Celebrating eight years of being the NCSC – a part of GCHQ

Today marks eight years since the National Cyber Security Centre, a part of GCHQ, opened its doors for the first time and tomorrow ends my tenure as interim CEO. And so unsurprisingly, I have been reflecting on where we are as an organisation and what comes next.
Since our inception we have seen a raft of technological changes, an increasingly complex threat landscape and an evolution in the capabilities and services of our organisation. Eight years is not a long time, but this period has been transformational to the way we all live and work online. One thing that has remained constant, however, and will remain so in the years ahead, is the symbiotic relationship between cyber security and intelligence.
The connections between these disciplines are not new. Bletchley Park’s pioneering work in cryptography and the long history of cryptologists working at GCHQ underline the foundational and interwoven role that security and intelligence has played over the last century. This has been essential to our safety and prosperity, with code-making (security) and code-breaking (intelligence) working hand in hand to protect and unlock critical information.
As a part of GCHQ, the NCSC, as the National Technical Authority for cyber security, unifies these functions. We take a combined approach, governed by a robust legislative regulatory framework and oversight regime that allows us to safeguard these technologies while maximising their potential for intelligence work. This also delivers the best value for the taxpayer, by minimising the inevitable duplication that would happen if these functions were separate. Ultimately this approach strengthens the effectiveness of our mission to make the UK the safest place to live and work online.
This is a responsibility that we hold ourselves accountable for delivering, and one that we hold in trust for our successors. It demands top-tier technical expertise, from cutting-edge post-quantum cryptography to safeguarding the industrial control systems essential to the UK's critical national infrastructure (CNI), and produces world-leading security outcomes for the UK at scale.
The close integration of cyber security and intelligence is already common across the Five Eyes countries and other international partners. For example, Australia's, New Zealand's and Canada's cyber and signals intelligence agencies are structured in the same way, and just last week our close friends and partners in Sweden became the latest to announce that their National Cyber Security Centre will evolve and formally operate within the FRA, Sweden's Signals Intelligence counterpart to GCHQ.
Configurations may differ from nation to nation, but the principle remains the same: collaboration between 'poachers and gamekeepers' strengthens both sides.
Looking to the future, this interdependency between security and intelligence will only become more critical. The risks and opportunities created by new and emerging technologies and ever more sophisticated adversaries require an approach that addresses both the security of these technologies and how to leverage them for intelligence purposes.
So as I hand the CEO baton to my successor Richard Horne (who joins us formally on Monday next week) and return to my permanent role as the NCSC Chief Operating Officer, I am focused on ensuring the NCSC is well positioned for the years ahead. We must be ready to meet the challenges that will face us, backed by the might of world-class signals intelligence and the deep expertise and insights that come with this, in the mission to make the UK the safest place to live and work online.