Site navigation

Report: Public Sector Scottish Cyber Activity 2026

Rachel Sim

,

public sector cyber resilience
The Scottish Government has shared the first of an annual publication in partnership with the Scottish Cyber Coordination Centre (SC3), analysing the cyber activity of the Scottish public sector. 

The report draws on findings from the Cyber Resilience Assessment (a comprehensive evidence base on Scotland’s public sector cyber posture) and SC3’s cyber incident data and intelligence.

It aims to help Scotland’s public bodies understand the wider cyber risk environment, benchmark their own resilience, learn from cross‑sector incidents and exercises, and prioritise investment for improved national security.

The Evolving Threat Landscape

SC3’s remit covers around 180 public sector bodies, including education, health boards, local authorities and emergency services. What is clear is that each part of the sector has differing and distinct risks which must be addressed. 

Early intervention is key – organisations must have timely threat intelligence, be able to detect threats and act to resolve issues before they escalate. 

Between 2018 and early 2026, SC3 responded to 183 cyber incidents of varying risk and impact. 14 were deemed as major incidents between 2023 and 2025, requiring a multi-agency response. The incidents happened across sectors and, despite the challenges, have created learnings and insight into the maturity and responses of the public sector. 

Encouragingly, 97% of surveyed public sector organisations confirmed they use service providers to gain threat intelligence – indicating a commitment from the public sector to stay informed and secure. 91% of respondents confirmed they act on threat intelligence intel, suggesting a robust approach to threats across the sector. 

Alongside identifying and addressing vulnerabilities, there is an increasing focus on strengthening response capabilities. Given the overlap in services across the sector, managing supply chain risk vulnerabilities is key to ensuring exploitation at scale can not occur. 

Incident response planning, business continuity planning, staff training, and access to specialist incident response capabilities are all priorities for the public sector, the report indicates. Investing in these areas allows any damage from cyber-attacks to be minimised and recovery to be more efficient. 

When asked about Incident Response Planning, 78% of public sector respondents confirmed they had a plan in place, 19% had a plan but felt it had limitations, whilst only 3% had no plan at all. Whilst this is a broadly positive outlook, gaps in plans could result in significant impact to systems and the public sectors’ ability to deliver services. 

Access to external support remains mixed. While 69% of organisations reported having access to cyber incident response services (either directly or through insurance), coverage is not sector-wide. 

Similarly, findings on cyber expertise in business continuity and disaster recovery were mixed. Around 43% reported ongoing specialist involvement, 48% had partial involvement and, concerningly,  9% had never considered this at all. 

The report warned that responding swiftly in the early hours of an incident is paramount. For organisations without a dedicated cyber incident response provider, a major incident can result in valuable time being lost. 

Of the threats recorded, ransomware was most prevalent, accounting for 20% of incidents since 2018. The growth of ransomware-as-a-service platforms and malware-as-a-service marketplaces is likely to increase these incidents in 2026. 

Across the UK, there is now an average of four nationally significant attacks per week, doubling in a single year, representing growth from 21% to 48% of all incidents. However, SC3 has reported limited growth of major incidents in the public sector, with rates remaining around 13% across 2023, 2024 and 2025 – positive news for the public sector. 

Cyber Readiness & Collaboration

The report highlighted the importance of testing organisational preparedness through structured cyber exercises. These activities are designed to assess technical capability, operational response and decision-making under pressure. 

In the last year, 64% of public sector organisations in Scotland have reported carrying out cyber exercising; further engagement in this process will improve preparedness, the report argues. Scenario exercises have included ransomware attacks, data leaks, and third party compromise activities. 

Although uptake of SC3-facilitated cyber exercising support is still relatively low, it is increasing, with eight organisations utilising support in 2024 and 11 utilising the service in 2025. 

The support services have been praised for building engagement and confidence, creating locally and organisationally relevant scenarios, and helping organisations that lack capabilities or resources to deliver this themselves. 

Cyber risks are affecting organisations across all sectors and sizes – and the public sector is no exception. Given the complexity of the cyber-threat landscape a collaborative approach will be most impactful.

However, the report suggested that lessons are not being shared or implemented fast enough across the public sector. The same gaps identified following the SEPA ransomware attack in 2020, and again after the Comhairle nan Eilean Siar (Western Isles Council) attack in 2023, have been identified as remaining today.

In sensitive situations, lessons should be captured, anonymised and circulated to ensure other organisations can avoid the same risks – learning from and implementing lessons learned. 

Resilient Leadership & Strategic Oversight

The report suggested, business continuity plans across the sector are not aligned to modern cyber realities and scenarios, particularly the possibility of long‑duration digital outages. Plans need to be re-scoped to consider long-term impact of cyber-incidents then robustly tested through simulations and regularly reviewed. 

Whilst technical expertise is essential in overcoming cyber risks, it is not solely an IT responsibility. Leadership has the responsibility to enforce governance and make strategic decisions which will future-proof organisations. 

Leadership and governance are the primary drivers of resilient outcomes: organisations that recover well are those with ownership of cyber risk at board level.

What must not be overlooked is that the reputational damage of a cyber-incident can be as damaging as the technical and operational impacts. Organisations must look at cybersecurity holistically and build communication plans which can be enacted in times of high pressure. Communication should be integrated into incident response plans rather than being treated reactively, ensuring confidence is instilled in both internal and external stakeholders. 

Looking Forward

Scotland’s public sector is facing a cybersecurity landscape which is rapidly evolving – the cost of which can be operational, financial, and reputational, and have significant repercussions for the citizens the public sector serves. 

Organisations who thrive will be the ones that invest in governance, planning, exercising and capability to ensure robust and timely responses. SC3’s annual cyber report hopes to act as a starting point to support national security.


Recommended reading


Alan Gray, head of the SC3 and deputy director of the Scottish Government’s National Cyber Security and Resilience Division said: “Our public sector delivers the services on which millions of people depend daily and holds vast quantities of sensitive data. It also operates in a threat environment that’s growing more sophisticated by the month – cyber risk is a truly systemic issue, cutting across all public sector organisations.

“Rather than isolated action, we need collaboration, shared intelligence, and coordinated response. The lessons in this report are clear: business continuity plans must be reviewed and routinely tested against real cyber scenarios; communications resilience must be treated as a core capability, not an afterthought.

“When the same lessons recur across incidents separated by years, we are not failing to learn; we are failing to implement. The cyber threat to Scotland’s public sector is real, it is growing, and it demands our collective attention.”

The report also gives cause for confidence: it reports that 97% of Scottish public sector organisations now receive actionable threat intelligence; the vast majority have incident response plans in place and are investing in cyber resilience training; and the quality of preparedness across the sector is measurably improving.

Gray continued: “These are not small achievements. They reflect years of sustained effort by dedicated professionals across every part of the public sector.”

Rachel Sim

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data