NAO urges Cabinet Office to coordinate Whitehall data security efforts

Written by Matt Foster and Rebecca Hill on 14 September 2016 in News
News

The government is failing to properly address data protection, with almost 9,000 breaches recorded in 2014-15, a report from the National Audit Office has said.

Cabinet Office needs to coordinate data protection across Whitehall - Photo credit: Fotolia

The report published today, said that the Cabinet Office needed to make it much easier for departments to carry out the “critical” task of protecting their information from unauthorised access or loss.

The NAO said that the Cabinet Office "has not yet established a clear role for itself in coordinating and leading departments’ efforts to protect their information".

It added that efforts to track performance are being hindered by patchy data and too many bodies with "overlapping responsibilities".

A further issue raised in the report is a lack of clarity on the money spent on security. The NAO said that the Cabinet Office had collected data on the annual spend on security in 34 departments that suggested it was £300m – but that it also believed the actual costs are “several times” that figure.


Related content

Whitehall 'not cool enough' to attract top cyber security talent
Are we entering a 'cognitive era'?


The NAO said that the 17 biggest government departments recorded 8,995 data breaches in 2014-15. In addition, the UK government’s security arm GCHQ dealt with an average of 200 cyber-related national security incidents a month in 2015 – twice as many as in 2014.

The watchdog said that there were “at least” 12 separate teams in the centre of government with a role in safeguarding information, with the governance arrangements above them "unclear and fragmented", and "no formal links" between the main players.

The NAO said that while the new National Cyber Security Centre – which launches next month to take the lead on shielding government networks from cyber-attack – will help pool "much of government’s cyber expertise", a more wide-ranging shake-up is needed "to further enhance the protection of information".

"The NCSC should streamline central government processes for dealing with information incidents in cyberspace," the report said.

"However, the scale and pace of the challenges of protecting information are such that these structural changes are unlikely to be sufficient on their own unless Cabinet Office also supports departments in addressing the wider problems set out in this report. "

It added: "The NCSC is designed to work with government and the private sector: whether it has the capacity to do so effectively remains to be seen."

Among its findings, the NAO said that departments have tended to treat information governance as a lower-order priority, and noted out that the Cabinet Office "does not provide a single set of governance standards for departments to follow, and does not collate or act upon identified weaknesses".

"Only a few departments set security standards through their supply chain," it added.

Meanwhile, the report said the Cabinet Office does not have access to "robust expenditure and benefits data" from departments that would allow the centre of government to take "informed strategic decisions on protecting information".

And the watchdog said that, despite the creation of a dedicated civil service security profession in 2013, it remains "difficult for government to attract people with the right skills "to take on key cyber security roles.

That finding echoes comments made this week by a recruiter for the Ministry of Justice, who said people with cyber security skills "still don’t think working for government is cool".

Departments were, the recruiter said in GOV.UK blogpost, still working to shake off the perception that government tech jobs meant working against "a massive legacy monolithic monster" and "trying to troubleshoot memory issues in a some mid-90s middleware".

The NAO said demand for such skills across government was "growing and is likely to continue to grow".

"Plans to cluster security teams may initially share scarce skills but will not solve the long-term challenge, and will pose questions for departmental accountability," the watchdog's report added.

Launching the NAO's latest findings, the audit office's head Amyas Morse said: “Protecting information while re-designing public services and introducing the technology necessary to support them is an increasingly complex challenge.

"To achieve this, the Cabinet Office, departments and the wider public sector need a new approach, in which the centre of government provides clear principles and guidance and departments increase their capacity to make informed decisions about the risks involved.”

Share this page

Tags

CONTRIBUTIONS FROM READERS

Please login to post a comment or register for a free account.

Related Articles

ICO urges Capita customers to ‘check their position’ after 90 organisations report data breaches
31 May 2023

Technology services firm has revealed two data-compromising incidents in recent week

 

MoJ reprimanded by ICO after ‘bags of confidential documents’ exposed for over two weeks
25 May 2023

Sensitive data was left unsecured in prison holding area, according to data watchdog

Interview: CDDO chief Lee Devlin on the ‘move from being disruptive to collaborative’
23 May 2023

In the first of a series of exclusive interviews, the head of government’s ‘Digital HQ’ talks to PublicTechnology about the Central Digital and Data Office’s work to unlock £8bn...

Rochford District Council pins data breach on Capita’s ‘unsafe storage’
17 May 2023

Authority claims it is taking ‘swift and decisive action’ in response to incident it claims affected several councils

Related Sponsored Articles

Proactive defence: A new take on cyber security
16 May 2023

The traditional reactive approach to cybersecurity, which involves responding to attacks after they have occurred, is no longer sufficient. Murielle Gonzalez reports on a webinar looking at...