Vulnerabilities

UK National Cyber Action Plan Delayed

July 3, 2026 04:01 · 12 min read
UK National Cyber Action Plan Delayed

The UK's National Cyber Action Plan, a forthcoming strategy for defending the economy against state-backed and criminal hacking, has been delayed again following Prime Minister Keir Starmer's resignation, according to multiple sources with knowledge of the matter.

Background

The plan had been due for publication on Monday, but its launch has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July 9. A government spokesperson told Recorded Future News that it remained committed to publishing the National Cyber Action Plan, emphasizing that protecting national security is its first duty.

“Protecting national security is our first duty, which is why we're taking action: strengthening our defenses through the Cyber Security and Resilience Bill, improving businesses' security with the national Cyber Resilience Pledge, and providing expert support to organizations across the country every day through the National Cyber Security Centre,” the spokesperson said.

Cyber Resilience Pledge

One part of the launch is still expected to proceed, with a number of FTSE 350 companies set to sign the government's Cyber Resilience Pledge on Tuesday. The pledge is a voluntary commitment to improve digital defenses, and companies that sign up will be required to make cybersecurity a board-level responsibility, join the NCSC's Early Warning service, and require Cyber Essentials certification across their supply chains.

Delays and Concerns

The delay is likely to contribute to ongoing concerns that cybersecurity remains a low political priority within Westminster. The National Cyber Action Plan is the latest enterprise in the British government’s cyber policy program to be delayed due to what some fear is political disinterest.

The Cyber Security and Resilience Bill, an update to the country's critical-infrastructure cyber laws, took more than four years to reach Parliament and is now not expected to be enforced until 2028. The core provisions of the CSRB had already been completed back in 2022 under Rishi Sunak, but the bill was delayed again amid a cabinet reshuffle.

Expert Insights

Tim Stevens, who leads the cybersecurity research group at King's College London, said cyber had “always been a de-politicized” issue in Britain, treated as “low politics.” He added: “Once you make it a political issue, if you don't fix it, it can come back and bite you on the ass.”

Jamie MacColl, a research fellow at the Royal United Services Institute, said that until there is a major incident, cybersecurity is just not going to get the coverage or the political will it deserves.

National Cyber Action Plan Contents

The plan’s contents have not been officially disclosed, but Recorded Future News understands it will include three pillars focusing on Threat, Growth, and Resilience. The clearest public indication of the government’s approach came in a lecture to the Royal United Services Institute (RUSI) in June by the NCSC’s chief executive Richard Horne, who called for a full court press across what he termed the “near, mid, and far spaces” of cyberspace.

Horne defined the near space as the defense of individual organizations, the far space as offensive action against adversaries, and the “mid space” as the shared “cloud, technology, and telecommunications infrastructure,” most of which he said was “in private hands.” He said the government would partner with providers to “harden the mid space and disrupt attacker activity.”

The NCSC handled more than 200 incidents affecting critical national infrastructure and its supply chain between June 2024 and May 2026, with 75% of them linked to state actors. The National Cyber Defense Capability aims to “join up intelligence and actions in the far, mid, and near space in real time” in what Horne called “an agentic AI world.”

Conclusion

The delay of the National Cyber Action Plan is a significant setback for the UK's cybersecurity efforts, and it remains to be seen how the government will prioritize this issue in the coming months. The Cyber Resilience Pledge and the National Cyber Defense Capability are important steps towards improving the country's cybersecurity, but more needs to be done to address the ongoing threats and challenges in this area.


Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free