Executive Summary
The United Kingdom faces an unprecedented convergence of threats — geopolitical, technological, and environmental — that collectively expose deep vulnerabilities in national resilience. This submission argues that the UK's current frameworks are insufficiently structured, inadequately resourced, and ill-suited to address the full spectrum of unconventional socio-economic warfare now being waged against its institutions, economy, and Critical National Infrastructure (CNI) by adversarial state actors, principally Russia and China.
Four targeted recommendations are advanced: the creation of a National Resilience Ministry; the establishment of an open-source National Resilience Insight Database; the development of a sovereign, independent internet capability; and a minimum cybersecurity software requirement for CNI assets. These are not aspirational proposals — they are strategic and operational necessities.
1. The National Resilience Threat Dimension
Global geopolitical instability has reached a level not seen since the height of the Cold War. Russia's kinetic aggression in Eastern Europe — through the attempted invasion and partial occupation of Ukraine — and the ongoing conflict in the Middle East have fundamentally altered the landscape of conventional warfare. Yet the most consequential evolution has occurred below the threshold of declared conflict.
The unconventional threat spectrum has expanded dramatically: sabotage, deniable attacks on Western CNI, lawfare, espionage, economic warfare, social influence operations, and physical aggression are now routinely deployed by aggressive foreign agencies, their conduit groups, penetration agents, and 'gig' (paid criminal) operators. These acts of aggression are deliberately calibrated to remain below the threshold of kinetic war — on land, in the air, in cyberspace, and beneath the oceans.
Layer upon this the accelerating effects of climate change — the shrinkage of polar icecaps, disruption of global ecosystem services, extreme weather events — and the result is a world that demands a qualitatively higher order of national management than any previous era has required. The resilience frameworks of the twentieth century are no longer equal to the threats of the twenty-first.
2. Defining National Resilience
The word 'resilience' is invoked frequently in policy discourse, yet its application is often insufficiently precise. The Oxford English Dictionary offers two complementary dimensions: (i) the capacity to withstand or recover quickly from difficulties — characterised as toughness; and (ii) the ability of a substance or object to spring back into shape — characterised as elasticity. Both qualities are essential components of an effective national resilience posture.
What this dual definition reveals is that resilience is not an abstract or all-encompassing ideology; it is a context-specific, functionally deployed capability — one that must be identified, evolved, and directed against a defined set of forces or threats. This analytical discipline is critical because, without it, resilience policy remains generic and therefore inadequate.
The central question that this Committee must confront is not whether the UK is resilient, but resilient against what, specifically? It is only by identifying and accepting the full range of forces — state-sponsored, environmental, technological — that the UK can build the targeted, tough, and elastic national situational resilience required to mitigate future armed conflict.
"In the 21st century, proactive national situational resilience is the most effective deterrent against armed conflict." — Ian Saunders
3. The Resilience Race
Where the Cold War was defined by the nuclear arms race, the current period is defined by what this submission terms the 'Resilience Race' — a sustained campaign by adversarial states to erode the social, governance, and productive operability of Western democracies through unconventional socio-economic means, operating below the threshold of declared war.
Unconventional socio-economic threats — the targeting and exploitation of economic, industrial, and social vulnerabilities — represent the most destructive wartime instrument deployed in peacetime. Those malign states that have pursued such strategies have done so over decades, investing systematically in intelligence, influence, and infrastructure penetration capabilities. Critically, they have in many instances published their doctrine openly; it is the West that has declined to read it.
Global markets have been weaponised. Private sectors are being aggressively targeted. Societal cohesion is being deliberately eroded. Fiscal headroom — once a buffer for crisis response — has been dramatically reduced. Being socially, commercially, and financially resilient now requires new frameworks for understanding and mitigating non-military risk at scale.
"Failing to generate effective resilience-focused intelligence is akin to denying a terminal illness." — Ian Saunders
Despite this reality, national resilience efforts in the UK remain fragmented. The 2025 Strategic Defence Review was a welcome step. The National Protective Security Agency (NPSA) is developing operational and tactical capabilities at pace. The Resilience Action Plan and the Resilience Academy offer valuable tactical-level tools. But these initiatives — individually commendable — do not yet constitute a coherent, strategic, whole-of-nation resilience architecture.
A vision-led approach is urgently required: one that defines and integrates Strategic, Operational, and Tactical resilience levels — from the physical protection of the internet and undersea data infrastructure at the strategic level, to community-led preparedness at the tactical level.
4. Critical National Infrastructure: The Overlooked Vulnerability
Critical National Infrastructure (CNI) encompasses the essential systems upon which the United Kingdom's operability depends: communications (including the internet in its entirety), energy, water, transport, financial institutions, food production, defence, law and order, and governance. To state plainly what policy documents have been reluctant to acknowledge: the cascading failure of CNI would represent the effective dissolution of the UK as a functioning state.
The cybersphere is the connective tissue of every CNI sector, and, with the introduction of AI, is under constant surveillance and probing for exploitable vulnerabilities. It is simultaneously the new battlefield and a potential weapon of mass destruction — should access to it be selectively or systematically denied.
