Day 2 Opening - Resilience Plenary
Nicola Connelly (Chief Executive Officer · SP Energy Networks), Jonathon Ellison OBE (Director of National Resilience · National Cyber Security Centre (NCSC))
CYBERUK 2026 · Day 2 · Main Plenary
Overview
This plenary session and subsequent expert panel discussion at CYBERUK centered on the critical and evolving landscape of national cyber resilience, focusing particularly on the role of regulation in accelerating cyber defense over the next decade. The session commenced with opening remarks from Beth Hopkins, COO of the NCSC, who emphasized the strategic importance of community collaboration and breaking silos to address the escalating scale and stakes of cyber threats. This was followed by a keynote from Nicola Connelly, CEO of SP Energy Networks, who highlighted the inseparable link between economic growth and robust cyber resilience, particularly within critical national infrastructure (CNI) like the energy sector.

Key moments
- 6:00 Welcome to Day 2 and key challenges
- 8:00 The 'rock' and 'landslide' analogy for change
- 9:15 Call to action: breaking silos and comfort zones
- 10:45 NCSC's specific recommendation: adopting passkeys
- 12:05 Introduction of Nicola Connelly, Scottish Power CEO
- 13:40 Scottish Power's investment and resilience in energy
- 14:30 Resilience defined as trust in essential services
Day 2 Opening - Resilience Plenary
Speakers: Beth Hopkins (Chief Operating Officer, National Cyber Security Centre); Nicola Connelly (Chief Executive Officer, SP Energy Networks); Jonathon Ellison OBE (Director of National Resilience, National Cyber Security Centre); Rita Effit (Assistant Director General of Global Powers and Counter Cyber Crime, Australian Cyber Security Centre); Claudia Plattner (President, Germany's Federal Office of Information Security); Rod Latham (Director of Cyber Security and Digital Identity, Department for Science, Innovation, and Technology); Natalie Black (Group Director for Networks and Communications, Ofcom)
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=UXoStGEcquY
Overview
This plenary session and subsequent expert panel discussion at CYBERUK centered on the critical and evolving landscape of national cyber resilience, focusing particularly on the role of regulation in accelerating cyber defense over the next decade. The session commenced with opening remarks from Beth Hopkins, COO of the NCSC, who emphasized the strategic importance of community collaboration and breaking silos to address the escalating scale and stakes of cyber threats. This was followed by a keynote from Nicola Connelly, CEO of SP Energy Networks, who highlighted the inseparable link between economic growth and robust cyber resilience, particularly within critical national infrastructure (CNI) like the energy sector.
The core of the session was a dynamic panel, moderated by Jonathon Ellison OBE, NCSC's Director of National Resilience, featuring leading figures from cyber security agencies and regulatory bodies across the UK, Europe, and Australia. The discussion delved into the intricacies of cyber regulation, exploring its necessity, scope, and adaptability in a world characterized by rapid technological advancement, global supply chains, and persistent cyber aggression. Key themes included the modernization of legislative frameworks, managing foreign ownership risks, integrating artificial intelligence (AI) for defensive advantage, and ensuring effective incident response and recovery. The talk collectively underscored that cyber resilience is not merely a technical challenge but a multifaceted, whole-of-society endeavor demanding concerted action from governments, industry, and international partners.
The overarching message conveyed throughout the session was one of urgency and shared responsibility. As digital transformation accelerates across all sectors, particularly within CNI, the panelists converged on the idea that robust, adaptive regulation serves as a fundamental lever to protect essential services, foster public trust, and enable sustainable economic growth. The discussions provided a comprehensive, high-level strategic perspective on how nations are grappling with these complex issues, offering insights into legislative approaches, international collaboration, and the future trajectory of cyber defense.
Background
▶ Watch: Welcome to Day 2 and key challenges (6:00)
The discussions at CYBERUK 2026 were framed against a backdrop of rapidly escalating cyber threats and profound technological shifts. Beth Hopkins set the stage by acknowledging the "scale and also the stakes of the threat that we're facing," compounded by the "pace and the acceleration of technology." This pervasive challenge necessitates a re-evaluation of national cyber defense strategies, moving beyond traditional reactive measures to embrace proactive and systemic resilience.
A key driver for the focus on regulation stems from the perceived inadequacy of existing frameworks. Rod Latham from DSIT highlighted that it had been "8 years since NIS came into UK law," a significant period in the fast-moving cyber security domain, rendering older regulations potentially outdated. The economic impact of cyberattacks further underscores this urgency, with Rod Latham citing a UK estimate of £14.7 billion per year – approximately half a percent of GDP – as the cost to the economy, emphasizing that this is "probably an underestimate." This economic burden elevates cyber security from a microeconomic concern for individual companies to a macroeconomic national security imperative.
The increasing digitization and interconnectedness of critical national infrastructure (CNI) are central to this problem. Nicola Connelly elaborated on how sectors like energy are becoming "more digital, more connected, and more interdependent," making them vulnerable to systemic risks. This interdependence means that "resilience increasingly needs to be approached at a system level through collaboration rather than isolation." Natalie Black from Ofcom further noted that "market failures" exist in national security, meaning the market alone cannot deliver the required level of protection, necessitating governmental and regulatory intervention.
Moreover, the global nature of supply chains and technology providers introduces complex challenges related to foreign ownership and high-risk vendors. Jonathon Ellison explicitly raised questions about managing foreign ownership in essential services and supply chains, and the concentration risk associated with a small number of key providers. This forms a critical aspect of national security, as demonstrated by the UK's experience with the Telecoms Security Act and the designation of specific high-risk vendors like Huawei. The need to build domestic capabilities and achieve "digital GDP" (Claudia Plattner) is a direct response to these geopolitical and technological dependencies.
Finally, the advent of Artificial Intelligence (AI) adds another layer of complexity and urgency. While AI offers immense potential for enhancing defensive capabilities, it also presents new attack vectors and amplifies the capabilities of malicious actors. The discussion acknowledged that regulators must adapt at the speed of technology change, ensuring frameworks remain relevant and effective in this rapidly evolving landscape.
Key Findings
▶ Watch: Call to action: breaking silos and comfort zones (9:15)
The plenary and panel discussion yielded several key findings regarding national cyber resilience and the strategic role of regulation:
- Regulation as a Necessary, Evolving Lever: While acknowledging that regulation is often a "last resort" (Claudia Plattner, BSI) and the "hardest lever" (Rod Latham, DSIT), there was universal agreement that it is indispensable. It's not merely about setting minimum standards but actively shaping the future, protecting essential services, enabling agility against new threats, and safeguarding public trust. The consensus was that current regulations, such as the UK's NIS, are outdated (8 years old) and require modernization through initiatives like the Cyber Security and Resilience Bill (CSRB), the EU's NIS2 Directive, and Australia's amended Security of Critical Infrastructure (SOCI) Act.
- Growth and Resilience are Intertwined: Nicola Connelly of SP Energy Networks articulated that "growth without resilience can be fragile." The panel emphasized that cyber resilience is not a separate consideration but must be integrated from the outset in infrastructure design, investment programs, and operating models. This ensures that the increasing digitization and electrification of critical sectors contribute to sustainable national growth rather than introducing systemic vulnerabilities.
- A Whole-of-Society, Collaborative Approach: The scale of the cyber threat demands a "team sport" mentality (Natalie Black, Ofcom). Panelists stressed the importance of breaking down silos – national, sectoral, and disciplinary – to foster collaboration between government, regulators, the private sector, and international partners. This includes sharing threat intelligence, co-creating policy through consultation, and ensuring that resilience extends across complex supply chains. Rita Effit (ACSC) highlighted the importance of mandatory reporting requirements in Australia's SOCI Act for gaining "incredible visibility into the cyber threat environment" and enabling better information sharing.
- Addressing Foreign Dependency and Building Digital Sovereignty: The discussion squarely confronted the challenges posed by foreign ownership and reliance on high-risk vendors in critical infrastructure. Natalie Black detailed the UK's approach with the Telecoms Security Act to manage risks from designated high-risk vendors like Huawei, acknowledging it as a "difficult" and "expensive" but necessary process. Claudia Plattner underscored the need to "get some control back" over technology ecosystems and "strengthen our own digital industry," referring to this as the "digital GDP." This involves significant investment in domestic capabilities, such as the UK's focus on sovereign AI.
- AI's Dual Nature and Regulatory Implications: AI was recognized as a powerful tool for defensive advantage, capable of processing vast quantities of data for detection, response, behavioral analytics, and vulnerability identification (Rita Effit). However, panelists were "clear-eyed about the risks," noting that AI also introduces new vulnerabilities and can be leveraged by attackers. Claudia Plattner distinguished between "cyber for AI" (securing AI systems and their use, addressed by regulations like the EU AI Act) and "AI for cyber" (using AI for defense). Regulation must ensure AI is used securely and ethically while enabling its defensive potential.
- Emphasis on Preparedness, Response, and Recovery: Beyond prevention, the panel highlighted the critical importance of being prepared for inevitable incidents. Rita Effit stressed, "prepare for when a cyber incident is going to happen to you, not just the if." This includes robust continuity plans, rapid restoration of services, and transparent communication with consumers and affected parties (Natalie Black). Australia's SOCI Act's direction power for extreme circumstances serves as a last-resort mechanism to secure and restore services, with the success measured by its non-use, demonstrating effective preparedness.
- Agile and Outcome-Focused Regulation: Regulators must be technology-neutral and focus on outcomes rather than prescriptive, quickly outdated rules (Natalie Black). The CSRB, for instance, aims for flexibility to adapt to future technological developments, allowing for changes in scope and requirements through secondary powers. This approach seeks to enable innovation while maintaining transparency and consistency for regulated entities.
Technical Deep Dive
▶ Watch: NCSC's specific recommendation: adopting passkeys (10:45)
While the plenary and panel primarily focused on policy and strategic aspects of cyber resilience, the discussions inherently touched upon significant technical implications and challenges within critical national infrastructure (CNI) and broader digital ecosystems.
The core premise of the talk revolved around the escalating digitization and interconnectedness of CNI. Nicola Connelly from SP Energy Networks detailed how the energy sector is undergoing a profound transformation with "data, digitization, and connectivity at the heart of everything we do." This includes the development of smart solutions for customers, the modernization of electricity transmission networks, and the integration of renewables. Technically, this implies a massive expansion of the attack surface, as operational technology (OT) systems, once isolated, become increasingly integrated with IT networks and the internet. The deployment of decentralized energy control boxes and various units, as mentioned by Claudia Plattner, introduces numerous new endpoints and potential vulnerabilities that require robust security from the outset.
A recurring technical theme was secure-by-design. Nicola Connelly explicitly stated that resilience "must be part of the design from the outset" in asset programs and operating models. This principle mandates that security considerations are embedded into the earliest stages of system architecture, software development, and infrastructure deployment, rather than being an afterthought. This includes practices like threat modeling, secure coding standards, and vulnerability management throughout the software development lifecycle.
Supply chain security emerged as a critical technical concern. Rod Latham emphasized that "we're only as strong as the wider ecosystem that we depend upon." From a technical perspective, this translates to demanding higher security baselines and better assurance from suppliers and technology providers. Claudia Plattner highlighted the EU's Cyber Resilience Act, which mandates a life cycle approach for digital products, including patch management and the provision of a Software Bill of Materials (SBOM). SBOMs are a crucial technical tool, offering a detailed inventory of components within software, enabling organizations to understand and manage their supply chain risks by identifying known vulnerabilities (e.g., CVEs) in third-party libraries and modules. NCSC's Cyber Essentials certification was also mentioned as a practical step businesses can take to assure the security posture of their supply chain partners.
The role of Artificial Intelligence (AI) in both offense and defense presented a complex technical landscape. Rita Effit from ACSC elaborated on AI's defensive capabilities, including its ability to process "incredibly large quantities of data at a speed and scale that we just aren't able to do" for behavioral analytics and pattern identification. This points to AI-driven Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms, which leverage machine learning algorithms to detect anomalies, identify sophisticated threats, and automate response actions. AI can also be integrated into software development processes to identify vulnerabilities in source code proactively. However, the panelists also acknowledged the technical risks: AI tools "rarely arrive in isolation," bringing "third-party dependencies" and components that can introduce new vulnerabilities if not managed with "good cyber hygiene" and "secure by design, secure by default" principles. The challenge of securing AI systems themselves ("cyber for AI") involves technical considerations like adversarial machine learning, data poisoning, and ensuring the integrity and trustworthiness of AI models.
The discussion on foreign ownership and high-risk vendors had direct technical ramifications. Natalie Black's reference to the UK's program to remove Huawei from telecommunications networks under the Telecoms Security Act illustrates a monumental technical undertaking. This involves complex network re-architectures, replacing existing hardware and software, ensuring interoperability with remaining infrastructure, and managing the associated technical debt and operational disruption. The pursuit of digital sovereignty and investment in sovereign AI (Rod Latham) signals a technical ambition to develop and control critical technological components domestically, reducing reliance on potentially untrusted foreign technologies and ensuring greater control over underlying technology stacks and data processing environments. This requires significant R&D, secure development practices, and the establishment of robust, domestically controlled cloud and AI infrastructure.
