> For the complete documentation index, see [llms.txt](https://guidance.ctag.org.uk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guidance.ctag.org.uk/horizon-scanning-2020.md).

# Horizon Scanning 2026

{% file src="/files/QFHhTBZApncvFC6Fcw9k" %}

**Introduction**

Horizon Scanning Definition:

**Horizon scanning** is a technique for detecting early signs of potentially important developments through a systematic examination of potential threats and opportunities, with emphasis on new technology and its effects on the issue at hand.

Source: <https://www.oecd.org/site/schoolingfortomorrowknowledgebase/futuresthinking/overviewofmethodologies.htm>

Horizon Scanning exists with a proper method that gets used within the commercial world, in the Government \[1], Health \[2], Military \[4] and Intelligence communities.

We’ve seen a lot of this work during the COVID-19 pandemic in the Health sector, referenced in \[2] above, it’s a valid and useful model, for planning and understanding the word and the surrounding complexity.

There is an excellent detailed handbook on Horizon Scanning \[3], which will help you if you wish to dive deeper into the subject.

You can't do horizon scanning within the constructs of a static system, it is dynamic thing. It is a moving fluid events driven paradigm and things change. So what does this mean on a day-to-day basis?  That means monitoring what's on the news, the big global and macro issues;

&#x20;The War in Ukraine

The Energy Crisis / Prices&#x20;

Cost of Living Concerns

&#x20;Climate Change,

On-Going Cyber Threats & Scams

Tiger Economies in Asia \[5], trade and Global Economies of China, Russia, the US, and Asia-Pacific Countries.

There are the issues raised in the Green Economy, new emergent issues like Doughnut Economics \[6].

These are all things, which have nothing to do with Cyber Security and Resilience, but everything to do with the economy and the way the criminals, hackers and foreign hostile states think. Foreign states and even our own all driven by a “Doctrine” \[7]. This includes the UK Cyber Doctrine \[8], that drive the military objectives, which on the civic side through the work of the Cabinet Office National Cyber Security Programme \[9], and the NCSC \[10]. Making sure you've got a good source of rich knowledge in terms of newsfeeds blogs, push content (Podcasts / blogs/ news feeds) notes and qualitative research memos\[11] from conversations, things you come across, reports that get written and just generally understanding your environment.&#x20;

Horizon scanning can take account of major news events and things happening in the country and globally. Obviously, you can’t track everything, but you’ll develop a set of “Lenses”, we refer to as Contexts. A few big issues to consider that could affect Cyber Security are

&#x20;• global warming

&#x20;• pandemics political elections,&#x20;

&#x20;• political takeovers in countries,

&#x20;• insurrections,&#x20;

&#x20;• civil unrest,&#x20;

Things that are going on within the environment of your own organisation. Horizon scanning is about looking at asset & risk management, threats,

facilities, vulnerabilities and exploits. Risk analysis and risk management and risk planning is all about understanding the current threats that you're facing vulnerabilities and In a complex computer system, there might be 50 vulnerabilities, but 49 of those vulnerabilities, remain unexploited. However, if more of those vulnerabilities start to get exploited. we often refer to zero-day exploits, that means someone has&#x20;

taken a theoretic vulnerability and turned it into an actual exploit and have been able to affect

the cause that they were seeking to do in relation to that vulnerability. that's when you've got a problem,&#x20;

that's when companies like Microsoft, Amazon, Google, release patches against current detected and reportedbvulnerabilities, hopefully before they become exploitable, but sometimes an exploit happens and it quickly industry has to move to patch that vulnerability.&#x20;

This has happened recently for instance attacks on Citrix and VM-ware, it is these are zero day (unpatched) vulnerabilities that are dangerous. Sometimes known vulnerabilities are kept secret and these are known as “equities”\[12], which can be used by foreign state actors for cyber-attacks, surveillance and espionage.

We can change our world view\[13] when new information comes to light. In fact refusing to change your worldview for political or organisational reasons in the light of new knowledge and information can lead to real world problems.

There is much to learn from Systems Theory\[14] and complex systems that can inform the horizon scanning process and approach.

We're constantly retraining, rechecking, reassessing, everything that's going on. We don't often know&#x20;

how critical a vulnerability, or a thing is. So, what we do is we use a five-by-five classification approach to help inform the process. The 5x5 intelligence classification system\[15] is used widely in the Police and Intelligence services.

These are known as sometimes as intelligence assessments\[16] or referred to as an Intelligence Estimate, by our American colleagues. An output from the intelligence process, becomes a product\[17], it means&#x20;

it's gone through the whole assessment machinery.

Part of that assessment machinery is the horizon scanning and validation of facts. So, using a five-by-five matrix gives a level of confidence and these assessments are constantly changing as well. So, I hope&#x20;

that basic introduction to riser scanning has been useful. And we will look at some of these areas now in more detail.

As we move into 2026, cybersecurity has transitioned from a niche technical concern to a fundamental pillar of organisational survival and national prosperity. The landscape is no longer defined by isolated malware attacks but by a professionalised, adaptive industry that exploits human trust, regulatory gaps, and systemic fragility. We have reached a tipping point where organisations that rethink their operating models will succeed, while those remaining reactive will face disproportionate harm.

Cybersecurity failure is now viewed as a failure of corporate governance. Regulators are shifting focus toward holding Directors and Officers personally accountable for data security negligence. Boards are now expected to treat cybersecurity as a fiduciary duty, ensuring it is a standing item on every agenda. Furthermore, cyber insurance is moving from a "nice to have" to a mandatory requirement for doing business, with insurers demanding demonstrable evidence of active monitoring and incident response capabilities.

**Digital Ethics**

Digital Ethics\[53] are something you might not consider. It might not have heard of, but it is&#x20;

really important. Why are  ethics so important then? Ultimately ethics define the moral boundaries that we need to stay within, through policy and consideration of societal acceptability. We all know about Human Rights, well that’s what ethics are. My philosophy has always been “At what price?” That relates to how badly you want something and the lengths your prepared to go to get them, “At what cost” to friends, relationships and consequences. The law also reflects a set of societal norms, in terms of our criminal laws and the punishments we have for breaking them. There are many ethical concerns at this time around Covid-19, Social distancing, lock downs, the acceptable way to behave and of course the vaccines being developed, who get them first, prioritisation and the order of events, these are all ethically driven \[54]decisions. That set’s the context for ethics, as we turn to digital ethics, they are the rules and algorithms that drive machine learning and artificial intelligence\[55]. We are getting use to the idea of driverless autonomous cars and vehicles, we hope they are programmed to do the right thing. Would we be as happy knowing a car had a peace and as war mode?....

When cybernetics first started and robots were the stuff of science fiction  stuff, right back in the days&#x20;

of guy Norbert Wiener\[29] a brilliant MIT Student in the 1950’we know that some of you might never&#x20;

have heard about him, he was an MIT student and went on to doing some of the founding work&#x20;

on cybernetics. It was always the intention to design machines that must not hurt the creator\[56].&#x20;

So if you think about the Terminator film and the robots, not to destroy their creators. That's called non malfeasance, do no harm. Digital Ethics is looking at how machine learning and artificial

intelligence is actually helping shape how these things work, Tesla cars, you don't own the software, you licence it. I'll talk about it more a bit later, but you're actually licensing the software. So when you get&#x20;

into a car and it's driving itself, it's been driven by algorithms. The algorithms get to make we hope ethical decisions all the time about what to do and what not to do. Is it a good thing trusting our lives to hope? you really need to have an understanding about digital ethics.&#x20;

**Smart Cities**

Smart Cities\[57]. Again, it's something that's emerging is bringing all the bits together. Because if you look at the internet of things, that's given us far more contextual information.&#x20;

If you look at some machine learningartificial intelligence and algorithms it, then culminates in what we're doing is smart cities . Aren't anything new, but bringing them all together actually is we're getting

&#x20;far more integrated around our  CCTV and transport networks. We've got travel cards.&#x20;

It's the Oyster card down in London.&#x20;

There are lots of other travel cards. Now, bike hire school, scooter hire all those fobs. Every time you get&#x20;

one of these higher bikes out, you “touch-in” your smart token on NFID device (such as your smart phone). Your then charged through your user account. But that token and account is tracking where you&#x20;

got the bike/scooter from, where you started your journey at what time, where you checked the bike/scooter back in (your Destination), the duration of your travel and likely through Geo-tracking technology in the bike/scooter, your route. This Geo-Temporal information is you leaving a deep, rich, digital footprint everywhere you go. Your journeys are being tracked so this is where ethics and privacy come into play in this poor wifi smart roadsigns smart motorways. It's all really joining everything up. A person, event, location and time. The Law Enforcement, Military and intelligence Agency dream.\[58]

People will know where you are, what you're doing. Data protection, privacy and Civil Liberty, and freedom, and everything is going to go far beyond where we've been in the past. In the past, it's all been&#x20;

about geo temporal information, but in the future, it's all about geospatial information as well. So the&#x20;

world is moving on at pace, but all of these disparate things are building up into a layered taxonomy. Now through cloud, through the software defined networks, zero trust the algorithms, digital ethics, and then&#x20;

culminates in smart cities. Not just what building you were in, but the floor, desk and device locations too.

Good security network architectural design, understanding that there are work flows following the&#x20;

data which we've always been doing with data protection and data privacy impact assessments.&#x20;

But you do need to understand your suppliers and your third parties, especially those processing your data that they are doing so in an ethical way.&#x20;

You do need to understand your supply chain, what kit you're buying works come from. Have they tested itYou do need to have dynamic business continuity. Now you need to start making staff aware of all this&#x20;

new technology and how it affects them. And if you need to have really good detailed documentation and&#x20;

you need to have a really good detailed diagrams and configuration, that's really important.

**Section 2 - Emergent Threats – What we’re seeing on the radar**

**Introduction**

Emerging threats again are some familiar topics that are today coming to the forefront of the threats we are facing on and seeing in our networks and on the Internet. Many of these you will know about, we aim to give you a better context. A quick recap on what we talk about as information assurance.\[59]

* **Confidentiality**, keeping information safe and secure accessible to those who are authorised
* **Integrity** – Ensuring the Information is accurate and hasn’t been altered.
* **Availability** – The ability to ensure we can access these systems and services when we need to.

**Virtualization.**&#x20;

Virtualization issues haven't gone away. The technology has been with us around forty years, going back to mainframes. The VMware sever is a great product, but it's got to be properly configured it can still be compromised. We need to make sure that the management layer is all completely locked down and is

being monitored. Understanding who's got access to it and all the different workloads are properly segmented and configured \[60].

Having remote suppliers providing technical via VPN connections into your network, is fine, but do you monitor their activities and ensure their sessions are terminated and logged afterwards? This issue has been with us for the past fifty years, going back to the days or remote mainframe access via remote dial up terminals and even teletypes, yet in this automated digital Internet, mobile device age, it is still a current problem!

If they're looking after, a server farm on your premises and keep using a VPN to gain access, especially working from home, do you close that session down afterwards? Technical Support with Remote Desktop Access enabled, are the remote access sessions monitored and recorded? &#x20;

Containers as a technology have been used for a long time, but it's only just beginning to find&#x20;

its way into local government circles, but certainly been in central government for the past eight years and all the digital transformation stuff we're doing now, as you moved towards cloud and everything,&#x20;

it's becoming to be very, very pervasive, but a badly configured Docker container is a very dangerous thing

you need to do code reviews and smoke tests. Only then can you trust the container configuration for automated continuous integration and deployment.

I've been playing around with some security tools, which are on Git Hub and downloading other people's&#x20;

Docker containers. If you're going to play with stuff make sure you trust the source code, use a sandbox machine and monitor what he containers are doing on your systems.

