Security News

UK Government Ditches 'Mandate and Hope' Cybersecurity Model After Damning Audit

Infosecurity Magazine · 24 Sept 2026
Key Takeaway Rather than just publishing security policies, small businesses should invest in making secure practices easy to adopt, since rules without the resources or tools to follow them rarely get implemented.

The UK government is rethinking how it manages cybersecurity across its sprawling civil service, made up of roughly 465 separate agencies and public bodies. Speaking at the Gartner Security & Risk Management Summit in London, Deputy CISO Breandán Knowlton-Hung explained that the 2022 national cyber strategy assumed departments would follow central standards simply because they were issued. A 2025 National Audit Office review found this wasn't happening: there was no clear implementation plan and no reliable way to measure progress.

The audit also revealed serious staffing shortfalls, with one in three cyber roles vacant or filled by temporary contractors, and most specialist architect positions unfilled on a permanent basis. Knowlton-Hung noted that departments weren't ignoring guidance out of defiance, but because of budget limits, legacy systems, and competing priorities they were directly accountable for.

The government is now moving toward what Knowlton-Hung calls 'polycentric governance', where central teams build and maintain a smaller set of shared services that departments actually want to use, rather than issuing broad mandates and hoping for compliance. The approach reflects a lesson relevant well beyond government: policy without practical support and resourcing rarely translates into real security improvement.

cybersecurity governance UK government risk management security strategy policy
Putting a number on risk like this? How to run an ISO 31000 risk assessment ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.