
The Authority On... · 2025-06-18 · 22 min
The UK's 2025 Strategic Defence Review, conducted externally for the first time, fundamentally reframes how the nation approaches defense by recognizing cyber and sub-threshold threats as equally important to conventional warfare. Grace Cassy explains that the review emerged from Russia's use of drones, electromagnetic warfare, and coordinated cyber attacks in Ukraine, revealing that modern conflict extends beyond traditional military domains. A central recommendation calls for strengthened public-private partnerships, as most critical national infrastructure is now privately owned and operated - from undersea cables carrying 95% of data flows to cloud providers whose resilience directly impacts national resilience. The discussion highlights machine learning and automation as essential tools for managing the massive scale of device deployments and vulnerabilities that humans cannot manually oversee. Device Authority's approach to automated credential rotation, certificate management, and dynamic device quarantine exemplifies the practical innovations needed. Cassy also identifies agentic AI as a significant emerging theme in security, where autonomous agents handle routine tasks like vulnerability processing and identity management, freeing overworked teams for complex analysis. The conversation emphasizes that resilience is now a strategic national priority, enabled by external perspectives and private sector innovation - a shift reflected in government acceptance of recommendations for broader supplier engagement beyond traditional large defense contractors.
It was the first strategic defense review conducted entirely externally rather than internally by defense ministries, incorporating broad consultation from the private sector, academia, veterans, and citizens to provide a more holistic perspective on future threats and defense requirements.
Russia's invasion of Ukraine demonstrated that modern conflict integrates drones, electromagnetic spectrum attacks, and coordinated cyber operations alongside conventional warfare, showing that conflicts occur both above and below the threshold of traditional war declarations.
They need automated solutions for credential management, certificate rotation, device identity verification, and quarantine procedures because the sheer number of networked devices and vulnerabilities makes manual security oversight impossible to maintain in real time.
The private sector owns and operates most modern critical infrastructure, so government must build different kinds of partnerships extending beyond traditional large defense contractors to include innovative technology companies, as national resilience depends on industry resilience.
Agentic AI can automate routine security tasks like vulnerability processing and identity management, reducing workload on security teams and freeing them to focus on complex, high-value analysis, though proper controls and human oversight remain critical.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of The Authority On… , we’re joined by Grace Cassy - co-founder of CyLon Ventures, board member at Ten Eleven Ventures, and external expert on the UK’s 2025 Strategic Defence Review. Grace brings a unique perspective at the intersection of cybersecurity investment, policy, and national resilience. Together, we explore how the Strategic Defence Review signals a shift in how the UK approaches security in a hyper-connected world - from protecting Critical National Infrastructure (CNI) to enabling public-private innovation in defence and beyond. We discuss the growing convergence of cyber and physical threats, the role of startups in securing national capabilities, and what it takes to build trust in a digital-first world. With input from the Device Authority team, this episode bridges strategy with on-the-ground security challenges faced by organisations today.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the Authority on um, a podcast brought to you by Device Authority. Hello and welcome to this episode of the Authority on. Today I am joined by Grace Cassie, co founder of Cylon Ventures, board member at 10:11, one of Fortune's leading investors in cyber security. Grace has also served as an external Expert on the UK's 2025 Strategic Defense Review of the most ambitious and future focused updates to national security in decades. Today we'll be discussing what this review means for cyber resilience, critical national infrastructure and the UK's evolving approach to digital threats. And as always, we'll be bringing in a Device Authority lens, connecting the strategic vision with the practical steps needed to secure connected devices identity and data across complex ecosystems. Hello Grace and welcome. It's great to have you on.
Speaker B: Thank you so much for having me.
Speaker A: So let's start with the review itself. You had a front row seat as an external expert. What stood out most to you from this route to branch rethink of defence?
