Industry7 min read28 September 2026

Website Security for UK Councils and Public Sector Bodies

UK councils and public sector organisations face unique cybersecurity challenges — legacy systems, constrained budgets, and high-value citizen data. This guide covers what good website security looks like for local government.

By Yrzo AI — UK cybersecurity specialists

The Public Sector Threat Landscape

UK councils and public sector bodies are among the most frequently targeted organisations in the country. The reasons are straightforward: they hold vast amounts of sensitive citizen data, they run critical services that cannot be easily shut down, and they operate under significant budget pressure that has historically made security investment difficult to prioritise.

The results are visible. Redcar and Cleveland Council suffered a ransomware attack in 2020 that cost an estimated £11 million in recovery costs and took down services for weeks. Gloucester City Council was hit in 2021. Hackney Council's 2020 attack took 18 months to fully recover from. These aren't outliers — they reflect a systematic targeting of public sector infrastructure by criminal groups who know that councils face pressure to restore services quickly and may be more likely to consider paying ransoms.

The National Cyber Security Centre (NCSC) has repeatedly warned that local government is under sustained attack, and its guidance for the sector is explicit: basic cyber hygiene, tested regularly, prevents the majority of successful attacks.

What Makes Public Sector Security Different

Public sector organisations face several constraints that shape how security needs to be approached:

**Legacy systems.** Many councils run line-of-business applications that haven't been updated in a decade, sometimes running on operating systems that are no longer supported. These systems often can't be patched quickly — or at all — because updates would break integrations with other council systems. Penetration testing identifies which legacy systems are externally reachable and what the real-world risk exposure looks like.

**Citizen-facing web services.** Councils increasingly deliver services through web portals — planning applications, council tax, housing benefit, social care referrals. These portals are public-facing, handle sensitive personal data, and are often built on third-party platforms with varying security track records. A penetration test of these portals checks for authentication weaknesses, insecure data handling, and injection vulnerabilities.

**Supply chain risk.** Public sector bodies rely heavily on third-party suppliers — managed service providers, software vendors, system integrators. The 2021 Kaseya attack, which affected MSPs serving public sector clients globally, illustrated how supply chain compromise can cascade into customer environments. Security testing should include an assessment of supplier access to council systems.

**Public Wi-Fi and shared networks.** Libraries, council offices, and civic centres often provide public Wi-Fi on shared infrastructure. Testing should verify that public-facing networks are properly segmented from internal administrative networks.

NCSC and Government Guidance

The NCSC's Cyber Assessment Framework (CAF) is the primary framework for UK public sector cybersecurity. It covers four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. Local authorities are expected to conduct regular self-assessments against the CAF, and penetration testing is one of the technical controls that supports several CAF indicators.

The Government Cyber Security Strategy, published in 2022, sets an explicit target: all critical government functions should be resilient to known vulnerabilities by 2025. For councils, this means addressing common weaknesses — unpatched systems, weak authentication, excessive third-party access — through a combination of technical controls and regular testing.

Central government departments and arm's length bodies are also subject to the Minimum Cyber Security Standard, which requires annual penetration testing of internet-facing systems. While this standard doesn't formally apply to local government, many councils use it as a benchmark.

Procurement and Due Diligence

UK public sector procurement is governed by the Public Contracts Regulations (being reformed under the Procurement Act 2023). Security requirements must be included in procurement specifications for digital services. Suppliers to councils should be expected to demonstrate security standards — typically through Cyber Essentials certification as a minimum, with Cyber Essentials Plus for higher-risk contracts.

When a council procures a citizen-facing web service, the contract should require the supplier to conduct penetration testing before go-live and after significant changes, and to provide test reports on request. Many councils don't include these requirements and then have no visibility into the security posture of systems handling citizen data.

What a Penetration Test Covers for a UK Council

A typical penetration testing engagement for a UK council covers:

**External infrastructure.** All internet-facing systems — websites, portals, email gateways, VPN endpoints, remote desktop services. This is where most successful attacks begin.

**Citizen-facing applications.** Planning portals, benefit claim systems, housing applications. Authentication, authorisation, session management, and data handling are all tested.

**Internal network (if in scope).** Active Directory configuration, internal service exposure, lateral movement paths between network segments.

**Reporting.** A findings report prioritised by risk, with specific remediation guidance. For public sector clients, the report should map findings to CAF objectives or Cyber Essentials requirements to support compliance reporting.

Practical Steps for Councils

For councils looking to improve their security posture, a pragmatic starting point is:

1. Achieve Cyber Essentials certification — this addresses the most common attack vectors and demonstrates a baseline commitment to security. 2. Conduct an annual penetration test of all internet-facing systems. 3. Ensure citizen-facing portals have been tested before go-live and after major updates. 4. Review supplier contracts to include security testing requirements. 5. Subscribe to NCSC's Early Warning service for free threat intelligence on your IP ranges.

Budget is always a constraint. Automated penetration testing tools like Yrzo AI can provide continuous coverage of your web-facing attack surface at a fraction of the cost of annual manual engagements — useful for councils that need ongoing visibility but can't commission quarterly manual tests.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →