Skip to content

Security1 publisher2 min readPublished

The UK Civil Service is replacing cyber mandates with services departments choose to use

The UK Civil Service says standards and assurance did not produce compliance across roughly 465 separate public bodies, so the centre is building services instead and reserving hard authority for systemic risks.

The Watch · Security desk

Illustration accompanying The UK Civil Service is replacing cyber mandates with services departments choose to use

What happened

  • Breandan Knowlton-Hung, deputy CISO for the UK Civil Service, told the Gartner Security & Risk Management Summit in London on September 23 that a 2025 National Audit Office report forced a rethink of the 2022 strategy's operating model.
  • The replacement model, which he calls polycentric governance, builds central services first, makes adoption cheaper than non-adoption, and keeps hard central authority for a small set of systemic risks.
  • He said a central vulnerability monitoring service cut the median time to fix domain-level vulnerabilities from about 50 days to eight, without the centre ordering any of the fixes.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability A scanner the centre runs, plus routing to the named owner of each finding, gives a federated security team reach into estates it has no budget authority over.
  • constraint With a third of cyber posts empty or contracted, any control that requires departments to staff it is capped by hiring, which leaves the centre with the work it can perform itself.
  • decision Groups assembled by acquisition face the choice Knowlton-Hung describes: fund shared services, or keep sending standards to teams with no capacity to pick them up.
  • exposure Eight days is the median for domain-level findings routed by one service. That figure leaves the rest of the estate's exposure window unmeasured.

The 465 departments, agencies and public bodies hold the risk, and the centre does the scanning [4]. No department has to accept a standard first for that to work. A central vulnerability monitoring service continuously checks thousands of public sector organisations for roughly a thousand classes of externally visible weakness, then routes each actionable notification to the owner who can close it [15].

Knowlton-Hung put one number on the result. "By integrating with how people actually work, we cut the median time to fix domain-level vulnerabilities from about 50 days to eight," he said [16]. That is 42 days off the median exposure window, a cut of 84% [1]. Infosecurity Magazine's account of the talk leaves out how many organisations sit behind that median and what period it covers.

One in three cyber roles were vacant or filled by temporary contractors, and a large majority of specialist architects held non-permanent posts [7]. That staffing picture is what made standards and assurance unworkable as a delivery mechanism. "You can issue all the mandates you like. If there's no one at the other end to pick them up, they won't get picked up," Knowlton-Hung said [8]. He also said the shortfall was not resistance: "People didn't refuse to act. They just couldn't, because of budgets, systems, or competing risks they actually own" [9].

The 2025 National Audit Office report is a public document; the phrases "no proper implementation plan" and "no way to tell whether any of it was really working" reached the London audience as Knowlton-Hung's summary of it [6]. The replacement model was described on September 23 by the office the audit examined [1].

What the centre keeps is deliberately small. Build useful central services, make adoption socially and operationally cheaper than non-adoption, and hold hard authority only for systemic risks where one failure can harm everyone [12]. "Own fewer things centrally, but own them harder," Knowlton-Hung said. "Everywhere else, be unmissably useful" [13]. Direction, the policy line and intervention on shared risks stay with the centre [14].

He named a limit as well. Assurance scores are improving year over year and, by his own account, still not fast enough against the threat [18]. An action plan is being layered on top of the operating model to speed up impact [19].

The part that travels beyond Whitehall is his claim about federations: the gap between policy and practice widens in any of them, including private companies that grew by acquisition [10]. "Go and be useful instead. Build the thing people want to pick up, then get out of the way while they use it," he said [20].

What to watch

  • Publication of the action plan layered on the operating model, and whether it names the systemic risks that keep hard central authority.
  • Whether the National Audit Office returns to the 2022 strategy and measures implementation itself, rather than the record resting on the deputy CISO's account.
  • Whether the vulnerability monitoring service's fix-time medians are published with organisation counts and coverage periods.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories