GoFirm
Back to Blog
Threat Landscape·4 min read

The NCSC's warning is clear. Vulnerabilities you tolerate today will be exploited in conflict tomorrow.

By GoFirm

Richard Horne, CEO of the UK National Cyber Security Centre, delivered the RUSI Annual Security Lecture on 17 June 2026. He disclosed that more than 200 cyber incidents affecting UK critical national infrastructure were managed by the NCSC in the year to May 2026. Three quarters of those incidents are believed to be linked to hostile state actors, including Russia, China, and Iran.

He made one statement that every CFO and board member in a UK organisation should read twice: the vulnerabilities that organisations tolerate today will be exploited in conflict tomorrow. If they are too expensive or hard to fix in peacetime, then they certainly will be in war.

That is not a security warning, it’s is a commercial argument. Organisations that cannot clear their patch backlog in peacetime will not clear it under pressure. The question is not how to patch faster. It is how to ensure that what remains unpatched cannot be exploited into a catastrophic outcome before the patch arrives.

From risk management to contest.

Horne made a deliberate and significant shift in the vocabulary of UK cyber security. For a decade, the NCSC's guidance has been built around risk management. Risk assessment, risk quantification, risk appetite. Horne's speech replaces that vocabulary with contest. Cyber security is no longer a risk to be managed and tolerated. It is an ongoing contest with capable adversaries.

That shift matters for the CFO conversation. Risk management implies tolerance. It implies that some level of exposure is acceptable, that organisations weigh the cost of a control against the probability of an incident, and accept the residual risk. Contest implies no tolerance for being beaten. The adversary is active, capable, and persistent. The question is not what level of risk is acceptable, but how to ensure the adversary cannot complete the action that causes catastrophic damage.

GoFirm's position has always been that for high-consequence irreversible actions, risk management is the wrong frame. Those actions either complete without confirmed human authority or they do not. There is no risk appetite for a production database deletion or an unauthorised transfer of significant funds. The control is deterministic or it is insufficient.

AI will accelerate exploitation of known vulnerabilities by 2028.

The NCSC assesses it highly likely that by 2028 AI-enabled cyber capabilities will be used by attackers to exploit known vulnerabilities in legacy technology at scale across critical national infrastructure. Horne described this as not a distant horizon but the next product cycle.

That timeline is the commercial urgency that the patch cycle cannot address. Most organisations already carry more vulnerabilities than they can realistically remediate. AI-accelerated exploitation compresses the window between a vulnerability being known and being weaponised. A 24-hour patch cycle cannot compete with a four-hour weaponisation timeline. The gap between discovery and remediation, always present, becomes catastrophic when the attacker can move at machine speed.

The response is not to patch faster, though that remains necessary. It is to ensure that unpatched vulnerabilities in critical systems cannot be exploited into a catastrophic outcome without a named person in your organisation confirming the request on a device they control. If that condition holds, the attacker can reach the asset and still cannot complete the action. The patch backlog becomes a planned programme rather than a permanent emergency.

The fundamentals are not in place.

Horne was direct about the state of UK cyber resilience. We still see far too many significant incidents today that are possible because the fundamentals are not in place. He called on every board member and executive to strengthen cyber resilience by understanding their exposure, building defences based on proven security fundamentals, and ensuring they can continue operating and recover quickly after an attack.

Understanding exposure and building defences are upstream activities. They reduce the probability of an attacker reaching a critical asset. Continuing to operate and recovering quickly are downstream activities. They address the damage after an incident has occurred.

The missing fundamental is the control that holds at the moment of consequence. Before a high-consequence irreversible action completes against a critical asset, a named human authority confirms the request on a device they control. If confirmation does not arrive, the action does not complete. The attacker may have reached the asset. They cannot complete the action. The organisation continues operating because the catastrophic outcome did not occur.

The commercial case in one sentence.

Horne said it directly: the vulnerabilities tolerated today will be exploited in conflict tomorrow. For organisations that cannot clear the backlog in peacetime, and most cannot, the answer is not to keep trying to clear it faster under existential pressure.

Secure the execution boundary of your most critical assets first. Unpatched vulnerabilities have nowhere to go. The existential pressure drops to near-zero immediately. The patch backlog becomes a planned programme, triaged rationally by actual consequence, executed without the emergency callouts, weekend deployments, and consultant spend that come with permanent crisis response.

The NCSC CEO has made the commercial argument. The control that delivers it is three lines of code.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai the collective intelligence platform for Security, Resilience & Defence. Osintos AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Horne, Richard. RUSI Annual Security Lecture 2026. National Cyber Security Centre, 17 June 2026. https://www.ncsc.gov.uk/speech/richard-horne-speaking-at-the-rusi-annual-security-lecture

2. NCSC. NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK critical systems. 17 June 2026. https://www.ncsc.gov.uk/news/ncsc-ceo-hostile-states-linked-to-three-quarters-of-cyber-attacks

3. The Record. Britain is already fighting the opening exchanges of future conflicts in cyberspace. 17 June 2026. https://therecord.media/britain-nation-state-cyberattacks-richard-horne-rusi

Share this article