CYBERUK 2026 - Ecosystem Track

Unknown

CYBERUK 2026 · Day 1 · Ecosystem Track

Overview

This talk, presented as a dynamic panel discussion at CYBERUK 2026, delves into Scotland's multifaceted approach to bolstering its national cyber resilience, with the overarching goal of becoming a "hard target" for malicious cyber actors. Moderated by Alan, the panel brought together key figures from the Scottish Government, industry, and the digital sector to explore strategies, challenges, and successes in this critical domain. The discussion moved beyond traditional technical defenses, emphasizing a holistic, collaborative ecosystem approach that integrates public awareness, education, industry support, and robust incident response planning.

Watch on YouTube

Visual summary for CYBERUK 2026 - Ecosystem Track by Unknown
Visual summary for CYBERUK 2026 - Ecosystem Track by Unknown

Key moments

  1. 4:00 Conference opening and welcome
  2. 8:00 Panel discussion begins, audience interaction setup
  3. 8:40 Scotland's cyber foundations and collaborative ecosystem
  4. 9:40 Innovative cyber education: "The Bongles" and lifelong learning
  5. 12:50 Challenge: Engaging SMEs in cyber security
  6. 13:20 Why SMEs struggle with cyber: complexity and cost
  7. 14:00 Solutions for SMEs: basic knowledge and shared responsibility

Making Scotland a Hard Target

Speakers: Maggie (Scottish Government), Karen Meekin (CEO, Scotland IS), Jess Emery (IT Director, Weir Group), Keith (Exercising Lead, SC3/Scottish Government)

Conference: CYBERUK 2026 - Ecosystem Track

YouTube: https://www.youtube.com/watch?v=_L2dSopvmKY

Overview

This talk, presented as a dynamic panel discussion at CYBERUK 2026, delves into Scotland's multifaceted approach to bolstering its national cyber resilience, with the overarching goal of becoming a "hard target" for malicious cyber actors. Moderated by Alan, the panel brought together key figures from the Scottish Government, industry, and the digital sector to explore strategies, challenges, and successes in this critical domain. The discussion moved beyond traditional technical defenses, emphasizing a holistic, collaborative ecosystem approach that integrates public awareness, education, industry support, and robust incident response planning.

The conversation highlighted Scotland's unique position as a smaller nation, leveraging agility and strong community ties to drive its cyber agenda. Speakers addressed the pervasive challenges of engaging small and medium-sized enterprises (SMEs) in cyber security, nurturing a diverse talent pipeline, and adapting to rapidly evolving threats like artificial intelligence. This talk is highly relevant for national security strategists, policymakers, industry leaders, and cyber security professionals seeking insights into how a nation can strategically enhance its cyber posture through a blend of policy, education, and public-private partnerships. It underscores the shift from mere technical compliance to a comprehensive, adaptive model of cyber resilience.

Background

▶ Watch: Conference opening and welcome (4:00)

Scotland's journey towards robust cyber resilience is not a recent undertaking, but rather an evolution rooted in initiatives dating back to 2015. The panel underscored that these foundational efforts have culminated in a new national strategy, fostering a highly collaborative ecosystem designed to achieve a "one nation effort" in cyber defense. A cornerstone of this strategy is the Cyber Scotland Partnership, a collective of 22 influential organizations working across various community aspects.

A significant focus has been placed on lifelong learning and public awareness. Scotland has embedded cyber resilience and security training into its education system, introducing concepts to young children through engaging storytelling, notably with the popular book series "The Bongles and The Crafty Crows," which teaches basic password hygiene and data protection. For students, resources like "Cyber Resilience in You" are available, while broader campaigns target older, more vulnerable populations through the third sector. These initiatives aim to drive public understanding of cyber risks, empower individuals to protect themselves, and encourage reporting of cybercrime, which remains significantly underreported.