Speaker B: Well, I think the first thing I would say is that this was the first time that a strategic defence review had been conducted externally. So typically these reviews in the past have been conducted by defence on themselves and this time uh, the Labour government uh, appointed an external team to uh, really take a look from the outside. And so that I think has given us a kind of different perspective. We obviously worked extremely closely with people across defence in the process of conducting the review. We also uh, had a very, very deep uh, and broad uh, external consultation. Uh, we sought input from private citizens, from serving members, uh, of uh, the defence forces, from veterans, uh, from the private sector, from academia and think tanks and so on. So we had a huge amount of input and I think that has enabled us to uh, really I hope, give the most rounded and holistic sense of how defence needs to change in the future. As to the themes of the report itself, I think one of the really key ones is around how defence must innovate in future. The nature of the threats that we face in the UK have been made more evident really since uh, Russia's invasion of Ukraine and how that campaign has developed, how that campaign has been fought. Right? The very visible use of drones, the use of the electromagnetic spectrum, the use of cyber as a tool, uh, in concert with uh, more conventional, uh, types of warfare, have really brought home that modern war looks quite different to what our defence system has been set up for hitherto. So we've looked very thoroughly and carefully at how the UK must be able to endure both above and below the threshold of war in future. And that of course has quite a significant focus on resilience, uh, and uh, cyber being an important part of that. You know, I'm a, I'm someone who spent a long time, you know, investing in cyber. So it's, it's something I obviously care about a great deal. And um, I'm encouraged to see the focus in the review on that aspect. You know, obviously the, the stuff that grabs the headlines is often around the submarines and the nuclear warheads and so on, all of which are of course vital. But I think it's important that we looked uh, more holistically at other aspects of how the UK is likely to confront adversaries in future. And that sub threshold area, I think, um, is just as important.
Speaker A: Yeah, it's really interesting. Like you said, Russia has shown a lot of ingenuity when it comes to utilizing cyber attacks throughout this conflict. Digital dependence generally as well. Now we operating our uh, critical national infrastructure even means that those dynamic threats and our digital dependency are more concerning, aren't they? That is exactly what we're hearing from our partners around securing IoT devices and operational systems. And that the um, emphasis around cyber as warfaring domain feels like a long overdue recognition of how that digital trust has become so key. And that really now takes us through into talking about critical national infrastructure from like energy to healthcare to defence supply chains. And um, the review calls for real investment in resilience, doesn't it? What exactly does that look like in practice?
Speaker B: Yeah, we definitely call for a greater focus on resilience. Uh, the review talks about things like uh, building up, uh, strengthening our cadet forces, trying to rebuild connections between the armed forces and society through, you know, education and skills and so on. All of which is, is hugely important. I think though, for uh, for your audience it's probably the, the focus on CNI and how, how technical infrastructure can be better protected is another area of significant focus for us. We make a specific recommendation around giving greater focus to ensuring that our CNI is protected, as I say, both above and below the threshold of war. We, um, seek further work on that. An important part of that is partnership between the public sector and the private sector. Much of modern CNI is owned and operated by the private sector. And this is not the days anymore where CNI was entirely a public good, if you like. Well, it is public good, but it's not publicly owned and controlled anymore. Some of it is. But if we're to really build our trust across our modern cni, that does require a different relationship with the private sector and it becomes more and more urgent as we see day by day. As you say, our dependence on our digital CNI is extreme, right? With 95% plus of our, of our data flowing through undersea cables, um, you know, energy pipelines, uh, even, even systemically significant companies for us, you know, if you think about the cloud providers and so on, that these are, um, you know, their resilience is our resilience and ensuring trust across that system between public and private is something that we very much want to see enhanced.
