PROTECT YOUR DNA WITH QUANTUM TECHNOLOGY
Orgo-Life the new way to the future Advertising by AdpathwayAfter taking almost 13 months to answer a Freedom of Information request, the Cabinet Office admitted that it holds no information about the cybersecurity requirements governing ministers’ devices.
By Ray Vahey
On 30 July 2025, the Cabinet Office received my Freedom of Information request asking what cybersecurity requirements apply to Cabinet ministers when using electronic devices for government business.
I asked about VPN requirements, encryption standards, device-security policies, compliance monitoring, security briefings and approved cybersecurity technologies. The Cabinet Office acknowledged the request the following day and said the Freedom of Information Act required it to respond promptly and, in any event, within 20 working days. It said I should receive a response by 29 August 2025.
Instead, the response was issued on 25 August 2026, 391 calendar days after the request was received.
After searching its records, the Cabinet Office said it did not hold the requested information. It suggested that I “may wish” to redirect my request to [email protected].[1]
It is hard not to wonder whether those 13 months were spent searching for an answer, or deciding how to admit that the Cabinet Office did not have one.
What prompted me to make this request was the UK government’s increasingly hostile tone towards VPN use, particularly when people use them to circumvent online restrictions.
During a House of Lords debate, the government said it would continue to monitor circumvention techniques, including VPNs. It said there were no current plans to ban VPN use because there were legitimate reasons for using them, but added that “nothing is off the table” when it comes to keeping children safe.[2] That surprised me because I had assumed VPNs, or equivalent secure networking technologies, would form a routine part of ministers’ own cybersecurity arrangements.
If the government recognises the value of VPNs in protecting sensitive official communications, it should not portray the same technology as inherently suspicious when ordinary people use it to protect their privacy and security.
To be clear, the response does not prove that ministers’ devices are insecure, nor does it establish that no security protocols exist elsewhere in government. It does, however, raise an obvious question. If the Cabinet Office does not hold this information, which department is responsible for setting these standards and ensuring ministers follow them?
More importantly, why does the Cabinet Office not appear to know with certainty who is responsible? Its unexplained redirect hardly inspires confidence. A department at the centre of government should surely know exactly who is responsible for protecting the devices and communications of Cabinet ministers.
Ministers are high-value targets for other states, cybercriminals and other malicious actors. But the consequences of weak security would not necessarily be limited to ministers themselves. A compromised device or insecure connection could expose the personal information and private communications of members of the public.
People do not need access to operational secrets, but they deserve reassurance that clear security standards exist, that ministers are trained to follow them and that compliance is properly monitored.
The government’s wider cybersecurity record gives little room for complacency. The following incidents were not connected to ministers’ devices, but they demonstrate why clear standards and accountability cannot simply be taken on trust.
In 2026, Companies House acknowledged that a security issue introduced during an update to its WebFiling system could allow logged-in users to access non-public information belonging to other companies and potentially make unauthorised filings. The data that may have been affected included dates of birth, residential addresses and company email addresses.[3]
In 2025, the Legal Aid Agency suffered a cyberattack in which attackers accessed and downloaded a significant amount of personal data belonging to people who had applied for legal aid. The affected information potentially included addresses, dates of birth, national ID numbers, criminal histories and financial data.[4]
The National Audit Office also found that all 58 critical government IT systems independently assessed through GovAssure had significant gaps in cyber resilience. It further reported that the government did not know how vulnerable at least 228 legacy systems were to cyberattack.[5]
Against that background, clear security standards and accountability at ministerial level are not optional. They are essential.
VPN use is important for everyone, particularly when connecting through public or otherwise untrusted networks. A reputable VPN encrypts internet traffic between a device and the VPN provider, making it harder for others on the same network to intercept communications or monitor online activity. It does not make somebody anonymous or provide a complete security solution, but alongside encrypted services, strong passwords, multifactor authentication and regularly updated devices, it provides an important additional layer of protection.
These concerns extend beyond ministers’ devices. Even if technically secure, centralised digital identity systems such as GOV.UK One Login and GOV.UK Wallet could give institutions greater power to link people’s identities to services and online activity.[6][7] For me, that presents risks of surveillance and censorship that cannot be solved by cybersecurity alone.
The government’s poor cybersecurity record makes trusting it with more personal information even harder, but perfect security would not remove the more fundamental threat to privacy and individual freedom.
The government is never short of ideas for monitoring the public, yet the Cabinet Office cannot identify the security rules protecting those at the top. It is difficult not to see the double standard: privacy for the government, surveillance for the governed.
Ray Vahey is a free speech and privacy advocate and the founder of BitChute and Blognice.com. His work focuses on protecting open expression, digital privacy and individual control online.
References
- Cabinet Office correspondence, FOI reference FOI2025/12593, acknowledgement dated 31 July 2025 and response dated 25 August 2026.
- Protection of Children Codes of Practice, House of Lords Hansard, 30 October 2025
- Update on Companies House WebFiling security issue, Companies House
- Legal Aid Agency data breach, Legal Aid Agency and Ministry of Justice
- Cyber threat to UK government is severe and advancing quickly, National Audit Office
- Proving your identity with GOV.UK One Login
- GOV.UK Wallet


3 hours ago
7
















.png)






.jpg)



English (US) ·
French (CA) ·