32
Conclusion
24th Report - Government cyber resilien…
Deferred
The Cabinet Office has prioritised implementing its central initiatives, such as GovAssure. However, it has not put robust arrangements in place to oversee how departments are implementing the Strategy, such 65 Q 67 66 Q 61 67 Q 79; GCR0004, Written evidence submitted by Nigel D Cook; GCR0007, Written evidence …
Read more
The Cabinet Office has prioritised implementing its central initiatives, such as GovAssure. However, it has not put robust arrangements in place to oversee how departments are implementing the Strategy, such 65 Q 67 66 Q 61 67 Q 79; GCR0004, Written evidence submitted by Nigel D Cook; GCR0007, Written evidence submitted by The Open Cloud Coalition 68 Hansard, CrowdStrike: IT Outage, 22 July 2024 69 Q 80 17 as a cross–Government plan or performance framework.70 The National Audit Office (NAO) concluded that government would not meet its aim for “government’s critical functions to be significantly hardened to cyber attack by 2025”. The Cabinet Office’s aim for the whole of government and the wider public sector to be “resilient to known vulnerabilities and attack methods no later than 2030” is ambitious.71 In April 2024, ministers expressed support for the Cabinet Office to be more directive and provide departments with more centralised capability and support.72 The Cabinet Office assured us that it was working across the devolved administrations to meet its cyber resilience aims for the whole of government.73
Show less
Government response AI summary
The government agrees and is defining a future Target Operating Model for Cyber and Digital Resilience, with DSIT setting out implementation plans for this model later in 2025.
Read full response →
HM Treasury
33
Conclusion
24th Report - Government cyber resilien…
Deferred
We asked the Cabinet Office how it intended to meet its target for 2030. The Cabinet Office was clear that the target would be challenging to meet. To do so, it told us that government would need to take a fundamentally different approach to cyber security. The Cabinet Office was …
Read more
We asked the Cabinet Office how it intended to meet its target for 2030. The Cabinet Office was clear that the target would be challenging to meet. To do so, it told us that government would need to take a fundamentally different approach to cyber security. The Cabinet Office was designing this new approach, which it said would focus on what the centre of government could do to bring about change. Its plans included strengthening accountability, setting requirements for departments and measuring their performance against them, and providing services “once and well” from the centre of government to the public sector. The Cabinet Office gave the example of cross–Government vulnerability scanning, which the Government Digital Service was testing.74
Show less
Government response AI summary
The government agrees and states that a Target Operating Model for Cyber and Digital Resilience is being defined, with DSIT setting out implementation plans later in 2025.
Read full response →
HM Treasury
34
Conclusion
24th Report - Government cyber resilien…
Deferred
We challenged the Cabinet Office on whether its plans were realistic. The Cabinet Office told us it had accepted the NAO’s recommendation that it needed a cross–Government implementation plan and a stronger monitoring and evaluation framework.75 It said these would be ready in the summer of 2025, after the Spending …
Read more
We challenged the Cabinet Office on whether its plans were realistic. The Cabinet Office told us it had accepted the NAO’s recommendation that it needed a cross–Government implementation plan and a stronger monitoring and evaluation framework.75 It said these would be ready in the summer of 2025, after the Spending Review concluded.76 We asked the Cabinet Office how it knew which were the right issues to focus on if it lacked oversight of departments’ activities. The Cabinet Office clarified that it was working closely with departments, including through GovAssure and the GC3, which has helped it better understand and measure department’s risks and challenges.77
Show less
Government response AI summary
The government agrees with the committee's observation and states that work is underway to define a future Target Operating Model for Cyber and Digital Resilience, with DSIT setting out implementation plans later in 2025.
Read full response →
HM Treasury