Source · Select Committees · Public Accounts Committee

24th Report - Government cyber resilience

Public Accounts Committee HC 643 Published 9 May 2025
Report Status
Government responded
Conclusions & Recommendations
35 items (15 recs)
Government Response
AI assessment · 34 of 35 classified
Accepted 30
Accepted in Part 1
Deferred 3
Government response
Treasury minutes: Government response to the Committee of Public Accounts on the Twenty-fourth report from Session 2024-26 · published 18 Sep 2025
Read the government response ↗ Response on the Index
Filter by: Clear

Recommendations & Conclusions

3 items
32 Conclusion Deferred

Government lacks robust oversight of departmental cyber strategy, risking 2025 resilience target.

Conclusion
The Cabinet Office has prioritised implementing its central initiatives, such as GovAssure. However, it has not put robust arrangements in place to oversee how departments are implementing the Strategy, such 65 Q 67 66 Q 61 67 Q 79; GCR0004, … Read more
Government Response Summary
The government agrees and is defining a future Target Operating Model for Cyber and Digital Resilience, with DSIT setting out implementation plans for this model later in 2025.
HM Treasury
View Details →
33 Conclusion Deferred

Cabinet Office designing new approach to meet challenging 2030 cyber security target

Conclusion
We asked the Cabinet Office how it intended to meet its target for 2030. The Cabinet Office was clear that the target would be challenging to meet. To do so, it told us that government would need to take a … Read more
Government Response Summary
The government agrees and states that a Target Operating Model for Cyber and Digital Resilience is being defined, with DSIT setting out implementation plans later in 2025.
HM Treasury
View Details →
34 Conclusion Deferred

Cabinet Office accepted NAO recommendation for cross-Government cyber security implementation and monitoring plan

Conclusion
We challenged the Cabinet Office on whether its plans were realistic. The Cabinet Office told us it had accepted the NAO’s recommendation that it needed a cross–Government implementation plan and a stronger monitoring and evaluation framework.75 It said these would … Read more
Government Response Summary
The government agrees with the committee's observation and states that work is underway to define a future Target Operating Model for Cyber and Digital Resilience, with DSIT setting out implementation plans later in 2025.
HM Treasury
View Details →