For businesses, particularly the vital SME sector, the Scotland IS organization, as the trade body and cluster manager for Scotland's digital and tech sector, has played a crucial role. Since its cyber cluster's inception in 2018 with 120 companies, it has grown to over 400. Despite these efforts, a persistent problem is the gap between cyber awareness and action among SMEs. Many small businesses perceive cyber security as too complex or expensive, often pushing it down the priority list behind immediate operational concerns like cash flow and growth. Furthermore, cyber security has historically been siloed as an IT problem, rather than being recognized as an overarching operational risk and reputational risk that spans marketing, HR, and executive leadership. Efforts to address this include funding for Cyber Essentials certification and programs designed to simplify complex cyber concepts, taking it back to basics like strong passwords and two-factor authentication.

The broader landscape is also characterized by evolving threats, with cyber criminals and threat actors becoming increasingly sophisticated. The emergence of AI presents a dual challenge: an opportunity to strengthen defenses, but also a potential tool for adversaries to accelerate attacks. This is compounded by a growingly complex regulatory landscape, as governments worldwide seek to hold organizations accountable for their cyber posture. These combined factors necessitate a strong community and collaborative approach, which Scotland has actively cultivated.

Key Findings

▶ Watch: Scotland's cyber foundations and collaborative ecosystem (8:40)

The panel discussion brought forth several critical findings regarding Scotland's cyber resilience efforts and the broader challenges facing any nation in the digital age:

  1. A Redefined "Hard Target": Being a "hard target" does not mean being unhackable—an unrealistic goal. Instead, it signifies a national capability to absorb shock, respond effectively, and recover quickly from inevitable cyber attacks, thereby minimizing their impact on essential services, business operations, and national infrastructure. This proactive resilience is central to Scotland's strategy.
  1. Strength in Collaboration and Agility: Scotland leverages its status as a smaller nation to foster a highly collaborative ecosystem, exemplified by the Cyber Scotland Partnership. This allows for quicker decision-making and a more unified "one nation effort" compared to larger, more fragmented entities. The ability to share insights and resources among peers is a distinct advantage.
  1. Holistic Lifelong Learning is a National Priority: Scotland has invested significantly in a comprehensive lifelong learning approach, integrating cyber resilience education from primary school (e.g., "The Bongles" books) through to professional development and support for vulnerable older populations. This broad educational foundation is considered a major area where Scotland "bats above its weight."
  1. SME Engagement Remains a Critical Bottleneck: Despite significant efforts, engaging Scotland's vast SME landscape in robust cyber security practices is the "hardest part." SMEs struggle with the perceived complexity, cost, and lack of clear responsibility, often prioritizing immediate business needs over cyber investment. A new approach, potentially involving "carrot and stick" incentives and simplified support models, is needed.
  1. Cyber as a Board-Level, Business-Wide Risk: The consensus among panelists is that cyber security is no longer solely an IT concern but a fundamental board-level risk and business responsibility. Every function, from marketing to HR to the CEO, has a role to play in ensuring cyber resilience. This shift in mindset is crucial for effective defense.
  1. The Dual-Edged Sword of AI: Artificial Intelligence presents both significant opportunities to strengthen defenses (e.g., enhanced threat detection) and substantial risks by potentially empowering adversaries with more sophisticated and rapid attack capabilities. Balancing this dual impact is a key challenge for organizations and nations alike.
  1. Talent Pipeline Challenges and Opportunities: While Scotland has robust programs for entry-level cyber talent (e.g., Cyber First, apprenticeships, HNDs), a mid-level skill bottleneck exists. The panel highlighted the need for better mentoring in hybrid work environments and the importance of recognizing and retraining existing diverse skill sets within organizations (e.g., a driver becoming an incident responder) to address talent shortages and broaden the perception of cyber careers beyond traditional "techie" roles.
  1. Compliance Does Not Equal Security: A crucial distinction emphasized is that achieving compliance (e.g., Cyber Essentials certification) is not synonymous with being secure. Over-reliance on tick-box exercises can create a false sense of security; true resilience requires continuous adaptation, testing, and a mindset that assumes compromise.

Technical Deep Dive

▶ Watch: Innovative cyber education: "The Bongles" and lifelong learning (9:40)

While the panel discussion centered on strategic and policy-level aspects of national cyber resilience rather than specific technical exploits or code, it deeply explored the implications of technical trends and the strategic technical capabilities required to "make Scotland a hard target." The core technical understanding underpinning the discussion is that cyber security is evolving beyond isolated technical fixes to an integrated, operational challenge.

