International Plenary - Global Perspectives On How to Stop Threat Outpacing Resilience
Unknown
CYBERUK 2026 · Day 2 · Main Plenary
Overview
In an era marked by profound geopolitical uncertainty and an ever-accelerating digital transformation, the challenge of maintaining pace with evolving cyber threats has become paramount. This plenary session at CYBERUK, uniquely composed entirely of NCSC's international partners, convened cybersecurity leaders from Singapore, Canada, Latvia, Japan, and France to share their global perspectives on how nations can collectively enhance resilience against a continuously intensifying threat landscape. Chaired by David Cole, Chief Executive of the Cyber Security Agency of Singapore, the discussion underscored a critical pivot: from a sole focus on preventing every cyber attack to building robust, adaptable cyber resilience capable of sustaining operations amidst inevitable breaches.

Key moments
- 0:00 Introduction, geopolitical context, and panel objective
- 2:00 Unprecedented international panel and NCSC's 10-year impact
- 3:15 Rajie on enduring cyber threat drivers and changing pace
- 5:30 The rise of 'democratization of exploitation' and AI
- 6:30 Are high cyber activity levels inevitable? Focus on root causes.
- 8:15 European legislative efforts: Cyber Resilience Act and NIS-2
International Plenary - Global Perspectives On How to Stop Threat Outpacing Resilience
Speakers: David Cole, Chief Executive, Cyber Security Agency of Singapore (Chair); Rajie, Representative from Canada's Cybersecurity Agency; Baba, Representative from Latvia's Cybersecurity Agency; Yoichi, Representative from Japan's National Cyber Office; Vansson, Representative from France's Cybersecurity Agency
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=TjwZ3FQNSvQ
Overview
In an era marked by profound geopolitical uncertainty and an ever-accelerating digital transformation, the challenge of maintaining pace with evolving cyber threats has become paramount. This plenary session at CYBERUK, uniquely composed entirely of NCSC's international partners, convened cybersecurity leaders from Singapore, Canada, Latvia, Japan, and France to share their global perspectives on how nations can collectively enhance resilience against a continuously intensifying threat landscape. Chaired by David Cole, Chief Executive of the Cyber Security Agency of Singapore, the discussion underscored a critical pivot: from a sole focus on preventing every cyber attack to building robust, adaptable cyber resilience capable of sustaining operations amidst inevitable breaches.
The panel explored the persistent drivers of cyber threats, the changing nature of adversarial tactics, and the efficacy of various national and international interventions over the past decade. A central theme emerged regarding the "democratization of exploitation," where advanced tools and techniques become accessible to a broader range of threat actors, further complicating defense efforts. The discussion highlighted the urgent need for harmonized international cooperation, proactive defense strategies, and a fundamental re-evaluation of how digital infrastructure is designed and secured, moving beyond a "high trust" environment that no longer reflects current realities.
This article delves into the insights shared by these international experts, examining the strategic shifts, technical approaches, and collaborative imperatives required to ensure that collective resilience can indeed outpace the escalating global cyber threat. It synthesizes their experiences and recommendations, providing a comprehensive overview of the current state of international cybersecurity thought and action.
Background
▶ Watch: Introduction, geopolitical context, and panel objective (0:00)
The past decade has witnessed a dramatic escalation in the sophistication, scale, and frequency of cyber threats, set against a backdrop of acute geopolitical flux. As David Cole highlighted, the post-World War II rules-based international order is being profoundly challenged, creating an environment where cyber conflicts are increasingly intertwined with broader geopolitical tensions. Rajie from Canada articulated several enduring threat drivers: geopolitical competition, the immense financial returns of cybercrime, and an ever-expanding digital dependency that inherently broadens the attack surface. He noted that the tech ecosystem has been characterized by systemic vulnerability for years, with human centricity remaining a core weakness despite technological advancements.
Despite significant innovation in cybersecurity, panelists acknowledged a broadly deteriorating picture where resilience often fails to keep pace with the evolving threat. Baba from Latvia presented sobering statistics, noting that 2022 saw a six- to eight-fold increase in incidents and vulnerable devices compared to previous years. This pervasive challenge has led some to question whether high levels of malicious cyber activity have become an accepted, almost inevitable, part of the digital landscape. However, the consensus among the panelists was that while acceptance of the presence of high threat levels is necessary, a passive stance is unsustainable. Instead, the focus must shift to understanding and addressing root causes, which are often surprisingly basic.
Legislative efforts, particularly within the European Union, such as the Cyber Resilience Act (CRA) and NIS2, represent attempts to establish a legal framework for improved cyber hygiene and resilience. These regulations aim to raise the bar for security standards and incident reporting across critical sectors. However, the panel also recognized the inherent tension between the rapid pace of technological change and the slower, more deliberate nature of legislative processes. This disparity necessitates a re-evaluation of traditional policy-making approaches to better suit the dynamic cyber domain. The overarching sentiment was a call for a fundamental reorientation of strategy, moving away from an unattainable goal of absolute prevention towards a more pragmatic and achievable objective of rapid recovery and sustained operations in the face of persistent threats.
Key Findings
▶ Watch: Rajie on enduring cyber threat drivers and changing pace (3:15)
The panel's discussion yielded several critical findings that underscore the evolving global cybersecurity landscape and the strategic shifts required to navigate it:
- Shift from Cybersecurity to Cyber Resilience: A unanimous theme was the necessity to transition from solely focusing on cybersecurity (preventing all attacks) to prioritizing cyber resilience (the ability to withstand, recover from, and adapt to cyber incidents). Vansson from France explicitly stated, "We move from the cyber security to the cyber resilience concept which means we stop fighting a losing battle to prevent every cyber attack." This shift acknowledges the inevitability of breaches and emphasizes rapid recovery and continuous operation as primary objectives. Yoichi from Japan echoed this, highlighting the goal to "sustain the government activities... ensure the stable supply of infrastructure services and... maintain our socioeconomic activities as a society as a whole."
- Engagement of Non-Cyber Specialists: A significant finding was the profound impact achieved when cybersecurity discussions move beyond specialists. Vansson noted that the most significant improvements in resilience occurred when "non-cyber security people" became engaged, citing France's major crisis exercise involving over a thousand organizations and focusing on executives, HR, PR, and finance personnel. David Cole humorously (but pointedly) summarized this: "we should actually scary thought speak to non-cyber people nonit people."
- Democratization of Exploitation and Borderless Threats: Rajie highlighted the "democratization of exploitation," driven by phenomena like cybercrime-as-a-service and AI advancements, which expand the world of threat actors. Yoichi emphasized that cyberspace is "borderless," meaning threats from "country of concern" can impact critical infrastructure globally. This interconnectedness necessitates international cooperation, yet differing national standards and regulations create friction.
- The Enduring Importance of Basics and Proactive Measures: Despite advanced threats, the panel stressed that many vulnerabilities stem from basic issues. Rajie mentioned Canada's "top 10 list" of cybersecurity basics, still relevant after 14 years. Baba advocated for foundational controls like DNS firewalls and blocking spoofed calls, citing Latvia's mandatory DNS firewall blocking 2.5 billion malicious requests in three months for a small country. Proactive identification of phishing infrastructure was also highlighted as crucial.
- The Criticality of Trust-Based Partnerships: Rajie emphasized that "establishing that trust and confidence ahead of time" is absolutely vital for effective partnerships, especially during crises. He showcased Canada's success with the Canadian Internet Registry Association (CIRA) and Mozilla Firefox to provide free protective DNS to citizens. The panel broadly agreed that government alone cannot solve these challenges, requiring collaboration with the private sector, local authorities, civil society, and academia.
- Need for Agile Policy and Harmonization: Rajie argued that traditional, slow-paced legislative and policy frameworks are ill-suited for the rapidly evolving tech ecosystem. He advocated for "sharpening the point on some of our engagements internationally" and suggested countries need to "give up a little bit of our individuality, our sovereignty and move collectively and harmonize some of these things."
- Japan's Embrace of Active Cyber Defense (ACD): Yoichi detailed Japan's significant policy update, introducing Active Cyber Defense in its National Security Strategy in 2022. This includes new legislation for information collection, mandatory incident reporting from critical infrastructure operators, and new authority to "penetrate into the malicious servers and computers and neutralize some program."
- France's Focus on Distributed Architecture and Fixing Brittle Infrastructure: Vansson outlined France's move towards a distributed cyber security architecture, including creating regional/sectoral CERTs to spread capabilities and avoid single points of failure. He also raised a fundamental concern about the "brittle" nature of the digital world, arguing that shortcuts taken during its development, biased towards a "high trust environment," now demand fixing, particularly regarding traceability in software supply chains.
Technical Deep Dive
▶ Watch: The rise of 'democratization of exploitation' and AI (5:30)
While the plenary was a high-level strategic discussion rather than a deep dive into specific exploits, several technically significant concepts and initiatives were highlighted, reflecting current national cybersecurity strategies and operational approaches.
A core technical theme was the shift towards resilience-oriented defense mechanisms. This is exemplified by the emphasis on ensuring critical functions can continue or rapidly recover post-incident. Japan's adoption of Active Cyber Defense (ACD) represents a significant technical posture shift. Yoichi detailed new legislation enabling "information collection measures" and "mandatory incidental reporting from critical infrastructure service operators." More notably, Japan is gaining "new authority to penetrate into the malicious servers and computers and neutralize some program which may cause serious damage over our government or critical infrastructure operators." This implies a move beyond passive defense to proactive offensive-defensive operations within its national jurisdiction, aimed at neutralizing threats at their source or within compromised systems before widespread impact. While the specific tools or protocols for penetration and neutralization were not discussed, the strategic intent signals a robust technical capability under development.
From a foundational defense perspective, the panel underscored the effectiveness of basic, yet often underutilized, technical controls. Baba from Latvia championed DNS firewalls as a critical mechanism. He reported that in Latvia, mandatory DNS firewalls for all operators blocked approximately 2.5 billion requests to malicious websites in just three months. This demonstrates the immense scale of routine cyber threats (like phishing and malware command-and-control communications) that can be mitigated at the network edge through simple, widespread technical deployments. This approach directly addresses the "vast majority of population" suffering from less sophisticated attacks.
Canada's initiative to provide free protective DNS to every Canadian citizen, in partnership with the Canadian Internet Registry Association (CIRA) and integrated via a Mozilla Firefox browser plugin, further illustrates the technical potential of making robust security solutions accessible and easy to adopt. This involves CIRA leveraging a shared threat intelligence feed (from Canada's cyber center and commercial sources) to filter malicious traffic, protecting users at the DNS resolution layer. The integration into a popular web browser via a plugin lowers the technical barrier for adoption, making a significant security improvement largely transparent to the end-user.
Vansson from France introduced the concept of building a distributed cyber security architecture. This involves establishing regional and sectoral CERTs (Computer Emergency Response Teams) to decentralize incident response and crisis management capabilities. The technical implication is a move away from a monolithic, centralized defense model towards a more resilient, load-balanced system where "no single point of failure" can cripple national response efforts. This architectural approach aims to enhance overall system robustness by spreading both defensive capabilities and the impact of attacks across multiple, independent nodes.
Furthermore, Vansson critically pointed out the "brittle" nature of the current digital infrastructure, which he attributes to "shortcuts in building that digital landscape over the 30 years where we were talking about dividends of peace and probably we've designed the digital space biased towards a high trust environment." This technical critique highlights fundamental design flaws, particularly concerning supply chain dependencies and traceability. He drew a stark comparison: "it's mindboggling that if you buy a sausage you actually have access to more information than if you buy software nowadays." This calls for a technical re-engineering effort to embed security, transparency, and accountability more deeply into the software development lifecycle and supply chain, especially as new technologies like AI are deployed, urging caution not to "create new weaknesses."
