Home TECHNOLOGY Security Britain’s Councils Are Fighting a Cyber War With One Hand Tied Behind...

Britain’s Councils Are Fighting a Cyber War With One Hand Tied Behind Their Back

0
11
Cyber War
Image Source: Pexels

Ask most people what critical national infrastructure means, and they will picture power stations, ports, or perhaps the NHS. Few would name the local authority that empties their bins, houses vulnerable families, or runs the school transport rota. Yet councils hold some of the most sensitive data in the country, social care records, housing benefit claims, and safeguarding files on children, and they are doing it with security budgets that would embarrass a mid-sized retailer. 

That mismatch has been building for years, but it has become impossible to ignore. Redcar and Cleveland, Hackney, and Gloucester City Council each spent months, sometimes years, and millions of pounds recovering from ransomware attacks that started with something as mundane as a phished login. The pattern is now familiar enough to be almost boring, which is precisely the problem. Boring risks get deprioritised in favour of whatever crisis is loudest that week.

“There’s a real gap between the threats councils are facing and the tooling and staffing they’ve actually got to face it with,” says Ugochukwu Anthony Igboko, a cybersecurity expert specialising in public-sector organisations and the protection of UK local authorities. His work focuses on the practical cybersecurity challenges councils face as they manage sensitive citizen data, legacy infrastructure, cloud platforms, remote access and increasingly complex third-party supply chains. 

This is not a resourcing gripe dressed up as analysis. It is a structural issue with structural consequences. Councils sit at the intersection of legacy IT, outsourced services, and public accountability, which makes them harder to secure than a typical business and considerably more damaging to fail. When a private firm is breached, customers can usually go elsewhere. When a council’s systems go down, there is no alternative supplier for adult social care or emergency housing. The service simply stops.

Part of the trouble is how local government has been asked to think about security in the first place. Compliance frameworks, GDPR, the NCSC’s Cyber Assessment Framework, and ISO 27001 have given councils a language for describing risk, but language is not the same as capability. A council can pass an audit and still be one unpatched server away from disaster, because audits measure documentation, not resilience under pressure. 

Igboko sees this gap most clearly in vulnerability management, where councils often mistake activity for progress. “A lot of authorities can tell you how many vulnerabilities they’ve scanned for,” he says. “Far fewer can tell you how long a critical one actually sits open before it’s patched, and that number is the one that matters.” In his experience, closing that window, and tracking it as a standing metric rather than an annual audit line, has a bigger effect on real-world risk than adding another tool to the stack. The same discipline applies once an incident is underway: he points to structured incident response exercises, run before anything goes wrong, as the difference between a council that contains a breach in hours and one that is still working out who has authority to act after several days. 

That distinction matters more in health and social care contexts than almost anywhere else. Council-run public health services increasingly rely on shared platforms and data-sharing agreements with the NHS and private providers, meaning a weakness in one council’s network can ripple across systems well beyond its own walls. It is not just about protecting a database; it is about protecting the people whose care depends on that database being available at 2am on a Tuesday. 

There is also a cultural piece that gets less attention than firewalls and endpoint protection but arguably matters more. Councils employ thousands of staff across dozens of departments, most of whom did not sign up to think about phishing emails. “Awareness training gets treated as a box to tick once a year,” Igboko notes, “when really it should be something that’s built into how people actually work day to day, not a slide deck they click through in December.” He points to phishing simulation click-rates as one of the few awareness metrics that actually tells you something: a council that moves the needle there over successive quarters is building real behavioural change; one that runs a single test in December and files the results is just generating a number for the compliance report. Security-first culture cannot be bolted on through an annual e-learning module; it has to be lived, which is a far harder and slower thing to fund than a new piece of software. 

None of this is unique to Britain, but Britain’s particular mix of austerity-era cuts and increasingly digitised public services has made its councils an especially exposed test case. Other countries are watching how this plays out, partly because the same structural pressures, thin budgets, outsourced infrastructure, and high-value data apply to municipal government almost everywhere. 

What would actually help is not another framework or another awareness campaign, but a shift in how risk gets funded. Central government could ring-fence cybersecurity spending for councils the way it does for other statutory obligations, rather than leaving it to compete against potholes and social care in an annual budget round, which it will usually lose. Insurers and auditors could start distinguishing more sharply between organisations that have genuinely tested their incident response and those that have merely written a policy document about one. And councils themselves could be more willing to share what goes wrong, rather than treating every breach as a reputational event to be managed quietly rather than a lesson the sector as a whole needs to learn from. 

“The organisations that recover fastest aren’t always the ones with the biggest budgets,” Igboko says. “They’re the ones that had already worked out, before the incident, who does what and how fast.” 

Councils will not close the resourcing gap overnight, and pretending otherwise helps no one. But treating local government as an afterthought in the national cybersecurity conversation is a choice, not an inevitability, and it is one Britain can no longer afford to keep making quietly.