UK splashes £210M on cyber plan to stop Whitehall getting pwnd
(2026/01/06)
- Reference: 1767695865
- News link: https://www.theregister.co.uk/2026/01/06/government_cyber_action_plan/
- Source link:
The UK today launches its Government Cyber Action Plan, committing £210 million ($282 million) to strengthen defenses across digital public services and hold itself to the same cybersecurity standards it's imposing on critical infrastructure operators.
The funding will establish a Government Cyber Unit, led by the UK's CISO and overseen by the Department for Science, Innovation and Technology (DSIT), to improve risk identification, incident response, and recovery capabilities.
The unit will also create a dedicated Government Cyber Profession, elevating cybersecurity from its current placement under the broader Government Security Profession.
[1]
Announced alongside the second reading of the [2]Cyber Security and Resilience Bill , the plan subjects government departments to the same security requirements as cloud providers, search engines, and operators of critical infrastructure, including datacenters. The UK estimates this investment will save up to £45 billion annually across the public sector.
[3]
[4]
"Cyberattacks can take vital public services offline in minutes – disrupting our digital services and our very way of life," said digital minister Ian Murray.
"This plan sets a new bar to bolster the defenses of our public sector, putting cybercriminals on warning that we are going further and faster to protect the UK's businesses and public services."
[5]
The announcement follows mounting security failures. The [6]Foreign Office confirmed an October intrusion widely attributed to Chinese state-sponsored actors, while the Legal Aid Agency - overseen by the Ministry of Justice - [7]suffered a major breach in April .
A [8]scathing report by the National Audit Office (NAO) twelve months ago found 58 of 72 critical IT systems it reviewed across central government contained "multiple fundamental system controls that were at low levels of maturity."
[9]UK's long-delayed Emergency Services Network eyes satellites for help
[10]Ministers confirm breach at UK Foreign Office but details remain murky
[11]GOV.UK to unleash AI chatbot on confused citizens
[12]UK surveillance law still full of holes, watchdog warns
Further, ministers were advised that government security risk is "extremely high." In March 2024, auditors identified at least 228 legacy systems, 28 percent of which were flagged as having a high likelihood of operational and security risks.
DSIT also today launched a Software Security Ambassador Scheme to drive adoption of its Software Security Code of Practice. Initial ambassadors include Cisco, NCC Group, Palo Alto Networks, Sage, and Santander, who will champion secure development practices and contribute to future policy.
The initiative mirrors CISA's [13]Secure by Design pledge , which recruited more than 340 organizations in 2024 to commit to improvements like multi-factor authentication and mandatory patching.
[14]
The UK is also looking to shore up supply chain security in a similar way by pressing the biggest vendors to ship secure code and enforce secure practices among users. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2025/11/12/uk_cyber_security_and_resilience/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2025/12/19/uk_foreign_office_hack/
[7] https://www.theregister.com/2025/05/19/legal_aid_agency_data_theft/
[8] https://www.theregister.com/2025/01/29/nao_blasts_uk_gov_cyber/
[9] https://www.theregister.com/2026/01/05/uk_esn_satellite_comms/
[10] https://www.theregister.com/2025/12/19/uk_foreign_office_hack/
[11] https://www.theregister.com/2025/12/19/govuk_chatbot/
[12] https://www.theregister.com/2025/12/18/snoopers_charter_loopholes/
[13] https://www.theregister.com/2024/05/09/68_tech_firms_sign_cisas/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
The funding will establish a Government Cyber Unit, led by the UK's CISO and overseen by the Department for Science, Innovation and Technology (DSIT), to improve risk identification, incident response, and recovery capabilities.
The unit will also create a dedicated Government Cyber Profession, elevating cybersecurity from its current placement under the broader Government Security Profession.
[1]
Announced alongside the second reading of the [2]Cyber Security and Resilience Bill , the plan subjects government departments to the same security requirements as cloud providers, search engines, and operators of critical infrastructure, including datacenters. The UK estimates this investment will save up to £45 billion annually across the public sector.
[3]
[4]
"Cyberattacks can take vital public services offline in minutes – disrupting our digital services and our very way of life," said digital minister Ian Murray.
"This plan sets a new bar to bolster the defenses of our public sector, putting cybercriminals on warning that we are going further and faster to protect the UK's businesses and public services."
[5]
The announcement follows mounting security failures. The [6]Foreign Office confirmed an October intrusion widely attributed to Chinese state-sponsored actors, while the Legal Aid Agency - overseen by the Ministry of Justice - [7]suffered a major breach in April .
A [8]scathing report by the National Audit Office (NAO) twelve months ago found 58 of 72 critical IT systems it reviewed across central government contained "multiple fundamental system controls that were at low levels of maturity."
[9]UK's long-delayed Emergency Services Network eyes satellites for help
[10]Ministers confirm breach at UK Foreign Office but details remain murky
[11]GOV.UK to unleash AI chatbot on confused citizens
[12]UK surveillance law still full of holes, watchdog warns
Further, ministers were advised that government security risk is "extremely high." In March 2024, auditors identified at least 228 legacy systems, 28 percent of which were flagged as having a high likelihood of operational and security risks.
DSIT also today launched a Software Security Ambassador Scheme to drive adoption of its Software Security Code of Practice. Initial ambassadors include Cisco, NCC Group, Palo Alto Networks, Sage, and Santander, who will champion secure development practices and contribute to future policy.
The initiative mirrors CISA's [13]Secure by Design pledge , which recruited more than 340 organizations in 2024 to commit to improvements like multi-factor authentication and mandatory patching.
[14]
The UK is also looking to shore up supply chain security in a similar way by pressing the biggest vendors to ship secure code and enforce secure practices among users. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2025/11/12/uk_cyber_security_and_resilience/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2025/12/19/uk_foreign_office_hack/
[7] https://www.theregister.com/2025/05/19/legal_aid_agency_data_theft/
[8] https://www.theregister.com/2025/01/29/nao_blasts_uk_gov_cyber/
[9] https://www.theregister.com/2026/01/05/uk_esn_satellite_comms/
[10] https://www.theregister.com/2025/12/19/uk_foreign_office_hack/
[11] https://www.theregister.com/2025/12/19/govuk_chatbot/
[12] https://www.theregister.com/2025/12/18/snoopers_charter_loopholes/
[13] https://www.theregister.com/2024/05/09/68_tech_firms_sign_cisas/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aVzrTQikQXIQDYnSZ2A3tgAAARY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/