Foundry4

Public sector technology 8 min read

The quiet crisis in local authority software

Seven of 61 funded local government digital projects ever spread beyond the council that built them. The evaluation says why, and the money explains the rest.

Between 2018 and 2025 the Local Digital programme put £74.6 million into English local government technology and supported 268 authorities. Of the 61 projects funded by the Local Digital Fund, seven scaled beyond the councils that received the initial money. Seven out of 61, or 11%.

That number is not from a critic. It is from the government’s own evaluation of the programme, published on 22 June 2026 and carried out by a consortium of PUBLIC, Socitm and Daintta with Perspective Economics. The evaluators put the main cause squarely on the market: technical barriers in the local government software sector, and specifically a lack of interoperability and data standards.

There is one conspicuous exception, and it is instructive. LocalGov Drupal, a shared content management platform built collaboratively by councils, reached a 14% share of the local government CMS market. Websites are the layer with the fewest dependencies and the most substitutability. As soon as you move inland, to revenues and benefits, social care case management or planning, the substitution stops.

Why a council cannot switch

The obvious explanation, that councils lack the skills, is only a third right.

Capability is genuinely thin. The State of digital government review found local government digital and data professionals at around 2% of headcount, against a benchmark of 4%, the worst ratio of any part of the public sector it measured. A council with a hundredth of its staff in technology roles is not going to lead a systems migration on its own.

But capability is not what stops a switch. Dependency does. A revenues and benefits system does not sit in isolation. It exchanges data with the Department for Work and Pensions, feeds the council’s general ledger, drives statutory notices with legal deadlines, holds years of case history that has evidential value, and is wired into a document management system that a different supplier maintains. Replacing it means rebuilding every one of those joints while continuing to pay housing benefit every week without interruption.

The evaluation’s finding about interoperability and data standards is the polite version of this. Where standards do not exist, the integration is bespoke, and bespoke integration is what makes a supplier hard to leave. That is not a scandal. It is the predictable result of a market of several hundred small buyers, none of whom can individually specify a standard, purchasing from a handful of suppliers with no commercial reason to agree one.

The money makes replacement structurally hard

Even a council that has decided to move often cannot fund it, and the reason is the shape of local government finance rather than a shortage in any single year.

The National Audit Office’s report on local government financial sustainability, published on 28 February 2025, records that forty-two authorities have received over £5 billion of exceptional financial support since 2020-21, which allows a council to borrow or sell assets to fund day-to-day spending. Between January 2018 and January 2025, seven authorities issued ten section 114 reports saying they could not balance their budgets. Seven statutory interventions relating to financial governance were live.

The report also records that the median authority in its sample spent 77% of its income from council tax, business rates and central grants on demand-led costs in 2023-24. Adult and children’s social care alone took £42.3 billion across local government in that year, and the average cost per looked-after child rose 35% in real terms between 2015-16 and 2023-24, to £97,326.

Set a system replacement against that. It is a multi-year capital and revenue commitment, its benefits are efficiency rather than statutory compliance, and it competes for attention with a care budget that is legally unavoidable and growing. The paper never gets written, and next year the case is the same only the system is a year older.

One more mechanism sharpens the timing. The auditors note that the Department for Education’s central estimate put accumulated high needs deficits at £4.6 billion by March 2026, that 50 authorities were estimated to have deficits larger than their reserves at the end of 2025-26, and that some 43% of authorities may be at risk of needing to issue a section 114 report if the statutory override ends as planned in March 2026. That is a specific risk about a specific accounting treatment rather than a general prediction of collapse, and it is the kind of thing that empties a capital programme in a single committee meeting.

What happens when the systems fail

The clearest published account of what an unmaintained estate costs a council is the Information Commissioner’s reprimand of the London Borough of Hackney, issued on 17 July 2024 for an attack that took place in October 2020.

The findings are worth reading in the regulator’s own terms. Attackers accessed and encrypted 440,000 files affecting at least 280,000 residents and others including staff. Of those, 9,605 records were exfiltrated, and the council acknowledged a meaningful risk of harm to 230 people. The attackers deleted 10% of the council’s backup before it could intervene. Systems were disrupted for many months, and in some cases services were not back to normal until 2022.

The two failures the ICO identified are ordinary. The council had not ensured a security patch management system was actively applied to all devices, and it had not changed an insecure password on a dormant account still connected to its servers, which the attackers used. The regulator’s deputy commissioner described the second as a simple mistake and noted that dormant accounts where username and password match keep appearing in these cases.

The ICO considered a fine and issued a reprimand instead, applying its public sector approach, having weighed the council’s remediation and the effect of the pandemic on local authority resources. It also disclosed the sector context: over 150 cyber incidents reported by local government in the preceding year.

A dormant account and an unevenly applied patching regime are exactly what an estate accumulates when nobody has custody of it. They are not exotic failures. They are the failures of an organisation whose systems outnumber the people who understand them.

The national picture stops at the town hall door

Here is the structural oddity in British public sector technology reporting. The most thorough national assessment of legacy risk, the National Audit Office’s work on government cyber resilience, covers ministerial and non-ministerial departments and their arm’s-length bodies. It explicitly does not cover local government.

So the best available dataset on legacy IT in Britain, the one that produced the count of at least 228 legacy systems in departments and the finding that 53% had no fully funded remediation plan, stops precisely where the density of systems is highest and the capability is thinnest. Nobody publishes the equivalent for 300-plus councils.

What exists instead is a support programme. MHCLG’s Local Digital team reports £19.9 million of cyber support funding to 192 councils, an 83% reduction in initial risk across focus areas between 2020 and February 2025, an 82% improvement in backup resilience, and annual savings of around £11 million across the sector. Over 200 councils have completed its Get CAF Ready programme, working towards the Cyber Assessment Framework for local government.

Those are respectable results and the evaluation found the cyber interventions clearly outperformed the digital ones. They are also a national programme delivering targeted improvement to a sector nobody measures nationally, which means the baseline for the 83% is the programme’s own assessment rather than an independent census.

The conclusion nobody wants

The pattern in the evidence is consistent. Councils cannot switch because the market has no standards. They cannot afford to switch because demand-led costs consume the budget. They cannot staff the switch because 2% of their people work in technology. And nobody counts the resulting estate because national audit stops at the boundary.

Every one of those is fixable by something other than a grant to a council. Standards are set nationally or not at all. Multi-year capital certainty is a Treasury decision. A national legacy census for local government would cost a fraction of a single failed migration.

Until then the honest description of the situation is not that councils are behind. It is that the part of the state closest to residents is running the systems least likely to be replaced, in the organisations least able to replace them, and that this is a design outcome rather than an accident.

What a council can actually do about it

Nothing above is a reason for inaction, and there is a version of this problem that a council can address without waiting for anyone.

Know the estate. A written list of every system, its supplier, its support status, the person who understands it and the date the contract ends is a document most authorities do not hold in one place, and it costs officer time rather than capital. Everything else in this field depends on having it.

Buy exit terms while you still have leverage. The moment a council has any is at procurement, and the clauses that matter are data extraction format, extraction cost, and how long the supplier must keep the service running after notice. Those are cheap to negotiate then and unobtainable later.

And treat the dormant account as a system, not an oversight. The Hackney findings were not sophisticated. They were the residue of an estate with more accounts than owners.

The estate-wide view sits under public sector technology, and the route by which compromise now arrives, through a supplier rather than the front door, is examined in the vendor breach problem in public services.

Sources

  1. MHCLG, Local Digital programme evaluation: executive summary, 22 June 2026 gov.uk
  2. National Audit Office, Local government financial sustainability, HC 691, 28 February 2025 nao.org.uk
  3. Information Commissioner's Office, London Borough of Hackney reprimanded following cyber-attack, 17 July 2024 ico.org.uk
  4. MHCLG Digital, Supporting local government to reduce cyber risk through targeted interventions, 10 June 2025 mhclgdigital.blog.gov.uk