Richard Horne's Government Cyber Security Conference speech
NCSC CEO delivers keynote speech to the annual government conference on cyber security.

Introduction
Good morning.
Thank you for inviting me to speak to you.
This is my first Government Cyber Security Conference as CEO of the NCSC and I want to start with a huge thank you to this community for making me so welcome.
The NCSC has always maintained that the UK’s collective cyber resilience depends upon everyone – from individuals and families to SMEs and large enterprises, and of course government – playing their part.
We often say that cyber security is a team sport, and it is.
As government, we have made a great deal of progress in recent years, but there is much more to do.
To meet the threats we will face in the coming decade, we must continue working together to transform how we approach cyber security in government.
Threat landscape
It will not be news to anyone in this room that the world continues to grow more complex, more unstable and more unpredictable...and the threat we face, continues to evolve.
The NCSC - as the UK’s technical authority on cyber security, and in our privileged position as being part of GCHQ - see the full spectrum of cyber threats and challenges to our society and economy – through intelligence, incidents and near misses.
Russia continues to act as a capable, motivated and irresponsible threat actor in cyber space.
China continues to be a highly sophisticated and capable threat actor, targeting a wide range of sectors and institutions across the globe, including in the UK – and we see that sophistication growing rapidly.
And Iran and the DPRK continue to pose risk to the UK and our allies.
And this is all happening at the same time that criminal enterprises are continuing to target people and organisations in the UK at will.
With ransomware being the biggest day-to-day cyber security threat to UK organisations and our critical national infrastructure – with a stream of near misses constantly reminding us how close we are to a high-impact ransomware event.
But it’s easy to just focus on the threat, when it is only part of the risk picture. The other two parts are Exposure and Vulnerability.
As we transform our society, and especially government services, we are making ourselves more dependent on technology, and therefore more exposed to the impact of cyber attacks – and so the stakes are being raised constantly.
But the thing that is most in our collective control is our vulnerability, and I include in that our defence and our resilience ...
The challenge
And it is why...we welcome the report that the National Audit Office are publishing today on the government’s cyber resilience.
The report will continue to drive honest conversations across government on the integrity of our cyber defences, which is essential.
As building resilience is not just best practice. It’s a strategic imperative.
The upcoming Cyber Security and Resilience Bill will be an important step in achieving this.
And the recent State of Digital Government report reminds us all of the importance of security in the vast array of government digital products, which we all rely on every day.
We are all using digital technology to our benefit: to drive growth, drive innovation, drive productivity, drive better public services...drive prosperity.
And so we should.
Government organisations - and the functions and services they deliver - are the cornerstones of our society. It is their significance. But this also what makes them an attractive target for our adversaries.
So as I said, as technology advances and our dependence on technology increases so to will the potential impact. This is inevitable.
So again we need to focus on the ‘so what can we do about it?’.
When the NCSC launched the Annual Review in November last year, we addressed something called the ‘widening gap’ - between threat and exposure on one hand, and defence and resilience on the other
This gap will only become more apparent over time.
So where does the NCSC fit?
We will continue to develop and use the knowledge we have as the most authoritative voice on UK cyber security to bolster UK cyber defences.
This knowledge is communicated through the NCSC publishing advice, guidance and frameworks that aim to drive up the cyber security of the UK, and that will continue.
Driving adoption of the advice, guidance and frameworks is now one of our biggest challenges across the UK – and we will continue to partner with Whitehall policy departments to ensure we collectively use policy levers to drive adoption and cyber security at scale.
A part of this raising resilience ‘across the board’ is investing in interventions that scale – revamping our Active Cyber Defence services.
Our position in GCHQ is more important than ever. As our adversaries become more and more sophisticated, a critical driver for our success in defending the UK will be our ability to:
- increase our intelligence as to what our adversaries our doing,
- turn that into actions that can be taken to hunt for their activity on government, CNI and other systems,
- and then work jointly with owners and providers of those systems to defend them and evict the attackers.
And that will require increased partnering with international partners, providers of technology and users of technology who are critical to our nation.
Finally, we need to take seriously our voice as the national technical authority – in being clear about the risk, and clear about actions that need to be taken. To that point, there is a leadership message that I will be repeating endlessly – that it is a leadership responsibility to:
- Understand their organisation’s exposure (and that includes through the supply chain)
- Ensure appropriate defences are in place
- Have a plan for how to continue operations and recover in the face of a successful cyber attack
Government developments
It is clear – from our own experience and the lessons that we have learnt from our allies – that the current rate of improvement...against the trajectory of the threat, is not as advanced as it should be.
The Government Cyber Security Strategy laid out in 2022, that we must continue work to harden our critical national infrastructure and ensure that the rest of the public sector is resilient to known vulnerabilities/attack methods by 2030 – and we know that we are a way off.
We know that building the cyber defence capability to detect and respond to advanced threat will require changes.
And this will build on the progress of the Government Cyber Coordination Centre that was established in 2023, which coordinates the operational cyber security efforts across the government sector. Enhancing government’s resilience and ability to ‘Defend as One’.
And 2024 saw the first set of annual GovAssure returns from government departments, which provides an assessment of the cyber security of critical systems underpinning government’s essential services – which has put hard data behind the view that it needs to be improved.
Conclusion
The threat we face is very real, it isn’t hypothetical. It is having real world impact.
We want the UK to make the most of new technology as it develops.
Because we know that reaping the benefits of technology is one of the most powerful forces for public service reform, and when it is successful, it changes lives and the public experience of government.
The UK public sector has digital services that we should all be proud of.
But we are still a long way from building a truly digital state that is well-defended and resilient. And it’s why we want to continue working with you all here today, as we navigate our shared challenges and opportunities.