Source · Select Committees · Public Accounts Committee
Recommendation 26
26
Department received specific funding to upgrade high-risk legacy IT systems over three years
Conclusion
We asked the Department if it had been given extra resources to deal with some of its legacy IT and what its plans were. The Department confirmed it did get specific funding in the Spending Review for both its increase in cyber security and its ‘legacy tech debt’ programme. It explained that it had aggregated the risk scores for every single system it had categorised– scoring each system against a number of dimensions. Over the next three years, it was planning to upgrade its high-risk legacy systems with the aim of reducing its overall risk score from legacy IT by 58%. The Department said that it planned to tackle the larger systems used by more staff and customers first, with the 36 highest-risk systems being addressed this year. It told us that it was not that its legacy systems could not be protected from cyber attack, but it had to put layers of protection in place so that specific threats relevant to one bit of the overall system were lessened.39
Government Response
A response document is linked to this report, dated 1 April 2026. Response attribution to this conclusion has not been verified. Read the response document ↗