Opening Plenary - Cyber on the Front Line: Protection, Advantage and the Next Decade

Anne Keast-Butler (Director · GCHQ), General Sir Rob Magowan (Commander Cyber & Specialist Operations Command · Ministry of Defence)

CYBERUK 2026 · Day 1 · Main Plenary

Overview

In the opening plenary of CYBERUK, Anne Keast-Butler, Director of GCHQ, and General Sir Rob Magowan, Commander of the UK Cyber and Specialist Operations Command (CSOC) within the Ministry of Defence (MOD), engaged in a pivotal discussion about the evolving landscape of cyber operations. Moderated by Beth, the conversation explored the critical roles of both offensive and defensive cyber capabilities and the collective demands on the UK's cyber posture over the next decade. Against a backdrop of accelerating technological change and a volatile geopolitical environment, the speakers underscored cyber's transformation from a supporting function to a central component of national security and defense.

Watch on YouTube

Visual summary for Opening Plenary - Cyber on the Front Line: Protection, Advantage and the Next Decade by Anne Keast-Butler, General Sir Rob Magowan
Visual summary for Opening Plenary - Cyber on the Front Line: Protection, Advantage and the Next Decade by Anne Keast-Butler, General Sir Rob Magowan

Key moments

  1. 0:00 Introduction to GCHQ Director and Cyber Commander
  2. 1:00 GCHQ's three main contributions to national security
  3. 2:30 MOD's Cyber & Specialist Operations Command and multi-domain integration
  4. 4:15 Five key lessons from the cyber battlefield in Ukraine
  5. 4:30 Ukraine example: Electromagnetic spectrum is decisive battle space
  6. 6:20 Understanding and protecting data as the vital ground
  7. 7:20 Confronting the threat through national and international partnership

Opening Plenary - Cyber on the Front Line: Protection, Advantage and the Next Decade

Speakers: Anne Keast-Butler (Director, GCHQ); General Sir Rob Magowan (Commander Cyber & Specialist Operations Command, Ministry of Defence)

Conference: CYBERUK

YouTube: https://www.youtube.com/watch?v=8ygUKr289KI

Overview

In the opening plenary of CYBERUK, Anne Keast-Butler, Director of GCHQ, and General Sir Rob Magowan, Commander of the UK Cyber and Specialist Operations Command (CSOC) within the Ministry of Defence (MOD), engaged in a pivotal discussion about the evolving landscape of cyber operations. Moderated by Beth, the conversation explored the critical roles of both offensive and defensive cyber capabilities and the collective demands on the UK's cyber posture over the next decade. Against a backdrop of accelerating technological change and a volatile geopolitical environment, the speakers underscored cyber's transformation from a supporting function to a central component of national security and defense.

The talk highlighted the shared responsibilities of GCHQ and the MOD, particularly within the National Cyber Force, emphasizing the necessity of deep integration between intelligence and military operations. Keast-Butler detailed GCHQ's three main contributions: housing the National Cyber Security Centre (NCSC), securely connecting national security systems with advanced cryptographic and network solutions, and providing intelligence and effects to support government direction. General Magowan outlined CSOC's lead command authority across seven functions for defense, with a specific focus on the cyber and electromagnetic domain, stressing the imperative for intelligence-led, integrated capabilities to counter contemporary adversaries.

The discussion delved into the characteristics of state-sponsored threats, the lessons learned from ongoing conflicts such as in Ukraine, and the UK's strategic approach to operating within the "gray zone"—the complex space between peace and war. Both leaders emphasized the indispensable nature of cross-sector partnerships with industry, academia, and international allies, as well as the urgent need to cultivate a robust and diverse talent pipeline. Ultimately, the plenary served as a clarion call for accelerated innovation, strong foundational cyber security, and a unified national effort to maintain a decisive advantage in the rapidly evolving cyber domain.

Background

▶ Watch: Introduction to GCHQ Director and Cyber Commander (0:00)

The contemporary global security landscape is characterized by unprecedented technological acceleration and geopolitical volatility, fundamentally reshaping the nature of conflict and statecraft. In this environment, cyber capabilities are no longer auxiliary but have become central to national defense and the projection of influence. This shift is deeply rooted in the concept of multi-domain integration, where cyber operations are seamlessly interwoven with traditional land, sea, air, and space domains to achieve strategic objectives. The UK's approach, as articulated by Keast-Butler and Magowan, reflects a recognition that adversaries operate across these domains, necessitating a comprehensive, integrated response.

