UK's Cybersecurity Revolution: Professionalization's Global Impact

Andrew Elliot (Deputy Director, DSIT · UK Government), Sian John (CTO · NCC Group), Jon France (CISO · ISC2), Dan Gorecki (Principal & CISO · NGC Risk)

RSA Conference 2025 · Day 1 · Policy · Policy & Government

Overview

The UK Cybersecurity Council is pioneering a formal professional framework for cybersecurity — complete with chartership, a professional register, and eight recognized specialisms — modeled on the centuries-long evolution of medicine, law, and engineering. With roughly 500 registered professionals and growing international interest from Canada, Japan, Singapore, and others, the initiative is being positioned as a global template for elevating cybersecurity from an ad hoc technical role to a recognized profession. The panel at RSA 2025 explored why that transformation is urgently needed, how it works in practice, and what it will take to reach critical mass. ---

Watch on YouTube

Visual summary for UK's Cybersecurity Revolution: Professionalization's Global Impact by Andrew Elliot, Sian John, Jon France, Dan Gorecki
Visual summary for UK's Cybersecurity Revolution: Professionalization's Global Impact by Andrew Elliot, Sian John, Jon France, Dan Gorecki

Key moments

  1. 7:30 Four structural failures in cybersecurity workforce: status, career ladder, hiring, accountability
  2. 9:36 Chartership goes beyond certification: adds professional conduct and applied competency
  3. 20:16 Certification paradox: people with every cert still can't perform in practice
  4. 14:09 NCC Group: chartership now mandatory prerequisite for UK government security contracts
  5. 30:57 Surgery took 200 years to professionalize; cybersecurity must compress that timeline now
  6. 17:46 UK Council established by last royal charter signed by Queen Elizabeth II
  7. 48:00 70% of UK cyber workforce aware of council and planning to join
  8. 37:59 Six-nation founding coalition builds globally portable professional certification model

UK's Cybersecurity Revolution: Professionalization's Global Impact

Speakers: Andrew Elliot (UK Government, DSIT), Sian John (NCC Group), Jon France (ISC2), Dan Gorecki (NGC Risk, moderator)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=SKoiyjGffSE

Reading time: ~8 minutes

TL;DR

The UK Cybersecurity Council is pioneering a formal professional framework for cybersecurity — complete with chartership, a professional register, and eight recognized specialisms — modeled on the centuries-long evolution of medicine, law, and engineering. With roughly 500 registered professionals and growing international interest from Canada, Japan, Singapore, and others, the initiative is being positioned as a global template for elevating cybersecurity from an ad hoc technical role to a recognized profession. The panel at RSA 2025 explored why that transformation is urgently needed, how it works in practice, and what it will take to reach critical mass.

Introduction

Ask students in a UK school what they want to be when they grow up, and they will name doctors, lawyers, and architects — but rarely cybersecurity professionals. That aspiration gap, according to Andrew Elliot, Deputy Director for Cyber Policy at the UK's Department for Science, Innovation, and Technology (DSIT), is precisely the kind of cultural and structural problem the UK Cybersecurity Council was designed to solve.

At RSA Conference 2025, a panel moderated by Dan Gorecki — CISO at NGC Risk and a volunteer member of the council's technical working group — convened to explain how the UK is building the scaffolding for a true cybersecurity profession, why that matters globally, and what the road ahead looks like. The conversation brought together the architect of the council (Elliot), a licensed body that validates candidates (Jon France, CISO at ISC2), and a major employer that has already committed to the chartership model (Sian John, CTO at NCC Group).

The Problem the Council Was Built to Solve

Elliot laid out four distinct failures in the current cybersecurity workforce ecosystem that the council is designed to address. First, the profession lacks status. Young people do not see cybersecurity as a prestigious career, and professionals in the field often find their advice dismissed rather than heeded — unlike a lawyer, an accountant, or a doctor whose professional opinion carries legal and social weight.

Second, there is no coherent career ladder. Many cybersecurity professionals entered the field by accident, moving laterally from IT helpdesks or network engineering roles, with no recognized pathway for progression. "The answer can't be 'by accident,'" said Sian John, capturing a widely shared frustration. ▶ Watch: Career pipeline problem (22:56)

Third, employers are confused. Hiring managers default to requesting the same narrow list of certifications and an arbitrary number of years of experience, creating a constrained talent pool that excludes qualified candidates from non-traditional backgrounds. Elliot pointed out that many job ads simply do not help organizations identify who they actually need — whether an analyst, a penetration tester, or a security architect.

Fourth, government and regulators have no reliable mechanism to verify that the people managing their most sensitive environments are genuinely competent. The council's professional register is intended to serve as that quality control layer. ▶ Watch: Four problems Elliot wants the council to fix (7:51)

How Chartership Works — and Why It Goes Beyond Certification

The chartership model sits above individual certifications. Jon France, whose organization ISC2 is one of the council's licensed bodies, was careful to distinguish between the two: existing certifications like the CISSP measure knowledge and its application, but chartership adds a layer of professional conduct, communication ability, and demonstrated competency in context.

"Professionalization doesn't just mean the acquisition of knowledge — it's actually got to be the application of that knowledge to the situation you're facing," France said. ▶ Watch: Chartership vs. certification explained (11:08) The ISC2's CISSP, which requires five years of experience as well as passing an exam, maps naturally onto the chartership pathway — not as a pre-qualification, but as compatible evidence.

France also noted a common experience in the industry: encountering people who hold every available certification but cannot perform in practice. "We've all worked with those people that have every single certification and then they walk in and they can't actually do anything." Chartership is designed to filter for genuine capability through a structured attestation review. ▶ Watch: The certification paradox (20:09)

The council has defined eight specialisms across the cybersecurity field, each with its own body of knowledge, career progression framework, and compatible certification pathways. Candidates who meet the standard have their names entered into the council's professional register — a public record of verified competency.

