Lead Sponsor Keynote - Scottish Power Energy Networks
Nicola Connelly (Chief Executive Officer · Scottish Power Energy Networks)
CYBERUK 2026 · Day 2 · Main Plenary
Overview
In a compelling keynote address at CYBERUK, Nicola Connelly, Chief Executive Officer of Scottish Power Energy Networks, underscored the critical importance of cyber resilience in safeguarding the UK's vital energy infrastructure. Delivered from Glasgow, the home city of Scottish Power, the talk resonated with the conference's theme, "the next decade, accelerating our cyber defense," by emphasizing that the future of energy is being shaped now through strategic investments and the continuous strengthening of foundational security. Connelly articulated a vision where resilience is not merely a reactive measure but an intrinsic component of growth, essential for building public trust and ensuring the sustained operation of essential services in an increasingly electrified and interconnected world.

Key moments
- 1:50 Scottish Power's record investment in UK clean energy
- 2:40 Resilience is about trust in essential services
- 3:30 Scottish Power's ambition: Securing a better future quicker
- 5:00 National resilience requires government and industry collaboration
- 6:00 Scottish Power's four priorities for accelerating cyber defense
- 8:05 People and culture are fundamental to real resilience
- 9:10 Making cybersecurity a board-level responsibility
Lead Sponsor Keynote - Scottish Power Energy Networks
Speakers: Nicola Connelly, Chief Executive Officer, Scottish Power Energy Networks
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=xHDCHgmqu6o
Overview
In a compelling keynote address at CYBERUK, Nicola Connelly, Chief Executive Officer of Scottish Power Energy Networks, underscored the critical importance of cyber resilience in safeguarding the UK's vital energy infrastructure. Delivered from Glasgow, the home city of Scottish Power, the talk resonated with the conference's theme, "the next decade, accelerating our cyber defense," by emphasizing that the future of energy is being shaped now through strategic investments and the continuous strengthening of foundational security. Connelly articulated a vision where resilience is not merely a reactive measure but an intrinsic component of growth, essential for building public trust and ensuring the sustained operation of essential services in an increasingly electrified and interconnected world.
The address highlighted Scottish Power's ambitious investment of up to £24 billion by 2028—equating to £18 million every working day—into clean, green energy infrastructure. This unprecedented commitment to modernization and expansion brings with it a profound responsibility: to ensure that this growth is not fragile but is instead underpinned by robust security and governance. Connelly positioned cyber resilience as a shared national endeavor, requiring seamless collaboration between government, regulators, the private sector, and national bodies. The talk served as a powerful reminder that as the UK transitions to a cleaner, more digital energy landscape, the speed of technological advancement must be matched by an accelerated and integrated approach to cyber defense.
The core message stressed that electricity underpins nearly every facet of modern life—from homes and hospitals to transport and digital communications. As the economy electrifies further, the imperative for resilient energy systems only intensifies. Connelly's insights provided a strategic roadmap for integrating security into every stage of infrastructure development, operational models, and supply chain management, ultimately aiming to build a future where trust in essential services is unwavering, even in the face of complex and evolving cyber threats.
Background
▶ Watch: Scottish Power's record investment in UK clean energy (1:50)
The context for Nicola Connelly's keynote at CYBERUK is framed by a confluence of accelerating trends: the global push for decarbonization, the rapid digitization of critical infrastructure, and an escalating cyber threat landscape. The UK, like many nations, is undergoing a significant energy transition, moving away from fossil fuels towards renewable sources such as wind and solar. Scottish Power, as a major player in the UK's energy sector and part of Iberdrola, one of the world's leading electricity companies, is at the forefront of this transformation. Their planned investment of £24 billion by 2028 is a testament to the scale of this undertaking, focusing on building and modernizing networks, connecting more renewables, and digitizing infrastructure to meet future energy demands.
This massive investment, while crucial for economic growth and environmental sustainability, simultaneously expands the attack surface for cyber adversaries. The increasing interconnectivity of operational technology (OT) with information technology (IT) systems, the deployment of smart grids, and the reliance on data-driven operations introduce new vulnerabilities that must be proactively addressed. Traditionally, OT environments, which control industrial processes like power generation and distribution, were air-gapped or isolated. However, the drive for efficiency, remote management, and real-time data insights has led to greater integration, making these systems accessible to network-based threats.
The problem of cyber resilience in Critical National Infrastructure (CNI) is further compounded by its inherent interdependencies. As Connelly highlighted, "No single organization, however capable, can strengthen national resilience on its own. We do it together." An attack on one component of the energy grid can have cascading effects across multiple sectors, including transport, communications, and healthcare, due to the foundational role of electricity. This systemic risk necessitates a whole-of-society effort where government, regulators, and private sector entities collaborate closely.
Prior work and ongoing initiatives provide a framework for this collective action. Connelly specifically welcomed the NCSC's guidance for CNI on preparing for and recovering from cyber attacks, acknowledging its vital role in shaping industry best practices. The upcoming UK's Cyber Security and Resilience Bill also signals a legislative commitment to strengthening national defenses, underscoring the government's recognition of the urgency. These efforts collectively aim to address the persistent challenge of ensuring that technological progress and economic growth are not undermined by security vulnerabilities, echoing the sentiment shared by Richard from Aratico (mentioned in the talk) that resilience ultimately boils down to trust—trust that essential services will be there when needed, regardless of disruption.
Key Findings
▶ Watch: Scottish Power's ambition: Securing a better future quicker (3:30)
Nicola Connelly's keynote distilled the complex challenge of cyber resilience in the energy sector into several foundational principles and strategic priorities. The overarching finding is that resilience is not an optional add-on but an inseparable condition for sustainable growth and trust in critical national infrastructure. This perspective reframes security from a cost center to a core enabler of progress, particularly in light of the significant investments being made in electrifying the UK economy.
The talk emphasized that the future energy system, characterized by increasing digitization and interconnectivity, necessitates a proactive, "secure by design" approach. Resilience must be considered "from the start in asset programs, operating models, supply chains, and leadership decisions." This means embedding security considerations into the very earliest stages of planning and development for new infrastructure, rather than attempting to bolt them on retrospectively.
Scottish Power's strategy for accelerating cyber defense over the next decade is articulated through four key priorities, which represent the main discoveries and contributions of their approach:
- Strengthening UK Energy Security and Resilience: This priority underscores the conviction that resilience is what makes growth possible and sustainable. As networks are modernized and digitized, security must be an inherent part of the design, ensuring customer confidence, investor assurance, and overall system strength.
- Securing National Networks Across Partners and Supply Chains: Recognizing that "we're only as strong as the wider ecosystem that we depend upon," Scottish Power highlights the critical need to extend resilience beyond organizational boundaries. This involves implementing stronger baselines, better assurance mechanisms, and practical collaboration, specifically recommending the adoption of NCSC's Cyber Essentials certification within supply chains to ensure dependability.
- Innovating a Smarter, Safer System through Digitization, AI, and Data-Driven Operations: While embracing digital technologies offers benefits like better insights and faster response, Connelly stressed that these advancements "need to be matched with strong governance and thoughtful risk management in critical infrastructure." Innovation and responsibility, therefore, must go hand in hand.
- Empowering Our People and Building a Future-Ready Security Culture: Ultimately, resilience is driven by people—engineers, operators, analysts, and leaders. The talk highlighted that investing in skills, capability, preparation, practice, and culture is as crucial as investing in technology and infrastructure. Cyber security must become a board responsibility, fostering a culture where organizational security and readiness are owned at the highest levels.
These priorities collectively form a holistic framework for accelerating cyber defense, emphasizing that effective resilience is a continuous cycle of prevention, preparedness, response, and recovery, driven by human judgment and collaborative effort across the entire ecosystem.
Technical Deep Dive
▶ Watch: National resilience requires government and industry collaboration (5:00)
While Nicola Connelly's keynote provided a high-level strategic overview rather than a granular technical exposition, her four priorities for accelerating cyber defense offer profound implications for technical implementation within the energy sector. These strategic directives translate into concrete technical requirements and architectural considerations essential for securing Critical National Infrastructure (CNI).
The first priority, "Strengthening UK Energy Security and Resilience" by integrating it "from the outset," points directly to the principle of Secure by Design. Technically, this means that security must be a foundational requirement in the System Development Life Cycle (SDLC) for all new energy infrastructure. This includes performing threat modeling during the design phase of new substations, smart grid components, or renewable energy plants. It necessitates the adoption of zero-trust architectures for network segmentation, ensuring that even within the trusted network perimeter, every access request is authenticated and authorized. Furthermore, it implies the use of immutable infrastructure principles where possible, reducing the attack surface by preventing unauthorized changes to critical system configurations. For Operational Technology (OT) environments—such as SCADA (Supervisory Control and Data Acquisition) and ICS (Industrial Control Systems) that manage power generation and distribution—this translates to designing air-gapped or logically segmented networks, implementing one-way data diodes for secure data transfer to IT networks, and employing specialized security controls that respect the unique constraints of OT (e.g., real-time operations, legacy systems, proprietary protocols).
The second priority, "Securing National Networks Across Partners and Supply Chains," addresses the complex interdependencies of modern infrastructure. Technically, this requires robust supply chain risk management (SCRM) programs. Organizations like Scottish Power must implement rigorous due diligence processes for all technology providers and suppliers, extending beyond financial checks to include deep dives into their cybersecurity posture. The recommendation to use NCSC's Cyber Essentials certification serves as a baseline technical assurance mechanism, ensuring that suppliers meet fundamental cybersecurity hygiene standards. Advanced SCRM might involve mandating Software Bill of Materials (SBOMs) for critical components, conducting vulnerability assessments and penetration testing on third-party software and hardware before deployment, and establishing secure communication channels for threat intelligence sharing across the ecosystem. Technically, this also means implementing strong vendor access controls, potentially using privileged access management (PAM) solutions for third-party remote access to critical systems, and continuous monitoring of vendor security performance.
The third priority, "Innovating a Smarter, Safer System through Digitization, AI, and Data-Driven Operations," presents both immense opportunities and significant technical challenges. The integration of Artificial Intelligence (AI) and machine learning (ML) for predictive maintenance, grid optimization, and enhanced threat detection requires robust AI governance frameworks. Technically, this involves ensuring the security and integrity of training data to prevent data poisoning attacks, securing AI model deployments against adversarial attacks, and implementing explainable AI (XAI) to understand decision-making processes, especially in critical operational contexts. For data-driven operations, this mandates strong data encryption at rest and in transit, data loss prevention (DLP) solutions, and advanced security information and event management (SIEM) systems capable of correlating vast amounts of data from diverse sources (IT, OT, IoT) to identify anomalous behavior and potential threats. The proliferation of Internet of Things (IoT) devices in smart grids also necessitates device authentication, firmware integrity checks, and secure over-the-air (OTA) updates to prevent compromise.
Finally, "Empowering Our People and Building a Future-Ready Security Culture," while primarily a cultural and organizational imperative, has crucial technical underpinnings. Investment in skills translates to training for security analysts in OT-specific threat detection and incident response, engineers in secure coding practices, and operators in recognizing social engineering attacks. Technically, this involves deploying advanced security awareness platforms that simulate phishing attacks, implementing multi-factor authentication (MFA) across all critical systems, and conducting regular tabletop exercises and red team/blue team drills to test both technological defenses and human response capabilities. The emphasis on cybersecurity as a board responsibility means that technical teams must be able to translate complex security risks into clear, business-relevant metrics and reports for executive decision-making.
In essence, while the keynote was strategic, its implications demand a sophisticated, multi-layered technical architecture that integrates security from the earliest design stages, extends robust controls across an interconnected supply chain, responsibly leverages emerging technologies like AI, and empowers a human workforce equipped with the necessary technical skills and security mindset.
Demo / Proof of Concept
▶ Watch: People and culture are fundamental to real resilience (8:05)
As a strategic keynote address delivered by a Chief Executive Officer, Nicola Connelly's presentation at CYBERUK did not feature a live technical demonstration or proof of concept. The focus was on outlining the strategic vision, priorities, and philosophical approach of Scottish Power Energy Networks towards cyber resilience within the broader context of national energy infrastructure.
However, in the spirit of illustrating the practical application of her points, one could envision several types of demonstrations that would align with the themes discussed. For instance, a proof of concept showcasing a secure by design approach might involve a simulated deployment of a new smart grid component, demonstrating how security controls are integrated from the initial architectural drawings, through secure coding practices, to final deployment and monitoring. This could highlight the use of immutable infrastructure, automated vulnerability scanning in CI/CD pipelines, or the implementation of zero-trust network segmentation within a simulated OT environment.
Alternatively, a demonstration could focus on supply chain security, illustrating how Scottish Power vets its technology providers using NCSC Cyber Essentials as a baseline. This might involve a portal showing vendor security scores, automated alerts for supply chain vulnerabilities, or a simulated incident where a compromised third-party component is quickly identified and isolated due to robust vendor risk management protocols. A sophisticated demo could even illustrate the challenges and solutions for securing AI/ML models in critical infrastructure, perhaps by showing how an AI-driven grid optimization system is protected against adversarial attacks or how its decision-making process is made transparent through explainable AI techniques. While these were not part of the keynote, they represent the tangible technical manifestations of the strategic imperatives Connelly articulated.
Defensive Implications
▶ Watch: Making cybersecurity a board-level responsibility (9:10)
The strategic vision articulated by Nicola Connelly presents a clear mandate for cybersecurity defenders within the energy sector and across other critical national infrastructure domains. The defensive implications are profound, demanding a shift from traditional perimeter-based security to a holistic, integrated, and proactive resilience posture.
Firstly, the emphasis on "resilience by design" necessitates a fundamental change in the development lifecycle of critical infrastructure. Defenders must engage with engineering and operational teams from the very genesis of projects, integrating threat modeling and security architecture reviews into every phase. This means advocating for and implementing secure coding practices, promoting the use of secure-by-default configurations for new devices and systems, and ensuring that security requirements are non-negotiable for all new infrastructure investments. For OT environments, this implies a deep understanding of industrial protocols, device vulnerabilities, and the specific operational constraints that dictate security control implementation.
