‘Crumbling’ Government cyber defences outpaced by cyber criminals – report

9 May 2025, 00:04

A woman’s hand pressing keys of a laptop keyboard
Cybersecurity Readiness Index. Picture: PA

The report from the Public Accounts Committee warned there are significant gaps in public sector IT systems, leaving them vulnerable.

Government cyber defences have not kept up with the dangerous and evolving threats from hackers, a report from MPs has warned.

The Public Accounts Committee (PAC) said hostile states and criminals have developed the ability to severely disrupt public services and critical national infrastructure faster than the Government expected.

According to Government estimates, vulnerable “legacy” IT systems make up 28% of all public sector IT, and the PAC report said the Cabinet Office had acknowledged that there was now a significant gap between the cyber threat and the Government’s response to it.

A serious cyber attack is not some abstract event taking place in the digital sphere

Sir Geoffrey Clifton-Brown, Public Accounts Committee

The report comes in the wake of high-profile cyber attacks on UK retailers, including Marks and Spencer and Co-op, incidents which Chancellor of the Duchy of Lancaster Pat McFadden said should be a “wake-up call” for British businesses, as he announced a new £16 million package to boost cyber defences during a cyber security conference earlier this week.

In its report conclusions, the PAC also said there was a shortage in Government of technical cyber skills and experience, cyber security had not been prioritised as a key issue, gaps remained in the Government’s understanding of how resilient public sector IT systems were to attack, and that existing supply chains were complicated to properly secure.

It called on the Cabinet Office to carry out a major audit of IT systems and report back with details on how it plans to fix the range of issues raised.

Sir Geoffrey Clifton-Brown, chairman of the committee, said: “Government departments are beginning to wake up to the serious cyber threat they face.

“It is positive to see independent verification now in place to gain a better picture on critical systems resilience.

“Unfortunately, this has only served to confirm that our battlements are crumbling.

“A serious cyber attack is not some abstract event taking place in the digital sphere.

“The British Library cyber attack is a prime example of the long-lasting cost and disruption that these events can cause.

It must not take a devastating attack on a critical piece of the country’s infrastructure for defensive action to be taken

Sir Geoffrey Clifton-Brown, Public Accounts Committee

“Hostile states and criminals have the ability to do serious and lasting harm to our nation and people’s lives.

“If the Government is to meet its own ambition to harden resilience in the wider public sector, a fundamental step change will be required.

“This will involve infusing every top team with the required digital expertise, with cyber and digital specialists at the top level of every department, both management and boards to bring about a change in thinking throughout the Civil Service for greater threat awareness and digital transformation.

“Part of this will be Government finally grasping the nettle on offering competitive salaries for digital professionals, and we were encouraged to hear the Cabinet Office thinking in these terms.

“For too long, Whitehall has been unwilling to offer attractive remuneration for experts who are able to secure high-paid work elsewhere.

“Making sure that the right people are in the right jobs to defend the UK against this serious threat, and reducing the use of expensive contractors at the same time, is clearly sound value for money.

“This is an issue our committee will continue to scrutinise closely.

“It must not take a devastating attack on a critical piece of the country’s infrastructure for defensive action to be taken.”

A Government spokesperson said: “Just this week, we announced action to boost our country’s cyber security, helping to grow the economy and create jobs through the Plan for Change. This includes backing for the rollout of cutting-edge CHERI technology which could prevent up to 70% of the most common cyber attacks.

“Last month we also unveiled details of our Cyber Security and Resilience Bill which will be introduced to Parliament later this year, ensuring our critical national infrastructure and digital economy are better protected and less vulnerable to attack.”

By Press Association

More Technology News

See more More Technology News

Sir Elton John performing

Elton John says ‘we will not back down’ in awards speech addressing AI concerns

Live
Customers purchase Nintendo Switch 2 at an electronics retailer in Tokyo on June 5, 2025.

Nintendo Switch 2 launch live: Where to buy, best deals, and early verdict

In this photo illustration, an Apple logo is seen displayed alongside the Google logo.

Tech giants Apple and Google 'profiting from phone thefts', MPs claim

A man's hands using a laptop keyboard

Scots warned of ‘scamdemic’ as £860,000 lost to cyber criminals in 12 months

A close up image of a The North Face fleece

North Face and Cartier customer data stolen in cyber attacks

Imagery of a Zilch payments card and a virtual card

Buy now pay later provider Zilch to launch first physical card

UK’s most EV-friendly city has been revealed by new research.

Cities with slowest EV charging times and least amount of chargers revealed

View of a VodafoneThree logo outside the firm's offices

Vodafone completes Three UK mega-merger to form ‘new force’ in mobile market

A hand holding a Monzo bank card and a mobile phone showing the Monzo app

Monzo annual profit surges as paying subscribers boost digital bank

Majestic British Airways Airbus A380 taking off from London Heathrow at sunset, amazing colors

UK airspace shake-up could slash journey times and cut flight delays for millions of passengers

File photo dated 30/05/25 of the saltmarsh at Abbotts Hall in Essex. Saltmarshes are 'significant' carbon stores, but are at risk from rising sea levels, new research reveals

UK's muddy saltmarshes vital to tackle climate change, report finds

Nigel Farage

Reform backs cryptocurrency tax cut as party receives first Bitcoin donations

Digital devices on office workplace table of young business woman

‘Young people and black workers at highest risk of workplace surveillance’

Debris from the Titan submersible, recovered from the ocean floor near the wreck of the Titanic, is unloaded from the ship Horizon Arctic at the Canadian Coast Guard pier in St. John's, Newfoundland, in June 2023

The shock household item discovered in 'sludge' of OceanGate sub wreckage

Google is facing a £25 billion legal claim in the UK, accusing the tech giant of abusing its dominant position in the online search advertising market

Google facing £25 billion legal claim over abuse of search advertising market

A hand holding a phone showing the Nvidia logo

Nvidia posts strong growth despite ongoing tariff challenges