GCHQ has warned that government procurement rules “designed for the 1900s” are making it harder to turn British technology into national security capability – and risk pushing promising companies overseas.
Hannah Lim, director general of technology at GCHQ, said the intelligence agency has undergone a “massive shift” in how it works with industry as technological expertise increasingly moves beyond government.
“If you go back not that long ago, really 20, 25 years ago, pretty much all the things GCHQ did, we were world-class at it in-house, and that’s where the majority of the ideas came from,” Lim said at the Resilience Conference in London.
Today, GCHQ recognises that other organisations are better than it in some areas making closer partnerships with industry essential. “We know we will not succeed unless we bring those ideas in,” she said.
But Lim said the challenge is increasingly what happens next: taking technology that has proved its value and getting it deployed across government.
“For me, the next step is then how do we actually transition those ideas into enterprise-scale solutions?” she said. “And that’s still tricky because we are using government procurement frameworks and rules that were essentially designed for the 1900s.”
She added that small companies cannot be expected to wait six months for government invoices to be paid, and urged industry to “hold our feet to the fire” on whether promising technology is actually pulled through and scaled.
The consequences go beyond individual programmes. Lim warned that companies may choose not to remain in the UK unless there is both a healthy investment market and a route to government contracts.
“You then need contracts, so companies are incentivised to stay here,” she said.
The government is attempting to tackle that gap through organisations including HMGCC and the National Security Strategic Investment Fund (NSSIF).
Simon Fabri, HMGCC’s chief executive, said its traditional model of developing technology internally and through conventional contracts could no longer keep pace with the range of threats facing the UK.
“This approach doesn’t scale,” he said.
HMGCC now runs a co-creation programme that turns classified national security requirements into problems that can be shared openly with industry. Fabri said around 100 companies have successfully passed through the pipeline, with individual challenges typically attracting about 100 applicants.
The scale-up problem remains, however. Paloma McGuiness, chief executive of NSSIF, said the fund has developed processes that can get companies under contract within a couple of weeks, but moving successful projects into full procurement is the next hurdle.
“Getting the money at the start isn’t such a challenge,” she said. “Finding the right route into government is still not straightforward.”
Fabri described the industry’s much-discussed “valley of death” as a real problem, caused by technology entering the system but not being pulled through into operational use quickly enough.
The pressure to fix that is growing as the threat environment accelerates. Lim said GCHQ has been building up its readiness for greater state threats for at least five years, while AI could give the agency a way to overcome some of its own capacity constraints.
“We are now on the cusp of an abundance of cognition,” she said, arguing that AI agents could take on engineering work and free up specialists to focus on bringing external technology into GCHQ.
Lim said the UK already has “a really good, strong position on AI at the top secret level,” which she described as “pretty unrivalled amongst similar countries.”
She also pushed back on the idea that Britain must achieve complete technological sovereignty, arguing that global supply chains make that effectively impossible. Instead, the UK needs to identify areas where it can build world-leading capabilities and become indispensable to its allies.
Asked for the biggest challenge to UK resilience as technology and threats accelerate, Lim’s answer was simpler: “Pace.”
“I think we know what we need to do,” she said. “We just have to do it fast enough.”












