www.infosecurity-magazine.com 24 Sept 2026, 11:00 UTC

UK Civil Service Slashes Vulnerability Fix Times with Shared Services

UK Civil Service Slashes Vulnerability Fix Times with Shared Services
CyberSIXT Evidence Panel Source marked as original reporting

THE UK government is changing how it manages cybersecurity across the civil service, moving from top-down mandates towards centrally delivered services that departments and frontline teams are more likely to adopt. Breandán Knowlton-Hung, Deputy CISO at the UK Civil Service, said the shift followed a 2025 National Audit Office (NAO) report which found that, three years after the 2022 National Cyber Security Strategy, there was “no proper implementation plan” and no way to determine whether it was working.

The challenge is amplified by the civil service’s federated structure, comprising roughly 465 ministries, agencies and other public bodies with their own budgets, systems and leaders. The NAO also highlighted capacity constraints: one in three cyber roles were vacant or occupied by temporary contractors, while most specialist architects were not permanent.

Knowlton-Hung said the new “polycentric governance” model will build useful shared services, make adoption easier than non-adoption and retain strong central authority for systemic risks. A central vulnerability monitoring service already scans thousands of public-sector organisations for about 1,000 categories of externally visible weaknesses and sends actionable alerts to relevant owners.

According to Knowlton-Hung, the service reduced the median time to fix domain-level vulnerabilities from about 50 days to eight, despite relying on local teams rather than mandates. He added that assurance scores are improving year on year, but not quickly enough to match the threat, and that an action plan is being added to accelerate progress.

View full article

Article by CyberSIXT