Resilience Plenary - Secure By Law: How Regulation Shapes The Nation's Cyber Future
Jonathon Ellison OBE (Director of National Resilience · National Cyber Security Centre (NCSC))
CYBERUK 2026 · Day 2 · Main Plenary
Overview
This plenary session delves into the intricate and increasingly vital role of regulation in shaping national cyber resilience in an era of rapidly evolving technology and interconnected global supply chains. Moderated by Jonathon Ellison OBE from the NCSC, a distinguished panel of cybersecurity leaders from the UK, Germany, and Australia explored the delicate balance between fostering security and managing economic impact, the challenges of foreign ownership in critical infrastructure, and the imperative for regulatory agility in the face of emergent threats like artificial intelligence. The discussion underscores that cybersecurity is no longer merely an IT problem but a fundamental component of national resilience, economic stability, and public trust.

Key moments
- 0:00 Introduction: Regulation's role in national cyber resilience
- 2:00 Panel introduction: Experts from UK, Australia, Germany
- 3:50 UK's economic cost of cyber attacks: £14.7 billion annually
- 4:50 CSRB: Balancing security standards with business burden
- 6:20 German perspective: Regulation as a last resort
- 7:40 Cyber threats' macroeconomic scale necessitates regulation
Resilience Plenary - Secure By Law: How Regulation Shapes The Nation's Cyber Future
Speakers: Jonathon Ellison OBE (Director of National Resilience, National Cyber Security Centre (NCSC)), Rita Erfitt (Assistant Director General of Global Powers and Counter Cyber Crime, Australian Cyber Security Centre (ACSC)), Claudia Plattner (President of Germany's Federal Office of Information Security (BSI)), Rod Letham (Director of Cyber Security and Digital Identity, Department for Science, Innovation, and Technology (DSIT)), Natalie Black (Group Director for Networks and Communications, Ofcom)
Conference: CYBERUK
YouTube: https://www.youtube.com/watch?v=hj9Dg8m886Q
Overview
This plenary session delves into the intricate and increasingly vital role of regulation in shaping national cyber resilience in an era of rapidly evolving technology and interconnected global supply chains. Moderated by Jonathon Ellison OBE from the NCSC, a distinguished panel of cybersecurity leaders from the UK, Germany, and Australia explored the delicate balance between fostering security and managing economic impact, the challenges of foreign ownership in critical infrastructure, and the imperative for regulatory agility in the face of emergent threats like artificial intelligence. The discussion underscores that cybersecurity is no longer merely an IT problem but a fundamental component of national resilience, economic stability, and public trust.
The talk highlights a critical shift in perspective: cyber regulation is not just about setting minimum standards but acts as a powerful lever to define a nation's cyber future. With a recent report indicating that over one-third of leaders in the UK’s 13 Critical National Infrastructure (CNI) sectors cite regulatory requirements as the primary influence on their security programs, the impact is tangible. The panel scrutinizes whether current and proposed regulations, such as the UK's Cyber Security and Resilience Bill (CSRB), the EU's NIS2 directive, and Australia's Security of Critical Infrastructure Act (SOCI), go far enough—or perhaps too far—in addressing complex issues like supply chain concentration risk and the rapid pace of technological change.
The core message resonating throughout the discussion is that cyber resilience is inextricably linked to national security. The decisions made today regarding regulatory frameworks will profoundly influence national competitiveness and resilience for the coming decade. The speakers collectively emphasize the urgency and necessity of government intervention where market forces alone prove insufficient to protect society from the macroeconomic consequences of widespread cyber incidents, which in the UK alone are estimated to cost £14.7 billion annually, or about half a percent of GDP.
Background
▶ Watch: Introduction: Regulation's role in national cyber resilience (0:00)
The landscape of cyber threats has transformed dramatically in recent years, necessitating a re-evaluation of national strategies for resilience. Historically, cyber incidents might have been viewed as individual company misfortunes; however, as Claudia Plattner of Germany's BSI articulated, they have escalated "out of this microeconomic scale into a macroeconomic scale." This realization forms the bedrock of modern regulatory efforts, acknowledging that market mechanisms alone cannot adequately safeguard national security, economic stability, or public confidence.
Several key legislative and policy initiatives underpin this global push for enhanced cyber resilience. In the United Kingdom, the existing NIS (Network and Information Systems) Regulations, introduced eight years prior, are being modernized through the forthcoming Cyber Security and Resilience Bill (CSRB). Rod Letham from DSIT explained that this bill aims to expand regulatory scope to new sectors, such as data centers designated a couple of years ago, and strengthen government powers to address contemporary threats. This update is crucial given the rapid advancements in cyber capabilities and the increasing sophistication of attacks.
Across the European Union, the NIS2 directive represents a significant step forward, aiming to raise the baseline level of cybersecurity across member states. It achieves this by expanding the sectors under its purview, strengthening incident reporting requirements, and elevating expectations around risk management. Complementing NIS2 is the proposed Cyber Resilience Act, which targets producers of digital products, mandating a lifecycle approach to security, including patch management and the provision of Software Bill of Materials (SBOMs). This proactive approach seeks to embed security from the design phase, shifting responsibility to manufacturers for the inherent security of their products.
Australia, having enacted its Security of Critical Infrastructure Act (SOCI) in 2018 and amended it in 2022, offers a glimpse into more mature regulatory frameworks. Rita Erfitt of the ACSC noted that SOCI mandates standards and legal obligations for owners and operators of critical infrastructure across sectors like energy, transport, and health. A key feature is mandatory reporting requirements, which provide invaluable visibility into the cyber threat environment, enabling better information sharing and mitigation strategies. The Australian experience underscores the ongoing evolution of these frameworks in response to persistent targeting of critical infrastructure by malicious cyber actors, much of which is privately owned.
These international approaches collectively highlight several underlying problems: the inherent vulnerability introduced by global supply chains, the risks associated with foreign ownership in essential services, the dangerous concentration of risk in a small number of key providers, and the pervasive challenge of regulators adapting at the speed of technological change. The collective consensus is that while regulation should be a last resort, it has become an indispensable tool to address these systemic vulnerabilities and ensure a resilient digital future.
Key Findings
▶ Watch: UK's economic cost of cyber attacks: £14.7 billion annually (3:50)
The panel discussion illuminated several critical findings and shared perspectives on the evolving landscape of cyber regulation:
- Regulation as a Necessary Last Resort: A universal consensus emerged that regulation, while a "hard lever" and a last resort, is absolutely necessary. Speakers, particularly Claudia Plattner, emphasized that cyber incidents have transcended individual business problems to become macroeconomic threats, necessitating government intervention where market forces fail to adequately protect national security and economic stability. Rod Letham cited the UK's £14.7 billion annual economic cost from cyberattacks as a clear indicator of this macroeconomic imperative.
- Expanding Scope and Lifecycle Security: Modern regulatory frameworks are characterized by an expanded scope and a focus on the entire digital product lifecycle. The UK's CSRB is bringing new sectors like data centers into scope, while the EU's NIS2 broadens covered entities and strengthens risk management. Critically, the EU Cyber Resilience Act introduces obligations for producers of digital products to ensure life cycle security, including patch management and Software Bill of Materials (SBOMs), mirroring expectations for physical product safety.
- The Challenge of Foreign Ownership and Digital Sovereignty: Managing risks associated with foreign ownership and high-risk vendors (HRVs) in critical infrastructure is a pressing concern. Natalie Black of Ofcom described the UK's experience with Huawei under the Telecoms Security Act as a difficult but necessary process, highlighting the significant financial and opportunity costs involved. The discussion also underscored the broader ambition for digital sovereignty—not necessarily cutting ties, but regaining control and strengthening domestic digital industries (what Claudia Plattner termed "digital GDP") through substantial investment, particularly in emerging areas like AI.
- Agility and Outcomes-Based Regulation are Paramount: To remain effective in a world of rapid technological change, regulatory approaches must be agile, outcomes-focused, and technology-neutral. Natalie Black explained Ofcom's approach of focusing on outcomes rather than prescribing specific technologies, allowing for flexibility, especially in areas like AI. Rod Letham highlighted the CSRB's incorporation of secondary powers to adapt to unforeseen developments and bring new sectors into scope, ensuring the legislation remains relevant over time.
