28 July 2026

Richard Horne speaking at the RUSI Annual Security Lecture

National Cyber Security Centre  |  Richard Horne

National Cyber Security Centre CEO Richard Horne warned at the RUSI Annual Security Lecture that state-sponsored cyber adversaries are actively prepositioning within critical national infrastructure to enable rapid exploitation during future conflicts. Between June 2025 and May 2026, the agency managed over 200 incidents impacting critical national infrastructure, with 75 percent linked to state actors.

This persistent targeting reflects a shift from managing cyber security as a static risk register item to contesting it as an active, multi-dimensional conflict across near, mid, and far spaces. To counter these threats, the United Kingdom is leveraging GCHQ and the National Cyber Force to disrupt adversaries at the source while preparing the Cyber Security and Resilience Bill to mandate stronger domestic defences. Furthermore, frontier artificial intelligence models are projected to highly likely enable attackers to exploit legacy technology vulnerabilities by 2028. Consequently, national resilience under NATO's Article 3 serves as a vital deterrent against pre-conflict cyber espionage campaigns like Volt Typhoon.

Comment
Reframing cyber security as a continuous contest fundamentally alters how GCHQ and the National Cyber Force structure their joint operations. This doctrine prioritises forward-deployed disruption in the far space over simple perimeter defence. Such proactive engagement directly counters pre-positioning tactics seen in state-sponsored campaigns like Volt Typhoon. Consequently, British cyber deterrence relies on the demonstrated capability to degrade hostile networks at source before kinetic conflict begins.

No comments: