Site navigation

Report: Cyber Training Gaps Leave Public Sector Exposed

Graham Turner

,

Public sector cyber training
More than one in four surveyed employees said they had received no effective training in the past year, or none at all.

A new study has uncovered a mismatch between public sector workers’ confidence in spotting cyber threats and the cybersecurity training they’ve actually received.

The findings come after a cyber attack on the Department for Education exposed more than 600,000 records, highlighting the growing threat facing public sector organisations.

The figures have been published by compliance training provider, Skillcast, in its latest report, Careless Clicks: How to reduce the risk of cyber-attacks in the public sector?. It surveyed 200 employees in the public sector to understand their awareness of the changing cybersecurity risks at work.

Despite 85% believing they could identify a sophisticated phishing attack, more than one in four say they haven’t received effective cybersecurity training in the past year – or any training at all.

Almost half (45%) use work devices to check personal emails or social media, potentially creating additional opportunities for phishing attacks.

Meanwhile, almost one in five (18%) are either unaware of their organisation’s cybersecurity and data handling policies or only know they exist.

Sofia Chaqiri, Senior Client Partner for the public sector at Skillcast, said: “Cyber-attacks are getting more sophisticated and widespread – and the public sector is a key target because of the amount of data organisations hold, and the potential disruption to vital services in sectors like healthcare and transport.

“Our data suggests that while most people are confident they could spot a phishing email, and generally follow good practices, there are clear gaps in training.

“The fact that some people haven’t received effective training for at least 12 months is particularly worrying. They may understand the risks in theory, but it’s easy to let your guard down when you’re working quickly, or at home casually scrolling through social media on a work device.”

She added that compliance training had to evolve in line with the growing risks: “Compliance training has to evolve beyond one-off, yearly or generic sessions that don’t reflect the reality public sector workers are facing today. Just because it’s serious doesn’t mean it has to be dry – quizzes, phishing simulations, and instant feedback are more engaging and help people stay up-to-date.

“Personalised training is also valuable because risks vary according to an individual’s role. Someone on the front line in admin or customer service may see different challenges to line managers, so sessions should be relevant and matched to their capabilities.”


Recommended reading


Dr John Kingston, Senior Lecturer in Cyber Security in the Department of Computer Science at Nottingham Trent University, and a contributor to the report, echoed her comments, saying:

“Education takes time to be fully effective, so attackers can often outflank organisations that are trying to protect themselves. But that only reinforces how important it is to train staff properly. Organisations cannot afford to stand still – technology and cyber threats are evolving too quickly for that.

“Delivering regular and in-depth training that reflects real-life scenarios is the best way for organisations to stay agile. Cybersecurity has to be made an ongoing and high-priority concern from top to bottom – not to stoke fear, but to build a healthy and rational vigilance among staff.”

Graham Turner

Sub Editor

Latest News

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far

Cybersecurity Security Skills

Report: Cyber Training Gaps Leave Public Sector Exposed