West Midlands Cyber

Regional Cyber Community

From industrial resilience to workforce transformation, activity across the region demonstrates how cyber increasingly intersects with manufacturing, AI, skills, leadership and economic development.

Contents

West Midlands Cyber in Action: Community, Skills and Industrial Resilience

Regional cyber ecosystems are easiest to understand when they are observed in operation rather than described through organisational charts. The important relationships rarely fit neatly within a single institution. Cyber security intersects with technology adoption, industrial transformation, skills, investment, university research, public services and the leadership decisions being made inside organisations throughout the regional economy.

A particularly concentrated example of those relationships was visible in Birmingham in May 2026, when the Tech Transformation Summit, Birmingham City University’s Innovation Fest and an evening supporting Sandwell and West Birmingham NHS charity activity brought different parts of the region’s technology and civic communities together on the same day.

The originating account, Super-Productive WM Cyber Day: Reflections from the Tech Transformation Summit, Innovation Fest and the SWBH NHS Charity Quiz Night, recorded the discussions across those events. Its significance for the West Midlands Cyber Cluster lies less in the diary of the day than in what the conversations collectively revealed: cyber resilience is moving beyond its traditional position as a specialist IT concern and becoming connected with operational continuity, leadership, workforce development, innovation and regional economic resilience.

That shift is particularly important in the West Midlands. The region’s cyber opportunity is not detached from its wider economy. It emerges partly because manufacturers, engineering businesses, healthcare organisations, universities, technology companies, public bodies and SMEs are becoming increasingly dependent on digital systems. The resulting cyber requirements create demand for expertise while making resilience a condition of wider regional competitiveness.

The events of that day therefore provide a useful snapshot of a cyber ecosystem becoming more connected to the economic and institutional environment around it.

See the community in action. The West Midlands Cyber Hub looks at how regional activity is connecting businesses, skills, research, innovation and emerging areas such as AI security, in the companion article “West Midlands Cyber in Action: Community, Skills and Innovation”.

Key Takeaways

  • Cyber resilience is increasingly being discussed as an operational and leadership issue because disruption to digital systems can affect production, services, supply chains and organisational continuity rather than information systems alone.
  • The West Midlands has a distinctive opportunity around industrial cyber resilience because its manufacturing, engineering, logistics and supply-chain economy creates persistent demand for security in operational and digitally dependent environments.
  • Regional cyber capability depends on more than cyber companies. Universities, major technology users, SMEs, investors, public institutions, students and professional communities all contribute different parts of the ecosystem.
  • Skills development becomes more effective when education is connected with employers, practical experience and the changing requirements of organisations adopting AI and other digital technologies.
  • SMEs require accessible routes into cyber support and assurance, particularly as larger customers and regulated organisations place greater emphasis on supply-chain resilience.
  • The value of regional coordination lies in connecting these different forms of demand and capability rather than treating cyber security as a self-contained technology sector.

Cyber Is Moving into the Operational Conversation

One of the clearest themes across the Tech Transformation Summit was the changing position of cyber security within organisational leadership.

For many years, cyber could be treated primarily as a technical function. Security teams protected networks and devices, IT departments managed systems, and senior leaders often encountered cyber principally through compliance, audit or the aftermath of an incident.

That separation has become increasingly difficult to maintain.

Organisations now depend on digital infrastructure for ordinary operations. Manufacturing requires production planning, industrial control, engineering systems and digital supply chains. Healthcare depends on clinical and administrative technology. Logistics relies on interconnected data and communications. Universities operate extensive digital environments supporting research, education and administration. Even relatively small businesses can depend heavily on cloud platforms, online payments, customer databases and external technology providers.

Cyber disruption consequently crosses organisational boundaries very quickly.

A ransomware incident affecting a manufacturer can become a production problem. Compromise of a technology supplier can become a customer problem. Loss of access to a critical cloud service can become a business-continuity problem. An incident affecting healthcare systems can interfere with service delivery.

