‘Crumbling’ Government cyber defences outpaced by cyber criminals – report

9 May 2025, 00:04

A woman’s hand pressing keys of a laptop keyboard
Cybersecurity Readiness Index. Picture: PA

The report from the Public Accounts Committee warned there are significant gaps in public sector IT systems, leaving them vulnerable.

Government cyber defences have not kept up with the dangerous and evolving threats from hackers, a report from MPs has warned.

The Public Accounts Committee (PAC) said hostile states and criminals have developed the ability to severely disrupt public services and critical national infrastructure faster than the Government expected.

According to Government estimates, vulnerable “legacy” IT systems make up 28% of all public sector IT, and the PAC report said the Cabinet Office had acknowledged that there was now a significant gap between the cyber threat and the Government’s response to it.

A serious cyber attack is not some abstract event taking place in the digital sphere

Sir Geoffrey Clifton-Brown, Public Accounts Committee

The report comes in the wake of high-profile cyber attacks on UK retailers, including Marks and Spencer and Co-op, incidents which Chancellor of the Duchy of Lancaster Pat McFadden said should be a “wake-up call” for British businesses, as he announced a new £16 million package to boost cyber defences during a cyber security conference earlier this week.

In its report conclusions, the PAC also said there was a shortage in Government of technical cyber skills and experience, cyber security had not been prioritised as a key issue, gaps remained in the Government’s understanding of how resilient public sector IT systems were to attack, and that existing supply chains were complicated to properly secure.

It called on the Cabinet Office to carry out a major audit of IT systems and report back with details on how it plans to fix the range of issues raised.

Sir Geoffrey Clifton-Brown, chairman of the committee, said: “Government departments are beginning to wake up to the serious cyber threat they face.

“It is positive to see independent verification now in place to gain a better picture on critical systems resilience.

“Unfortunately, this has only served to confirm that our battlements are crumbling.

“A serious cyber attack is not some abstract event taking place in the digital sphere.

“The British Library cyber attack is a prime example of the long-lasting cost and disruption that these events can cause.

It must not take a devastating attack on a critical piece of the country’s infrastructure for defensive action to be taken

Sir Geoffrey Clifton-Brown, Public Accounts Committee

“Hostile states and criminals have the ability to do serious and lasting harm to our nation and people’s lives.

“If the Government is to meet its own ambition to harden resilience in the wider public sector, a fundamental step change will be required.

“This will involve infusing every top team with the required digital expertise, with cyber and digital specialists at the top level of every department, both management and boards to bring about a change in thinking throughout the Civil Service for greater threat awareness and digital transformation.

“Part of this will be Government finally grasping the nettle on offering competitive salaries for digital professionals, and we were encouraged to hear the Cabinet Office thinking in these terms.

“For too long, Whitehall has been unwilling to offer attractive remuneration for experts who are able to secure high-paid work elsewhere.

“Making sure that the right people are in the right jobs to defend the UK against this serious threat, and reducing the use of expensive contractors at the same time, is clearly sound value for money.

“This is an issue our committee will continue to scrutinise closely.

“It must not take a devastating attack on a critical piece of the country’s infrastructure for defensive action to be taken.”

A Government spokesperson said: “Just this week, we announced action to boost our country’s cyber security, helping to grow the economy and create jobs through the Plan for Change. This includes backing for the rollout of cutting-edge CHERI technology which could prevent up to 70% of the most common cyber attacks.

“Last month we also unveiled details of our Cyber Security and Resilience Bill which will be introduced to Parliament later this year, ensuring our critical national infrastructure and digital economy are better protected and less vulnerable to attack.”

By Press Association

More Technology News

See more More Technology News

People ride an upward escalator next to the Dior store at the Icon Siam shopping mall on June 12, 2024 in Bangkok, Thailand.

Luxury fashion giant Dior latest high-profile retailer to be hit by cyber attack as customer data accessed

A plane spotter with binoculars from behind watching a British Airways plane landing

‘Flying taxis’ could appear in UK skies as early as 2028, minister says

Apple App Store

Take on Apple and Google to boost UK economy, think tank says

A survey of more than 1,000 employers found that around one in eight thought AI would give them a competitive edge and would lead to fewer staff.

One in three employers believe AI will boost productivity, research finds

Hands on a laptop showing an AI search

One in three employers believe AI will boost productivity, research finds

Music creators and politicians take part in a protest calling on the Government to ditch plans to allow AI tech firms to steal their work without payment or permission opposite the Houses of Parliament in London.

Creatives face a 'kind-of apocalyptic moment’ over AI concerns, minister says

Ngamba Island Chimpanzee Sanctuary on Lake Victoria, Uganda

Chimps use medicinal plants to treat each other's wounds and practice 'self-care' as scientists hail fascinating discovery

Close up of a person's hands on the laptop keyboard

Ofcom investigating pornography site over alleged Online Safety Act breaches

The Monzo app on a smartphone

Monzo customers can cancel bank transfers if they quickly spot an error

Co-op sign

Co-op to re-stock empty shelves as it recovers from major hack

The study said that it was often too easy for adult strangers to pick out girls online and send them unsolicited messages.

Social media platforms are failing to protect women and girls from harm, new research reveals

Peter Kyle leaves 10 Downing Street, London

Government-built AI tool used to cut admin work for human staff

In its last reported annual headcount in June 2024, Microsoft employed 228,000 full-time workers

Microsoft axes 6,000 jobs despite strong profits in recent quarters

Airbnb logo

Airbnb unveils revamp as it expands ‘beyond stays’ to challenge hotel sector

A car key on top of a Certificate of Motor Insurance and Policy Schedule

Drivers losing thousands to ghost broker scams – the red flags to watch out for

Marks and Spencer cyber attack

M&S customers urged to ‘stay vigilant’ for fraud after data breach confirmed