A significant technical trend highlighted was the pervasive influence of Artificial Intelligence (AI). Jess Emery from Weir Group, a multinational engineering technology company, articulated the dual nature of AI. On one hand, AI offers immense potential for productivity gains and can be leveraged to strengthen cyber defenses, for instance, through advanced threat detection, anomaly identification, and automated response mechanisms. On the other hand, the rapid development of new AI models presents a significant risk, potentially enabling adversaries to conduct more sophisticated and rapid attacks, such as generating highly convincing phishing campaigns or automating vulnerability exploitation. The challenge lies in keeping pace with this accelerating technology and ensuring that defensive AI capabilities outmatch offensive ones.

The concept of "secure by design" was briefly mentioned by Karen Meekin, noting that the cyber sector itself has, for over a decade, been creating products and services with security inherently built-in. This principle, while not elaborated with specific architectural examples, underscores a fundamental shift in technical development philosophy—moving away from retrofitting security onto existing systems to integrating it from the outset. This applies not just to software but to hardware, networks, and operational processes, aiming to reduce the attack surface and build inherent resilience.

From a capability development perspective, the discussion touched upon specific programs designed to cultivate technical skills within the workforce. Initiatives like funded HNDs in cyber-focused topics for individuals under 25, apprenticeship routes, and specialized training such as 6-week pen testing courses and 6-week OSINT courses for military personnel transitioning into civilian roles, directly address the need for advanced technical proficiencies. These programs are crucial for developing the "techies" required for roles like incident response, penetration testing, and security architecture, ensuring a steady supply of skilled individuals capable of understanding and mitigating complex technical threats.

Keith's role as the exercising lead also implicitly involves a deep understanding of technical systems and their vulnerabilities. While he focuses on organizational response, the effectiveness of these exercises hinges on simulating realistic technical attack scenarios and evaluating the technical controls and recovery procedures in place. This includes understanding the impact of data breaches, ransomware encryption, and denial-of-service attacks on critical infrastructure and services, requiring a solid grasp of network protocols, system architectures, and data management.

In essence, while the talk avoided granular technical details, its strategic recommendations are deeply informed by an understanding of the evolving technical landscape, the need for secure by design principles, the dual nature of emerging technologies like AI, and the imperative to cultivate a technically proficient workforce capable of building, defending, and recovering complex digital systems. The emphasis is on integrating technical considerations into a broader strategy of risk management and operational resilience.

Demo / Proof of Concept

▶ Watch: Why SMEs struggle with cyber: complexity and cost (13:20)

The CYBERUK 2026 panel discussion, by its very nature as a strategic dialogue, did not feature a live technical demonstration or a proof of concept (PoC) in the traditional sense of showcasing a specific exploit or a new security tool. The format was dedicated to a high-level discussion among experts on policy, strategy, and national resilience.

However, the concept of validating security posture through practical application was central to the discussion, particularly through Keith's role as the exercising lead. He emphasized the profound impact of organizational exercises as a form of "proof of concept" for resilience strategies. These exercises, which he conducts regularly, simulate significant cyber attacks, allowing organizations—especially at the leadership level—to "live through" the experience. This practical engagement helps to translate abstract policies and written procedures into tangible understanding, revealing gaps in preparedness that might otherwise remain undiscovered.

Keith recounted an anecdote of a Head of IT who, despite being aware of cyber threats, genuinely "never thought that this was actually possible and would happen" until experiencing it through an exercise. This highlights how exercises serve as a crucial validation mechanism, proving (or disproving) the effectiveness of an organization's incident response, business continuity, and disaster recovery plans in a controlled environment. They act as a stress test for resilience, demonstrating how an organization would absorb the shock of an attack, respond effectively, and recover quickly, aligning directly with the definition of "making Scotland a hard target." While not a technical PoC of a vulnerability, these exercises are a "proof of concept" for organizational and national resilience capabilities.

