Source · Select Committees · Public Accounts Committee

Recommendation 5

5

Secure clear assurance from departments managing cyber risk across arm’s-length bodies and supply chains.

Conclusion
The scale and diversity of government’s supply chains, and the size of the public sector, makes it significantly harder for government to manage cyber risk. The Cabinet Office expects departments to understand and tackle the cyber risk to their arm’s–length bodies and the wider public sector that they are responsible for. Departments should work closely with the Cabinet Office, in particular the Government Security Group, in assuring this risk as arm’s–length bodies may be an entry point for cyber attackers. Departments have not always met this expectation because of insufficient funding, staff, and oversight mechanisms. Lessons can be learned from the Department of Health and Social Care, which has begun to improve the resilience of its sector by putting in place a cyber security strategy, strengthening assurance processes, investing in common services, and setting clear policies. Departments also need to understand and manage the risks to security from their supply chains, which can be vulnerable to adversaries seeking to gain access to or disrupt government networks. The ransomware attack on Synnovis is an example of a supply 5 chain attack that had serious consequences for individuals and disrupted services. The Cabinet Office says it is giving departments text to include in contracts so that suppliers put appropriate cyber security measures in place, and that it plans to work with strategic suppliers to help improve government’s resilience. recommendation The Cabinet Office should secure clear assurance from departments that they understand and are effectively managing the cyber risk from their arm’s–length bodies and supply chains.
Government Response

A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