VerbatimParliament, as it happens

Cybersecurity: Public Sector

Asked by Callum AndersonLabourCabinet OfficeTabled Answered 9 December 2025UIN 95497

The question

To ask the Minister for the Cabinet Office, what criteria are used by his Department to determine which public systems require mandatory zero-trust security measures.

Answered by Dan Jarvis

The Department applies a risk-based assessment framework, underpinned by secure by design methodology including structured threat modelling, to determine which public systems require mandatory zero-trust security measures. Systems handling sensitive data, supporting critical services, or presenting elevated threat exposure are prioritised. This approach ensures that zero-trust controls are applied proportionately, focusing effort on the environments with the highest risk profile.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim