Global Cyber Policy
Chris Inglis (Former U.S. National Cyber Director, MITRE Trustee · MITRE), Anne Keast-Butler (Director, GCHQ · Government Communications Headquarters (GCHQ), UK)
RSA Conference 2025 · Day 1 · YBCA Stage · Keynote
Overview
GCHQ Director Anne Keast-Butler, in conversation with former U.S. National Cyber Director Chris Inglis, delivered a keynote fireside chat on the state of global cyber cooperation. She argued that no single actor — government, industry, academia, or citizen — can secure the digital ecosystem alone, and that the UK's model of embedding the National Cyber Security Centre within GCHQ as a convening institution offers lessons for the world. The conversation ranged from ransomware as the dominant operational threat, to AI as both accelerant and equalizer, to the hard economics of why security by design is cheaper than remediation. ---

Key moments
- 6:16 GCHQ names ransomware as the single biggest current cyber threat
- 9:29 Bletchley Park AI Safety Summit — UK's coalition-building model explained
- 19:17 NCSC 100 program — industry embedded in GCHQ for collaborative problem-solving
- 20:59 Resilience by design vs security by design — UK pushing global standard shift
- 31:22 60% of ransomware attacks preventable with multi-factor authentication alone
- 32:22 EU, UK, US on diverging cyber policy paths — harmonization or fragmentation?
- 41:52 Generative AI: offense is one year ahead of defense in adoption and capability
- 41:56 Quantum computing looms behind AI as next transformative threat horizon
Global Cyber Policy: A Transatlantic Conversation at the Highest Level
Talk ID: RSA25-015
Speakers: Chris Inglis (MITRE), Anne Keast-Butler (Government Communications Headquarters, GCHQ, UK)
Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Stage: YBCA Stage | Track: Keynote
YouTube: Watch on YouTube
Reading Time: ~7 minutes
TL;DR
GCHQ Director Anne Keast-Butler, in conversation with former U.S. National Cyber Director Chris Inglis, delivered a keynote fireside chat on the state of global cyber cooperation. She argued that no single actor — government, industry, academia, or citizen — can secure the digital ecosystem alone, and that the UK's model of embedding the National Cyber Security Centre within GCHQ as a convening institution offers lessons for the world. The conversation ranged from ransomware as the dominant operational threat, to AI as both accelerant and equalizer, to the hard economics of why security by design is cheaper than remediation.
Introduction
At RSA Conference 2025, the most senior serving intelligence official from the United Kingdom took the stage for the first time. Anne Keast-Butler, the seventeenth Director of GCHQ — the agency founded in 1919 responsible for signals intelligence, information assurance, and cryptography in support of keeping the UK safe — sat down with Chris Inglis, former U.S. National Cyber Director and now at MITRE, for a rare and substantive transatlantic exchange.
Keast-Butler noted it was her first RSA Conference. "Really great to get that sense of community of people all working together to keep our citizens safe," she said. The conversation that followed covered threat landscape realities, models for public-private collaboration, the economics of cyber investment, and the challenge of aligning international frameworks — all from the perspective of a serving national intelligence director.
Section 1: The State of Play — A Mixed Picture
Keast-Butler opened by acknowledging genuine progress alongside persistent gaps. Awareness of cyber vulnerabilities has grown, digital skills are improving, and government-industry collaboration is deepening. But the pace of threat evolution is outrunning defense.
"The adversaries are as innovative and not bound by some of the constraints as those of us who are defending," she said. The UK's National Cyber Security Centre annual report tracks specifically the gap between defensive capability and the vulnerabilities of an increasingly interconnected world.
▶ Watch: GCHQ Director describes the mixed picture of global cyber defense (04:00)
The critical national infrastructure concept, she noted, has evolved. What once meant power stations and food supply chains now centrally includes data centers and the broader digital ecosystem. "That is at the heart of what we try to defend."
Inglis asked a blunt performance question: when do you know you've succeeded? Keast-Butler's answer was equally direct: "I don't think you ever succeed. This is a constant work in progress." The goal is not victory but closing the gap — keeping pace with a changing threat environment.
Section 2: Ransomware as the Defining Operational Threat
When the conversation turned to the most immediate threat, Keast-Butler was unambiguous: ransomware is the biggest cyber threat right now.
"It can be small, cheap to execute, accelerated by some of the latest technologies around AI, and have really significant impacts," she said. The UK, like the United States, has seen repeated ransomware attacks on its health sector.
▶ Watch: Keast-Butler names ransomware as the #1 cyber threat (06:00)
Crucially, she framed ransomware defense as foundational security, not a specialized capability. "If you can defend against that, you're also starting to hardwire in some of the basic fundamentals that prevent you from being vulnerable to more sophisticated state threats." The defensive hygiene required to resist a ransomware affiliate is much of the same hygiene required to resist a sophisticated nation-state actor.
The UK's Cyber Essentials program illustrates the point: organizations that take up even this basic certification are significantly less likely to suffer a ransomware attack — yet only a fraction of eligible firms have adopted it. "How do we reach everyone else?" she asked. That question animated much of the rest of the conversation.
Section 3: The Collaboration Model — Who Is Committed, Not Just Involved
Inglis deployed an old American joke — the chicken-and-egg breakfast, where the chicken is involved but the pig is committed — to frame the central question of shared responsibility. Who actually has to be committed to securing digital infrastructure?
