Source · Select Committees · Public Accounts Committee

Recommendation 6

6

Require MoJ and LAA to detail cyberattack lessons and funding for system vulnerabilities.

Recommendation
Despite lessons learned from the cyberattack on the LAA, funding to address weaknesses across MoJ systems is uncertain. Vulnerabilities in LAA’s systems had been on MoJ’s risk register since 2021. However, MoJ’s investment of over £50 million to transform and stabilise LAA’s systems was insufficient to prevent hackers accessing a large amount of both provider and legal aid applicant data. While the investment led to improvements that enabled LAA to identify the breach in April 2025, this came four months after attackers initially accessed the system in December 2024. LAA recognises that contingency measures it put in place as services were taken offline have created additional pressures for providers and its staff, and that there are several lessons to be learned from the crisis that can be shared across government. For example, the importance of longer-term continuity plans, and of ensuring that senior leaders understand the vulnerabilities associated with their systems. Following the attack, MoJ reviewed all of its systems to identify where vulnerabilities exist but addressing these vulnerabilities will depend on its internal decisions on how it allocates its Spending Review settlement. recommendation In the Treasury Minute response, the Ministry of Justice and the Legal Aid Agency should set out: • the lessons it has learned from the crisis and how and when it plans to share these lessons with other government departments. • whether it has sufficient funding to address the key risks identified from the review of its systems, once allocations are decided. 6 1 MoJ and HMPPS’s decision to renew the HMP Dartmoor lease Introduction
Government Response

A response document is linked to this report, dated 1 April 2026. Response attribution to this recommendation has not been verified. Read the response document ↗