerabilities across "major operating systems" at a speed surpassing human teams and existing automated tools for "over two decades" signifies an exponential leap in vulnerability research. This challenges traditional patch management cycles and the efficacy of human-centric security auditing processes.
- Criticality of Flaws: The uncovering of "critical flaws" suggests AI's ability to not only identify bugs but also potentially assess their severity and exploitability, which is a complex task even for expert human analysts.
The Minister's assertion that "we cannot fight a machine-speed threat with human-speed bureaucracy" underscores a fundamental technical and operational dilemma. Traditional security operations often involve manual analysis, human decision-making, and bureaucratic approval processes for patching and remediation. When AI can discover vulnerabilities and launch attacks at "machine speed," human response times become a critical bottleneck. This necessitates technical solutions that can match or exceed this speed, leading to the call for national-scale AI-powered cyber defense capabilities.
While specific technical architectures were not detailed, the objective is clear: capabilities that can "autonomously identifying and addressing vulnerabilities at a speed and scale that no human can match." Conceptually, such a system would require several advanced technical components:
- AI-driven Threat Intelligence and Analysis: Ingesting and processing vast amounts of data, including "sovereign classified intelligence," to identify emerging threats, attack patterns, and adversary tactics in real-time.
- Autonomous Vulnerability Management: Continuously scanning and assessing critical national infrastructure (CNI) and government systems for vulnerabilities, potentially using AI models similar to Mythos, but applied defensively.
- Automated Remediation and Active Defense: The capability to not just identify but also "address" vulnerabilities autonomously. This could involve AI-driven patch deployment, automated configuration changes, network segmentation adjustments, or even the deployment of honeypots and deception technologies to misdirect attackers.
- Scalable Distributed Architectures: To protect the "nation's most critical networks," these AI defense systems would need to operate across diverse and geographically dispersed environments, requiring highly scalable, resilient, and distributed computing architectures.
- Secure AI Development: Given the criticality, the development of these AI defense systems themselves would require rigorous security engineering to prevent adversarial AI attacks or unintended consequences.
The call for collaboration between government and frontier AI companies is technically driven. Government holds unique "sovereign classified intelligence," offering an unparalleled dataset for training and refining defensive AI models. Industry, conversely, possesses the "speed of the market, commercial agility, and the engineering talent to build at scale," which is essential for developing and deploying cutting-edge AI technologies rapidly. This partnership aims to bridge the technical gap between intelligence and implementation, creating a synergistic approach to building advanced cyber defenses.
Demo / Proof of Concept
▶ Watch: Urgent call for government-industry collaboration against AI threats (9:00)
As a ministerial keynote address focused on policy, strategy, and future initiatives, the talk did not include any live technical demonstrations or proofs of concept. The content was entirely declarative, outlining the government's understanding of the threat landscape and its planned responses.
Defensive Implications
▶ Watch: UK becoming a leading global hub for AI innovation (9:40)
The Security Minister's address provides a clear blueprint for defensive action across various organizational levels, emphasizing a shift towards proactive and collaborative cybersecurity. The core defensive implications can be distilled into several key areas:
- Elevated Importance of Basic Cyber Hygiene: Minister Jarvis stated, "Basic cyber hygiene is no longer optional, but the baseline." This means that fundamental security practices—such as strong passwords, multi-factor authentication, regular software updates, basic firewall protection, and regular backups—are now considered the absolute minimum expectation for any organization. Negligence in these areas is implicitly framed as a national security risk. Organizations must invest in robust implementation and continuous enforcement of these foundational controls.
- Mandatory Adoption of Cyber Essentials: The government will "help organizations implement the Cyber Essential standard." This indicates a strong push for organizations, particularly SMBs, to achieve this baseline certification. Cyber Essentials provides a clear framework for implementing essential security controls, making it a critical first step for improving an organization's defensive posture against common cyber threats.
- The Cyber Resilience Pledge: This new initiative, launching in the summer, outlines specific actions for major organizations to elevate their cybersecurity commitment:
- Board Responsibility: Cybersecurity must be treated as a board responsibility, ensuring that it receives strategic oversight, adequate resources, and accountability at the highest organizational levels. This shifts cybersecurity from a purely IT function to a core business risk.
- NCSC Early Warning Service: Organizations are encouraged to sign up for the NCSC's Early Warning service. This allows the NCSC to provide alerts on potential threats targeting an organization's publicly exposed systems, enabling proactive defense.
- Supply Chain Certification: A crucial defensive measure is the demand that "your suppliers are cyber essentials certified." This recognizes that an organization's attack surface extends through its supply chain. By mandating certification, organizations can significantly reduce the risk of compromise through third-party vulnerabilities, a common attack vector.
- Supply Chain Encouragement: Beyond mandating, organizations are urged to "encourage these actions within your own supply chains," fostering a culture of collective security throughout the ecosystem.
- Strategic Investment for SMBs: The £90 million investment is explicitly targeted at providing "practical, targeted support to help our small and medium-sized businesses." SMBs are often disproportionately vulnerable due to limited resources and expertise. This investment aims to provide the necessary tools and guidance to uplift their defenses, recognizing their collective importance to the national economy and supply chains.
- Leveraging AI for National Cyber Defense: The most forward-looking defensive implication is the call to "build national-scale AI-powered cyber defense capabilities." This means that defenders must embrace advanced AI to:
- Match Machine Speed: Counter AI-driven attacks with AI-driven defenses, capable of "autonomously identifying and addressing vulnerabilities at a speed and scale that no human can match."
- Proactive Vulnerability Management: Utilize AI for continuous, autonomous discovery and remediation of vulnerabilities, moving beyond reactive patching.
- Enhanced Threat Intelligence: Integrate AI with "sovereign classified intelligence" to gain a deeper, faster understanding of the threat landscape.
- Collaboration: Private sector AI expertise is critical for developing these capabilities. Organizations with AI talent are called upon to partner with the government in this "generational endeavor."
- Collective Responsibility: The Minister concluded by emphasizing that "Whether you are a sole trader, a supplier to an NHS trust, or the CTO of a multinational, you are part of our national defense." This instills a sense of shared responsibility, urging every entity to contribute to the nation's digital borders by adopting preventative systems and matching the "speed and ambition" of adversaries.
In essence, the defensive implications require a multi-layered approach: strengthening the basics, securing the supply chain, investing strategically in vulnerable sectors, and aggressively adopting advanced AI capabilities through public-private partnerships to build a truly resilient national cyber posture.
Key Takeaways
- Cybersecurity is National Security: The security of British businesses is no longer just a corporate concern but a critical matter of national security, demanding strategic oversight and investment from all organizations.
- AI Transforms the Threat Landscape: Artificial Intelligence is accelerating the volume, sophistication, and automation of cyberattacks, lowering barriers for adversaries and enabling rapid discovery of zero-day vulnerabilities at machine speed.
- Proactive Defense is Paramount: The UK must shift from reactive responses to building preventative, resilient systems, mirroring historical innovation, to counter evolving threats effectively.
- Basic Cyber Hygiene is Non-Negotiable: Implementing and maintaining fundamental security practices like the Cyber Essentials standard is the absolute minimum expectation for all organizations operating in the modern economy.
- Supply Chain Security is Critical: Organizations must extend their security mandates to their supply chains, demanding Cyber Essentials certification from suppliers and encouraging best practices throughout their networks.
- AI-Powered National Defense is the Future: The government is committed to developing national-scale AI-powered cyber defense capabilities, requiring direct partnership with frontier AI companies to autonomously identify and address vulnerabilities at unprecedented speed and scale.
About the Speaker(s)
Dan Jarvis MP is the Security Minister for the UK Government. Prior to entering politics, he served in the armed forces, a background he referenced in his speech when discussing the shift from physical to cyber warfare. His current role places him at the forefront of the UK's national security strategy, particularly concerning cyber threats and the integration of emerging technologies like AI into defensive frameworks.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A ministerial keynote that hits the expected notes — cyber is national security, AI is changing everything, SMBs need help — but delivers almost nothing an informed practitioner couldn't have reconstructed from last year's NCSC annual review and a government press release. The one moment that could have been genuinely interesting, the Anthropic Claude 'Mythos' AI model claim about autonomously finding thousands of zero-days across major operating systems, is either a hallucination in the summary writeup or a grossly irresponsible unverified claim dropped from a ministerial podium without qualification. Either way it's a problem. The £90M SMB investment and the Cyber Resilience Pledge are…
Heather Calloway (CISO) — WEAK
Dan Jarvis delivers a competent ministerial keynote that correctly elevates cybersecurity as a national security concern and announces real commitments — £90 million in SMB investment and a Cyber Resilience Pledge with board-level accountability requirements. But the talk is undermined by a factually dubious centerpiece claim about an 'Anthropic Claude Mythos' model autonomously finding thousands of zero-days across major operating systems, a claim that has no public corroboration and reads like either a hallucination in the source article or a ministerial briefing error. That problem aside, the speech leans heavily on rhetorical framing — 'the frontline is already here,' 'machine-speed…