Cybersecurity: Public Sector

(asked on 28th November 2025) - View Source

Question to the Cabinet Office:

To ask the Minister for the Cabinet Office, what criteria are used by his Department to determine which public systems require mandatory zero-trust security measures.


Answered by
Dan Jarvis Portrait
Dan Jarvis
Minister of State (Cabinet Office)
This question was answered on 9th December 2025

The Department applies a risk-based assessment framework, underpinned by secure by design methodology including structured threat modelling, to determine which public systems require mandatory zero-trust security measures. Systems handling sensitive data, supporting critical services, or presenting elevated threat exposure are prioritised. This approach ensures that zero-trust controls are applied proportionately, focusing effort on the environments with the highest risk profile.

Reticulating Splines