I was looking at some particular containers and what was going on inside it looking at what was going on&#x20;

behind the scenes, via a command line terminal as they're spinning up, there were all sorts of erroneous

bits of code being spun up in the background. That wasn't necessarily part of the thing that the container&#x20;

was being used for. So when you start getting into these things, make sure you understand how it works&#x20;

and make sure you do code reviews and smoke testing and monitoring of the traffic and know what data is going into the containers and what's coming out of it. Continuous integration is the orchestration layer I&#x20;

was talking about earlier. Software like Jenkins and chef and lots of other new tools that are coming along.

Virtualization you really need to understand it. Quizzing your suppliers on the assurance side, might&#x20;

not only show you understand your supply chain security. might show, you know, what's happening.&#x20;

**Phishing**

Phishing might seem like it was yesterday's news, but it isn't. At the moment, it is the single biggest attack&#x20;

vector and the problem with phishing is that getting more and more sophisticated, starting to introduce&#x20;

primary, secondary and tertiary types of attack vectors. You may get an email that might also get an SMS message. You might even get a voice call and an awful lot of financial fraud is happening as the criminals themselves are going on-line because of the Covid restrictions and change of opportunities.

For instance, in the banking sector. Now you're getting it all followed up with a phone call. You're on a&#x20;

telephone to somebody and their say about this problem, you’re your bank account or they have detected a virus remotely on your computer. It's getting very, very sophisticated.&#x20;

We're actually seeing things out there now where you're getting SIM takeovers, so they can make their mobile phone look like your to the bank. Spoofing you number or that of your banks.

So you can't even rely on the phone number to be truthful. There is fraud utilising the SIPP IP Protocol, spoofing messages and contact centre details.

SIP is the voiceover IP protocols being used in some of this stuff\[61]. And the other thing that's starting&#x20;

to emerge with phishing attacks, I'm afraid issues and things like that. teams. So even Microsoft Teams\[63], is now becoming an attack vector\[64]. You need to bear in mind that these attackers

are getting more and more sophisticated. Make sure you are talking to our staff and doing awareness

raising because partially it's it's high, but awareness raising campaigns are the best line of defense. You've got the next slide please.

Blended attacks, are where you're starting to see attackers as I was just saying with phishing building&#x20;

stuff up. So NCSC National Cyber Security Centres, active cyber defence, ACD tools, come in really useful. The public DNS service (PDNS) \[65]  is available to all public sector bodies&#x20;

free of charge. The only problem with not using PSNs is of you running things like Cisco umbrella because NCSC are aware of incompatibilities. But when I was talking about, security zoning and domains earlier on, you might even want to think about splitting up some of your and IP ranges for different parts of

what you're doing and using PDNS, which when connected immediately flags malicious activities.

You have to remember is that the criminals now all starts in with their own pyramid of pain, because a lot of the, people deploying EMOTET\[64] at the bottom of the pyramid , the bottom level of these attacks&#x20;

are script kiddies, low value attackers and hackers. But the minute a machine beacons out after a successful takeover,  phone's back and says, yep, I've got into that network. They are then selling those credentials on those IP addresses to the next level of criminals up. Finally that's when you get in a tight spot of really&#x20;

serious people doing the malware attacks. And there has been a massive prevalence of malware and the

ransomware as an attack vector, especially since we've experienced the Covid lockdown and are working from home. The criminals are sitting at home plenty of time on their hands and they follow the money.&#x20;

**PROINT (Protected Information Intelligence)**

A new Provence is Protected Information Intelligence. This is where criminals are trying to steal&#x20;

protected, credential information, credit card information, you private identity information.&#x20;

But apart from these identities, the other stuff you've got to be aware of now is location information is becoming to be valuable because criminals know where you are.“I know you're not at home”. That is scary that you need to think through where this stuff's all going and biometric data as well. Biometric facial recognition say for mobile phone or laptop login. It's all new types of information and&#x20;

credentials that criminals are after.&#x20;

So you need to think that now it's all about passwords to biometrics, putting multiple lives, the text, Memphis there's personal information and privacy, all the same thing that you've got to remember that youngsters have a very different feel about privacy. And the fact that sometimes convenience can override privacy&#x20;

and they don't necessarily have the same view about this as we do in our generation.

So you need to bear that in mind, protected information is what people are after, because that's where the money is, wearables, body networks, smartphones, Fitbits etc. It's collecting all sort of information,&#x20;

proximity networks as well. Cars now have wifi networks or their own Bluetooth. It's always on, it's a new world we're moving into, but the really exciting stuff.&#x20;

The core of this whole talk for this second part of emerging threats, everything we do, which gives us an&#x20;

opportunity, brings me challenges and attack vectors. We've augmented reality now (Some will have seen tee new EE mobile phone advert for the iPhone 12) which shows an augmented reality scene over the roof tops of the city of London.

It is as much about geospatial information, not just knowing where you are, but what floor you're on, what&#x20;

office you're in. You're in, within a building, what shop you're in, in, within a shopping center, it's tracking these metrics. In time as we get more into this augmented reality and Facebook, Google, Apple, they're all working on new sets of super specs. The age of Joe 90 really is upon us.

A whole new world that is going to be a very different place in the next couple of years, what life&#x20;

boundaries are going to get blurred and working from home is going to be the new normal. So you need to think these issues through. Oculus has now been bought out by Facebook. You can't use the new Oculus&#x20;

Quest 2 devices unless you've got Facebook account. I've started doing some research on all of this&#x20;

right now, and it's going to take me a while to synthesize it all. Believe me, sitting there with a virtual&#x20;

reality headset on and doing work and coming up with all these computer screens from the fiscal world,&#x20;

moving into that new, augmented reality and virtual reality is going to be a way that if we're going to be&#x20;

working from home, someone's going to have the bright idea of, Oh, you won't be just about  MS teams&#x20;

anymore.

Should we use the, the new Facebook infinity office that, Facebook's working on right now. If you&#x20;

haven't do it, go and have a look, but that's where ethics come in. New personas. Will you have a different view for work and virtual reality to your persona at work and in our climate, in the real world, all you start to think about, especially with data protection, for the right speed forgotten. It's a new world of pain trying to manage multiple personas because Facebook won't let you do that. You've got to use your real personal Facebook account with your real personal identity to use the virtual reality stuff. Interesting times ahead.&#x20;

The global situation in 2026 is marked by a definitive shift from the old order to a more volatile "new order". Key factors influencing this include:

•           Opportunistic Aggression: Geopolitical rivalries, including the ongoing war in Ukraine and rising tensions between global powers, have normalised infrastructure failures and extreme economic uncertainty.

•           The War for Compute: Access to the physical technologies and talent required to process data—"compute"—has become a defining geopolitical risk. Access to this infrastructure is increasingly controlled by states, leading to stepped-up regulation and strategic competition.

•           Organised Crime as a Proxy: Hostile state actors are increasingly using networked criminal groups as proxies to exploit geopolitical rivalries. These groups operate with high reach and low cost, often targeting business processes rather than just computer systems.

•           Social and Political Grievances: Growing polarisation and "democratic backsliding" are eroding trust in institutions, leading to faster, more intense social unrest that can ignite with little warning.

&#x20;

**Dominant Trends and Emerging Threats**

Five core trends will dominate the risk landscape for UK organizations this year:

1\.        AI-Driven Deception at Scale: Generative AI has enabled "deceptive realism". Attackers now create hyper-realistic impersonation attempts via synthetic voice calls and deepfake videos that mimic executives or suppliers with near-perfect accuracy.

2\.        Machine-Speed Attacks: AI-powered reconnaissance and adaptive malware now rewrite themselves to bypass detection at "machine speed," easily outpacing traditional human-led security teams.

3\.        The Supply Chain as a Weapon: Smaller vendors have become the preferred entry point for attackers. Taking down a single crucial vendor can stop the operations of a global brand, creating a "domino effect" across the ecosystem.

4\.        Digital Extortion Beyond Ransomware: Threat actors have shifted to multi-vector extortion, combining data theft, regulatory pressure, and operational disruption. In the UK, new legislation prohibits publicly funded entities from paying ransoms, forcing a rapid shift toward robust resilience rather than negotiation.