GCHQ, with its origins in signals intelligence during conflict, has a long history of supporting military operations. Its evolution to encompass the NCSC underscores the convergence of national security intelligence and public-facing cyber defense. The establishment of the MOD's Cyber and Specialist Operations Command (CSOC) and the National Cyber Force, a joint GCHQ-MOD entity, further institutionalizes this integration, ensuring that military cyber operations are deeply informed by cutting-edge intelligence. This organizational structure is a direct response to the escalating threat from state actors who exploit cyber vulnerabilities not only for espionage but also for disruption and to shape geopolitical outcomes without escalating to open conflict—a realm often referred to as the gray zone.

The "gray zone" represents a critical area of strategic competition, where states engage in coercive actions below the threshold of armed conflict. These activities often involve sophisticated cyber operations, disinformation campaigns, and economic pressures designed to achieve political aims while maintaining plausible deniability. The challenge for nations like the UK is to develop capabilities that can effectively counter these threats, defend national interests, and deter adversaries within this ambiguous space, all without inadvertently triggering wider escalation. This strategic imperative forms the bedrock of the UK's current cyber policy, emphasizing a "whole-of-system" approach that leverages both offensive and defensive cyber tools in an integrated, intelligence-led manner.

Key Findings

▶ Watch: MOD's Cyber & Specialist Operations Command and multi-domain integration (2:30)

The plenary session delivered several critical insights into the nature of modern cyber warfare and the UK's strategic response. General Magowan presented five key lessons derived from the ongoing conflict in Ukraine, offering a vivid illustration of the contemporary battle space:

  1. The Electromagnetic Spectrum (EMS) is the Decisive Battle Space: The Ukrainian conflict has demonstrated that control and exploitation of the EMS are battle-winning. Magowan provided an example where Ukrainian forces, upon shooting down an adversary drone, rapidly extract its memory board, analyze operating frequencies, and then use that intelligence to spoof or jam those frequencies across the front line. This rapid cycle of intelligence gathering and counter-action highlights the critical importance of electronic warfare (EW) capabilities.
  1. Proactive Engagement is Essential: Nations cannot afford to wait to be attacked. A proactive stance, engaging in operations across the electromagnetic spectrum at a time and choosing, is crucial for maintaining freedom of action. This necessitates legislative frameworks, such as the UK's Defense Readiness Bill, to enable agile and decisive cyber operations.
  1. Local Dominance, Not Universal Domination: It is impossible to dominate the cyber and electromagnetic domains universally and constantly. Instead, the focus must be threat-led, aiming for local dominance for specific periods to achieve particular effects. This requires deep intelligence integration with "fires" (military actions) to understand the domain and apply capabilities precisely.
  1. Data is the Vital Ground: Traditional concepts of "vital ground" (e.g., a strategic hill) have been superseded by data. Protecting data, ensuring its accessibility to authorized personnel, and transforming its protection into a national endeavor are paramount. Magowan stressed that there are "no more Luddites in the battle space"; understanding data as the "bloodstream of the battle space" is fundamental for modern military operations. The more sovereign data is, the more easily it can be shared with allies under fewer restrictions.
  1. Coherent National and International Response: The cyber threat is multifaceted, originating from state actors, criminals, and terrorists, targeting government, industry, and supply chains. No single entity or nation can confront it alone. A coherent, integrated response across national agencies (GCHQ, MOD) and with international allies is the only viable path to defeat these threats.

Anne Keast-Butler further elaborated on the UK's strategic posture in the gray zone, emphasizing a "whole-of-system" approach where cyber operations are part of integrated campaigns. She highlighted the UK's competitive advantage in having a relatively small, interconnected community where government, industry, and academia can readily collaborate. A key finding is the UK's commitment to transparency of approach in cyber statecraft. While specific operational details remain classified, the UK publicly acknowledges that cyber effects operations are a legitimate tool of statecraft, outlined in defense reviews and openly discussed by leaders. This transparency aims to build trust, encourage collaboration with partners, and clearly define the legal and ethical frameworks governing UK cyber actions, thereby making its "fighting machine able to defend us" against a range of threats, from state-sponsored actors to online criminals. The ongoing debate about the efficacy of deterrence in the clandestine "gray zone" was also acknowledged as a complex, unresolved question.

Technical Deep Dive

▶ Watch: Five key lessons from the cyber battlefield in Ukraine (4:15)

While the plenary was primarily strategic, it underscored several critical technical areas and requirements for maintaining cyber advantage. The emphasis on the electromagnetic spectrum (EMS) as a decisive battle space directly implies the need for sophisticated electronic warfare (EW) capabilities. This includes advanced systems for signals intelligence (SIGINT) to rapidly identify adversary frequencies and communication protocols, as well as robust jamming and spoofing technologies to deny, degrade, or deceive enemy forces. The Ukrainian example of stripping drone memory boards for frequency analysis points to a highly agile, real-time technical exploitation capability, requiring expertise in embedded systems, radio frequency engineering, and rapid data forensics.