Defensive Implications

▶ Watch: Solutions for SMEs: basic knowledge and shared responsibility (14:00)

The discussion at CYBERUK 2026 yielded numerous critical defensive implications, offering actionable insights for a wide range of stakeholders, from individual SMEs to national governments. The overarching theme is a strategic shift from a purely preventative "security" mindset to a more holistic "resilience" framework.

For Small and Medium-sized Enterprises (SMEs):

The panel unanimously identified SME engagement as the most significant challenge. Defenders need to recognize that current approaches are not sufficiently effective.

  • Revisit Engagement Strategy: A new "carrot and stick" approach is needed, moving beyond simply "scaring them to death." This could involve mandating basic cyber security levels for public sector procurement, thereby creating a market incentive.
  • Simplify Support and Incentivize: Learn from international models, such as Singapore's "ACD for SMEs" which reportedly captured 50,000 SMEs by taking away inhibitors and offering incentives and trusted services.
  • Focus on Practicality over Compliance: While Cyber Essentials is a good first step, it must not become a "tick-box exercise." The emphasis should be on genuine security posture improvement, not just certification. Karen Meekin highlighted the availability of funding and partnerships via the Cyber Scotland Partnership to guide SMEs, underscoring the collaborative intent.

For All Organizations (Public and Private Sector):

The paradigm must shift from simply preventing attacks to assuming compromise and preparing for rapid recovery.

  • Embrace Resilience, Not Just Security: Jess Emery stressed that organizations will be targeted and will suffer incidents. The focus must be on building systems, services, and business models that are inherently resilient, capable of absorbing impact and maintaining operations even if systems are unavailable. This involves comprehensive business continuity planning alongside traditional disaster recovery.
  • Test, Test, Test: Keith's expertise highlighted the critical role of organizational exercises. These simulations are invaluable for leadership to experience the reality of an attack, understand written policies, and identify gaps in their response and recovery capabilities. This moves understanding from theoretical to experiential.
  • Cyber as a Business Responsibility: Cyber security must be elevated to a board-level risk and a collective business responsibility, no longer siloed within IT. This requires literacy across all departments—marketing, HR, operations—and leadership buy-in.
  • Compliance Does Not Equal Security: This fundamental principle must guide all defensive efforts. Achieving certifications is a baseline, but true security requires continuous adaptation, threat intelligence, and a proactive posture against evolving threats.

For National Cyber Defense and Talent Development:

Scotland's unique collaborative ecosystem offers specific advantages and responsibilities.

  • Invest in Lifelong Learning and Diverse Talent: Defenders should actively support and expand initiatives like Cyber First, Cyber Drive programs, student placement programs, and scholarships. Crucially, address the mid-level skill bottleneck through enhanced mentoring and internal development.
  • Retrain and Upskill Existing Workforce: Maggie and Keith highlighted the untapped potential within existing workforces. Programs that identify transferable skills (e.g., a MOD driver becoming an incident responder) and offer focused training (e.g., 6-week pen testing or OSINT courses) can significantly bolster national capabilities, especially for those committed to remaining in Scotland.
  • Broaden the Perception of Cyber Roles: Actively challenge the "coder in a hoodie" stereotype. Emphasize the diversity of roles in cyber security, from technical specialists to those in risk management, policy, and communications, to attract a wider talent pool, including those not technically minded.
  • Strategic Measurement of Progress: Maggie and Keith discussed the difficulty but necessity of measuring national cyber resilience. A mix of quantifiable KPIs (e.g., number of businesses achieving Cyber Essentials, students in computing science) and qualitative indicators (e.g., public awareness, recovery capability) is essential to direct focused interventions and demonstrate "direction of travel."
  • Address Public Sector Interconnectedness and Supply Chain Risk: Keith pointed out that Scotland's public sector is highly interconnected, creating both opportunity and risk. This implies a need for robust supply chain concentration risk management and standardized security requirements across all public sector entities and their vendors.

In summary, defensive implications point towards a future where cyber resilience is a continuous, collaborative, and deeply integrated aspect of national and organizational operations, driven by strategic foresight, educational investment, and pragmatic engagement with all sectors of society.

