Richard Horne speaking at the RUSI Annual Security Lecture
NCSC CEO, Richard Horne's full speech delivered at the RUSI Annual Security Lecture 2026.

NCSC CEO Richard Horne speaking at RUSI Annual Security Lecture 2026
Introduction
Good afternoon.
I stand here today with a sense of humility for three reasons.
First, because of you, this august audience gathered here and this stage on which I have the privilege to speak. A forum shaped by serious thought, respected voices and the many individuals who have stood here before.
Second, because I have enjoyed a whole career in cyber security. Long before we even called it cyber security.
My journey began working on the development and implementation of chip cards for payments, at a time when trust in digital transactions was being established which I’ll return to later.
Across decades, one lesson has become increasingly clear and it is captured well in the old adage the more I know, the more I realise how much I do not know.
Cyber security refuses to stand still. It evolves continuously as the technologies that underpin modern life rapidly develop.
And in such an environment, humility is not just a virtue it is a necessity.
And the third reason for humility, is the sheer consequence of this subject today. To speak about cyber security is no longer to discuss a narrow discipline.
It is to speak about something much more... our very foundations. The going concern of our businesses, delivery of our critical national services, the health of our economy - as we saw starkly in October last year and ultimately our national security.
And for those reasons, I want to use this occasion not simply to inform but to provoke.
To provoke thought, reflection, and I hope, discussion.
And to challenge mindsets that might hold us back as we confront one of the defining issues of our age: how to build a more secure digital society.
Contest not risk
So my first challenge to you is that I believe we often view cyber security as something it isn't.
We view it as a risk.
Many of you will recognise the sight of cyber security high on your board risk register, ultimately treated as another ‘risk’ to be mitigated.
But that is often the wrong framing. At times the language of risk can be helpful, but it can do us a disservice.
Sadly, while we might like to think that individuals, companies and nations should have the right to operate in the digital territory of the world unbothered by those who would do us harm, it is not a given.
But it is something we have to contest.
And understanding cyber security as a contest is crucial for us all.
The language of risk encourages us to think about what's needed to get it under control, to get to a point where it’s ‘in appetite’; where we can tolerate it.
But the language of a contest is about capability and performance, not control.
It focusses on constantly striving to be better, because we know our adversaries are doing exactly the same.
So, when executives ask ‘when will we be done investing in cyber security?’, the answer is: never!
I had the pleasure of meeting Sarina Wiegman this morning, the ladies' England football manager if you didn't know. I suspect she might never conclude that the England team are now 'good enough' and the risk of losing is 'within appetite'.
Of course not. We all understand that competition demands constant development. The margin between winning and losing is rarely fixed. It is something that shifts, constantly, and therefore requires a constant push to improve.
Then, we often see a desire to benchmark cyber security against peers. Which is a common approach in risk management.
But, whilst benchmarks have their place and can illuminate blind spots, being ‘roughly as good as your peers’ is not a complete strategy for security.
In any contest, the only benchmark that matters is how your capability and performance compares to that of your opponent.
Understanding where your defences are weaker than you would like, how an adversary might exploit those weaknesses and where your strengths can give you an advantage.
And this contest is not confined to a compact space. It's not like a wrestling match in a closely-defined territory as some have suggested. It is more akin to a football or basketball game (or even quidditch, if you want more dimensions!), played across a large field of play, where success depends on how you operate across the entire pitch.
In this analogy, we can describe the spaces we need to contest in cyber security as ‘near’, ‘mid’ and ‘far’ spaces.
The different parts of the environment where we come into contact with our adversaries – with different approaches in each.
And today, I will explore what it means to think about cyber security as a contest across all three of those spaces, in a coordinated way – in a ‘full court press’ to use the basketball analogy.
Far space
So let me start with the far space.
This is the adversary’s home turf, their systems, their tooling, their networks.
It is the ground they believe they control. But where we, and our allies, bring pressure to bear, through intelligence collection, sanctions, law enforcement action and offensive cyber operations to disrupt and degrade their capability at source.
It's also where we understand the attackers' intent and capability and is why the National Cyber Security Centre’s position within GCHQ and alongside our partners in the National Cyber Force, is so important.
As you will appreciate, many examples of the action we take in this space must remain secret, but our strength in this area is critical to maintaining strategic advantage over those who wish to harm our nation.
