The UK government announced that its new Vulnerability Monitoring Service (VMS), a centralized platform continuously scanning internet-facing public sector systems for known weaknesses, has sharply reduced the time to fix serious flaws and the backlog of unresolved issues.
The service, which monitors around 6,000 public sector organizations, has helped cut unresolved security issues by roughly 75% and reduced the median time to fix critical vulnerabilities from about 50 days to approximately eight days.
Officials said the VMS detects around 1,000 different types of weaknesses each month and provides specific guidance to agencies on how to remediate them. Alongside this capability, the government is launching a dedicated “Cyber Profession” initiative to recruit, train, and retain cybersecurity experts, including a Cyber Resourcing Hub and a Cyber Academy to support long-term defensive capabilities across the public sector.
The UK government said these efforts are designed to protect public services from cyber-attacks and strengthen national cyber resilience. The announcement outlined plans for structured career pathways aligned with Cyber Security Council standards and emphasized improved detection, prioritization, and response across departments.
Denis Calderone, CTO, Suzu Labs:
“Scanning 6,000 public sector organizations and cutting DNS fix times from 50 days to 8 is genuinely good news. Find it, assign it, track it, close it. That’s how vulnerability management should work. Worth noting though that the 84% number is specifically for domain-related issues. Other vulnerability types went from 53 days to 32, so closer to a 40% improvement. Still real progress, just not quite as dramatic.
“The part that should give everyone pause is that these vulnerabilities were sitting across the public sector for years and nobody knew. NHS trusts, legal aid, ambulance services. Turning on a scanner and finding this much is a win, absolutely, but it also tells you just how blind these organizations were before. You can’t fix what you can’t see.
“And this is why it kind of bugs me that the government exempted itself from the Cyber Security and Resilience Bill it’s putting on the private sector. You have to wonder what the numbers would look like if they pointed these same scanners at their own departments with actual legal obligations behind them.”
Rajeev Raghunarayan, Head of GTM, Averlon:
“Reducing median remediation time from roughly 50 days to single digits across thousands of public sector organizations is meaningful progress. It shows that when vulnerability management is treated as an operational priority, measurable improvements follow.
“At the same time, modern attack cycles move quickly. Even an eight-day exposure window can be significant. The real takeaway is not improved scanning alone, but operational follow through. Most organizations already have visibility into weaknesses. The challenge is translating findings into prioritized, accountable remediation and consistently shrinking the time between discovery and fix.”
Noelle Murata, Sr. Security Engineer, Xcape, Inc.:
“The UK government’s implementation of the Vulnerability Monitoring Service (VMS) marks a significant move from reactive patching to proactive, centralized security management for 6,000 public sector organizations. This initiative drastically reduces the average time to fix critical vulnerabilities from fifty days to just eight, effectively eliminating the window of opportunity that state-sponsored attackers and ransomware groups exploit for initial access. The focus on DNS vulnerabilities is a key strategic choice, as these frequently overlooked misconfigurations are the main method used for covert redirection and data interception.
“Complementing this technical solution is the new “Cyber Profession” initiative, which includes a Cyber Academy and a Resourcing Hub in Manchester, aiming to tackle the persistent skills shortage that has historically hindered public sector cybersecurity resilience. Crucially, the VMS approach reorients cybersecurity from a reactive “firefighting” mode to ongoing risk management. By combining this technical capacity with a structured “Cyber Profession” development program, the government is also addressing the human resource deficit that often undermines sustained resilience.
“While scanning tools are essential, they don’t resolve vulnerabilities on their own; skilled professionals and clear accountability are what truly fix them. Other governments would benefit from observing this model. This includes mandatory, continuous scanning of Internet-facing assets, coordinated centrally but executed by individual agencies. Talent development programs that establish cybersecurity as a viable career path can close security gaps more effectively than any regulation or budget increase.
“When governments treat patching speed as a national security metric, attackers lose their advantage: time.”
The UK government lately has been known to come up with some good ideas on the cybersecurity front. This is one of those good ideas because it forces those who are responsible for defending government networks to actually defend those networks in a way that reduces the attack surface.
UK adds cyberattacks on critical systems to National Risk Register
Posted in Commentary with tags UK on July 15, 2026 by itnerdThe UK government has added cyberattacks targeting data infrastructure, water systems and police networks to its 2026 National Risk Register, which outlines the most serious risks facing the country.
The updated register also includes “digital resilience failure” as a new risk, drawing on lessons from the July 2024 CrowdStrike outage. The government cited the increasing sophistication of artificial intelligence as one factor affecting the cyber threat landscape.
The UK plans to conduct its largest home defense exercise in decades in 2027, testing government and public-sector responses to hybrid threats including cyberattacks, disinformation and critical infrastructure sabotage.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Seven new risks on the UK’s National Risk Register. The one that undermines the rest is “interference in democratic processes.” Every other addition, cyberattacks on water operational technology (OT), police networks and colocation data centers, has an identifiable technical failure state and a technical remediation path. Democratic interference does not. Once the integrity of the information environment becomes a national security risk, someone in government must decide what constitutes manipulation, disinformation, or an unacceptable influence operation. Those are political judgments, and the standards will change with the government making them.
“Operation Albiston Shadow, the UK’s largest home defense exercise in decades, is supposed to test readiness for cyberattacks and infrastructure sabotage. To the extent the scenario requires officials to adjudicate information quality, it stops being a purely technical drills.
“The technical risks themselves are overdue, though I’d feel better if the UK’s follow-through matched the announcements. In just over a week, the government released Cyber Shield’s blueprint for autonomous AI defense at machine speed, the Risk Register update and Albiston Shadow. Three announcements centered on identifying, modeling, and exercising risk, with no funded remediation commensurate with the risks being announced. The National Audit Office (NAO) reported in January 2025 that departments were running at least 228 legacy IT systems and lacked fully funded remediation plans for 120 of them, 53%.
“Discovery is the easy part. Critical infrastructure teams too often avoid testing production OT because they lack the tooling or the risk appetite to touch systems that can’t go down. The vulnerability scan runs on the IT side, the OT side gets a paper assessment, and the exercise report says “tested.” That’s how exercises become security theater. Albiston Shadow runs in 2027, and without funded remediation, it risks testing many of the same weaknesses the government already knows about.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“The most significant development in the UK’s National Risk Register isn’t simply the recognition of growing cyber threats, it’s the recognition that digital resilience is now a national resilience issue. The strategic question is not whether we can prevent every cyber attack, it is whether society can continue functioning when digital systems fail.”
“This is part of a broader international shift. In the United States, initiatives such as the June AI Executive Order, the Gold Eagle public-private cybersecurity partnership, and increasingly realistic resilience exercises all point toward the same conclusion: cybersecurity must evolve to address cyber civil defense. Governments don’t own most critical infrastructure, so resilience must be built through trusted public-private partnerships, shared situational awareness, and a collective defense which measures and addresses the exposures before a real crisis reveals them. Plans don’t build resilience. Realistic adversarial emulation, quantitative performance metrics, and OODA loops do.”
“Artificial intelligence is accelerating this transformation for both attackers and defenders. Human-speed defensive workflows will increasingly struggle to keep pace with machine-speed offensive operations. The limiting factor is no longer finding flaws, but the speed and effectiveness of coordinated response. Ultimately, success should be measured not simply by whether attackers gained access, but by whether essential services remained available and recovered quickly when disruption occurred, and whether the attack remains contained, or affects adjacent infrastructures.”
Seemant Sehgal, Founder & CEO, BreachLock:
“The UK government putting cyberattacks on the same list as floods and pandemics is a policy signal worth reading carefully.
“What stands out to me about the UK’s approach is the inclusion of digital resilience failure as a distinct risk, because the CrowdStrike outage showed that the most disruptive events can originate inside your own trusted systems, not from an adversary at all.
“The 2027 exercise is the right instinct, but the gap between planning for a scenario and actually being prepared for it is where most organizations need to focus on closing.”
The USA should copy the UK as clearly the UK are on the right side of history.
Leave a comment »