I spent the first ten years of my cyber security career in the Civil Service and the last twelve leading government cyber work at PwC. During that time, I have worked across central government, the NHS, Defence, Critical National Infrastructure and other large, complex organisations - on everything from long-term cyber transformation, high-availability security architectures, and supply-chain security to major incident response. PwC is also an NCSC-assured Enhanced Cyber Incident Response provider, and we have worked on some of the largest cyber incidents in the UK and internationally, including the independent post-incident review of the 2021 Conti attack on Ireland’s national health service, the HSE.

Across those experiences, I keep coming back to an ostensibly simple question: not just “how secure is this system?”, but “what absolutely has to keep working when several things go wrong at once?”
Start with what must keep working
Recent incidents make that very real. The 2024 attack on pathology provider Synnovis disrupted services across the NHS and delayed more than 11,000 outpatient appointments and elective procedures. More recently, the cyber incident affecting Boston Scientific disrupted order processing and shipping, requiring NHS Supply Chain and the wider system to manage shortages, backlogs and alternative arrangements.
These are good reminders that a cyber incident does not stay a cyber incident for long. It becomes a healthcare problem, a logistics problem, a citizen-service problem.
The NCSC’s recent guidance on highly disruptive attacks centres recovery on “minimum viable operations” - the lowest level of capability at which an organisation can continue safely, meet its obligations and maintain trust.
That leads me to a broader question we’ve been exploring here at PwC: what might a Minimum Viable UK look like?
Our resilience work uses the idea of a “survival core”: identify the services and outcomes that must continue through serious disruption, and then trace the people, data, technology, infrastructure and suppliers that make them possible. At national level, the useful questions become: what must continue, at what minimum level, for how long, what does it depend on, and who can make the difficult prioritisation decisions when capacity is constrained?
This is not about accepting poorer public services. It is about knowing, before a crisis happens, where scarce protection and recovery capacity matters most.
The pathways are familiar. The tempo is changing.
AI only makes that challenge more urgent.
The UK AI Security Institute has found that the length of cyber tasks frontier models can complete autonomously has been doubling on the order of months, not years. Its latest work also suggests leading open-weight models are now only around four to seven months behind the closed frontier on cyber capability.
The NCSC puts the consequence plainly: “activities that once took weeks can now take minutes.” AI is already accelerating vulnerability discovery and reconnaissance, reducing the time available to detect, decide and contain.
Importantly, AI is not only an attacker advantage. The NCSC’s Cyber Shield vision explores agentic AI for national-scale vulnerability discovery, detection and response. That is exactly the kind of opportunity we should be looking for: using AI to increase defensive speed as well as understanding the risks it creates.
For me, this changes the case for collective defence.
Collective defence is really about tempo
The Government Cyber Action Plan sets out a stronger, active centre, better government-wide visibility, central services and greater ability to coordinate response to fast-moving and concurrent events, while departments retain responsibility for their own services and risks.
Richard Horne, CEO of the NCSC and someone I was fortunate to work for and learn from for more than a decade at PwC, has described government’s role as being to “catalyse a response at scale”.
I think that gets to an important point. The benefit of stronger central capability is not simply economies of scale. It is tempo.
If a vulnerability affects technology used across government, or a critical supplier is compromised, the threat will not wait while multiple organisations independently investigate, agree priorities and mobilise action.
A useful test, therefore, is whether collective capability reduces the time it takes government to see, decide and act. Can we see once, understand once and act many times - through shared intelligence, common technical capability, coordinated support and pre-agreed intervention where risks become systemic - while keeping accountability and operational ownership close to individual services?
That is not an argument for putting everything in one place. Indeed, centralisation can itself create concentrations of risk. The more interesting model is federated: local ownership combined with collective visibility, capability and speed.
When circumstances deteriorate, what do we actually control?
Supply chains bring these issues together.
I’ve worked extensively on supply-chain cyber security across the NHS, CNI and many other complex organisations, as well as with the MOD on developing the Defence Cyber Protection Partnership and Cyber Security Model. The latest Cyber Security Model explicitly focuses not just on information, but on organisational security and resilience, and aims to flow requirements down through subcontracting tiers.
For me, the lesson is consistent: the boundary of an essential service rarely matches the boundary of the organisation delivering it. Cloud, SaaS, telecoms, identity providers, managed services, software components and specialist people can all sit inside the critical dependency chain.
This is also why I think digital sovereignty needs to be understood much more broadly than data residency.
PwC’s Digital Sovereignty Framework, which we are now using with many clients, looks across strategic and geopolitical resilience, people and governance, supply chains, operational resilience, cloud, data, applications and AI. It asks where control is essential, where dependency is an acceptable and deliberate choice, and whether organisations retain credible options to continue, recover, substitute or exit when conditions change.
Put simply: when circumstances deteriorate, what do we actually control?
Would our plans still work if several departments or suppliers were under attack at once? If normal communications or identity services were degraded? If the same scarce responders were needed everywhere? If disruption lasted days or weeks rather than hours?
In PwC’s wider resilience work we have used a simple challenge: plans alone aren’t capability – real capability is what you can demonstrate through exercising, stress testing and confidently using.
Richard Horne has argued that “while breaches are inevitable, catastrophic impacts need not be.” So, on a practical and affordable level, how can we make sure they aren’t?
At DigiGov, I am looking forward to exploring what that means in practice: how we identify what matters most, how government can act collectively at the pace of the threat, and how we retain enough control over the technologies and supply chains we depend on to keep essential public services resilient when conditions are at their most challenging. Join me on the cyber stage from 10.30 23rd September, or get in touch to learn more.
Nick Spray, Government & Health Cyber Security Leader, PwC UK