Over 80% of the UK's CNI is privately owned and maintained. According to the UK Infrastructure Strategy, investment requirements between 2023 and 2033 stand at between £700 billion and £725 billion across economic and social infrastructure. The question that demands an answer is whether the resilience dimension of this enormous investment commitment is being adequately assessed against the full spectrum of emerging and evolving threats.
A Significant Policy Gap
CNI appears only ten times in the entire UK National Risk Register (NRR). The majority of those references are definitional or illustrative — situating telecommunications or financial markets infrastructure within the CNI spectrum — rather than substantively addressing CNI resilience as a collective national vulnerability. More strikingly, CNI resilience does not feature in the NRR risk matrix, which is guided by the National Security Risk Assessment (NSRA).
This submission also notes that, upon enquiry, it has been advised that there is an official but no statutory legal definition of CNI within the UK government. Given that CNI constitutes a primary hybrid warfare target, the Committee may wish to seek confirmation of this position and consider whether legislative clarification is warranted.
There is, furthermore, a critical intelligence gap: CNI threat intelligence is not being systematically generated, mapped, or made available openly to the private sector entities that own and operate the infrastructure in question. Identified instances of corporate, SME, and supply chain manipulation, exploitation, subversion, disruption, and destruction — with particular reference to CNI assets and supply chains — indicate that the threat has already moved from hypothetical to operational. The question is no longer 'if' or 'when'; it is already underway.
5. Hybrid Warfare: The Two-Pillar Model
The UK's contemporary security challenge is best understood through the lens of hybrid warfare — a two-pillar model comprising National Defence (conventional military operations on the geopolitical front) and National Resilience (unconventional socio-economic operations on the home front).
The National Defence pillar, though currently under-resourced, benefits from an established budgetary framework, accepted threat assessments, and dedicated institutional architecture. The National Resilience pillar, by contrast, lacks credible open-source private sector intelligence, a dedicated resilience budget, or a ministerial structure of equivalent standing. Existing provision — primarily cyber-warfare frameworks and lower-level organisational resilience tools — provides no holistic deterrent against the unconventional socio-economic attacks being directed at both public and private sectors.
The result is a zero-funded approach to approximately 50% of national security. This is an asymmetry that adversaries have identified, documented, and are actively exploiting.
Figure 1: The Hybrid Warfare Two-Pillar Model — National Defence and National Resilience. Source: Ian Saunders, 2026.
6. Adversarial Doctrine: Are We Refusing to Listen?
Russia's hybrid warfare architecture is codified in the New Generation Warfare (NGW) doctrine, first articulated publicly in 2013 by General Valery Gerasimov, Chief of the General Staff of the Russian Armed Forces. China's equivalent is the Three Warfares Doctrine, which systematises Psychological Warfare, Media Warfare, and Lawfare as instruments of strategic competition. Both frameworks are less siloed than Western counterparts, prioritising the targeting of productive capacity, social cohesion, and governance operability over traditional military objectives.
Figure 2: The Gerasimov Doctrine — Russia's New Generation Warfare framework, placing unconventional operations primary to kinetic conflict.
Russia's phased approach to non-military influence is explicitly designed to reduce the cost — in human and economic terms — of any subsequent kinetic conflict. China's doctrine similarly positions cognitive and informational operations as precursors to and enablers of conventional military action. Both states have published these intentions; neither has concealed them.
Russia and China are in no doubt that they are engaged in the non-military, unconventional phase of a hybrid war with the West. The UK, meanwhile, continues to operate on a broadly peacetime footing — simultaneously supporting Ukraine in its kinetic conflict and providing material to counter Iranian-aligned forces, yet without applying the same urgency to its own unconventional vulnerabilities at home. This cognitive dissonance is itself a strategic liability.
Russian and Chinese hybrid warfare doctrine explicitly identifies national dependencies and resilience deficiencies as strategic vulnerabilities to be exploited in ongoing campaigns of targeted destabilisation. These states have made no secret of this. The question for this Committee is whether the UK's response matches the seriousness of the threat.
7. Cyber Warfare and the Vulnerability of the Data Supply Chain
The evolution of the internet has produced the most significant cultural and operational shift in human history since the invention of the printing press. Governments, economies, and civil society are now comprehensively dependent upon the internet to a degree that its failure has become almost inconceivable to those who rely upon it — though not, it must be noted, to those who seek to exploit that dependency.
The World Wide Web does not reside in a metaphorical 'cloud'. It travels through approximately 900,000 miles of fibre-optic cables spanning the world's oceans, connecting continents and underpinning the real-time movement of data that powers modern governance, commerce, and defence. In 2023, Telegeography estimated that these cables facilitate the daily movement of $10 trillion — a figure exceeding the annual GDP of many national economies.
According to research by CloudZero, a sustained national internet outage would cost the United Kingdom approximately $3.27 billion per 24-hour period. At that rate, the cumulative loss would equal the UK's entire annual defence budget within approximately 24 days.
