Decoding the world of cybersecurity

ONS cyber FOI exposes reporting gaps

An ONS freedom of information response shows how retention limits and security exemptions can narrow public visibility of cyber exposure.

ONS cyber FOI exposes reporting gaps
Summary
  • The ONS says malicious email data is retained for only 30 days, limiting historical disclosure.
  • It disclosed DDoS attempts and said all were mitigated, while withholding unauthorised-access and phishing simulation details under a crime-prevention exemption.
  • The response illustrates the difficulty of comparing public sector cyber exposure when retention, disclosure, and security-risk judgements vary.

The Office for National Statistics has published a freedom of information response that shows how public cyber accountability can be narrowed by data retention limits and security exemptions.

The 22 July response covered requests for malicious email volumes, distributed denial of service attempts, confirmed unauthorised-access incidents, ransomware attempts, and phishing simulation results between 2022 and 2025. The ONS said it does not hold the requested malicious email data because such information is retained for only 30 days.

On DDoS activity, the response says attempts were made against ONS-run websites during the period and that all were mitigated by defensive countermeasures. The wording appears internally inconsistent, referring to two attempts during the period while then identifying one attempt in 2024 and two in 2025. Any follow-up reporting should avoid relying on a precise total without clarification.

The ONS withheld information on confirmed unauthorised access and phishing simulation outcomes under section 31(1)(a) of the Freedom of Information Act, which relates to the prevention or detection of crime. It said disclosure could expose possible vulnerabilities and increase the likelihood of successful attack. The office also said it holds sensitive personal information about businesses and individuals and takes its duty to safeguard that data seriously.

The response is not evidence of a hidden incident. It is a useful example of how public bodies manage cyber transparency. Requests for incident figures can support democratic accountability, but detailed disclosure about unauthorised access, phishing-test results, or defensive weaknesses can also help attackers understand where to apply pressure.

Retention policy creates a separate limitation. If malicious email data is retained for 30 days, historical reporting is not available even where disclosure would be safe. That may be reasonable for operational or storage reasons, but it means long-term trend analysis depends on what each public body records, how long it keeps records, and how it defines incidents.

Public sector cyber metrics are often treated as objective evidence of resilience. In reality, they reflect monitoring coverage, logging maturity, retention periods, legal judgement, operational risk appetite, and willingness to publish. One organisation may disclose counts, another may withhold similar figures, and another may not hold the records. Comparing those responses can confuse better security with better recordkeeping or more cautious disclosure.

The UK may need more consistent models for cyber resilience reporting across public bodies. Aggregated or anonymised data could give Parliament, taxpayers, and oversight bodies a clearer view of exposure without publishing details that would assist hostile actors. Sector-level reporting can also support investment decisions, staffing, incident readiness, and assurance.

The ONS is a particularly sensitive institution because public trust depends on confidence in the handling of population, business, and economic data. Transparency should support that trust, but raw disclosure is not always the safest mechanism. The better test is whether public bodies can show that cyber risk is measured, governed, learned from, and independently scrutinised without providing attackers with a catalogue of weaknesses.

×