Technology and Leadership Plenary

Richard Horne (Chief Executive Officer · National Cyber Security Centre (NCSC)), Carolyn Ainsworth (Deputy Director Chief Engineer · National Cyber Security Centre (NCSC)), Keri Gilder (Chief Executive Officer · Colt Technology Services), Dr. Els Debuf (Head of Delegation for Cyberspace · International Committee of the Red Cross)

CYBERUK 2026 · Day 2 · Main Plenary

Overview

This plenary session at CYBERUK brought together a diverse group of leaders from national cybersecurity, academia, industry, and humanitarian aid to address the critical challenges of technology and leadership in an increasingly complex and threatened digital landscape. The discussion, initiated by Olly Whitehouse, Chief Technical Officer for the National Cyber Security Centre (NCSC), underscored the escalating risks from commercial proliferation of advanced cyber capabilities, software supply chain vulnerabilities, and the rapid, often insecure, adoption of artificial intelligence. The core of the session centered on the tension between short-term tactical responses and the imperative for long-term strategic planning, emphasizing the need for a paradigm shift in how governments, industries, and individuals approach cyber defense.

Watch on YouTube

Visual summary for Technology and Leadership Plenary by Richard Horne, Carolyn Ainsworth, Keri Gilder, Dr. Els Debuf
Visual summary for Technology and Leadership Plenary by Richard Horne, Carolyn Ainsworth, Keri Gilder, Dr. Els Debuf

Key moments

  1. 4:00 Olly White House's introduction and opening remarks
  2. 5:00 Analysis of the evolving cyber threat landscape
  3. 6:20 How AI is changing the threat calculus and vulnerability
  4. 7:50 Balancing short-term fixes with long-term strategic goals
  5. 9:20 Intergenerational perspective on leadership and future planning
  6. 10:50 Call for international collaboration and game-changing solutions
  7. 12:00 Preparing for the agentic era: identity and architectures

Technology and Leadership Plenary

Speakers: Richard Horne (Chief Executive Officer, National Cyber Security Centre (NCSC)); Carolyn Ainsworth (Deputy Director Chief Engineer, National Cyber Security Centre (NCSC)); Keri Gilder (Chief Executive Officer, Colt Technology Services); Dr. Els Debuf (Head of Delegation for Cyberspace, International Committee of the Red Cross); Olly Whitehouse (Chief Technical Officer, National Cyber Security Centre (NCSC)); Barbara Gruie (Visiting Scholar, Jesus College Cambridge); Jamie McColl (Senior Research Fellow, Royal United Services Institute); Katherine Day (Co-founder, National Strategy Project)

Conference: CYBERUK

YouTube: https://www.youtube.com/watch?v=5KtD0tY4Ivo

Overview

This plenary session at CYBERUK brought together a diverse group of leaders from national cybersecurity, academia, industry, and humanitarian aid to address the critical challenges of technology and leadership in an increasingly complex and threatened digital landscape. The discussion, initiated by Olly Whitehouse, Chief Technical Officer for the National Cyber Security Centre (NCSC), underscored the escalating risks from commercial proliferation of advanced cyber capabilities, software supply chain vulnerabilities, and the rapid, often insecure, adoption of artificial intelligence. The core of the session centered on the tension between short-term tactical responses and the imperative for long-term strategic planning, emphasizing the need for a paradigm shift in how governments, industries, and individuals approach cyber defense.

The panel delved into the profound human and organizational dimensions of cyber resilience, moving beyond purely technical considerations. Speakers shared insights on fostering a culture of long-term thinking, drawing parallels from national security and humanitarian crisis management. A particularly poignant segment explored the often-overlooked human cost of cyberattacks, including the psychological trauma experienced by employees and the critical need for a "social contract" within organizations to support staff through prolonged crises. This holistic perspective highlights that effective cyber defense in the coming decade will hinge not just on technological prowess, but equally on robust leadership, collective responsibility, and the cultivation of human resilience.

Background

▶ Watch: Olly White House's introduction and opening remarks (4:00)

Olly Whitehouse's opening remarks painted a stark picture of the current cyber landscape, characterized by several critical and compounding issues. He highlighted the commercial proliferation of advanced cyber capabilities to a wider range of malicious actors, significantly lowering the barrier to entry for sophisticated attacks. The NCSC has observed a concerning rise in supply chain attacks, particularly within software, leading to "six-digit scale intrusions across organizations of all types." Compounding this, organizations are simultaneously grappling with the demands of legacy technology while attempting to build an AI-driven future, often deploying new AI solutions without adequate security robustness. Whitehouse also noted the increasing scale of state-sponsored intrusions, which become more evident as defensive capabilities improve, and the dual-edged sword of AI's growing efficacy in both finding and exploiting vulnerabilities.

A central theme was the "latent vulnerability" in technological infrastructure becoming "extremely evident and extremely quickly," alongside the inherent opacity of complex technology to most users. This necessitates expert guidance from communities like CYBERUK to inform organizations and the public. Whitehouse articulated a fundamental tension: balancing short-term incentives with long-term intent, requiring unprecedented scale and pace in response. He advocated for a shift from reactive vulnerability discovery to proactive measures like adopting memory-safe languages and demanding universal hot patching from technology vendors, arguing that constant reboots for patching are unsustainable. Longer-term, he envisioned legislative frameworks and market incentives that deeply reward "above bar" cybersecurity behavior, defining minimum standards and measuring compliance.

Barbara Gruie, drawing on her experience with the 9/11 Commission, underscored the historical failures of "lack of imagination, failure of policy, failure of capabilities, and failure of management." She argued that governments have effectively "seeded national security and economic security" to CISOs and corporate boards, a dangerous precedent when cyberattacks can have consequences akin to intercontinental ballistic missile strikes. Jamie McColl reinforced this, using the analogy of car safety standards: just as manufacturers are held responsible for vehicle safety, software vendors should bear greater liability for the security of their products. Katherine Day further emphasized that while crises are often foreseen, a persistent "failure of imagination" and discipline prevents adequate preparation. The panel collectively highlighted the systemic and human challenges within large organizations and governments—such as short political cycles, lack of incentive for long-term investment, and high staff rotation—that impede the ability to make and sustain long-term, evidenced-based decisions in cybersecurity. Jamie McColl pointed out the persistent "lack of evidence, data, metrics" to prove the return on investment for cybersecurity controls, hindering strategic decision-making in both public and private sectors.

Key Findings

▶ Watch: How AI is changing the threat calculus and vulnerability (6:20)

The plenary session yielded several critical findings that collectively advocate for a transformative approach to cybersecurity, emphasizing a blend of technical foresight, organizational resilience, and human-centric leadership:

  • The Unavoidable Tension of Time Horizons: A core finding is the inherent conflict between immediate, tactical responses to cyber threats and the long-term, strategic investments required for enduring resilience. Olly Whitehouse stressed that balancing short-term incentives with long-term intent is paramount, necessitating legislative frameworks and market mechanisms that reward proactive, "above bar" cybersecurity practices rather than just compliance.
  • Cybersecurity as a National and Economic Security Imperative: Barbara Gruie powerfully argued that treating cybersecurity as solely an organizational responsibility is a critical failure. Given the potential for nation-state cyberattacks to cause societal disruption on par with physical warfare, governments must reclaim their role in setting national standards, fostering collective defense, and intervening where market failures persist, akin to establishing safety standards for critical infrastructure or products.
  • The Profound Human Cost of Cyberattacks: Keri Gilder's candid account of Colt Technology Services' major cyberattack highlighted that the ultimate impact of such incidents is profoundly human. Beyond system downtime, employees experience genuine trauma, PTSD, burnout, and significant health issues. This reveals a critical gap in current incident response planning: the lack of a "social contract" that explicitly addresses psychological support, staff rotation, and long-term well-being during and after a prolonged cyber crisis.
  • Leadership Beyond Management: Katherine Day and Dr. Els Debuf articulated that navigating the turbulent cyber landscape demands extraordinary leadership distinct from mere management. Leaders must cultivate courage, guide organizations into an uncreated future, and foster a culture where individuals take responsibility for collective well-being, rather than expecting government or others to solve all problems. This includes preparing for the "unexpected"—such as key personnel freezing or being unavailable during a crisis—and training for rapid, common-sense judgment when established protocols might fail.
  • The Imperative for "Offline" Preparedness: Katherine Day's stark warning about the inevitability of widespread technology failure underscores the need for "equal and opposite investment" in preparing for an offline world. Organizations and societies must cultivate the ability to "survive and thrive" without technology, a critical aspect of resilience often overlooked in digital-first planning.
  • A Shared National Mission for Cyber Resilience: Jamie McColl and Katherine Day concluded with the call for a stronger, shared national mission around cyber resilience. This involves moving beyond fragmented efforts to a cohesive, cross-sector approach that recognizes the collective responsibility of government, industry, and citizens in building a resilient digital future.

Technical Deep Dive

▶ Watch: Balancing short-term fixes with long-term strategic goals (7:50)

Olly Whitehouse's opening address provided a forward-looking technical roadmap for enhancing national cyber resilience, focusing on foundational shifts and innovative defense mechanisms. He articulated a vision for addressing systemic vulnerabilities and preparing for future challenges, particularly in an increasingly autonomous and AI-driven world.

A cornerstone of this vision is the widespread adoption of memory-safe languages. Whitehouse cited the example of Cherry, a capability designed to prevent memory corruption vulnerabilities that have plagued software for decades. This shift is critical because a significant portion of exploitable vulnerabilities stem from memory safety issues. Complementing this, he advocated for technology vendors to universally implement hot patching. The ability to apply security updates without requiring system restarts is deemed "key" for survival in a world where constant reboots for every vulnerability are simply "not tenable" across a range of critical situations.

In the realm of identity, the NCSC is actively working on identity and access management (IAM) solutions, specifically highlighting passkeys as a more secure and user-friendly alternative to traditional passwords. Looking ahead, Whitehouse raised the complex challenge of agentic identity in the emerging "agentic era" – how autonomous AI agents will establish and manage their identities and access rights within digital ecosystems.

Architecturally, the NCSC emphasizes the importance of "immutable architectural primitives." A prime example cited is Privileged Access Workstations (PAWs) for Critical National Infrastructure (CNI). These highly secured, purpose-built workstations are designed to minimize the attack surface for privileged users, drawing on established and trusted architectural approaches from classified environments.

Preparing for future cryptographic challenges, Whitehouse highlighted the impending post-quantum crypt transition. This involves a proactive shift to cryptographic algorithms resistant to attacks from future quantum computers, a significant undertaking requiring widespread coordination and implementation. Furthermore, the NCSC is actively involved in developing standards for Security Operation Centers (SOCs) and promoting memory safety within organizations like ETSI (European Telecommunications Standards Institute), laying essential groundwork for long-term benefits.

Whitehouse also discussed the strategy of engineering resilience to minimize the blast radius of intrusions. This involves bringing robust cross-domain technologies and concepts, proven in classified environments, to the wider CNI space. These technologies have a "long trusted pedigree" and are known to work effectively in high-assurance settings.

Finally, looking towards the future of AI in cyber defense, Whitehouse outlined the concept of an "agentic AI for cyber defense." This vision includes a "national cyber shield" where real-time red and blue agents – AI-driven systems simulating both attackers and defenders – are able to probe for vulnerabilities and, more importantly, mitigate them at scale across a national digital landscape. This represents a significant shift towards automated, intelligent defense capabilities.

It is important to note that while Olly Whitehouse's opening provided a detailed technical outlook, the subsequent panel discussion largely shifted focus to the human, organizational, and policy aspects of cyber resilience.

Demo / Proof of Concept

▶ Watch: Call for international collaboration and game-changing solutions (10:50)

The plenary session itself did not feature a live technical demonstration or proof of concept from the speakers. However, the event did highlight initiatives focused on fostering innovation and exploring future scenarios in cybersecurity.

Carolyn Ainsworth, Deputy Director Chief Engineer at the NCSC, announced the winner of the annual Cyber Den competition. This competition is designed to recognize and support innovation in tackling cyber challenges. The 2026 winner was Hackatronics, an OT (Operational Technology) cyber security training platform. Hackatronics was chosen for its "unique opportunity to upskill OT engineers in cyber security, which is a material gap today." The prize includes 12 months of NCSC support, encompassing consultancy, targeted vulnerability research, potential government department product testing, and mentoring from the NCSC CTO and growth team. This initiative serves as a platform for emerging cybersecurity solutions to gain traction and development support.