And it's from our operations in the far space that we are able to generate actionable intelligence for defence.
Mid-space
Now to the mid-space.
This is where we can deliver collective scaled impact through hardening cloud, technology and telecommunications infrastructure, and by disrupting adversary positions within those environments.
The reality is much of this space is in private hands. Which means success here demands genuine collaboration between government and private sector, which is at the heart of our approach in the NCSC.
It means sharing what we learn in the far space, pooling what government and industry together see in the near space and turning that collective insight into action that raises the security of the whole ecosystem, not just individual organisations.
We published an article a couple of weeks ago highlighting how attackers are compromising environments, often in the cloud, that are part of the open source ecosystem and provide crucial building blocks to much of the technology we use.
And then using that access to spread malicious code and having a scaled impact on our vulnerability.
A prescient example of how our adversaries see the benefit of operating in the mid-space.
And then we must also understand the role that cloud-based AI services will play to enable attackers in this space.
We've already seen commercially available cloud-hosted cyber security tools, such as Cobalt Strike, be abused by nation states and cyber criminals.
And when new AI powered security tools are released, it’s not long before discussions appear on cyber crime forums exploring how those same capabilities can be repurposed for cyber attacks.
So we should expect to see cyber criminals increasingly exploit the mid-space.
Near space
And finally, we come to the near space…
Which is the defence and resilience of the organisations and systems being targeted.
This is where arguably the greatest scale of action is required and where the widest range of people must be involved if we are to remain competitive in this contest.
There is little value in contesting the mid and far space if, as a nation, our own systems, networks and institutions remain inherently vulnerable. And that challenge is only going to be exacerbated as AI continues its march of progress.
Recent developments of frontier AI models have demonstrated their effectiveness at finding inherent vulnerabilities in the technology we rely on.
Our latest Assessment shows that by 2028, it is highly likely that AI-Cyber capabilities will be used by attackers against known vulnerabilities in legacy technology in our critical national infrastructure.
So, our role as government is to catalyse a response at scale. From the largest organisations, all the way to individuals in their own homes.
Initiatives such as the Cyber Security and Resilience Bill will help drive that action, using regulation to strengthen the defence and resilience of our most essential and national services.
But those will only get us so far, we need every organisation to step up in this contest.
Every board member and every executive, in every organisation, must grasp three fundamental imperatives of cyber security.
Capabilities that every organisation must deliberately build.
The first is to understand.
They must understand the exposure of the organisation. Where are they exposed through new technology? Through their old, legacy technology? Through their supply chains? The list goes on.
And what adversary capability might be thrown at them?
Where have they, consciously or unconsciously, bet the organisation’s entire operations on technology that could easily be disrupted?
The second capability is to defend...which has many elements to it.
The starting point has to be foundational capabilities consistently deployed, everywhere – the basics of ‘blocking and tackling’ to use the language of team sports.
We often refer to these as Cyber Essentials and have argued for their adoption for over a decade.
Yet we still see far too many significant incidents today that are possible...because the fundamentals are not in place.
And many organisations will need to do more than just those fundamentals.
Just as we empower organisations through a national system that drives the adoption of Cyber Essentials, we also provide a far broader set of more advanced tools, guidance, and support available to strengthen cyber defence, such as the Cyber Assessment Framework.
From architecting systems so that a breach can be contained, the blast radius minimised and it does not have catastrophic impact through to developing advanced threat hunting capabilities that can detect and disrupt increasingly sophisticated attackers.
Every organisation has to decide for themselves the precise capability they need to be fit for the contest they face as they choose to operate in the digital realm.
Then the third capability is the ability to respond.
To be able to continue critical operations.
And rebuild systems, at scale, in the event of a successful cyber attack disrupting systems and causing impact.
It is a hard capability to develop and often requires rethinking some longstanding business choices that were once primarily driven by cost.
But in today’s world, the ability to absorb cyber attacks, contain their impact, sustain critical operations and recover quickly is no longer optional.
It is a core competence for any digital organisation ... and today, that is pretty much every organisation.
And the near space is also where we should have the home advantage.
Because we should have ownership and control over the technology we operate.
But increasingly, for good reasons, connected systems retain an element of control by technology providers.
And this is where trust comes into play. At both organisational and national levels, we have to ask difficult questions as to who we are trusting when we deploy technology.
