Why cyber must remain at the heart of government

UK prime minister Andy Burnham outside No 10 Downing StreetJust days after becoming Prime Minister, Andy Burnham has begun a significant reshaping of Whitehall. In his first speech outside Downing Street on 20 July, Burnham reflected on becoming the seventh Prime Minister since 2016, acknowledging public frustration with political instability and arguing that the UK needs to regain confidence in government and long-term national direction.

As part of that agenda, one of the first major structural changes has been the decision to abolish the Department for Science, Innovation and Technology (DSIT).

 

The move forms part of a wider Whitehall restructuring which will see DSIT’s responsibilities divided between a strengthened Department of Digital, Culture, Media and Sport (DCMS) – renamed to include digital – the Cabinet Office and the newly created Department for Business, Innovation, Science and Trade.

The decision has prompted concern and debate across the technology sector.

For those working across cyber security, technology and digital transformation, the announcement immediately prompts an important question: what does this mean for the future of cyber security in the UK?

The answer remains uncertain. What is certain is that cyber security cannot afford to lose prominence at a time when the UK’s threat landscape continues to evolve at pace.

In the same week as we welcomed a new Prime Minister, we also saw the sentencing of two individuals associated with the Scattered Spider cybercrime group for their role in the 2024 cyber attack against Transport for London. The attack disrupted services used by millions of people, exposed sensitive data and generated recovery costs running into tens of millions of pounds. It has been described as one of the largest cybercrime prosecutions ever brought before the UK courts.

The timing is a useful reminder, if we even needed one, that cyber security remains a matter of national resilience. While government departments may change, the threats facing organisations across public and private sectors continue to grow in scale and sophistication.

Under the new arrangements, many of DSIT’s digital responsibilities will move into a strengthened Department for Digital, Culture and Media Sport (DCMS), while responsibility for AI strategy, public sector AI adoption and the AI Security Institute will transfer to the Cabinet Office. Importantly, the government has also created a dedicated Minister for Artificial Intelligence, Kanishka Narayan, who will attend Cabinet. While DSIT may be disappearing, AI has arguably been elevated closer to the centre of government than ever before.

There are potential advantages to this approach.

Digital policy increasingly overlaps with online safety, information resilience, communications, media and public services. Bringing these areas together within a strengthened DCMS may create opportunities for greater coordination. Similarly, placing AI policy at the heart of government recognises its growing importance to economic growth, public sector transformation and national competitiveness. Few would argue that AI should not receive close ministerial attention.

However, there are also legitimate concerns.

DSIT may have been a relatively young department, but it provided a clear focal point for technology, digital transformation and cyber-related engagement. Stakeholders knew where leadership sat. With responsibilities now distributed across DCMS, the Cabinet Office and the newly renamed Department for Business, Innovation, Science and Trade, there is a risk that accountability becomes less clear and that cyber security competes for attention among a broader range of policy priorities.

The key question is not whether government structures should evolve. They inevitably will. The more important question is whether cyber security continues to retain a strong and visible voice at the centre of government.

Whether cyber sits in one department or several, the UK still requires a coherent approach to cyber skills, professional standards and workforce development if it is to meet growing demand and strengthen resilience.

As cyber security continues to mature as a profession, recognised standards, professional accreditation and ongoing development become increasingly important. Other professions entrusted with public safety and economic wellbeing have long-established frameworks for assuring competence and professionalism. Cyber security is following the same path, and the pace of technological change makes that journey more important than ever.

Whether responsibility sits within DCMS, the Cabinet Office or elsewhere, success will be measured not by departmental structures but by outcomes: stronger resilience, better capability, increased public trust and a workforce equipped to meet the cyber challenges of the future.

For CIISec, the mission remains unchanged. Professionalising the cyber security profession, supporting career development, accrediting competence, advancing capability and helping organisations build trusted cyber expertise are all essential contributions to UK cyber resilience.

The structures may change. The need for skilled professionals, strong standards and sustained investment in cyber capability has never been greater

Share this Article
Facebook
X
LinkedIn
WhatsApp
Telegram
Email

Other Relevant Articles

The 7 Cs of Resilience: What tech leaders can learn from psychology
The Risk Nobody Accepted – How governance decisions in one domain silently transfer exposure into another

Board of Directors

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.