General Atomics

Three government hacks in one week: Has Whitehall learnt its lesson?

Trevor Dearing, Director of Critical Infrastructure at Illumio, argues that three government breaches in one week show why Whitehall must focus less on keeping attackers out and more on limiting the damage once they are inside.

Headshot for Trevor Dearing Director of Critical Infrastructure at Illumio
Photo: Ilumino / ADS Advance

Trevor Dearing, Director of Critical Infrastructure at Illumio, argues that three government breaches in one week show why Whitehall must focus less on keeping attackers out and more on limiting the damage once they are inside.

In the space of a week in July, we saw three separate government departments, the Department for Education, the Ministry of Defence and the Home Office, all suffer data breaches at the hands of the ExfilSquad data extortion group. The result was thousands of records being leaked, including the Police National Legal Database (PNLD) and MoD employee data.

Now, I would like to say it’s shocking that a breach like this could ever happen, but then I would be lying.

In the past few years, we’ve witnessed data breaches against the Legal Aid Agency, the Electoral Commission and the Police Service of Northern Ireland. These are just a few of the major ones targeting public-sector entities; I could list plenty of others.

The bit that does surprise me is that even after all these incidents and years of warnings, the government sector is apparently still not learning its lesson. Attackers retain the ability to access such large volumes of sensitive data, and that, to me, suggests many departments remain too reliant on keeping attackers out rather than limiting what they can reach once they’re in.

The challenges facing government departments

One thing I should make clear from the start is that public-sector security is not easy. Public-sector organisations face significant cybersecurity barriers compared with their private-sector counterparts. Budget constraints, a familiar issue across most Civil Service departments, are particularly challenging.

Limited spending ability impacts both access to new security solutions and the hiring and development of staff. Combined with the size and complexity of public-sector departments, shifting to new strategies often has the laborious feeling of trying to turn a supertanker.

Modern government infrastructure is sprawling and interconnected, with applications, workloads, users and data sitting across multiple different environments. The reliance on third parties only aggravates the risk.

Many third-party suppliers do not adhere to the strict security standards required to protect sensitive government assets and information. While these suppliers might pass the initial vetting process, new vulnerabilities and risks can show up at any time.

Computer hacker with mobile phone smartphone stealing data
Photo: stock.adobe.com

The issue is that many government departments don’t have visibility into those risks. In May 2025, the Public Accounts Committee released a report which found that departments had self-identified 319 legacy systems, with around a quarter of those flagged as high risk, and even the Cabinet Office admits it doesn’t know the true scale beyond that.

This almost sums up the problem facing government departments and explains the latest attacks. A technical analysis of the PNLD data breach suggests that the likely attack vector was the exploitation of a misconfigured public-facing application.

Conducting regular audits and continuously monitoring these providers’ systems ensures that they comply with the necessary security protocols, thereby minimising potential vulnerabilities.

Departments’ approach to security is wrong

Whilst more audits and monitoring are good, government departments need to be addressing the root cause rather than just trying to fix systems.

Public-sector cyber contract values have surged dramatically, rising by more than 300% since 2020. However, the NCSC dealt with 204 ‘nationally significant’ cyberattacks against the UK in the 12 months to August 2025, rising from 89 in the previous year. So that shows there’s something wrong with our approach.

Of course, every public-sector organisation wants to avoid being the victim of a data breach and being back in the news again. It’s this mentality that puts them in this position because the assumption is to try to stop attackers from entering.

It might sound logical, but trying to stop every attack from breaching the perimeter is impossible. AI has made the odds even smaller, allowing attackers to discover misconfigurations, generate exploits and pivot laterally at machine speed. When adversaries operate faster than humans can respond, prevention becomes a probability game you can’t win.

Cyber security being done by a man on a computer
Photo: stock.adobe.com

The difference between a well-contained, managed incident and a front-page crisis has always been about what happens after the criminal has got in. The Home Office, for example, doesn’t mandate the police to prevent crimes before they happen. They accept there will always be criminals, so they try to reduce the risks and contain them when they happen.

The aim of government departments must be to restrict the ability of attackers to move within systems and reduce the impact of attacks. We found that nearly 90% of organisations have experienced security incidents involving lateral movement in the last 12 months.

And the public sector will experience the same issue. A single point of compromise cascades into wider disruption because systems weren’t separated from one another. When everything is flat and interconnected, one exploited vulnerability in one ageing system becomes a route into everything else.

Limiting what attackers can access once inside

The first priority is assessing the current capabilities, mapping the most critical risks and establishing protocols that allow rapid decision-making when attacks occur. This doesn’t mean generating more alerts or collecting more logs. That will only make things worse.

Government needs to understand which risks matter most, how they connect and where an attack is likely to spread. By leveraging AI and deep-network observability tools, security teams can cut through the noise to see real exposure and act before threats escalate.

The second priority is containing lateral movement. As mentioned before, this is what turns a minor disruption into a multimillion-pound crisis.

By proactively segmenting networks, isolating workloads and enforcing least-privilege access, departments can protect critical systems, isolate risky legacy infrastructure and force attackers to slow down. That friction exposes their activity sooner, reducing both dwell time and impact.

