Source · Select Committees · Public Accounts Committee
Recommendation 18
18
Departments remain reluctant to share cyber incident information, hindering collective learning.
Conclusion
We asked the Cabinet Office what the impact was when departments did not share information about their cyber incidents. The Cabinet Office agreed that sharing data is essential to learn lessons, understand vulnerabilities, share best practice and work out what has gone wrong. The Cabinet Office reassured us that if departments find any vulnerabilities that could affect other parts of government, it shares these immediately. The Cabinet Office accepted that departments could be cautious and concerned about reputational damage, but noted there may also be good reasons to not share data. The Cabinet Office told us it wants to increase transparency and that its role is to challenge departments on how much they share and help manage their concerns.38 When we asked the Cabinet Office what it was doing to promote a culture of learning from mistakes and near misses, it responded that this was one of its biggest cultural priorities.39
Government Response
A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