Skillcast Blog

Managing the Cybersecurity Compliance Challenge in the Public Sector | Skillcast

Written by Sofia Chaqiri | 04 Aug 2026

Public sector organisations rightly attract intense public and regulatory scrutiny. They must adhere to strict privacy standards and financial controls, all while handling sensitive personal information and remaining accountable to the public.

The impact of failing to comply with regulations extends far beyond financial loss. Critical services could also be disrupted, including access to care, security and education. Breaches also damage some members of the public’s already fragile trust in institutions, making them less likely to engage.

Cyber threats have escalated this risk significantly in recent years. With attackers routinely targeting public infrastructure, maintaining robust cybersecurity has quickly become the most urgent compliance challenge facing the public sector today.

In this article, we examine what our latest research reveals about employee behaviour, how cyber threats to the public sector have evolved, and how organisations can strengthen compliance by building better cybersecurity habits.

Key takeaways

  • Recent Skillcast data shows that 61% of public sector professionals feel only somewhat confident in identifying a targeted cyber threat to their organisation, while over 38% have either never received interactive cybersecurity training or have not had any in the past year.

  • Cybersecurity has become the public sector’s biggest compliance challenge as cyber criminals increasingly target employee behaviour instead of technical systems.
  • Artificial intelligence has made phishing and social engineering attacks more convincing, placing greater importance on routine decisions such as handling emails, payments and sensitive information.

  • Strong policies must be supported by practical training, regular reinforcement and an open reporting culture to help public sector employees recognise and respond to cyber threats.

What our research reveals about cybersecurity in the public sector

Skillcast’s recent report on cybersecurity in the public sector suggests that many organisations are not preparing their teams adequately to spot and deal with potential cyber threats:

Most employees are not completely confident they could identify a sophisticated phishing attack targeting their department, highlighting how convincing AI-generated phishing attempts have become.

More than a quarter of respondents have received little or no recent interactive cybersecurity training.

Nearly half of respondents use work devices for personal activities, increasing opportunities for phishing and other forms of social engineering.

Around one in five employees would hesitate, or are unsure whether they would report accidentally clicking a suspicious link immediately, potentially delaying an organisation's response to an incident.

More than half of respondents are only somewhat familiar with their organisation's cybersecurity policy, suggesting there is still room to improve employees' understanding of how those policies apply in practice.

“There are a few structural reasons why the public sector is more exposed to cyber threats. Many organisations are operating within tight budgets, and that can limit investment in cyber defences and training. Staff often don’t recognise that the sensitive data they work with – personal details and health records, for example – can be just as vulnerable to hackers as financial or commercial information.

“The need to interact with the general public also works against strict procedures sometimes. Because staff are dealing with a high volume of requests across multiple channels, they’re under pressure to get things done quickly and efficiently. In that kind of environment, even the strongest controls can be bypassed or applied inconsistently.”

– Dr John Kingston, Senior Lecturer in Cyber Security, Nottingham Trent University.

Why cyber attacks on the public sector are becoming more common

For many years, organisations could reduce the risk of cyber attacks by investing in stronger technical controls. Firewalls, antivirus software and secure networks used to be the best form of cyber defence – and they are still essential.

But cyber attackers are increasingly diverting their attention towards human behaviour, using a tactic known as social engineering to mislead individuals into sharing sensitive information or granting access to internal systems.

Artificial intelligence tools have made this tactic much easier to deploy at scale, with attackers now producing convincing phishing attempts and highly personalised messages almost instantly. In this context, actions as simple as opening an email, approving a payment or responding to an unexpected request all carry new compliance risks.

Recent incidents show how varied those dangers have become. In 2025, the Legal Aid Agency suffered a breach that exposed the personal information of 2.1 million people after longstanding concerns about vulnerable IT systems went unheeded.

The Ministry of Defence was also affected when a third-party supplier exposed the details of 3,700 Afghan refugees. Elsewhere, the Post Office accidentally left unredacted personal information online for almost two months, while criminals used stolen details to create fraudulent HMRC accounts and claim £47 million in tax rebates.

These incidents confirm that compliance failures no longer stem solely from organisations misunderstanding regulations or failing to implement the right policies. Increasingly, they happen because cyber criminals exploit human judgement and hijack routine decisions.

How to strengthen compliance in the public sector

Cyber attacks will continue to evolve, but the principles of good compliance remain the same. Organisations reduce risk most effectively when they help employees recognise threats, make informed decisions and feel confident reporting concerns. The following steps can help strengthen your organisation’s compliance culture while also reducing exposure to cyber risk.

