By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: From breach to resilience: How the Electoral Commission rebuilt its cyber defences | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > From breach to resilience: How the Electoral Commission rebuilt its cyber defences | Computer Weekly
News

From breach to resilience: How the Electoral Commission rebuilt its cyber defences | Computer Weekly

News Room
Last updated: 2025/09/22 at 5:16 PM
News Room Published 22 September 2025
Share
SHARE

When most people think of critical national infrastructure (CNI), they tend to picture energy grids, transport networks, or hospitals. But the UK’s electoral system belongs firmly in that category too. It underpins our democracy, so protecting it from those who seek to disrupt our elections is an essential task. And the threat is real.

Around the world, electoral systems have faced a sharp rise in cyber-attacks in recent years. The UK experienced this first-hand in October 2022 when the Electoral Commission discovered its systems had been accessed in a sophisticated breach. While the attack did not affect the security of our elections, it exposed a number of vulnerabilities in the Commission’s systems and reminded us, and the wider IT community, how underinvestment can leave public bodies exposed.

Like many intrusions, the breach went undetected for longer than it should have. Our protections at the time were not strong enough to prevent the attack, and it took us longer than it should have to uncover. But recognising the scale of the problem became the catalyst for major change. We were able to act quickly alongside the National Cyber Security Centre (NCSC) to remove the compromised systems, clean our network, and eventually rebuild our security infrastructure from the ground up. From the outset we knew this could not be about patching over weaknesses and that it had to be the start of a long-term programme of resilience.

Even before the incident, we had begun a wide-ranging programme of security improvements. Since then, we have accelerated and expanded this work: moving our infrastructure to the cloud, enforcing multi-factor authentication (MFA), upgrading to Office365 E5 licences, and deploying 24/7 monitoring services. Staff now undergo continuous training, and we’ve signed up to the NCSC’s early warning system to detect threats before they escalate. We’ve tripled our annual spend on cyber security and embedded it into every aspect of how we operate. And as well as commanding the confidence of the NCSC and Information Commissioner’s Office, our improved IT systems have now received Cyber Essentials Plus certification for the first time, giving us, and our partners, assurance that we are adhering to the highest standards in information security. Taken together, these changes have given us a level of resilience that is better able to meet the challenges we face. Challenges that show no sign of abating.  

On the day the 2024 UK general election was announced, we blocked two major DDoS attacks to our website, and on polling day itself, our strengthened systems blocked more than 60,000 attempted cyber attacks to our website. This ensured that the million users that visited our site that day were able to find the information they needed about how and where to vote. The lesson for IT leaders is clear: do not mistake your recent successes as the end of the journey. Cyber security is not a destination, but a constant process of monitoring, adapting, and strengthening. The threat landscape evolves daily, and malicious actors innovate just as quickly as the technologies they exploit. Complacency is the most dangerous vulnerability of all.

The Commission’s commitment now extends beyond shoring up our own defences. We are working with the UK’s governments, political parties, and other public bodies to share what we have learned and encourage organisations to strengthen their defences. If we are to maintain public confidence in democracy, every organisation within the electoral community must recognise the risks and be ready to respond to them. The dispersed nature of the UK’s electoral system is one of its strengths, making it harder for any single point of failure to undermine the whole, but that resilience still depends on every part doing its job and functioning correctly.

I would urge peers across IT leadership not to wait for an incident to expose your weaknesses. Invest in resilience now and engage with the right partners. Share learning across sectors. Cyber threats are a reality for us all, in both the public and private sectors. Our security lies in how we prepare and how we respond. For the Commission, the breach of 2021-22 was a wake-up call that provided us with an opportunity to rebuild stronger. Although we have now recovered, we will not take our success for granted. We will continue to ensure our security keeps pace with emerging and existing threats in order to safeguard the democratic process.

Andrew Simpson is head of digital, information, technology and facilities (DITF) at The Electoral Commission.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Instagram Rolls Out Product Tagging to All Users in the US |
Next Article Save $100 on the Apple AirPods Max, our favorite headphones for iPhone users!
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

NIO shares surge as revenue beats estimates, margin improves ·TechNode
Computing
Apple TV+ subreddit to hold AMA with Slow Horses’ Roddy Ho – 9to5Mac
News
Score a free solar panel when you buy the EcoFlow Delta 2 Max portable power station at Amazon for the lowest price ever
News
Photo Dumps: What They Are and How to Start Posting Them |
Computing

You Might also Like

News

Apple TV+ subreddit to hold AMA with Slow Horses’ Roddy Ho – 9to5Mac

2 Min Read
News

Score a free solar panel when you buy the EcoFlow Delta 2 Max portable power station at Amazon for the lowest price ever

4 Min Read
News

Google Gemini Has One Gaming Feature That ChatGPT Can’t Compete With (Yet) – BGR

5 Min Read
News

A new Kindle bug may prevent you from reading some specific books

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?