Ecosystem Plenary - Cyber in the UK's Industrial Strategy: Breaking Barriers to Growth
Unknown
CYBERUK 2026 · Day 1 · Main Plenary
Overview
This plenary session at CYBERUK delves into the critical role of the UK's burgeoning cyber sector within the nation's broader industrial strategy. Featuring a diverse panel of experts from government, venture capital, academia, and pioneering startups, the discussion centers on how to maximize the sector's growth potential while simultaneously bolstering national resilience. The talk explores the inherent tension between treating cybersecurity as a strategic growth engine and its foundational, horizontal role in underpinning the security of all other economic sectors.

Key moments
- 0:00 Introduction: UK cyber sector growth, challenges, and strategic importance
- 1:45 Andrew Elliot: Cyber as a high-growth sector in industrial strategy
- 3:06 Kirsten Connell: Investor's view on cyber, AI, and trust
- 7:00 Ali Al Kafarani: Cyber security must be recognized as core infrastructure
- 8:24 Rachel Connell: Founder's journey for a safer, more secure internet
Ecosystem Plenary - Cyber in the UK's Industrial Strategy: Breaking Barriers to Growth
Speakers: Andrew Elliot, Deputy Director for Cyber Security, Department for Science, Innovation, and Technology; Kirsten, First Check Fund, Octopus Ventures; Ali Al Kafarani, Founder & CEO, PQ Shield; Dr. Rachel Connell, Founder & CEO, Trust Elevate; Simon, University of Bristol
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=KO7TFoD2QSk
Overview
This plenary session at CYBERUK delves into the critical role of the UK's burgeoning cyber sector within the nation's broader industrial strategy. Featuring a diverse panel of experts from government, venture capital, academia, and pioneering startups, the discussion centers on how to maximize the sector's growth potential while simultaneously bolstering national resilience. The talk explores the inherent tension between treating cybersecurity as a strategic growth engine and its foundational, horizontal role in underpinning the security of all other economic sectors.
The session highlights that despite impressive double-digit growth and a valuation exceeding £13 billion, the UK cyber sector faces significant systemic barriers. These include challenges in securing later-stage investment, navigating complex government procurement processes, and fostering a culture that truly values and integrates cyber innovation. The panelists collectively argue that overcoming these hurdles is essential not only for the cyber sector's continued prosperity but also for safeguarding the UK's economic future and critical national infrastructure against an ever-evolving threat landscape.
The discussion is particularly relevant for policymakers, investors, cybersecurity professionals, and entrepreneurs seeking to understand the strategic direction of the UK cyber ecosystem. It offers a candid assessment of current strengths and weaknesses, proposing actionable insights into how the UK can better align its strategic choices to benefit both economic growth and national security, ultimately aiming to position the UK as a global leader in cyber resilience and innovation.
Background
▶ Watch: Introduction: UK cyber sector growth, challenges, and strategic importance (0:00)
The UK cyber sector has demonstrated robust growth, with Andrew Elliot, Deputy Director for Cyber Security at the Department for Science, Innovation, and Technology (DSIT), noting its double-digit growth every year since 2017, now valued at over £13 billion. This impressive trajectory led to its conscious inclusion as one of the six frontier technologies within the UK's industrial strategy, signifying its recognition as a key driver of economic prosperity. However, the panel quickly establishes that cyber's role is dual-faceted: it is both a high-growth sector in its own right and a horizontal enabler of resilience across the entire economy.
The foundational premise of the discussion is that while the UK possesses significant talent and ambition in cybersecurity, fully realizing its potential requires addressing entrenched challenges. Simon, lead author of the Cyber Growth Action Plan and a researcher at the University of Bristol, underscores this by stating that despite the sector's healthy growth, "the problem is getting bigger, the threat's getting bigger." This escalating threat necessitates not just fundamental cyber hygiene but continuous innovation, a demand signal that needs to originate from other sectors to foster a "virtuous cycle" of growth and resilience.