- AI: A Force Multiplier for Both Attackers and Defenders: Artificial Intelligence presents both immense opportunities for enhancing national cyber resilience and significant new risks. Rita Erfitt outlined AI's defensive benefits in rapid detection and response, behavioral analytics, pattern identification, and vulnerability identification in software development, acting as a "force multiplier" for human analysts. However, Claudia Plattner warned that attackers are already adept at using AI, making it crucial for defenders to be equally fast and effective. The need for secure AI systems ("cyber for AI") and reliable, trusted AI providers ("whose AI should we be relying on?") was also emphasized.
- Robust Incident Response and Recovery Expectations: Even with strong regulation, incidents will occur. Regulation plays a vital role in ensuring organizations can recover effectively. Natalie Black stressed the importance of clear board-level communication and engaging consumers during incidents, citing Ofcom's £17.5 million fine to BT for a 999 outage as an example of enforcement for communication failures. Rita Erfitt described Australia's SOCI Act's "direction power" as an extreme last resort for national-level incidents, with its non-use being a measure of its success.
Technical Deep Dive
▶ Watch: CSRB: Balancing security standards with business burden (4:50)
The technical underpinnings of the discussed regulatory frameworks showcase a concerted effort to move beyond basic compliance towards comprehensive, adaptable, and lifecycle-oriented cybersecurity.
The UK Cyber Security and Resilience Bill (CSRB), currently live in Parliament, is designed to modernize the protection of systems and services critical to the country. A key technical aspect of the CSRB, as highlighted by Rod Letham of DSIT, is its inherent flexibility. Recognizing that the pace of technological change outstrips traditional legislative cycles, the bill incorporates secondary powers. These powers allow for the rapid amendment of what is being asked of critical infrastructure operators and the bringing of additional sectors into scope without requiring entirely new primary legislation. This adaptability is crucial for addressing unforeseen developments, such as the precise capabilities of future frontier AI models. The bill aims to avoid the need for a "CSRB2" by being inherently future-proofed against technological shifts.
In the European Union, two directives form a robust regulatory pair. The NIS2 directive significantly expands the scope of entities considered critical or essential, thereby bringing more organizations under stricter cybersecurity requirements. Technically, this means a broader application of robust risk management measures, including incident response, supply chain security, and network and information system security. It also strengthens reporting requirements for cyber incidents, aiming to provide a more comprehensive picture of the threat landscape across the EU. Complementing this is the groundbreaking Cyber Resilience Act (CRA). This act introduces a novel concept: holding producers of digital products accountable for the security of their offerings throughout their entire lifecycle. Technical requirements include mandatory life cycle patch management to address vulnerabilities post-release and the provision of a Software Bill of Materials (SBOM). An SBOM is a formal, machine-readable list of ingredients that make up software components, crucial for identifying and managing supply chain vulnerabilities. As Claudia Plattner of Germany's BSI explained, this mirrors expectations for physical products, where manufacturers are responsible for safety flaws.
Australia's Security of Critical Infrastructure Act (SOCI), amended in 2022, provides a mature example of critical infrastructure protection. Rita Erfitt of the ACSC detailed its technical mechanisms:
- Mandated Standards and Legal Obligations: Imposes specific cybersecurity standards and legal duties on owners and operators across sectors like energy, transport, and health.
- Mandatory Reporting Requirements: Critical for gaining visibility into the cyber threat environment. The more reporting, the better the understanding of threats, enabling more effective information sharing and mitigation strategies.
- Limited Use Obligations: Designed to encourage better communication between victim entities and government by providing assurances regarding how reported information will be used.
- Direction Power: A highly significant, albeit rarely used, power. In extreme circumstances of a national-level cybersecurity incident, the government can provide guidance, direct specific actions, or even intervene to secure or restore critical services. This power is a last resort, with its success often measured by its non-utilization, demonstrating preparedness for worst-case scenarios.
The discussion also delved into high-risk vendors (HRVs) and foreign ownership. Natalie Black of Ofcom explained the UK's approach under the Telecoms Security Act. This act grants the Secretary of State the power to designate HRVs (e.g., Huawei). Ofcom's role is to monitor progress against specific actions, such as the mandated removal of Huawei equipment from UK 5G networks by the end of 2027. This technical process involves complex network migrations and significant financial and opportunity costs, forcing operators to re-architect their infrastructure to reduce dependency.
Finally, the panel explored the technical implications of AI. From a defensive standpoint, AI's ability to process vast quantities of data at speed and scale enables advanced behavioral analytics and pattern identification for detection and response. It can also assist in vulnerability identification during software development, detecting flaws in source code before deployment. However, AI itself introduces new technical vulnerabilities and supply chain dependencies. The concept of "cyber for AI" focuses on securing AI systems against adversarial attacks or misuse, while "AI for cyber" involves leveraging AI to automate and enhance defensive capabilities at scale. The challenge, as Claudia Plattner noted, lies in ensuring defenders can implement and control AI tools faster and more effectively than attackers, particularly with sensitive data.
Demo / Proof of Concept
▶ Watch: German perspective: Regulation as a last resort (6:20)
The plenary session was a panel discussion focused on policy, regulation, and strategic approaches to national cyber resilience. As such, it did not include any live demonstrations or technical proofs of concept of tools, exploits, or defensive mechanisms. The discussion was primarily conceptual and strategic, exploring the frameworks and principles guiding regulatory efforts rather than showcasing specific technical implementations.
Defensive Implications
▶ Watch: Cyber threats' macroeconomic scale necessitates regulation (7:40)
The insights from the panel offer several critical implications for cybersecurity defenders at both the organizational and national levels:
- Prioritize Foundational Cyber Hygiene: Despite the rapid evolution of threats and technologies like AI, the bedrock of effective defense remains strong cyber hygiene. Rita Erfitt emphasized that any new application or network change, including AI tools, can introduce vulnerabilities if not built upon a solid foundation. Defenders must continue to focus on secure by design and secure by default principles, ensuring that new technologies are integrated into a robust security posture.
- Embrace Outcomes-Based Security: Regulators are increasingly focusing on outcomes rather than prescriptive technical controls. Defenders should align their security programs with these outcomes, demonstrating measurable improvements in resilience rather than merely achieving compliance checkboxes. This requires a deeper understanding of organizational risk and the ability to articulate security posture in terms of tangible impact.
- Proactive Preparedness for Incidents: The consensus is that cyber incidents are a matter of "when," not "if." Defenders must shift from reactive incident response to proactive preparedness, layering in capabilities that anticipate and mitigate the impact of successful attacks. This includes robust backup and recovery strategies, clear communication plans, and regular testing of incident response playbooks.
- Enhance Supply Chain Visibility and Security: The global nature of supply chains and the increasing reliance on third-party components, particularly in AI tools, necessitate greater vigilance. Defenders must demand Software Bill of Materials (SBOMs) from vendors (as mandated by the EU Cyber Resilience Act) to understand their software dependencies. Comprehensive risk assessments of all third-party suppliers, especially those providing critical technology or operating in CNI, are essential.
- Invest in Digital Sovereignty and Diversification: Organizations, particularly those in critical sectors, should assess their reliance on single foreign technology providers. While complete isolation is unrealistic, strategic investment in diverse technologies and, where feasible, supporting domestic capabilities can reduce concentration risk and enhance control. This aligns with the broader national push for "digital GDP."
- Strategically Leverage AI for Defense: AI offers significant advantages for defenders, acting as a force multiplier for detecting sophisticated threats, identifying vulnerabilities, and automating responses. Defenders should actively explore and implement AI-powered solutions for detection and response, behavioral analytics, and vulnerability management. However, this must be done with caution, understanding the risks inherent in AI systems ("cyber for AI") and carefully vetting trusted AI providers, especially when handling sensitive data.
- Elevate Cybersecurity to the Boardroom: Effective incident response and recovery are heavily dependent on board-level engagement and understanding. Defenders need to effectively communicate cyber risks and incident impacts to senior leadership, ensuring that cybersecurity is treated as a strategic business risk, not just a technical problem. Clear internal and external communication plans for incidents, particularly with consumers and affected parties, are paramount to maintaining public trust and mitigating regulatory penalties.
- Engage with Regulatory Bodies: Regulators like Ofcom (UK), BSI (Germany), and ACSC (Australia) are striving for transparency and seeking feedback. Defenders should actively engage with these bodies to understand evolving expectations, provide practical insights from the front lines, and collaboratively shape effective frameworks.
Key Takeaways
- Regulation is a critical, albeit last resort, tool for national cyber resilience, directly addressing market failures and the macroeconomic risks posed by cyber incidents, which can cost economies billions annually (e.g., £14.7 billion in the UK).
- Modern cyber regulation is expanding its scope to cover more critical sectors (e.g., data centers in the UK), strengthening incident reporting requirements, and crucially, enforcing lifecycle security for digital products through measures like patch management and Software Bill of Materials (SBOMs).
- Managing foreign technology dependencies and fostering digital sovereignty are paramount, requiring strategic investment in domestic digital industries ("digital GDP") and a focus on regaining control over critical technological ecosystems.
- Agile, outcomes-focused, and technology-neutral regulatory frameworks are essential to keep pace with rapid technological change, particularly the emergence of AI, utilizing secondary legislative powers for flexibility.
- Artificial intelligence presents significant opportunities for defenders (e.g., enhanced detection and response, vulnerability identification) but must be adopted with a clear understanding of its inherent risks, supply chain implications, and the need for secure AI systems ("cyber for AI").
- Effective incident response and recovery hinge on strong board-level engagement, proactive preparedness, and transparent communication with affected parties, with regulators prepared to enforce accountability for failures in these areas.
About the Speaker(s)
- Jonathon Ellison OBE is the Director of National Resilience at the National Cyber Security Centre (NCSC), the UK's authority on cyber security. He moderated the panel, guiding the discussion on national cyber resilience.
- Rita Erfitt serves as the Assistant Director General of Global Powers and Counter Cyber Crime at the Australian Cyber Security Centre (ACSC). She provided insights into Australia's experiences with the Security of Critical Infrastructure Act (SOCI).
- Claudia Plattner is the President of Germany's Federal Office of Information Security (BSI), the country's national cyber security authority. She shared perspectives on EU regulations like NIS2 and the Cyber Resilience Act.
- Rod Letham is the Director of Cyber Security and Digital Identity at the Department for Science, Innovation, and Technology (DSIT), the UK government department with lead policy responsibility for the incoming Cyber Security and Resilience Bill.
- Natalie Black is the Group Director for Networks and Communications at Ofcom, the UK's communications regulator, where she leads the regulation of the UK's telecoms and network infrastructure. She offered a regulator's perspective on managing risks and ensuring compliance.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent policy plenary from credible speakers with genuine institutional authority — the people here actually hold the levers they're describing. The session delivers a reasonable survey of active regulatory activity across the UK, EU, and Australia, names real legislation (CSRB, NIS2, CRA, SOCI), and occasionally surfaces useful signal: the £14.7B UK cost figure, the 2027 Huawei removal deadline, SOCI's direction power, and the CRA's SBOM mandate. The moderator kept things reasonably focused. But the conversation never escapes the altitude of a well-produced government press release. There's no candid tension, no honest account of what isn't working, no admission that any of these…
Heather Calloway (CISO) — STRONG ACCEPT
A substantive policy plenary with genuine institutional weight behind it — five senior government officials from three allied nations comparing regulatory doctrine on critical infrastructure protection. The panel earns its place on a conference program. It surfaces real governance architecture: the UK's CSRB secondary powers mechanism, Australia's SOCI direction power and its deliberate non-use, the EU's Cyber Resilience Act imposing lifecycle accountability on digital product manufacturers. These are consequential regulatory instruments, and the speakers know them from the inside. The limitation is a familiar one for government panels: the conversation stays comfortably at the framework…