NCC Group's Experience as an Early Adopter

For NCC Group — a UK-headquartered cybersecurity firm marking its 25th anniversary in 2025 — the chartership model has moved from aspiration to operational requirement. As Sian John explained, CREST accreditation (a prerequisite for testing UK government and critical national infrastructure) now requires migration to the council's certification framework.

"We do a lot of testing for government and critical national infrastructure, and it's a requirement to have that certification," John said. ▶ Watch: CREST and the council (13:41) Among the roughly 500 people currently on the professional register, NCC Group accounts for a notable share — particularly from its penetration testing practice.

John described a practical commercial benefit beyond compliance: when a client receives a tester who is council-accredited, they know the person meets a verified minimum standard. That gives the firm a quality argument in competitive bids. It also creates internal career progression — NCC Group employees gain a recognized credential that is more portable and legible than informal experience alone.

Historical Parallels: Lessons from Engineering and Medicine

One of the panel's most illuminating threads was the comparison of cybersecurity professionalization to the historical evolution of other technical professions. Medicine, law, and engineering all went through extended, sometimes messy periods of formalization before arriving at their current status.

John drew a direct analogy to surgery: "It took about 200 years for surgeons to professionalize — we don't want to take 200 years to professionalize cybersecurity, we want to do it now." ▶ Watch: The 200-year surgery comparison (30:54) The urgency is not merely aspirational. The speed at which cyber threats evolve — combined with the safety implications of incompetent cybersecurity in critical environments — makes the slow-burn historical model impractical.

Elliot noted that the council has a distinctly unusual legal foundation: it was established by royal charter — the last one issued by Queen Elizabeth II before her death. That heritage ties it to the same institutional lineage as the Institution of Engineers and other chartered professional bodies that have shaped British professional life for over a century. ▶ Watch: Royal charter significance (17:50)

International Ambitions and the 500-Member Challenge

The council currently has approximately 500 registered professionals — a number that Elliot openly describes as still "startup mode." A 2024 survey found that 70% of the UK cyber workforce is aware of the council and planning to take steps toward membership. ▶ Watch: Adoption rates and next steps (47:46)

To accelerate adoption internationally, the UK has formed a founding coalition with Canada, Dubai, Ghana, Japan, and Singapore. Representatives from CISA and NICE in the United States have participated in dialogue, though the US has not yet formally joined. The strategy deliberately avoids asking other countries to start from scratch — instead, it looks to build on existing certifications and licensed bodies, keeping the system composable and avoiding the creation of yet another parochial national framework.

The question of whether to require a "license to practice" — as medicine and law do — was deliberately left open. Elliot confirmed that UK public consultation showed widespread support for the principle, but that realistic implementation timelines point to a more gradual approach. "You have to be realistic," he said. ▶ Watch: License to practice discussion (34:40) The more immediate mechanism is embedding the council's standards into government procurement and regulatory frameworks — making chartership a de facto requirement in high-stakes roles without mandating it across the board.

Notable Quotes

"I feel that we need to give a little bit of that status to the UK and the global cybersecurity workforce — that your parents would be proud of, to be blunt."

— Andrew Elliot, DSIT ▶ 7:51

"Professionalization doesn't just mean the acquisition of knowledge — it's actually got to be the application of that knowledge to the situation you're facing."

— Jon France, ISC2 ▶ 11:08

"The answer to 'how did you get into this?' can't be 'by accident.'"

— Sian John, NCC Group ▶ 22:56

"It took about 200 years for surgeons to professionalize — we don't want to take 200 years to professionalize cybersecurity."

— Sian John, NCC Group ▶ 30:54

"70% of the UK cyber workforce are now familiar with the council and planning to take steps towards getting on board."

— Andrew Elliot, DSIT ▶ 47:46

Key Takeaways

  • The UK Cybersecurity Council is a chartered professional body established in 2022 with eight recognized specialisms, a formal professional register, and a chartership process that goes beyond certification to assess applied competency and professional conduct.
  • Chartership complements, not replaces, existing certifications. Programs like the CISSP are explicitly recognized as compatible with the chartership pathway, lowering the barrier for experienced professionals to qualify.
  • NCC Group's adoption demonstrates that the model works at scale for major employers: chartership has become a prerequisite for UK government and critical national infrastructure testing work.
  • The profession-building urgency is real. Cyber threats cannot wait two centuries. The council is borrowing from the historical playbook of medicine and engineering but compressing the timeline significantly.
  • International expansion is underway. A founding coalition of six governments (UK, Canada, Dubai, Ghana, Japan, Singapore) is developing a globally portable model — one built on interoperability with existing certifications rather than duplication.
  • The goal is not just better security — it is professional legitimacy. When a cybersecurity professional's recommendation carries the same institutional weight as a lawyer's or a doctor's, organizations will invest differently, hire differently, and listen differently.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

The UK Cybersecurity Council professionalization argument is genuinely important and chronically underrepresented at RSA — the credential-over-competency hiring disaster is real, and chartership as a filter for applied capability rather than certification acquisition addresses something the industry has failed to self-correct for twenty years. Still too early-stage with 500 members to assess whether this is medicine or homeopathy for the workforce problem.

Heather Calloway (CISO) — SOLID

UK Cybersecurity Council presents the case for professionalizing cybersecurity — defined career pathways, consistent competency frameworks, ethics codes, and legal recognition comparable to engineering or medicine. The workforce crisis is reframed as a profession design failure.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025