The implication is not that every operational risk is fundamentally a cyber risk. It is that digital dependency has become sufficiently extensive that cyber resilience must be considered alongside the other conditions required for organisations to continue operating.

This changes the leadership conversation. Boards and senior managers need to understand not only whether security controls exist, but which digital dependencies are critical, how disruption would affect operations and whether the organisation can recover within acceptable timescales.

Cyber resilience therefore becomes part of operational governance.

Resilience Depends on Organisational Capability, Not Awareness Alone

The source discussion also highlighted a distinction that is easily lost in conversations about cyber culture: awareness is necessary, but it is not equivalent to resilience.

Employees can understand that phishing is dangerous while an organisation still lacks effective authentication. Senior leaders can recognise cyber as important while formal incident planning remains weak. Policies can exist without being reflected consistently in operational practice.

The 2025/26 Cyber Security Breaches Survey illustrates this gap nationally. Seventy-two per cent of businesses said cyber security was a high priority for senior management, yet only 30% had undertaken a cyber risk assessment during the previous 12 months and only 25% had a formal incident-response plan.

Those figures describe different levels of maturity. Leadership attention establishes the conditions for action, but resilience depends on whether that attention is converted into risk assessment, technical controls, governance, exercising and recovery capability.

Culture matters because implementation occurs through ordinary organisational behaviour.

Security requirements that continually conflict with operational incentives are likely to be bypassed. Incident plans that exist only as documents are unlikely to perform well under pressure. Employees who fear blame may delay reporting mistakes. Operational teams excluded from security decisions can encounter controls that do not reflect how systems are actually used.

A mature cyber culture therefore involves more than awareness campaigns. It aligns leadership behaviour, technical controls and operational practice sufficiently well that security becomes part of how the organisation functions.

That is why cyber increasingly belongs within discussions about organisational transformation rather than being treated as an isolated technical programme.

AI Makes the Relationship Between Transformation and Resilience More Important

Artificial intelligence was another recurring theme across the day’s discussions.

Organisations are experimenting with generative AI, automation and data-driven tools while simultaneously trying to understand the governance, workforce and security implications of adoption. The pace of experimentation creates an important tension: the economic pressure to exploit new capability can move faster than the organisational mechanisms required to manage the dependencies being created.

This is not an argument for slowing innovation indiscriminately.

It is an argument for treating secure adoption as part of successful adoption.

AI systems can introduce questions concerning access to data, external model providers, intellectual property, authentication, model behaviour and the integrity of automated outputs. Organisations also need to understand where employees are using AI services outside formally approved environments and what information may consequently be leaving organisational boundaries.

The UK’s cyber market is already responding. The 2026 Cyber Security Sectoral Analysis identified 111 firms explicitly offering security capability relating to AI, compared with 66 previously, an increase of 68%.

That growth indicates rapidly developing supply, but the business-adoption picture remains less mature. The 2025/26 Breaches Survey found that 31% of businesses were using, adopting or considering AI, while only 24% of that group reported cyber-security practices specifically addressing AI risks.

The comparison suggests that technology adoption and security adaptation are not necessarily proceeding at the same rate.

For a regional technology economy, this matters because successful digital transformation should increase productive capability without creating unmanaged dependencies that subsequently undermine it.

Cyber expertise therefore needs to sit closer to the adoption process.

The West Midlands Opportunity Is Shaped by Its Industrial Economy

The West Midlands should not assume that a successful regional cyber ecosystem needs to resemble those found elsewhere in the UK.

Different regions possess different economic structures and institutional anchors. The West Midlands’ strongest proposition arises from the interaction between cyber capability and its wider industrial economy.

Manufacturing, engineering, mobility, aerospace, logistics and interconnected supply chains create substantial dependence on digital systems. Production environments increasingly incorporate connected machinery, software, remote access, cloud services, sensors and data-driven processes.

That creates security requirements extending beyond conventional corporate IT.

