Tag Archives: DSIT

Resilience by Design: How UK Think Tanks and Standards Bodies Shape Security-by-Default

Secure by default isn’t just a buzzword; it’s becoming the blueprint for how Britain builds its digital infrastructure. In a world of escalating cyber risk, the UK is shifting from reactive defences to resilience by design, embedding security principles from the earliest stages of product development, system architecture, and national infrastructure planning. This shift isn’t being driven by legislation alone. It’s being shaped by a constellation of think tanks, technical standards bodies, and influential advisors who guide how resilience is defined, measured, and built into UK systems from day one. This article unpacks who’s influencing the secure-by-default movement in Britain, and how vendors, policymakers, and professionals can engage.

Continue reading

The Grant Delusion: Why Government Should Commission, Not Compete, in UK Innovation

David Richards MBE is right, the UK’s innovation economy has become addicted to grants, not growth. But the problem isn’t funding itself; it’s design. Innovate UK and its peers were meant to bridge the early-stage gap between research and market, but instead became destinations in their own right. Government now competes with, rather than commissions, the innovators it should empower. The fix is simple: commission outcomes, not applications; fund practitioners, not paperwork.

Continue reading

Winning Influence Without a Badge: Non-Traditional Routes Into UK Cyber Leadership

You don’t need a government role or a corporate title to shape the future of cybersecurity in the UK. In the UK cyber ecosystem, influence isn’t just about where you work, it’s about what you contribute, who you connect, and how you show up. While traditional routes like senior roles in government, Big Four consultancies, or defence primes still hold sway, an increasing number of leaders, convenors, and policy-shapers are rising through non-traditional paths. This article explores how founders, freelancers, academics, and community builders are gaining real influence without formal badges, and how you can do the same.

Continue reading

Cyber, Growth, and Regional Futures: A Comparative Synthesis of Six 2025 Reports: From Fragmentation to Framework

2025 has been a year of noise, policy papers, strategies, and growth plans, each declaring the next leap for UK cyber and regional innovation. But noise isn’t movement. Across six flagship reports, DSIT’s Cyber Growth Action Plan, WMCA’s Futures and Growth Plans, the Tech Nation 2025 report, the Midlands Engine Cyber & Defence report, and DSIT’s Cyber Skills 2025, the pattern repeats: good intent, weak execution, no continuity. Together, they map £77 billion in Gross Value Added (GVA), 143,000 cyber professionals, and £17 billion in projected uplift, but no coherent operating model. This paper builds one: treating cyber as economic infrastructure and the West Midlands as the proof-of-concept for a practitioner-led, resilient growth framework.

Continue reading

Cyber Security Skills in the UK Labour Market 2025: A Critical Analysis

This article critically examines the Cyber Security Skills in the UK Labour Market 2025 report, highlighting strengths, weaknesses, and regional implications. It synthesises the findings into a practitioner-academic analysis, with recommendations for aligning graduate supply, employer demand, and future skills in areas such as AI and cyber resilience.

Continue reading

Unlocking the UK’s Growth Potential: A Critical and Constructive Review of the Tech Nation Report 2025

The Tech Nation Report 2025 reaffirms the UK’s position as Europe’s leading tech hub, valued at $1.2 trillion and home to 163 unicorns. Yet it also exposes structural barriers, capital bottlenecks, talent shortages, regional imbalances, and over-reliance on London and AI. This article critically reviews the report, adds practitioner-led insights, and proposes a roadmap for sustainable and regionally inclusive growth.

Continue reading

Breaking Into the Defence & Critical Infrastructure Cyber Supply Chain

Security clearances. Procurement portals. Legacy gatekeepers. Here’s how cyber vendors and professionals gain access to the UK’s most protected sectors. Selling into the UK’s defence, energy, transport, and national infrastructure sectors is not like selling into commercial enterprises. The barriers to entry are higher, the procurement cycles are longer, but the opportunities are vast and durable. Whether you’re a startup with a novel capability or a professional looking to work in high-trust environments, this guide explains how to navigate the real routes into defence and critical national infrastructure (CNI) supply chains.

