Site navigation

NAO: UK Government ‘Slow’ to Address ‘Severe’ Cyber Threats

Elizabeth Greenberg

,

nao uk cyber resilience cyber threats uk government
“The risk of cyber-attack is severe, and attacks on key public services are likely to happen regularly, yet government’s work to address this has been slow,” Gareth Davies, head of the NAO.

The cyber threat to the UK government is severe and advancing quickly, the National Audit Office (NAO) has found, as it urges the government to act now to protect its own operations and key public services.

The public spending watchdog evaluated whether the UK government was keeping pace with the rapidly evolving cyber threat it faces from hostile actors.

The body found significant gaps in the cyber resilience of the government’s new cyber assurance scheme, GovAssure, which independently assessed 58 critical departmental IT systems by August 2024.

Multiple fundamental systems controls were found to be at low levels of maturity across these departments, the report found, with at least 228 ‘legacy’ IT systems in use by the departments as of March 2024, with the government unaware of how vulnerable these systems are to a cyber-attack.

These failings come after decades of work to build the UK’s cyber resilience over successive governments, including publishing a strategy for improving government organisations’ cybersecurity in January 2022. But the government has yet to meet its cyber resilience aims, the NAO says.

One of the reasons for this lack of cyber resilience could be related to the cyber skills shortage in the government.

In 2023-24, a third of cybersecurity roles in the government were vacant or filled by temporary staff, with more than half of cyber roles in various departments vacant. Further, nearly three in four (70%) of specialist security architects in post were temporary staff.

Departments reported that the salaries they can pay and civil service recruitment processes are barriers to hiring and keeping people with cyber skills.

Other concerns include a lack of coordination within the UK government jeopardising effective cyber defence.

The respective roles of departments and organisations at the centre, such as the NCSC, are insufficiently understood. Departmental leaders have not consistently recognised the relevance of cyber risk to their strategic goals.

Financial pressures have also meant that some departments have significantly reduced the scope of their work to build cyber resilience, which could increase the severity of an attack when it happens.


Recommended reading


In March 2024, departments did not have fully funded plans to remediate around half of government’s legacy IT assets (53%, or 120 out of 228), leaving these systems increasingly vulnerable to cyber-attack.

For instance, under-investment in technology and cyber was a key factor in the British Library cyber incident.

“The risk of cyber attack is severe, and attacks on key public services are likely to happen regularly, yet government’s work to address this has been slow,” Gareth Davies, head of the NAO.

“To avoid serious incidents, build resilience and protect the value for money of its operations, government must catch up with the acute cyber threat it faces.

“The government will continue to find it difficult to catch up until it successfully addresses the longstanding shortage of cyber skills; strengthens accountability for cyber risk; and better manages the risks posed by legacy IT.”

In the next six months, the NAO is urging the UK government to develop share, and begin using a cross-government implementation plan for the government cyber security strategy, as well as set out how the whole of government needs to operate differently, and what is needed for this transformation to be effective.

Within the next year, the NAO urges recommends the UK government make and enact plans to fill cyber skills gaps in workforces.

Elizabeth Greenberg

Staff Writer

Latest News

AI Technology

Glasgow Researchers Test Virtual Agents for Safer Driving

Cryptocurrency Editor's Picks

HMRC Warns Crypto Investors to Pay Their Dues

Events Featured

ScotSoft Returns to Edinburgh This September!

Editor's Picks Privacy

Children Easily Bypassing Parental Controls, ICO Finds