Speaker A: One of the things that we're really seeing from our side is the push to automate device trust and credential management within those critical sectors. Even the colonial pipeline attack as well, um, it went to go and show just how susceptible critical infrastructure could be to attack. So making sure that credential management is looked after within those areas is so important and obviously not optional anymore. If a water utility or defence contractor couldn't rotate certificates or verify device identity automatically, then they're exposed. And resilience now means being able to enforce trust dynamically and at scale. When we think about how tiny little sensor on a production line is and how many there are, how vast they are throughout production line and they're all single points of entry as well, which is quite, quite scary when you think about it. Uh, but uh, it just goes to show again how important that is, doesn't it?
Speaker B: Yeah, it doesn't. You know I think what we all see quite quickly, quite clearly um, through recent years, both in the context of Ukraine and just in the context of daily life, is the sheer mass of devices that are now being deployed and networked and um, operated on a daily basis. That the scale of that really requires automation in order to manage effectively and the pace at which we need to understand the data coming off those devices and act upon it again it's such that old systems are not really suitable anymore. So innovative solutions to enable the best, fastest use and um, sort of trusted understanding of the data on those devices, ah, at uh, scale is important for sure.
Speaker A: Um m. You're deeply involved in the venture world, ah, funding the next generation of security solutions. Where do you see the biggest shifts happening?
Speaker B: Um, gosh, there's a lot of interesting areas. I think the most obvious one which people obviously talk a lot about is the collision of AI and security. Um, it's been a theme in the security industry for some time now of course, um, but you know, perhaps marketing of AI has become even more noisy in the last year or so. But you Know, I think beneath the noise, I think there are some genuinely interesting shifts. I think the development and deployment of various types of agentic AI in security is an important theme to watch. Its early days still, uh, and there are still legitimate concerns among users around trusting agents to conduct any sort of unsupervised tasks. But, but I think what we're seeing at the cutting edge is that these agents are very powerful and can uh, with the right controls around them really take a lot of load off overworked security teams. And if one can automate much of the uh, more basic work, whether that be in uh, processing vulnerabilities or managing identities or any other process in a security program, then it does offer the prospect of freeing up time for people to focus on more complex, higher value tasks. So I think that agentic AI theme is a really interesting one to watch. Um, both the use of IT and the oversight and control of it. In both areas there are innovators doing very interesting work. Um, I think from a kind of policy perspective various governments are still looking quite hard at how to make software and systems more secure by design so that we're building in security at an earlier stage rather than trying to apply it as a retrospective patch later. Uh, and I think you know there's, there's some again interesting companies applying various forms of automation and AI to that challenge, uh, to help as you know, particularly as things like coding becomes more uh, easy for the non expert to achieve. Right tooling that make vibe coding as it's called, uh, that does need to be secure too. So um, ensuring that innovators keep security in mind and providing good low friction products to enable that to happen, uh, I think is another really interesting area.
Speaker A: Based on what we've been talking about, what really resonates with us as a company around AI and we've been looking at our own AI product although I suppose it really falls more within the machine learning space as it were, which helps to identify vulnerabilities based on the SBoM and then quarantining that device so that if it's not got the right certificate or even if it is running a slightly different operating system to the rest of the network, it can then be quarantined for review so that nothing terrible can spread throughout the network. While you're waiting for the human element, um, to notice the notification, then sort it out, which, which can take time because when you're looking after vast networks of devices, even traditional um, IT devices, it can take some time to, to locate that device and then Have a proper look at it and sort it all out. So.
Speaker B: Yeah, that's right. I think, I think vulnerability management as a theme is a really interesting one that's quite susceptible to AI as a tool. I think the sheer scale of vulnerabilities that exist out there and the number of um, systems and devices that we're deploying around the economy are such that as you say, it's pretty, I mean, impossible really for humans to keep on top of that in the timeframe that keeps people safe. So I think the application of machine learning, AI, automation to that challenge is a very interesting use case.
