Threat Plenary - Looking Back, Looking Forwards: In Conversation with Chich
Paul Chichester CMG (Director of Operations · National Cyber Security Centre (NCSC)), Geoff White (Author and Investigative Journalist)
CYBERUK 2026 · Day 1 · Main Plenary
Overview
This plenary session at CYBERUK offered a compelling dialogue between Paul Chichester CMG, Director of Operations for the National Cyber Security Centre (NCSC), and investigative journalist Geoff White. The conversation served as a critical retrospective on the evolution of cyber threats and defensive strategies over the past decade, while also casting an eye towards future challenges, particularly those posed by artificial intelligence. The discussion covered a broad spectrum of topics, from the changing nature of data breaches and the role of attribution in international cyber policy to the complexities of inter-agency coordination within the UK and the persistent menace of ransomware.

Key moments
- 0:00 Welcome, speaker introductions, and session overview.
- 1:30 The disappearing data breach story in cyber news.
- 2:30 Communicating the real impact of cyber threats.
- 4:00 Storytelling in cyber: Victims, Villains, Heroes analogy.
- 4:50 Attribution: breakthrough, drive, and unintended consequences.
- 5:50 NCSC's perspective: reasons and value of attribution.
Threat Plenary - Looking Back, Looking Forwards: In Conversation with Chich
Speakers: Paul Chichester CMG (Director of Operations, National Cyber Security Centre (NCSC)); Geoff White (Author and Investigative Journalist)
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=TjsbSN3XL_w
Overview
This plenary session at CYBERUK offered a compelling dialogue between Paul Chichester CMG, Director of Operations for the National Cyber Security Centre (NCSC), and investigative journalist Geoff White. The conversation served as a critical retrospective on the evolution of cyber threats and defensive strategies over the past decade, while also casting an eye towards future challenges, particularly those posed by artificial intelligence. The discussion covered a broad spectrum of topics, from the changing nature of data breaches and the role of attribution in international cyber policy to the complexities of inter-agency coordination within the UK and the persistent menace of ransomware.
The talk is highly significant for the cybersecurity community, offering insights directly from a senior figure at the NCSC, the UK's leading cyber security authority. It provides a strategic overview of the NCSC's operational philosophy, highlighting its commitment to collaboration, proactive threat intelligence, and national resilience. For cyber defenders, policymakers, and industry leaders, the session underscores the enduring nature of fundamental cyber security challenges and the adaptive approaches required to mitigate them in an increasingly fractured and technologically advanced world.
Background
▶ Watch: Welcome, speaker introductions, and session overview. (0:00)
The discussion initiated with a look back approximately ten years to 2016, a period Geoff White recalled as being dominated by headlines concerning massive data breaches, such as the Yahoo incident. While these events were difficult to get on air due to the lack of immediate, tangible narratives, they highlighted a foundational problem: the struggle to communicate the real, long-term impact of cyber incidents to a wider audience. Paul Chichester confirmed that bulk data targeting by criminals and states remains a pervasive threat, despite industry efforts to protect against it. This points to a persistent gap in public and corporate understanding of cyber risk, where the "bang and then silence" nature of cyber events makes sustained engagement challenging for journalists and communicators alike.
A significant shift observed over the decade was in attribution. Ten years ago, identifying the "villains" behind cyberattacks was notoriously difficult. The turning point remembered by White was the US government's attribution of the Sony Pictures Entertainment hack to North Korea under President Obama. This marked a new era where states increasingly named perpetrators, which significantly aided journalists in storytelling by providing the "victim, villain, and hero" components. However, the conversation also explored potential unintended consequences, questioning whether the drive for attribution could introduce risks or pressures. Chichester clarified that while not a "silver bullet," attribution serves multiple layers of value: it helps establish norms in cyberspace, gives a "face" to the threat, and makes it easier to persuade organizations to take defensive actions by linking them to specific, identified threat actors. The NCSC's attribution process is described as an "all source, all intelligence sort of process," not purely technical, and employs probabilistic language (e.g., "highly likely with high confidence") to reflect confidence levels.
Another historical challenge addressed was the perceived "alphabet soup" of UK entities dealing with cybercrime a decade ago (NCA, NCSC, MI5, MI6, City of London Police, Cabinet Office, Foreign Office). White questioned whether coordination had improved. Chichester affirmed that while these entities retain distinct statutory purposes, coordination is now "huge" and happens "daily." This organic, rather than strictly formal, approach ensures a coherent response, particularly during major incidents like ransomware attacks, where information is shared in real-time, and embedded staff facilitate seamless collaboration. This evolved coordination underpins a more unified national cyber defense posture.