Keast-Butler's answer: everyone, and that's the hard part. Government has a role in convening, standard-setting, and regulation. Industry holds the cutting-edge insights into how the internet is actually being used, where malware appears, and what vulnerabilities are being exploited. Academia drives foundational research. Citizens must demand security and be willing to accept the friction it sometimes creates.
▶ Watch: "No one creature can do this on their own" — on shared responsibility (06:00)
The NCSC model — embedded within GCHQ, with full access to signals intelligence but an outward-facing mandate to communicate with industry and citizens — is Keast-Butler's answer to building this coalition. The NCSC's "100" program brings industry professionals into the building to work alongside government staff, not in theory but on real problems of mutual interest.
"Human relationships are really key," she said. "Creating spaces where people can come together really matters." The UK's geographic advantage — a smaller country where travel between stakeholders is less burdensome — helps, but the principle transfers. The requirement is a shared sense of mission and practical spaces for collaboration.
Section 4: International Divergence and the Harmonization Challenge
▶ Watch: EU, UK, and US on diverging cyber policy paths (32:03)
The conversation took a more strategically complex turn when Inglis asked about apparent divergence between the EU's regulation-first approach, the UK's coalition-and-resilience model, and the United States' current reassessment of the relationship between cyber offense and defense. For companies operating across all three jurisdictions, inconsistency creates real friction.
Keast-Butler pushed back gently on the demand for perfect harmonization. "If we spend all of our time trying to align different nations and governments who've been elected by different populations to do the same thing, we're probably wasting precious time to actually do something."
Her preferred model: co-created minimum performance standards and guardrails that allow each jurisdiction to set its own ambition and legislative framework, while providing companies the baseline consistency they need. "Performance-based, not scripted" — a minimum service level built into products, with national governments choosing the mechanism to achieve it.
The Five Eyes alliance is the natural first resort for trust and shared standards, but as she noted, limiting cooperation to Five Eyes leaves enormous portions of the global population without access to that guidance or without a sense that it is relevant to them. The UK actively co-signs advisories with as many nations as possible for exactly this reason.
Section 5: AI, Economics, and Security by Design
▶ Watch: Offense is a year ahead of defense in AI adoption (42:03)
The NCSC published an assessment roughly a year after generative AI's emergence comparing how attackers and defenders were using the technology. The finding: offense is approximately one year ahead. The reason, Keast-Butler acknowledged, is structural — adversaries are not bound by the same caution requirements, are experimenting freely, and are setting the pace.
Her optimism for the defensive catch-up rests on AI's strengths in coding, anomaly detection, and automated patch deployment. "AI is really good at coding. It should help us get rid of some of those bugs right from the outset, so they're not even there." She anticipated parity in speed, if not immediate capability parity.
The economics of security by design received sharp attention. A UK ransomware victim lost eight times its annual profit to the attack — but that loss doesn't appear neatly in a balance sheet, making it easy to ignore in advance. Roughly 60 percent of ransomware attacks on small businesses could have been prevented by multi-factor authentication. "It is always much cheaper to build it in than it is to retro-fix it or pick up the cost of it going wrong."
▶ Watch: The economics of security — why 60% of attacks are preventable (30:02)
Inglis framed this as a "third leg of the stool" — alongside innovation and market efficiency, resilience and safety need to be designed in from the start, not retrofitted after a crisis.
Notable Quotes
"The biggest cyber threat actually comes from ransomware — it can be small, cheap to execute, accelerated by AI, and have really significant impacts." — Anne Keast-Butler
"No one creature can do this on their own. The challenge is to make sure everyone is committed and everyone is involved." — Anne Keast-Butler
"The days when government felt it had the secrets and might sort of drip them out to other people — those days are long gone." — Anne Keast-Butler
"We're actually experiencing a cyber 9/11 right now. It's just diffused in time and space." — Chris Inglis
"It is always much cheaper to build security in than to retro-fix it or pick up the cost of it going wrong." — Anne Keast-Butler
Key Takeaways
- Ransomware is the current primary threat — not because nation-state threats are diminished, but because ransomware defense and nation-state defense use much of the same foundational hygiene.
- The NCSC model — government as convener, not gatekeeper — embeds classified intelligence capacity within an outward-facing collaboration institution; it is the UK's most exportable cybersecurity policy innovation.
- No single jurisdiction can secure the digital ecosystem alone — international cooperation must expand beyond Five Eyes, and harmonization should aim for minimum performance standards rather than regulatory uniformity.
- AI offense leads AI defense by approximately one year — but AI capabilities in coding and anomaly detection give defenders structural advantages that should close the gap.
- Security by design is an economic imperative — the cost of building security in at the start is a fraction of the cost of remediation or the business losses that follow a successful attack; 60 percent of ransomware incidents are preventable with basic controls.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
The most consequential policy session at RSA 2025. The sitting Director of GCHQ, in her first RSA appearance, delivering substantive doctrine on UK-US collaboration, ransomware, AI defensive gaps, and international regulatory divergence. Inglis is the ideal interlocutor — not a fan, a peer. If you care about how serious governments think about cybersecurity, this is unmissable.
Heather Calloway (CISO) — MUST SEE
GCHQ Director Anne Keast-Butler and former National Cyber Director Chris Inglis argue that the transatlantic alliance has entered a new phase — one where Western democracies must make affirmative choices about whether to coordinate on cyber norms or accept a fractured international order where adversaries define the rules. The governance stakes are explicit and the speakers have the institutional standing to name them.