The declaration that data is the vital ground signifies a profound shift towards data-centricity in military and intelligence operations. This necessitates advanced capabilities in data collection, processing, analysis, and secure dissemination. Technologies for big data analytics, machine learning (ML), and artificial intelligence (AI) are crucial for exploiting vast datasets at machine pace, moving beyond human-speed analysis. Secure data architectures, robust encryption, and sophisticated access control mechanisms are paramount to protecting this vital ground, particularly when sharing intelligence across national and international partners. The concept of "information advantage" hinges on the ability to rapidly secure, process, and act upon data.

General Magowan specifically mentioned the development of a Digital Targeting Web, a system designed to integrate "fires and intelligence and effect." This implies a complex technical architecture that likely involves:

  • Real-time data fusion: Combining intelligence from various sources (SIGINT, OSINT, human intelligence) into a unified operational picture.
  • Automated analysis and decision support: Leveraging AI/ML to identify targets, assess vulnerabilities, and recommend courses of action.
  • Secure communication protocols: Ensuring the integrity and confidentiality of targeting data across diverse operational environments.
  • Interoperability: Facilitating seamless integration with various military platforms and cyber tools.
  • Agile development methodologies: The call for industry to "pick and choose" problem statements within a commercial model suggests a modular, component-based approach to rapidly develop and deploy capabilities for the Digital Targeting Web.

The discussion also highlighted the role of hyperscalers (large technological and IT companies) as both providers of intelligence and targets themselves. Their extensive infrastructure and global visibility offer unique insights into the cyber battle space. Collaborating with them technically involves secure intelligence sharing platforms and joint efforts to identify and mitigate supply chain vulnerabilities—a critical concern given the pervasive nature of modern software and hardware dependencies.

Finally, the talk emphasized the need to accelerate innovation while simultaneously solidifying cyber foundations. This involves investing in the security of critical national infrastructure (CNI), strengthening supply chain resilience through technical standards and auditing, and promoting cyber hygiene among individual citizens. Keast-Butler explicitly mentioned harnessing AI and other tools to accelerate processes and overcome bureaucracy, suggesting a future where automated security operations, threat intelligence platforms, and secure development lifecycles are integrated to achieve "the pace of the machine" in cyber defense. The shift from "platform-centricity" to data-centricity is a fundamental technical and cultural change, recognizing that while physical assets may be slow to adapt, software and data can be rapidly iterated and deployed in the exponential age. This requires flexible, software-defined approaches to defense, enabling rapid adaptation of capabilities.

Demo / Proof of Concept

▶ Watch: Understanding and protecting data as the vital ground (6:20)

This opening plenary session was a strategic discussion and policy overview, not a technical demonstration or a presentation of a specific proof of concept. The speakers focused on overarching strategies, challenges, and collaborative approaches rather than showcasing particular tools, exploits, or defensive technologies.

Defensive Implications

▶ Watch: Confronting the threat through national and international partnership (7:20)

The insights from Keast-Butler and Magowan offer several crucial implications for cyber defenders across government, industry, and critical infrastructure:

  1. Prioritize Foundational Cyber Security: Both speakers stressed that innovation is undermined without strong foundations. Defenders must urgently focus on bolstering cyber foundations within critical national infrastructure (CNI), securing supply chains, and educating individual citizens. This includes implementing robust patching regimes, strong authentication, network segmentation, and incident response plans.
  1. Embrace Intelligence-Led Defense: The emphasis on intelligence as the "bloodstream of the battle space" means defenders must integrate threat intelligence deeply into their security operations. This involves actively consuming and analyzing intelligence shared by government agencies like GCHQ/NCSC, as well as collaborating with industry partners and hyperscalers to gain a holistic view of emerging threats, including supply chain vulnerabilities.
  1. Cultivate Data-Centric Security: Recognizing data as the "vital ground," defenders need to shift their focus from purely perimeter-based defenses to protecting data throughout its lifecycle. This requires advanced data loss prevention (DLP) solutions, robust encryption, stringent access controls, and continuous monitoring for data exfiltration or compromise. The ability to rapidly analyze and exploit security data at machine pace using AI/ML is also critical.
  1. Strengthen Supply Chain Resilience: The explicit concern about supply chain vulnerabilities, particularly those impacting major IT providers, highlights a critical area for defensive action. Organizations must implement rigorous vendor risk management programs, demand transparency from suppliers, and conduct thorough security assessments of third-party components and services.
  1. Foster Cross-Sector Partnerships: The UK's "whole-of-system" approach underscores the necessity of collaboration. Defenders in industry and academia should actively engage with government initiatives, participate in intelligence sharing forums, and contribute to the co-creation of security advisories and standards. This collective defense model enhances overall resilience against sophisticated state-sponsored threats.
  1. Invest in Talent and Diversity: The call for a diverse talent pipeline is not just a human resources issue but a defensive imperative. Diverse perspectives lead to more robust security designs and better problem-solving. Organizations should invest in continuous upskilling for their cyber professionals, create attractive technical environments, and support initiatives like "zigzag careers" that allow talent to move flexibly between public and private sectors, enriching the collective expertise.
  1. Advocate for International Standards and Interoperability: The complexity of international frameworks for cyber operations was identified as a pain point. Defenders should support efforts to develop and adopt common international standards and policies, which facilitate interoperability and seamless collaboration with global allies, ultimately strengthening collective defense capabilities.
  1. Prepare for the "Exponential Age" with Adaptability: The rapid pace of technological change, driven by AI, demands that defensive strategies be highly adaptable. Organizations should adopt flexible, software-defined security architectures that can be quickly updated and reconfigured, moving away from rigid, platform-centric approaches to enable rapid response to evolving threats. The concept of being "fitted for, not with" implies proactive preparation and the ability to bolt on new capabilities as needed.

Key Takeaways

  • Cyber is Central to National Security: Cyber operations are no longer a supporting function but a core element of defense and statecraft, requiring deep integration between intelligence and military capabilities within a multi-domain integration framework.
  • Lessons from Ukraine Drive Strategic Shifts: The conflict in Ukraine highlights the electromagnetic spectrum (EMS) as a decisive battle space, the criticality of data as vital ground, and the necessity for proactive, intelligence-led, and locally dominant cyber operations.
  • The "Gray Zone" Demands Integrated Statecraft: Operating effectively in the ambiguous space between peace and war requires a "whole-of-system" approach, balancing offensive and defensive cyber capabilities, and leveraging the UK's transparency in cyber statecraft to deter and defend national interests.
  • Partnerships are Non-Negotiable: Effective cyber defense and offense demand robust, two-way intelligence sharing and close collaboration with industry, academia, and international allies (e.g., Five Eyes, NATO, European partners) to counter multifaceted threats and secure global supply chains.
  • Talent and Diversity are Paramount: Building a strong cyber future relies on cultivating a diverse talent pipeline, fostering zigzag careers between public and private sectors, and creating technical environments that attract and retain skilled professionals who can contribute a "mix of minds."
  • Pace, Innovation, and Foundations: The exponential age necessitates accelerating innovation at "the pace of the machine," but this must be underpinned by strong cyber foundations in critical national infrastructure (CNI), robust data security, and a shift from platform-centric to data-centric approaches.

About the Speaker(s)

Anne Keast-Butler is the Director of GCHQ, one of the UK's three major intelligence agencies. Her role involves leading GCHQ's efforts in making the UK one of the safest places to live and work online, securely connecting national security systems, and delivering intelligence and effects to support government security objectives. She has a long history within the intelligence services, having been part of the GCHQ leadership team for over a decade, and emphasizes the importance of transparency and public engagement in cyber security.

General Sir Rob Magowan is the Commander of the UK Cyber & Specialist Operations Command (CSOC) within the Ministry of Defence. In this capacity, he holds lead command authority for the cyber and electromagnetic domain across defense. His background includes serving as the Deputy Commander of what was then UK Strategic Command and as the head of military capability in the UK Ministry of Defense, where he worked closely on the Strategic Defense Review. General Magowan's experience encompasses warfighting and strategic planning, and he is a strong advocate for multi-domain integration and intelligence-led operations.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent strategic keynote from two principals who genuinely hold the levers they're describing — the Director of GCHQ and the Commander of UK CSOC don't need to pad their credentials. The Ukraine-derived lessons, particularly the EMS framing and the 'data as vital ground' construct, give this more backbone than the usual ministerial word salad. But it never quite escapes the gravitational pull of the briefing-room approved talking points. The Digital Targeting Web mention and the 'local dominance not universal domination' doctrine are the closest this gets to genuine insider signal, and they're tantalizingly thin. For a CYBERUK opening plenary, this is what it's supposed to be —…

Heather Calloway (CISO) — SOLID

A credible, senior-level signal from two of the UK's most consequential cyber leaders — but the session operates at the level of strategic orientation rather than institutional instruction. Keast-Butler and Magowan articulate a coherent national posture with real conviction. The five lessons from Ukraine are the sharpest material in the room. But the talk is aimed at galvanizing a national community, not equipping security leaders with new decisions to make. For a CISO outside the UK defense and intelligence orbit, the actionable surface is limited.

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026