HomeRisk ManagementsUK Government Transitions to Service-Led Cyber Governance Following Audit

UK Government Transitions to Service-Led Cyber Governance Following Audit

Published on

spot_img

The UK government’s approach to cybersecurity within the civil service is undergoing a significant transformation, marking a shift from a top-down directive model to a more collaborative and service-oriented strategy. This change seeks to enhance adoption and practical usage by frontline teams, moving away from previous mandates that were not effectively implemented.

Breandán Knowlton-Hung, the Deputy Chief Information Security Officer (CISO) at the UK Civil Service, articulated this evolution during the Gartner Security & Risk Management Summit held in London on September 23. He emphasized that merely issuing mandates is insufficient for driving meaningful change. “A mandate is permission to direct. It isn’t the ability to make change happen,” Knowlton-Hung stated. This realization was borne from experiences within a decentralized framework that comprises about 465 distinct entities within the UK government, including ministries, agencies, and public bodies, each with its own leadership, budget, and systems.

The 2022 National Cyber Security Strategy aimed to establish an ambitious unified defense model under the banner of “defend as one,” which envisioned a collaborative approach where his office would set the overarching direction while individual departments would be responsible for managing their specific risks. However, Knowlton-Hung noted that this model often rested on the flawed assumption that simply issuing standards and requiring compliance would suffice to ensure that risks were mitigated effectively.

The pivotal moment for this reassessment came with the release of a 2025 report by the National Audit Office (NAO). The report highlighted that three years post-implementation of the strategy, the government lacked a coherent implementation plan and had no system in place to evaluate the effectiveness of the initiatives. Additionally, the NAO underscored critical staffing issues within the cybersecurity sector; an alarming one in three roles were either unfilled or occupied by temporary contractors, while many specialist positions were not permanent. “You can issue all the mandates you like. If there’s no one at the other end to pick them up, they won’t get picked up,” Knowlton-Hung stated, emphasizing the disconnect between policy intentions and on-the-ground realities.

This gap between policy and practice, he explained, often exacerbates challenges in federated systems, whether in governmental or corporate contexts characterized by rapid expansion through mergers and acquisitions. “People didn’t refuse to act. They just couldn’t, because of budgets, systems, or competing risks they actually own,” Knowlton-Hung noted, highlighting the complexities faced by organizations that must juggle multiple risks and governance structures.

To address these complex dynamics, Knowlton-Hung introduced a concept referred to as “polycentric governance” for cybersecurity. This model fosters multiple overlapping decision-making centers that work in coordination rather than adhering strictly to a centralized hierarchy. He presented three main actions guiding this new approach:

  1. Construct Central Services: The government will begin by developing centrally delivered services that tackle real and pressing problems encountered by users across the hundreds of government services.

  2. Facilitate Cheaper Adoption: The goal is to make adopting these services socially and operationally less costly than opting not to use them.

  3. Centralize Authority on Systemic Risks: While day-to-day operations are decentralized, the government will reserve hard central authority for a select few systemic risks that could adversely impact multiple entities if not managed properly.

“Own fewer things centrally, but own them harder,” Knowlton-Hung reiterated. The underlying philosophy is about making central services indisputable in their utility for users, thereby driving adoption organically rather than through coercion.

Despite this shift, Knowlton-Hung reassured that the central government will continue to provide strategic direction and policy oversight, particularly for joint risks that cannot be adequately addressed at local levels. He cited a central vulnerability monitoring service as an illustrative example of the new approach, which continually scans thousands of public sector organizations for various externally visible vulnerabilities, swiftly routing actionable notifications to relevant stakeholders.

“By integrating with how people actually work, we cut the median time to fix domain-level vulnerabilities from about 50 days to eight,” Knowlton-Hung explained, emphasizing that these local teams took ownership of the fixes prompted by the service’s support.

Attesting to the pace of progress, Knowlton-Hung candidly acknowledged that while cybersecurity assurance scores have seen year-on-year improvements, the pace remains insufficient in the face of ever-evolving threats. To expedite results, the UK government is implementing a layered action plan alongside the new operational model.

“Stop trying to force change through a memo,” Knowlton-Hung advised. “Go and be useful instead. Build the thing people want to pick up, then get out of the way while they use it.” This call to action reflects a renewed understanding that practical engagement and utility are far more effective in driving meaningful cybersecurity enhancements within the complex landscape of the UK’s civil service.

Source link

Latest articles

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity...

SCOUTz Unveils Prospect Intelligence Platform for MSPs with 30-Day Beta Launch

Phoenix, Arizona, September 24th, 2026, CyberNewswire — The landscape of cybersecurity sales for managed...

Thousands of AI Relays Conceal Chinese Users

Cybersecurity Weekly Roundup: Major Incidents and Developments In the ever-evolving landscape of cybercrime and cybersecurity,...

WordPress Addresses a Critical Security Vulnerability

Urgent Security Warning: The Evolving Threat Landscape for WordPress Users In a rapidly changing cybersecurity...

More like this

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity...

SCOUTz Unveils Prospect Intelligence Platform for MSPs with 30-Day Beta Launch

Phoenix, Arizona, September 24th, 2026, CyberNewswire — The landscape of cybersecurity sales for managed...

Thousands of AI Relays Conceal Chinese Users

Cybersecurity Weekly Roundup: Major Incidents and Developments In the ever-evolving landscape of cybercrime and cybersecurity,...