Connect with us

Infosecurity

Britain’s Next War Won’t Be an Away Game: A Q&A with the Former Head of Defence Intelligence

Published

on

Britain's next war

A Warning from the Shadows

General Sir Jim Hockenhull spent a career inside Britain’s military intelligence establishment. Yet he might be best remembered for giving secrets away.

As Chief of Defence Intelligence from December 2018 to May 2022, he made the call to declassify and publish London’s knowledge of Russia’s invasion plans—down to a map of the routes its forces would take. The goal was to expose the Kremlin’s intentions before Moscow could manufacture a pretext. The move is now widely seen as a success, though Hockenhull admits that when he first proposed it, almost no one in government thought it was a good idea.

Now out of uniform since June, he’s speaking with a new urgency. His message is blunt: Britain’s next war won’t be an away game. It will be fought at home, in cyberspace, and on the information front—long before any tanks roll.

The One Man Who Said Yes

In 2023, at Recorded Future’s Predict conference, Hockenhull revealed that only one person had backed his radical plan to publish intelligence. That person was Ben Wallace, the then-Defence Secretary.

“I was lucky it was him,” Hockenhull says now.

Bureaucracy, he explains, is designed to manage risk. “People tend not to say yes or no to anything. They’ll say, ‘that’s an interesting idea,’ and then ask lots of questions. If you’re not careful, you screen out the things that could be really good but are quite risky.”

Wallace was different. He understood intelligence from his time as security minister, and he was willing to take big decisions. “If you went to him with a reasoned argument, he’d back you. That’s why, with one person, we got it through.”

From Ultra to Open Source

The contrast with the Second World War is stark. Britain went to extraordinary lengths to conceal intelligence sources like Ultra. In 2022, Hockenhull made the opposite choice.

He sees it as a continuum. “It’s all the use of intelligence,” he says. The question is which direction you go, because once you commit, you’re committed. The first release on Feb. 17, 2022, showed the axes of Putin’s invasion plan. But it couldn’t be a one-off. A discrete team was set up to work out what could be shared publicly without compromising sources and methods.

The public releases were only part of a wider effort. For a long time, London didn’t make clear it was also sharing a great deal with the Ukrainians. “The conflict is broader than what happens on the ground. It’s in the information space, and it always has been.”

The arrival of the iPhone changed everything, he argues. “Suddenly everybody’s consuming information in a fundamentally different way. This was our first attempt to recognize that we’re in a modern digital era of communication.”

Deterrence Is Stuck in the 1950s

Who was the disclosure aimed at? All of them—the British public, allies, Ukraine, and Russia. The emphasis shifted over time.

“We wanted the British public to understand that a war was coming in Europe, that it was a long-planned Russian effort,” he says. The playbook was familiar—Georgia in 2008, Ukraine in 2014, Syria in 2016—but it had never been contested in advance.

That raises a wider question about deterrence. “We often revert to nuclear deterrence theory of the 1950s,” Hockenhull says. “But in the modern age, how do we use our insight, our knowledge dominance, to deter our adversaries?”

The key is that these aren’t psychological operations. “This is using the truth to let people know the real situation before Russian falsehoods take hold, because once a lie is established, it gains a life of its own and is almost impossible to kill.”

The Limits of Intelligence

Many assessments suggested Kyiv would fall quickly. It didn’t. Does that complicate the idea that 2022 was an intelligence success?

Hockenhull is candid. “The key insight we had was understanding the Russian plan for Kyiv to fall in five to seven days. What we understood less clearly was how Ukraine intended to fight.” The Ukrainians were loath to share their plans with anyone, sometimes even among themselves.

About a week before the invasion, his team wrote an assessment highlighting Russia’s weaknesses: an operation at a scale not attempted since WWII, logistics not well supported, a reliance on very quick success, challenging command and control, questionable morale, poorly trained conscripts. “What we didn’t imagine was that Russia would fall over all of them simultaneously.”

There’s a deeper point here. “When you use intelligence, you change the situation. By informing the people mounting the operations, they act on it, and that changes the context being assessed.” In other words, part of the reason it didn’t happen is the insight intelligence provided.

Cyber: Not Weapons, Lego Bricks

The new Defence Investment Plan focuses heavily on cyber defense rather than offense. Hockenhull isn’t surprised. The big investment in the National Cyber Force was made back in 2021 and guaranteed over a decade.

He rejects the idea of a cyber silver bullet. “A conventional weapon stays broadly the same object until it’s used. Cyber terrain changes continuously—someone updating their system could remove an opportunity, create a new one, or change the risk.”

His metaphor is telling: “Cyber tools are less like weapons in a warehouse and more like Lego bricks. Skilled people can combine them in different ways, but the usefulness of any combination depends on the target, the technology and the moment.”

This is where he sometimes admires Britain’s adversaries. “Not the methods, the risks, or the ethical bounds they storm through—but the way they use everything as tools of statecraft.” Britain, by contrast, is a responsive nation, dealing with everything below the threshold of war as separate incidents.

Successive governments have tried to build campaigns, but “government is very good at reorganizing itself, and that makes sustained campaigning over a long period difficult.” Spending-review budgets run only four years, and people at the top shift and move. “If we’re going to adopt a longer-term campaigning approach, we need consistency, in resourcing but also in intent and structure.”

The Digital Targeting Web

The Digital Targeting Web in the DIP reminds him of the Dowding System from the Battle of Britain: gather information, combine it, make a decision and act. The underlying logic isn’t new. What’s changed is the scale, speed and complexity.

“Modern forces can gather extraordinary amounts of information. The challenge is to make sense of it in space and time, then act at the speed of relevance.”

The real ambition is broader than “any sensor to any shooter.” It’s “anybody’s sensor to anybody’s shooter.” A Royal Navy system might detect a threat that’s then struck by a Netherlands Air Force aircraft. That raises hard questions of trust and law. “Am I going to take action that may kill someone, based on information from another country, trusting their process was sound? If the missile’s inbound, there may be no time for a second check.”

The First Battle: Talent

Hockenhull has said the battle for digital and cyber talent is the first battle of the next war. Britain is making progress, but it’s a work in progress.

For most of his career, people joined the Army, Navy or Air Force through traditional routes and only later moved into cyber. So they created a direct pathway. The first cohort did a short period of basic military training and then went straight into specialist cyber instruction. They joined in August and graduated in November.

The first group was small—about 40 people—but only one dropped out. “That’s far below the normal attrition in military training. We were reaching highly motivated people who might never have joined through the conventional system.”

The traditionalists don’t always welcome variation. “They’ve got a big sausage machine to run, and it’s easier to limit the variation. But for scarce digital skills, we have to be more flexible.”

Why the Public Must Know

Hockenhull’s final argument returns to where he began. Britain is attacked in cyberspace every day. It may face sabotage, espionage and attacks on its undersea cables long before anything resembling a shooting war. Yet almost everything the state knows about that threat stays classified.

That leaves people being asked to fund the response—with money that would otherwise go to schools and hospitals—largely on trust. “We assume the public understands the connection, but if our insight stays highly classified, we’re effectively asking people to trust us without seeing the evidence.”

Repeating that war is possible isn’t enough. “Particularly when more defense spending may mean less for a child’s education, or a longer wait for an NHS operation. That’s an asymmetric argument, and we’ve got to do much better.”

He wants a coalition, inside and outside government, willing to have a national conversation over time. “We jumped from the Strategic Defence Review straight to funding, and almost skipped the people who matter most—the ones who’ll pay for it and live with the consequences.”

His final warning is simple and stark: “Because war isn’t going to happen as an away game. If there is a conflict, it will be happening here.”

Continue Reading

Infosecurity

G7 Tells the World to Speed Up the Quantum-Safe Encryption Transition

Published

on

quantum-safe encryption transition

Quantum Risk Is No Longer a Distant Worry

For years, the threat of quantum computers breaking today’s encryption felt like a problem for the next generation. The G7 just declared that mindset obsolete.

On September 3, under France’s 2026 G7 Presidency, the French National Cybersecurity Agency (ANSSI) — which chairs the G7 Cybersecurity Working Group — published a new call to action. It pushes governments and private organizations to start the quantum-safe encryption transition now, not later.

The document is blunt: reframe the quantum threat from “a distant future problem” to “a near-term threat that demands action across all sectors, not just critical infrastructure.”

Why the Sudden Urgency?

Quantum computers capable of breaking RSA and ECC — the very backbone of public-key cryptography — aren’t here yet. But the G7 notes that “several recent advances suggest an anticipation” of such machines. The exact timeline is uncertain, which is precisely the problem.

Attackers can already harvest encrypted data today and decrypt it later, once quantum machines mature. That’s the “harvest now, decrypt later” scenario that keeps security experts up at night. Waiting for proof that a working quantum computer exists would be a catastrophic mistake.

