Local Government Lawyer

 

GLD Vacancies


Kensington and Chelsea Council has been told it must improve its IT systems and cyber security training after a cyber-attack last year disrupted several services and led to data theft.

The cyber incident was the result of a phishing attack that impacted Kensington and Chelsea Council, Westminster City Council and Hammersmith and Fulham Council – who all share a number of IT systems and services.

Kensington and Chelsea said it took immediate action in November 2025 after noticing unusual activity, disconnecting the council’s IT infrastructure from the internet.

The council later reported that it had found evidence that some data had been stolen as a result of the attack.  

The local authority was still recovering from the attack as late as July this year, when it announced that some resident’s services were still offline, although most affected services had been restored.  

It has since reported that all services have been restored.

In its annual report on the local authority, external auditors Grant Thornton found significant governance weaknesses in relation to the attack – and raised a key recommendation calling for the council to improve training, change its cyber security strategy and invest in a series of IT system upgrades.

The report – which was considered by the council’s Audit & Transparency Committee last week – notes that the attack was the result of “human error” following a phishing attempt.

Grant Thornton said the attack exposed the need for Kensington and Chelsea to improve its IT infrastructure and staff training.

The report said: "One factor in the incident and time to recover, is the need for the Council to strengthen its IT estate. Notably, certain systems require internet connection to operate, rather than the Council having invested in Software as a Service (SaaS) solutions.

"This meant that when the incident occurred the Council had to disconnect systems from the internet to limit data copying, but meant systems could only run offline.

“This system shut-down has impacted the Council operationally and financially, creating a backlog in several services’ case loads and revenue received by the Council from resident payments."

The auditor’s key recommendations call on the council to:

  • Develop a costed, prioritised plan to invest in system upgrades across Council services, evaluating SaaS and offline options, strengthening resilience against future cyber incidents;
  • rebalance its cyber security strategy to give equal weight to prevention alongside existing reactive incident response arrangements;
  • Increase the frequency, intensity and uptake of cyber awareness training for all staff, ensuring this includes a focus on phishing awareness.

Since the attack, the council has already launched a cyber resilience programme of strategic rationalisation and centralisation of controls to improve oversight and reduce technical debt and associated risks going forwards.

It has also made cyber awareness training, including phishing awareness for staff and for members, mandatory.

A Kensington and Chelsea Council spokesperson said: “The technical recovery from the cyber-attack is now complete, and we have restored all of the systems we intended to bring back.

“We’re now focusing on the longer-term work needed to strengthen our cyber resilience, modernise our technology and improve our digital capabilities.

“This is a significant programme of work which will help us make the Council more secure and save money while supporting staff to improve outcomes for residents and protect frontline services.

“We are developing an investment plan to support those longer-term priorities, and this will be discussed by the Leadership Team in November as part of the Council’s next budget.”

Adam Carey

Jobs

Directory

Newsletter signup