Additionally, Olly Whitehouse mentioned a short story competition supported by the Research Institute for Sociotechnical Cyber Security. The winning story, "The Wednesday Afternoon Fishing Club" by Leftky Caroni, aimed to explore how new technology could be a positive force for good, providing an "aiming point" for the future. While not a technical demo, this highlights the NCSC's interest in imaginative and forward-thinking approaches to cybersecurity challenges.

Defensive Implications

▶ Watch: Preparing for the agentic era: identity and architectures (12:00)

The discussions from the plenary panel offer a comprehensive framework for bolstering cyber defenses, spanning technical, organizational, and policy dimensions.

For Technology Vendors:

  • Embrace Memory-Safe Languages: The industry must proactively transition to memory-safe languages to eliminate a significant class of vulnerabilities, moving beyond the legacy issues of the past 20 years.
  • Implement Universal Hot Patching: Vendors should develop and universally adopt hot patching capabilities, allowing for critical security updates without requiring system downtime, a necessity for critical infrastructure and continuous operations.
  • Radical Transparency: Technology vendors must commit to "radical transparency" regarding their product components and the quality of underlying processes, enabling organizations to build collective defense with confidence.

For Organizations (CISO, Boards, IT Teams):

  • Prioritize Long-Term Resilience: Shift focus from short-term tactical fixes to intergenerational planning and strategic investments in foundational security, engineering resilience to minimize the blast radius of intrusions.
  • Modernize IAM: Implement advanced Identity and Access Management (IAM) solutions, such as passkeys, and begin to conceptualize how agentic identity will function in AI-driven environments.
  • Adopt Immutable Architectures: For Critical National Infrastructure (CNI), implement robust architectural primitives like Privileged Access Workstations (PAWs), drawing on proven cross-domain technologies from classified environments.
  • Prepare for Post-Quantum Cryptography: Proactively plan and execute the transition to post-quantum cryptographic algorithms to secure data against future quantum computing threats.
  • Invest in SOC Standards & Training: Adhere to and invest in developing Security Operation Center (SOC) standards and continuous cyber training, including specialized training for OT engineers (as highlighted by Hackatronics).
  • Plan for the "Offline World": Develop comprehensive contingency plans for scenarios where technology fails entirely. This includes manual processes and ensuring human capacity to operate without digital systems.

For Governments and Policymakers:

  • Legislative Frameworks & Market Incentives: Establish robust legislative frameworks and market incentives that reward strong cybersecurity practices and hold vendors accountable, similar to safety standards in other industries.
  • Define Minimum Standards: Set and enforce clear minimum cybersecurity standards across all sectors, ensuring a baseline level of protection for all "digital boats to rise."
  • Maintain Open-Source Ecosystems: Invest in properly maintained and secured open-source software ecosystems, recognizing their foundational role in modern technology infrastructure.
  • Foster a National Mission: Cultivate a strong, shared national mission for cyber resilience that encourages collective responsibility and action across government, industry, and citizens.
  • Invest in AI for Defense: Explore and invest in agentic AI for cyber defense, including real-time red and blue agents for automated vulnerability probing and mitigation as part of a "national cyber shield."
  • International Collaboration: Recognize that cyber defense is not an isolated effort; foster international collaboration to raise global resilience levels.

Human and Leadership Implications:

  • Acknowledge Human Cost: Leaders must recognize and prepare for the psychological trauma, burnout, and health issues staff may experience during and after cyberattacks.
  • Establish a Social Contract: Formalize a "social contract" with employees that outlines expectations during a crisis, provides clear support mechanisms (including psychological first aid), and plans for staff rotation and well-being.
  • Train for Crisis Leadership: Develop training programs that prepare leaders for making rapid judgments under pressure, cultivating common sense, and adapting to unexpected personnel challenges (e.g., critical individuals freezing or being unavailable).
  • Build Courage and Selflessness: Foster a culture that values courageous leadership, selflessness in working for future generations, and continuous learning from both successes and failures.