The Fragility of Security Through Obscurity
Fibre-optic cables have, since their first deployment, relied principally on security through obscurity — an assumption that the technical complexity and geographic dispersal of undersea infrastructure provide sufficient deterrence against attack. In a benign threat environment, this assumption was defensible. In the current environment, it is not.
Russia and China have demonstrated sustained interest in Western online dependency and the vulnerability of undersea cable networks. Russia, notably, is actively developing strategic independence from the global World Wide Web — a capability investment that, in the context of hybrid warfare doctrine, should be interpreted as preparation for offensive disruption, not merely defensive self-sufficiency.
The transmission speeds and carrying capacity of modern fibre-optic infrastructure — which enable the emergence of artificial intelligence, cryptocurrency markets, and real-time global finance — also represent the scale of the exposure. A coordinated, multi-point attack on the data supply chain would not merely inconvenience; it would disable the UK's capacity to govern, to trade, and to defend itself. The cascading effects would be rapid, severe, and in the near term, irreversible.
The UK has, until now, relied upon a fragile hybrid peace to protect its most critical assets. That peace is no longer guaranteed. The question is whether the frameworks now being built are adequate to protect those assets when it ends.
8. Assessment
Of the two pillars constituting hybrid warfare, the UK's conventional defence readiness — while subject to justified scrutiny regarding funding levels — at least benefits from established institutional frameworks, threat assessments, and a dedicated budgetary process. The non-military, socio-economic pillar does not. The UK has dramatically fallen behind in a domain that, when effectively defended, is arguably more consequential than any single conventional military capability — because it is the domain in which adversaries are currently and continuously active.
History consistently demonstrates that peacetime complacency creates the conditions for strategic surprise. This is not a theoretical concern; it is a documented pattern that adversaries study and deliberately exploit. The 'Resilience Race' is underway. The UK is not yet competing in it at the required level.
9. Recommendations
The following three recommendations are submitted for the Committee's consideration. They are presented in order of strategic priority and are interdependent: each reinforces the others, and none is sufficient in isolation.
RECOMMENDATION 1: Establish a National Resilience Ministry
The Government should create a dedicated National Resilience Ministry with full Cabinet-level representation, a ring-fenced budget, and statutory responsibility for coordinating the UK's unconventional threat response across public and private sectors.
Rationale: Current resilience functions are distributed across multiple departments without strategic coherence or unified accountability. The NPSA, while valuable and proactive, operates as an office of MI5 — a structural limitation that inhibits the 'whole-of-society' mandate its mission requires. A dedicated Ministry would provide the institutional architecture necessary to integrate strategic, operational, and tactical resilience across CNI, the private sector, and government; to commission and act upon threat intelligence; and to ensure that resilience receives the funding and political visibility commensurate with its importance. It would also provide a single point of accountability — to Parliament, to industry, and to the public.
RECOMMENDATION 2: Establish a National Resilience Insight Database
The Government should fund and deploy an open-source National Resilience Insight Database — a dynamic, multi-sector threat intelligence platform through which the UK's CNI operators, private sector entities, and government departments can identify, map, and monitor unconventional socio-economic threats in near real time.
Rationale: The most consequential gap in the UK's current resilience posture is the absence of holistic, dynamic threat intelligence covering the full CNI spectrum. Unlike in the conventional military domain — where threat assessment is a core institutional function — no equivalent mechanism exists for the unconventional socio-economic domain. The private sector, which owns and operates over 80% of UK CNI, is being targeted without the intelligence tools necessary to understand and respond to the threats it faces. A national, open-source database and analytical capability — appropriately tiered and governed — would democratise threat awareness, enable coordinated response, and create the shared situational awareness that effective resilience requires. It would also generate the evidence base needed to inform legislative, regulatory, and investment decisions.
RECOMMENDATION 3: Develop a Sovereign Internet Capability
The Government should commission a programme to develop a resilient, independent sovereign internet capability — reducing the UK's catastrophic single-point dependency on global undersea cable networks and ensuring continuity of critical communications, governance, and commerce under contested or degraded conditions.
Rationale: The UK's total operational dependency on a globally distributed, predominantly unprotected fibre-optic data supply chain represents a strategic vulnerability of the first order. The financial exposure alone — estimated at approximately $3.27 billion per 24-hour outage — would exceed the annual defence budget within a month of sustained disruption. Russia's documented investment in developing independence from the global internet should be read as a strategic signal, not merely a technical curiosity. A sovereign internet capability — whether based on dedicated domestic infrastructure, enhanced satellite contingency, or a combination of approaches — is not a luxury; it is the digital equivalent of maintaining a strategic reserve. The programme need not replace the existing internet for everyday use; it must ensure that critical national functions can continue to operate when that internet is compromised.
In addition to this recommendation, it would be proposed that a National minimum level of relevant cyber protection be introduced across each sector of the CNI spectrum and its supply chains. This would ensure a collective level of cybersecurity and protection that could be monitored for vulnerabilities across all (strategic, operational and tactical) levels.
23 April 2026