Government entities covered by the strategy: 465 (Source: Infosecurity Magazine, citing UK Civil Service Deputy CISO Breandán Knowlton-Hung, Gartner Security & Risk Management Summit, London (September 23, 2026))
A Federated System Outran Its Own Mandate
The UK Civil Service is retiring the operating model behind its 2022 National Cyber Security Strategy, after a government audit found the mandate-based approach had produced no way to measure whether it was working. In a September 23 talk at the Gartner Security & Risk Management Summit in London, UK Civil Service Deputy CISO Breandán Knowlton-Hung laid out the scale of the challenge: central government sets direction for close to 465 independently run ministries, agencies and public bodies, each controlling its own money, technology and management chain. The 2022 strategy assumed that issuing standards and requiring assurance from that many independent units would translate into consistent outcomes. It did not.
The Audit That Forced a Rethink
According to Knowlton-Hung, the National Audit Office's 2025 review — conducted three years after the strategy launched — found the government running blind: no implementation plan existed, and there was no mechanism to confirm the strategy was delivering results. The same review flagged a staffing gap that made top-down compliance unrealistic on its own: a large share of specialist architect posts were filled on a temporary basis, and departments were short of the people needed to act on central guidance even when willing. Knowlton-Hung attributed this to capacity rather than resistance — teams, he said, were often blocked by budget limits, systems constraints, or 'competing risks they actually own.'
A Service People Adopted Beat a Mandate They Ignored
Instead of writing another directive, the center built something departments could just use: a scanning service that watches thousands of government bodies around the clock for roughly a thousand types of externally visible security flaws, and sends each result straight to whichever team owns the exposed system. No mandate compelled anyone to respond, yet Knowlton-Hung reported that the typical fix time for domain-level vulnerabilities fell from roughly 50 days to eight once teams had direct visibility into their own exposures. Local teams acted because the tool solved a problem for them directly, not because compliance required it.
What This Means Beyond Whitehall
The pattern Knowlton-Hung described — a central function that writes policy but cannot force adoption across autonomous units — is familiar to any organization built through acquisition or holding multiple business units with their own budgets and legacy systems. His new 'polycentric governance' model keeps hard central authority for a narrow set of systemic risks and otherwise competes for adoption on usefulness. Knowlton-Hung was explicit that cyber assurance scores are still improving too slowly against the threat, even under the revised approach, so this is a reported operational shift rather than a solved problem.
Questions for Your Security Leadership
Ask how many of last year's security mandates or policies were actually implemented by every business unit, and how that was measured rather than assumed. Ask what share of security roles across the organization, including in acquired or federated units, are vacant or filled by contractors, and whether that gap was accounted for when policies were signed off. Ask whether central security teams currently ship any tool or service that local teams adopt voluntarily because it makes their job easier — and if the honest answer is no, ask what it would take to build one before writing the next mandate.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Infosecurity Magazine.





