jim hockenhull
Image: UKinUSA via Wikimedia Commons (CC BY-SA 2.0)

Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence

Although General Sir Jim Hockenhull spent his career inside Britain's military intelligence establishment, he may be best remembered for sharing certain secrets instead of keeping them under wraps.

As Chief of Defence Intelligence from December 2018 to May 2022, he took the decision to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take. The point was to expose the Kremlin’s intentions before Moscow could manufacture a pretext and dress the invasion in a false narrative. The move is now widely judged to have been a success, although Hockenhull said when he first proposed it, almost no one else in government thought it was a good idea.

Hockenhull rose as an intelligence officer and went on to lead Strategic Command in 2022, which runs Britain’s military cyber and intelligence effort across the armed services. He helped shape the National Cyber Force, the country’s offensive cyber organization established in 2020, drawing together capabilities from across the military, security and intelligence services. The son of a Royal Navy petty officer who became a taxi driver, and of a mother who assembled televisions in a factory, he speaks warmly of the armed forces as an engine of social mobility. Despite the rank and the knighthood, he prefers to be called Jim.

Out of uniform since June, Hockenhull said that he has come to admire something about Britain’s adversaries: they campaign continuously, treating every instrument of state as part of one long effort. Britain does not, and cannot easily, because it keeps rebuilding the machinery meant to deliver. Days after he spoke to Recorded Future News, the country appointed its fifth prime minister and its fifth defence secretary since the invasion of Ukraine four years ago.

Campaigning matters most in cyberspace, he argues, because capability there cannot be stockpiled like a weapon in an armory: a single software update can close the door. The tools are less like munitions than Lego bricks, assembled for a target and a moment that will not last. And he warns deterrence theory is still stuck in the 1950s, when the more useful modern question is what it does to an adversary to know that you can see them.

But the argument he presses hardest is about the public, and it returns to where he began. Britain is attacked in cyberspace every day, and may face sabotage, espionage and attacks on its undersea cables long before anything resembling a shooting war. Yet almost everything the state knows about that threat stays classified, which leaves people being asked to fund the response — with money that would otherwise go to schools and hospitals — largely on trust.

This interview has been edited for length and clarity.

Recorded Future News: I remember you speaking at Recorded Future’s Predict conference with the late Sir Alex Younger in 2023, you said that only one person had agreed with your proposal to declassify and publish intelligence about Russia’s plan to invade Ukraine. Who was that?

Jim Hockenhull: It was Ben Wallace, the Defence Secretary. I was lucky it was him.

Typically, in a bureaucracy, people tend not to say yes or no to anything. They’ll say, “that’s an interesting idea,” and then ask lots of questions and raise reasons why it might not be possible. If you’re not careful, you screen out the things that could be really good but are quite risky, because what people want to do is manage risk. As soon as you say, “we’re going to do this, it could go badly, we could be the subject of massive information operations” — well, we already were, and still are. So I didn’t see that as a particular risk.

There was a lot of reticence in the intelligence world about going public with our information. Usually that only happens in a court case or a public inquiry. It was almost against the prevailing culture. But Ben understood intelligence. He’d been security minister before, so he’d had a lot of dealings with the agencies. He and I did a great deal of work together preparing the government, and the Ministry of Defence, for the conflict — making the case that the invasion really was going to happen. Releasing intelligence was one part of that. Supporting Ukraine, including getting NLAW anti-tank weapons to them, was another.

Plenty of people asked whether arming Ukraine would provoke the Russians. My view was: they’re planning to invade, so what’s the worst that can happen if we provoke them? I was sure the invasion was coming. Those who were less convinced had a different risk calculus.

Ben was willing to take big decisions. If you went to him with a reasoned argument, he’d back you. That’s why, with one person, we got it through. If it had just been me and someone who wasn’t at Ben’s level, it would have been really difficult. I wonder how brave I would have been. But that’s a counterfactual.

RFN: Sir Alex passed away recently.

JH: It’s a great loss. It’s not easy for people who’ve worked in the shadows all their lives to then almost reinvent themselves in public. Alex did that remarkably well and became an important voice in the national debate.

The public saw his strategic insight, his fierce intellect and his ability to explain complex issues clearly. Those of us who knew him in government had always seen those qualities. When he was Chief of the Secret Intelligence Service, MI6, he was a reassuring presence: everyone felt he had their back. He wanted his teams to take risks, to go further, but he was also demanding — “okay, so where next?” — there was a restless intensity to him.

That the public saw this mattered, and not just for what he contributed. Serving intelligence officers could see that serious, responsible debate outside government was compatible with a lifetime of secret service.

RFN: During the Second World War, Britain went to extraordinary lengths to conceal intelligence sources such as Ultra. In 2022, you made the opposite choice and made that intelligence public. Are those contrasting approaches part of the same doctrine?

JH: I think there’s a continuum, which is about how you use information and intelligence — whether you exploit it without the adversary knowing, use it for informed decision-making, share it with partners, or use it publicly to shape the debate. It’s all the use of intelligence. And the challenge is deciding which way you go, because once you go in a particular direction, it commits you to a course of action. It’s the same with the codebreakers — the effort included the Poles as well as the British, and then the partnership with the U.S. Once you start building the machine and the enterprise for it, you’re committed.

Once we decided to release intelligence publicly, it couldn’t be a one-off. The first was on Feb. 17, 2022, showing the axes of Putin’s invasion plan. But a single tweet wouldn’t have been enough. It became: how are we going to do this now? We set up a discrete team, responsible for taking our classified products and working out what could be shared publicly without compromising sources and methods, or giving advantage to the adversary. We had remarkable insight into a conflict where we weren’t a party — and we had to decide what you can do with that.

The public releases were only one part of a much wider effort. For a long time we didn’t make clear that we were also sharing a great deal with the Ukrainians, to help them act effectively. That became more public last year, when for a brief moment the U.S. announced it was stopping intelligence-sharing with Ukraine. The sharing was a recognition that the conflict is broader than what happens on the ground. It’s in the information space, and it always has been. But one of the biggest changes in our lifetimes was the arrival of the iPhone. Suddenly everybody’s consuming information in a fundamentally different way. This was our first attempt to recognize that we’re in a modern digital era of communication — and to ask how an organization that sees itself as largely secret, but is also part of a government bureaucracy, becomes a player in a digital landscape it probably doesn’t understand as well as it might.

RFN: Who were you primarily trying to influence? The British public, allies, Ukraine or Russia?

JH: All of them, though the emphasis changed.

Initially, we wanted the British public to understand that a war was coming in Europe, that it was a long-planned Russian effort, and that there’d be a load of noise and false-flag information designed to provide a pretext. We’d seen that playbook before: Georgia in 2008, Ukraine in 2014, Syria in 2016. It was familiar, but it had never really been contested in advance. And Ben Wallace and I both wanted to say to the Russians: we know what you’re doing, and we’re so confident in that knowledge that we’re going to put it out there — not just brief our own ministers or NATO. In the Feb. 17 release we ended with a line saying President Putin still had a chance to choose the path of peace rather than war. That was always extremely unlikely, but it mattered to demonstrate the depth of our understanding.

That raises a wider question about deterrence. We often revert to nuclear deterrence theory of the 1950s. But in the modern age how do we use our insight, our knowledge dominance, to deter our adversaries? The important part is that these aren’t psychological operations. This is using the truth to let people know the real situation before Russian falsehoods take hold, because once a lie is established, it gains a life of its own and is almost impossible to kill.

RFN: Many assessments suggested Kyiv would fall quickly. It didn’t. What does that reveal about the limits of intelligence, and does it complicate the idea that 2022 was an intelligence success?

JH: The key insight we had was understanding the Russian plan for Kyiv to fall in five to seven days, and for most of the operation to be completed in about 35 days. What we understood less clearly was how Ukraine intended to fight. The Ukrainians were loath to share their plans with anyone, sometimes even among themselves, so it was hard to judge the correlation of forces.

It was clear Russia ought to have had overwhelming force, though not necessarily on the timescale they'd planned, which was always ridiculous. There are strong parallels with Hitler’s invasion of Russia in June 1941 — an overestimation of your own force, a diminution of your adversary, often on racial and other grounds.We wrote an assessment about a week before the invasion highlighting all the weaknesses we knew the Russians had: an operation at a scale they hadn’t attempted since the Second World War; logistics not as well supported as they should be; a reliance on very quick success, so that if they got bogged down at all it would be very difficult; challenging command and control between land and air forces; questionable morale; poorly trained conscripts, even with relatively modern equipment. We were realistic about all those faults. What we didn’t imagine was that Russia would fall over all of them simultaneously.

When you use intelligence, you change the situation. By informing the people mounting the operations, they act on it, and that changes the context being assessed. So being held to “you said this and it didn’t happen” — I’m happy to take criticism, but part of the reason it didn’t happen is the insight intelligence provided.

Intelligence is about uncertainty, and sometimes it’s wrong. But in this case we were right that an invasion was coming, right about the structure of the plan, and right that the Russians had serious weaknesses.

RFN: Part of the response in the United Kingdom, many years on, has been the new Defence Investment Plan. This has been looked at in detail elsewhere, but the cyber element seems particularly relevant to our discussion — it focuses heavily on cyber defense rather than offense. Is there a cyber equivalent to the invasion disclosures? And can Britain deter an adversary by demonstrating offensive cyber capability when so much of the culture around that activity is covert?

JH: The big investment in the National Cyber Force was made back in 2021 and guaranteed over a decade, so I’m not surprised the latest plan doesn’t announce another large increase. The Force is still building itself out.

We deliberately built a joint construct, led by the Ministry of Defence and GCHQ, with the Secret Intelligence Service and others as key partners. Instead of separate military and civilian capabilities, we have a single entity that can operate across the spectrum: cybercrime, online child sexual exploitation, terrorism, hostile states, and ultimately wartime targets.

Offensive cyber has usually grown out of the intelligence community, because intelligence is essential both to developing the capability and conducting the operation. That naturally makes it covert. But there are times you may want an adversary to know what you can do, or to know that a particular disruption was down to you. Over the last decade there’ve been attacks on the West where people were clumsy — sometimes deliberately not covering who they were. Think of the attack on Sony after the film mocking North Korea’s supreme leader — it didn’t quite have DPRK flags on the payload, but it may as well have.

That doesn’t always require a public announcement. You could mount a covert operation and then message privately, through diplomatic or intelligence channels: that thing that happened, that was us. Equally, you might want to tell your own population you’ve responded to an attack that disrupted daily life. The audience should determine the degree of disclosure.

But there’s a trade-off. Cyber operations often depend on exploiting a vulnerability, and as soon as you’re demonstrative about it, the adversary will almost certainly close that vulnerability. So there’s something around efficacy. There’s also a tendency to assume a cyberattack must be answered with another cyberattack. That’s too narrow. Cyber is usually best used in combination with other levers of power, where it has a compound, multiplying effect.

RFN: Some academics argue that nuclear-style deterrence doesn’t translate to cyberspace and that governments instead need a constant campaigning mindset. Do you agree?

JH: I’d certainly agree it’s about campaigns. The idea of a cyber silver bullet you keep in an armory and roll out at the decisive moment is fanciful. A conventional weapon stays broadly the same object until it’s used. Cyber terrain changes continuously — someone updating their system could remove an opportunity, create a new one, or change the risk. A capability that works today may be ineffective tomorrow.

Cyber tools are less like weapons in a warehouse and more like Lego bricks. Skilled people can combine them in different ways, but the usefulness of any combination depends on the target, the technology and the moment, and opportunities are often temporary. So you need a campaigning approach: people continuously developing access, understanding networks, adapting operations. But it needs to be nested within wider campaigns. A cyber campaign on its own might achieve remarkable things, but whether they’d lead to remarkable outcomes, I very much doubt.

This is where I sometimes admire our adversaries’ integrated approach — not the methods, the risks, or the ethical bounds they storm through — but the way they use everything as tools of statecraft. We got into the habit of being a responsive nation, with NATO providing the core of our security architecture, and then dealing with everything below the threshold of war as separate incidents.

Successive governments have tried to build campaigns and frameworks. When Mark Sedwill was Cabinet Secretary he worked hard to pull government together around campaigns against our adversaries, and that was effective for a while. But government is very good at reorganizing itself, and that makes sustained campaigning over a long period difficult. It’s difficult because spending-review budgets run only four years, so your time horizon shortens — and then the people at the top shift and move, with different views and different preferred constructs. If we’re going to adopt a longer-term campaigning approach, we need consistency, in resourcing but also in intent and structure.

I said about three years ago that this was the most dangerous time in my military career, which started before the end of the Cold War. Everybody appears to be saying it now, and that’s fine. The Strategic Defence Review speaks of a warfighting mindset, but we’ve still got quite some distance to go. The DIP is some of the money required. But it's not just money.

RFN: Returning to the WWII comparisons, the Digital Targeting Web in the DIP reminded me of the Dowding System from the Battle of Britain: gather information, combine it, make a decision and act. What is genuinely new about today’s version?

JH: Together with my team, I was one of the proponents of saying we needed investment in our targeting capability, so I’m really glad the DIP has provided significant funding.