5\.        OT and IoT Exposure: Manufacturers are pushing internet-connected features into legacy Operational Technology (OT) and Internet of Things (IoT) devices without adequate security, expanding the attack surface into physical infrastructure such as healthcare, transport, and utilities.

&#x20;

&#x20;

**Actionable Insights for Senior Leaders**

To navigate 2026, the following strategic actions are recommended:

•           Implement a Zero-Trust Baseline: Remove the assumption that anything inside your network is safe. Continuous verification of every user and device must become the norm.

•           Map and Assess Third-Party Risk: Only 14% of UK businesses currently review their supplier security. Leaders must move beyond this, ranking suppliers by risk level and setting clear rules in contracts.

•           Shift from Protection to Resilience: Recognise that a breach is probable. Invest in Managed Detection and Response (MDR) to provide the automated analysis required to counter real-time threats.

•           Institutionalise Red Teaming: Regularly simulate real-world attacks to test the effectiveness of decision-making processes and identify procedural blind spots.

•           Fix Broken Policies for AI: AI can drive efficiency, but automating bad processes only accelerates failure. Fix organisational policies before embedding AI agents into daily operations.&#x20;

&#x20;

&#x20;

&#x20;

**References: (All accessed July 2026)**

\[1] <https://www.gov.uk/government/groups/horizon-scanning-programme-team>

\[2] <http://portal.healthworkforce.eu/what-is-horizon-scanning-and-why-is-it-useful/>

\[3] <https://www.theirm.org/media/7423/horizon-scanning_final2-1.pdf>

\[4] <https://www.rand.org/blog/2019/02/how-horizon-scanning-can-give-the-military-a-technological.html>

\[5] <https://www.kent-life.co.uk/people/the-global-business-forecaster-kent-s-richard-scase-1-4435705>

\[6] <https://www.kateraworth.com/doughnut/>

\[7] <https://www.gov.uk/government/collections/joint-doctrine-publication-jdp>

\[8]<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/549291/20160720-Cyber_Primer_ed_2_secured.pdf>

\[9] <https://www.nao.org.uk/report/progress-of-the-2016-2021-national-cyber-security-programme/>

\[10] [https://www.ncsc.gov.uk](https://www.ncsc.gov.uk/)

\[11] <https://study.sagepub.com/sites/default/files/Birks_2008.pdf>

\[12] <https://www.ncsc.gov.uk/blog-post/equities-process>

\[13] <https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6735033/>

\[14] <https://uk.sagepub.com/sites/default/files/upm-binaries/49393_Walker,_Chapter_One.pdf>

\[15] <https://www.app.college.police.uk/app-content/intelligence-management/intelligence-report/>

\[16] <https://www.justsecurity.org/68075/three-things-to-look-for-in-the-2020-worldwide-threat-assessment-from-the-u-s-intelligence-community/>

\[17] <https://www.app.college.police.uk/app-content/intelligence-management/intelligence-products/>

\[18] <https://sloanreview.mit.edu/article/how-to-make-sense-of-weak-signals/>

\[19]<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/311572/20110830_jdp2_00_ed3_with_change1.pdf>

\[20] <https://worldview.stratfor.com/article/practical-guide-situational-awareness>

\[21] <https://hbr.org/2014/09/contextual-intelligence>

\[22] <https://azure.microsoft.com/en-gb/overview/what-is-cloud-computing/>

\[23] <https://www.redhat.com/en/topics/cloud-computing/what-is-cloud-infrastructure>

\[24] <https://www.gov.uk/government/publications/essential-digital-skills-framework/essential-digital-skills-framework>

\[25] <https://link.springer.com/chapter/10.1007/978-3-319-77839-6_3>

\[26] <https://www.ibm.com/uk-en/cloud/learn/iaas-paas-saas>

\[27] <https://www.cisco.com/c/en_uk/solutions/software-defined-networking/overview.html>

\[28] <https://docs.microsoft.com/en-us/azure/devops/learn/what-is-infrastructure-as-code>

