National cyber strategy ultimately has to be implemented by organisations. Regional clusters can provide the connective infrastructure between policy, providers, skills, research and businesses that need support.
Contents
- Contents
- The Missing Layer in UK Cyber Strategy: Regional Capability Infrastructure
- Key Takeaways
- National Policy Operates at a Different Scale from Business Implementation
- Business Capability Remains Highly Uneven
- Regional Infrastructure Can Reduce the Translation Gap
- Industrial Economies Create a Specific Coordination Problem
- Supply-Chain Assurance Makes Capability an Economic Requirement
- Skills Need to Be Connected to Operational Demand
- Cyber Firms Need Progression Infrastructure as Well as Startup Support
- Regional Capability Needs a Clear Division of Labour
- Regional Infrastructure Should Be Judged by Outcomes
The Missing Layer in UK Cyber Strategy: Regional Capability Infrastructure
The United Kingdom has developed an increasingly sophisticated national cyber architecture. Government sets policy and regulation, the National Cyber Security Centre provides technical leadership and guidance, regulators oversee higher-consequence sectors, universities contribute research and skills, and a substantial commercial cyber sector supplies products and services. At the other end of the system sit millions of organisations expected to translate that national capability into practical resilience.
The difficulty is that the connection between those two levels remains uneven. National institutions can establish standards, publish guidance and identify threats, but implementation takes place inside businesses whose resources and expertise vary considerably. The 2025/26 Cyber Security Breaches Survey illustrates the resulting gap: while 72% of businesses regarded cyber security as a high priority for senior management, only 30% had conducted a cyber risk assessment during the previous year, 25% had a formal incident-response plan and 15% reviewed cyber risks associated with immediate suppliers.
The originating analysis, CYBERUK 2026: The Missing Layer Between Strategy and Execution — Regional Capability Infrastructure, argued that this is partly an infrastructure problem. Between national policy and individual organisational implementation sits a regional layer through which businesses can access expertise, skills, assurance, research, investment and specialist suppliers. The argument is not that every cyber function should be regionalised, nor that regional organisations should reproduce the work of the NCSC. It is that national capability is more likely to influence organisational behaviour where institutions exist to translate common frameworks into the economic and operational circumstances in which businesses actually work.
For the West Midlands, the proposition is especially relevant because cyber requirements intersect with a large and varied productive economy. Manufacturers, engineering companies, technology providers and their supply chains operate at very different levels of cyber maturity while becoming increasingly dependent on connected systems, external technology services and customer assurance requirements. Regional cyber capability therefore has a potential role not as another tier of policy, but as part of the infrastructure through which national policy becomes usable.
What does this mean for your business? The West Midlands Cyber Hub explains why regional support matters and how businesses can benefit from easier access to cyber expertise, programmes and trusted networks, in the companion article “Why Businesses Need Regional Cyber Support”.
Key Takeaways
- National cyber capability does not automatically produce organisational resilience: in 2025/26, only 30% of businesses conducted a cyber risk assessment and 25% had a formal incident-response plan despite 72% describing cyber security as a high management priority.
- The implementation gap is strongly associated with organisational scale, with formal incident-response plans ranging from 21% of micro businesses to 76% of large businesses.
- Regional cyber infrastructure can perform functions that neither national institutions nor individual businesses can efficiently provide alone, particularly around translation, specialist access, skills, assurance and connections between cyber supply and local demand.
- The West Midlands case is strengthened by the interaction between cyber security and industrial supply chains, where smaller suppliers increasingly need to meet requirements established by larger customers.
- Regional capability should be judged by measurable changes in organisational and economic outcomes rather than the number of programmes, organisations or events operating under a regional cyber banner.
National Policy Operates at a Different Scale from Business Implementation
The UK’s national cyber system performs functions that require national coordination. The NCSC assesses threats, responds to significant incidents, develops technical guidance and supports the security of nationally important systems. Government establishes legislation and policy, while regulators apply requirements in sectors where cyber failure could create wider economic or societal consequences.