Secondly, securing supply chains is paramount. Defenders must establish robust third-party risk management (TPRM) programs that go beyond contractual clauses. This involves continuous vetting of suppliers, mandating adherence to recognized security standards like NCSC Cyber Essentials, and conducting regular security audits and assessments of critical vendors. Technical controls such as network segmentation for third-party access, privileged access management (PAM) for remote vendor support, and software bill of materials (SBOM) analysis for all deployed components become essential to manage the extended attack surface. Sharing threat intelligence related to supply chain compromises within the sector is also crucial.
Thirdly, the integration of digitization, AI, and data-driven operations demands a sophisticated approach to governance and risk management. Defenders need to develop and implement comprehensive AI security frameworks that address data integrity, model robustness, and ethical considerations. This includes securing the entire AI/ML pipeline, from data ingestion and training to model deployment and monitoring. For data-driven insights, robust data protection strategies involving encryption, access controls, and data loss prevention (DLP) are critical. Furthermore, Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms must evolve to ingest and analyze data from diverse IT, OT, and IoT sources, enabling faster and more accurate threat detection and response.
Finally, and perhaps most critically, the focus on people and culture underscores the need for continuous investment in cybersecurity workforce development. Defenders must champion training programs that enhance both technical skills (e.g., OT incident response, cloud security, AI security) and soft skills (e.g., communication, collaboration, risk articulation). Regular security awareness training for all employees, tailored to specific roles and threat vectors (e.g., phishing simulations), is essential. Conducting tabletop exercises and full-scale incident response drills helps build muscle memory, test response plans, and foster a culture of preparedness. Importantly, defenders must cultivate strong relationships with executive leadership and board members, ensuring that cybersecurity is understood as a strategic business risk and a shared responsibility across the organization, aligning with the call for cybersecurity to be a board responsibility. This collaborative, multi-faceted approach is the only way to build truly resilient national infrastructure capable of withstanding the complex threats of the next decade.
Key Takeaways
- Resilience is Foundational to Growth: Cyber resilience must be an integral part of all infrastructure investment and development, not an afterthought, to ensure sustainable growth and public trust.
- Whole-of-Society Collaboration is Essential: Strengthening national cyber defense requires seamless partnership between government, regulators, industry, and national bodies.
- Supply Chain Security is a Shared Responsibility: Organizations are only as strong as their weakest link; robust security measures and certifications like NCSC Cyber Essentials must extend across the entire supply chain.
- Responsible Innovation is Key: The adoption of digitization, AI, and data-driven operations in CNI must be balanced with strong governance and thoughtful risk management to ensure safety and security.
- People and Culture are the Ultimate Defense: Investing in skills, training, and fostering a strong security culture at all levels, including board responsibility, is as crucial as technological controls.
- Proactive "Secure by Design" Approach: Embedding security from the outset in asset programs and operating models is critical for building enduring trust and capability in national infrastructure.
About the Speaker(s)
Nicola Connelly is the Chief Executive Officer of Scottish Power Energy Networks, a pivotal organization within the UK's energy sector. Scottish Power, headquartered in Glasgow, operates across renewables, networks, and supply, playing a crucial role in the country's transition to a cleaner, more electrified future. As part of Iberdrola, one of the world's leading electricity companies, Scottish Power is committed to significant investment in infrastructure, with plans to inject up to £24 billion by 2028. Ms. Connelly is a strong advocate for integrating cyber resilience into this growth, emphasizing that security and governance are fundamental to building trust and ensuring the sustained operation of critical services. Her leadership reflects a commitment to a collaborative, whole-of-society effort in accelerating cyber defense for the next decade.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A lead sponsor keynote from a utility CEO that delivers exactly what the label predicts: high-level strategic framing, no insider signal, no concrete commitments beyond a capital investment figure already in Scottish Power's public filings, and talking points that could have been written by any communications team in the energy sector. Judged generously as a strategic/executive keynote, it still fails to clear the bar — there's no budget broken out for security specifically, no named programs, no regulatory commitments, no data on threat actors targeting UK energy CNI, and nothing a CISO in the room couldn't have read in an NCSC annual review. The £24 billion figure is a headline for a…
Heather Calloway (CISO) — SOLID
Nicola Connelly makes a credible, senior case for embedding cyber resilience into critical infrastructure investment — and the framing of resilience as a condition for growth, not a cost of compliance, is exactly the right message at the board and executive level. But the talk stays in strategic terrain without ever producing a moment of real accountability, decision, or operational direction. It's a well-positioned statement of intent from a CEO who clearly understands the stakes. It is not a session that changes how anyone defends anything.