UK Government Ditches 'Mandate and Hope' Cybersecurity Model After Damning Audit
The UK government is rethinking how it manages cybersecurity across its sprawling civil service, made up of roughly 465 separate agencies and public bodies. Speaking at the Gartner Security & Risk Management Summit in London, Deputy CISO Breandán Knowlton-Hung explained that the 2022 national cyber strategy assumed departments would follow central standards simply because they were issued. A 2025 National Audit Office review found this wasn't happening: there was no clear implementation plan and no reliable way to measure progress.
The audit also revealed serious staffing shortfalls, with one in three cyber roles vacant or filled by temporary contractors, and most specialist architect positions unfilled on a permanent basis. Knowlton-Hung noted that departments weren't ignoring guidance out of defiance, but because of budget limits, legacy systems, and competing priorities they were directly accountable for.
The government is now moving toward what Knowlton-Hung calls 'polycentric governance', where central teams build and maintain a smaller set of shared services that departments actually want to use, rather than issuing broad mandates and hoping for compliance. The approach reflects a lesson relevant well beyond government: policy without practical support and resourcing rarely translates into real security improvement.