Foundry4

Cybersecurity 8 min read

Councils are being breached through their vendors

One council's cyber lead put it exactly: every time we have been compromised it was through a third party. The regulator's fine list now reads like a supplier list.

A cyber security team leader at an English council, speaking to researchers commissioned by the Department for Science, Innovation and Technology, described the position more precisely than any policy document has managed: “the times that we have been compromised have all been through third party. We’ve never been compromised as such; our third parties have been attacked.”

That quotation appears in The changing cyber threat profile and potential impact on local councils, a study carried out by WSP and published on 9 June 2026. The sample is small and self-selected, which the report says clearly: 30 survey responses from English councils and 15 interviews, drawn from a recruitment pool of 120 authorities, with findings the authors state are not generalisable to the sector. It is qualitative evidence and should be read as such. It is also the most direct account we have of how the people running council IT experience the problem, and it does not match how the problem is procured.

The regulator’s fine list is now a supplier list

Look at what the Information Commissioner has actually penalised in the last eighteen months and the pattern is unmistakable.

In March 2025 the ICO fined Advanced Computer Software Group £3,076,320 over an August 2022 ransomware attack on its health and care subsidiary. Attackers reached the systems through a customer account without multi-factor authentication. Personal information belonging to 79,404 people was taken, including details of how to get into the homes of 890 people receiving care at home. NHS 111 was disrupted and clinical staff lost access to patient records. The regulator’s provisional figure had been £6.09 million.

In October 2025 it fined Capita £14 million, split £8 million to Capita plc and £6 million to Capita Pension Solutions, over the March 2023 attack. The personal information of 6.6 million people was stolen. Capita Pension Solutions processes data on behalf of over 600 organisations running pension schemes, and 325 of those were affected. The chain of events is worth reading closely: a malicious file downloaded onto an employee device on 22 March, a high priority alert raised within ten minutes, and the device not quarantined for 58 hours against a target response time of one hour. Nearly a terabyte of data left between 29 and 30 March. Ransomware was deployed on 31 March. The ICO found no tiering model for administrative accounts, a failing raised as a vulnerability three times or more and left unfixed, a security operations centre that was understaffed and had missed target response times for at least six months beforehand, and systems holding millions of records that were penetration tested once on commissioning and never again. The provisional penalty was £45 million.

Neither of those organisations is a public body. Both were fined for what happened to other organisations’ data and other organisations’ services. That is the whole argument in two enforcement notices.

Synnovis is the case that shows what the impact actually is

The clearest published account of a supplier failure reaching patients is the ransomware attack on Synnovis, the pathology provider co-owned by Guy’s and St Thomas’, King’s College Hospital and SYNLAB, on 3 June 2024.

By 4 October 2024 NHS England reported that 10,152 acute outpatient appointments and 1,710 elective procedures had been postponed at the two most affected trusts. Because the affected trusts could not carry out cross-matching for blood transfusions, they had to use O-type blood, which is safe for all recipients, and that in turn contributed to a national shortage of O-type supplies. A pathology IT system failing in south-east London moved the national blood stock position. Very few risk registers contain that dependency.

The tail is longer than the outage. NHS England’s public questions and answers, last updated on 10 November 2025, record that services were fully restored by December 2024 but that working out whose data had been taken took more than a year, because the stolen files were unstructured, incomplete and fragmented. Synnovis is contacting impacted customer organisations, and it is those NHS organisations, not the supplier, that must then assess the risk and decide whether to notify patients. Eighteen months after the attack, the incident was still generating work in NHS trusts that had done nothing wrong.

Councils buy the same systems from the same firms and assure them separately

The WSP study surfaces a structural absurdity that nobody has an incentive to fix. Over half of survey respondents did not know whether their council provided any advice or training on cyber security to the supply chain for critical-sector projects, and a quarter said cyber security requirements were not regularly included in contractor or supplier contracts at all.

Where diligence does happen, it happens hundreds of times over. One IT team leader put the question directly: “Why are we all trying to assess their [suppliers] cyber security maturity as individual authorities. Why are we doing it 400 times? That’s the kind of thing could be done to a better level once nationally.”

The same respondent group described the mirror image problem when they are the ones being assessed. Multiple regulators and customers now ask for assurance against the NCSC’s Cyber Assessment Framework, which is progress, but they ask at different levels and for different scopes, so the same council tells the same story to ten different bodies at ten different times. Assurance effort is being spent on repetition rather than on coverage.

