NAO report highlights severe cyber-threats to UK government

30 January 2025

The National Audit Office (NAO) is anticipated to release a report highlighting severe and rapidly evolving cyber threats faced by the UK government, necessitating immediate protective measures for critical operations and public services.

The report is expected to reveal that 58 critical government IT systems, independently assessed in 2024, had significant deficiencies in their cyber resilience. There is a lack of knowledge regarding the vulnerability of 228 legacy IT systems. These findings underscore a pressing need for improvement in cyber resilience.

"The NAO report is a timely reminder and warning for UK enterprises to double down on their cybersecurity posture, given the rise in the sophistication, frequency and scope of cyberattacks against the UK. This exposure will not change since the UK has an open information society and is home to enterprises that hold vast financial wealth and lucrative strategic information,” said Megha Kumar, Chief Product Officer at CyXcel. "The recent UK government proposal to ban ransomware payments, if enacted, would remove one of the tools that UK businesses frequently rely on: they take insurance cover which covers potential ransom payments and then become complacent about ways to mitigate cyber risks proactively. However, this proposal would oblige enterprises to shift from reactive to proactive cybersecurity, which is a necessary step so businesses should prepare now."