Question
To ask the Secretary of State for Digital, Culture, Media and Sport, with reference to the National Audit Office's report entitled Government cyber resilience, published on 29 January 2025, how many of the critical IT systems with significant gaps in government cyber resilience have since been reassessed.
The critical systems referenced in the National Audit Office report were assessed by GovAssure – Government's cyber assurance programme. Of the 72 assessed systems referenced in the report, 18 have been reassessed since publication.
GovAssure requires organisations to scope and assess their critical IT systems on an annual basis in tranches, prioritising Critical National Infrastructure systems first. Once assessed, organisations will work through Targeted Improvement Plans, so systems may not be immediately reassessed the following year whilst remediation is ongoing.
Government has acknowledged that it faces significant cyber security and resilience risks and has set out its wider package of measures to tackling these through the Government Cyber Action Plan, published in January 2026 and backed by over £210 million.