The panel also touched upon the "democratization of exploitation," a phenomenon amplified by technical advancements like cybercrime-as-a-service platforms, which provide sophisticated tools and infrastructure (e.g., ransomware kits, phishing services) to a wider range of less technically skilled actors. The rapid advancements in AI, as Rajie noted, are expected to further accelerate this trend, making it easier for adversaries to generate convincing phishing content, automate attacks, and bypass traditional defenses. This necessitates a continuous technical evolution of detection and prevention mechanisms to stay ahead of AI-powered threats.
Finally, the European legislative frameworks, NIS2 and the Cyber Resilience Act (CRA), though policy instruments, have significant technical implications. The CRA, for instance, aims to mandate cybersecurity requirements for hardware and software products throughout their lifecycle, pushing manufacturers to integrate security by design and default, thereby reducing systemic vulnerabilities at a foundational level.
Demo / Proof of Concept
▶ Watch: Are high cyber activity levels inevitable? Focus on root causes. (6:30)
This panel discussion, focusing on high-level strategic and policy perspectives from international cybersecurity leaders, did not include any technical demonstrations or proofs of concept. The format was entirely conversational, sharing insights and national approaches.
Defensive Implications
▶ Watch: European legislative efforts: Cyber Resilience Act and NIS-2 (8:15)
The insights from this international panel provide a compelling roadmap for defenders grappling with the escalating cyber threat landscape. A primary implication is the urgent need to fundamentally shift defensive strategy from an unattainable goal of absolute prevention to a pragmatic focus on cyber resilience. This means designing systems and processes not just to prevent attacks, but to anticipate, withstand, recover from, and adapt to inevitable breaches, minimizing their impact and ensuring continuity of critical operations.
Defenders must actively engage non-cyber personnel across their organizations. This involves extensive training and awareness campaigns for executives, human resources, public relations, and finance teams, ensuring they understand their roles in crisis management and can contribute effectively when a cyber incident occurs. Cybersecurity can no longer be an isolated domain; it must be an integrated organizational responsibility.
The panel underscored the enduring importance of cybersecurity basics. Defenders should prioritize the implementation of foundational controls that yield high impact. This includes widespread deployment of DNS firewalls to block access to known malicious domains, as demonstrated by Latvia's success. Similarly, efforts to block spoofed calls and other common social engineering vectors should be enhanced. Organizations should revisit their "top 10" or similar lists of essential security practices, recognizing that many pervasive vulnerabilities stem from neglecting these fundamentals. The advice to "stop talking about changing passwords" reflects a move towards more robust authentication methods and a recognition that frequent password changes often lead to weaker, more predictable passwords.
Crucially, fostering public-private partnerships is paramount. Defenders need to proactively build relationships and establish trust with key partners – including other government agencies, critical infrastructure owners, technology companies, and non-profit organizations – before a crisis hits. Canada's initiative with CIRA and Mozilla Firefox for free protective DNS highlights how such partnerships can deliver impactful security solutions at scale, making them easy for citizens to adopt. Information sharing, particularly cyber threat intelligence, is a cornerstone of these collaborations.
From a national security perspective, the adoption of Active Cyber Defense (ACD), as implemented by Japan, signals a strategic evolution. Defenders in relevant national contexts should explore policies and capabilities that allow for proactive measures, such as neutralizing malicious programs or infrastructure, within legal and ethical bounds. This requires sophisticated threat intelligence, robust legal frameworks, and advanced technical capabilities.
Addressing the "brittle" nature of digital infrastructure is a long-term defensive imperative. This involves advocating for and implementing security-by-design principles, demanding greater traceability in software supply chains, and critically evaluating the security implications of new technologies like Artificial Intelligence from their inception. Organizations should push vendors for more secure products and transparent development practices.
Finally, defenders must advocate for agile legislative and policy frameworks that can keep pace with technological change. This includes promoting international harmonization of cybersecurity standards and regulations to reduce friction in global threat response and information sharing. Simultaneously, domestic legislative barriers that hinder the proactive capabilities of CERT teams – such as restrictions on scanning or data handling due to privacy concerns – should be reviewed and updated to empower defenders without compromising fundamental rights. The goal is to create an environment where defenders are not "tying the hands of our own defenders" while adversaries operate without such constraints.
Key Takeaways
- Shift to Cyber Resilience: The primary focus must move from preventing every cyber attack to building robust systems capable of withstanding, recovering from, and adapting to inevitable incidents.
- Engage Non-Cyber Specialists: Cybersecurity is a whole-of-organization challenge; involving executives, HR, PR, and finance personnel significantly improves overall resilience.
- Prioritize the Basics: Many widespread vulnerabilities stem from neglecting fundamental security practices like DNS firewalls, blocking spoofed calls, and strong authentication, which offer substantial defensive impact.
- Proactive, Trust-Based Partnerships: Building strong public-private and international partnerships, founded on trust established before crises, is essential for effective threat intelligence sharing and collective defense.
- Agile Policy and Harmonization: Legislative and regulatory frameworks must evolve more rapidly to match the pace of technological change, with an emphasis on international harmonization to reduce friction and enhance global cooperation.
- Fix Brittle Infrastructure: Address fundamental design flaws in digital infrastructure, including improving software supply chain traceability and ensuring security by design, particularly with emerging technologies like AI.
About the Speaker(s)
The panel was chaired by David Cole, the Chief Executive of the Cyber Security Agency of Singapore. He set the stage by highlighting the acute geopolitical uncertainty and the growing sophistication of cyber threats, emphasizing the panel's focus on how governments and critical infrastructure owners can build resilience.
The panel featured a distinguished group of international cybersecurity leaders:
- Rajie represented Canada's cybersecurity agency. He reflected on enduring threat drivers like geopolitical competition and cybercrime's financial returns, and emphasized the "democratization of exploitation" and the importance of foundational security practices. He also highlighted Canada's successful public-private partnership with CIRA and Mozilla Firefox to provide free protective DNS.
- Baba represented Latvia's cybersecurity agency. He provided data on the increasing number of incidents and vulnerable devices, stressing the need to focus on resilience and the efficacy of basic measures like mandatory DNS firewalls in his country.
- Yoichi represented Japan's National Cyber Office. He detailed Japan's significant policy updates, including the establishment of his organization and the introduction of Active Cyber Defense in the national security strategy, granting new authorities for information collection and neutralizing malicious programs.
- Vansson represented France's cybersecurity agency. He underscored the importance of engaging non-cyber specialists in resilience efforts and discussed France's move towards a distributed cyber security architecture. He also critically assessed the "brittle" nature of current digital infrastructure, calling for fundamental design improvements.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent international policy panel that largely delivers what it promises: senior national cyber agency heads comparing notes on strategy, legislative posture, and collective defense philosophy. The lane here is clearly strategic/executive, and graded on those terms it performs adequately. There are a few genuine signals worth catching — Japan's ACD legislation with explicit offensive-neutralization authority is the sharpest disclosure, Latvia's DNS firewall numbers give rare operational texture, and Canada's CIRA/Firefox partnership is a concrete model other nations could replicate. But the session never escapes the gravity well of five officials reading from their respective national…
Heather Calloway (CISO) — SOLID
A competent, well-structured international plenary that reflects genuine senior practitioner consensus on the resilience-over-prevention pivot. The panel surfaces real operational examples — Latvia's DNS firewall numbers, Canada's protective DNS partnership, Japan's Active Cyber Defense legislation — and correctly identifies that organizational breadth, not just technical depth, is where resilience actually lives. But this is a conversation among peers, not a session that advances the field. The findings land as confirmation of what experienced security leaders already believe, not a challenge to existing assumptions. Useful as a reference point on where allied national cyber agencies are…