Cyber threat towards UK Government 'severe and advancing quickly' - as resilience levels 'lower' than Whitehall estimated

29 January 2025, 05:28 | Updated: 29 January 2025, 06:12

No code is uncrackable. an unidentifiable computer hacker using a smartphone to hack into a computer network at night.
A shortage of cyber skills within Government and risks posed by old IT systems are among concerns. Picture: Alamy

By Flaminia Luck

The cyber threat towards the UK Government is "severe and advancing quickly", according to a new report from the Government's spending watchdog, with cyber resilience levels "lower" than Whitehall had estimated.

Listen to this article

Loading audio...

Officials have been told that Wednesday's report from the National Audit Office should serve as a "wake-up call" and push them to "get on top of this most pernicious threat".

A shortage of cyber skills within Government and risks posed by old IT systems are among the concerns officials have been told they must address if they are to "catch up with the acute cyber threat".

According to the NAO report, more than 50% of roles in several departments' cyber security teams were vacant on 2023/24, and at least 228 so-called legacy IT systems were in use across Government in March 2024, with officials unable to know how vulnerable those older systems may be to attack.

Among recent high-profile cyber attacks are one against the British Library in 2023, which saw employee data leaked, and a ransomware attack last summer that saw thousands of appointments cancelled at two London NHS trusts.

The National Cyber Security Centre managed 430 cyber incidents between September 2023 and August 2024 because of their potential severity. Of these, 89 were deemed to be "nationally significant".

The report concluded that "the cyber threat to the Government is severe and advancing quickly", and although the Government has started work to implement a cyber strategy, "progress is slow and cyber incidents with a significant impact on Government and public services are likely to happen regularly, not least because of the growing cyber threat".

It found that resilience levels are "lower" than Government had previously estimated and that some departments have "significant gaps" in the functions important to cyber resilience.

The report states: "To avoid serious incidents, build resilience and protect the value for money of its operations, Government must catch up with the acute cyber threat it faces.

"The Government will continue to find it difficult to do so until it successfully addresses the long-standing shortage of cyber skills, strengthens accountability for cyber risk and better manages the risks posed by legacy IT."

The head of the NAO has told the Government they must now "catch up" with the risk.

Gareth Davies said: "The risk of cyber attack is severe, and attacks on key public services are likely to happen regularly, yet Government's work to address this has been slow.

"To avoid serious incidents, build resilience and protect the value for money of its operations, Government must catch up with the acute cyber threat it faces.

"The Government will continue to find it difficult to catch up until it successfully addresses the long-standing shortage of cyber skills; strengthens accountability for cyber risk, and better manages the risks posed by legacy IT."

The head of a cross-party committee of MPs has said that public services have been left "exposed" as Government response has "not kept pace" with the evolving cyber threat.

911 Operations Center at Suffolk County Police Headquarters in Yaphank, New York
The head of the NAO has told the Government they must now "catch up" with the risk. Picture: Getty

Read more: Keir Starmer insists economy is 'beginning to turn around' as he bids to rescue UK's stuttering finances

Read more: Ministers reject calls to widen the definition of extremism

Sir Geoffrey Clifton-Brown MP, chairman of the Public Accounts Committee, said: "We have seen too often the devastating impact of cyber attacks on our public services and people's lives.

"Despite the rapidly evolving cyber threat, the Government's response has not kept pace. Poor co-ordination across Government, a persistent shortage of cyber skills, and a dependence on outdated legacy IT systems are continuing to leave our public services exposed.

"Today's NAO report must serve as a stark wake-up call to Government to get on top of this most pernicious threat."

A Government spokesperson said: "Many of the NAO's findings mirror the Government's own findings in the state of digital government review published last week.

"Since July, we have taken action to repair cyber defences neglected by successive governments - introducing new legislation to give us powers to protect critical national infrastructure from cyber attacks, delivering 30 new regional cyber skills projects to strengthen the country's digital workforce, and merging digital teams into one central Government Digital Service led by the Department for Science, Innovation and Technology.

"And last week we went further, announcing plans to upgrade technology across Government, both strengthening our defences against attack and transforming public services as part of the plan for change."

More Latest News

See more More Latest News

A Ryanair passenger plane taxis on the runway at Luton airport.

Ryanair plane from UK crashes into barrier on landing after ‘severe turbulence’ leaving passengers scared

Lively's team applied to prevent Justin Baldoni obtaining the messages between her and Taylor Swift, arguing they were irrelevant.

Messages between Blake Lively and Taylor Swift can be handed over to Justin Baldoni as part of legal battle, judge rules

Trump to decide on US involvement in Iran 'in the next two weeks' as White House reveals attack timeline

Trump to decide on US involvement in Israel-Iran conflict 'in the next two weeks' as White House unveils attack timeline

The elderly woman was found holding kitchen utensils and she was targeted with the Taser when she refused to drop them.

Police officers face misconduct hearing after dementia patient, 90, 'handcuffed and hooded' for holding kitchen utensils

Coco Gauff of United States during the Roland-Garros 2025, French Open, Grand Slam tennis tournament on 7 June 2025 at Roland-Garros stadium in Paris, France

Coco Gauff suffers shock defeat to Wang Xinyu in Berlin

Exclusive
The Iranian State Radio and Television (IRIB) building could be seen burning from a distance after the strike

Implications of a US attack on Iran 'might be greater' than Iraq in 2003, former Defence Secretary claims

Father James has been jailed for seven years for preying on the vulnerable teenage boys at Ampleforth College in North Yorkshire.

Monk, 71, jailed after sexually abusing boys at ‘Catholic Eton’ for two decades

'Major incident' declared as smoke seen billowing from motorway tunnel with drivers told to 'stay in cars'

Rush hour chaos as smoke seen billowing from motorway tunnel with drivers told to 'stay in cars'

Expats take to social media to react to 'unbearable' UK heatwave that 'feels like a sauna'

'90 feels like 120 here': US expats react to 'unbearable' heatwave that makes UK 'feel like a sauna'

Jennifer Abbot, 69, was discovered stabbed to death in her Camden home

Woman, 66, arrested on suspicion of killing film director in 'Rolex murder'

Britain's Prime Minister Keir Starmer poses with a personalised England shirt as he meets with the England Women's football team, the Lionesses, at St George's Park in Staffordshire, England.

PM unveils new school PE drive as he meets Lionesses to give pupils 'opportunity to play for England'

Garner-Abbey had gone to the hotel with 22 year old Philip Wood, who was her partner at the time, but isn’t the father of the unborn child.

Pregnant teenager jailed for 'throwing rocks and stoking fires' in Rotherham migrant riots

F1 Grand Prix of Abu Dhabi

What have critics said about F1: The Movie?

HMP Dorchester Prison, Dorset, Britain, UK

Violence ‘excessively high’ in prisons driven by overcrowding and drugs, report reveals

Sexual predator Chinese student Zhenhao Zou has been jailed

Chinese PhD student jailed for life for raping 10 women offered to be chemically castrated for lighter sentence

Sabrina Carpenter performs at the 2025 BRIT Awards

Sabrina Carpenter 'open' to banning phones at concerts despite 'backlash' from fans