What the G7 Wants Organizations to Do

The call to action isn’t just a warning. It lays out a practical roadmap for the PQC migration.

First, identify the systems holding your most critical data. Prioritize those for the transition. Then inventory all cryptographic assets, map dependencies, and build a phased, risk-based plan.

The G7 also has a cost-saving tip: integrate post-quantum cryptography (PQC) into products you’re already buying. Replace systems as part of your standard renewal schedule rather than doing emergency rip-and-replace later. Starting early, the document argues, means lower migration costs overall.

Five Priorities for Governments and Industry

The G7 document outlines five concrete priorities that need attention from policymakers and the private sector:

  • Raise awareness about quantum threats across all sectors.
  • Develop national PQC strategies, including building an adequate supply of quantum-safe hardware and software.
  • Focus R&D on advancing PQC through practical innovation.
  • Build public-private partnerships between government, industry, and academia to grow domestic expertise.
  • Integrate PQC into cybersecurity requirements and procurement standards.

The document was signed by the national cybersecurity agencies of all G7 members — Canada, France, Germany, Italy, Japan, the UK, and the US — with support from the EU Commission and the EU Agency for Cybersecurity (ENISA).

ANSSI Is Already Moving the Goalposts

This isn’t ANSSI’s first warning shot. Months earlier, the agency announced it would stop vetting products that lack quantum-safe encryption starting in 2027. By 2030, post-quantum security becomes mandatory in procurement for certain security products in France.

That’s a hard deadline. If you sell security products into the French market, the clock is ticking. The G7 call to action suggests other member states may follow suit with similar requirements.

What This Means for Your Security Roadmap

If you haven’t started planning for the quantum-safe encryption transition, this document is your cue. The conversation has shifted from “if” to “when,” and from “someday” to “now.”

Start by taking inventory. You can’t protect what you don’t know you have. Map your cryptographic dependencies, identify crown-jewel data, and begin conversations with vendors about their PQC roadmaps. Many cybersecurity vendors are already preparing for the migration — make sure yours is one of them.

The quantum threat isn’t science fiction anymore. The G7 just made that official. Will your organization be ready when the deadline hits?

Continue Reading

Infosecurity

OpenAI Puts $1 Billion on the Table to Arm Critical Services with AI Defenses

Published

on

OpenAI cybersecurity pledge

A Billion-Dollar Bet on the Little Guys

OpenAI has committed a staggering $1 billion to put its cutting-edge AI cybersecurity tools into the hands of those who need them most: the people keeping your lights on and your water running. The announcement, made on September 3, outlines a plan to subsidize access to its Daybreak AI models for essential services across the United States and, eventually, the globe.

It’s a direct response to a grim reality. Small municipalities, rural utilities, and local non-profits are getting hammered by sophisticated cyberattacks, yet they often lack the budget and specialized staff to fight back effectively. They are defending aging infrastructure with outdated tools against adversaries who move at machine speed.

This isn’t charity; it’s a strategic move to level a playing field that has grown dangerously tilted.

What Exactly is Daybreak?

For the uninitiated, Daybreak is OpenAI’s dedicated cybersecurity initiative, first unveiled back in May 2026. It’s not a single product but a suite of capabilities that leverages the company’s frontier large language models (LLMs) alongside its AI-coding assistant, Codex. These tools are designed to be deployed by approved defenders for a wide range of security tasks.

By August, OpenAI had evolved this into a two-tier system: Daybreak Red and Daybreak Blue. Red focuses on offensive security—hunting for vulnerabilities before the bad guys find them. Blue is about defense, helping teams monitor, analyze, and respond to threats in real time.

The New ‘Frontline Defenders’ Program

The new initiative, dubbed Daybreak for Frontline Defenders, is all about integration. OpenAI isn’t just handing out API keys. The program is designed to help critical sectors actually embed these AI models into their existing cybersecurity tools, services, and daily workflows. The goal is to make AI assistance as routine as a firewall update.

Which sectors are first in line? Think water treatment plants, electricity grids, local government networks, non-profits, and banking institutions. The rollout starts in the US, but OpenAI explicitly states it intends to expand to partner countries in the coming weeks.

The potential impact is huge. With Daybreak access, a two-person IT team at a rural water authority could review legacy code for flaws, analyze suspicious network activity, and even develop and test fixes—tasks that would typically require a team of expensive security engineers.

