Question
To ask the Secretary of State for Digital, Culture, Media and Sport, how many cybersecurity incidents affecting government departments in each of the last three years originated in or involved a third-party supplier; and what steps are being taken to strengthen cybersecurity requirements throughout government supply chains.
The Government is aware of the risk created by supply chain cyber security incidents and is taking a range of steps to strengthen cyber resilience across government’s supply chains. These include embedding cyber security considerations into commercial and procurement activity, promoting the adoption of recognised cyber security standards, and working across government to identify and manage supply chain cyber risks.
In addition, the Government is engaging directly with its Strategic Suppliers through the Government Cyber Charter. As part of this work, all 39 Strategic Suppliers have been invited to sign the Government Cyber Resilience Pledge, which was launched last week as a public commitment to strengthening organisational cyber resilience. More than 20 Strategic Suppliers have already joined the first cohort of signatories, including major suppliers to government such as Microsoft, Accenture, Deloitte, Vodafone and Capgemini. Through the Charter, Government is working with Strategic Suppliers to strengthen cyber governance, increase the adoption of the National Cyber Security Centre’s Cyber Essentials scheme throughout supply chains, and improve secure software development and AI practices.
The Government Cyber Action Plan, published in January 2026, sets out how Government will improve incident reporting over the next 3 years.