\
\[29] <https://mitpress.mit.edu/books/norbert-wiener-life-cybernetics>

\
\[30] <https://aws.amazon.com/cloudhsm/>

\[31] <https://www.cbronline.com/feature/punched-tape-ukkpa>

\[32] <http://www.serverspace.co.uk/blog/containerisation-vs-virtualisation-whats-the-difference>

\[33] <https://codeship.com/continuous-integration-essentials>

\[34] <https://cyclr.com/orchestration-layer>

\[35]<https://www.researchgate.net/publication/319487635_Research_of_Penetration_Testing_Technology_in_Docker_Environment>

\[36] <https://www.infoq.com/articles/practices-better-code-reviews/>

\[37] <https://docs.microsoft.com/en-us/azure/aks/operator-best-practices-multi-region>

\[38] <https://www.ncsc.gov.uk/blog-post/zero-trust-architecture-design-principles>

\[39] <https://www.wandera.com/zero-trust-security/>

\[40] <https://www.ncsc.gov.uk/collection/mobile-device-guidance/infrastructure/network-architectures-for-remote-access>

\[41] <https://www.cyber.gc.ca/en/guidance/network-security-zoning-design-considerations-placement-services-within-zones-itsg-38>

\[42] <https://www.zachman.com/ea-articles-reference/58-conceptual-logical-physical-it-is-simple-by-john-a-zachman>

\[43] <https://www.opengroup.org/togaf>

\[44] [https://sabsa.org](https://sabsa.org/)

\[45] <https://livebook.manning.com/book/microservices-security-in-action/chapter-1/1>

\[46] <https://www.microsoft.com/en-gb/security/business/zero-trust>

\[47] <https://www.pwc.com.au/pdf/essential-8-emerging-technologies-internet-of-things.pdf>

\[48] <https://www.i-scoop.eu/internet-of-things-guide/>

\[49] <https://csrc.nist.gov/CSRC/media/Projects/Supply-Chain-Risk-Management/documents/briefings/Workshop-Brief-on-Cyber-Supply-Chain-Best-Practices.pdf>

\[50] <https://www.thethingsnetwork.org/docs/lorawan/>

\[51] <https://www.ncsc.gov.uk/section/advice-guidance/all-topics?topics=artificial%20intelligence>

\[52] <https://www.ncsc.gov.uk/section/products-services/active-cyber-defence>

\[53] <https://socitm.net/wp-content/uploads/2020/10/Digital-ethics-table.pdf>

\[54] [https://www.moralmachine.net](https://www.moralmachine.net/)

\[55] <https://plato.stanford.edu/entries/ethics-ai/>

\[56] <https://www.newscientist.com/article/2175195-robot-laws-5-new-rules-that-could-save-human-lives-at-least-on-tv/>

\[57] <https://www.centreforcities.org/reader/smart-cities/what-is-a-smart-city/>

\[58] <https://fas.org/irp/agency/nga/doctrine-2018.pdf>

\[59] <https://www.theguardian.com/government-computing-network/2011/jun/13/local-cio-council-information-assurance-strategy-mark-brett>

\[60]<https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/network_segmentation.pdf>

\[61] <https://link.springer.com/chapter/10.1007/978-3-642-11530-1_10>

\[62] <https://secureteam.co.uk/news/microsoft-office-files-increasing-used-as-attack-vector/>

\[63] <https://resources.infosecinstitute.com/topic/hacking-microsoft-teams-vulnerabilities-a-step-by-step-guide/>

\[64] <https://www.ncsc.gov.uk/news/ryuk-advisory>\[65] <https://www.ncsc.gov.uk/information/pdns>

!\[Shape

Description automatically generated]\(/files/-Mj9At5Ly8WUs9ySWcAy)

![](/files/-Mj9At5Mjojm6TXqX2gQ) [www.nlawarp.net](http://www.nlawarp.net/) @nlawarp

!\[A picture containing logo

Description automatically generated]\(/files/-Mj9At5N33UXOWKn-khq)

<https://www.londonmet.ac.uk/research/centres-groups-and-units/cyber-security-research-centre/>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://guidance.ctag.org.uk/horizon-scanning-2020.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