A Pilot with MS-ISAC: Putting Words into Action

Talk is cheap, so OpenAI is pairing the pledge with a concrete pilot. They’ve announced a collaboration with the Multi-State Information Sharing and Analysis Center (MS-ISAC). This pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders.

MS-ISAC is a critical piece of the US cyber defense puzzle. It provides threat intelligence, incident-response support, and real-time information sharing to thousands of public-sector organizations. The plan is to start small, develop a repeatable approach, and then expand the partnership over time. It’s a sensible, methodical start.

The Stark Warning That Preceded the Check

This $1 billion pledge didn’t happen in a vacuum. It landed exactly one week after a coalition of over 100 tech and cybersecurity companies—OpenAI included—published an open letter on August 27. That letter was a blunt instrument, warning of a “narrowing window” to act before AI-enabled attacks escalate to a level that puts critical public services at severe risk.

The message was clear: the same AI that powers defensive tools also supercharges attackers. If we don’t democratize access to frontier AI for defenders, we’re essentially handing the keys to the kingdom to cybercriminals.

OpenAI echoed this sentiment in its announcement, stating that the defender’s window “will not stay open indefinitely.” The opportunity, they argue, is to ensure the advantages of frontier AI extend beyond the largest companies and best-resourced security teams, reaching into the communities and institutions whose security affects millions of people.

Beyond this pledge, OpenAI is also working on what it calls a Defense Factory—an automated approach designed to continuously discover, validate, and fix vulnerabilities. It’s part of a broader push to make AI-driven security proactive rather than reactive.

For anyone tracking the intersection of AI and national security, this is a significant development. The question isn’t whether AI will play a role in defending critical infrastructure—that’s a given. The real question is whether the defenders of that infrastructure will have equal access to the tools. With this billion-dollar bet, OpenAI is trying to make sure they do. For more on how AI is reshaping security, check out our analysis of AI-powered threat detection methods and the growing role of automated vulnerability patching tools.

Continue Reading

Infosecurity

US and UK Join Forces to Dismantle Scam Centers Behind Billions in Fraud

Published

on

scam center takedowns

A New Alliance Against Cyber Fraud

The United States and the United Kingdom are pooling resources to shut down the sprawling scam centers that have siphoned billions from victims worldwide. A memorandum of understanding signed Thursday commits both nations to parallel investigations and shared intelligence on the organized crime networks behind these operations, many of which are based in Southeast Asia.

U.S. Attorney Jeanine Ferris Pirro met with senior officials from the U.K.’s National Crime Agency and Crown Prosecutor to formalize the agreement. Pirro stated the objective is to “disable” the Chinese gangs that operate these compounds.

How the Partnership Will Work

The memorandum outlines a framework for both countries to identify overlapping cases and decide which jurisdictions will bring charges. The goal is to prioritize cases that can deliver significant mutual impact.

Officials from both sides had already flagged substantial case overlaps. They are now committed to a joint disruption event with private industry partners, scheduled for early October in London and hosted by the National Crime Agency.

The Scam Center Strike Force Takes the Lead

This initiative is spearheaded by the Scam Center Strike Force, launched last November to coordinate U.S. enforcement against cyber-enabled fraud. The numbers are staggering: the FBI reports that cyber-enabled fraud accounts for nearly 85% of all losses reported to the agency. Americans lost over $12 billion to these scams last year — a figure likely far below reality, as many victims never come forward.

Assistant U.S. Attorney Karen Seifert leads the Strike Force. Testifying before Congress in March, she noted the team includes more than 150 personnel, drawing on prosecutors and agents from the FBI, IRS, and U.S. Postal Inspection Service.

Human Trafficking at the Core

These scam centers are not merely criminal enterprises; they are built on human trafficking. Victims are held in compounds across Myanmar, Cambodia, Laos, and neighboring countries, forced to run investment and romance fraud schemes. Chinese syndicates control the operations, often with the complicity of compromised local officials.

Early Wins and the Road Ahead

The Strike Force has already claimed a major victory. The disruption of Prince Group, a Chinese front company used to launder illicit proceeds, led to sanctions from both U.S. and U.K. agencies. The Justice Department also seized roughly $15 billion in bitcoin tied to the company’s CEO, Chen Zhi.

That seizure sent a clear message. But the problem is vast, and the syndicates are adaptive. The new US-UK partnership signals a recognition that no single nation can tackle this threat alone.

For more on related efforts, see how cyber fraud reporting works and the rise of Southeast Asian scam compounds.

Continue Reading

Trending