And that has to be a factor in everyone’s choices, not just cost and features.
We don't have the luxury of time
So that was my first challenge. The next two are shorter!
My second challenge is that we do not have the luxury of time.
Any time we have is limited, and so we must use it to best effect.
In some ways, it's obvious – given the pace at which technology is developing – and in all my public speaking since taking this role 20 months ago, I have stressed the urgency with which organisations need to act, for their own protection.
But when viewed from the perspective of future conflict, the imperative to act with urgency is even greater.
Because any conflict we fight tomorrow will depend on how well we engage in the contest today.
Let me give you three reasons as to why this is the case.
First, kinetic targeting in any conflict tomorrow will be based on intelligence gathered today. Part of preparing for any potential conflict involves cyber espionage... gaining a clear understanding of the landscape to inform and refine potential targets.
This isn't something theoretical. It is a pattern we have seen repeatedly play out in recent conflicts.
Second, often vulnerabilities can't be fixed overnight. And so the many vulnerabilities that organisations tolerate today will be exploited in conflict tomorrow. If they are too expensive or hard to fix in peacetime, then they certainly will be in war.
And third, we know that adversaries are prepositioning today establishing footholds within technology that underpins critical national infrastructure that could enable rapid exploitation, to cause mass disruption in a time of conflict.
The highest profile example of this was a campaign often referred to as Volt Typhoon against largely US critical national infrastructure, that was attributed in 2024.
And we are seeing our critical infrastructure being targeted, regularly finding and stopping breaches, before their intent becomes clear.
Between June last year and this May, we managed more than 200 incidents impacting organisations within our CNI and supporting ecosystem.
And of those incidents, 75% were believed to be linked to state actors.
So, in addition to protecting ourselves today, this is why we must act with urgency as a nation. And with international partners – as we are not a digital island.
And it is also why I stand here with humility. The stakes in cyber security could not be higher. In cyber space, we are not preparing for tomorrow’s conflicts... to some degree we are fighting them today.
And this is reflected in NATO’s Article 3, which stresses the importance of national and collective resilience.
Crucially, that article also reflects opportunity. By making our environment harder for adversaries to operate in, and engaging in the contest better, we can play an important part in altering potential adversaries’ options and deterring conflict.
We can be successful
Then my third and final challenge is a simple encouragement. We can be successful in this contest.
It's easy, especially for businesses, to slip into the mental trap of ‘well what can we really do’ and to accept the inevitability of catastrophic events.
I would argue that while breaches are inevitable, catastrophic impacts need not be.
And when I feel unsure, I often pat my pocket. For in there, like many of you, I have a payment card.
And I go back to the start of my career, and the development of the EMV specification for payment chip cards. In a couple of weeks, we can celebrate the 30th anniversary of the first issue of that specification. Probably not a milestone that was top of your mind!
And it has held strong for three decades, constantly attacked, consistently prevailing.
Of course, vulnerabilities and implementation flaws have emerged, but have been rapidly contained and addressed.
Why? Because it was built for the contest.
Security at its heart. Designed to be constantly upgraded, evolved and improved. Sustained investment over its lifetime to ensure that has happened.
At the heart of hundreds of billions of payments all over the globe, every second of every day. Within one of the most hostile environments for security to thrive over such a period of time and as we look ahead to the wider contest we must adopt the same mindset.
UK initiatives such as CHERI can be a game changer, revisiting fundamental design choices in hardware and software to enforce memory safety and protect against whole classes of vulnerabilities.
Work we are driving in the NCSC to move us towards a National Cyber Defence Capability to support the security of the nation in an agentic AI world. To join up intelligence and actions in the far, mid and near space in real time. To reimagine cyber security in an AI world.
Work we do every day to empower organisations to be capable of defending themselves in this rapidly changing world and partnering with infrastructure providers to harden the mid space and disrupt attacker activity.
And, of course, the work that your organisations do day-in and day-out to contest the digital space on which you rely. With an often-unseen army of cyber defenders across our nation, united in a shared mission.
Conclusion
The truth is that in this great contest there are no spectators, we are all on the pitch. From boardrooms to IT help desks, to sofas at home, to operations and partners abroad the contest is everywhere.
If we collectively embrace the contest, understand the urgency and believe we can be a match for any opponent, then we can and will prevail.
Thank you.