Continue reading

From Policy to Place: Aligning the UK Cyber Policy with the West Midlands Futures Growth Plan

The UK Cyber Policy 2025 and the West Midlands Futures Green Paper 2025 set bold agendas but risk gaps without practitioner-led delivery. The national policy offers ambition but lacks continuity, metrics, and practitioner voice. The regional plan lays strong scaffolding but underweights cyber, leaning too heavily on AI. A ten-point roadmap shows the way forward: formally recognise cyber as a standalone cluster, unify governance, foster community, attract investment, establish a hub, launch a festival, rebuild narrative, reform SME funding access, enhance talent strategy, and create a regional benchmarking index. Anchored in the West Midlands Cyber Hub, this approach can balance national ambition with regional delivery, making resilience a driver of inclusive growth.

Continue reading

UK Cyber at a Crossroads: Three Essays on Policy, Practice, and Growth, in Reaction to the 2025 Cyber Growth Action Plan

The UK’s cyber policy has made progress but suffers from churn, overlap, and regional imbalance. The 2025 Cyber Policy sets out ambition but lacks continuity and practitioner voice. This three-part series traces the history, critiques the new policy, and argues for a practitioner-led, regionally balanced ecosystem to stabilise the base finally.

Continue reading

Reviewing the 2025 UK Cyber Growth Action Plan: Promise, Blind Spots, and the Challenge of Continuity

This article, written in reaction to the DSIT Cyber Growth Action Plan 2025, reviews and critiques the government’s new approach. It recognises what the policy gets right — framing resilience as growth, creating safe havens, and calling for a one-team response — but also highlights what is missing: metrics, continuity, practitioner voice, and regional balance. Without these, the new policy risks becoming rhetoric rather than a platform for real progress. Unless the UK moves decisively from aspiration to delivery, the 2025 Cyber Growth Action Plan will join its predecessors as another missed opportunity.

Continue reading

A Potted History of the UK’s Cyber Economy: From Secrecy to Sector

This article, written in reaction to the DSIT Cyber Growth Action Plan 2025, traces the uneven history of the UK’s cyber economy. From CESG’s secretive assurance role to NCSC’s public authority and DSIT’s contested remit, the story is one of incremental gains but persistent churn. Programmes such as Cyber Essentials, CyberFirst, CyberASAP, Cyber Runway, and Cyber Resilience Centres have delivered value but lacked continuity, scale, and coherence. Unless the government commits to stabilisation and long-term delivery, the UK will continue to recycle initiatives rather than build a durable cyber base.

Continue reading

How to Join a Government Working Group (Without Being a Civil Servant)

Yes, you can shape UK cyber policy, even from the outside. Here’s how people get in. Government working groups in the UK might seem closed-off, formal rooms filled with civil servants, consultants, and institutional insiders. But increasingly, government departments are seeking outside voices: founders, engineers, researchers, and community leaders who bring real-world experience. Whether you’re trying to influence cyber skills policy, secure-by-design standards, or public-sector procurement, joining the right working group can amplify your voice and build visibility for your organisation or sector. This article breaks down how non-civil servants are contributing to cyber and tech policy via working groups, what types exist, and how you can get involved.

Continue reading

From Startups to Scaleups: The UK’s Cyber Commercialisation Ladder, Explained

How Britain takes a cyber idea from academic paper to procurement-ready product, and who’s involved at each step. The UK has quietly built one of the world’s most interconnected cyber innovation ecosystems, a ladder of support that helps researchers, entrepreneurs, and early-stage companies turn ideas into commercial products, funding rounds, and contracts. But it’s not always obvious how it works, who owns which stage, or what the unwritten rules are. This article breaks down the UK’s cyber commercialisation journey, from research spinouts to public sector procurement, and highlights the critical programmes, accelerators, and gatekeepers at each level.

Continue reading

CyberFirst Celebration in the West Midlands: Reflections on What Makes Cyber Special

A reflection on the CyberFirst Celebration in the West Midlands, marking its transition to TechFirst. The event highlighted achievements, explored what makes cyber unique, and underlined the importance of maintaining the sector’s distinctive strengths, especially its uniquely inquisitive culture, as the programme broadens.