Operational technology needs to remain available and safe. Engineering information requires protection. Remote access needs to be controlled. Suppliers need appropriate assurance. Incident-response plans need to account for production consequences as well as compromised computers.

The UK cyber provider market indicates that specialist industrial capability remains a relatively small part of the wider sector. DSIT’s 2026 analysis associates 7% of providers with SCADA or industrial-control-system security, while its analysis of company websites identifies industrial or OT security among approximately 10% of offerings.

For the West Midlands, that creates an opportunity grounded in actual customer demand.

Regional cyber companies can develop expertise against the requirements of manufacturers and other industrial organisations. Universities can research problems emerging from those environments. Students and practitioners can acquire specialist experience. Customers gain access to relevant capability while providers develop evidence and intellectual capital that can subsequently be sold beyond the region.

This is a more durable basis for regional specialisation than simply attempting to increase the number of businesses carrying a cyber label.

Supply-Chain Resilience Connects Large Organisations and SMEs

Industrial cyber resilience cannot be considered solely at the level of individual organisations because production and service delivery increasingly depend on interconnected suppliers.

The cyber maturity of those suppliers varies substantially.

National evidence from the 2025/26 Breaches Survey shows that 48% of large businesses reviewed cyber risks associated with their immediate suppliers, compared with 30% of medium-sized businesses, 22% of small businesses and 12% of micro businesses.

Only 15% of businesses overall reviewed immediate supplier risks, while 6% considered the wider supply chain.

These figures do not demonstrate the maturity of West Midlands supply chains specifically, but they reveal an important national challenge for a region whose economy contains extensive networks of smaller industrial businesses.

A supplier does not need to be large to be operationally important.

A specialist engineering company may provide a component that is difficult to replace. A small managed service provider can hold privileged access to several customers. A software supplier can support a process used across multiple organisations. The consequence associated with compromise can therefore exceed what might be inferred from turnover or employee numbers.

Larger organisations increasingly respond by imposing assurance requirements on suppliers.

This can improve resilience, but it can also create barriers where smaller businesses lack the expertise or capacity to interpret what customers require. Regional support becomes valuable when it helps those businesses move from generic awareness towards proportionate, demonstrable capability.

The objective should be stronger supply chains rather than merely more compliance activity.

Cyber Essentials Provides a Baseline, Not an Endpoint

Cyber Essentials featured in the source discussion as one of the practical mechanisms available to organisations seeking a clearer starting point for cyber improvement.

Its value lies partly in simplicity. The scheme concentrates on a defined set of technical controls and provides a recognised mechanism through which organisations can demonstrate implementation.

National adoption remains limited but is increasing. The 2025/26 Breaches Survey found that 5% of businesses held Cyber Essentials certification, up from 3% in the previous year. Among small businesses the proportion increased from 5% to 12%, while large-business certification rose from 21% to 35%.

Certification should nevertheless be understood in proportion to risk.

Cyber Essentials establishes a useful technical baseline; it is not a complete resilience model for every organisation. A manufacturer operating complex production technology, a managed service provider with privileged customer access and a microbusiness using standard cloud services have different dependencies and consequences.

Their security requirements should therefore progress differently.

This is where practical regional guidance can improve outcomes. Businesses need help understanding which baseline controls should be established first, what customer or regulatory requirements apply, and when their operational risk justifies more extensive governance, assurance or technical capability.

The progression route matters more than promotion of any single framework.

SMEs Need Navigable Support More Than Additional Complexity

The source account emphasised a recurring issue in regional cyber discussions: smaller businesses frequently face constraints of time, expertise and management bandwidth rather than a simple absence of concern about cyber security.

A small organisation may know that security matters while struggling to determine what should be done first.

The market does not always make that decision easier. SMEs encounter government guidance, certification schemes, commercial providers, insurers, customer questionnaires and regulatory information, often using different terminology and addressing different levels of maturity.

The result can be paralysis rather than action.

Regional infrastructure can add value by making the route through that landscape easier to navigate.

