When the U.K. government launched its Cyber Action Plan recently to complement its Cyber Security and Resilience Bill in aid of galvanizing Britain’s cybersecurity posture, there was one interesting detail concerning two American network security giants.
Part of the $282 million (£210 million) investment was the founding of a Government Cyber Unit to be led in part by the Department for Science, Innovation and Technology (DSIT). The body will run a Software Security Ambassador Scheme to drive adoption of its Software Security Code of Practice, with initial ambassadors including Cisco and Palo Alto Networks.
At a time when digital sovereignty is a hot topic, the inclusion of the pair alongside British leaders like Sage may have raised some eyebrows. But according to Carla Baker, senior director of government affairs for the U.K. and Ireland at Palo Alto Networks, size matters when it comes to the overwhelming scope of the security and sovereignty question.
“What we bring as a global cybersecurity company, is security at scale,” Baker said. “So being a global provider gives you global insights, global protections. And if you want the kind of sovereign ability or sovereign approach, you won't get that security at scale because you're not accessing that data lake.”
The Palo Alto director added having a “unique” global perspective on threats from the likes of China and Russia, passing on that knowledge to its customers.
“I think sometimes the sovereignty debate really clouds the fundamentals of benefits of what security and technology at scale can actually bring," Baker said.
Baker’s views on sovereignty echo those of U.K. software patron Cisco. Matt Fussa, VP of trust and compliance at Cisco, is keen to clarify the sovereignty discussion.
“One of the things I dislike about sovereignty is it's really a legal premise," Fussa said. "We're a technology company, and I try to think about this from a technology problem perspective. So when we think about sovereignty, it's really kind of an extension of something we've been focused on for a long time for our entire history as a company and our history of doing business in Europe: secure, resilient, transparent, and assured infrastructure.”
For Fussa, the sovereignty conversation is an “unproductive one” for overly focusing on political risk.
“But the risk that a system that we build and deploy in a customer site can be degraded, impacted, impeded, stopped, brought to its knees by an attack or something like that. That risk exists today," Fussa said. "It's hard for us to make promises about what another government may do, right? But one thing we can control is the way we [provide solutions] so customers know that when they make that investment, that's an investment that's going to last through the ups and downs of political cycles.”
The AI question
In one way, political cycles bring about new ideologies on the politics spectrum. But it’s easy to forget they bring in new attitudes, too, with Palo Alto’s Baker more optimistic about the U.K’s cybersecurity footing compared to the past.
“We've got a different relationship with government now,” Baker said, harking back to her tenure at technology organization TechUK. “I think it was more like parent/child back in 2010 where it was, ‘I will come up with guidance which you will follow.’ Where now it’s about co-designing policies. We get to work on information sharing partnerships. There's a different dynamic with government and industry that wasn't there before.”
Someone who’s seen this change from the other side of the fence is Matt Warman, former U.K. Minister for Digital and Broadband, and current chair of the Cybersecurity Business Network (CBN).
“Cybersecurity was an issue that was something that people were sort of constantly saying, ‘this needs more attention at board level. It's not getting enough focus.’ And of course, in recent years, you've seen it rocket up the agenda for all the wrong reasons,” Warman said, highlighting a spate of British cybersecurity attacks in recent years on local giants such as vehicle makers Jaguar Land Rover, retail brand Marks & Spencer, and the National Health Service.
Warman noted a sea change in cybersecurity attitudes, but warned there was “a huge amount more work to do,” especially with the advent of AI.
“AI is playing more and more a part of everybody's lives," Warman said. "It relies on data where cybersecurity is more and more important. … So if you think cybersecurity is important now, I think you ain't seen nothing yet.”
AI as a driver was also noted by Alym Rayani, Microsoft VP of security, when comparing his most recent visit to the U.K. with past excursions.
“The thing that I have seen since my last trip here, which was in November, and then the one two years ago, is the conversation shift from, ‘are we adopting AI?' to ‘we're adopting it, and so we must put the security controls in place,'" Rayani said. “I couldn't tell you if that's directly related to government sort of initiatives or other things, but I see a real appetite to do agent security for the agentic era."
The agentic theme dominated both Microsoft’s recent AI Tour in London, alongside the London leg of Palo Alto Networks’ Ignite tour. Cisco is, of course, also hot on the theme (who isn’t?). But with AI agents comes yet another possible threat to sovereignty, with agents and AI as a whole arguably shifting key decisions, data, and infrastructure to the transnational platforms and private firms behind the technology, as run on cross‑border algorithmic systems.
Cisco and Palo Alto’s footing in U.K. affairs may seem more problematic as a result, especially if having the ear of government may mean decision makers hearing non-stop praises about certain agentic wares. Warman, though, sees the relationship in more pragmatic terms.
“It’s a simple fact that they are huge players in the U.K. ecosystem, and it's really important to get the views of all of those stakeholders," Warman said. "That is not the same thing as the government being driven by any one company, regardless of where they're headquartered.”
Noting the unique cybersecurity relationship between the private sector and the public sector, with the drive mainly coming from the former, Warman sees the CBN as an “honest broker” between the government and companies both big and small, aiming to serve as the unified voice of Britain's cybersecurity industry.
“It’s for the industry to define what sovereignty means to this administration. But it's obvious that cannot mean entire reliance on one company, one country or all of that," Warman said. "If you were talking about a hypothetical huge British company that were to be just as dominant in the sector as Cisco or whoever, it wouldn't be right to allow them to dictate policy. It has to be about a balanced ecosystem, where there is competition, where there are a range of options, and where people are not necessarily having to go to one player that effectively ends up becoming, if not a monopoly, part of a very small system of players.”
Interestingly, like Baker and Fussa, Warman also thinks today’s sovereignty talk also clouds some basics that may be overlooked among all the hype.
“We want the [players] to be British. Of course we do," Warman said. "But sovereignty is an issue that I think we sometimes imagine is a new thing. We've been dealing with monopolies and overreliance and all of that in industries across the piece for many, many years. Regulators have to step up, but they have to do that in the knowledge of what is realistic and what looks like the kind of approach to competition that promotes new entrants as well."
Comments