Key Findings
▶ Watch: Communicating the real impact of cyber threats. (2:30)
The discussion yielded several critical findings regarding the current state and future direction of cyber security:
- Persistent Data Breach Threat: Despite reduced media attention, data breaches remain a regular and significant threat, with criminals and states continuously targeting bulk data. The challenge lies in effectively communicating the real-world impact to a broad audience.
- Multi-layered Value of Attribution: Attribution is a strategic tool used by the NCSC not merely to identify culprits but to establish international norms for cyberspace, provide concrete justification for defensive actions by organizations, and facilitate preemptive attribution—alerting victims to impending attacks before they materialize. This process is comprehensive, drawing on "all source" intelligence and conveying confidence levels through probabilistic language.
- Evolved Inter-agency Coordination: UK cyber defense agencies operate with a high degree of daily, organic coordination rather than relying solely on formal, periodic meetings. This ensures rapid information sharing and joint responses to incidents, as well as strategic collaboration on investigations and public awareness campaigns.
- Resilient International Operational Partnerships: Despite geopolitical fragmentation and political shifts, operational relationships with key international partners like the US (CISA, NSA, FBI) remain "hugely load-bearing." The shared understanding of transnational cyber threats drives this collaboration, often intensifying in areas of common concern.
- Data Sovereignty vs. Data Resilience: The NCSC advises against viewing data sovereignty (storing all data within national borders) as a panacea. Instead, the focus should be on data resilience, encompassing strategies like data federation, robust backups, and ensuring accessibility, given the transnational nature of most cyber threats.
- Ransomware as a Top National Threat: Ransomware is unequivocally identified as the biggest cyber threat to the UK. A key policy recommendation from the NCSC is increased transparency around ransomware incidents, potentially through a mandatory reporting register. This would provide a clearer national picture of the threat's scale and encourage boards and shareholders to drive better security postures.
- AI as a "Step Change": Artificial Intelligence is recognized as a significant catalyst and a "step change" in capability, impacting both offensive and defensive cyber operations. While it offers immense potential for automated defense, finding vulnerabilities, and accelerating responses (e.g., the Cyber Shield program), it also introduces risks related to model access and potential adversarial exploitation.
- Real-time Intelligence Sharing: The NCSC actively facilitates real-time intelligence sharing through programs like Share and Defend (with telecoms for DNS protection) and the Early Warning service, which automatically alerts organizations to threats targeting their registered IP addresses and domain names.
Technical Deep Dive
▶ Watch: Storytelling in cyber: Victims, Villains, Heroes analogy. (4:00)
The conversation delved into several technical and operational aspects of national cyber defense, illustrating the NCSC's strategic approach.
The NCSC's attribution methodology is presented as a sophisticated, multi-faceted process. It is not "purely technical" but rather an "all source, all intelligence sort of process" led by the NCSC on behalf of the UK government. This means combining technical indicators (malware analysis, infrastructure fingerprints) with human intelligence, signals intelligence, and open-source information. The outputs of this process are communicated using probabilistic language such as "highly likely to have conducted an operation... with high confidence." This nuanced approach acknowledges the inherent uncertainties in cyber attribution while providing governments with actionable intelligence for policy decisions and diplomatic responses. A critical function highlighted is preemptive attribution, where the NCSC uses intelligence to alert organizations to precursor malware or ongoing targeting before a full-blown attack occurs, effectively stopping a significant number of incidents.
Regarding inter-agency coordination, Chichester emphasized that its effectiveness stems from a deep, organic integration rather than just formal meetings. This involves "embedded staff" from different agencies within teams, constant sharing of "pretty much everything we see," and joint investigations and campaigns. For instance, when dealing with a major ransomware incident, the NCSC works hand-in-hand with the National Crime Agency (NCA) or regional law enforcement. This continuous, real-time collaboration ensures a unified response, leveraging the distinct statutory powers and expertise of each entity. Campaigns are a core tool for coordination, whether they are comms campaigns, threat-specific campaigns, or technology-focused initiatives, ensuring a single, coherent message to the UK.
The discussion on data sovereignty highlighted a crucial technical and strategic distinction. While some advocate for storing all data within national borders, the NCSC's advice focuses on data resilience. This means implementing architectures that ensure data is federated, regularly backed up, and accessible even in the face of attack or geopolitical disruption. The argument is that since most threats are transnational, simply relocating data geographically offers limited protection; robust technical controls and architectural resilience are paramount. Organizations are urged to understand where their data resides and to recognize that risk cannot be outsourced.
In terms of threat intelligence, the NCSC advocates for a layered approach: strategic, operational, and tactical.
- Strategic intelligence informs long-term risk management and policy decisions.