The framework itself moved to meet this. The NCSC released version 4.0 of the Cyber Assessment Framework on 6 August 2025, and one of its four substantive additions is a new component on ensuring that software used in essential services is developed and maintained securely. The others cover attacker methods and motivations, security monitoring and threat hunting, and artificial intelligence risks. The NCSC gave its reason plainly, describing a widening gap between the escalating threat to critical services and the collective ability to defend them. A supply chain principle has been in the framework since the beginning; what is new is the recognition that a supplier’s development practices are part of your risk surface, not just its incident response.

Set against that, the national statistics say what you would expect. The Cyber security breaches survey 2025/2026, published on 30 April 2026, found 15% of businesses formally review the risks posed by their immediate suppliers and 6% look at the wider supply chain. Among large businesses it is 48% for immediate suppliers. Even at the top of the market, half of the organisations best resourced to do this are not doing it.

What the state has decided to do about it

Two documents matter and they arrived within months of each other.

The Government Cyber Action Plan, published on 20 March 2026, creates a Government Cyber Unit inside DSIT led by the Government Chief Information Security Officer, backed by over £210 million, with a build phase to April 2027 and a scaling phase to April 2029. On suppliers it commits the unit to establishing formal strategic partnerships with government’s designated strategic suppliers, with cyber security and resilience requirements built into them, so that the centre can hold those suppliers to account for the government-wide risk they carry. That is a meaningful shift. Until now each department has negotiated its own terms with the same handful of firms, which is the 400-times problem at national scale.

The plan also contains an admission that deserved more coverage than it got. The target in the 2022 strategy, for all government organisations to be resilient to known vulnerabilities and attack methods by 2030, is stated in the plan to be not achievable by that date. Departments are told they must urgently invest in replacing legacy systems, and the plan repeats the estimate that nearly a third of the government technology estate is legacy. It also cites the 2024 CrowdStrike outage, which was not an attack at all, as evidence of how a single supplier dependency creates widespread disruption, and puts its cost to the UK economy at between £1.7 and £2.3 billion.

The second is the legislation. Ministers introduced the Cyber Security and Resilience Bill in November 2025, bringing managed service providers into regulatory scope for the first time and creating a category of designated critical supplier. The government’s policy statement sets a data centre threshold at 1MW of capacity, or 10MW for an enterprise site, which it expects to catch around 182 third-party sites and 64 operators. It requires notification of a significant incident to the regulator and the NCSC within 24 hours, followed by a fuller report within 72.

If you buy managed services, both halves of that reach you. Your provider acquires duties that will be priced into your renewal, and a regulator acquires a route to ask why you did not know what your provider was doing.

What a public body can do before any of that lands

Three things, none of which require legislation or money.

Rank suppliers by the length of the outage they can cause, not by contract value. Those lists differ sharply, and the cheap entries are frequently the dangerous ones: the bureau that runs the payroll, the laboratory that returns the test results, the firm that prints and posts letters with statutory deadlines on them, and the integrator whose engineers hold administrative credentials on four separate systems.

Write the notification clause you will need on the worst day. The recurring complaint from data controllers in the public sector is that when a processor is breached, the information needed to meet a statutory duty arrives late, incomplete or not at all. That is a contract problem with a contract solution, and it is cheap at procurement and unobtainable afterwards.

And rehearse the manual fallback for the two or three suppliers whose failure would stop a statutory service. Synnovis was restored in six months. The trusts had to keep treating people throughout.

The structural reasons councils end up here, and why replacing the systems underneath is so hard, are set out in the quiet crisis in local authority software. Incident reporting and the regulatory picture around it are tracked under cybersecurity, the wider procurement and audit view sits in public sector technology, and the obligations arriving from the European side are covered in the three routes by which NIS2 reaches Britain.

The uncomfortable conclusion is that the compromise is increasingly not yours to prevent. It is yours to survive, and survival is decided by contract terms and rehearsed fallbacks agreed years before anything happens.

Sources

  1. ICO, Software provider fined £3m following 2022 ransomware attack, 27 March 2025 ico.org.uk
  2. ICO, Capita fined £14m for data breach affecting over 6m people, 15 October 2025 ico.org.uk
  3. NHS England, Almost all services back on track after cyber attack hit south east London, 4 October 2024 england.nhs.uk
  4. NHS England, Synnovis cyber incident: public questions and answers, last updated 10 November 2025 england.nhs.uk
  5. WSP for DSIT, The changing cyber threat profile and potential impact on local councils, published 9 June 2026 gov.uk
  6. DSIT, Government Cyber Action Plan, 20 March 2026 gov.uk
  7. DSIT and Home Office, Cyber security breaches survey 2025/2026, 30 April 2026 gov.uk
  8. DSIT, Cyber Security and Resilience Bill policy statement, 9 April 2025 gov.uk
  9. NCSC, Cyber Assessment Framework v4.0 released in response to growing threat, 6 August 2025 ncsc.gov.uk