CYBERUK 2023: Welcome from Lindy Cameron
NCSC CEO welcomes delegates to the first day of CYBERUK 2023 at ICC, Belfast on 19 April.

Good morning and welcome to CYBERUK 2023.
Thank you for coming together here in Belfast. I am particularly grateful to our delegates and speakers, including our closest international colleagues.
Together, you are the people that make CYBERUK what it is.
I’d also like to give a big thank you to our lead sponsors, AWS and Google Cloud, as well as our other supporters and exhibitors, especially BT, Microsoft and CISCO who have laid on excellent networking opportunities this week, which I hope you've all recovered from last night.
Northern Ireland
For those of you that can’t tell from my accent – I’m very proud to be a “Derry Girl” and call Northern Ireland my home and place of birth.
I’m truly delighted to welcome you to Belfast.
Not only am I CEO of the National Cyber Security Centre (NCSC) but I am also basically Northern Ireland’s biggest fan.
In fact, the NCSC must be the only part of Government to have been consistently led by people from Northern Ireland.
I'm delighted that my predecessor, Ciaran Martin, is at the conference this week.
You’ll have seen the events marking the 25th Anniversary of the Belfast Good Friday Agreement. This is a truly remarkable milestone.
When I was growing up in Northern Ireland in the 70s and 80s, the kind of peace we have seen over the past 25 years was simply unimaginable.
The Belfast Good Friday Agreement has broken down boundaries, brought people together and opened up opportunities.
The prosperous economy you see here today has been built on the foundations of the Peace Process. And Northern Ireland’s thriving cyber security industry is just one fantastic example of this.
It’s no wonder that Northern Ireland is the prime investment location for US cyber security firms.
A crucial part of that success story is the strong connection between industry and education in Northern Ireland, as well as the world-class research and excellence in vocational training at institutions such as Queen’s University Belfast and Ulster University.
I'm really delighted to welcome some of their representatives here today. I encourage you all to meet with them and be enthused by their ambitious approach.
They are creating a global cyber security ecosystem, with Northern Ireland academic institutions at its heart.
Reflections on the last year
So back to the last year in cyber security. Many of the collective challenges we face in cyber security are not focused on how we secure today, but how we secure tomorrow.
That is why we have focused CYBERUK 2023 on securing an open and resilient digital future.
But before we think about those future challenges, I want to offer some reflections on the past year and what’s changed. In particular, I want to talk about the profound importance of resilience.
Ukraine
Russia’s horrific and illegal invasion of Ukraine has seen them maintain a high operational tempo in their cyber operations, with the GRU taking a leading role.
However, a significant collaborative effort mounted by Ukraine’s cyber defences - with support from foreign governments and the cyber security industry has been fundamental in reducing the effectiveness of Russian offensive cyber activity.
On a personal note, I am really proud of the role the NCSC played, in conjunction with FCDO and our allies, in supporting the Ukrainians’ staunch cyber defence in the face of Russian hostility.
And I am also delighted that Victor Zhora and his team from Ukraine have joined us here today in Belfast. Welcome to them.
If there is to be a single takeaway from the Russia-Ukraine conflict, it’s the importance of effective cyber resilience.
However, I don’t think we are yet doing enough to protect our infrastructure from the cyber threats emerging from Russia-aligning groups.
Oliver Dowden, the Chancellor of the Duchy of Lancaster and Secretary of State for the Cabinet Office, will say more about this shortly.
But let me set out the NCSC's position: if the UK is to be the safest place to live and work online, then resilience must urgently move to the top of our investment shopping list.
It is simply not good enough to say that it is too difficult or, worse, that it is not a priority
The UK’s Critical National Infrastructure is crucial for maintaining national security and preventing disruption to essential energy, transportation, and communication services.
These sectors are responsible for the day-to-day functioning of our society and economy, so we cannot simply hope that everything will be OK.
Cyber crime
We must also be resilient to all threats, whether they come from nation states or cyber criminals.
Since we met in Newport at last year’s CYBERUK, we continue to respond to complex nationally significant incidents.
As the National Cyber Strategy makes clear, we've got to do more to make the UK as unattractive a target as possible for cyber criminals.
And today, the new Department for Science, Innovation and Technology (DSIT) has published the latest cyber breaches survey.
It shows that that over the past 12 months, nearly a third, 32% of all businesses and nearly a quarter of charities reported a cyber incident – though these percentages are much higher – almost double – for medium and large businesses.
And the disruption caused by these attacks is not just inconvenience – it is also financial.
It is estimated that the average cost each to businesses of any size was approximately £1,100. For medium and large businesses, this was nearly £5,000.
Many of these incidents are the result of poor cyber hygiene rather than complex or sophisticated attack techniques.
This is why we are encouraging organisations to consider Cyber Essentials certification as part of an annual cyber security 'MOT'.
We know that organisations that implement the Cyber Essentials controls are 80% less likely to make a claim on cyber insurance than organisations that don't have Cyber Essentials.
And if you don't know where or how to start, I’m pleased to announce that NCSC is launching a new Cyber Advisor scheme to help you and the millions of small and medium organisations that we know don’t have the skills inside their organisation to keep themselves secure on-line achieve a baseline level of cyber security.
Securing future technology
But as we come together here in Belfast, our focus is firmly fixed on the future.
Our theme for this year's conference reflects the Prime Minister's own ambitions for a concerted focus on developing UK Science and Technology skills.
Unsurprisingly, we as the NCSC, think it is crucial for cyber security to be bult into future tech and their supply chains from the outset.
The government’s PSTI Bill (Product Security and Telecommunications Infrastructure Bill) does exactly that - setting out the importance of establishing a strong framework for managing future technology.
Good cyber security will not only help industry, CNI and government realise the benefits of these advances, it will also help build public trust in technologies.
They underpin our way of life: our economic prosperity; our national security and our freedom to live true to our values.
In a world of accelerating change, NCSC’s role as the UK’s National Technical Authority is to provide timely and high-quality input to others.
We want to shape and influence tech policy to help realise the Government’s ambition to make the UK a science and tech superpower.
Cyber security must be built into thinking on artificial intelligence, semiconductors, quantum technologies, and future telecoms – all of which are underpinned and enabled by data.
Ensuring the security of these elements will be essential for the UK to thrive in the face of uncertainty…and will help secure that resilient and digital future.
The security of AI is an emerging field. It is fundamental for AI being safe, ethical, explainable, and reliable. We are just getting started and there are lots of challenges in the research space that I hope some of you will take up.
Despite being widely used already, Artificial intelligence (AI) and Machine Learning (ML) developers must predict possible attacks and identify ways to mitigate them. Failure to do so will risk designing vulnerabilities into future AI systems.
So DSIT – the Department for Science, Innovation and Technology - have already set the ball rolling with their AI white paper published last month. It sets out a sensible practical approach to regulating artificial intelligence that will help create the right environment for AI to flourish safely in the UK.
Large Language Models (LLMs) like ChatGPT are a great example of the broader challenge that we face as technology advances at an ever-increasing speed.
The benefits of LLMs are incredible – and clear for all to see. They’ll revolutionise industries, make our economy more efficient, and provide a valuable service to consumers across the world.
Since its release last year, ChatGPT has captured the world’s imagination – and ignited debate about the possibilities and pitfalls of tech advances that are here today, not just on the horizon.
As with any emerging technology, there are rightly questions about what this means for security.
The NCSC has recently published thinking on the cyber security implications of ChatGPT and other LLMs, helping people like you to think through the challenges we all face in securing these technologies.
The semiconductor industry is another area for focus for us all. Semiconductors continue to find their way into more and more technology and we rely on their performance and resilience to underpin the modern economy.
Yet they have complex supply chains for their design and manufacturing and there is lots of work to do to ensure we can rely on their integrity.
So, I urge you to join the panel discussions about how the UK is addressing challenges of securing our future technology, with a specific focus on semiconductors.
That panel will be discussing what can be done to build in the required resilience to future tech, what STEM skills are required to sustain the workforce, and how best to collaborate with partners in industry, academia and our international government partners to grow the ecosystem.
When it comes to Quantum Technologies, organisations must factor the impact of quantum computing into their long-term roadmaps.
We must all prepare for the rollout of post-quantum cryptography over the coming years, safeguarding the security of the cryptography that underpins the internet, and therefore the digital economy.
Major global vendors will, in due course, update their operating systems and cryptographic libraries with internationally accepted and standardised quantum resistant solutions.
Organisations and individuals with standard office set-ups will, if you ensure you update regularly, benefit from those improvements automatically.
But we know some sectors have more specialised needs, either because they have bespoke infrastructure, or where there are genuine practical constraints on regular updating - that's not an excuse!
NCSC is generating plans to identify your needs…and guidance to help you.
As well as these challenges, the UK can also harness the nearer-term opportunities that quantum computing will provide, such as the chance to solve complex logistics and simulation problems in a sustainable and energy efficient way…a real boost to our digital economy.
Two final areas requiring our combined attention are telecoms networks and cyber proliferation.
It may feel like 5G is only just here, and we've dealt with the challenges, but we need to be thinking right now what we want 6G to be.
Our mobile phones will soon be connecting to satellites when there’s no cell tower coverage on the ground. That’s amazing, particularly in remote areas, but it fundamentally changes the security model, so we need to look at the new risks that introduces and figure out how to deal with those.
Securing data infrastructure and future telecoms networks will need collaboration and coordination between government, industry and academia to ensure our future reflects our democratic values and interests, as well as those of our allies.
And values are right at the heart of the debate around cyber proliferation. The rapid expansion of the commercial cyber capability market is lowering the bar to entry, as I have said before.
It is increasing the risk of proliferation of ‘state-level' capability to non-state actors. This makes the threat landscape more difficult and more volatile.
How we define and enact responsible cyber behaviour will be key to addressing this challenge. The panel session closing today will explore how we do that collectively to determine what should and should not be tolerated.
Secure by design
I mentioned earlier the need to secure semi-conductor supply chains.
Centring the cyber security of these and other future technologies and their associated supply chains is paramount.
It is something I spoke about with David Koh at Singapore Cyber Week, but it bears repeating.
Secure-by-design and secure-by-default development practices must change if we are to alleviate the burden of cyber risk from the consumer.
We need to be running faster towards automatically fixing those things that we know are important. If we don’t take this seriously now and keep pace with the rapid rate of tech development, then we are going to be in big trouble very soon.
Much of our digital architecture was never designed with security at its heart - you all know that better than anybody. It was built on foundations that are flawed and vulnerable. And, unless we act now those same flawed foundations will underpin tomorrow’s technology as well.
The UK government is partly addressing this through the Digital Security by Design programme, which is pioneering UK academic research into real hardware that developers can actually use.
And just last week, our US counterparts, CISA, published a joint guide with us...Australia, Canada, Germany, New Zealand and the Netherlands, many of whom are here today, to help technology manufacturers put security at the heart of how they design and develop their products.
We’ll be exploring this topic in greater detail over the next two days, examining what is needed to fix our foundations, so we can benefit from advances in tech that will power the next generation of our connected infrastructure.
The simple fact is that technology and digital service providers need to work with government and academic partners to make connected systems more secure at source and behind the scenes.
And today's Stream C sessions provide great insight into how investment in research is developing new techniques for doing that. I will also be chairing a panel discussion tomorrow looking at how we are incentivising our economies to build this technology into resilient systems.
Rise of China
For all the talk about future technology, we cannot do so without addressing the epoch-defining challenge that we are all facing: the dramatic rise of China as a technology super-power.
The Integrated Review Refresh published in March sets out a new approach to manage this challenge.
It recognises China’s size and significance on almost every global issue.
We already know that China has huge ambitions to grow its technology base; rightly so.
China has identified several existing and emerging technologies – AI, quantum computing and semiconductors – as rightly being vital to its future national security.
And it has an aspiration to become a world leader in setting technological standards.
So, we need to be clear: China is not only pushing for parity with Western countries, it is aiming for global technological supremacy.
It wants to achieve a dominant role in global affairs.
Last year marked the first anniversary of China’s Data Security Law that requires security researchers to report vulnerabilities to the state, before disclosing them to other entities; thereby delivering strategic advantage to China in further developing its cyber capabilities.
And, China continues to use cyber in pursuit of its comprehensive global intelligence collection and surveillance platform, to acquire intellectual property and achieve its strategic geopolitical goals.
So what does this mean for all of you, for us, in cyber security?
Bluntly, we cannot afford not to keep pace with China. Otherwise, we risk China becoming the predominant power in cyberspace.
Some may dismiss this as far-fetched or scare-mongering, but it is a risk I would urge you to take seriously and think about how it is we avoid complacency.
This is simply not something that we can be complacent about.
We have a legitimate concern about whether the technology China is producing will allow us to secure ourselves effectively in a way that means we can do cyber security in ten years’ time.
We want to make sure that people developing these technologies are thinking about how they can be used safely for genuine public benefit as opposed to simply for national strategic advantage.
We possess huge advantages that give me confidence that we’ll keep pace: our liberal economy, democratic values and collaborative allies.
Collaboration is one of the keys to our success. It’s the USP of our free, open, democratic culture. Only through collaboration between industry, government and academia will we maintain a cyberspace which is a safe and prosperous place for everyone.
We, as a community, all of you out there, are responsible for individual and collective actions, and must ensure that new capabilities are produced and used in a way that is legal, responsible and proportionate.
Conclusion
So together, we can and will continue to secure cyberspace, so it remains free, open and democratic.
Focused investment and interventions by industry, government and academia will nurture and grow the talent needed to innovate and build the technologies that underpin our values and make us resilient to future threats, risks and vulnerabilities.
Doing this will ensure we are competing at the front of the pack in the technologies that will define the next decade.
The decisions you take today – and some of them are hard – will lay the foundations for a secure free, open and democratic cyberspace.
A secure digital tomorrow really does start today.
I hope you enjoy CYBERUK 2023 – i hope you spent the next two days having fun and leave with re-doubled conviction to play your part in securing our futures.
Thank you.
I’m now delighted to welcome to the stage, the UK’s lead government minister for cyber security, The Right Honourable Oliver Dowden MP, Chancellor of the Duchy of Lancaster and Secretary of State for the Cabinet Office.