Digital Minister Liz Lloyd spoke on cyber security at the New Statesman Security and Resilience Conference on Tuesday 5 May 2026.
https://www.gov.uk/government/speeches/minister-lloyd-cyber-security-speech-at-the-new-statesman
Glossary
1) Cyber Security Breaches Survey 사이버 보안 침해 설문조
2) CyberUK conference 사이버 UK 컨퍼런
3)Code of Practice 실천강령, 실무지
4)Software Vendors 음차
5)The Cyber Bill 사이버 법안
6)Cyber Security and Resilience Bill 사이버 보안 및 회복탄련성 법안
Words: 756
Thank you. It’s a pleasure to be here today.
We are meeting at a moment of genuine uncertainty.
Across the world, the security environment is unsettled. Geopolitical tensions are higher. Conflict is being felt far beyond borders.
And technology – while offering extraordinary opportunity – is increasingly being exploited as a tool of disruption.
In that context, good cyber security is no longer a “nice to have”.
It is foundational to our national security, our economic resilience, and our ability to grow with confidence.
Whether you run a global firm or a growing SME, cyber resilience now shapes whether businesses can operate, innovate, and survive in an increasingly hostile digital environment.
And the message I want to be very clear about today is this:
The cyber threat is getting worse.
And businesses that do not act now are leaving themselves exposed.
The rising cyber threat
The reality is that cyber incidents are becoming more frequent, more disruptive, and more costly.
Attacks that once targeted only a handful of organisations can now cascade rapidly through entire supply chains – bringing operational disruption, financial loss and reputational damage.
Last week we published our latest Cyber Security Breaches Survey, which once again underlines the scale of the challenge.
It shows the scale of the cyber threat remains significant, and widespread:
43% of businesses experienced a cyber breach or attack in the last 12 months
For large firms, this figure rises to 69% and
29% of firms said they suffered attacks at least once per week.
Those numbers matter.
But behind them are disrupted services, frustrated customers, lost time and money, and broken trust – and in the worst cases, businesses that never fully recover.
Which is why this government is clear: cyber resilience is not optional.
AI is accelerating the cyber threat
What makes this moment more urgent is the rapid advancement of artificial intelligence.
AI is transforming how we work, how we grow, and how we compete.
But it is also transforming the cyber threat landscape.
As the Security Minister set out recently at the CyberUK conference, frontier AI capabilities are already being used to:
identify vulnerabilities at scale,
automate reconnaissance,
and lower the barrier to entry for sophisticated attacks.
In plain terms, AI is making it easier and faster to exploit organisations that have not put basic protections in place.
And it will increasingly expose where fundamentals – like patching, access controls, backups and monitoring – have simply not been done.
That reality creates a stark dividing line:
Between those organisations that have invested in cyber resilience, and those that are relying on hope.
The answer is not to slow down innovation.
It is to secure it properly.
Secure by design must be the default
That is why we are clear that technology must be secure by design.
Software, systems and connected devices should not be shipped with known weaknesses. Security cannot be bolted on afterwards, or left to users to fix.
We are already setting expectations through:
the government’s Code of Practice for Software Vendors, and
our Code of Practice for AI Cyber Security, developed with industry and experts.
These codes are pragmatic, actionable, and focused on what works - embedding security at every stage of development.
And my message to tech leaders today is simple:
Building secure technology is not a barrier to growth.
It is what enables trust, adoption and long‑term success.
The Cyber Bill
Of course, while most of our approach is about enabling and supporting organisations to do the right thing, there are areas where government does need to regulate – and that is why we are taking forward the Cyber Security and Resilience Bill.
The Bill strengthens our existing cyber framework to better protect the most essential services the public relies on every day – from energy and transport, to water, health and digital infrastructure.
It focuses regulation where the risks and impact are highest, requiring organisations that underpin our national resilience to have proportionate security measures in place and to report serious incidents, so we can respond more quickly when things go wrong.
But this is a targeted, risk‑based approach. We are not seeking to regulate the whole economy.
For the vast majority of businesses, our approach is deliberately voluntary – setting clear expectations, providing practical guidance and tools, and supporting organisations to raise their cyber resilience in ways that are right for them.
Ultimately, though, government cannot do this alone.
Businesses must take responsibility and act on the guidance available, because resilience is only real when it is put into practice
첫댓글 AI 녹음 특성상 들으실 때 헷갈릴 거 같아서, 11번째 줄 "The rising cyber threat"과 글로서리 5번은 녹음본에 포함시키지 않았습니다. 참고들 부탁드립니다~!