The Cabinet Office's own playbook calls ageing IT the government's biggest cyber risk, then tells departments to prove resilience with a scheme built to skip it. Its own auditor has since found half those systems have no funded fix.
Estimated reading time: 7 minutes
In short. The Digital, Data and Technology Playbook tells central government departments that "departments shall assess their cyber resilience against the appropriate government profile under the NCSC's Cyber Assessment Framework (CAF)... in accordance with... the HMG GovAssure cyber assurance regime" [1] (p.8), because legacy IT "has a significant impact on cyber and national security" [1] (p.8). The National Audit Office found that "GSG has not included 'legacy' IT systems within the scope of GovAssure" [3] (p.26), and that departments had no fully funded remediation plan for 120 of the 228 legacy systems they reported [3] (p.38). Four documented mistakes: three stars.
Every digital project run by a central government department is supposed to pass through the Digital, Data and Technology Playbook, mandated on a "comply or explain" basis since 2022 [1] (p.12). Its central promise on security is simple: assess the risk, use the government's own cyber framework to prove it, move on. The National Audit Office has since checked whether the framework it points to actually covers the risk the Playbook itself names as the worst one.
The risk it names and the scheme it points to
The Playbook does not bury the risk. Legacy IT, it says, "refers to systems and their component software and hardware that are outside of vendor support, on extended support and/or on bespoke support arrangements," and "this is a burden on the public and has a significant impact on cyber and national security, the operational resilience of critical systems, and value for money" [1] (p.8). Having named that risk, the Playbook sends departments to a specific mechanism to manage it: "Departments shall assess their cyber resilience against the appropriate government profile under the NCSC's Cyber Assessment Framework (CAF). This should be conducted in accordance with the guidance and policy under the HMG GovAssure cyber assurance regime and the Government Cyber Security Policy Framework" [1] (p.8).
GovAssure is real. Between April 2023 and July 2024, 35 departments self-assessed 72 critical IT systems against CAF outcomes, with 58 of those independently reviewed [3] (p.11). What GovAssure does not do, on the government's own account, is look at legacy IT. The National Audit Office's January 2025 report on government cyber resilience states it as a formal note on its own diagram of the scheme: "GSG has not included 'legacy' IT systems within the scope of GovAssure" [3] (p.26). The reason given elsewhere in the same report is that GovAssure's "recommended system controls would not be applicable to legacy systems" [3] (p.11). The Playbook's own words identify legacy IT as the thing most likely to hurt national security. Its own named assurance route was built without it.
What is left to check it, and what that check found
Legacy IT is not entirely unwatched: the Central Digital and Data Office (CDDO) runs a separate legacy IT risk assessment framework, published September 2023, which collects departments' own assessments of risk and remediation plans [3] (p.11). That is the route left standing once GovAssure is out of scope, and it is thinner: the NAO notes these self-reported assessments "were not detailed and included aspects of cyber security in addition to other criteria" [3] (p.11), a self-assessment of a self-assessment, with no independent reviewer role of the kind GovAssure at least applies to 58 systems.
What that thinner route has found is not reassuring. In March 2024, departments reported using at least 228 legacy IT systems, of which 63 (28%) were red-rated for a high likelihood and impact of operational and security risk [3] (p.11). Fully funded remediation plans existed for 78% of the red-rated systems (49 of 63), which is the one genuinely reassuring number in this data. But departments had no fully funded plan, partial funding only or no funding status at all for 120 of the full 228 legacy systems, 53% of the total, and specifically for 64% (106 of 165) of the legacy systems that were not red-rated "yet still presented a risk" [3] (pp.38-39). The Playbook's own stated goal is "preventing future legacy IT and remediating what already exists" [1] (p.8). On the government's own most recent count, remediation is unfunded for over half the legacy estate it is supposed to be shrinking.
The £20 million line that decides who gets checked at all
Assurance under the Playbook is not evenly applied even before legacy IT enters the picture. The Playbook is explicit that independent Cabinet Office scrutiny is a function of contract size: "For all projects over £20 million (total contract value), additional controls are applied by the Cabinet Office and departments are encouraged to engage with SAS (controls) as early as possible" [1] (p.29). Two things follow from that sentence. Below £20 million, a department's own governance processes and its own submissions through the Commercial Spend Control's self-service channels are the only check that applies [1] (p.29). And even above £20 million, the Playbook only "encourages" early engagement with the Cabinet Office's own assurance team, rather than requiring it. Most departmental DDaT contracts, the everyday agile builds and system upgrades this Playbook is meant to govern day to day, sit well under a £20 million threshold built for the government's largest and most complex deals.
A promised update that never came
The Playbook itself flagged, in its June 2023 text, that it would need revisiting once procurement law changed: "The new rules that will be introduced as a result of the enactment of the Procurement Bill and its associated regulations... will have implications for the policies set out within this Playbook... The Playbooks will be updated to reflect the new regulations in due course" [1] (p.9). The Procurement Act 2023 "came into force on 24 February 2025" [4]. The Playbook's own change history on GOV.UK records no update since 20 June 2023 [2]. Nineteen months after the Act it flagged as relevant took effect, the document promising to reflect it still reads as it did before the Act existed.
The claims, tested
| The document's own words | What the evidence actually shows | Verdict |
|---|---|---|
| Legacy IT "has a significant impact on cyber and national security," and departments "shall assess their cyber resilience... under the... GovAssure cyber assurance regime" [1] (p.8) | GovAssure formally excludes legacy IT from its scope [3] (p.26) | The named cyber check does not check the named worst risk |
| The Playbook's aim is "preventing future legacy IT and remediating what already exists" [1] (p.8) | 53% of the 228 reported legacy systems (120) have no fully funded remediation plan [3] (pp.38-39) | Remediation is the stated goal; it is unfunded for over half the estate |
| "The Playbooks will be updated to reflect the new regulations in due course" once the Procurement Bill passed [1] (p.9) | The Procurement Act came into force 24 February 2025 [4]; the Playbook's own history shows no update since June 2023 [2] | A promised update, 19 months overdue on the document's own terms |
The mistakes, counted
The Playbook's own named cyber check does not check the risk it names as worst (1). Legacy IT is called out on the same page as a "significant impact on cyber and national security" and as the subject of the "shall assess" mandate to GovAssure [1] (p.8), yet GovAssure formally excludes legacy IT [3] (p.26).
Remediation of existing legacy IT, the Playbook's own stated aim, is unfunded for most of the reported estate (2). Departments had no fully funded plan for 120 of 228 reported legacy systems as of March 2024 [3] (pp.38-39), against the Playbook's goal of "remediating what already exists" [1] (p.8).
Independent Cabinet Office assurance only applies above a £20 million threshold, and is optional even then (3). Below that figure, a department's own governance is the only check; above it, engagement with the Cabinet Office's own controls team is merely "encouraged" [1] (p.29).
A promised update tied to the Procurement Act is 19 months overdue on the document's own terms (4). The Playbook said it would be updated once the then-Procurement Bill became law [1] (p.9); the Act came into force 24 February 2025 [4], and the Playbook's own change history shows nothing since June 2023 [2].
Credit where due
The Playbook does not hide the legacy IT problem or wave it away as solved; it names the risk in plain terms and points to a dedicated companion Legacy IT Guidance Note rather than leaving departments to work it out from a single paragraph [1] (p.8). The £20 million assurance threshold, while it leaves most projects outside it, is at least a published, objective figure rather than a discretionary judgement call, and the Government Major Contracts Portfolio it sits alongside does commit to tracking the most complex deals on a quarterly basis [1] (p.28). And the National Audit Office's own figures show the system is not uniformly neglected: departments had funded plans for 78% of the legacy systems rated as the highest risk [3] (p.38), even if the remaining lower-rated majority fares worse.
Verdict
Three stars, from four documented mistakes. The Digital, Data and Technology Playbook correctly identifies legacy IT as one of government's biggest cyber and national security risks, then names a cyber assurance scheme that was built without it, on the government's own admission. Where responsibility for legacy IT actually sits, funding has not followed for over half the reported estate, independent scrutiny of any kind stops well short of most departmental projects, and a plain commitment to update the document for a law that took effect 19 months ago has not been kept. None of this means the Playbook is empty; its risk language is honest and its named highest-risk systems are, mostly, being funded. But a policy that correctly diagnoses its worst risk and then routes around it on paper is not yet a working safeguard against that risk.
Sources
- The Digital, Data and Technology Playbook, Cabinet Office, published 28 March 2022, updated 20 June 2023
- The Digital, Data and Technology Playbook, GOV.UK publication page, Cabinet Office
- Government cyber resilience, National Audit Office, HC 546, Session 2024-25, 29 January 2025
- Transforming public procurement, GOV.UK collection, Cabinet Office