The Cyber Security and Resilience Bill illustrates the direction of travel. Introduced in November 2025, it is intended to expand and strengthen the UK’s Network and Information Systems regime, bringing additional organisations into scope, increasing regulatory powers and introducing enhanced incident-reporting requirements. Government estimates that approximately 1,000 additional organisations would come directly within the regulatory framework.
These interventions can establish minimum expectations and improve visibility of serious cyber risk, but legislation does not implement itself. An organisation subject to incident-reporting requirements needs the technical and organisational capability to detect an incident, assess its consequences, determine whether the threshold has been met and provide information while simultaneously managing the event. A supplier asked to achieve Cyber Essentials needs to translate the standard into configuration changes across its actual technology estate.
The distance between specifying an outcome and delivering it becomes greater as organisations become smaller or their technology becomes more specialised. National institutions cannot reasonably provide bespoke implementation support to every SME, while individual businesses cannot each reproduce the expertise available within national bodies or large enterprises. The resulting gap is structural rather than simply informational.
Business Capability Remains Highly Uneven
The Cyber Security Breaches Survey provides evidence of how pronounced that implementation gap can be. Although basic technical measures are relatively widespread, formal management practices remain much less common. In 2025/26, 81% of businesses reported up-to-date malware protection, 74% used secure cloud backups and 74% had password policies. By comparison, only 30% had conducted a cyber risk assessment and 27% had a formal cyber security strategy.
Organisational size produces an even clearer distinction. Formal incident-response plans were reported by 21% of micro businesses, compared with 57% of medium-sized businesses and 76% of large businesses. Board-level responsibility for cyber security reached 68% among large organisations, while immediate supplier cyber risk was reviewed by 48% of large businesses but only 12% of micro businesses and 22% of small businesses.
These figures do not demonstrate that every smaller business requires enterprise-level security capability. Proportionality remains essential: a ten-person business with conventional cloud applications has different requirements from a nationally significant operator. The problem arises where economic dependencies connect organisations whose capabilities differ substantially.
A small engineering supplier may not warrant a large internal security team, for example, but it may hold commercially sensitive information, access customer platforms or provide a component whose interruption affects production elsewhere. Its cyber requirements are consequently shaped partly by its position within a wider system rather than by its headcount alone.
This is where implementation becomes difficult. The business needs enough capability to understand what level of security is proportionate, which customer requirements apply, when specialist support is necessary and how to demonstrate that appropriate controls have been implemented.
Regional Infrastructure Can Reduce the Translation Gap
Regional cyber organisations are sometimes understood principally as mechanisms for networking, promotion or sector representation. Those functions can be useful, but they do not by themselves establish a compelling economic rationale for regional cyber infrastructure.
A stronger rationale comes from translation. National frameworks are necessarily general because they must operate across sectors and geographies. Implementation problems are specific: a manufacturer needs to understand how identity controls interact with remote maintenance; a smaller supplier may need help meeting a customer’s assurance requirements; a growing cyber company needs access to customers against which its technology can be validated.
Regional infrastructure can reduce the distance between those general frameworks and specific operating environments by connecting organisations with the capability required to act. That may involve specialist providers, universities, training organisations, certification support, peer networks or larger companies able to articulate supply-chain requirements.
The distinction from conventional business support is important. Cyber security frequently requires trust, specialist judgement and understanding of operational context. A business seeking help with industrial control systems, incident preparation or customer assurance cannot always use generic digital support interchangeably with specialist cyber expertise.
The value of a regional layer therefore lies partly in reducing search and coordination costs. Businesses do not need every capability to exist within one institution; they need a credible mechanism for finding the right capability and understanding how it relates to their problem.
