Government cyber security has a structural problem: the centre is accountable for national resilience but doesn't own the risk, hold the budgets, or run the systems. Standards flow down; behaviour rarely changes. Drawing on frontline experience reshaping the UK's approach, this session makes the case for a polycentric model — where accountability stays local, capability is built where the work happens, and the centre shifts from mandating compliance to enabling delivery. It examines what the centre can genuinely influence versus control, why activity rarely equals outcome, and how to intervene without breaking what already works.