Government approach to cyber security ‘dysfunctional’

Image

The government’s approach to handling public sector data breaches is ‘inconsistent and dysfunctional’ and it should do more to consolidate an ‘alphabet soup’ of agencies involved in the fight against cybercrime, according to a report from the public accounts committee (PAC)

PAC says as recently as April 2016, there were still at least 12 separate teams or organisations in the centre of government with a role in protecting information, creating several lines of accountability with little coherence between them.

The Cabinet Office has since amalgamated many of these bodies into the National Cyber Security Centre (NCSC), designed to act as a bridge between industry and government, providing a unified source of advice, guidance and support on cyber security, including the management of cyber security incidents; and the Cabinet Office’s cyber and government security directorate, responsible for all aspects of government protective security.

The report says the breadth of the NCSC’s role is considerable and it is still unclear which organisations from across the public and private sectors can call on the NCSC for assistance. PAC recommends that the Cabinet Office should develop a detailed plan for the NCSC by the end of this financial year, setting out who it will support, what assistance it will provide and how it will communicate with organisations needing its assistance. It also wants more explicit advice for delivery partner and individual users of government websites about cyber risks.

PAC says the Cabinet Office’s ability to make informed information security decisions is undermined by what it calls ‘inconsistent and chaotic’ processes for recording personal data breaches, coupled with poor monitoring of the costs and performance of individual departments’ efforts to protect information.

The inquiry found ‘major and unexplained’ variations in the extent to which individual departments report security breaches. In 2014–15, the 17 largest departments recorded a total of 14 data incidents that they considered reportable to the Information Commissioner’s Office, and recorded 8,981 non-reportable incidents.

Of the 8,981 total, HMRC recorded 6,038 (67%) and the Ministry of Justice 2,798 (31%). The other 15 departments recorded only 145 between them, fewer than 2% of the total. Several departments recorded no non-reportable incidents at all, including the Department for Work and Pensions, a large department with a comparable level of online activity to HMRC, PAC pointed out.

In addition, centrally managed government information projects are not yet delivering as planned. PAC points out that the Government Security Classifications (GSC) system (a three-point system to classify information consistently across government) was not subjected to a detailed financial business case before the project began, although it was initially forecast to deliver between £110m to £150m million annually in benefits. The department concerned did not have confidence in these figures and consequently has not had a baseline against which to judge whether the GSC has produced any financial benefits.

The Cabinet Office is planning to amalgamate 40 separate departmental security teams into four larger clusters, and has established the first pilot cluster, to better enable the sharing of scarce skills across central government, but PAC also warns the government is struggling to ensure its security profession is suitably skilled.

Meg Hillier, chair of the PAC, said: ‘Government has a vital role to play in cyber security across society but it needs to raise its game.

Its approach to handling personal data breaches has been chaotic and does not inspire confidence in its ability to take swift, coordinated and effective action in the face of higher-threat attacks.

Leadership from the centre is inadequate and, while the National Cyber Security Centre has the potential to address this, practical aspects of its role must be clarified quickly.’

Michael Izza, ICAEW chief executive, said PAC’s report ‘makes frightening reading’ as it highlighted a major problem with under-reporting of data breaches and other cyber crime incidents.

‘What Britain needs is a single, senior person charged with leading the UK’s fight against cyber-crime and clarity of responsibility within government to end the “alphabet soup” of agencies the report mentions. The role of the National Cyber Security Centre needs to be confirmed, including responsibilities and funding.

‘In addition, what we need is a “cyber safe space” enabling people to disclose security breaches, attacks and other intelligence with peers without fear of consequences. Where victims are not sharing their experience, it means criminals can use the same methods again and again and so responses cannot be developed.’ Izza said.

PAC’s report, Protecting information across government, is here.

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe