Copy article

New cyber action plan to tackle threats and strengthen public services

ended 06. January 2026

Backed by over £210 million, the Government Cyber Action Plan published today sets out how government will rise to meet the growing range of online threats. 

Driven by a new Government Cyber Unit, the govertnment says the plan will rapidly improve cyber defences and digital resilience across government departments and the wider public sector, so people can trust that their data and services are protected.  

It underpins UK Government plans to digitise public services. This will make more services accessible online, reduce time spent on phone queues and paperwork, and enable citizens to access support without repeating information across multiple departments. This approach could unlock up to £45 billion (note) in productivity savings by using technology effectively across the public sector. 

However, realising these benefits depends on trust. As services move online, they must be secure and resilient. Cyber attacks can take vital public services offline in minutes, disrupting lives and undermining confidence. The new plan addresses this challenge head-on. 

Released as the Cyber Security and Resilience Bill has its Second Reading in the House of Commons, the Bill sets out clear expectations for firms providing services to government to boost their cyber resilience. From energy and water suppliers to healthcare and data centres, strong defences throughout supply chains will help keep the water running and the lights burning - facing down the cyber attackers who want to grind our country to a halt.   

The plan will lead to: 

  • clearer visibility of risks: shining a light on cyber and digital resilience risks across government, so we can focus efforts where it matters most
  • stronger central action on the toughest challenges: taking decisive, joined-up action across departments on severe and complex risks that no single organisation can solve alone with a dedicated team overseeing coordination
  • faster response to threats and incidents: reacting quickly to fast-moving cyber threats and vulnerabilities to minimise harm and speed up recovery by requiring departments to have robust incident response arrangements in place
  • higher resilience across government: boosting resilience at scale, with targeted measures to close major gaps and protect critical services

Digital Government Minister Ian Murray said: “Cyber-attacks can take vital public services offline in minutes – disrupting our digital services and our very way of life. This plan sets a new bar to bolster the defences of our public sector, putting cyber-criminals on warning that we are going further and faster to protect the UK’s businesses and public services alike. This is how we keep people safe, services running, and build a government the public can trust in the digital age.”

3 responses from the Newspage community

Copy all

Copy

£210 million sounds impressive, but how much of it is funding people, especially at entry level?

Across cybersecurity, like many other industries, we’re quietly replacing junior roles with AI and automation. As an AI strategist, I welcome AI as an assistant. But when it replaces people, it chokes the talent pipeline. Entry-level cyber roles used to be the training ground where judgement was formed. That’s how we grew mid-level professionals.

Mid-level cyber is not technical work. It’s decision work. It’s interpreting AI outputs, making risk trade-offs under uncertainty and, crucially, explaining impact to non-technical leaders. These are precisely the things AI struggles with, and humans are essential for.

If we automate the bottom of the ladder for short-term savings, we shouldn’t be surprised when there’s no one standing in the middle to save us from complex cyber threats.
Copy

£210m sounds impressive until you remember the Jaguar Land Rover hack cost 0.5% of GDP. That's the real benchmark here. Not whether we have a plan, but whether this plan can actually plug holes faster than an army of attackers find them.

The Government Cyber Unit is operating within a sprawling patchwork of national and international suppliers, contractors, and legacy systems holding up every digital service. You can't secure a leaky bucket by pouring in more money if you haven't mapped and patched every crack first. Even with perfect visibility, no security protocol ever stops humans being phished or going rogue.

Are we funding resilience that scales with threat evolution, or are we building yesterday's defences for tomorrow's attacks?

Digitising services only works if the infrastructure underneath can handle pressure, not just from hackers, but from the humans already inside the system.

Trust isn't built with announcements. It's earned when systems hold under repeated fire.
Copy

The government is dangling a dazzling £45bn in ‘productivity savings’ while throwing pocket change at the security required to protect it. This is classic ‘boardroom fantasy’ maths: executives get addicted to the efficiency numbers on a spreadsheet but refuse to pay for the concrete foundation needed to support them.

In my experience, you cannot automate your way out of structural inefficiency. Digitising a bad manual process doesn't fix it, it just means you get bad results at light speed, now with added cyber risk.

If this new Cyber Unit is just another layer of bureaucracy ticking boxes, it will fail. We need to stop selling digitisation as a magical cost-cutting exercise and start treating it as critical infrastructure. Security isn't a feature you bolt on later to save money; it’s the cost of doing business. Don't confuse a press release with protection.