Key Takeaways

  • Long-term Vision is Paramount: Effective cyber defense demands a strategic shift from reactive, short-term fixes to proactive, intergenerational planning, supported by legislative frameworks and market incentives that reward superior security.
  • Human Resilience is the Ultimate Defense: Cyberattacks are profoundly human crises. Organizations must prioritize the psychological well-being of employees, establish a clear "social contract" for crisis response, and train for human resilience as rigorously as for technical systems.
  • Government's Role Extends Beyond Advice: Governments must act as catalysts, setting minimum security standards, driving collective investment, and taking responsibility for national cyber and economic security, rather than solely delegating it to individual businesses.
  • Embrace Foundational Technical Shifts: The future of cyber defense relies on widespread adoption of memory-safe languages, universal hot patching, advanced identity management (like passkeys), and leveraging AI-driven defense mechanisms such as red and blue agents.
  • Prepare for the "Offline" Reality: Societies and organizations must actively plan and train for scenarios where technology is unavailable or compromised, ensuring the capacity to operate and thrive in a non-digital environment.
  • Cultivate Courageous Leadership and a Shared Mission: Navigating the complex cyber landscape requires leaders who inspire courage, prioritize long-term societal benefit, and foster a collective, cross-sector national mission for cyber resilience.

About the Speaker(s)

The plenary session featured a distinguished group of speakers and panelists, each bringing unique expertise to the discussion:

  • Olly Whitehouse: Chief Technical Officer for the National Cyber Security Centre (NCSC). Whitehouse set the stage for the discussion, outlining the evolving cyber threat landscape and the NCSC's strategic technical priorities for long-term resilience.
  • Richard Horne: Chief Executive Officer, National Cyber Security Centre (NCSC). As the NCSC's CEO, Horne concluded the conference, emphasizing the importance of community and seizing the current moment in cyber defense.
  • Carolyn Ainsworth: Deputy Director Chief Engineer, National Cyber Security Centre (NCSC). Ainsworth announced the winner of the Cyber Den competition, highlighting NCSC's support for innovation in the cybersecurity sector.
  • Keri Gilder: Chief Executive Officer, Colt Technology Services. Gilder provided a powerful, firsthand account of leading her company through a major cyberattack in August 2025, focusing on the intense human and organizational impact.
  • Dr. Els Debuf: Head of Delegation for Cyberspace, International Committee of the Red Cross (ICRC). Debuf offered a unique perspective from humanitarian crisis management, discussing leadership, human behavior under extreme stress, and the "social contract" with employees in high-risk environments.
  • Barbara Gruie: A Visiting Scholar at Jesus College Cambridge. Her background includes serving as Senior Counsel on the 9/11 Commission and working at MITRE on cyber risk management for the government of Japan, informing her insights on government failures and national security.
  • Jamie McColl: Senior Research Fellow at the Royal United Services Institute (RUSI) in the cyber and tech team, where he leads work on UK cyber policy. Jamie shared a unique career path from professional musician to cyber policy expert.
  • Katherine Day: A biological anthropologist by background, Day spent 25 years in government working on national security and international affairs, having advised eight prime ministers. She is now the co-founder of the National Strategy Project, dedicated to creating new ways for large groups to think, decide, and act together.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent strategic plenary from CYBERUK that earns its lane — this is a ministerial/executive keynote, not a technical research drop, and grading it otherwise would be lazy. Judged as strategic and policy content, it delivers reasonable signal: Whitehouse's technical roadmap names real priorities (memory-safe languages, hot patching, PAWs for CNI, post-quantum transition, agentic identity), Gilder's firsthand account of Colt's 2025 breach adds genuine human texture, and the framing around organizational 'social contract' during cyber crises is underrepresented at most conferences. But the session suffers from a recurring problem with flagship government plenaries: too many speakers, too…

Heather Calloway (CISO) — SOLID

A well-assembled plenary that covers real ground — the human cost of incidents, vendor liability, long-term investment failures, and the governance gap between governments and corporations — but stays at the altitude of observation rather than prescription. The most important things get said. They don't always get landed.

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026