- Operational intelligence supports ongoing defensive operations and incident response.
- Tactical intelligence provides immediate, actionable indicators for frontline defenders.
The most effective organizations integrate all three layers, using strategic understanding to drive broader risk management and tactical insights for immediate protection.
The NCSC's approach to ransomware is multi-pronged. Operationally, it involves providing specific advice and guidance to organizations. Strategically, it supports legislation like the Cyber Security and Resilience Bill, aiming to drive greater resilience across the UK through regulation. A core technical and operational tenet is that "the easiest thing to do is avoid being ransomed." This involves adherence to baseline security standards like Cyber Essentials, which provides a foundational set of controls to protect against common cyber threats. The NCSC stresses that proactive protection is far more cost-effective and impactful than dealing with the aftermath of a successful attack, even if a ransom is paid.
The emergence of Artificial Intelligence is viewed as a transformative force. The NCSC, leveraging its connection to GCHQ and through the UK government's AISI (AI Safety Institute), is actively testing frontier models for their capabilities in finding vulnerabilities. The NCSC anticipates a future with "more automated attacks" and, consequently, the need for "more automated responses." This is being addressed through initiatives like the Cyber Shield program, which aims to exploit AI technologies to find vulnerabilities and defend the UK at "machine speed." The challenge lies in ensuring responsible disclosure and managing access to these powerful models, preventing them from falling into adversarial hands where they could be exploited for malicious purposes.
Finally, the NCSC's commitment to real-time intelligence sharing is concretized through programs such as Share and Defend and Early Warning. Share and Defend involves sharing significant amounts of threat data in real-time with UK telecommunications companies to enable national-level DNS protection. The Early Warning service allows organizations to subscribe by providing their IP addresses and domain names, receiving automated alerts if the NCSC observes threats targeting their registered assets. These services exemplify the NCSC's drive to move beyond periodic reports to continuous, machine-speed defense. An enterprise-level example of sophisticated defense highlighted was a model that mapped threats against countermeasures, assessing the return on investment (ROI) for each countermeasure every six months based on its unique effectiveness in blocking attacks. This level of data-driven optimization allows organizations to prioritize and refine their security spending.
Demo / Proof of Concept
▶ Watch: Attribution: breakthrough, drive, and unintended consequences. (4:50)
The nature of this session was a conversational plenary, focusing on strategic and operational insights rather than a technical demonstration. Therefore, no specific demo or proof of concept was presented or discussed during the talk.
Defensive Implications
▶ Watch: NCSC's perspective: reasons and value of attribution. (5:50)
The insights shared by Paul Chichester carry significant implications for cyber defenders across all sectors:
- Prioritize Communication and Transparency: Defenders must become better communicators of cyber risk and impact. This extends beyond technical teams to engaging boards, shareholders, and the wider public. Emphasizing the long-term, cumulative effects of incidents, rather than just immediate "bang" stories, is crucial for driving investment and behavioral change. The NCSC's call for transparency in ransomware payments, possibly through a reporting register, aims to provide a clearer picture of the national threat landscape and hold organizations accountable.
- Understand Geopolitical Context: Organizations, especially those with international operations, must develop a deeper understanding of the geopolitical context in which they operate. While not every defender needs to track every APT group, knowing the specific threat actors and their motivations relevant to their industry, geographic footprint, and data interests is vital for tailored risk management.
- Focus on Data Resilience over Pure Sovereignty: Instead of solely focusing on where data is geographically stored, defenders should prioritize data resilience. This involves robust strategies for data federation, comprehensive and tested backup solutions, and ensuring data accessibility under adverse conditions. Recognizing that risk cannot be outsourced and that transnational threats necessitate robust internal controls is key.
- Implement Layered Threat Intelligence: Adopt a multi-tiered approach to threat intelligence, integrating strategic, operational, and tactical insights. Strategic intelligence should inform long-term security roadmaps, operational intelligence should guide ongoing defensive activities, and tactical intelligence should provide immediate, actionable alerts to frontline teams. This holistic view enables both proactive defense and rapid response.
- Proactive Ransomware Defense is Paramount: The NCSC reiterates that avoiding ransomware infection in the first place is the most effective defense. This means rigorously implementing foundational security controls, such as those outlined in Cyber Essentials, maintaining robust patch management, strong authentication, and continuous security awareness training. Relying on ransom payment as an "easy way out" is a false narrative, as operational impact and recovery costs remain substantial regardless of payment.
- Embrace AI for Automated Defense: Defenders should actively explore and invest in AI-driven tools and capabilities to enhance their defensive posture. As adversaries increasingly leverage automation, security teams must develop automated responses at "machine speed" to detect vulnerabilities, analyze threats, and respond to incidents. This includes participating in initiatives like the UK's Cyber Shield program where applicable, and understanding how frontier AI models can be responsibly deployed to find vulnerabilities before adversaries.
- Leverage NCSC Services: Organizations should actively utilize NCSC's free services like the Early Warning service (registering IP addresses and domain names for automated threat alerts) and engage with sector-specific trust groups and information exchanges. These platforms provide targeted advice, facilitate peer-to-peer sharing, and ensure organizations receive relevant, up-to-date threat intelligence.
- Invest in Data-Driven Security Optimization: Implement sophisticated models to map threats against countermeasures and assess the return on investment (ROI) of security controls. Continuously evaluate the effectiveness of defensive measures to ensure resources are allocated optimally and to adapt strategies as the threat landscape evolves. This data-driven approach allows for mature, accountable security spending.
- Champion Diversity and Inclusion: Actively work to diversify the cyber security workforce. Recognizing the need for a mix of minds and diversity of thought in all dimensions (gender, ethnicity, background) is critical for innovative problem-solving. Companies should move beyond pledges to concrete action plans, measurable metrics, and support for initiatives like CyberFirst and women in cyber communities.
Key Takeaways
- Communication of Impact is Crucial: The long-term, cumulative impact of cyber incidents, particularly data breaches, is often underestimated. Effective communication to broader audiences and organizational boards is vital for driving necessary defensive actions and investment.
- Attribution as a Strategic Tool: Attribution, while complex and relying on multi-source intelligence, is more than just naming and shaming. It's a critical mechanism for establishing international norms, providing actionable threat intelligence, and enabling preemptive defense.
- Integrated National Defense: The UK's cyber defense relies on highly coordinated, organic collaboration between diverse agencies. This operational unity, rather than formal structures, ensures a robust and adaptive response to transnational threats, resilient even amidst geopolitical shifts.
- Ransomware Demands Transparency and Proactive Defense: Ransomware remains the UK's top cyber threat. Increased transparency through reporting mechanisms and a strong emphasis on implementing foundational security controls (like Cyber Essentials) are essential to mitigate its impact and shift organizational behavior.
- AI Reshapes Cyber Security: Artificial Intelligence is a transformative catalyst, offering immense potential for automated defense and vulnerability discovery. However, it also introduces challenges around model access and responsible deployment, necessitating rapid adaptation for both defenders and policymakers.
- Resilience Trumps Location: For data protection, focusing on comprehensive data resilience strategies (federation, backups, accessibility) is more effective than simply relying on data sovereignty, given the inherently transnational nature of cyber threats.
- Diversity Fuels Innovation: Cultivating a diverse cyber security workforce with varied backgrounds and perspectives is paramount for fostering innovation, adapting to evolving threats, and solving complex challenges effectively. Concrete action plans and measurable progress are key.
About the Speaker(s)
Paul Chichester CMG is the Director of Operations for the National Cyber Security Centre (NCSC). In this capacity, he is responsible for the national incident management arena, working closely with victims of cyberattacks, particularly ransomware, and dealing with their consequences. His role involves leading the NCSC's efforts in threat attribution, inter-agency coordination, and developing strategic responses to evolving cyber threats, including the integration of AI into national defense.
Geoff White is an acclaimed author and investigative journalist specializing in cybercrime. He was the co-host of the BBC's podcast series The Lazarus Heist, which delved into North Korea's emergence as a computer hacking power, and will be hosting its successor, Cyberhack, focusing on ransomware gangs. White is known for his deep dives into complex cyber narratives, often engaging directly with the subjects he covers, including ransomware groups, to provide unique insights into the cyber underworld.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent strategic/intel briefing lane session featuring Paul Chichester — a speaker who genuinely has the seat and the access — but one that largely stays in safe, well-trodden territory. The insider signal is real but measured: attribution methodology, inter-agency coordination mechanics, and ransomware policy posture are discussed with more candor than a press release, but rarely with the specificity that would make a seasoned practitioner lean forward. What's here is credible and professionally delivered; what's missing is the kind of 'I can't believe he just said that on stage' moment that separates a memorable plenary from a well-structured summary.
Heather Calloway (CISO) — SOLID
A credible, senior-level conversation between two people who clearly know the terrain — but it stays at altitude. Chichester brings genuine institutional weight and there are real signals here on attribution strategy, data resilience framing, and ransomware transparency. The problem is the format doesn't force precision. What could have been a pointed interrogation of national cyber governance becomes a retrospective with good instincts but no hard edges. Useful for understanding how NCSC thinks. Not a session that changes what you do Monday morning.