Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we look at new updates and guidance from the NCSC as CyberUK 2026 kicks off, examine the hype around Anthropic’s new ‘Mythos’ model, and review the government’s open letter on AI and cyber.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

Head of NCSC warns that the UK is at the edge of a ‘perfect storm’ of cyber threat

Richard Horne, chief executive of the National Cyber Security Centre (NCSC), used his opening keynote at CyberUK in Glasgow to frame the next decade of UK cyber security as navigating a ‘perfect storm’ of rapid technological change and intensifying geopolitical tension. 

His message to government, regulators, and organisations was that cyber security is now a core strategic capability and must be treated as such. Horne argued that AI in cyber defence, such as Anthropic’s new Mythos system, will be a net positive if the UK moves as fast as its adversaries. 

Frontier AI systems are already helping to identify and exploit vulnerabilities at scale, exposing organisations running unpatched, insecure or legacy systems. While the UK has not yet seen a wave of new AI‑driven attacks, Horne warned that defenders must adopt AI ‘at least as quickly’ as attackers, normalising AI‑enabled detection, monitoring and incident response. 

Horne also highlighted the sobering statistic that state-sponsored attacks now account for the majority of the NCSC’s nationally significant incidents, even as criminal ransomware remains the most common threat for most organisations.

Horne listed China, Iran and Russia as posing the greatest threat to the UK and Europe, and emphasised the importance of developing the UK’s offensive cyber capabilities in order to match escalating risks to national security. 


Anthropic announces Claude Mythos to mixed response across industry and government

Anthropic’s new Claude Mythos model, announced on the 7th April as part of the larger ‘Project Glasswing’, is a new model for Anthropic’s Claude AI designed to find and exploit software vulnerabilities. However, the new model has rapidly become a test case for how governments and regulators handle emerging technologies – particularly frontier AI.

Mythos is capable of identifying vulnerabilities by reading a program’s source code, configuration files, logs and documentation to map out an attack surface (inputs, APIs, authentication flows, etc.). It then applies its training on common bug patterns to identify weaknesses and vulnerabilities. 

Anthropic has said Mythos has already outperformed ‘all but the most skilled humans’ at finding and exploiting vulnerabilities, and has uncovered thousands of previously unknown bugs, some up to 27 years old, as reported by The Guardian.

This has triggered a large-scale reaction from both industry and government. NCSC CEO Richard Horne stated that it could be a net positive if the UK is quick to embrace it in his keynote address at CyberUK.

Meanwhile, in Washington, US Treasury Secretary Scott Bessent reportedly summoned the CEOs of major US banks, including Goldman Sachs, Bank of America, Citi, Morgan Stanley and Wells Fargo, to discuss the cyber risks posed by the potential use of Mythos by bad faith cyber actors. 


International cyber agencies warn on China-linked covert cyber networks

In a new joint advisory launched on the second day of the UK government’s CyberUK 2026 conference, international cyber security agencies are urging organisations to strengthen their defences against a growing threat from China-linked covert cyber networks. 

The guidance, led by the NCSC with the support of industry and 15 international partners across 9 countries, sets out how organisations can better protect themselves against attacker tactics used to hide malicious activity.

Covert networks take advantage of the Internet of Things (IoT) by compromising a number of smaller, everyday internet-connected devices, such as home routers or smart devices. NCSC are warning that these networks are currently being used by attackers linked to China in order to target critical sectors worldwide, steal sensitive data, and maintain persistent access to victims systems. 

The advisory also highlights the role of Chinese information security companies in creating and operating these covert networks. NCSC highlighted a China-based firm named Integrity Technology Group, which had been linked to the Flax Typhoon botnet and publicly called out by the NCSC and partners in September 2024. They were later sanctioned by the UK government for reckless and indiscriminate malicious cyber activity.


Policy & Political

UK ministers warn business on rapidly escalating AI-driven cyber threats

The government published an open letter on the 22nd April to business leaders from Security Minister Dan Jarvis and Secretary of State for Science, Innovation and Technology Liz Kendall that AI is currently transforming the cyber threat landscape, and that companies must urgently raise their game when it comes to cyber security policy.

Jarvis and Kendall highlight that advanced AI models, like the previously mentioned Mythos, can now perform tasks that once required rare specialist skills, such as finding and exploiting software vulnerabilities, at an unprecedented speed and scale. 

Recent testing by the government’s AI Security Institute (AISI) found Mythos to be significantly more capable in cyber offence than any system previously assessed, with frontier AI capabilities judged to be doubling roughly every four months. This has triggered an industry-wide shift, as OpenAI followed by expanding its Trusted Access for Cyber programme – including through a new partnership with Microsoft’s Secure Future Initiative, which was announced after the letter was published on the 23rd April.

The letter stresses that the UK Government is acting through evaluation capabilities at AISI, guidance from the NCSC, the Cyber Security and Resilience Bill, and the upcoming National Cyber Action Plan. But ministers are clear that government efforts alone are not enough, and that criminals will target organisations of all sizes, across every sector. 

The letter concludes by urging boards to treat cyber risk as a standing leadership issue, calling on organisations to adopt the Cyber Governance Code of Practice, rehearse incident response, and consider investing in cyber insurance. They also recommend achieving a Cyber Essentials certification and embedding the requirements across supply chains.


Photo credits: RUSI

Government publishes new Defence Diplomacy Strategy

The UK Government has published a new Defence Diplomacy Strategy, setting out how defence will be used more systematically as a tool of statecraft to support foreign policy, economic resilience, and industrial growth. 

The new strategy focuses on developing larger defence assets, including deployable military forces, specialist engineering, credible maritime presence etc. It also places emphasis on developing offensive and defensive cyber expertise. These tools will be used in support of the priorities of the Foreign, Commonwealth & Development Office, Cabinet Office, Home Office, Department for Business and Trade, and other government departments.

A central focus of the strategy is on integrating defence diplomacy with wider government activity overseas. That means all defence activity will be tightly aligned with cross-government objectives: countering hostile state activity, supporting allies, enabling trade, protecting critical infrastructure and promoting UK expertise in emerging domains, including cyber.

The new strategy will also work to deepen industrial partnerships and attract inward investment. Since July 2024, the UK defence sector has already secured a record £3.2 billion in foreign direct investment, and ministers argue that a secure, thriving and innovative defence industrial base is key to building lasting strategic relationships with allies and partners. 


NCSC Updates


Business & Industry

New research demonstrates culture of fear around reporting cyber incidents in UK businesses

New research from UK cybersecurity and cloud services provider Kocho reveals a worrying culture of fear and blame around cyber breaches in UK organisations. Out of the 501 UK CIOs, security analysts and IT professionals surveyed in the new research, 27% say they’ve felt pressured to cover up a security breach or data loss. This is despite the fact that 92% reported believing that their board understands day‑to‑day cyber realities. 

Businesses must currently report incidents under GDPR breach‑notification and NIS reporting regimes. The incoming Cyber Security and Resilience Bill, currently before Parliament, will mandate initial reporting after 24 hours for in-scope businesses.

Additionally, 20% of UK professionals reported a persistent culture of blame, and 14% said that they’ve been personally held responsible for incidents. Boardroom dynamics are reportedly a major stressor, with 73% saying that managing C‑suite expectations is demanding, rising to 81% in organisations with 100-250 employees. 

The research also highlighted a level of brutal honesty amongst them. 52% have been asked by boards or customers for cyber assurances they cannot honestly give. 39% believe clearer support and recognition from senior leadership would reduce stress, while 28% say visible executive backing for cyber priorities would make them feel more positive about their role.


CBN Updates

All-Party Parliamentary Group for Cyber Innovation holds briefing with DSIT to discuss Cyber Security and Resilience Bill

On Thursday 16th April, the All-Party Parliamentary Group (APPG) for Cyber Innovation met with the Government’s lead Minister on Cyber Security, Baroness Liz Lloyd of Effra, and the Department for Science, Innovation and Technology to discuss the progress of the Cyber Security and Resilience (Network and Information Systems) Bill ahead of its report stage in the House of Commons.

Alongside a comprehensive analysis of the Bill, the APPG also explored wider areas of the government’s cyber security policy with the Minister and DSIT. These included greater investment in cyber skills, the changing role of regulators, international standards alignment, and digital sovereignty.

If you’d be interested in keeping up to date with the activities of the APPG for Cyber Innovation, please feel free to follow the APPG LinkedIn page here

If you’d like to get in touch with the APPG secretariat, please email secretariat@cb-network.org


Events

Clarity Cyber Leaders Forum: Bridging the policy-industry gap on UK cyber resilience

The UK’s cyber resilience is being tested on every front – from escalating state-sponsored attacks to ransomware and supply chain threats. Yet, the way cyber progress is discussed in Westminster too often diverges from what security leaders can deliver day-to-day.

Clarity’s Cyber Leaders Forum will bring together Parliamentarians, senior security leaders and analysts for an on-the-record, fast-paced panel debate on how to close this gap and drive real-world security outcomes. 

Underpinned by new survey findings on where policy and industry priorities align, and where they don’t, the discussion will explore accountability, board-level preparedness, sovereignty, skills, AI, and the evolving threat landscape.

Our expert panellists include Matt Warman, Chair, Cybersecurity Business Network and former Minister for Digital, and Mark Ward, Senior Research Analyst at the Information Security Forum. 

See below for more event details:

Title: Clarity’s Cyber Leaders Forum

Date: Monday, 1st June 2026

Time: 17:00-19:30

Venue: Zetland House, 5-25 Scrutton Street, London, EC2A 4HJ

Format: Panel discussion, Q&A and networking

Places are limited – if you’d be interested in attending, please get in touch to secure your spot at secretariat@cb-network.org 


Join CyberSummit 2026 – Turning Cyber Threats into Resilience and Growth

Senior leaders from across the UK cyber ecosystem will come together on Tuesday 23 June 2026 for CBN’s inaugural CyberSummit.

Held at Bird & Bird, 12 New Fetter Lane, London EC4A 1JP, this full‑day forum (10:00–17:00, followed by networking) will bring together 100+ senior figures including policymakers, government representatives, CISOs and C‑suite executives from critical sectors such as health, finance, energy, telecoms and insurance.

The summit will move beyond threat awareness to focus on tangible, layered resilience strategies, structured around four core themes:

Open to CBN members, C‑suite leaders, technology heads and senior public sector representatives, CyberSummit 2026 is your chance to help shape a more resilient and prosperous digital future for the UK.

Please see more details about the CyberSummit here

If you have any questions about CyberSummit or any upcoming events, feel free to get in touch at secretariat@cb-network.org.


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.