"A mandate is permission to direct. It isn't the ability to make change happen," said Breandán Knowlton‑Hung, Deputy CISO at the UK Civil Service.
Why the 2022 "defend as one" approach ran into trouble
The National Cyber Security Strategy published in 2022 set out an ambitious "defend as one" vision in which central offices would set direction while departments owned their local risks. On paper the approach acknowledged the UK's fractured landscape — roughly 465 separate ministries, agencies and public bodies with their own leaders, budgets and systems — but implementation depended on a quiet assumption: that issuing standards and requiring assurance would produce compliance.
That assumption failed to survive external review. According to Breandán Knowlton‑Hung, the 2025 National Audit Office (NAO) report found that, three years into the strategy, the government had "no proper implementation plan" and "no way to tell whether any of it was really working."
NAO audit findings: gaps in plans and people
The NAO audit described not only a lack of a practical delivery plan but also wide capacity constraints across the civil service. About one in three cyber roles were vacant or filled by temporary contractors, and a large majority of specialist architects were not permanent, Knowlton‑Hung said.
"You can issue all the mandates you like. If there's no one at the other end to pick them up, they won't get picked up," he noted, explaining how budgets, local systems and competing operational risks prevented teams from acting even when they wanted to.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePolycentric governance: the three operational pivots
In response, the civil service is shifting to what Knowlton‑Hung calls a "polycentric governance" model: multiple, overlapping centers of decision‑making that coordinate rather than obey a single hierarchy. He framed the operational change in three concrete actions:
- Start by building useful, centrally delivered services that solve real problems for users in the hundreds of government services
- Make adoption socially and operationally cheaper than non‑adoption
- Reserve hard central authority for a small set of systemic risks where one failure can harm everyone
"Own fewer things centrally, but own them harder," Knowlton‑Hung said. "Everywhere else, be unmissably useful." He also emphasized that central government will still set direction, hold the policy line and intervene strongly on shared risks that no single agency should accept locally.
Central vulnerability monitoring: a test case
Knowlton‑Hung offered a tangible example of the new approach: a central vulnerability monitoring service that continually scans thousands of public sector organizations for roughly a thousand classes of externally visible weaknesses. The service routes actionable notifications to the right owners rather than trying to compel fixes by fiat.
That operational integration produced measurable change: by aligning with how local teams work, the service cut the median time to fix domain‑level vulnerabilities from about 50 days to eight. "We didn't order those fixes. Local teams owned and carried them out because the service helped them," he said.
What this means for technologists, policymakers, and public bodies
- Technologists and security teams: Expect centrally provided tools and services to be the primary channel for remediation and monitoring; adoption will be driven by practical usefulness and the relative ease of operational integration rather than by top‑down mandates.
- Policymakers and regulators: Central authorities will retain hard power over systemic risks but are shifting to owning fewer things broadly and owning the remaining central capabilities more tightly; the government is layering an action plan on top of the new operating model to accelerate impact.
- Public bodies (departments, agencies and public bodies): Responsibility for local risk remains, but incentives and operational support will come through services that make compliance cheaper to adopt than to ignore; persistent capacity shortages remain a structural constraint.
Knowlton‑Hung was candid about the limits and the pace: cyber assurance scores are improving year‑over‑year but still "not fast enough against the threat," and the government is stacking an action plan atop the new model to speed results. He summed the tactical lesson plainly: "Stop trying to force change through a memo. Go and be useful instead. Build the thing people want to pick up, then get out of the way while they use it."
The NAO's 2025 audit forced a rethink of the 2022 strategy; the central question now is whether a service‑led, polycentric model — backed by a focused action plan and the limited hard authority reserved for systemic risks — can close the gap between policy and the stretched, partly contractor‑filled workforce charged with carrying it out.