The West Midlands Cyber Resilience Centre, Cyber Advisor services, the West Midlands Cyber Hub and other regional and national mechanisms can perform different functions within that journey. The objective should not be to force businesses through every available programme. It should be to identify the problem, direct the organisation towards proportionate support and make progression easier.

For one business, the immediate requirement may be Cyber Essentials. Another may need an incident-response exercise. A manufacturer may require specialist OT assessment. A growing supplier may need help interpreting the security requirements of a major customer.

This is one reason a functioning ecosystem matters. No single organisation needs to provide every service if businesses can move between appropriate sources of capability without having to reconstruct the support landscape themselves.

Universities Are Part of the Regional Cyber Economy

Birmingham City University’s Innovation Fest provided a different perspective on the same ecosystem.

Universities are sometimes treated principally as suppliers of graduates to the cyber labour market. That is important, but it understates their economic role.

They generate research, provide specialist expertise, support entrepreneurship, operate technical facilities and bring together disciplines that commercial organisations may encounter separately. They also create environments in which students can work on problems before entering employment.

For cyber security, these functions are increasingly valuable because the field itself is becoming more interdisciplinary.

Operational resilience requires understanding of technology and business processes. Industrial cyber combines engineering with security. AI security draws on software, data science, governance and risk. Online harms intersect with behavioural research, safeguarding, digital forensics and policy.

The relationship between universities and the regional cyber economy should therefore extend beyond recruitment fairs.

Businesses can provide research questions and real-world problems. Universities can contribute technical investigation and experimentation. Students can obtain practical exposure. Research can generate intellectual property, policy evidence or commercial opportunities.

Innovation Fest illustrated the wider environment from which these connections can emerge. The strategic task is ensuring that interaction persists after individual events.

The Skills Challenge Is Increasingly About Experience and Relevance

The UK’s cyber skills problem has also become more nuanced.

The 2025 cyber labour-market research estimated the annual workforce shortfall at approximately 3,800 people, compared with 3,500 the previous year and 11,100 in 2023. At the same time, employers continued to report substantial technical skills gaps.

Demand for entry-level candidates has weakened relative to demand for experience. The proportion of core cyber job postings seeking candidates with less than one year’s experience declined from 25% in 2022 to 22% in 2023 and 17% in 2024. Around 63% of postings sought candidates with between two and six years of experience.

This creates a progression problem.

Universities and training providers can produce capable entrants, but employers often want evidence that candidates can operate in real organisational environments. Candidates cannot acquire that evidence without opportunities to work on realistic problems.

Regional ecosystems can help reduce that gap through placements, internships, mentoring, industry projects, cyber exercises and stronger relationships between practitioners and education providers.

The content of experience also matters.

A region seeking to build capability around industrial cyber resilience needs people exposed to manufacturing environments, operational technology and supply-chain assurance. Generic cyber education provides a foundation, but specialist regional capability develops when people encounter the operational contexts in which security is being applied.

Skills strategy should therefore follow regional demand rather than treating cyber employment as homogeneous.

Workforce Diversity Expands the Available Capability Base

The source discussions also addressed participation by women, neurodivergent people and those entering cyber through non-traditional routes.

The economic case for widening participation is straightforward. A sector concerned about skills availability weakens itself if recruitment practices unnecessarily restrict the population from which capability can emerge.

There is also a substantive relationship between cyber work and cognitive diversity.

Security teams perform activities including systems analysis, investigation, pattern recognition, communication, governance, adversarial reasoning and incident coordination. These tasks do not require a single cognitive or professional profile.

Likewise, the increasing interaction between cyber and operational environments creates demand for people arriving from engineering, risk, law, policing, behavioural science and other disciplines as well as traditional computing pathways.

Diversity should not be reduced to an assumption that particular demographic or neurological groups possess predetermined abilities. Individuals vary considerably.

The stronger principle is that cyber capability benefits from multiple routes into the profession and recruitment systems capable of recognising relevant ability where it exists.

