Infosecurity Magazine iconInfosecurity MagazineSep 24, 2026 ~5 min source read

UK government abandons top-down cyber mandates for service-led governance after critical NAO audit

Whitehall will shift from issuing mandatory controls to building centrally delivered cyber services that local teams adopt, prompted by a 2025 National Audit Office finding that the 2022 strategy lacked an implementation plan and capacity to deliver.

Share this story

Send the public story page.

Useful takeaways from this story.

A 2025 NAO audit found the 2022 National Cyber Security Strategy had no proper implementation plan and no way to measure effectiveness, prompting a governance rethink.

The civil service is moving to a ‘polycentric governance’ model: build centrally run services that local teams find useful, make adoption cheaper than non-adoption, and reserve central authority for systemic risks.

Capacity shortages — one in three cyber roles vacant or filled by contractors, and few permanent specialist architects — undermined the previous mandate-based approach.

# What changed and why The UK civil service is changing how it governs cybersecurity. A National Audit Office (NAO) report in 2025 concluded the 2022 National Cyber Security Strategy lacked a proper implementation plan and had no way to tell whether it was working. That audit, plus evidence of severe staffing shortages, forced a rethink of a model that relied largely on issuing standards and asking departments to comply.

# From mandate to service The old approach treated mandates and assurance as the main lever: central teams set standards and expected the roughly 465 bodies across government to implement them. In practice, those organisations have their own leaders, budgets and competing risks. The central office discovered that "a mandate is permission to direct. It isn't the ability to make change happen," and that many teams simply could not carry the load because of budgets, systems or capacity.

# The new operating model: polycentric governance Deputy CISO Breandán Knowlton-Hung describes the replacement as "polycentric governance." The model has three concrete moves:

  • Build useful, centrally delivered services that solve real problems for the hundreds of operational teams.
  • Make adoption socially and operationally cheaper than non-adoption.
  • Reserve hard central authority for a small set of systemic risks where one failure harms everyone.

Knowlton-Hung summarized the approach: "Own fewer things centrally, but own them harder. Everywhere else, be unmissably useful."

# How services change behaviour

# Capacity and assurance remain challenges The NAO audit also exposed capacity problems: one in three cyber roles were vacant or staffed by temporary contractors, and most specialist architects were not permanent. That meant many departments lacked the hands to act on mandates or complex changes. Knowlton-Hung noted assurance scores are improving year over year but still not fast enough relative to threat activity. He said the government is layering an action plan on the new operating model to accelerate impact.

# Practical guidance embedded in the shift The central theme of the change is pragmatic: stop relying on memos and mandates and instead build tools and services that people want to use. The central government retains policy direction and will intervene on shared systemic risks, but it will focus its direct control on a narrower set of outcomes while making adoption of central services the easier operational choice for local teams.

# What to watch next Expect the government to continue expanding central services (monitoring, notification, integration with local workflows) and to focus investment on permanent specialist capacity. Progress metrics will be whether central services reduce time-to-remediate and whether assurance scores accelerate as adoption grows.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app