Panelists bring varied perspectives to this background. Kirsten, from Octopus Ventures, provides an investor's view, highlighting the UK's strong heritage and talent but also pointing to a critical gap in growth-stage funding compared to the US market. Ali Al Kafarani, founder of PQ Shield, a company specializing in post-quantum cryptography, articulates the challenges faced by deep-tech startups building foundational infrastructure, where the development cycle for new standards can span many years, creating a disconnect with typical startup investment horizons. Dr. Rachel Connell, CEO of Trust Elevate, further elaborates on the "ultramarathon" nature of building standards-based solutions, particularly in areas like age checking (PAS 1296, now ISO 27566) and delegated authority for AI agents, where regulatory adoption lags technical innovation.
A recurring theme is the perceived status of cyber within the broader strategic framework. Ali Al Kafarani provocatively asserts that cyber security is not truly "sitting" anywhere but is "squeezing itself between tech and defense." He argues passionately that cyber security should be recognized as a core infrastructure in itself, akin to physical infrastructure like steel, rather than merely a support function for other critical national infrastructure (CNI). This sentiment sets the stage for a discussion on how to elevate cyber's strategic importance and dismantle the barriers currently impeding its full contribution to the UK's industrial ambitions.
Key Findings
▶ Watch: Andrew Elliot: Cyber as a high-growth sector in industrial strategy (1:45)
The panel discussion unveiled several critical findings regarding the state and future trajectory of the UK's cyber sector within the national industrial strategy:
- Cyber's Strategic Underappreciation: Despite its recognized status as a high-growth frontier technology, there's a strong sentiment that cyber security is not yet fully treated as a core infrastructure. Ali Al Kafarani's assertion that it "squeezes itself between tech and defense" highlights its perceived lack of a distinct, central strategic position. The panel argued that this underappreciation leads to it being viewed as an operational cost rather than a fundamental capital investment essential for business continuity and national resilience.
- Growth-Stage Investment Gap: While the UK boasts a vibrant early-stage investment landscape with active angel communities and numerous funds, Kirsten from Octopus Ventures identified a significant growth-stage funding gap. She noted that UK companies, even those with strong product-market fit and scaling nicely, often have to seek later-stage funding from the US. This frequently necessitates establishing a US footprint, potentially diverting focus and talent away from the UK and preventing the nation from fully reaping the rewards of its initial investments in innovative startups.
- Ineffective Government Procurement: Andrew Elliot revealed concerning statistics regarding government procurement of cyber security solutions. In the last 12 months, the public sector awarded £1.5 billion in cyber security contracts. However, while 37% of these contracts went to SMEs (the same percentage as in 2019), the value of those contracts awarded to SMEs plummeted from 25% in 2019 to a mere 9%. This "wrong trajectory" indicates a systemic failure in translating policy intent into practical support for UK startups, creating an immense barrier for innovators like Ali Al Kafarani, who described navigating government procurement as "more difficult than finding backstage here."
- Regulation as a Double-Edged Sword: Dr. Rachel Connell articulated the "ultramarathon" challenge faced by startups building standards-based solutions to meet regulatory demands. While legislation like the Online Safety Bill can drive demand, the process of developing, adopting, and enforcing standards (e.g., PAS 1296 evolving into ISO 27566) is painstakingly slow, often taking years. This extended timeline creates significant pressure on startups, who need sustained investor faith to survive until regulatory compliance creates market pull.
- Shifting Liability and Board-Level Imperative: Rachel Connell also highlighted a "massive sea change" in liability, particularly driven by recent court rulings. She cited cases where platforms were held responsible for harms due to "design deficits" in their AI algorithms, and judges ruled that insurers were not obliged to cover directors and officers (D&O) or fines for "deliberate" security failures. This shift transforms cyber resilience from an IT-department issue into a board-level concern, as directors face direct personal liability, thereby compelling greater strategic investment and oversight.
- Culture as the Ultimate Enabler/Barrier: Simon emphasized that while specific programs and policies are necessary, the underlying culture is paramount. He stressed the need for a "culture of cyber innovation and cyber growth" that permeates from government leadership to boardrooms and wider society. This cultural shift would foster a broader understanding of the threat, drive demand for resilience, and create the conditions for leaders to connect knowledge creation (universities) with knowledge exploitation (market adoption) more effectively.
Technical Deep Dive
▶ Watch: Kirsten Connell: Investor's view on cyber, AI, and trust (3:06)
While the panel discussion primarily focused on strategic, economic, and policy aspects of the UK cyber sector, it touched upon several advanced technical domains, illustrating the complexity and long-term investment required for foundational cybersecurity innovation. The panelists, particularly Ali Al Kafarani and Dr. Rachel Connell, represent companies operating at the cutting edge of critical technical challenges.
Post-Quantum Cryptography (PQC): Ali Al Kafarani, as the founder and CEO of PQ Shield, is at the forefront of post-quantum cryptography. This field is dedicated to developing cryptographic algorithms that are secure against attacks by future large-scale quantum computers. Ali explained that PQC involves "changing the underlying math so that the problems that we believe are difficult to solve for classical computers are also difficult to solve for quantum computers." PQ Shield is actively involved in co-authoring new global standards for cryptography, a monumental undertaking with a projected timeline of 7 to 8 years for the standards to mature from draft to official adoption. This extended development cycle underscores the challenge for deep-tech startups operating in areas that require significant, patient capital and government backing before market adoption can be driven by standardized compliance. The work in PQC is not merely an incremental improvement but a fundamental overhaul of the cryptographic foundations that secure global digital communications and data.
Agentic AI Commerce and Delegated Authority: Dr. Rachel Connell's work with Trust Elevate addresses the complex identity and security challenges emerging with the proliferation of agentic AI, particularly in commerce. Her platform aims to "orchestrate IDs for the agentic AI commerce and actually all agentic AI." This involves tackling intricate questions such as:
- How do we give an AI agent an identity?
- How is that identity bound to a human and connected to a business?
- How do AI agents operate across domains securely?
- How are situations handled where AI agents subdelegate and become autonomous?
- What happens when the underlying Large Language Model (LLM) brain of an AI agent needs to be switched (e.g., from one LLM to another for different tasks)?
The critical need for cyber resilience in this context is paramount, as demonstrated by scenarios where an AI agent's compromise could lead to "bank accounts being drained." Rachel's work extends from her previous experience authoring the PAS 1296 age checking code of practice, which has since become ISO 27566—an international standard for age verification. She is now actively working with the Open ID Foundation and ISO on developing standards for delegated authority, which she sees as a perfect blueprint for managing AI agents. This involves establishing technical standards, policy frameworks (in collaboration with organizations like UNHCR and the European Commission), and certification processes to ensure legal and technical interoperability globally (e.g., with the Canadian Trust Framework DIAC). This area highlights the intersection of cutting-edge AI, identity management, international standards, and legal compliance.
Cyber Essentials: Simon highlighted Cyber Essentials as a successful example of a program that has created a "virtuous circle." This government-backed scheme helps organizations, particularly SMEs, protect themselves against a range of common cyber attacks. Its technical core revolves around five key controls: firewalls, secure configuration, user access control, malware protection, and patch management. The success of Cyber Essentials lies not just in improving organizational resilience but also in fostering a vibrant ecosystem. Simon noted that the number of companies involved in providing certifications has grown from about 20 to 400, with an additional 150 companies offering cyber advisor services. This demonstrates how a clear, actionable technical standard, when coupled with government procurement requirements, can effectively drive both defensive posture and economic growth within the cyber sector.
These examples underscore that while the plenary was a high-level discussion, the underlying technical work driving the UK's cyber future is deeply complex, foundational, and requires long-term strategic support.
Demo / Proof of Concept
▶ Watch: Ali Al Kafarani: Cyber security must be recognized as core infrastructure (7:00)
As this was a panel discussion focused on strategic and policy issues within the UK cyber sector, there were no live demonstrations or proof-of-concept presentations. The format was entirely conversational, with panelists sharing insights, experiences, and proposals.
Defensive Implications
▶ Watch: Rachel Connell: Founder's journey for a safer, more secure internet (8:24)
The panel discussion offered several critical defensive implications for organizations, governments, and the broader cybersecurity community, emphasizing a shift from reactive protection to proactive, strategic integration of cyber resilience.
- Elevate Cyber Security to Core Infrastructure Status: Ali Al Kafarani's impassioned plea to recognize cyber security as a core infrastructure, akin to physical utilities, is perhaps the most significant defensive implication. This reframing demands that governments and organizations cease treating cyber as merely an IT operational cost or an optional burden. Instead, it must be viewed as a foundational capital investment essential for business continuity and national resilience. For defenders, this means advocating for budgets and strategic planning that reflect this fundamental importance, ensuring that cyber security is integrated into the earliest design phases of all new technologies and systems.
- Board-Level Accountability and Risk Management: Dr. Rachel Connell's insights into the shifting legal landscape, particularly regarding insurer liability and direct director/officer responsibility for "design deficits" leading to cyber incidents, are a game-changer. This makes cyber resilience an undeniable board-level issue. Defenders must leverage this to gain executive buy-in, secure adequate resources, and elevate cyber risk discussions to the highest echelons of organizational leadership. It mandates a shift from compliance-driven minimums to a proactive, risk-aware culture where security by design is not just a buzzword but an enforceable principle with personal consequences for leaders.
- Prioritize Innovation and Standards Adoption: The panel highlighted the critical need for CISOs and government departments to actively engage with and adopt innovative UK cyber products and standards. Andrew Elliot noted that CISOs' roles extend beyond "protect and defend" to "get ahead of the threat" through innovation. This implies a defensive strategy that doesn't just rely on established vendors but actively partners with early-stage companies developing cutting-edge solutions, such as post-quantum cryptography or AI agent identity management. Defenders should advocate for dedicated innovation budgets (as suggested by Simon) and participate in initiatives that connect government buyers with startups to validate and integrate novel technologies.
- Influence and Adopt Foundational Standards: Rachel Connell's experience with ISO 27566 and her work on delegated authority for AI agents underscore the long-term defensive value of standards. While the process is an "ultramarathon," investing in and adopting these foundational standards ensures interoperability, consistency, and a globally recognized baseline for security. Defenders should engage with standards bodies, advocate for their adoption, and prioritize solutions built upon open, collaborative standards rather than proprietary, siloed technologies.
- Rethink Government Procurement as a Defensive Tool: Andrew Elliot's data on declining SME share in government cyber contracts reveals a systemic weakness. A more agile and accessible government procurement process is not just an economic lever but a defensive one. By streamlining access for innovative UK startups, the government can directly strengthen its own cyber posture with cutting-edge, domestically developed solutions. Defenders within government should push for reforms that enable "fast-track" procurement for innovative technologies, transforming government into a "design partner" and "seal of approval" for nascent solutions.
- Foster a Culture of Cyber Resilience and Growth: Simon's emphasis on culture—a "culture of cyber innovation and cyber growth"—is a holistic defensive strategy. This involves educating employees, fostering internal talent, and creating an environment where security is seen as an enabler, not a blocker. For organizations, it means investing in training, promoting cyber awareness from the top down, and encouraging cross-sector collaboration to share threat intelligence and best practices, ultimately creating a more resilient national ecosystem.
- Integrate Cyber Security into New Technology Investments: Ali Al Kafarani's proposal for a 20% "overhead" for cyber infrastructure in major technology investments, such as the UK's £500 million for AI and £2 billion for quantum, is a direct defensive recommendation. This ensures that security is baked in from the outset, not bolted on as an afterthought. For any organization embarking on new technology adoption (AI, IoT, quantum computing), this model serves as a blueprint for proactive security budgeting and integration, preventing future vulnerabilities and costly retrofits.
In essence, the defensive implications from this panel converge on a strategic imperative: cyber security must transition from a technical support function to a central, integrated pillar of national and organizational strategy, driven by leadership, innovation, and a robust standards-based ecosystem.
Key Takeaways
- Cyber as Core Infrastructure: The UK cyber sector, despite its £13 billion valuation and double-digit growth, must be strategically recognized and treated as a core national infrastructure rather than merely a supporting technical function, necessitating a shift in investment and policy focus.
