Source · Select Committees · Public Accounts Committee
Recommendation 28
28
Departments lack resources and oversight to ensure cyber resilience across wider public sector.
Recommendation
Departments, arm’s–length bodies and their partners use a wide range of IT systems and technology to provide public services.63 The Government Cyber Security Strategy: 2022–2030 (‘the Strategy’) set out that government departments’ cyber responsibilities included ensuring their arm’s–length bodies and wider public sector meet resilience targets. In April 2024, the Cabinet Office reported it could not be confident that departments were meeting these responsibilities. Departments reported that they did not have enough funding, people, or oversight to understand and improve resilience across their sectors.64
Government Response
A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