Are we winning against cyber crime in the UK public sector?
3 minute read
Fred Astfeldt
January 22nd, 2026
Cyber crime is no longer a distant threat, it’s a daily reality for the UK public sector. From local councils to NHS trusts and central government departments, attacks are becoming more frequent, more sophisticated, and more disruptive. The question is: with all the investment, strategies, and awareness campaigns, are we actually winning this fight?
The current landscape
The scale of the challenge is sobering. According to the UK Government’s Cyber Security Breaches Survey 2024, half of businesses and around a third of charities reported a cyber breach or attack in the past year, with phishing being the most common vector. Public sector organisations, which hold vast amounts of sensitive data and deliver critical services, are prime targets for ransomware, phishing, and supply chain attacks.
Recent incidents underline the stakes. In June 2024, a ransomware attack on Synnovis, a pathology supplier, forced NHS trusts in London to cancel over 10,000 outpatient appointments and 1,700 elective procedures, while attackers leaked nearly 400GB of sensitive patient data online. The British Library attack in late 2023 disrupted services for months and cost hundreds of thousands of pounds to remediate.
These aren’t isolated cases. The National Cyber Security Centre (NCSC) managed over 200 nationally significant incidents in the past year, a 50% increase on the previous year, including 18 categorised as highly significant. Clearly, the threat is escalating.
What’s been done so far?
The UK hasn’t been idle. The Government Cyber Security Strategy 2022–2030 set out an ambitious vision to build a cyber-resilient public sector, backed by initiatives like GovAssure (an independent cyber assurance scheme) and guidance from the NCSC. The National Cyber Strategy also aims to strengthen the UK’s cyber ecosystem, improve skills, and foster collaboration across government, industry, and academia.
Progress has been made. The NCSC’s Active Cyber Defence programme blocked billions of phishing attempts and removed thousands of malicious websites last year, helping organisations prevent attacks at scale. There’s also a legislative push: the proposed Cyber Security and Resilience Bill will tighten requirements for managed service providers and critical suppliers, introduce tougher reporting rules, and impose significant penalties for non-compliance.
These steps matter. They show a commitment to improving resilience and closing gaps in regulation. But are they enough?
The challenges we still face
Despite progress, major obstacles remain:
- Legacy systems: around 28% of the public sector’s IT estate is made up of legacy systems, many of which haven’t undergone independent security assessments. These outdated platforms are a hacker’s dream
- Skills shortage: one in three cyber security roles in government are vacant or filled by temporary staff. Some departments report over 50% vacancy rates for specialist roles. Without skilled people, even the best strategies lose strength or momentum
- Budget pressures: cyber security competes with other priorities, and investment often lags behind the threat
- Evolving threats: nation-state actors and organised crime groups are deploying increasingly sophisticated tactics, including AI-driven exploits and supply chain compromises
These challenges mean that while we’re improving, the gap between threat and defence remains significant.
So, are we winning?
In short: we’re holding the line, but we’re not winning yet.
There are clear successes: better awareness, improved incident response, and stronger frameworks. But the reality is that attacks are increasing in volume and impact. The Cabinet Office has already admitted it will miss its target for government to be cyber-resilient by the end of 2025, and helping the wider public sector achieve resilience by 2030 will require a fundamentally different approach.
Winning against cyber crime isn’t a one-off achievement; it’s a continuous battle. Right now, we’re in a stalemate progressing, but not fast enough.
What needs to happen next?
To tip the balance, the UK public sector must:
- Accelerate digital transformation with security built in from the start
- Invest in skills, not just recruitment, but training and retention
- Adopt proactive measures like threat intelligence, monitoring zero trust architecture, and rigorous supply chain security
- Strengthen collaboration between sectors
- Embed resilience as a design principle, not an afterthought
Cyber crime is advancing faster than regulation. Without decisive action, the financial, operational, and social costs will continue to escalate.
Find out more
The UK public sector has made strides, but the battle is far from over. The question isn’t just whether we’re winning, it’s whether we’re ready to fight harder.
If you’re a public sector leader, review your cyber strategy today.

