The UK government is facing mounting scrutiny after finally releasing a long-delayed review into 11 major public sector data breaches, nearly two years after the report was completed.
The review, commissioned in 2023 following the exposure of personal details of around 10,000 Police Service of Northern Ireland officers, examined high-profile breaches across HMRC, the Metropolitan Police, the Ministry of Defence and the benefits system. It also included cases where the data of Afghan nationals who worked with the British military, victims of child sexual abuse and thousands of disability claimants were compromised.
The Cabinet Office investigation uncovered a series of recurring weaknesses in how sensitive data is handled across Whitehall and other departments. One of the most significant failings was the lack of adequate controls over ad hoc downloads and bulk exports of sensitive information, leaving personal records vulnerable to error or misuse.
Another common problem was the mishandling of email communications. Sensitive information was repeatedly disclosed through emails being sent to the wrong recipients, alongside failures to use blind carbon copy (bcc) properly, exposing individuals’ personal details unnecessarily.
The review also highlighted how personal data often became embedded in spreadsheets and other files later intended for public release, meaning information thought to have been anonymised was still identifiable when published.
The report was completed in 2023 but withheld for 22 months. It was only released on Thursday after pressure from the Science, Innovation and Technology Committee and the Information Commissioner.
Andy Ward, SVP International at Absolute Security said: “Cyber resilience isn’t just about responding to the latest breach, it’s about having a structure that can both withstand inevitable attacks and recover quickly when incidents occur. The government’s own review highlights how everyday issues such as email handling, large data exports, and hidden spreadsheet data can expose even the most security-focused organisations to risk. Public bodies are often targets, therefore, by embedding cyber resilience as a foundation rather than an afterthought, the public sector can better protect sensitive data and more quickly return to normal operations following a disruption.”
Chi Onwurah MP, who chairs the committee, welcomed the release but raised fresh concerns. She questioned why the government had only implemented 12 of the 14 recommendations and why the review itself was kept secret, even after the Afghan breach became public in 2022. Onwurah warned that public trust in government-led digital transformation depends on demonstrable improvements in data security.
The Information Commissioner, John Edwards, echoed these concerns, urging ministers to act “as a matter of urgency” and fully implement all recommendations to prevent further breaches.
Among the measures still under discussion are a cross-government communications campaign to tackle poor information-handling practices, working with the National Cyber Security Centre to review technical controls for sensitive data and reassessing sanctions for negligent handling of personal information.
Cabinet Office Minister Pat McFadden and Science Secretary Peter Kyle acknowledged that while progress had been made, there was no room for complacency. In a joint statement, they said: “We must guard against complacency. This is an area on which we must keep a consistent focus to ensure standards continue to improve.”


