CYBERUK 2026 - Welcome to Day 2

Beth Hopkins (Chief Operating Officer · National Cyber Security Centre (NCSC))

CYBERUK 2026 · Day 2 · Main Plenary

Overview

Beth Hopkins, Chief Operating Officer of the National Cyber Security Centre (NCSC), delivered a compelling welcome address for Day 2 of CYBERUK 2026. Her talk, titled "Welcome to Day 2," served as a strategic call to action, reflecting on the critical themes that emerged from the conference's opening day and setting an ambitious tone for the collaborative efforts ahead. The address moved beyond a mere procedural welcome, instead urging the assembled cybersecurity community to embrace a proactive, interconnected approach to countering the escalating global cyber threat.

Watch on YouTube

Visual summary for CYBERUK 2026 - Welcome to Day 2 by Beth Hopkins
Visual summary for CYBERUK 2026 - Welcome to Day 2 by Beth Hopkins

Key moments

  1. 0:00 Welcome and stark themes of cyber threat
  2. 1:09 The 'rock' metaphor for sparking change
  3. 2:16 Focusing on Day 2's tactical goal
  4. 2:41 Key advice: break silos, step out of comfort zone
  5. 3:20 Examples of breaking silos at Cyber UK
  6. 4:00 Personal invitation for Day 2 engagement
  7. 4:22 Specific call to action: support passkeys

CYBERUK 2026 - Welcome to Day 2

Speakers: Beth Hopkins, Chief Operating Officer, National Cyber Security Centre (NCSC)

Conference: CYBERUK

YouTube: https://www.youtube.com/watch?v=jzks05nd7WM

Overview

Beth Hopkins, Chief Operating Officer of the National Cyber Security Centre (NCSC), delivered a compelling welcome address for Day 2 of CYBERUK 2026. Her talk, titled "Welcome to Day 2," served as a strategic call to action, reflecting on the critical themes that emerged from the conference's opening day and setting an ambitious tone for the collaborative efforts ahead. The address moved beyond a mere procedural welcome, instead urging the assembled cybersecurity community to embrace a proactive, interconnected approach to countering the escalating global cyber threat.

The essence of Hopkins' message revolved around the dual challenges of the immense scale and high stakes of cyber threats, exacerbated by the relentless pace of technological advancement. Recognizing the community's inherent sense of responsibility, she proposed a powerful metaphor: the idea of creating a "landslide" of positive change through individual sparks of connection, collaboration, and innovation. This vision underscored the NCSC's strategic imperative for collective action, emphasizing that isolated efforts are insufficient against a pervasive and evolving adversary.

This talk is particularly significant because it frames the tactical opportunities of a conference like CYBERUK within a broader strategic imperative. It serves as a directive from a leading national cybersecurity authority, highlighting that the path to resilience lies not just in technical prowess but equally in organizational agility, cross-sectoral cooperation, and a willingness to challenge established norms. By focusing on breaking down silos and encouraging participants to step out of their comfort zones, Hopkins articulated a crucial pathway for the cybersecurity community to move from merely reacting to threats to actively shaping a more secure digital future.

Background

▶ Watch: Welcome and stark themes of cyber threat (0:00)

The context for Beth Hopkins' address was the conclusion of Day 1 of CYBERUK, a day marked by speeches from prominent figures, including Richard and the Security Minister, alongside numerous panel discussions. From these, Hopkins observed "pretty stark themes" that painted a clear, albeit challenging, picture of the contemporary cyber landscape. Foremost among these was the sheer scale and stakes of the threat, a pervasive and ever-present danger impacting national security, economic stability, and individual privacy. This threat, she noted, is further "compounded by the pace and the acceleration of technology," implying that defensive strategies must adapt rapidly to keep pace with an attacker's evolving capabilities and the proliferation of new attack surfaces.

Another profound theme that resonated through Day 1, and which Hopkins highlighted, was the tangible "sense of responsibility that this community hold to respond to that challenge." This collective burden, while weighty, also represents a powerful impetus for action. Hopkins used two competing mental images to illustrate the dilemma facing the community. The first, a "bleak" depiction of King Canute futilely attempting to command the tide with a trident, symbolized the futility of isolated or insufficient efforts against an overwhelming, natural force. This analogy underscored the core problem: traditional, siloed approaches, where individual organizations or nations attempt to stem the tide of cyber threats independently, are destined to fail given the global, interconnected nature of the adversary and the digital realm.

