Source · Select Committees · Public Accounts Committee

Recommendation 25

25

Department maintains a prioritised cyber incident response and business continuity framework

Conclusion
The Department explained that it had a security incident response framework in place that, in the case of a cyber attack, would enable it to keep its services running as much as possible. It told us that its business continuity plan would put in place the most important steps first—getting money to people—with some of its advisory processes being of lower priority.38
Government Response

A response document is linked to this report, dated 1 April 2026. Response attribution to this conclusion has not been verified. Read the response document ↗