The underlying logic isn’t new. What’s changed is the scale, speed and complexity. Modern forces can gather extraordinary amounts of information. The challenge is to make sense of it in space and time, then act at the speed of relevance and at the scale the situation demands. Look at the 1982 Falklands task force: relatively few missiles, defenses at times overwhelmed, leading to catastrophic loss. Now look at the volume of ballistic missiles, shorter-range weapons and drones being thrown around the Middle East — as we’ve seen in Ukraine, and in the Israeli, then Israeli–U.S., operations against Iran. You can only respond with an information architecture that lets you make sense of everything, fast enough for people and systems to act.

And the public tolerance for loss has changed. Think back to Afghanistan, to the wonderful people of Royal Wootton Bassett saluting the coffins of those who died. Each of those casualties was like a dagger to the heart of the country. The threat that could be manifest upon us now isn’t just to our armed forces, it’s to the people of the United Kingdom, who no longer sit in their homes quite as securely as we’d imagined all our lives.

The threat comes through many domains — air, land, sea, cyber, space, the information environment — and no single service, or single country, can handle that alone. People describe the targeting web as “any sensor to any shooter.” But the real ambition is broader: anybody’s sensor to anybody’s shooter. A Royal Navy system might detect a threat that’s then struck by a Netherlands Air Force aircraft. The challenges are so overwhelming that we can’t keep operating in our own little bubbles.

That’s why it has to be built closely with NATO, and it raises hard questions of trust and law. Am I going to take action that may kill someone, based on information from another country, trusting their process was sound, and act without further review? If the missile’s inbound, there may be no time for a second check. We already accept that with some close partners; we’ll have to do it on a much larger scale.

You can’t go to the market and buy a Digital Targeting Web, because they don’t exist. It’s a federation of things, brought together securely. The most important shift is from protecting individual networks to protecting and controlling data wherever it moves. Uncrewed and autonomous systems are largely data engines — they need so much support that if you get the underpinning architecture wrong, you won’t exploit them. The targeting web should supercharge the rest of the investment. If we get it wrong, my fear is that quite a lot of it will be wasted.

RFN: You have said the battle for digital and cyber talent is the first battle of the next war. How is Britain doing?

JH: It’s still a work in progress, but we’ve begun to do some genuinely different things.

For most of my career, the model was that people joined the Army, Navy or Air Force through traditional routes and only later moved into cyber. In the Army, you might spend anything from four to seven years — initial training, trade training, language instruction, an initial posting — before reaching the job that attracted you in the first place. So we created a direct pathway. The first cohort did a short period of basic military training and then went straight into specialist cyber instruction. They joined in August and graduated in November, and within months they were working in the National Cyber Force and defensive cyber units.

The first group was small — about 40 people — but only one dropped out. That’s far below the normal attrition in military training. We were reaching highly motivated people who might never have joined through the conventional system.

The traditionalists in the services don’t always welcome variation — they’ve got a big sausage machine to run, and it’s easier to limit the variation. But for scarce digital skills, we have to be more flexible. Someone with exceptional cyber aptitude may not fit the conventional image of a soldier, sailor or aviator, yet may be indispensable. So we’ve also created separate career management for cyber operators.

RFN: Now that you have left the Army, what comes next?

JH: It’s still early, but I want to contribute to a serious effort to explain the threats facing the United Kingdom, and why responding to them matters. Collectively, we haven’t made that case well enough. We assume the public understands the connection, but if our insight stays highly classified, in the hands of senior officials and politicians, we’re effectively asking people to trust us without seeing the evidence. It doesn’t help when different people name different years by which we might be at war.

Repeating that war is possible and that we must be ready isn’t a sufficient argument — particularly when more defense spending may mean less for a child’s education, or a longer wait for an NHS operation. That’s an asymmetric argument, and we’ve got to do much better. It’s a role not just for government but for people outside it, and for organizations too. I’m sad Alex Younger passed, because he was an important voice in making that case. But the risk is we make it on the Today program or Newsnight, and for most people that’s not where they get their insight. So how do we make it accessible and understandable?

If we’re going to do it, it has to be a campaign. You won’t change anything just by becoming another voice shouting into the square. We need a coalition, inside and outside government, willing to have that national conversation over time. We jumped from the Strategic Defence Review straight to funding, and almost skipped the people who matter most — the ones who’ll pay for it and live with the consequences.

And it’s not just the warfighting. What’s a certainty is that we’ll be attacked in cyberspace and in the information space. We may see sabotage, espionage, assassination, attacks on undersea fibre-optic cables, or contest in space, well before anything resembling major war. When we talk about it publicly, we paint it in primary colours, because there’s no time for a sophisticated debate, or because we’re trying to generate a particular outcome. Doing it properly will take time. But it’s really important that we do it. Because war isn’t going to happen as an away game. If there is a conflict, it will be happening here.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79