error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...


      If the UK is to remain an attractive destination for global investment and talent, it must fast strengthen its approach to cyber resilience. In an increasingly interconnected and digitally enabled economy, cyber security is no longer a purely technical consideration – it is a strategic enabler of growth, public trust and long-term competitiveness.

      The cyber threat landscape facing the UK is evolving in both scale and sophistication. A broad spectrum of actors – including state-sponsored groups, organised criminal networks and hacktivists – are increasingly targeting critical infrastructure and high-value sectors. Their objectives range from financial gain to intelligence gathering and disruption.

      Recent data highlights the growing frequency of attacks. Last year alone, the National Cyber Security Centre (NCSC) helped UK organisations deal with 204 nationally significant incidents – that’s more than one every other day. Their most recent annual report suggests the frequency of attack jumped 129% between 2024 and 2025¹.

      At the same time, the UK economy is undergoing rapid digital transformation. Advanced technologies and AI are becoming embedded across sectors, further increasing reliance on secure, resilient connectivity. As a result, cyber security is deeply intertwined with national security, economic stability and public trust.

      Against this backdrop, there are six priority areas where closer collaboration between public and private sector organisations can help reinforce the UK’s position as a leading global cyber power.

      Cliodhna Potter

      Director, Advisory

      KPMG in the UK


      Six focus areas for strategic cyber resilience

      For the UK to maintain its position as a leading and responsible cyber power, we need to shift from our traditional – largely reactive – approach to one based on proactive, strategic resilience. And that will require the UK public and private sectors to focus on:



      • Regulation

        The UK is already making some good progress with the Cyber Security and Resilience Bill, introduced in late 2025. It represents a more assertive, mandatory regulatory approach across public and private sectors. Its scope is much broader than its predecessor, bringing managed service providers, data centres and organisations operating high‑impact connected technologies into oversight. Regulators can also designate suppliers as ‘critical’, reflecting the reality that cyber risk increasingly sits within supply chains.

      • Investment

        The UK is also leading by example through the Government Cyber Action Plan, backed by £210 million of investment, which aims to take a more coordinated and centralised approach to cyber security by strengthening the government’s own incident response and embedding secure-by-design principles across the public sector supply chain. That’s alongside a range of other public funding that has already been committed to improving cyber resilience and modernising legacy networks.

      • Innovation

        Bad actors are continuously reinventing their craft. Which means that the good actors must also continue to innovate. We continue to see a strong pipeline of startups, SMEs and university spin offs – particularly in areas related to critical national infrastructure protection. And, encouragingly, we are seeing robust clusters of cyber capabilities build regionally in places like Manchester, Leeds and Bristol.

      • Governance

        Cyber security has moved decisively from a technical concern to a strategic business issue with the Government and NCSC now engaging much more closely with senior business leaders and reinforcing expectations of board ownership. High performing organisations we support are responding by strengthening governance, giving CISOs direct access to the board and embedding cyber risk into broader decision-making processes and frameworks.

      • Operational readiness

        Cyber security isn’t just about how well you defend against threats. It’s also about how effectively you operationally respond to and recover from cyber incidents. We are seeing the strongest organisations assume a ‘breach first’ mindset, regularly rehearsing incidents and building the institutional and capability muscle memory needed to make effective decisions under pressure in the moment. That, in turn, is raising the collective resilience of the UK economy.

      • Skills

        The UK is increasingly taking a more coordinated public and private sector approach to addressing the skills gap. Public and private sectors are working together to expand cyber education and career pathways, strengthen apprenticeships and conversion programmes and invest in the development of a dedicated cyber profession across both sectors. The focus is shifting from simply producing more specialists to building a sustainable, diverse skills pipeline that supports our long-term national resilience.


      A secure and trusted UK in a volatile world

      At KPMG, our broad network of cyber security experts helps organisations to build, maintain and evolve their cyber security position. Our experience shows that responding effectively to today’s more volatile environment requires more than incremental improvement – it demands a step change in how cyber resilience is defined, prioritised and delivered. This will depend on deeper collaboration between government and industry, sustained investment and a shared commitment to long-term strategic resilience.

      If the UK can make that change, it will be well placed not only to manage the risks of a more unpredictable cyber landscape while making our society more resilient, but to differentiate itself globally – reinforcing its position as a secure, trusted and resilient digital economy.


      This insights article is based on a keynote presentation delivered by Cliodhna at the Westminster eForum policy conference: ‘Next steps for cyber security policy and regulation in the UK’ on 23 March 2026.



      Further insights

      Cyber security is more than a technology issue – it’s a golden thread that runs throughout your business, enabling it to operate effectively, efficiently, and securely.

      Building on the NIS Regulations, the Cyber Security and Resilience Bill introduces a more strategic approach and places greater emphasis on Managed Service Providers (MSPs) and supply chain security.

      Turning risk into regional strength

      In collaboration with KPMG, the World Economic Forum offers practical guidance for organizations seeking to harness AI as a strategic capability in their cybersecurity efforts

      Something went wrong

      Oops!! Something went wrong, please try again


      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.