The UK government announced over £210 million in central investment for public-sector cyber resilience when it published its Government Cyber Action Plan on 6 January 2026. The funding is intended to establish a central coordinating unit and expand support, shared services and incident-response capability. The published sources do not give a complete breakdown of how the money will be allocated.
What is the Government Cyber Action Plan?
The Government Cyber Action Plan is a programme to strengthen cyber security and digital resilience across government departments and the wider public sector. Published by the Department for Science, Innovation and Technology (DSIT), it forms part of the broader Roadmap for a Modern Digital Government. The plan responds to concerns about legacy systems, technical debt, persistent cyber threats and uneven resilience, with the goal of keeping digital public services trustworthy and available. DSIT’s publication record lists the plan as published on 6 January 2026 and updated on 20 March 2026.
What will the over-£210 million fund?
The investment is described as over £210 million in central funding. Official descriptions say it will establish a Government Cyber Unit within DSIT and enable scalable services, support and response capability. They do not publish a full pound-by-pound allocation, so the total should not be treated as a confirmed budget for any single service, supplier or workstream. The sources also do not establish how much had been committed or spent.
The plan’s delivery framework covers four connected areas:
Recommended Free Tools
#1 Best Overall
- Risk oversight: improving visibility of cyber risks and reporting across government.
- Support and services: developing shared services, a service finder and technical advisory capability.
- Response and recovery: improving incident readiness, including through a planned Government Cyber Incident Response Plan and common measures of service impact.
- Skills: developing the public-sector cyber workforce.
These are delivery commitments and intentions; the plan does not mean every proposed milestone or capability is already in place. It also identifies Secure by Design, supplier risk and incident readiness as areas where measurable outcomes are intended.
Which organisations and public services are covered?
The plan uses “government organisations” broadly. It includes government departments, arm’s-length bodies and wider publicly funded organisations that deliver services, often at local or regional level. Examples include NHS trusts and local authorities. Devolved governments are invited to support and align with the plan where doing so does not affect their devolved functions. The plan sets out this scope.
Who is responsible for public-sector cyber resilience?
DSIT’s Government Cyber Unit
The Government Cyber Unit is the central coordinating unit within DSIT. The plan assigns it a role in driving transformation through direction, accountability and targeted support. It is intended to strengthen coordination rather than replace the responsibilities of individual organisations.
Departments and public bodies
Departments and public bodies remain responsible for managing their own cyber security and risks. Lead government departments oversee the sectors and bodies within their remit, including reporting sector-wide risks, applying appropriate standards and managing escalation. Organisations are also expected to address supply-chain security through procurement, contractual requirements and review.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
The National Cyber Security Centre
The National Cyber Security Centre (NCSC) provides specialist technical expertise and guidance and works alongside the Government Cyber Unit. Separately, the Government Cyber Coordination Centre (GC3) coordinates government incident response. Ministers described GovAssure and Secure by Design as existing measures that the new plan builds on, while setting out a more joined-up operating model. The plan describes the unit’s relationship with the NCSC; the written ministerial statement discusses GC3 and existing measures.
Why did ministers argue that action is needed?
In a written ministerial statement on 6 January 2026, ministers cited two incidents to illustrate the consequences of attacks on public services. They said an incident at the Legal Aid Agency compromised personal data and affected digital processing of legal aid applications and bills. They also said an attack on NHS pathology supplier Synnovis delayed over 11,000 outpatient and elective procedure appointments and contributed to a patient’s death. These examples were cited by ministers; they are not investigations conducted by the action plan. The plan sets out the wider policy response.
Rank #4
What does the plan say about software supply chains?
DSIT announced a Software Security Ambassador Scheme to encourage adoption of its voluntary Software Security Code of Practice. Cisco, Palo Alto Networks, Sage, Santander and NCC Group were named as scheme participants. Their participation is not a government endorsement of their products or evidence that they are suppliers to the funded programme. DSIT’s announcement also cites a Ponemon Institute figure that 59% of organisations experienced software supply-chain attacks in the past year. The announcement does not state the report year, so the statistic should not be assigned one without checking the original report.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is the government’s £45 billion productivity figure a guaranteed saving?
No. DSIT’s announcement says digitising public services could unlock up to £45 billion in productivity savings. That is a government estimate of potential, not a realised or guaranteed saving and not a stated allocation from the cyber-resilience investment. The announcement points to DSIT’s State of Digital Government review. The announcement gives the estimate and its qualification.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
What has been reported since the plan launched?
In a written parliamentary answer dated 22 May 2026, DSIT reiterated that the over-£210 million investment establishes the Government Cyber Unit and enables scalable services, support and response capability. The answer also reported the Cyber Security and Resilience Bill’s parliamentary stage as of that date; that status is only a dated snapshot and should not be read as the bill’s current position. The answer does not state how much of the investment had been spent or committed. The parliamentary answer provides the dated update.
What the announcement means for public services
The plan combines central coordination and shared support with continued organisation-level accountability. Its practical test will be whether bodies can identify and report risks, prepare for incidents, manage supplier exposure and recover services effectively. The announced total establishes the scale of the government’s commitment, but without a published detailed allocation it does not show which specific organisation or service will receive what amount.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




