Source · Select Committees · Public Accounts Committee
Recommendation 17
17
Require every government department to appoint a very senior Chief Information Officer.
Recommendation
We asked the Cabinet Office if departments have underestimated the cyber risk. It told us that until recently it had not done enough to ensure leaders across government understood the cyber threat, but that it had made 28 Q 17 29 C&AG’s Report, para 4.16 30 Qq 17–18 31 C&AG’s Report, para 4.2–4.4 32 C&AG’s Report, para 4.9–4.12 11 significant improvements in the last three years.33 These included bringing all the permanent secretaries together to discuss their responsibilities for cyber risk and writing to them to remind them of their duties.34 We suggested to the Cabinet Office that all departments needed to have a Chief Security Officer operating at senior levels. The Cabinet Office agreed that government should have senior people accountable and there was a need to have a very senior Chief Information Officer in every single department as standard.35 We asked the Cabinet Office if its senior board had a digital expert and it explained that it was recruiting new non–executive members and that these would include at least one digital expert. The Cabinet Office expected every department to do the same.36 The Cabinet Office reassured us that as part of the 2025 Spending Review, government was undertaking a comprehensive review of its technology budget and how it is spent.37
Government Response
A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