UK cyber chief urges persistence, partnership in digital defense
Richard Horne, the CEO of the UK’s National Cyber Security Centre (NCSC), used his first official trip to the United States since being appointed last year to deliver a clear message: Defending our way of life in cyberspace requires shared responsibility, continuous innovation and a deepened partnership between allies such as the U.S. and the UK.
In an interview for the Cyber Focus podcast, Horne emphasized that cybersecurity is not a one-time fix – it’s a “contest” that demands ongoing effort, agility and resilience. “We all need to recognize we have a responsibility for cybersecurity – for ourselves and for others,” he said.
A former private-sector executive and longtime advocate for public-private collaboration, Horne now leads the UK’s foremost cybersecurity agency. He spoke about the importance of partnerships such as Five Eyes in helping nations stay ahead of advanced persistent threats, noting that “the relationship with the U.S. and the Five Eyes really does underpin especially our understanding of the most advanced threat.”
As ransomware and zero-day vulnerabilities continue to disrupt hospitals, schools and businesses, Horne urged organizations to view cybersecurity as a core responsibility and not just a compliance burden. “Cybersecurity is part of their mission. It’s not an additional cost – it’s actually part of your mission,” he said.
One of the sharpest tools in that mission, according to Horne, is artificial intelligence. But it’s a tool that both defenders and adversaries can use. “AI is almost like when we moved from wooden [tennis] rackets to composite rackets. Was that an advantage? It was an advantage to both sides. … If you stick with a wooden racket, then ultimately you’re going to be overcome.”
Horne also called out the need for better software development practices, pointing to ongoing exploitation of basic code flaws. “We see many cyberattacks exploiting zero-day vulnerabilities that frankly shouldn’t be there,” he said. “And the quality of code that we have in our hardware, software … is a big issue.”
With the UK and U.S. both pushing to prepare for post-quantum threats, Horne stressed that cooperation between governments and industry is key. That cooperation, he argued, must be matched by internal resilience: the ability to manage exposure, strengthen defenses and reduce the consequences of inevitable breaches.
That collaborative mindset, Horne emphasized, must extend beyond traditional alliances. “The more we can create a unified sort of approach to combating some of these advanced threats, the more it will benefit us all because we are a global society and we depend on each other,” he said.
The full episode of Cyber Focus can be found here.