Skip to Main Content

Want to stay up-to-date with the latest IT news?
Subscribe to our mailing list to hear the latest news, events, free resources, and more for your industry.

Sign up now
Blog

Are we winning against cyber crime in the UK public sector?

3 minute read

Fred Astfeldt

January 22nd, 2026

Are we winning against cyber crime in the UK public sector?

3 minute read

Fred Astfeldt

January 22nd, 2026

Cyber crime is no longer a distant threat, it’s a daily reality for the UK public sector. From local councils to NHS trusts and central government departments, attacks are becoming more frequent, more sophisticated, and more disruptive. The question is: with all the investment, strategies, and awareness campaigns, are we actually winning this fight?

The current landscape

The scale of the challenge is sobering. According to the UK Government’s Cyber Security Breaches Survey 2024, half of businesses and around a third of charities reported a cyber breach or attack in the past year, with phishing being the most common vector. Public sector organisations, which hold vast amounts of sensitive data and deliver critical services, are prime targets for ransomware, phishing, and supply chain attacks.  

Recent incidents underline the stakes. In June 2024, a ransomware attack on Synnovis, a pathology supplier, forced NHS trusts in London to cancel over 10,000 outpatient appointments and 1,700 elective procedures, while attackers leaked nearly 400GB of sensitive patient data online. The British Library attack in late 2023 disrupted services for months and cost hundreds of thousands of pounds to remediate.  

These aren’t isolated cases. The National Cyber Security Centre (NCSC) managed over 200 nationally significant incidents in the past year, a 50% increase on the previous year, including 18 categorised as highly significant. Clearly, the threat is escalating.  

What’s been done so far?

The UK hasn’t been idle. The Government Cyber Security Strategy 2022–2030 set out an ambitious vision to build a cyber-resilient public sector, backed by initiatives like GovAssure (an independent cyber assurance scheme) and guidance from the NCSC. The National Cyber Strategy also aims to strengthen the UK’s cyber ecosystem, improve skills, and foster collaboration across government, industry, and academia.  

Progress has been made. The NCSC’s Active Cyber Defence programme blocked billions of phishing attempts and removed thousands of malicious websites last year, helping organisations prevent attacks at scale. There’s also a legislative push: the proposed Cyber Security and Resilience Bill will tighten requirements for managed service providers and critical suppliers, introduce tougher reporting rules, and impose significant penalties for non-compliance.  

These steps matter. They show a commitment to improving resilience and closing gaps in regulation. But are they enough? 

The challenges we still face

Despite progress, major obstacles remain: 

These challenges mean that while we’re improving, the gap between threat and defence remains significant. 

So, are we winning?

In short: we’re holding the line, but we’re not winning yet. 

There are clear successes: better awareness, improved incident response, and stronger frameworks. But the reality is that attacks are increasing in volume and impact. The Cabinet Office has already admitted it will miss its target for government to be cyber-resilient by the end of 2025, and helping the wider public sector achieve resilience by 2030 will require a fundamentally different approach.  

Winning against cyber crime isn’t a one-off achievement; it’s a continuous battle. Right now, we’re in a stalemate progressing, but not fast enough. 

What needs to happen next?

To tip the balance, the UK public sector must: 

  • Accelerate digital transformation with security built in from the start 
  • Invest in skills, not just recruitment, but training and retention 
  • Adopt proactive measures like threat intelligence, monitoring zero trust architecture, and rigorous supply chain security 
  • Strengthen collaboration between sectors 
  • Embed resilience as a design principle, not an afterthought 

Cyber crime is advancing faster than regulation. Without decisive action, the financial, operational, and social costs will continue to escalate. 

Find out more

The UK public sector has made strides, but the battle is far from over. The question isn’t just whether we’re winning, it’s whether we’re ready to fight harder.

If you’re a public sector leader, review your cyber strategy today.

Image of a smiling IT support professional talking on a headset
Fred Astfeldt headshot

About the author

Fred Astfeldt, Head of Managed Security Solutions.

Fred has over 12 years’ experience working in network security and managed services having held roles in a number of leading global organisations.

Fred’s roles were initially in account management and pre-sales before moving to leaderships roles within business management, service management, and SOC management, where he managed the delivery of Managed Security Services for customers.

Connect with Fred on LinkedIn.