Industrial Economies Create a Specific Coordination Problem
The West Midlands provides a particularly relevant test because its cyber requirements are closely connected to industrial activity. Manufacturing and engineering businesses increasingly depend on enterprise IT, cloud platforms, operational technology, remote support, software and digitally coordinated suppliers. These systems create dependencies that cross conventional organisational and technical boundaries.
Industrial cyber capability also remains relatively specialised nationally. DSIT’s 2026 Cyber Security Sectoral Analysis identifies 2,603 firms active in the UK cyber market, but SCADA and industrial-control-system security is associated with only 7% of firms. A separate analysis of providers’ web offerings identifies industrial and operational technology security among 10% of suppliers, compared with 63% offering security consulting and advisory services and 62% offering governance, risk and compliance services.
The figures do not demonstrate a shortage of industrial cyber capability in the West Midlands specifically, because the national analysis does not provide sufficient regional detail to support that conclusion. They do show that industrial cyber is a specialist segment within a much broader security market.
That distinction creates a coordination problem for an industrial region. Demand can exist within manufacturers and infrastructure operators without being easily visible to cyber providers, while specialist suppliers may struggle to identify customers prepared to test or procure their capabilities. Universities can possess relevant research expertise without a straightforward route into commercial deployment. Smaller manufacturers may recognise a cyber problem without knowing whether it requires a general security provider, an OT specialist or changes to operational processes.
Regional infrastructure can help connect these elements, but its purpose should be defined in terms of solving those coordination failures rather than simply increasing regional cyber activity.
Supply-Chain Assurance Makes Capability an Economic Requirement
The need for coordination becomes more pronounced as cyber expectations move through procurement. Large organisations increasingly use contractual requirements, questionnaires, certifications and supplier assessments to manage risks beyond their own organisational boundary.
The Breaches Survey shows that this process remains incomplete. Only 15% of businesses reviewed cyber risks associated with immediate suppliers in 2025/26 and 6% examined their wider supply chain. Large businesses were substantially more active, with 48% assessing immediate supplier risks.
As larger organisations increase scrutiny, smaller suppliers can face requirements that originate from customers rather than regulators. Cyber Essentials provides one established mechanism for demonstrating baseline controls, and certification has begun to increase: 5% of businesses held Cyber Essentials in 2025/26, compared with 3% the previous year, while the rate among small businesses increased from 5% to 12%.
This creates a direct connection between cyber capability and regional competitiveness. A supplier that cannot satisfy a proportionate security requirement may find access to particular contracts restricted even where its underlying product or service remains competitive. Conversely, businesses able to demonstrate appropriate security may be better positioned within supply chains where assurance is becoming a routine part of procurement.
Regional cyber infrastructure can help make that process more efficient by improving understanding of assurance requirements and connecting businesses with credible routes to implementation. It should not weaken customer standards or create competing regional certifications. The objective is to reduce unnecessary friction between the requirement and the supplier’s ability to satisfy it.
Skills Need to Be Connected to Operational Demand
Cyber skills are another area where national supply and organisational demand do not connect automatically. A region can contain universities producing technically capable graduates while employers simultaneously report difficulty recruiting people with the experience required for particular roles.
The problem is partly one of occupational breadth. Cyber security encompasses governance, incident response, security engineering, operational technology, architecture, assurance, testing, product development and numerous other specialisms. Aggregate measures of cyber vacancies or graduate numbers therefore provide only a partial indication of whether the labour market is producing the right capability.
Regional coordination can improve the quality of that signal. Employers can articulate emerging requirements to universities and training providers; students can gain exposure to real operational problems; and specialist pathways can develop around areas where regional demand is sufficiently concentrated.
For the West Midlands, industrial cyber provides one possible example. If regional employers demonstrate sustained demand for OT security, secure industrial systems or supply-chain assurance, that evidence can inform curriculum development, professional training and research collaboration. Without a mechanism for aggregating demand, individual signals may remain too fragmented to influence provision.
This does not mean skills planning should attempt to predict every future cyber role. The more realistic objective is to shorten the feedback loop between employers, educators and practitioners so that capability can adapt as regional demand becomes clearer.
Cyber Firms Need Progression Infrastructure as Well as Startup Support
The supply side of the regional cyber economy creates a related challenge. The UK sector is growing: DSIT estimates that 2,603 cyber firms generated £14.7 billion in revenue and £9.1 billion in gross value added in the latest analysis. The number of firms earning more than £10 million annually from cyber activity has increased to 241, from 105 two years earlier.
That national progression does not guarantee equivalent regional development. Smaller cyber companies need more than formation support if they are to become sustainable providers. Technical products and services have to be validated with customers, adapted to procurement requirements, converted into recurring commercial relationships and, where appropriate, supported by investment.
The funding environment makes those commercial routes more significant. Dedicated cyber firms raised £184 million across 47 investment deals in 2025, down from £206 million across 59 deals in 2024, continuing the decline from the investment peak reached in 2022.
Regional infrastructure can therefore perform an economic-development function by connecting cyber companies with demand rather than concentrating exclusively on startup creation. For an industrial region, customer validation with manufacturers, engineering businesses or infrastructure operators can be particularly valuable because it provides evidence that a product or service works within demanding operational environments.
The objective should be progression: moving capable providers from early technical development towards reference customers, repeatable sales and sustainable scale.
Regional Capability Needs a Clear Division of Labour
The case for regional infrastructure weakens if it simply duplicates functions already performed nationally. A coherent model requires a clear division of labour.
Threat assessment, national incident coordination, authoritative technical guidance and national standards benefit from central consistency. Creating regional alternatives to those functions would risk fragmentation and unnecessary complexity. Regional organisations are better placed to address problems where proximity, relationships and understanding of the local economy materially improve delivery.
That includes identifying sector-specific demand, connecting businesses with trusted expertise, supporting adoption of national standards, strengthening employer-education relationships, facilitating commercial validation and helping smaller organisations navigate assurance requirements.
Universities, cyber companies, local government, economic-development organisations and business networks can each contribute different capabilities, but the existence of multiple organisations is not itself evidence of an effective system. Without coordination, regional ecosystems can reproduce the same fragmentation they are intended to solve.
The relevant design question is therefore not how many cyber initiatives a region possesses, but whether an organisation with a defined problem can move efficiently from identifying that problem to accessing appropriate support and demonstrating an improved outcome.
Regional Infrastructure Should Be Judged by Outcomes
Treating regional cyber capability as infrastructure imposes a higher standard than treating it as community activity. Infrastructure should change what the economy is capable of doing.
For the West Midlands, useful measures would therefore extend beyond event attendance, membership numbers or the volume of organisations participating in programmes. Evidence of impact could include increased adoption of recognised assurance among regional suppliers, improvements in incident preparedness, stronger progression of cyber SMEs into larger revenue bands, greater procurement between regional cyber providers and industrial customers, improved access to specialist OT capability, or demonstrable reductions in particular skills gaps.
Not all of these outcomes can currently be measured reliably at regional level. That is itself an evidence problem worth addressing. National datasets provide substantial information about business cyber maturity and the cyber sector, but regional analysis remains comparatively limited, particularly where cyber capability is embedded within companies whose primary business lies outside the cyber sector.
The West Midlands therefore needs to avoid two unsupported conclusions. The first is that national cyber capability will naturally diffuse through the regional economy without deliberate implementation mechanisms. The second is that creating regional institutions automatically solves the problem.
The more defensible proposition sits between them. National policy provides common direction, standards and specialist capability; organisations ultimately produce resilience through implementation; and regional infrastructure can reduce the friction between those levels where local economic structure, specialist demand and organisational scale make direct translation difficult.
If that regional layer is functioning effectively, its impact should eventually be visible not in the prominence of the infrastructure itself, but in the capability of the organisations and cyber businesses that no longer encounter the same barriers because it exists.