A strategy that doesn’t break the bank

Importantly, a containment-first approach fits into the government’s Cyber Action Plan, which is pushing for greater accountability, visibility, faster response, recovery and systemic risk management in the public sector.

Containment isn’t about ripping out every legacy system or cutting every third-party supplier, because that isn’t going to happen. It’s about changing the mindset adopted by government departments so that resilience is built by limiting damage, not by pretending it can always be avoided.

The public sector has had years of warnings and no shortage of breaches to learn from. The lesson has been sitting there the whole time. It’s time departments actually acted on it.

Related

‘The economic case stacks up’: UK chancellor renews government backing for Heathrow expansion
Heathrow Airport
‘The economic case stacks up’: UK chancellor renews government backing for Heathrow expansion
Former Chancellor Rachel Reeves decided in January 2025 to back a third runway as part of Labour's plans to boost economic growth.
Aerospace

11 Sep 2026

Syensqo supports NOEMI’s bid for the world’s first certified electric amphibious seaplane
NOEMI's all-electric amphibious seaplane.
Syensqo supports NOEMI’s bid for the world’s first certified electric amphibious seaplane
NOEMI Aerospace will use Syensqo advanced composites and adhesives to support the lightweight airframe of its pioneering all-electric amphibious aircraft.
Aerospace Member News

10 Sep 2026

Winter hydrogen trial at Exeter Airport strengthens case for lower-carbon ground operations
HyGPU trial Exeter Airport
Winter hydrogen trial at Exeter Airport strengthens case for lower-carbon ground operations
Exeter Airport’s latest hydrogen trial found a converted dual-fuel ground power unit could operate safely in winter, reducing diesel burn and carbon emissions.
Aerospace

10 Sep 2026

Royal Navy spends more than £123,000 on content creators
XC Excalibur uncrewed submarine for the Royal Navy
Royal Navy spends more than £123,000 on content creators
The Ministry of Defence confirmed the spend as it looks to reach new audiences and support recruitment.
Defence

11 Sep 2026

US private equity group agrees £1.1bn takeover of key UK defence supplier
Self sheilded storage box for contaminated nuclear waste
US private equity group agrees £1.1bn takeover of key UK defence supplier
Cerberus Capital Management has agreed a £1.1bn acquisition of Goodwin engineering businesses tied to sensitive UK defence, nuclear and naval supply chains.
Defence

11 Sep 2026

G2E consortium awarded Edgewing contract to develop GCAP sensing and comms
GCAP
G2E consortium awarded Edgewing contract to develop GCAP sensing and comms
As a strategic enabling partner to Edgewing, the GCAP Electronics Evolution (G2E) consortium will provide sensing and communications capability for the Global Combat Air Programme (GCAP), delivering information superiority for the next-generation fighter aircraft in future complex and contested airspace.
Defence Member News

11 Sep 2026

Skyrora completes hot-fire testing of advanced LEO engine
Skyrora engine test
Skyrora completes hot-fire testing of advanced LEO engine
Skyrora has conducted hot fire testing of its LEO engine at its Midlothian facility in Loanhead, demonstrating the potential of stronger, lightweight parts for future propulsion systems.
Member News Space

11 Sep 2026

UK spends nearly £30m on SpaceX satellite services as military shifts to Starshield
Starlink already offers unparalleled end-to-end user data encryption. Starshield uses additional high-assurance cryptographic capability to host classified payloads and process data securely, meeting the most demanding government requirements.
UK spends nearly £30m on SpaceX satellite services as military shifts to Starshield
The UK military operates around 1,000 SpaceX Starshield terminals after spending nearly £30m on Starshield and Starlink satellite communications.
Defence Space

11 Sep 2026

NewOrbit gains launch slot for first VLEO commercial mission
NEO1
NewOrbit gains launch slot for first VLEO commercial mission
Reading-based NewOrbit will conduct the first commercial mission on which any payload developer can fly, test and validate technology in Very Low Earth Orbit (VLEO), approximately 200-300km above the Earth.
Space

10 Sep 2026

Lindy Cameron appointed as first female FCDO Permanent Under-Secretary
Lindy Cameron appointed as first female FCDO Permanent Under-Secretary
With vast experience across national security, diplomacy and development, Lindy Cameron has become the first female Permanent Under Secretary at the Foreign, Commonwealth and Development Office (FCDO).
Security

12 Sep 2026

MI5 chief warns next major threat may come from where the UK is not looking
MI5 Director General Ken McCallum
MI5 chief warns next major threat may come from where the UK is not looking
MI5 chief Sir Ken McCallum says the next major security shock may already be developing where intelligence agencies are not looking, 25 years after 9/11.
Security

11 Sep 2026

Barbara Supplee appointed CEO of Serco North America
Barbara Supplee
Barbara Supplee appointed CEO of Serco North America
Drawing on her vast experience of supporting some of the United States' most important defence and national security missions, Barbara will lead Serco's delivery of mission-critical programmes in North America.