74% of UK businesses reported a cyber incident in 2026, according to the DSIT Breaches Survey. The public sector figure is higher. The incidents are, on average, more severe. None of this is contested: the NCSC has said it, the NAO has documented it, the Public Accounts Committee has published it.
The question worth asking is not whether the gap exists. It’s whether the conditions that created it are changing fast enough to matter.
They are not.
Why the Gap Is Structural, Not Accidental
The instinct in Whitehall when these reports land is to reach for governance solutions: a new framework, a clearer accountability structure, a programme with a catchy name. The diagnosis is wrong. The public sector’s security posture is not primarily a function of intent or awareness. Most SROs and IT leads in central government have a reasonable working knowledge of the threat picture. The problem is structural, and it operates across several compounding dimensions at once.
Start with the fragmented estate. The UK public sector doesn’t have a unified IT infrastructure; it has hundreds of separate ones. Departments, agencies, NHS trusts, local councils, police forces: each with its own procurement cycle, its own legacy systems, its own managed service relationships, and its own IT refresh cadence. The average NHS trust still runs systems that were already ageing when WannaCry struck in 2017. Some councils are managing security on budgets that haven’t materially moved since austerity.
NCSC’s Active Cyber Defence programme does real work here: DNS filtering, mail check, web check services across government genuinely reduce commodity threat exposure. But it works at the network perimeter. It doesn’t fix unpatched PLCs, weak privileged access management, or the simple absence of endpoint detection capability in most local government environments. Those problems require estate-level investment that ACE cannot substitute for.
Then there’s procurement. Government IT buying is, structurally, optimised for capital cost: value for money as defined in a business case template. Security capabilities that resist easy quantification (detection and response capability, threat intelligence, genuine SOC services) lose procurement evaluations against cheaper proposals routinely. The consequences compound: the department that chose the cheaper managed service five years ago is now dealing with a supplier that has no contractual incident notification obligation, inadequate monitoring, and enough leverage in the renewal negotiation to make security terms commercially inconvenient to revisit.
The talent situation is the third leg of this. A senior SOC analyst or threat intelligence lead at a government department earns materially less than the same person at a large bank or major consultancy. Entry-level analysts cycle through on two-year stints on their way to better-compensated private sector roles. Specialist skills (OT security, threat intelligence analysis, complex incident response) get contracted in rather than built. When the contract ends, the institutional knowledge walks out with it.
GovAssure Is Better Than Nothing. That’s the Bar It Clears.
The Cabinet Office’s GovAssure programme requires central government departments to self-assess against the NCSC’s Cyber Assessment Framework and have those assessments reviewed. It’s a genuine improvement on what came before, which was essentially no systematic assurance at all.
The scope limitations are significant. GovAssure covers central government departments and their immediate arm’s-length bodies. It doesn’t cover local government (43 million people interact with council services), most NHS trusts, or the extended government IT supply chain. Pre-positioning activity in Tier 2 supplier networks sits almost entirely outside GovAssure’s remit.
The self-assessment model also has obvious limitations. Organisations that understate their cyber risk in other contexts will understate it in a compliance framework. The review process catches some of this; it doesn’t catch all of it.
The Bill Gets Passed. The Threat Moves On.
The Cyber Security and Resilience Bill is the most significant legislative development in this space for several years. Mandatory incident reporting extended. NIS Regulations expanded to cover more digital infrastructure providers. Enhanced enforcement powers for regulators. The supply chain provisions are particularly consequential: in practice, many government IT suppliers will enter a formal reporting and assurance regime for the first time.
It’s welcome legislation. The timing problem is real, though. The threat landscape when this Bill is fully in force will not look like the threat landscape that motivated its drafting. Legislative timelines in cyber security have historically lagged threat evolution by years. The gap between when a framework is designed and when it’s operationally effective is exactly the window adversaries work in.
Where Things Are Actually Improving
Not everything is static. The NCSC has grown substantially in capability since 2016. GovCERT is more capable. Information sharing across the public sector has improved, particularly in the NHS, which absorbed the WannaCry lesson in ways that some other sectors haven’t. The Government Security Group is more explicit about risk assessments than its predecessors were.
At the departmental level, the most critical environments have held their investment. MoD, GCHQ, and the intelligence community have maintained genuine capability. HMRC and DWP, which between them hold citizen financial and benefits data at enormous scale, have invested heavily. DSIT and the Cabinet Office have credible teams.
The deficit is concentrated where it’s hardest to fix: local government, smaller NHS trusts, the extended supply chain, and the many arm’s-length bodies that combine meaningful IT estates, high data sensitivity, and security investment that is a fraction of what the exposure warrants.
The Honest Position
The gap between the public sector’s security posture and the threat it faces isn’t primarily a political failure. It’s the structural consequence of building public IT over decades under cost pressure, with security treated as overhead, now meeting a threat environment that has become dramatically more capable faster than any reform programme can match.
The policy response is correct. It is slow. And the threat does not wait.
The realistic near-term objective isn’t parity with private sector investment levels, and it isn’t eliminating the legacy estate before the next significant incident. It’s identifying the highest-risk concentrations (the environments that sophisticated actors are most likely to target for the most consequential outcomes) and treating them differently from the baseline. That requires honest risk assessment and the political willingness to act on the answer when it’s inconvenient.