Home › Blog

The UK has some of the best cyber brains in the world… and yet some of the weakest executi

The UK has some of the best cyber brains in the world… and yet some of the weakest execution.

We built the NCSC — admired globally. We can stand up an offensive cyber unit and quietly dismantle hostile infrastructure. We can publish guidance in plain English that even a board director can understand.

But when it comes to domestic resilience? That’s where the cracks show.
• Cyber Essentials was meant to raise the floor. Instead, it’s become a tick-box exercise SMEs resent.
• The NIS Directive was transposed into UK law, but ask any CISO in healthcare or energy how “enforced” it feels.
• The skills gap is a bit weird and off balance between the ninja class and green newbies.
• SMEs and local councils are sitting ducks. No subsidies, no incentives, just guidance PDFs no one reads.
• Supply chain security? Weak - I would personally say off the charts in terms of risk. AI risks? Barely touched. Yet we host summits about “AI safety” while the NHS still runs unpatched systems.

The UK excels at intelligence-led defence and global cyber diplomacy.
But it is failing at national resilience — the bit that actually protects hospitals, small businesses, and local authorities.

WannaCry in 2017 should have been the wake-up call. Instead, we got another strategy paper and a handful of pilots.

Cybersecurity here is treated like a strategic weapon, not a public utility.

Until we start treating cyber as infrastructure — like roads, power, or water — the UK will keep winning headlines abroad while bleeding quietly at home.

Scott G - >)

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing