West Midlands Cyber

Researchers, practitioners and organisations across the West Midlands are contributing to the challenge of online harm. CyberDIVA highlights how collaboration across technology, safeguarding, policy and research can help address complex digital risks.

Contents

CyberDIVA: Tackling Online Harm Through West Midlands Research and Collaboration

Online harm is often discussed as though it were primarily a problem for large technology platforms, national regulators and specialist cyber-security teams. In practice, its effects are experienced much closer to home: by children and families, schools and colleges, community organisations, businesses and public services trying to understand how rapidly changing digital environments affect the people who use them.

That makes online safety a particularly important area for collaboration. Technical controls matter, but technology alone cannot address problems involving behaviour, identity, trust, education, platform design and social interaction. Effective responses require researchers, cyber specialists, educators, policymakers, communities and technology organisations to work across disciplinary boundaries.

CyberDIVA provides a West Midlands example of that approach. The originating article, CyberDIVA: A West Midlands Cyber Innovation Tackling Online Harm, examined the initiative as part of the region’s developing cyber ecosystem. For the West Midlands Cyber Hub, its significance is also practical: it demonstrates how regional research capability can be connected with community needs and real-world cyber challenges rather than remaining isolated within individual institutions.

CyberDIVA matters not because one project can solve online harm, but because it illustrates the type of multidisciplinary collaboration required to make progress on a problem whose technical and human dimensions cannot sensibly be separated.

Read the wider regional analysis. The West Midlands Cyber Cluster examines CyberDIVA as an example of how multidisciplinary research and regional capability can contribute to emerging cyber challenges, in the companion article “CyberDIVA: Tackling Online Harm Through West Midlands Research and Collaboration”.

Key Takeaways

Online Harm Is a Cyber Problem with a Human Context

Cyber security is sometimes framed primarily in terms of protecting systems, networks and information from malicious activity. Online harm extends the problem into the environments in which people actually use digital technology.

Harassment, manipulation, abuse, harmful content, fraud and other forms of malicious or damaging behaviour can be enabled by digital platforms without fitting neatly into the conventional model of an attacker compromising a computer system.

The consequences can nevertheless be serious.

People can be targeted through social engineering, impersonation or manipulation. Young users can encounter harmful interactions or content. Organisations responsible for education, safeguarding or community support can find themselves dealing with consequences generated through platforms over which they have little direct control.

Artificial intelligence adds further complexity by making it easier to generate convincing synthetic material, automate interactions and personalise content at scale.

Addressing these problems therefore requires more than conventional perimeter security.

Computer science and cyber-security expertise can help understand technical mechanisms and develop protective tools. Behavioural and social research can examine how people interpret and respond to online interactions. Education and safeguarding expertise can help determine what interventions are appropriate for particular groups.

The challenge is inherently multidisciplinary.

That is one reason initiatives such as CyberDIVA are relevant to the wider regional cyber ecosystem: they broaden the definition of cyber capability beyond protecting organisational infrastructure and towards understanding how digital systems affect people.

Research Becomes More Valuable When Disciplines Connect

Universities contain considerable specialist expertise, but complex societal problems rarely align neatly with academic departments.

An online-harm problem may involve cyber security, artificial intelligence, psychology, sociology, education, criminology, data science and policy simultaneously. Examining only one dimension can produce an incomplete understanding.

Multidisciplinary programmes create the opportunity to combine those perspectives.

This does not mean that every research question needs every discipline. The value lies in selecting the expertise required by the problem rather than forcing the problem into the boundaries of one existing field.

For the West Midlands, this approach has wider implications.

The region’s universities represent a significant component of its cyber capability. Their contribution should not be measured only by the number of cyber-security courses or graduates they produce. Research, knowledge exchange, specialist facilities and collaboration with external organisations are also part of the regional asset base.

The challenge is making that capability accessible.

A school, SME, community organisation or public body may have a genuine cyber-related problem without knowing which academic discipline, research group or institution could help address it. Researchers can similarly possess relevant expertise without an obvious route to the organisations experiencing the problem.

Regional networks can help bridge that gap.

Collaboration Can Improve the Quality of Cyber Innovation

Innovation programmes often concentrate on the technology being developed. For cyber and online-safety applications, the context in which that technology will be used can be equally important.

A technically sophisticated intervention may fail if users do not understand it, trust it or use it as expected. A tool designed to identify harmful behaviour may create unintended consequences if it does not reflect how different communities communicate. An educational intervention may provide accurate information without changing behaviour.

Bringing potential users and practitioners into the development process can expose these problems earlier.

This is particularly important when technology affects children, vulnerable groups or sensitive social interactions. Technical performance is only one component of effectiveness; usability, ethics, privacy and safeguarding also matter.

CyberDIVA’s wider relevance therefore lies in the model of collaboration surrounding the problem.

Research can identify patterns and test assumptions. Practitioners can contribute knowledge of real environments. Communities can provide perspectives that are difficult to infer from technical data alone. Technology specialists can translate findings into systems capable of operating at useful scale.

The resulting innovation process is more demanding than simply developing a product in isolation, but it can also produce interventions better aligned with the circumstances in which they will actually be used.

Artificial Intelligence Is Changing the Online-Harm Environment

AI is altering both the opportunities available to legitimate organisations and the methods available to malicious actors.

Generative systems can create text, images, audio and video rapidly. They can support education, accessibility, customer service and creative work, but the same capabilities can be used for impersonation, deception and the production of harmful or misleading material.

The UK cyber sector is already responding to the broader security implications of AI.

The 2026 Cyber Security Sectoral Analysis identified 111 firms offering AI-security capabilities, compared with 66 in the previous analysis, an increase of 68%. Thirty-two were identified as specialist AI-security companies.

Much of that commercial activity concerns areas such as model security, infrastructure, advisory services and red teaming. Online harm presents an overlapping but distinct challenge because the consequences arise not only from whether an AI system itself is technically secure, but from what people can produce and distribute using it.

This creates difficult questions.

How can synthetic material be recognised? How should systems respond to harmful interactions without blocking legitimate communication? How can younger users develop the ability to question convincing digital content? What responsibilities should sit with platforms, developers, organisations and individuals?

No single technical control provides a complete answer.

Research programmes capable of combining technical and human perspectives are therefore likely to become more important as AI-generated content becomes more commonplace.

Young People Need More Than Generic Cyber Awareness

Children and young people experience digital technology differently from adults who encountered social platforms later in life.

Online communication can be integrated into friendships, education, entertainment and identity. Advice that simply separates an “online world” from a supposedly independent offline environment can therefore fail to reflect how digital interaction is actually experienced.

Effective cyber education needs to recognise that context.

Traditional awareness approaches often concentrate on passwords, suspicious links and personal information. Those remain useful, but online resilience also involves recognising manipulation, understanding privacy, responding to harmful behaviour and knowing when and where to seek support.

AI creates an additional literacy requirement.

Young people increasingly need to understand that convincing content may not represent a real event, person or conversation. That is partly a technical issue, but it is also a question of critical reasoning and media literacy.

Research can help determine which interventions work for different age groups and circumstances rather than assuming that one awareness message will be equally effective for everybody.

The same principle applies to parents, teachers and organisations supporting young people. They need practical ways to understand emerging risks without being expected to become cyber-security specialists.

Regional collaboration can help connect these groups with researchers and practitioners capable of translating technical change into useful guidance.

Community Participation Can Improve Research

There is an important difference between conducting research about communities and conducting research with them.

Where cyber problems involve lived experience, researchers may benefit from involving affected groups in defining the questions being examined and evaluating potential interventions.

Community participation can reveal assumptions that are difficult to identify from outside.

A technical team may believe that a particular security warning is clear, while users interpret it differently. Researchers may focus on one form of harmful behaviour while participants identify another as more significant. An intervention designed around one demographic group may not transfer effectively to another.

Participation does not remove the need for rigorous research methods. It can improve the relevance of the questions those methods are being used to answer.

This approach also creates a different relationship between cyber innovation and the public.

Rather than presenting new technology to communities only after development is complete, organisations can create mechanisms through which users influence how solutions are designed and evaluated.

For online safety, where trust and behaviour are central to effectiveness, that relationship can be particularly valuable.

Businesses Have a Role in the Online-Safety Ecosystem

Online harm may appear distant from the immediate concerns of many SMEs, but businesses increasingly operate digital environments in which customers, employees and communities interact.

Technology companies have the clearest connection. Developers of platforms, applications and AI-enabled services need to consider how products could be misused and how users can report or respond to harmful activity.

Other organisations also encounter related responsibilities.

Employers may need to address online harassment affecting staff. Education and training providers work directly with younger users. Professional-services organisations may handle sensitive information about vulnerable people. Businesses operating online communities or customer platforms may need moderation and reporting processes.

The appropriate response depends on the service.

A small business does not need the trust-and-safety infrastructure of a global platform. It should nevertheless understand how people use its digital services and what forms of misuse could create meaningful harm.

Research partnerships can be useful where the problem is novel or difficult to evaluate internally.

For companies developing products in cyber security, AI, education technology or online safety, university collaboration can also provide access to expertise and evidence that strengthens product development.

The West Midlands Can Connect Research with Commercial Innovation

Research programmes create knowledge, but regional economic benefit depends partly on what happens next.

Some findings may influence public policy or professional practice. Others may generate tools, intellectual property, spinouts or commercial partnerships. Businesses may discover applications for research that were not apparent when the original project began.

A functioning regional ecosystem makes these transitions easier.

Researchers need routes to businesses capable of applying or commercialising ideas. Companies need ways to discover research relevant to their products and customers. Investors need enough visibility to distinguish credible innovation from technology without a validated market.

The CyberDIVA model is relevant because online harm is not only a social challenge; it is also an area in which new security and safety capabilities are likely to be required as digital environments become more complex.

The opportunity for the West Midlands is not to force every research project towards commercialisation.

It is to ensure that potentially useful research does not remain disconnected from organisations capable of applying it.

That requires relationships extending beyond individual funding rounds or projects.

Regional Networks Can Make Specialist Expertise Easier to Reach

One recurring problem across cyber security is that expertise exists but is difficult for non-specialists to navigate.

A community organisation dealing with online abuse may not describe its problem in the terminology used by a cyber researcher. An SME developing an AI product may recognise a safety issue without knowing which academic group studies it. A university researcher may have relevant expertise but limited contact with regional businesses.

A regional Hub can help improve those connections.

The West Midlands Cyber Hub is not intended to replace universities, commercial providers, community organisations or national cyber institutions. Its useful role is to make the regional network easier to enter.

For organisations interested in online safety, research collaboration or related cyber innovation, that can mean finding relevant events, programmes, researchers, practitioners and potential partners without needing an existing relationship with every institution involved.

The same principle applies in the other direction.

Research organisations can use regional networks to understand the problems businesses and communities are encountering, helping to inform future research and knowledge-exchange activity.

The value lies in reducing the distance between capability and need.

Innovation Needs Routes Beyond Individual Projects

Funded projects have defined beginnings and endings. Regional capability should not.

One of the recurring weaknesses in innovation ecosystems is that valuable relationships form around a programme and then dissipate when funding concludes. Knowledge remains inside the participating organisations, while businesses and communities outside the project struggle to discover what was learned.

The stronger approach is to retain the network value created by individual initiatives.

That might involve continued practitioner communities, follow-on research, business collaboration, public engagement, demonstrators or routes through which lessons can inform other projects.

For the West Midlands, programmes such as CyberDIVA can therefore contribute at two levels.

The first is the direct work undertaken on online harm.

The second is the collaborative infrastructure developed while undertaking it: relationships between disciplines, institutions, practitioners and communities that can be applied to subsequent challenges.

Regional cyber capability becomes stronger when those connections accumulate rather than repeatedly being rebuilt from zero.

Online Harm Shows Why Cyber Cannot Be Treated as a Narrow Technical Field

Cyber security increasingly intersects with areas that were once discussed separately: artificial intelligence, industrial resilience, education, economic security, regulation and online safety.

CyberDIVA illustrates this expansion particularly clearly.

The challenge it addresses involves digital technology, but the desired outcome is not simply a more secure computer system. It is a safer environment for people using technology.

That changes the expertise required and the way success should be assessed.

Technical performance remains important, but so do behaviour, accessibility, trust, evidence and real-world outcomes. Researchers need practitioners and communities; technology developers need social and behavioural insight; organisations working directly with users need access to technical expertise.

For the West Midlands Cyber Hub, this is precisely the type of connection a regional ecosystem should make easier.

The region already contains universities, cyber businesses, public-sector organisations, community groups and practitioners with relevant capabilities. The opportunity is to create enough connectivity between them that difficult cyber problems can be addressed collectively rather than within institutional boundaries.

CyberDIVA provides one example of what that can look like.

Its broader lesson is that regional cyber innovation becomes more valuable when research capability is connected to the people and organisations experiencing the problem. Online harm is too complex for any single discipline or institution to resolve independently; the regional advantage comes from making collaboration sufficiently practical that they do not have to.

Leave a Reply

Your email address will not be published. Required fields are marked *