What happened

The UK Civil Service is changing how it governs cyber security across government, moving away from top down mandates and toward centrally built services that departments choose to use. Breandán Knowlton-Hung, Deputy CISO at the UK Civil Service, set out the shift at the Gartner Security and Risk Management Summit in London on September 23.

The rethink was forced by a 2025 National Audit Office report. Three years into the 2022 National Cyber Security Strategy and its "defend as one" vision, the audit found no proper implementation plan and no way to tell whether any of it was working. The reality that strategy had to cover is roughly 465 separate entities, each with its own leadership, budget and systems.

Capacity was the second finding. One in three cyber roles were vacant or filled by temporary contractors, and a large majority of specialist architects were not permanent staff. Knowlton-Hung described the practical effect plainly: a mandate is permission to direct, not the ability to make change happen, and issuing more of them does not help when nobody is there to pick them up.

The replacement model is what he calls polycentric governance, with several overlapping centres of decision making that coordinate rather than obey a single hierarchy. Three actions define it: build centrally delivered services that solve real problems, make adoption socially and operationally cheaper than non adoption, and keep hard central authority for a small set of systemic risks where one failure harms everyone.

One working example is a central vulnerability monitoring service that continually scans thousands of public sector organisations for roughly a thousand classes of externally visible weaknesses, then routes actionable notifications to the right owners. Median time to fix domain level vulnerabilities fell from about 50 days to eight. Knowlton-Hung said those fixes were not ordered. Local teams owned and carried them out because the service helped them.

Why this is a GRC story

Assurance is not the same as outcome. The NAO finding is the classic failure mode of a controls programme: standards were issued, assurance was collected, and the strategy still could not show it had changed anything. Any organisation that reports compliance without evidence of effect is carrying the same risk.

Federated structures break directive governance. Government is an extreme case at 465 entities, but a group that grew by acquisition looks the same. Local leaders own budgets and competing risks, so a central team that can only write policy has no levers left once people do not act.

Capability is a control. One in three vacant roles and a contract heavy architecture is a resourcing failure that becomes a security failure. Workforce planning belongs inside the risk register, not beside it.

What to watch

Watch whether the new operating model moves the assurance scores that are still improving too slowly, and whether the action plan layered on top produces measurable change rather than another set of commitments. The harder test is whether central services stay voluntary in practice or quietly become mandates with better branding.

The practical takeaway for a security or compliance function inside a large or fragmented organisation: before writing the next policy, check who would actually carry it out, whether they have the capacity, and what would make doing it easier than not doing it.

Attribution: Analysis based on Infosecurity Magazine and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News