VerbatimParliament, as it happens

Legal Aid Agency: Cybersecurity

Asked by Iqbal MohamedIndependentMinistry of JusticeTabled Answered 19 June 2026UIN 8843

The question

To ask the Secretary of State for Justice, whether his Department or the Legal Aid Agency received internal or external warnings between January 2020 and December 2024 concerning cyber security risks or weaknesses in the Legal Aid Agency’s IT systems.

Answered by Sarah Sackman

Risks relating to the Legal Aid Agency’s (LAA) digital systems including cyber security have been on the LAA and Ministry of Justice (MoJ) risk registers since 2021 and, in financial year 2022-2023, the LAA’s digital infrastructure was assessed as the most complex and fragile across MoJ.

MoJ commissioned a three-month externally-led review to urgently provide a clear evidenced base for the investment needed to stabilise legacy systems and reduce the likelihood of system failure, corroborating earlier assessments of the risk and digital system architecture. The Government inherited the LAA digital systems which were fragile due to chronic lack of investment.

This is why we took action, investing £10.5m in 2024-2025 for immediate remedial action. This funding enabled the implementation of the security measures, including the introduction of enhanced automated monitoring and alerting capabilities. But for the investment made by the Government we would not have detected the cyber attack when we did in April 2025. The restoration process introduced a range of improvements, including the adoption of defined security alerts and a much closer integration with the MoJ Security Operations Centre. These measures have enabled improved continuous monitoring and threat detection.

Although these steps improved Justice Digital’s readiness to modernise, they did not substantially reduce the residual risk during 2024 to 2025. Legacy systems continued to present high levels of technical debt and cyber exposure. The preparatory work undertaken, however, has allowed the agency to accelerate risk reduction since the cyber-attack through funded delivery of new platforms and targeted recruitment of additional specialist capability. Under this government investment in LAA digital systems has increased from £25m to £61m (2022/23-2025-26), a 144 percent rise with a focus on the stabilisation and transformation of these core systems. Over the spending review period we have secured additional funding of over £200m for transformation, recovery from the cyber-attack, and for moving our legacy systems to a modern and safe technology platform.

Due to the previous Government’s failure to invest in the LAA technology, the LAA’s legacy technology systems were assessed as not compliant with HM Government’s Cyber Security Standards at the time of the attack. Work is now underway to bring systems to the required standards.

As part of funding to transform LAA services, a dedicated cyber security team has been established within Justice Digital, working closely with development teams to identify and address risks early in the development process, to coordinate independent security testing, and tailor security monitoring to individual systems. The LAA has strengthened its Information, Risk and Security Committee to oversee remediation from the cyber‑attack and ensure new services are secure by design and meet government standards.

Dedicated governance has also been introduced to oversee transformation, with transparent reporting on progress, risks and compliance, alongside the MoJ’s Technology and Cyber Risk Improvement Programme to strengthen resilience and central security services.

The compromised digital portal has been replaced by a new, secure single sign-in tool for LAA online services (SiLAS). SiLAS has been designed and built in line with UK government and industry good practices for secure development. Security has been included from the ground up, including multi factor authentication, with independent testing activities to validate that the appropriate security controls are in place. Dedicated funding now underpins the wider LAA transformation programme, with additional funding secured over the Spending Review period for transformation, cyber‑attack recovery, and moving legacy systems onto a modern and safer technology platform. New legal aid digital services will be built to Government Digital Service standards, secure by design principles, the MoJ Security Policy Framework and in line with National Cyber Security Centre guidance.

The MoJ has established formal governance and assurance processes to ensure that risks identified by external professional bodies are reviewed and acted upon promptly. External findings are considered through departmental risk management and audit frameworks, with issues escalated to senior governance forums where required and tracked through formal remediation plans and improvement programmes.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim