Decoding the world of cybersecurity

UK cyber brief survives Whitehall restructure

Baroness Liz Lloyd has received joint appointments across two reorganised departments, preserving ministerial continuity as the UK expands cyber regulation and infrastructure oversight.

UK cyber brief survives Whitehall restructure
Summary
  • Baroness Liz Lloyd has been appointed jointly to the government’s reorganised digital and business departments.
  • Her recent ministerial responsibilities have included cyber, telecoms, economic security, digital infrastructure, and technology policy.
  • The government has yet to publish a complete, settled division of cyber responsibilities across the new departmental structure.

The UK government has retained an experienced cyber minister through its latest departmental restructuring, although the final division of policy responsibilities across the new machinery of government has yet to be set out fully in official records.

Baroness Liz Lloyd of Effra was appointed as a parliamentary under-secretary in the Department for Business, Innovation, Science and Trade on 22 July and the Department for Digital, Culture, Media and Sport on 23 July 2026.

She previously served as a parliamentary under-secretary in the Department for Science, Innovation and Technology from September 2025 until the restructuring. The portfolio associated with that role included cyber, telecoms, space, economic security, the Regulatory Innovation Office, digital inclusion and skills, and technology talent.

Official GOV.UK pages were still being updated when reviewed. Lloyd’s personal page records the two new appointments, while the ministerial-role page continues to describe responsibilities through the former departmental structure. Her continued presence provides personnel continuity, although a complete account of which department owns each part of cyber policy has not yet been published.

Cyber responsibilities cut across business regulation, national security, digital infrastructure, public services, economic security, and industrial strategy. Delivery requires coordination with the Cabinet Office, Home Office, HM Treasury, the National Cyber Security Centre, sector regulators, and the departments responsible for essential services.

Lloyd’s recent portfolio has included connected-device security, telecoms, subsea internet-cable resilience, cyber-sector growth, and wider digital-economy policy. Retaining a minister familiar with those areas reduces the loss of institutional knowledge that can accompany the creation, merger, or renaming of departments.

The immediate legislative programme includes the Cyber Security and Resilience Bill. The proposed legislation is intended to update the UK’s network and information systems regime, extend coverage to additional digital and infrastructure providers, strengthen incident reporting, and give government greater flexibility to respond to changing threats.

Passage through Parliament will be followed by a substantial implementation programme. Newly covered organisations will need guidance on scope, reporting thresholds, evidence, regulator expectations, and the treatment of suppliers. Regulators will require resources, technical capability, and a consistent approach to supervision.

The government must also determine how new requirements interact with existing sector rules. Financial services, telecoms, energy, transport, healthcare, cloud providers, datacentres, and managed service providers may already face overlapping security, privacy, continuity, and incident-reporting obligations.

Departmental boundaries can slow that work when ownership of legislation, digital growth, critical infrastructure, and business engagement is divided without a clear route for decisions. Organisations dealing with several regulators need to know which department controls policy, which authority will issue guidance, and where responsibility sits when requirements conflict.

Lloyd’s joint appointment provides a link between the digital and business portfolios. It also places importance on the formal definition of each department’s remit, budget, and decision-making authority, particularly where regulation affects technology investment, market entry, and the obligations imposed on suppliers.

The same policy brief includes the growth of the UK cyber sector, skills, procurement, and secure technology adoption. Measures intended to improve resilience can alter compliance costs and competition, while policies designed to accelerate deployment can create new dependencies across cloud infrastructure, software, connected products, and external service providers.

Continuity at ministerial level gives the government an established point of contact while those responsibilities are reorganised. Updated portfolios will need to confirm how authority is divided and how the new departments will coordinate legislation, regulator engagement, infrastructure resilience, and industry policy.

The Cyber Security and Resilience Bill will provide an early test of that arrangement, since its effectiveness will depend on consistent implementation across sectors rather than the statutory text alone.

×