- Bridging the Investment Gap: While early-stage capital is robust, a significant growth-stage funding gap in the UK forces promising cyber companies to seek US investment, potentially leading to a loss of talent and economic benefit.
- Government Procurement Barriers: Government procurement processes are a major impediment, with the value of cyber contracts awarded to SMEs plummeting from 25% to 9% of the £1.5 billion public sector spend between 2019 and 2023, hindering innovation adoption.
- Evolving Liability and Board Responsibility: Recent legal rulings are shifting liability for cyber incidents to a board-level imperative, making direct personal accountability for "design deficits" a critical driver for increased strategic investment in cyber resilience.
- The "Ultramarathon" of Standards: Developing and adopting foundational standards (e.g., ISO 27566 for age checking, new post-quantum cryptography standards) is a multi-year "ultramarathon" for startups, requiring sustained support and patient capital to deliver long-term systemic change.
- Culture is Paramount: A fundamental culture change is needed across government, industry, and society to foster cyber innovation, empower leaders with growth missions, and drive a demand signal for advanced cyber resilience solutions.
About the Speaker(s)
- Andrew Elliot is the Deputy Director for Cyber Security at the Department for Science, Innovation, and Technology (DSIT). With a background that includes managing the Digital Economy Act, he brings a government perspective on policy, regulation, and the strategic positioning of cyber security within the UK's industrial strategy. He is focused on how government decisions can drive growth and support UK startups.
- Kirsten is an investor currently running the First Check Fund at Octopus Ventures, a sector-agnostic pre-seed fund that has backed 60 companies in the last three years, including several cyber security firms. She began her career at CCAM, investing in transformational businesses, and later launched Sylon, Europe's first cyber security accelerator, supporting over 60 innovative companies like Tessian, Immersive Labs, and Risk Ledger.
- Ali Al Kafarani is a mathematician and cryptographer, the Founder and CEO of PQ Shield, a company specializing in post-quantum cryptography. He co-founded the cryptography group at Oxford University's math department, a project funded by NCSC and GCHQ, after working at HP Labs for over a decade. PQ Shield is an international company working with governments, including the US, to co-author new standards for cryptography.
- Dr. Rachel Connell is the Founder and CEO of Trust Elevate, a platform orchestrating IDs for agentic AI commerce and all agentic AI. With a PhD analyzing pedophile activity on the internet, she has dedicated three decades to creating a safer internet. She is the author of the PAS 1296 age checking code of practice, which has become ISO 27566, and works with the Open ID Foundation and ISO on delegated authority and AI agent identity.
- Simon is associated with the University of Bristol, bringing over 30 years of industry experience, much of it at HP Labs where he served as Director of Cyber Security Research. He was a lead author for the Cyber Growth Action Plan, focusing on levers to help the cyber sector grow and its strategic role within the industrial strategy, particularly the connection between cyber resilience and other economic sectors.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent ecosystem panel from CYBERUK that stays firmly in the strategic/policy lane. The strongest moment is Andrew Elliot dropping a concrete, uncomfortable number — SME share of government cyber contract value collapsing from 25% to 9% between 2019 and 2023 against a £1.5B spend baseline. That's the kind of specific, attributable, unflattering data point that makes a policy panel worth attending. Everything else is solid but familiar: growth-stage funding gap, procurement friction, culture change, cyber-as-core-infrastructure. The panel has the right people — a DSIT deputy director who actually owns the levers, a VC who built Europe's first cyber accelerator, a PQC founder with…
Heather Calloway (CISO) — SOLID
A credible and well-composed policy panel that does real work naming structural barriers — procurement failure, growth-stage funding gaps, liability shift, cultural inertia — but stays firmly in the problem space. The governance framing is present and the specific data point on SME contract value dropping from 25% to 9% is the kind of number that belongs in a board deck. The liability discussion is the most consequential thread in the session. But the panel never quite commits to telling anyone what to do next, and the 'cyber as core infrastructure' argument, while directionally correct, remains rhetorical rather than actionable. For a CISO audience this is a useful situational read on the…