VerbatimParliament, as it happens

Cybersecurity: Government Departments

Asked by Callum AndersonLabourDepartment for Science, Innovation and TechnologyTabled Answered 8 December 2025UIN 95525

The question

To ask the Secretary of State for Science, Innovation and Technology, whether her Department has formalised reporting requirements for departments that experience repeated cyber incidents.

Answered by Ian Murray

The Government Cyber Security Policy Handbook sets clear expectations for departments to follow in the event of a cyber incident, including the communication plans that departments need to have in place to notify relevant bodies and organisations.

The Government Cyber Coordination Centre (GC3) will shortly publish the Government Cyber Incident Response Plan (G-CIRP) which reiterates departmental responsibilities during cyber incidents, including reporting.

Furthermore, DSIT expects to publish the Government Cyber Action Plan this Winter, which sets out clear structures and actions to improve our collective response to fast-moving incidents. It also articulates how the Government Cyber Coordination Centre will provide departments with more support in understanding, detecting and responding to threats.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim