The UK government has announced a £90 million investment to strengthen the nation's cyber defences alongside a new voluntary Cyber Resilience Pledge, as the National Cyber Security Centre warned that the country is facing a "perfect storm" of risk driven by rapid technological change and rising geopolitical tensions.
The announcements were made by Security Minister Dan Jarvis MBE in his keynote address at the NCSC's annual CYBERUK conference in Glasgow, against a backdrop of mounting evidence that artificial intelligence is dramatically increasing both the scale and sophistication of cyber attacks.
NCSC chief warns of 'perfect storm'
Richard Horne, Chief Executive of the National Cyber Security Centre, framed the current threat environment in stark terms during his CYBERUK keynote, describing cybersecurity as operating within a "perfect storm" of rapid technological change and rising geopolitical tension.
The warning comes as official data reveals that the number of nationally significant incidents handled by the NCSC more than doubled in 2025, with hostile states and criminal actors increasingly deploying automated AI systems to identify and exploit vulnerabilities. Government figures also show that 43 per cent of UK businesses have experienced a cyber breach or attack in the past year.
Recent testing by the UK's AI Security Institute of Anthropic's new Mythos model found it to be "substantially more capable at cyber offence than any previously assessed model". The system reportedly completed a 32-step enterprise attack simulation autonomously. Tests of such advanced frontier AI models show that AI cyber capabilities are accelerating even faster than expected.
£90 million to bolster small business defences
The £90 million investment will be delivered over the next three years through existing programmes managed by the Department for Science, Innovation and Technology and the National Cyber Security Centre, with a focus on strengthening the cyber resilience of small and medium-sized businesses.
Speaking to media during CYBERUK, Jonathan Ellison, NCSC Director for National Resilience, said uptake for Cyber Essentials — the government-backed certification scheme — was up around 20 per cent in the last financial year compared to the previous, marking the programme's best year to date. Quarterly certifications have now surpassed 10,000 for the first time.
However, industry figures were quick to temper the announcement with calls for more substantial intervention. James Neilson, SVP of International at OPSWAT, argued that while the investment is "nice on paper and helpful for SMEs," it is "nowhere near enough" to address the scale of the problem. "SMEs either have small security teams or none at all, so it's not just a funding issue but also a knowledge issue," he said.
Cyber Resilience Pledge: three key actions for business
Alongside the funding, the government is inviting UK organisations to sign a voluntary Cyber Resilience Pledge, which requires signatories to take three specific actions designed to have an "immediate positive impact" on their resilience to cyber attacks.
Businesses signing the Pledge must:
-
Make cyber security a board-level responsibility — implementing the government's Cyber Governance Code of Practice and ensuring all board members undertake NCSC Cyber Governance Training within three months, and then on an annual basis
-
Sign up to the NCSC's free Early Warning service — receiving information on potential cyber attacks within one month of signing, giving organisations invaluable time to act before an incident escalates
-
Require government-backed Cyber Essentials certification across their supply chains — using the Cyber Essentials Supplier Check Tool within two months, conducting a comprehensive audit of Cyber Essentials coverage across the entire supply chain, and taking a risk-based approach to requiring certification from suppliers
Cyber Security Minister Baroness Lloyd has already written to the CEOs and Chairs of over 180 of the UK's leading businesses, encouraging them to sign up to the Pledge ahead of a formal launch later this summer.
"The cyber threat facing UK businesses is serious, growing and evolving fast," Baroness Lloyd said. "AI is giving attackers capabilities that would have seemed extraordinary just a year ago, and no organisation can afford to be complacent."
The Minister emphasised that the three actions are "practical, achievable, and are proven to work — there is no good reason not to act". She added: "Cyber resilience isn't just a technical issue; it's a board issue."
'A generational endeavour'
In his CYBERUK address, Security Minister Dan Jarvis issued a direct call for leading AI companies and UK innovators to collaborate with the government on building AI-powered cyber defence capabilities.
"The nature of warfare has fundamentally changed," Jarvis said. "Attacks on British systems are increasing in volume, in sophistication, and in ambition. They come from criminal syndicates operating across borders. They come from ransomware gangs who treat children's nurseries as targets of opportunity. And yes, they come from hostile states."
Jarvis cited the recent attack on Jaguar Land Rover as an example of the real-world damage cyber attacks can inflict. "If this damage had been caused by an old-school, physical attack it would have been the equivalent of hundreds of masked criminals turning up to dealerships across the country breaking glass, smashing up computers and driving cars right off the forecourt."
The Minister characterised the development of AI cyber defence as a "generational endeavour" that will "test the absolute limits of our engineering and innovation". He said cooperation could achieve "capabilities that can protect our nation's most critical networks by autonomously identifying and addressing vulnerabilities at a speed and scale no human can match".
"We've already made the UK a top destination for AI investment and want to take this work a step further in a generational endeavour to protect the UK from a new era of threats," Jarvis said.
Growing cyber sector and regulatory backdrop
The announcements come as the UK cyber security sector continues to expand rapidly. According to new figures from the Department for Science, Innovation and Technology, the sector generated revenue of £14.7 billion, up 11 per cent since last year. The number of companies operating in the industry jumped 20 per cent, with 438 new cyber security firms emerging, while the sector added 2,300 jobs over the same period.
The government's push also sits alongside the Cyber Security and Resilience Bill, which is currently making its way through Parliament. Later this year, the government will publish a new National Cyber Action Plan, which has been developed in consultation with more than 500 organisations.
Formal launch this summer
The Cyber Resilience Pledge will be formally launched in the summer, with a public announcement of those organisations which have signed up. The government has published full guidance, a declaration form and frequently asked questions on the GOV.UK website.
The Pledge has been designed primarily for medium and large organisations, but organisations of any size in any sector can sign up and the government encourages all to do so. Companies that sign the Pledge are committing to providing an annual public update on their progress.
Industry reaction and calls for stronger incentives
While industry leaders broadly welcomed the government's focus on cyber resilience, several called for more concrete measures to drive adoption.
Jonathan Lee, Director of Cyber Strategy at TrendAI, told Infosecurity that "the government and the NCSC are saying the right things, but we have to move from this position of gently encouraging organisations to do things, providing advice and guidance to providing some incentive for them to do so." Lee suggested that tax credits should be explored further. "Let's incentivise people to invest more in their resilience because ultimately, we're told it's a team sport and everyone needs to work together," he said.
Trevor Dearing, Director of Critical Infrastructure at Illumio, emphasised that "what many small businesses lack is practical guidance on how to protect sensitive data and keep critical services running when incidents occur."
A new standard for British business
The government's message to businesses has been consistent and urgent: the era of treating cyber security as purely an IT function is over. With AI giving attackers capabilities that were unimaginable just a year ago, cyber resilience must now be a board-level responsibility.
For British businesses of all sizes, the message from CYBERUK 2026 is unambiguous: adapt to the new reality of AI-powered threats, or risk being left behind. The Pledge provides a tangible way for organisations to boost their resilience, differentiate themselves from competitors, and demonstrate to investors, customers and trading partners that they take cyber security seriously.
