Government Departments: Digital Service Providers

(asked on 13th July 2026) - View Source

Question to the Department for Science, Innovation & Technology:

To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the potential operational and national-security risks arising from government departments deploying a small number of cloud-service providers.


Answered by
Kanishka Narayan Portrait
Kanishka Narayan
Minister of State (Cabinet Office) (Jointly with the Department for Business, Innovation, Science and Technology)
This question was answered on 20th July 2026

The State of Digital Government Review, published in January 2025, highlighted that concentrating workloads on a limited number of suppliers creates systemic concentration risks. The National Risk Register 2026, published on 14 July, further identifies disruption to third-party suppliers and digital infrastructure as a significant resilience risk.

Existing Government cyber policy and technology frameworks already support a range of resilience measures to tackle this, by requiring departments to assess security, resilience and business continuity risks when procuring and operating cloud.

The Government's Cloud First policy encourages organisations to consider all suitable suppliers and supports competition in cloud procurement, while the Multi‑Region Cloud Policy promotes deployment across multiple regions to improve resilience. Public procurement seeks to maintain a diverse supplier base, while the Competition and Markets Authority is independently examining competition in the UK cloud market.

Alongside this, Government is tackling these risks through the implementation of the Government Cyber Action Plan, which sets out our approach to enhancing cyber security and resilience across the public sector, including through enhanced cyber assurance and oversight.

Reticulating Splines