Continue reading

Cyber Clusters and Regional Powerbases: Influence Beyond London

From Cheltenham to Belfast, regional ecosystems are quietly shaping the future of UK cybersecurity. When people think of UK cybersecurity, they often picture Whitehall meetings or Canary Wharf boardrooms. But real influence increasingly lies outside London, in regional clusters, civic innovation groups, and place-based partnerships that combine skills, startups, and strategy into powerful local ecosystems. These clusters aren’t just delivering training or running meetups. They are shaping national policy, securing investment, and building sovereign capabilities in collaboration with local government, academia, and industry. This article maps out the regional powerbases transforming the UK’s cybersecurity landscape, and how to engage with them.

Continue reading

West Midlands Cyber Hub Diaries: Day One (Or Perhaps Day Sixty)

The West Midlands Cyber Hub marks a long-held ambition to give the region a central home for cyber. Building on the rebooted West Midlands Cyber Working Group (WM CWG), the Hub is designed to strengthen community coherence, increase investment, and connect students, SMEs, enterprises, and universities in a neutral space. Supported by DSIT, Innovate UK, Aston University, TechWM, and the Innovation Alliance for the West Midlands, the Hub will open its first phase at Enterprise Wharf in Birmingham, forming the core of a hub-and-spoke model across the region. The project team, led by Sevgi Aksoy and I (Wayne Horkan), with Rebecca Robinson as PM, is preparing for a pre-launch event on 30th September 2025.

Continue reading

UK Cyber Skills Landscape: The Real Gatekeepers of Talent and Training

Beyond bootcamps and degrees, who actually shapes how the UK finds, trains, and qualifies its cyber workforce? The UK cyber skills gap is well known, but less discussed is who actually defines what “skilled” means, who sets the standards, and who controls the flow of talent into real jobs. From formal certifying bodies to regional academies, neurodivergent networks to employer-led bootcamps, this article maps out the real gatekeepers of UK cyber skills and training, the organisations, programmes, and influencers that determine who gets hired, funded, or fast-tracked.

Continue reading

From Policy to Procurement: How Standards Bodies Influence UK Cyber Buying Cycles

It’s not just what’s secure, it’s what’s accepted, assured, and approved. Here’s how standards quietly determine what gets bought in cybersecurity. In cybersecurity, buying decisions are rarely made on features alone. Especially in the UK public sector and regulated industries, procurement is often shaped by frameworks, certifications, and official guidance issued (or heavily influenced) by standards bodies. These organisations, from NCSC and NIST to IASME, ISO, and CIISec, may not sell products, but they define the guardrails within which procurement happens. They help determine what “good” looks like, what qualifies as “secure enough,” and what’s required to win a bid. This article breaks down how standards bodies and frameworks influence what UK organisations actually buy, adopt, and fund when it comes to cybersecurity.

Continue reading

The Shadow Ecosystem: Alumni Networks, Closed Groups, and Whisper Influence in Cyber

Beyond public policy and LinkedIn posts lies a quiet web of influence, trusted groups, off-book referrals, and unseen signals that shape who gets funded, hired, or heard in UK cybersecurity. Cybersecurity in the UK has a formal face: policy frameworks, standards bodies, public panels, and professional networks. But beneath that, there exists a shadow ecosystem, informal, invitation-only, and often more influential than any official organisation. This is where reputations are made (or unmade), where partnerships are brokered before anyone sees a press release, and where quiet nods matter more than job titles. This article explores the informal infrastructure of UK cyber influence, the alumni groups, private chat channels, Slack collectives, and backchannel referrals that quietly shape decisions in hiring, procurement, investment, and policy.

Continue reading

What CISOs Really Read: Reports, Forums, and Signals That Shape Decisions

Forget the vendor hype. Here’s what makes it to the top table when security leaders plan, buy, and act. Chief Information Security Officers (CISOs) are drowning in noise. Every week brings new whitepapers, vendor webinars, analyst reports, and threat briefings, but only a handful cut through and shape decisions at the enterprise level. So, what do CISOs trust? What do they read, bookmark, cite, and share internally when building strategy or justifying spend? This article examines the forums, publications, briefings, and individuals that significantly influence CISO thinking in the UK, beyond vendor brochures.

Continue reading