National Cyber Resilience Advisory Board (NCRAB) minutes: June 2026

Minutes from the meeting of the group on 23 June 2026.


Attendees and apologies

Board members in attendance

Maggie Titmuss (Chair)
Deryck Mitchelson (Vice-Chair – DM) Carla Baker (CB)
George Fraser (GF)
Freha Arshad (FA)
Jordan Schroeder (JS)
Ollie Bray (OB)
Phil Ford (PF)
Alan Gray, Deputy Director, National Cyber Security and Resilience Division, Scottish Government – Ex Officio (AG)

Apologies

ACC Stuart Houston (SH) – Ex-Officio
Don Smith (DS)
Martyn Wallace (MW)
Natalie Coull (NC)
Steve Watt (SW)

Also in attendance

Head of the National Cyber Resilience Unit (NCRU)
NCRU Head of Policy and Programme
NCRU Public Sector Lead
Scottish Cyber Coordination Centre (SC3) Service Lead 
Scottish Cyber Coordination Centre (SC3) Excersing Lead 
NCRU Learning and Skills Senior Policy Officer
NCRU Policy and Programme Officer
National Cyber Security Centre (NCSC) Devolved Administrations Lead (YW)
Scottish Government (SG) Service Design Owner 
DCS Andy Patrick, Police Scotland (AP) 
CEO, Swordbreaker.

Items and actions

Welcome, introductions, last meeting actions and conflicts of interest

The Vice Chair welcomed Members to the meeting. The minutes of the March 2026 meeting were approved. No conflicts of interest were noted. 

The NCRU Head of Policy and Programme ran through outstanding meeting actions: 

•    MAR26/01: Head of NCRU and NCRU Head of Policy and Programme to investigate if online messaging on electoral misinformation/disinformation threat could be undertaken as part of monthly social media postings in run up Scottish election run election. The NCRU undertook electoral information awareness raising comms via CyberScotland social media platforms. Action closed. 

•    MAR26/02: The Chair and AP to discuss Cyber Choices separately. Action closed

•    MAR26/03: SC3 Service Lead and SW to discuss academics cyber incidents separately. Action closed. 

•    MAR26/04: Education Scotland to provide further update of CIC by June. OB provided an update later during the meeting, see below. Action closed.

•    MAR26/05: Invite Head of AI and Digital Economy to June Board meeting.
Head of CRU has had a number of conversations with the Head of AI and Digital Economy. NCRU are meeting AI Scotland lead organisation (Data Lab) to discuss cyber security, AI and how best to raise awareness. Action closed. 

Cyber threat landscape

The National Cyber Security Centre (NCSC) Devolved Administrations Lead (YW) provided a general threat update to members. YW advised that NCSC continue to progress guidance and support at pace given the changing cyber landscape. 
Acceleration of Artificial Intelligence (AI) has flagged that cyber security fundamentals continue to be weak. YW advised that risk was not caused by AI, however it was important to note that risk is being enhanced by rapid developments in AI. The increased use of AI to identify vulnerabilities would require organisations to move quickly and patch systems more frequently. YW stated that investment in people and partnerships will continue to be a good defence against the threats that developments in AI pose. 

The Vice Chair flagged that developments in AI capability may drive cyber inequality. He advised that not every person, business and organisation would have access to the appropriate governance, investment and expertise that should be considered when adopting and using AI safely. 

JS commented that the role of NCRAB was to drive positive change and that it would be critical for Members to recognise that many organisations fall significantly behind in terms of technological advancement, given that adversaries are using AI to increase the scale and impact of threats. 

The Vice Chair questioned if organisations were realistically aware of the threat that AI posed to them. He also stated that it was critical for organisations to understand that these threats posed a significant business continuity risk. 

The Head of the NCRU suggested that a Member provide an update to the CyberScotland Partnership Steering Group on the threat that AI posed. A discussion then followed on a more strategic approach to highlight the risks associated with increased AI adoption and how organisations can remain cyber resilient while using AI. 

JUN26/01: NCRU Head of Policy and Programme to identify opportunities for collaboration with the Vice Chair, JS and YW to deliver AI awareness raising for a range of stakeholder groups in Scotland, including the CyberScotland Partnership, the Third Sector and the Public Sector Network. This should include risks associated with AI use and some actions organisations can take to support safer adoption of AI. 

The SC3 Service Lead also provided a short update on cyber threats that SC3 had been involved with over the last quarter. He advised that recent events had highlighted a gap in coordination and that they were undertaking action to resolve this. 

DCS AP provided a short update from Police Scotland. He advised that there had been an increase in reports of Computer Misuse crimes, sextortion and sexual offences. He also advised that ransomware continued be a significant concern. 

Horizon Scanning

JS provided an overview of the evolving cyber threat landscape, with particular emphasis on the rapid acceleration of AI. AI has significantly increased the speed, scale, and accessibility of cyber threats, which has enabled adversaries to quickly develop, refine and distribute attack techniques.

JS advised that AI has not created new forms of cyber crime but has amplified scale, scope availability and efficiency of existing threats, which included phishing, ransomware and fraud. Of particular concern is the rise in AI-enabled phishing, including voice phishing (vishing) and impersonation attacks targeting citizens, especially through fraudulent communications posing as government authorities. 

JS advised that novel use of AI, such as device code phishing, means that multi-factor authentication was no longer as secure as before. JS suggested a move towards phishing-resistant multifactor authentication was required quickly. 
JS advised that these developments have placed growing pressure on organisations’ ability to absorb cyber risk and significant change was required to keep up with threats. 

JS also advised that ‘edge devices’ such as routers, VPNs, cameras, industrial systems and supplier-managed edge devices provide routes into transport, energy, water and local services. He advised that these devices were being exploited and leveraged at scale. JS said knowledge and awareness of the vulnerabilities that these devices pose and identification and remediation of patching levels is critical. 

JS emphasised that cyber resilience must be redefined, shifting focus beyond prevention toward adaptability and rapid response. Leadership-level awareness, education, and engagement were identified as critical to ensuring that public sector bodies recognise their role as major information processors and act accordingly.

The Head of the NCRU acknowledged that proactive communication with Ministers and senior officials was important and suggested the Board provide support which would elevate key messages and articulate the risks associated with new technological developments including AI. She also suggested the option of offering briefings to Ministers and other Senior Officials. 

JUN26/02: NCRU to discuss and take forward engagement with Senior Officials and Ministers of key cyber risks including AI development. This will include briefings. 

The Head of the NCRU also suggested an Extraordinary meeting to discuss AI in further detail. However, it has been agreed that the September 2026 meeting will have a focus on these topics. The agenda will be amended appropriately to reflect the planned discussions. 

Update on UK developments

The Head of the NCRU outlined the three main pillars of the UK Government’s National Cyber Action Plan (NCAP): Counter Threats, Strengthen Resilience and Secure Growth, noting a focus on resilience and secure growth. 
She reported that the Cabinet Office was preparing a business-focused launch in the Summer. The Head of the NCRU also described the shift from CyberFirst to TechFirst through the UK Government programme to boost skills not only in cyber security but also across other frontier technologies such as AI and quantum. She further advised that the aim of TechFirst was to have one million young people aged 11 to 18 access digital learning. 

The Head of the NCRU noted the risk associated with rebranding from CyberFirst to TechFirst in Scotland, particularly in managing communications with schools that have established CyberFirst identities in Scotland. To this end, she advised that Education Scotland will manage the transition of CyberFirst into TechFirst, but with a clear continuation of building on the success of Cyber First in Scotland. Furthermore, a memorandum of understanding is in development and that funding for three years has been secured for Scotland to support the growth of tech skills in Scotland. 

The Vice Chair noted that in other countries, such as China, AI skills are embedded into the curriculum at a very early age and in order to achieve the vision of Scotland as a truly digital nation, it would be imperative to ensure digital skills were embedded as early as possible. Head of NCRU advised that there is work underway to build early concepts in cyber learning in primary school. 

The SC3 Service Lead detailed the Scottish Government's participation in the UK Government's Cyber Action Plan (GCAP) which included funding applications to the Devolved Governments Fund for projects aimed at improving cyber risk visibility and incident responsiveness.
He provided a brief overview of the bids that the Scottish Government had submitted for consideration and advised that these bids would be delivered over a three-year period and hoped to have a decision on funding in July 2026. 

Cyber Resilience Centre 

DCS AP provided an update on the potential to establish a police-led, not for profit a Cyber Resilience Centre for Scotland focusing on prevention, early intervention and accessible support, especially for Scotland’s SME’s (over 99% of the private sector in Scotland). 

JUN26/03: DCS AP to share Scottish Cyber Resilience Centre concept paper with NCRU Policy and Programme Officer. NCRU to share this with Members. 

The Chair added that if there was anything the Board could do to support, to please let her know. The Chair and DCS AP to arrange meeting between themselves following the meeting. 

Curriculum Improvement Cycle, including cyber security 

OB provided an update on the ongoing review and redesign of the Scottish curriculum, with a focus on embedding digital skills, cyber resilience and interdisciplinary learning from early years through to secondary education.

OB outlined a four-stage review process, with sample materials being released for teacher feedback in January 2027, with full implementation scheduled for August 2028, giving teachers time to plan with materials before full implementation. He shared that the new curriculum aimed for greater specificity and alignment with qualifications.

