External auditors issue key governance recommendation over council cyber attack
- Details
Kensington and Chelsea Council has been told it must improve its IT systems and cyber security training after a cyber attack last year disrupted several services and led to data theft.
The cyber incident was the result of a phishing attack that impacted Kensington and Chelsea Council, Westminster City Council and Hammersmith and Fulham Council – who all share a number of IT systems and services.
Kensington and Chelsea said it took immediate action in November 2025 after noticing unusual activity, disconnecting the council’s IT infrastructure from the internet.
The council later reported that it had found evidence that some data had been stolen as a result of the attack.
In an update in July this year, the council said it was still working to get some residents’ services back online, although most affected services had been restored.
In its annual report on the local authority, external auditors Grant Thornton found significant governance weaknesses in relation to the attack – and raised a key recommendation calling for the council to improve training, change its cyber security strategy and invest in a series of IT system upgrades.
The report – which was considered by the council’s Audit & Transparency Committee last week – notes that the attack was the result of “human error” following a phishing attempt.
Grant Thornton said the attack exposed the need for Kensington and Chelsea to improve its IT infrastructure and staff training.
The report said: "One factor in the incident and time to recover, is the need for the Council to strengthen its IT estate. Notably, certain systems require internet connection to operate, rather than the Council having invested in Software as a Service (SaaS) solutions.
"This meant that when the incident occurred the Council had to disconnect systems from the internet to limit data copying, but meant systems could only run offline.
“This system shut-down has impacted the Council operationally and financially, creating a backlog in several services’ case loads and revenue received by the Council from resident payments."
The auditor’s key recommendations call on the council to:
- develop a costed, prioritised plan to invest in system upgrades across Council services, evaluating SaaS and offline options, strengthening resilience against future cyber incidents;
- rebalance its cyber security strategy to give equal weight to prevention alongside existing reactive incident response arrangements;
- Increase the frequency, intensity and uptake of cyber awareness training for all staff, ensuring this includes a focus on phishing awareness.
Since the attack, the council has already launched a cyber resilience programme of strategic rationalisation and centralisation of controls to improve oversight and reduce technical debt and associated risks going forwards.
It has also made cyber awareness training, including phishing awareness for staff and for members, mandatory.
Adam Carey


