
Much of the discussion about the recent sentencing of Thalha Jubair and Owen Flowers following the cyber-attack on Transport for London has understandably focused on the seriousness of their crimes. The attack caused widespread disruption, compromised the personal data of millions of passengers and left TfL with estimated recovery and lost revenue costs of almost £40 million.
But as the dust settles, we should also be asking how the UK can ensure exceptional cyber-skills like theirs are redirected towards strengthening our national cyber-defences, rather than allowing that talent to go to waste.
This is not an argument for lighter sentences, and it is not in any way excusing criminal behaviour. The organisations that experience cyber-attacks deserve justice, and everyone affected deserves to know there have been consequences. However, punishment on its own does nothing to solve the shortage of highly skilled people who are capable of defending our digital infrastructure.
Organisations across critical national infrastructure, government and the private sector are competing for experienced security professionals, and demand outstrips supply. We invest heavily in cyber-security education, apprenticeships, capture-the-flag competitions and other talent development programmes because we recognise that the highest level of technical expertise is difficult, time-consuming and expensive to grow.
Yet when individuals demonstrate exactly those advanced technical capabilities, albeit in the worst possible way, the conversation often begins and ends with how to punish them, with relatively little discussion about what could happen afterwards. This needs to change.
The uncomfortable truth is that prison won’t eliminate their technical ability. Someone capable of identifying complex vulnerabilities or understanding sophisticated attack techniques will still have these capabilities after serving a sentence. The question is whether we create legitimate pathways for them to be used in ways that strengthen, rather than undermine, the UK’s cyber-resilience.
Cyber-security has seen transformations before. Kevin Mitnick spent years as one of the world’s most famous hackers before becoming a respected security consultant. Hector Monsegur, better known as "Sabu", went from leading LulzSec to working with law enforcement and becoming an influential voice on cyber-crime. Their stories do not diminish the seriousness of their crimes, but they do demonstrate that exceptional technical ability can be successfully redirected.
So, how do we create opportunities for that redirection?
The UK already has some of the foundations in place. Through Regional Organised Crime Units (ROCUs), the National Crime Agency and the Cyber-Choices programme, policing has been identifying and diverting technically gifted young people before they become involved in cyber-crime. These initiatives recognise that curiosity and technical ability can be redirected into legitimate careers through early intervention.
INTERPOL has echoed this thinking internationally, emphasising that enforcement alone cannot solve youth cyber-crime. Alongside disruption, it advocates prevention, education and pathways that encourage technically gifted individuals to use their skills constructively.
But that same philosophy should not end at prevention; it should extend into rehabilitation. Instead of viewing imprisonment as the end of the process, it should become the beginning of a structured pathway that enables those who have genuinely demonstrated remorse and rehabilitation to contribute positively to society.
There needs to be recognition that not every cyber-offender presents the same risk. A teenager motivated by status or technical curiosity requires a different long-term approach from an organised criminal motivated by financial gain or a state-sponsored actor. Better assessment of motivations, behaviour, and wider risk factors could help identify those with genuine rehabilitation potential and shape the kind of support that would actually work.
In the TfL case, the judge cited both defendants’ autism diagnoses as mitigating factors, and the NCA has also said that their ages, backgrounds and neurodiversity all shaped how the investigation was handled.
It is important to be clear that being neurodivergent does not make anyone a criminal. The overwhelming majority of neurodivergent will never offend. But those engaged in diversion have recognised that some young people with intense technical focus and a strong need for recognition can be drawn into online communities where status is earned through escalation. Cyber-Choices aims to interrupt that pathway.
That same understanding should carry through to rehabilitation. Assessment, mentoring and structured technical development will all be more successful when they adapt for how an individual actually processes information, responds to supervision and builds trust. Generic programmes may fail people who need clear structure, predictable expectations and communication that doesn’t depend on unwritten social rules.
None of this works without rigorous assessment and the case of Jubair and Flowers illustrates exactly why. The pair have also been linked to the wider Scattered Spider collective, associated with attacks on major UK retailers and US healthcare providers and Jubair faces separate US allegations connected to significant ransom proceeds. Whether any individual is suitable for a structured rehabilitation pathway must be determined on a case-by-case, evidence-led basis. No one should be considered automatically eligible, which is why any programme must be underpinned by robust governance, thorough vetting and ongoing oversight.
Where individuals are assessed as suitable for rehabilitation, the focus should shift from punishment alone to creating a structured pathway back into legitimate cyber-security. That pathway must balance accountability with opportunity, ensuring that exceptional technical ability is developed responsibly and ultimately put to work strengthening the UK’s cyber-resilience.
Mentoring should become a formal part of rehabilitation. The cyber-security industry is full of experienced professionals who understand both the technical and ethical dimensions of the profession. Pairing suitable offenders with trusted mentors could help replace the status they once sought in criminal communities with recognition earned through legitimate achievement.
Rehabilitation needs structured technical development. Supervised participation in defensive security exercises, capture-the-flag competitions, accredited training and industry certifications would allow technical ability to continue developing while reinforcing ethical practice. Skills should not be left to stagnate; they should be redirected.
There needs to be carefully monitored routes into employment. Following release, individuals who have demonstrated sustained behavioural change could be considered for supervised internships, apprenticeships or employment in appropriate cyber-security roles, supported by rigorous vetting, ongoing monitoring and clear safeguards. Public trust is of course essential, but permanent exclusion from the cyber-security workforce should not automatically be the only option.
This is not something government can achieve alone. The cyber-security industry has spent years highlighting the UK’s cyber-skills shortage. Employers, training providers, professional bodies and industry associations have an opportunity to become part of the solution. Many already have neurodiversity programmes and inclusive hiring practices in place, and those same capabilities are directly relevant here. Working alongside law enforcement, probation services and education providers, they could help create credible rehabilitation pathways that strengthen both the workforce and national resilience. Clearly not everyone should qualify. Serious organised criminals and repeat offenders may never be suitable candidates. Any programme would require robust governance, transparent criteria and careful oversight because accountability must always come first.
At a time when nation-state attacks, ransomware groups and cyber-criminal organisations are evolving fast, the UK cannot afford to waste scarce cyber-security expertise. National resilience depends not only on technology but on people who understand how attackers think, operate and innovate.
The TfL case needs to prompt more than a debate about sentencing. It should encourage policymakers, law enforcement and industry to consider what happens after justice has been served.
The question isn’t whether Britain should punish cyber-crime. It should. But if the punishment is simply prison followed by permanent exclusion from the profession, we risk valuable technical skills returning to the wrong side of the law.
If, instead, we build carefully governed pathways that combine accountability with rehabilitation, we have an opportunity to strengthen the UK’s cyber-resilience, reduce future offending and make better use of some of the rarest technical skills in the country.
Jonathan Boakes is Managing Director, UK at Infinum
Main image courtesy of iStockPhoto.com and D-Keine
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543