• Have a question? Call us : +44 (0) 1256 744 780

  • Have a question? Call us :+44 (0) 1256 744 780

Press Release: How The UK’s Recent Cabinet Changes Could Impact Cybersecurity

Published On: August 17, 2026/Categories: Cyber Security News/3.6 min read/

What the UK’s Cabinet Reshuffle Means for Cybersecurity Leaders

When Prime Minister Andy Burnham reshaped his cabinet in July, cybersecurity moved with it. The Department for Science, Innovation and Technology (DSIT) has been dissolved, with its responsibilities split three ways: cybersecurity, telecoms and digital policy now sit within an expanded Department for Digital, Culture, Media and Sport (DCMS); AI strategy and the AI Security Institute have moved to the Cabinet Office; and science and industrial technology have gone to a new Department for Business, Innovation, Science and Trade.

On paper, this is machinery of government. In practice, it raises real questions for anyone responsible for resilience.

A well-formed function, now split three ways

Yogesh Agarwal, CEO at RightCue, has been vocal about the risk this creates. Commenting on the changes, he noted that the government has “effectively split up a well-formed function into three separate departments” and that this matters because AI and cyber are so closely linked. AI systems create new attack surfaces, while cyber controls are what protect the data, models and infrastructure AI depends on. Separate the two in government, and there’s a risk that regulation, guidance and accountability become less joined up than they need to be.

Other experts interviewed alongside Agarwal share the concern. Grace Carter, government affairs counsel at Elastic, points out that cybersecurity now moves to a department where it doesn’t feature in the name or the primary remit, a contrast she calls “hard to ignore” given the Cyber Security and Resilience Bill is still working its way through parliament.

Yogesh Agarwal, CEO at RightCue, believes the new prime minister has “effectively split up a well-formed function into three separate departments.”

This matters because AI and cyber are so closely linked, says Agarwal. “AI systems create new attack surfaces, while cyber controls are needed to protect the data, models, systems and infrastructure that AI depends on. If AI governance and cyber resilience sit in different parts of government, there is a risk that regulation, guidance and accountability become less joined up.”

The bill to watch

That bill remains the most significant piece of cyber policy in progress in the UK, and reorganisations like this one have historically slowed things down, not through any deliberate change of direction, but through the practical disruption of ministers settling in and officials being redeployed. Legal commentary from Pinsent Masons has already flagged that this could add delay to an implementation timeline that was expected to extend towards 2029.

The consensus among the experts is that the overall direction of travel for UK cyber regulation isn’t changing. What’s less certain is the timing, and who organisations should be talking to as the new departmental lines settle.

What this means in practice

For businesses, the immediate risk isn’t a change of policy, it’s a change of clarity. As Agarwal puts it, organisations need to know “who owns cyber policy, who is responsible for upcoming regulation, and which department they should engage with.” Where that becomes unclear, there’s a natural temptation to wait for things to settle before acting.

Our view is the opposite. Political and structural change may affect timing and ownership, but it shouldn’t delay preparation. The regulatory direction is clear regardless of which department is holding the pen: organisations should keep strengthening resilience, improving oversight of suppliers and third parties, and making sure AI and cyber risk are governed together rather than in separate silos.

The UK’s Cyber Security Pledge, a straightforward way for organisations to demonstrate their commitment to security — is still very much in place, and remains a sensible starting point for anyone unsure where to focus first.

The takeaway

Government departments will keep reorganising; that’s normal. What matters for cybersecurity leaders is not getting distracted by where responsibility sits on an org chart, and instead staying focused on the fundamentals that don’t change with a reshuffle: supplier oversight, joined-up AI and cyber governance, and readiness for regulation that is coming, even if its exact timing is now a little less certain.

Source: SC Media UK, “How The UK’s Recent Cabinet Changes Could Impact Cybersecurity”, 10 August 2026.

Follow us for more RightCue insights

Is your cyber governance ready, whoever ends up owning policy?

RightCue helps organisations build supplier oversight, AI governance and evidence-ready resilience that holds up no matter which department is in charge.

Related articles & guides

Go to Top