OB also shared that the revised curriculum would explicitly include digital skills and cyber resilience as core components, with a dedicated strand running from ages 3 to 18. The approach included integration across subjects and school culture.

Given that much of the discussions during the meeting focused on AI, OB noted that AI would be embedded across multiple strands, including citizenship and creativity and would not be a standalone topic. OB further shared that the curriculum would also address the cognitive impact of AI on young learners and adapt pedagogical techniques accordingly.

OB suggested bringing Education Scotland colleagues along to a future meeting to discuss planned materials in further detail. The Board agreed. 

JUN26/04: OB to update further on embedding of digital skills and cyber resilience in the curriculum at a future meeting and to consult with Board on this aspect of the CIC if the opportunity allowed. 

Spotlight 1: “Cyber Resilience and You!”

The NCRU Learning and Skills Senior Policy Officer updated Members on the ‘Cyber Resilience and You!’ tool for colleges and universities. Cyber Resilience and You! The one hour online learning course is designed to increase awareness of cyber security among students in higher and further education institutions. The course equips students with knowledge and skills to counter cyber threats directly relevant to their daily lives. He advised this was developed in partnership with Scottish universities and colleges, including Abertay University, members of the CyberScotland Partnership and the Scottish Government.

Informed by feedback arising from co-design with students themselves, the course informs participants on key areas of cyber resilience including; phishing, accessing the internet safely, combatting online scams, creating and managing passwords and protecting devices with security updates. 

At the time of the meeting 24 universities and colleges in Scotland had used, made available and promoted the course. The course has also been advertised through cyber roadshow events held during Freshers week in September and October 2025. 

The Members were advised that over 3,600 students had completed the course, by June 2026, and this figure was expected to rise over the coming months as the new academic term was due to start. 

Data gathered from the course has shown that there was a 14% increase in students’ awareness of cyber threats, a 17% increase in students’ capability to address a threat and that 82% of students who had completed the course would alter their security habits as a result. 

The NCRU Learning and Skills Senior Policy officer shared that future plans for the course included creation of a workforce package in early 2027 and collaboration with Sabhal Mor Ostaig, Scotland’s National Centre for Gaelic Language and Culture to develop the course in Gaelic. An objective of the course is also to form and sustain a relationship with the Cyber Security Research and Networking Environment (CRANE), to enrich knowledge of the academic ecosystem and harness the benefits of cyber research. He also advised that the course has been so well received that discussions were underway to involve the Universities and Colleges Information Systems Association (UCISA) and it is hoped that this will also be rolled out in England, Wales and Northern Ireland. 

AG asked how students were being encouraged to engage with the course. 
The NCRU Learning and Skills Senior Policy Officer advised that the tool has been included in induction packs for incoming students and work was underway to ensure awareness raising of the course ahead of the new academic year starting in August/September 2026.

On the back of this successful project, the NCRU are now developing a workplace edition which aims to be launched during Cyber Security month. 

Spotlight 2: SOC for Scotland

The SG Service Design Owner provided an update on plans to develop a Security Operations Centre (SOC) for the Scottish public sector.

The SOC would provide 24-7 monitoring, detection and response as a shared service, using a federated model which allowed organisations to retain control of their systems while benefiting from centralised expertise and data aggregation.

Members discussed risks such as integration challenges, potential duplication, and the need for clear operational relationships with existing SOC’s. 

The Board endorsed the proposal and members offered to provide expertise and oversight to ensure successful implementation and integration with other national cyber initiatives. Also it was agreed that there needed to be close collaboration with the Digital Office – Scottish Local Government as this progresses.

Spotlight 3: CivTech projects – Supply25, Lupovis and Swordbreaker

The NCRU Public Sector Lead reported on the deployment of Supply 25, a tool for centralising management of supply chain risk and assurance from the start of the procurement process. Over 180 procurements have been assured through the platform from the Scottish public sector and there is an ongoing pilot with a number of local authorities in the northeast of England. The Scottish Government and Supply 25 have recently won the Procurement Transformation Through Technology Award at the National Go Awards. 

The SC3 Service Lead advised of ongoing work with Lupovis on deception technology and threat intelligence sharing. He shared that a Deception-as-a-Service (DaaS) pilot was underway to deploy deception technology within public sector networks. The aim of this pilot was to gather enriched threat intelligence, with data then being integrated into the Malware Information Sharing Platform (MISP) and then used to inform public sector defences.

The CEO at Swordbreaker updated Members on the technical approach of Swordbreaker which aims to disrupt ransomware attacks without relying on signatures or agent-based detection. He advised the product had been piloted and was being rolled out in production environments, with ongoing development of further ransomware countermeasures.

Any other business and close

No other business was raised. The Chair thanked members for their attendance and advised the next ordinary meeting would be 1 September 2026, in Edinburgh.

Back to top