Identify and manage risks proportionately

Public sector bodies face diverse threats, from financial fraud to sophisticated cyber attacks. Leaders must check internal systems and third-party suppliers regularly to understand where their departments are exposed.

Sorting these risks by severity helps you prioritise where to spend your time and money, and ensures your policies and practices remain flexible as risks evolve.

Train staff regularly

Compliance risks and regulations evolve quickly, and knowledge fades if it is not reinforced. Short, regular sessions make it easier for staff to recall best practices, ultimately making it easier to behave compliantly than to make mistakes.

Tools that support ongoing, targeted training – such as Skillcast’s FastTrack – help organisations deliver regular compliance updates without forcing their staff to retake sessions on topics they have already mastered.

Make training relevant to real work

Training is more effective when it reflects the situations public sector workers face every day, such as handling supplier requests, managing sensitive data or responding to unexpected messages.

Recreating realistic scenarios helps staff recognise risks and understand what to do in the moment, rather than relying on their memory of a policy or piece of legislation they read months ago.

Don’t overlook the basics

Simple acts of vigilance are still essential, particularly when it comes to cybersecurity.

Strong passwords, multi-factor authentication, caution with links and limiting downloads all reduce risk. It’s easy for standards to slip when teams are busy, but sometimes the simplest solutions are the most effective ones.

Make it easy to check and report

Staff are more likely to act carefully if they can quickly sense-check something that does not look right. Clear reporting processes are essential, as well as easy access to up-to-date guidance.

A single, reliable source of policies and procedures means staff can quickly check how to handle a request, whether to share information or when to escalate a concern. Interactive AI tools like Skillcast’s Aida can support this by providing quick, consistent, reliable answers to common questions.

Make sure any new guidance or reporting procedures are simple and proportionate to the risks involved, as too many rules can quickly overwhelm staff.

Build an open culture that encourages honest reporting

Employees report mistakes quickly when they know managers will support them rather than penalise them.

Treating a compliance error as an opportunity to improve training and security – rather than an opportunity to punish the offender – helps staff feel comfortable admitting when something goes wrong, and makes them less likely to hide their mistake.

A simple and supportive escalation process ensures workers raise concerns quickly and openly, allowing your organisation to catch compliance errors before they evolve into serious breaches.

Reinforce expectations as often as possible

Compliant behaviour only becomes routine if it is reinforced and rewarded. That can be as simple as recognising employees who report suspicious activity, following up after training with reminders, or using internal communications to highlight common risks and recent incidents.

Managers and leaders, in particular, must set clear expectations and lead by example. A message from the CEO or a senior leader instantly demonstrates that compliance is important to everyone in the organisation, regardless of seniority.

If junior staff see compliance training as simply another administrative job that only applies to them, they will take it much less seriously. Poor role models make it much harder for staff at every level to make the right choices.

Want to strengthen compliance across your public sector organisation?

Our Public Sector Compliance Hub brings together practical e-learning on the key risks facing public bodies, including courses on cybersecurity, data protection and fraud prevention designed specifically for public sector organisations.

FAQs on cybersecurity in the public sector

Why is cybersecurity a compliance issue in the public sector?

Public sector organisations hold some of the country's most sensitive information, from health records to financial and criminal justice data. Protecting that information is a fundamental compliance responsibility, and the growing sophistication of cyberattacks has made it one of the sector's most significant challenges.

What are the biggest cybersecurity risks facing the public sector?

Public sector organisations face a wide range of cyber threats, including phishing attacks, social engineering, ransomware, data breaches and risks introduced through third-party suppliers. Many of these attacks now target employee behaviour rather than technical systems, making it essential for organisations to combine robust security controls with practical training and clear reporting processes.

How can public sector organisations improve cybersecurity compliance?

Improving cybersecurity compliance requires more than strong technical controls. Organisations should provide regular, practical training, reinforce clear policies throughout the year and create a culture where employees feel confident questioning unusual requests and reporting concerns quickly. Together, these measures help staff make better decisions while reducing the likelihood of compliance failures.

What is social engineering in cybersecurity?

Social engineering is a technique that manipulates people into sharing confidential information or granting access to systems. It often involves convincing emails, phone calls or messages that appear to come from trusted sources.

How often should public sector employees complete cybersecurity training?

Cybersecurity training should be delivered regularly throughout the year using practical, scenario-based learning that reflects evolving threats, rather than relying solely on annual refresher courses.