Cabinet Office boosts cyber spending by 500% amidst Whitehall CCTV security fears

Michael Gove’s department splashes out over £300,000 on training courses including ethical hacking, digital forensics and cyber skills.

The Cabinet Office has splashed £274,142.85 on cybersecurity training for staff in the most recent financial year (FY 20-21) – a 483 per cent increase on the £47,018 in the previous year (FY 19-20), according to official figures. The total spends over the two year period was £321,161.66.

The data, obtained by the Parliament Street think tank using Freedom of Information (FOI) legislation, is revealed amidst a series of security issues plaguing Whitehall, including CCTV of former Health Secretary Matt Hancock and his mistress in a passionate clinch being leaked by an unknown whistleblower.

The Cabinet Office, which is run by Michael Gove MP, and his close team of special advisers, is responsible for supporting the Prime Minister and Cabinet of the UK.

The full FOI response included a complete breakdown of the courses attended by Cabinet Office staff and revealed that 428 separate cyber training courses were booked in FY 20-21, compared to just 35 in FY 19-20.

By far, the most popular course, which received 332 bookings, was for NCSP Foundation e-Learning. This course provides introductory-level training on how to prevent, detect and respond to cyber-attacks.

The second most popular course was for a Foundation Certificate in Cyber Security, attended by 33 staffers in FY 20-21. 33 employees also attend this course in FY 19-20.

Some other cyber training courses attended in FY 20-21 included training in ‘the art of hacking’, attended by 12; ‘digital forensics fundamentals’, attended by two; ‘ethical hacking’, attended by one. Also, four staffers underwent training to become certified Lead Auditor and once joined a ‘CyberSec First Responder’ course.

Cyber expert Andy Harcup, senior director at Gigamon, said: “The Cabinet Office is tasked with managing some of the most sensitive data imaginable, so increasing cyber training and resources is a wise move, particularly with hackers relentlessly targeting government departments. However, far too many public sector organisations continue to operate without full visibility into network traffic, making it harder to spot hostile threats and take action before the damage is done. Large organisations with overstretched IT teams require complete visibility to manage complex cloud environments as well as identifying security threats to keep critical data safe, so taking action in this area must be a top priority.”

Security specialist Edward Blake, Area Vice President EMEA, Absolute Software, said: “It’s encouraging to see the government levelling up its cyber defences, particularly at a time when recent CCTV leaks are raising fresh questions about security standards across Whitehall. In addition to training staff with the latest cyber skills, it’s also critical to ensure government devices containing confidential data like laptops are properly protected so that they can be tracked, wiped or frozen in the event of loss or theft. Additionally, staff should be urged to report incidents of data loss or suspected hacking with immediate effect so action can be taken to recover or remedy the situation.”

READ MORE:

Full FOI table, provided by the Cabinet Office:

About the Parliament Street think tank

Founded in 2011, the Parliament Street think tank produces policy papers and research into how technology can improve public services.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Luke Conrad

Technology & Marketing Enthusiast

Six ways to maintain compliance and remain secure

Patrick Spencer VP at Kiteworks • 16th September 2024

With approximately 3.4 billion malicious emails circulating daily, it is crucial for organisations to implement strong safeguards to protect against phishing and business email compromise (BEC) attacks. It is a problem that is not going to go away. In fact, email phishing scams continue to rise, with news of Screwfix customers being targeted breaking at...

Enriching the Edge-Cloud Continuum with eLxr

Jeff Reser • 12th September 2024

At the global Debian conference this summer, the eLxr Project was launched, delivering the first release of a Debian derivative that inherits the intelligent edge capabilities of Debian, with plans to expand these for a streamlined edge-to-cloud deployment approach. eLxr is an open source, enterprise-grade Linux distribution that addresses the unique challenges of near-edge networks...

Embracing digital AI recruitment without rocking the boat

Katherine Loranger • 11th September 2024

Artificial intelligence (AI) is set to become indispensable in business operations. For global enterprises, AI offers significant benefits by simplifying complexity and enabling confident decisions—when used in the right way. Those HR recruitment teams that seamlessly integrate AI technologies will optimise their recruitment practices and will have the opportunity to better realise their commitment to...

Why a data strategy underpins a successful AI strategy

Jim Liddle • 05th September 2024

AI and machine learning offer exciting innovation capabilities for businesses, from next-level predictive analytics to human-like conversational interfaces for functions such as customer service. But despite these tools’ undeniable potential many enterprises today are unprepared to fully leverage AI’s capabilities because they lack a prioritised data strategy. Bringing siloed and far-flung unstructured data repositories into...
The Digital Transformation Expo is coming to London on October 2-3. Register now!