For the West Midlands, universities, colleges, employers and professional communities can make those routes more visible and provide the practical experience through which entrants become established practitioners.

Investment Needs to Follow Commercial Capability

The day’s conversations also extended into investment, including discussion of the West Midlands Co-Investment Fund and the broader requirements of regional technology businesses.

Investment is relevant to cyber ecosystem development because technically capable businesses do not scale automatically.

Companies need customers, management capability and commercial evidence before capital can be deployed effectively. The national financing environment has also become more selective: dedicated UK cyber firms raised £184 million across 47 investment deals during 2025, down from £206 million across 59 deals in 2024.

For regional cyber companies, this reinforces the importance of customer access.

The West Midlands’ wider industrial economy can provide an advantage if emerging cyber firms can reach organisations with genuine security requirements. A successful deployment with a demanding manufacturer can produce revenue, technical evidence and a customer reference. Those assets strengthen a company’s subsequent commercial and investment proposition.

Regional coordination should therefore connect investment with the rest of the ecosystem rather than treating it as an independent workstream.

A company becomes more investable when the surrounding system helps it acquire the evidence required to justify investment.

Cyber Resilience Is Becoming Part of Regional Economic Resilience

The most important lesson from the day’s activity was the convergence between conversations that might previously have been treated separately.

Leadership discussions concerned organisational adaptation and trust. Cyber discussions concerned operational continuity. AI discussions concerned technology adoption and governance. Innovation Fest concerned research, entrepreneurship and future capability. SME conversations concerned practical support and assurance. Investment discussions concerned the ability of regional companies to progress.

Cyber security sits across all of them because digital dependency connects them.

That does not mean every regional technology initiative should become a cyber initiative. It means that security and resilience increasingly influence whether wider technology adoption succeeds.

A manufacturer cannot obtain the full productivity benefit of connected production if the resulting systems create unacceptable operational exposure. An SME cannot participate confidently in increasingly demanding supply chains if it cannot demonstrate proportionate cyber maturity. AI adoption cannot be considered complete if organisations have not addressed the security of the data, systems and providers on which that adoption depends.

Cyber capability consequently has value beyond the revenue generated by the cyber sector itself.

It protects and enables activity elsewhere in the economy.

For the West Midlands, whose competitive strengths include sectors becoming rapidly more digitally dependent, that enabling role is economically significant.

A Regional Ecosystem Becomes Visible Through Its Connections

A busy day of summits, university innovation activity and civic events does not by itself demonstrate the existence of a mature cyber cluster.

What it can reveal is the density of relationships from which one can develop.

The Tech Transformation Summit brought technology leadership, cyber resilience, AI, investment and organisational change into the same conversation. Birmingham City University’s Innovation Fest connected that discussion with students, research and entrepreneurship. Wider participation from businesses, practitioners, public organisations and regional institutions demonstrated that cyber capability increasingly extends beyond a narrowly defined security profession.

The strategic opportunity is to turn those encounters into persistent relationships.

Cyber companies need access to customers. Industrial organisations need specialist expertise. SMEs need navigable routes into support. Universities need connections with operational problems. Students need experience and employment pathways. Investors need credible companies. Regional institutions need evidence about where the system is working and where organisations continue to encounter barriers.

The West Midlands Cyber Cluster can add value where it makes those connections easier without attempting to own every part of the system.

That is the distinction between activity and ecosystem development.

The events of May 2026 provided a useful snapshot of a region in which cyber, technology, industry, education and economic development are increasingly intersecting. The opportunity now is to ensure that those intersections become part of the ordinary operation of the regional economy rather than exceptional moments created by a particularly busy day.

If that happens, the West Midlands’ cyber proposition will be grounded in something more substantial than sector promotion. It will be visible in the relationships between organisations adopting technology, businesses providing specialist capability, universities developing knowledge, people building careers and industries whose resilience increasingly depends on all of them working together.