The government set itself a 2025 deadline to harden its critical computer systems against cyber attack. Its own replacement strategy, published a year later, never says whether it made it.
Estimated reading time: 6 minutes
In short. The Government Cyber Security Strategy 2022-2030 set a hard deadline: government's critical functions "significantly hardened to cyber attack" by 2025. The National Audit Office (29 January 2025) and the Public Accounts Committee (9 May 2025) both concluded, before the deadline arrived, that it would be missed. The Government Cyber Action Plan, published 6 January 2026 to replace the strategy, never states whether the 2025 target was in fact met. It quietly concedes a second deadline gone, the 2030 target, and reports its legacy-IT problem using a different measurement to the one the auditors used, so nobody can check whether that specific problem got better or worse. Three documented mistakes: four stars.
In January 2022 the Cabinet Office published an eight-year plan for keeping government online. It gave itself a first checkpoint, four years out: by 2025, the computer systems that run the country's most critical functions would be hardened against attack. That checkpoint has now passed. The document that was supposed to mark it, the strategy's own formal successor, does not say what happened when the clock ran out.
The claims, tested
| The document's own words | What the record actually shows | Verdict |
|---|---|---|
| Government Cyber Security Strategy 2022-2030, Executive Summary, "Vision and Aim": the aim is "for government's critical functions to be significantly hardened to cyber attack by 2025" [1] | The National Audit Office's "Government cyber resilience" (HC 546, 29 January 2025): "the government will not meet its aim for its 'critical functions' to be resilient to cyber attack by 2025" [2]. The Public Accounts Committee's report of the same name (HC 643, 9 May 2025): "Government's work to date has not been sufficient to make it resilient to cyber attack by 2025" [3] | The 2025 target was confirmed missed by the government's own auditor and its own oversight committee before the deadline even arrived |
| Government Cyber Action Plan, the strategy's formal successor, Chapter 1 ("Introduction"): cites "the challenge of defending our digital estate from sophisticated cyber threats by nation states and organised crime groups" as the National Audit Office's contribution, with no reference to what the NAO or the Committee actually concluded about 2025 [4] | Nowhere in the published Action Plan, its ministerial foreword or its introduction is there a sentence confirming or denying that the 2025 hardening target was met. The strategy's own GOV.UK publication page, still live, carries no updated verdict either, only a notice pointing readers to the Action Plan "for the latest details" [5] | A reader who trusts the government's own account of its own strategy cannot learn, from either document, whether the 2025 promise was kept |
| Government Cyber Action Plan, Chapter 1: "we now recognise that the target set out in the GCSS for all government organisations to be resilient to known vulnerabilities and attack methods is not achievable by the original target date of 2030" [4] | The original strategy's second target, for the whole public sector, was "no later than 2030" [1]. The Action Plan's own replacement phases run "Building" to April 2027 and "Scaling" to April 2029, with "Improving" left open-ended beyond that [4] | A second missed deadline, conceded in the same document that stayed silent on the first, replaced with a phase structure that has no fixed end date |
The mistakes, counted
A missed deadline that the government's own successor document never confirms was missed (1). The 2022 strategy was explicit and measurable: government's critical functions "significantly hardened to cyber attack" by 2025 [1]. Two independent bodies checked that claim against the evidence and reached the same conclusion before the deadline arrived. The National Audit Office found "the resilience of the hundreds of ageing legacy IT systems that departments still use is likely to be worse" than assumed, and that "departments have no fully funded remediation plans for half of these vulnerable systems" [2]. The Public Accounts Committee went further, its chair Sir Geoffrey Clifton-Brown telling the press that GovAssure's independent assessments "have only served to confirm that our battlements are crumbling" [6]. The Government Cyber Action Plan, published 6 January 2026 specifically to succeed the 2022 strategy, mentions the National Audit Office exactly once, in a general sentence about the scale of the threat, and never states the outcome of the 2025 target its own predecessor document set [4]. A strategy that sets a measurable deadline and a successor that skips past it in silence is not a continuity of policy; it is a policy that quietly stopped grading its own homework.
A second deadline conceded, in softer language, in the same breath as the first was ignored (2). The 2030 aim was for "all government organisations across the whole public sector" to be "resilient to known vulnerabilities and attack methods" [1]. The Action Plan states plainly that this "is not achievable by the original target date of 2030" [4]. That is a franker admission than anything offered about 2025, yet it comes wrapped in a rebrand: a new Government Cyber Unit, "backed by over £210 million of central investment," presented in the ministerial foreword as the start of "a radical shift in approach" rather than as recovery from a missed target [4]. The Committee had already told the department what it wanted to see instead: following the 2025 Spending Review, it recommended the Cabinet Office set out "what levers and instruments the centre of government will use to take a fundamentally different approach to cyber resilience" [3]. The Action Plan's three delivery phases, Building to April 2027, Scaling to April 2029, and Improving "beyond" with no closing date, describe a process but not a lever: there is no parliamentary reporting rhythm, no independent review point, and no date by which the public can check progress again [4].
The one number that mattered most has been swapped for a different one (3). The specific failure identified in 2025, unfunded legacy IT, was measured by the NAO in systems: "hundreds of ageing legacy IT systems," with "no fully funded remediation plans for half" of the vulnerable ones [2]. Reporting on the same committee's findings, PublicTechnology recorded a more precise snapshot as of January 2025: 28 public sector organisations had identified 319 legacy systems, with "around 25% as 'red'" [6]. The Action Plan's own figure for the same problem is different in kind, not just in size: "nearly a third (28%) of the government technology estate is estimated to be legacy technology" [4]. A system count and a percentage of an unstated total cannot be reconciled against each other. Whether the specific, named problem that blocked the 2025 target has gotten better, worse, or simply been recounted differently is not answerable from the government's own published figures.
Credit where due
The Action Plan is not empty rebranding. GovAssure itself, the independent assessment regime the 2022 strategy created, is a genuine improvement on what came before: it replaced departments marking their own homework with outside scrutiny, which is exactly how the 2025 shortfall got documented and put in front of a select committee in the first place, a point the committee's own chair credited directly [6]. The "Defend as One" model addresses a failure both the NAO and the Committee identified repeatedly: cyber security handled as 25 separate departmental problems rather than one government-wide one [3]. And £210 million of new central investment, with a named unit accountable for spending it, is a real resourcing commitment, not a slogan [4]. The design responds to real, documented failures. What it does not do is tell the public whether the failure it was built to fix has actually improved.
Verdict
Four stars, from three documented mistakes. The Government Cyber Action Plan replaces a strategy that missed its first measurable deadline, according to the government's own auditor and its own oversight committee, without ever saying so. It concedes its second deadline is gone too, but wraps that concession in a relaunch rather than an account of what went wrong, and offers no fixed date for the public to check again. And the one number that explained the 2025 shortfall, unfunded legacy IT systems, has been replaced with a different, unreconcilable one. GovAssure, the "Defend as One" model and the new investment are real. Whether they are working is, by the government's own published record, currently unknowable.
Sources
- Government Cyber Security Strategy: 2022 to 2030 (HTML), GOV.UK / Cabinet Office, published 25 January 2022
- Government cyber resilience, National Audit Office, HC 546, published 29 January 2025
- Government cyber resilience, Committee of Public Accounts, HC 643, published 9 May 2025
- Government Cyber Action Plan (HTML), GOV.UK / Department for Science, Innovation and Technology, published 6 January 2026
- Government Cyber Security Strategy: 2022 to 2030, GOV.UK / Cabinet Office, published 25 January 2022, updated 6 January 2026
- Committee finds government cyber defence 'outpaced by hostile states', Sam Trendall, PublicTechnology, published 13 May 2025