UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
UK Civil Service drops mandate-led cyber governance for useful central services after a critical audit.
UK Civil Service Deputy CISO Breandán Knowlton-Hung said a 2025 National Audit Office review found the 2022 National Cyber Security Strategy had no proper implementation plan and no way to measure whether it worked. Across roughly 465 government bodies, about one in three cyber roles were vacant or filled by contractors. The service is shifting to “polycentric governance,” building central services such as vulnerability monitoring that cut median domain-level fix time from about 50 days to eight, while keeping hard authority for shared systemic risks.
52