NCSC CEO, Richard Horne - RSAC conference keynote
NCSC CEO Richard Horne warns of rising cyber risks, growing vulnerabilities, and AI‑driven challenges in his RSAC keynote, urging stronger digital resilience.

Introduction
We live in unprecedented times for cyber risk, with it being of greater consequence than ever before.
Cyber risk is often discussed as a function of threat, vulnerability and impact, so I will take each of these in turn, starting with impact.
Impact & exposure
We see both the potential and actual impact of cyber attacks consistently rising.
As a simple example: in October last year, the UK economy recorded negative growth. Economists have attributed that downturn to a single cyber attack on a major manufacturer, and the ensuing impact on their supply chain.
Or the potential impact on energy supply to a nation that we saw with the recent attack on the Polish electricity supply.
This rise in impact, I would suggest, is driven by our ever-increasing exposure.
As our society becomes more dependent on digital technologies, as we rightly exploit them to fuel our growth, support our industries and connect our communities, we, in turn, are more exposed to the impact of cyber attacks.
Vulnerability
Now vulnerability. I think it’s fair to say that vulnerability management approaches are maturing, but not at the pace and scale required by the increasing exposure.
Over the past decade, we have seen a step change in organisations investing in cyber security, but we often see victims of cyber attacks who did have multi-year improvement programmes in place recognising in hindsight that they had not made real-world progress at the speed required.
And then we do face a fundamental issue of the quality of the technology we use, and the inherent vulnerabilities that result.
Our research shows that the rate of defects per line of code has remained broadly static, while the software source code in systems doubles on average every 42 months, with zero-day vulnerabilities regularly weaponised before organisations have been able to patch for them.
Now we see technology advances changing the landscape. It has rapidly become normal to use AI to write and develop code, offering huge benefits in productivity and accessibility.
But this must not be at the expense of security.
The attractions of vibe coding are clear, and disrupting the status quo of manually produced software that is consistently vulnerable is a huge opportunity, but not without risk of its own.
The AI tools we use to develop code must be designed and trained from the outset so that they do not introduce or propagate unintended vulnerabilities.
If vibe coding and other tools are to reshape how we think about software, then we as a community have both the opportunity and responsibility to help shape that future, ensuring that it is a net positive for security.
Threat
The third part of the risk equation is threat.
We often talk about individual categories of the threat landscape: criminals, state actors and so on. Yet what has struck me most since taking this role is how the totality of threat landscape is evolving and morphing.
Let me give you a perspective on the components of that threat landscape through the lens of their relationship to nation states.
Nation states
We first have the nation states, often conducting cyber attacks through their intelligence services or military capabilities, with rapidly increasing sophistication.
The Chinese and Russian intelligence services are the most advanced in that space, followed by others.
Nation state-directed
Next is what I would refer to as nation state-directed. Organisations such as IT security companies in China like iSoon, whom we have sanctioned in the UK, for carrying out attacks against the UK and our allies on behalf of their state, broadening the range and scale of threats we face.
Nation state-aligned
The next category is actors which are nation state-aligned, often referred to as hacktivist groups.
The likes of NoName057 and Z-Pentest-Alliance, who seek to cause disruption and present themselves as independent, but their activity consistently aligns with the strategic interests of their nation state.
Their capabilities appear to be evolving, moving beyond just denial-of-service attacks to targeting exposed industrial control systems. For example, in July, the attack against a Norwegian dam that altered water flow, fortunately without material consequence.
Nation state bought
Then there is nation state-bought. Commercial Cyber Intrusion Companies provide exploits and tooling to cyber actors of all kinds.
This marketplace has legitimate need, supporting law enforcement and defensive research.
Through our work with private sector companies we see increasing evidence that these offensive capabilities are propagating, being sold to less‑responsible states and making their way into the hands of criminal groups, lowering the barrier to entry raising the risk to us all.
Nation state-sheltered
And then nation state-sheltered groups. Organisations such as ransomware groups in Russia whose primary motivation is criminal profit. Not directly linked to their host nation but enjoying a degree of sheltering from international law enforcement.
Over the past few years, these groups have honed their techniques to increase their ability to cause disruptive impact or locate sensitive data for their grubby extortion tactics and they sit at the heart of a vibrant criminal ecosystem.
Criminals
Which brings me to the final category: pure criminals. Potentially linked with other forms of criminality, they don’t need huge sophistication themselves because they can benefit from acting as affiliates to the large ransomware groups acquiring the tools and services they need.
The why
Now I explain the threat in this way for two reasons.
First, because we increasingly need to see the whole map to understand that it is a web of actors, who blur the categories, increasingly linking to and enabling each other.
For example, research from several commercial organisations has shown certain criminal groups who execute ransomware attacks also acting as exploit brokers and intelligence agencies using criminal tooling when convenient.
The second reason for laying out the threat in this way is to consider what it means for us as defenders. If the threat is multi-dimensional, then our approach to defending our societies must match that.
I grew up playing basketball, which was less common in the U.K. at the time. Clearly given my height, I was point guard and not centre, and sadly my ability to sink three-pointers was not exactly Caitlin Clark’s.
But, I learnt the concept of a full court press for defence, applying pressure in every area of the court, and that has to be how we think about cyber defence.
In the NCSC, we think in terms of cyber defence in the near, mid and far spaces and the need to apply pressure consistently across them.
Near space
The near space is the defence and resilience of the organisations and systems being targeted. That means every organisation – large or small – getting the basics right consistently and comprehensively across every part of their networks and supply chains; behaviours that we refer to as the Cyber Essentials.
It also means medium and large organisations, and particularly our Critical National Infrastructure, continually improving their defences.
In the UK, we have the Cyber Security and Resilience Bill going through Parliament with that objective for our critical national infrastructure, building on the Telecoms Security Act which has matured defences of telecoms companies.
It also means all organisations viewing the ability to continue critical operations when IT has been turned off and to rebuild IT at scale as a core part of their cyber resilience.
Mid-space
The mid-space is where we can deliver collective scaled impact. Hardening cloud infrastructure, for example, and disrupting adversary positions within those environments as Google recently demonstrated with the disruption of IPIDEA.
As another example, our Share and Defend capability is sharing known malicious links with
internet service provider partners in almost real time, to enable them to block over a billion attempted connections a year and prevent real harm to their customers.
Far space
And then the far space is the adversary’s home turf, their systems, their tooling, their networks. It is the ground they believe they control but where we bring pressure to bear, through intelligence collection, sanctions, law enforcement action and offensive cyber operations, to disrupt and degrade their capability at source.
Executing the full court press
The trick for us, as a defence collective, is to execute that full court press as effectively as we can.
In a full court press, no one action will solve it: it is the collective pressure from all actions together that makes the difference.
Whether it's through law enforcement interventions, infrastructure takedowns, public advisories,
Threat hunting on victim networks, offensive cyber operations, encouraging organisations to have resilience and recovery plans in place.
Targeted regulation that makes investment in cyber defences part of the price of providing a critical service, incentivising technology providers to ship more secure code.
International efforts such as the Pall Mall Process to limit the irresponsible spread of attack tooling, or many other tools we have at our collective disposal.
Conclusion
So our challenge, and our exciting opportunity, is to lean in as a collective to that full court press.
Increasing the pressure in each element on our adversaries, coordinating our actions across the near, mid, and far spaces through deeper intelligence and alignment activities.
Thank you for stepping into your part in that full court press. We all rely on each other for it to have maximum effect.
The threat landscape is huge, complex and diversifying, but together we are better.
Thank you.