Cyber security threats to local government remain a “significant strategic risk”, according to a report, with the creation of two new unitary councils posing “further complexity” to IT security.
Guildford Borough Council’s audit and risk committee will next week review an update to its corporate risk register, which outlines and grades operational challenges.
These risks range from financial stability to climate change – as well as the ongoing local government reorganisation that will see two new unitary councils created next spring.
But the report also highlighted the dangers of cyber security threats to councils across the country, which the document says are “increasingly vulnerable” to such attacks.
These threats can take many different forms, including ransomware attacks, data breaches or Distributed Denial of Service (DDosS) incidents.
The report reads: “Cyber security remains a significant strategic risk given the increasing volume and sophistication of cyber threats facing local authorities, together with the potential operational, financial and reputational consequences of a successful attack.”
It adds that the ongoing local government reorganisation, which will see Surrey County Council and the 11 district councils scrapped next year to make way for the new East and West Surrey Councils, makes the situation more complex.
“The ongoing transition associated with Local Government Reorganisation adds further complexity to the Council’s technology and information environment and reinforces the need for continued vigilance,” the report says.
The council will continue to invest in preventative measures to mitigate the likelihood and potential impact of cyber attacks, the document adds.
“The risk remains above appetite due to the external threat landscape and the potentially significant impact of a successful cyber attack,” it says. “Given the nature of the risk, the majority of threat activity remains outside the council’s direct control.”
A Guildford Borough Council spokesperson told the Local Democracy Reporting Service (LDRS): “We take our IT security and governance responsibilities very seriously.
“As part of this commitment, we provide councillors with a high-level summary of the cyber security measures we have in place. We do not publicly share specific details about security controls.
“We’re currently working with IT professionals from across county, district, and borough councils to ensure our IT systems remain secure when we come together on 1 April 2027.”
James Moules Local Democracy Reporter
.
Idealised image


