Site navigation

UK Gov Falling Short On Cyber Defence, Warns New Report

Tom Quinn

,

UK government cybersecurity
The UK’s cyber defences are no match for the current threat landscape, says a new parliamentary report.

The UK Government’s cyber defences are falling far short of what’s needed to protect the public sector and must be fundamentally overhauled to meet the severity of the modern threat landscape, warns a new report from an influential parliamentary committee. 

The UK Public Accounts Committee (PAC) latest study, Government Cyber Resilience, cautions that hostile states and cyber-criminals are outpacing the government in their ability to disrupt public services and critical national infrastructure, moving far quicker than the Cabinet Office anticipated.

Criticising the government’s slow response to the rapid evolution of cyber warfare, the PAC said that there is now a ‘substantial gap’ between the threats the UK now faces and the government’s ability to respond.

As evidence of the government’s lack of cyber defence readiness, the PAC report highlights that as of January 2025, 319 legacy IT systems were still in use across departments, with around a quarter of these having a ‘red’ rating, indicating a high likelihood of cyber risk.

Alarmingly, the government estimates that ‘risky’ legacy IT systems make up 28% of the public sector’s IT estate, although the report claims that the government does not know how many legacy systems there are in total.

The PAC said that the government had so far proved ‘unwilling’ to pay the kind of salaries necessary to compete with the private sector for the best talent in cybersecurity, leaving a scarcity of digital and security leaders across Departments, although pay levels are set to increase, with the Committee’s report calling on the government to set out how many cyber vacancies its interventions will fill.

Added to that, the analysis found that one in three cybersecurity roles remain either vacant or filled by expensive contractors, despite the government having increased its digital workforce to 23,000 people – 6% of the total civil service.

That will make it extremely difficult for the Cabinet Office to meet its ambitious aim for the whole of government and the wider public sector to be ‘resilient to known vulnerabilities and attack methods’ no later than 2030.

According to the report, the Cabinet Office itself admits its cyber defences aren’t resilient enough to respond and recover from a cyber-attack that slips through undetected, and acknowledged to the PAC’s inquiry that there is a significant gap between rising cyber threat levels and the government’s response.

“Government Departments are beginning to wake up to the serious cyber threat they face,” said Sir Geoffrey Clifton-Brown MP, chair of the PAC.

“A serious cyberattack is not some abstract event taking place in the digital sphere. Hostile states and criminals have the ability to do serious and lasting harm to our nation and people’s lives.

“If the Government is to meet its own ambition to harden resilience in the wider public sector, a fundamental step change will be required. 

“This will involve infusing every top team with the required digital expertise, with cyber and digital specialists at the top level of every department, both management and boards, to bring about a change in thinking throughout the civil service for greater threat awareness and digital transformation.”


Recommended reading


The PAC’s dire warnings follow on the heels of the latest report from the UK’s National Cyber Security Centre, which stressed that the country’s critical national infrastructure is at severe risk of AI-enabled threats, due in part to insufficient cybersecurity controls.

The evolution of cyber risk has, to be fair, been top of mind for the government. Less than a year into its term, Labour unveiled its landmark Cyber Security and Resilience Bill, with sweeping new regulations designed to harden the nation’s defences.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data