All Insights

Why Legacy Compliance Won’t Protect Tomorrow’s Digital Infrastructure

Cyber Security • September 15, 2026 • Written by: Gareth Jones • Read time: 5 - 7 min

Preparing for the Next Shock: Why Legacy Compliance Won’t Protect Tomorrow’s Digital Infrastructure 

Connecting National Security Intelligence with Practical Enterprise Architecture & NCSC Secure by Design Principles 


“We must of course always learn from the last attack – but must beware of preparing brilliantly to fight yesterday's enemy, using yesterday's methods, against yesterday's target. The uncomfortable truth is that the next strategic shock may already be taking shape somewhere we are not yet looking.”

— Sir Ken McCallum, Director General, MI5


When MI5 Director General Sir Ken McCallum delivered his commentary reflecting on 25 years of evolving threat vectors, his primary warning was not simply about counter-terrorism. It was a fundamental critique of organisational complacency. 

In our day-to-day work delivering digital transformation at Methods, this operational trap is something we navigate continuously. Organisations invest heavily in perfecting static compliance frameworks designed around past incidents. Yet, when critical digital services face novel, multi-vector threats ranging from grey-  one supply chain compromise to rapid advancements in post-quantum vulnerability, traditional tick-box security fails to hold the line. 

While these challenges are often discussed in the context of high-assurance, air-gapped sovereign cloud environments, air-gapping is simply a boundary condition, not a different set of security physics. The reality is that these principles apply universally across every modern IT estate. To build genuine digital resilience across government, critical national infrastructure, and enterprise IT, we need to bridge the gap between high-level national security intelligence, user-centered service delivery, and practical architecture. 

The Universal Operational Trap: Yesterday’s Methods vs. Tomorrow’s Reality 

  • The Myth of the Perimeter Shell: Traditional IT relied on building thick outer walls, whether a corporate firewall or a physical air-gap, and importantly assuming everything inside was inherently trustworthy. Modern threats bypass perimeters through compromised supply chain updates, insider risk, and third-party SaaS integrations. Zero Trust is no longer optional for any estate. 

  • Operational Ambiguity During a Crisis: One of McCallum’s most pointed questions hits directly at governance and target operating models: “We cannot wait for the next shock to discover who owns the vulnerability, who has the authority to act, or who was supposed to pick up the phone.” In complex multi-cloud ecosystems crossing department boundaries and supplier networks, unclear ownership turns manageable incidents into catastrophic outages. 

  • Static Accreditation in a Dynamic Landscape: Point-in-time compliance signoffs create a dangerous illusion of safety. Threat vectors do not pause because a system passed a gate check six months ago. Whether preparing for an ISO audit or a formal accreditation gate, static compliance fails everywhere when architectures are too rigid to integrate continuous threat intelligence.

Aligning Enterprise Resilience with NCSC Guidance 

At Methods, our approach to digital transformation centers on moving past legacy security by embedding the National Cyber Security Centre (NCSC) Secure by Design principles and the Cyber Assessment Framework (CAF) directly into the service delivery lifecycle.

 

LEADERSHIP & GOVERNANCE

Target Operating Model with Clear Vulnerability & Service Ownership

CONTINUOUS ASSURANCE & CAF

Real-Time Telemetry • Agile Cryptography • NCSC Principles

HYBRID, CLOUD & SOVEREIGN INFRASTRUCTURE

Multi-Cloud Resilience • Supply Chain Attestation • Zero Trust

 

  • Continuous Assurance Over Point-in-Time Sign-Off: Security must be treated as an ongoing operational discipline. NCSC Principle 09 (Embed continuous assurance) mandates that telemetry, automated guardrails, and threat-led testing run continuously throughout the service lifecycle. 

  • Flexible Architecture and Crypto-Agility: Designing for resilience means building modular environments capable of adapting as standards evolve. Preparing for Post-Quantum Cryptography (PQC) and sovereign data protection requires underlying architectures that support seamless upgrades without disrupting critical operations. 

  • Usable Security That Supports Operational Pace: NCSC Principle 04 (Design usable security controls) stresses that security mechanisms must align with human workflows. Controls creating excessive friction force users to invent workarounds creating the exact unmonitored blind spots intelligence agencies warn against.

The “How”: Operationalising Resilience in 4 Execution Phases 

Transitioning an enterprise from static compliance to NCSC-aligned resilience isn't an abstract theory it requires structural execution built directly into the Target Operating Model: 

1. Shift Security Left into Discovery & Alpha — Security architecture must be defined alongside user needs from day one. Threat modeling and NCSC Secure by Design outcomes must shape technical requirements before code is written or infrastructure is provisioned. 

2. Automate Guardrails into the CI/CD Pipeline — Replace manual, late-stage security gateways with automated compliance policy checks, container scanning, and continuous integration testing. Security assurance becomes a real-time byproduct of deployment rather than a bottleneck. 

3. Establish Unambiguous Single-Point Ownership — Codify service ownership across hybrid and multi-cloud environments. Every digital asset, API, and dataset must have an explicit operational owner accountable for vulnerability management, supply chain risk, and incident escalation. 

4. Implement Continuous CAF Outcome Benchmarking — Move away from annual audits by operationalising the NCSC Cyber Assessment Framework. Use live telemetry and automated posture monitoring to assess CAF indicators of good practice in real time. 

Designing for the Unknown 

High-assurance, air-gapped environments simply force us to solve these architectural challenges under the most demanding conditions. But the core lessons of crypto-agility, continuous assurance, automated guardrails, and unambiguous ownership are the baseline requirements for any resilient modern IT estate. 

We cannot predict the exact nature or timing of the next strategic shock. However, as technology leaders, program directors, and practitioners, we have absolute control over how our architectures and operating models are built to respond. 

Sovereign and enterprise cloud resilience is not achieved by building higher walls around outdated systems or hiding behind point-in-time accreditation. It is achieved by establishing accountable governance, embedding NCSC-aligned outcomes into continuous delivery, and building flexible digital services capable of absorbing unexpected shocks without compromising public trust or critical operations

The threat landscape has evolved. It is time for our delivery models to do the same. 

Gareth Jones

Gareth Jones is UK Group Chief Information Security Officer (CISO) for the Alten Group, where he leads cyber security, information assurance, and digital risk strategy across the UK organisation. With over 25 years’ experience in IT and cyber security, Gareth specialises in aligning enterprise cyber strategy to business risk, enabling secure digital transformation across government, defence and regulated sectors. He is an NCSC-recognised Cyber Consultancy Service Owner and Head Consultant for Risk Management and Security Architecture, with extensive expertise spanning cloud platforms (Microsoft Azure and AWS), enterprise architecture, and security governance aligned to ISO 27001, ISO 22301, ISO 27017, ISO 42001 (AI Management Systems), and the NCSC Cyber Assessment Framework (CAF). Operating at board level, Gareth advises executive teams on cyber risk, resilience and secure technology adoption, driving investment-led transformation to protect critical services and underpin organisational growth.

Back to top