Speaker A: Coming back to the CNI side of things, looking after um, edge and leaf devices, those devices that are not necessarily on the network or constantly connected to the network, like a wind turbine in the middle of a field thousands of miles away. Again they can be looked at and addressed prior to someone being able to fly out and go and look at that device. So things like that can help vastly reduce issues on a network like that. Which is really interesting from our perspective as well, seeing what other people within the market are producing around those as well. Which is. It's exciting times, isn't it? You've worked across diplomacy and national security. How important is, is cross border cooperation between public private partnerships and in this space?
Speaker B: Well, I think it's central. One of our core messages in the Strategic Defence Review is around necessity to build a different kind of partnership between defence and the private sector. I think our armed forces are only as strong as the industry that stands behind them. Our CNI is only as strong as the industry that stands behind it. And I think government increasingly recognizes that. And in the sdr, government has accepted our recommendations that we need to build a different kind of partnership with the private sector, that we need to move on from defense industry being considered to be a very small number of very large companies that operate in a, in a fairly closed system and understand that there are a far wider set of potential suppliers out there working across a wide variety of technology and service areas who can support defense and security missions. So um, yeah, I think, I think it's sort of hard to underestimate to be honest, that the cooperation element here, uh, to achieve the vision that we're setting out, I think outside of the kind of pure commercial space of working with different kinds of suppliers, I think there's also a great emphasis on other sorts of cooperation and sharing like shared framework, shared standards, um, enabling us to work better with our allies. So we've been very clear in our review that this is a NATO first review. We are explicitly prioritizing NATO as our core partnership. That means that we need to be able to work with our NATO allies and interoperate with our NATO allies. So we need to be working off shared, shared standards, whether that's in communications or um, land systems or air systems or cyber. So um, I think the ability to work across border effectively places even greater emphasis on single shared frameworks that enable that to happen.
Speaker A: That cohesion is so important, making sure everything works well together. One final thought. When you, when you look ahead, what gives you optimism in cyber security and strategic resilience?
Speaker B: I think there's a few reasons to be optimistic. I spend my time around innovators and a few days spending time with founders of interesting cutting edge technology companies does give you optimism about the quality and the commitment of those people to solving some of these challenges. There's no doubt that we've got some big challenges. We have very effective, well armed adversaries, both in conventional and unconventional warfare terms. But we have really, really great people too. We have effective defence and security forces and we have a really thriving and committed private sector. And um, particularly among the innovators, people that really want to solve these problems and are devoting their professional lives to creating the kind of tools that will enable us to be resilient and to uh, endure future challenges. So you know, I think that is cause for optimism. I think the fact that we have a lot of great allies is cause for optimism. I think sometimes if you look at our adversaries, the relationships they have with their partners can tend to be more transactional and we have long standing deep partnerships with allies that give us, I believe, long term strength and resilience.
Speaker A: The Strategic Defence Review goes towards showing that resilience is becoming that real national and strategic priority, not just a technical one, not just something that companies like Device Authority have been thinking about for a while, how we can support secure things, how we can, you know, automate that, make it easier and safer for everyone. But it's now at uh, the forefront of, of what this government's trying to do and you know what your, what the outside review is also trying to, to really pin down and that's shifting mindset that will enable this lasting change that our eyes have been opened with all the different kinds of warfare that include um, technology and cyber. It's really brought it to the forefront and now it's become this strategic priority that enables the government to really take a really hard look at what's going on. Having an external review not just an internal one carried out by the defence forces themselves, means that they're able to now take hold of those outside perspectives, and take hold of the perspectives of people like yourself, who are seeing startups like Device Authority and the others that you've invested in as well, who are working so hard to try and, uh, meet these needs created by change. So it's exciting.
Speaker B: Yeah, it is. It's exciting. Time.
Speaker A: Thank you so much for joining me today. If you've been listening and you enjoyed the conversation that Grace and I have had today, please do subscribe to the podcast and make sure to share it with your network. Thank you for listening to this episode of the Authority on a podcast brought to you by Device Authority. If you have any questions about the subject matter in this podcast, please head to the Device Authority website, deviceauthority.com See you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.