Finally, the regulatory frameworks discussed, such as the CSRB and NIS2, while policy-driven, mandate specific technical requirements. For instance, "strengthening reporting requirements" implies robust incident detection and logging capabilities. "Increasing expectations around risk management" translates to implementing comprehensive security controls, vulnerability assessments, penetration testing, and security audits. The designation of data centers as CNI (Rod Latham) places their physical, network, application, and data security under national security scrutiny, demanding adherence to stringent technical standards for their operation and resilience.
Demo / Proof of Concept
▶ Watch: Scottish Power's investment and resilience in energy (13:40)
This session was a high-level plenary and expert panel discussion focused on strategic policy, regulation, and the overarching challenges of national cyber resilience. It did not include any live technical demonstrations, proof-of-concept exploits, or detailed walkthroughs of security tools or methods. The format was entirely conversational, with speakers delivering prepared remarks and engaging in moderated dialogue.
Defensive Implications
▶ Watch: Resilience defined as trust in essential services (14:30)
The detailed discussions on national cyber resilience and regulation offer several critical defensive implications for organizations, particularly those operating within critical national infrastructure (CNI) or contributing to global supply chains:
- Prioritize Proactive Resilience and Secure-by-Design: The clear message is to shift from a reactive "if" mindset to a proactive "when" approach. Organizations must embed resilience into design from the outset ("secure-by-design, secure-by-default"). This means integrating cyber security considerations into every stage of infrastructure development, asset programs, operating models, and system architecture. This proactive stance is crucial for withstanding and recovering from attacks, rather than solely focusing on prevention which is rarely 100% effective.
- Strengthen Supply Chain Security: Defenders must recognize that their security is intrinsically linked to their entire ecosystem. This requires rigorous vetting and continuous assurance of partners, suppliers, and technology providers. Implementing measures such as requiring NCSC's Cyber Essentials certification (or equivalent) from suppliers is a tangible step. Furthermore, demanding Software Bill of Materials (SBOMs) for digital products and components, alongside robust patch management policies across the supply chain, is essential for identifying and mitigating vulnerabilities from third-party dependencies.
- Embrace AI for Defensive Advantage (with Governance): AI offers significant potential to augment defensive capabilities. Organizations should explore leveraging AI for automated threat detection, behavioral analytics, pattern identification, and vulnerability scanning within their networks and codebases. This can act as a force multiplier, freeing up human analysts to focus on complex, nuanced threats. However, this must be done with strong governance and thoughtful risk management, understanding the inherent vulnerabilities and dependencies introduced by AI tools themselves. Organizations need to secure their AI systems ("cyber for AI") while using AI for cyber defense.
- Modernize Security Programs in Line with Evolving Regulation: With new legislation like the UK's Cyber Security and Resilience Bill (CSRB), the EU's NIS2 Directive, and Australia's SOCI Act, organizations, especially CNI operators, must actively engage with these frameworks. This involves understanding expanded scopes, enhanced reporting requirements, and increased expectations around risk management. Compliance should not be seen as a mere checkbox exercise but as a baseline for improving actual security posture, contributing to national resilience.
- Invest in People and Culture: Technology and controls are vital, but "ultimately, resilience is about people" (Nicola Connelly). Defenders must prioritize investing in skills, capability, and culture. This includes training engineers, operators, and analysts, fostering a security-aware culture across the organization, and ensuring that cyber security is a board responsibility. Leadership engagement is critical for driving strategic security initiatives and allocating necessary resources.
- Develop Robust Incident Response and Recovery Plans: Recognizing that some attacks will inevitably succeed, organizations must have well-practiced incident response and recovery plans. These plans should focus on rapid service restoration, business continuity, and transparent, effective communication with affected consumers and stakeholders. The example of Ofcom fining BT £17.5 million for poor communication during a 999 outage underscores the importance of clear, timely engagement during crises. Regularly testing these plans through drills and exercises is crucial for preparedness.
- Foster Collaboration and Information Sharing: Breaking down silos and fostering collaboration is paramount. Organizations should actively participate in information sharing initiatives with government agencies (like NCSC, ACSC, BSI) and industry peers. This allows for better threat intelligence, shared best practices, and a collective, system-level approach to national security challenges.
Key Takeaways
- Regulation is an essential, evolving lever for national cyber resilience, not just a compliance burden, but a tool to shape the future, protect services, and safeguard public trust in the face of escalating threats and rapid technological change.
- Cyber resilience is inseparable from economic growth, requiring a "secure-by-design" approach that integrates security from the outset in all infrastructure investments, operating models, and supply chains to ensure sustainable national development.
- A "whole-of-society" and collaborative effort is critical, demanding that governments, regulators, industry, and international partners break down silos, share intelligence, and work together to manage systemic risks across increasingly interconnected digital environments.
- Artificial Intelligence (AI) offers significant defensive advantages for detection, response, and vulnerability identification, but its adoption must be coupled with strong governance, thoughtful risk management, and a focus on securing AI systems themselves ("cyber for AI") to avoid introducing new vulnerabilities.
- Addressing foreign technology dependencies and building domestic digital capabilities (e.g., sovereign AI, digital GDP) is crucial for national security, requiring strategic investment and frameworks to manage risks associated with global supply chains and high-risk vendors.
- Proactive preparedness, robust incident response, and transparent communication are paramount for managing inevitable cyber incidents, with effective recovery plans and clear engagement with affected parties being as critical as prevention.
About the Speaker(s)
The plenary session and subsequent panel brought together a distinguished group of leaders in cyber security and national resilience:
- Beth Hopkins is the Chief Operating Officer of the National Cyber Security Centre (NCSC). She opened Day 2 of CYBERUK, emphasizing the importance of community, collaboration, and breaking down silos in the face of accelerating cyber threats.
- Nicola Connelly serves as the Chief Executive Officer of SP Energy Networks, part of Iberdrola, one of the world's leading electricity companies. Her keynote highlighted the critical link between economic growth and cyber resilience within the energy sector, emphasizing Scottish Power's significant investment in clean energy and resilient infrastructure.
- Jonathon Ellison OBE is the Director of National Resilience at the National Cyber Security Centre (NCSC). He moderated the expert panel, guiding the discussion on the intricate relationship between regulation, technology, and national cyber resilience.
- Rita Effit is the Assistant Director General of Global Powers and Counter Cyber Crime at the Australian Cyber Security Centre (ACSC). She provided an international perspective on Australia's Security of Critical Infrastructure (SOCI) Act, discussing its mandatory reporting requirements and intervention powers.
- Claudia Plattner is the President of Germany's Federal Office of Information Security (BSI), serving as the country's cyber security authority. She offered insights into European regulatory approaches, including the NIS2 Directive and the Cyber Resilience Act, and the challenges of building digital sovereignty.
- Rod Latham is the Director of Cyber Security and Digital Identity at the Department for Science, Innovation, and Technology (DSIT). He represents the UK department with lead policy responsibility for the incoming Cyber Security and Resilience Bill (CSRB), discussing its scope and the balance between security and economic burden.
- Natalie Black is the Group Director for Networks and Communications at Ofcom, the UK's regulator for telecoms and network infrastructure. She shared Ofcom's experiences in managing security risks, particularly concerning high-risk vendors under the Telecoms Security Act, and the challenges of regulating at the speed of technological change.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent strategic/policy plenary from CYBERUK featuring genuinely senior speakers with real institutional authority — the kind of panel where the people on stage actually control the levers they're discussing. The session covers the UK CSRB, EU NIS2, Australia's SOCI Act, the Huawei removal program, and the BSI's framing of 'cyber for AI' versus 'AI for cyber.' There are occasional flashes of genuine signal — the £14.7bn GDP cost figure, the SOCI direction power framing, Ofcom's £17.5m BT fine as a case study in crisis comms — but the overall product is high-quality conference furniture: well-organized, credibly delivered, and almost entirely predictable if you've been following…
Heather Calloway (CISO) — SOLID
A well-assembled panel of senior national security and regulatory figures covering the right terrain — regulation as resilience lever, supply chain risk, AI's dual role, foreign dependency — but the session delivers strategic alignment more than strategic clarity. The conversation is credible and the speakers are legitimate. What's missing is the kind of specific, uncomfortable accountability that turns a good plenary into a memorable one. Leaders leave knowing the consensus; they don't leave knowing what to decide differently.