The second, more optimistic image, and the one Hopkins ultimately championed, was that of a "landslide." This metaphor directly addresses why the problem exists and how it can be overcome. Instead of a lone figure battling an unstoppable force, a landslide suggests that "you only need one rock, one idea, one conversation, one spark, one connection, one collaboration" to initiate a cascade of change. The implicit prior work here is the ongoing, often fragmented, efforts of the cybersecurity community. The problem is not a lack of effort, but often a lack of integrated, synergistic effort. Hopkins' call to break down silos and step out of comfort zones directly targets this fragmentation, recognizing that the current threat environment demands a departure from conventional, insular practices to foster the widespread, collaborative "landslide" necessary to effectively counter the relentless "tide" of cyber threats.

Key Findings

▶ Watch: Focusing on Day 2's tactical goal (2:16)

While Beth Hopkins' address was a keynote and not a presentation of research findings in the traditional sense, it laid out several critical observations and strategic directives that serve as the "key findings" of her analysis of the current cyber landscape and the community's response. These can be categorized as follows:

Firstly, the overwhelming nature of the cyber threat: Hopkins explicitly stated the "scale and also the stakes of the threat that we're facing and that's compounded by the pace and the acceleration of technology." This is a foundational observation, acknowledging the severity and dynamism of the environment in which the cybersecurity community operates. It underscores the NCSC's view that the challenge is not static but continually expanding and evolving, demanding equally dynamic countermeasures.

Secondly, the community's inherent sense of responsibility: Hopkins noted that she "heard but also felt was a sense of responsibility that this community hold to respond to that challenge." This highlights a crucial psychological and cultural aspect within the cybersecurity sector – a shared recognition of its vital role in safeguarding digital infrastructure and society. This collective ethos is identified as a powerful, though sometimes latent, asset that can be harnessed for greater impact.

Thirdly, the power of collective action and individual initiative: Rejecting the "bleak" image of King Canute, Hopkins introduced the "landslide" metaphor. This is a core "finding" about the mechanics of change in a complex system: "you only need one rock, one idea, one conversation, one spark, one connection, one collaboration to really get things moving." This emphasizes that significant strategic shifts can originate from seemingly small, individual acts of engagement and cooperation, rather than solely top-down directives. It reframes the challenge from an insurmountable problem to one that is amenable to distributed, community-driven solutions.

Fourthly, the critical mechanisms for progress: Drawing from discussions on Day 1, Hopkins distilled two primary imperatives for achieving this "landslide." These are the "importance of getting out of our silos and of breaking those down" and "stepping out of your own comfort zone." These are presented as essential operational and cultural shifts required for the community to effectively "reimagine our response." Breaking silos addresses organizational and national fragmentation, while stepping out of comfort zones encourages innovation, adaptability, and personal growth among professionals. Examples like the international day and the women in cyber breakfast were cited as practical demonstrations of these principles in action.

Finally, a specific strategic technical recommendation: In a direct call to action, Hopkins stated, "We wouldn't mind if you backed the idea of passkeys. Actually, we published a report yesterday recommending that it's the first choice for consumers logging into all digital services." This is a concrete technical finding and a significant policy recommendation from the NCSC. It highlights a specific technology solution that the NCSC believes can dramatically improve baseline security for a broad user base, moving away from vulnerable password-based authentication towards a more robust and user-friendly alternative. This recommendation serves as a tangible example of the type of innovative, impactful change the "landslide" aims to achieve.

Technical Deep Dive

▶ Watch: Key advice: break silos, step out of comfort zone (2:41)

While Beth Hopkins' address was primarily a strategic keynote focused on community engagement and collaboration rather than a detailed technical exposition, it did contain one significant technical recommendation that warrants specific attention: the endorsement of passkeys. Hopkins explicitly stated, "We wouldn't mind if you backed the idea of passkeys. Actually, we published a report yesterday recommending that it's the first choice for consumers logging into all digital services." This statement, though brief, carries substantial technical weight, indicating a clear strategic direction from the NCSC.

Passkeys represent a significant evolution in authentication technology, designed to replace traditional passwords and multi-factor authentication (MFA) methods with a more secure, phishing-resistant, and user-friendly approach. Technically, a passkey is a cryptographic credential that allows users to sign in to websites and applications without needing to type a password. Instead, it leverages public-key cryptography, where a unique pair of keys – a public key and a private key – is generated for each user account on a service.

When a user registers for a service using a passkey, their device generates these keys. The public key is securely stored with the service provider, while the private key remains on the user's device (e.g., smartphone, laptop, hardware security key). This private key is typically protected by the device's built-in security features, such as a biometric sensor (fingerprint, face recognition) or a device PIN.

The key technical advantages of passkeys, which likely informed the NCSC's recommendation, include:

  1. Phishing Resistance: Unlike passwords, which can be easily phished through malicious websites that mimic legitimate login pages, passkeys are cryptographically bound to the legitimate website or application. When a user attempts to log in, their device verifies the origin of the login request. If the website's domain doesn't match the one the passkey was registered with, the private key will not be used, effectively neutralizing phishing attempts. This is a critical improvement over traditional authentication, as phishing remains one of the most prevalent and successful attack vectors.
  2. Increased Security: By using strong, unique cryptographic keys for each service, passkeys eliminate common password-related vulnerabilities such as reuse across multiple sites, weak passwords, and credential stuffing attacks. Even if a service provider's database is breached, the stored public keys cannot be used to compromise user accounts, as the private keys are never transmitted to the server.
  3. Enhanced User Experience: From a user perspective, passkeys simplify the login process. Instead of remembering complex passwords, users can log in with a simple biometric scan or PIN, similar to unlocking their device. This ease of use can significantly improve adoption rates for stronger security practices.
  4. Cross-Device and Platform Compatibility: Passkeys are being standardized by the FIDO Alliance and major tech companies (Apple, Google, Microsoft), ensuring interoperability across different operating systems and browsers. Users can often use a passkey stored on one device (e.g., a phone) to authenticate on another device (e.g., a laptop) through proximity or cloud synchronization, provided their accounts are linked and secured.

While the talk itself did not delve into the intricate cryptographic protocols or implementation details of passkeys, the NCSC's recommendation for them as the "first choice for consumers logging into all digital services" underscores a strategic shift towards more robust, hardware-backed, and user-friendly authentication mechanisms. This guidance from a national cybersecurity authority signals a strong push for widespread adoption of a technology designed to fundamentally enhance online security against prevalent threats.

Demo / Proof of Concept

▶ Watch: Personal invitation for Day 2 engagement (4:00)

Beth Hopkins' address at CYBERUK 2026 was a keynote welcome speech, primarily focused on strategic vision, community engagement, and setting the tone for the conference's second day. As such, the presentation did not include any live technical demonstrations or proofs of concept. Her talk was designed to inspire collaboration and highlight key strategic directions, rather than showcase specific tools, vulnerabilities, or exploits.

Defensive Implications

▶ Watch: Specific call to action: support passkeys (4:22)

Beth Hopkins' strategic address, despite its high-level nature, carries profound defensive implications for the cybersecurity community. Her call to action provides a framework for how defenders, from individual practitioners to national organizations, should adapt their strategies to counter the escalating and evolving cyber threat landscape.

Firstly, the emphasis on breaking down silos is a critical defensive imperative. Cyber threats are rarely confined to a single sector, organization, or national border. Attackers frequently leverage supply chain vulnerabilities, target common software flaws across diverse industries, and operate globally. Therefore, defenders must move beyond isolated defenses. This implies:

  • Enhanced Threat Intelligence Sharing: Organizations and nations must actively share information about emerging threats, attack methodologies, and indicators of compromise (IOCs). This can be facilitated through platforms like ISACs (Information Sharing and Analysis Centers) and national cybersecurity agencies like the NCSC.
  • Cross-Sectoral Collaboration: Joint exercises, incident response planning, and shared best practices between critical infrastructure sectors (e.g., energy, finance, healthcare) are essential. This ensures a coordinated response when a threat impacts multiple interconnected systems.
  • International Cooperation: Cybercrime and state-sponsored attacks transcend national boundaries. Collaborative efforts with international partners, as exemplified by CYBERUK's international day, are vital for attribution, disruption, and collective defense.

Secondly, Hopkins' encouragement to step out of one's comfort zone translates directly into the need for continuous adaptation and innovation in defensive strategies. The "pace and acceleration of technology" means that static defenses quickly become obsolete. Defenders must:

  • Embrace New Technologies and Methodologies: This includes exploring and adopting advanced security architectures like Zero Trust, leveraging AI/ML for threat detection, and implementing cutting-edge authentication solutions like passkeys.
  • Foster a Culture of Learning and Experimentation: Security teams should be encouraged to research, test, and implement novel defensive techniques, even if they challenge established practices. This includes moving beyond traditional perimeter defenses to focus on detection and response capabilities within networks.
  • Challenge Assumptions: Regular red teaming, purple teaming, and security audits should not just identify vulnerabilities but also question underlying architectural and policy assumptions that might create blind spots.

Thirdly, the NCSC's explicit recommendation for passkeys as the first choice for consumer authentication has immediate and significant defensive implications. Widespread adoption of passkeys would:

  • Drastically Reduce Phishing Success Rates: As passkeys are cryptographically bound to specific domains, they inherently resist phishing attacks, which often rely on tricking users into entering credentials on fake websites. This would eliminate a major initial access vector for attackers.
  • Mitigate Credential Stuffing and Brute-Force Attacks: Since passkeys are unique and strong cryptographic credentials, they are not susceptible to dictionary attacks or the reuse of compromised passwords from other breaches.
  • Improve Overall Security Posture: By removing the weakest link (passwords) from the authentication chain, organizations can significantly enhance the baseline security for their users, reducing the attack surface and freeing up security resources to focus on more sophisticated threats. Defenders should actively advocate for and implement passkey support in their own services and educate their user base on the benefits and adoption of this technology.

Finally, the overarching metaphor of creating a "landslide" through "one spark, one connection" highlights the importance of individual agency within the defensive community. Every security professional, regardless of their role, has the potential to contribute to collective resilience by sharing insights, proposing innovative solutions, and fostering collaboration. This bottom-up contribution complements the top-down strategic guidance, creating a robust, multi-faceted defensive ecosystem capable of responding to the complex challenges of the modern cyber threat.

Key Takeaways

  • The global cyber threat landscape is characterized by its immense scale and high stakes, further complicated by the rapid pace and acceleration of technology, demanding a unified community response.
  • To effectively counter these threats, the cybersecurity community must actively break down silos – whether national, sectoral, or disciplinary – to foster enhanced collaboration and information sharing.
  • Individuals and organizations are urged to step out of their comfort zones, encouraging innovation, adaptability, and the exploration of new defensive strategies and technologies.
  • Significant strategic change can be initiated by seemingly small actions; "one rock, one idea, one conversation, one spark, one connection, one collaboration" can create a powerful "landslide" of positive impact.
  • The NCSC specifically recommends passkeys as the "first choice for consumers logging into all digital services," highlighting a critical technical shift towards more secure, phishing-resistant, and user-friendly authentication.
  • The cybersecurity community bears a profound sense of responsibility to collectively adapt, innovate, and collaborate to build a more resilient digital future.

About the Speaker(s)

Beth Hopkins serves as the Chief Operating Officer (COO) of the National Cyber Security Centre (NCSC), a component of GCHQ that provides cyber security guidance and support to the UK. In her role as COO, Hopkins is responsible for the operational effectiveness and strategic delivery of the NCSC's mission. Her address at CYBERUK 2026 underscored her commitment to fostering a collaborative and adaptive cybersecurity community. Her position places her at the forefront of the UK's national cybersecurity efforts, giving her a unique perspective on the strategic challenges and opportunities facing the nation and its partners in the digital realm. Her emphasis on breaking down silos and encouraging innovation reflects a leadership approach focused on collective strength and proactive engagement in the face of evolving threats.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A conference day-two welcome address from the NCSC COO that amounts to motivational framing with a single concrete technical data point — a passkeys recommendation buried in the closing minutes. Hopkins is a credible speaker with real institutional authority, but this slot produced nothing that a practitioner couldn't have gotten from a two-paragraph press release. The landslide metaphor is worked hard but delivers little payload. The one substantive signal — NCSC formally recommending passkeys as first-choice consumer authentication — is real and worth noting, but it was a reference to a separately published report, not content developed for this session.

Heather Calloway (CISO) — WEAK

Beth Hopkins is a credible senior operator delivering a welcome address from a position of genuine institutional authority. The passkeys endorsement is the one concrete, actionable output from this session — a clear national-level recommendation with real defensive relevance. But the surrounding talk is almost entirely motivational framing: landslide metaphors, calls to break silos, urgency about scale and pace. These are not findings. They are conference refrains. The article's attempt to dress them up as 'key findings' and a 'technical deep dive' doesn't change what the underlying session is: a day-two warm-up act. There's no accountability framework, no governance implication, no risk…

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026