Key Takeaways

  • Holistic Resilience over Pure Security: Scotland's strategy emphasizes building national resilience to absorb shock, respond effectively, and recover quickly from inevitable cyber attacks, rather than aiming for an unachievable "unhackable" state.
  • SME Engagement is Critical and Needs New Approaches: The backbone of Scotland's economy, SMEs, remain the most challenging sector to secure, requiring innovative "carrot and stick" incentives, simplified support models, and a move away from compliance-only mindsets.
  • Cyber is a Business-Wide, Board-Level Responsibility: Cyber security is no longer an isolated IT function but a fundamental operational risk that demands accountability and engagement from all levels of an organization, from the board to individual employees.
  • Talent Development Requires Diverse Pathways and Lifelong Learning: Scotland is investing in lifelong learning from primary school to professional upskilling, focusing on nurturing entry-level talent, addressing the mid-level skill bottleneck, and retraining existing workforces to fill diverse cyber roles.
  • AI Presents Dual Challenges and Opportunities: The rapid evolution of Artificial Intelligence offers powerful tools for strengthening defenses but simultaneously empowers adversaries with more sophisticated attack capabilities, necessitating constant vigilance and adaptation.
  • Collaboration and Agility are National Strengths: As a smaller nation, Scotland effectively leverages its strong collaborative ecosystem, particularly through the Cyber Scotland Partnership, and its inherent agility to implement national cyber strategies and respond to evolving threats more rapidly.

About the Speaker(s)

The panel comprised a diverse group of experts representing government, industry, and the digital sector, each bringing a unique perspective to Scotland's cyber resilience efforts:

  • Maggie (Scottish Government): A key figure in the Scottish Government's cyber initiatives, Maggie has been instrumental in outlining and building Scotland's cyber foundations since 2015, leading to the current strategic framework for cyber resilience. She is a strong advocate for lifelong learning and public awareness, overseeing programs like "The Bongles" book series for children and outreach to vulnerable older people, emphasizing skills as a strategic priority.
  • Karen Meekin (CEO, Scotland IS): As the CEO of Scotland IS, Karen leads the trade body and cluster manager for Scotland's digital and tech sector. She has been a driving force behind the growth of Scotland's cyber cluster, which now boasts over 400 cyber companies. Her work focuses on bridging the gap between cyber awareness and action for SMEs, simplifying complex cyber concepts, and fostering the cyber talent pipeline through initiatives like student placement programs and scholarships.
  • Jess Emery (IT Director, Weir Group): Jess serves as the IT Director for the Weir Group, a multinational engineering technology company based in Glasgow. Previously heading global cyber operations, she brings a vital industry perspective to the panel, particularly on managing the balance between AI opportunity and risk within a global enterprise. She champions the view of cyber security as a board-level risk and emphasizes the importance of a strong, collaborative community in tackling complex global technology challenges.
  • Keith (Exercising Lead, SC3/Scottish Government): Keith's extensive background includes years spent 24/7 on call, coordinating multi-agency support for organizations experiencing significant cyber attacks. In his current role as the exercising lead, he advocates for the critical importance of organizational exercises to prepare leadership and teams for the reality of an attack, ensuring that written policies translate into effective response and recovery capabilities. His focus is on minimizing the impact of attacks through preparedness and rapid recovery.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured policy and ecosystem panel that covers Scotland's national cyber resilience posture with reasonable candor. The speakers are credible in their lanes, the collaborative model is coherent, and a few moments — particularly the SME engagement critique and the 'carrot and stick' procurement lever — approach genuine insight. It doesn't break new ground and won't make headlines, but it's an honest account of what a small nation is actually doing, not just aspiring to, which puts it above the average ministerial fluff piece.

Heather Calloway (CISO) — SOLID

A competent, well-intentioned panel on national cyber resilience that gets the framing right — resilience over prevention, board-level ownership, SME engagement as the hard problem — but stays at the level of consensus without sharpening any of it into something a decision-maker can act on. Scotland's collaborative model is real and the instincts are sound, but the talk doesn't deliver enough specificity to move from interesting to instructive.

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026