Skip to content
Data from multiple Freedom of Information (FOI) requests to UK Government Departments, Agencies, and Non-Governmental Bodies relating to Cyber Security spending.
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
README.md

README.md

UK Cyber Security Spending

Project Status: On Going

Data from multiple Freedom of Information (FOI) requests to UK Government Departments, Agencies, and Non-Governmental Bodies relating to Cyber Security spending.

The informaiton contained within this repository was provided under the Freedom of Information Act 2000 / 2002 (Scotland) and is thus free to use. Images below created by myself are also free to use.

If you find this interesting please share it. Consider watching 👓 and/or leave a ⭐️

Contents

  1. Rationale
  2. The FOI Request
  3. Status of Requests
  4. The Data
  5. Copyright
  6. Contact
  7. References
  8. Appendix

Rationale

Cyber Security spending is an indication of the overall security of an organisation and how seriously they take security. The freedom of information requests sent during this project initially target areas of Government, agencies and public bodies whose security can be considered of national importance, and lack of security could be considered a risk to national security. Later, other departments, agencies and bodies will be added to this list.

With states exploring new ways to project their power, protect and enhance their national interests using Cyber; hybrid warfare, the "grey zone" and disruption. The security of Government and Public Bodies providing critical services is paramount.

This is, of course, complex. Public services, such as Ambulance, Police and Fire Services are deciding between protecting people and protecting their infrastructure. This becomes a larger Government issue where national projects, standards, guidelines and ultimately money needs to be provisioned to provide an appropriate level of security nation-wide.

This data can be used to encourage the improvement of cyber security and the overall resilience of the UK.

The FOI Request

Each Department, Agency or Non-Governmental Body was asked to provide the same information (see appendix for full text):

  1. Provide the total amount of money spent on Cyber Security for financial years 2015-18.
  2. The term "Cyber Security" is defined as: "... consider the term to encompass activities relating to information security, computer security and computer network security. Including staff training, consultant services, software and hardware."
  3. Additionaly, "Details on what training and consultant services were for ..."

At the time of the request (December 2018) 1. would provide approximately three years of data.

Status of Requests

Legend

  • Sent 📬
  • Acknowledged 👍
  • Complete: Data Held ✔️
  • Complete: No Data Held / Data Withheld
  • Overdue 🚩

GitHub doesn't allow text highlighting, so icons were used to increase comprehension at-a-glace.

Prime Ministers Office and Ministerial Departments

Recipient Status Ref No. Date Sent Deadline
Prime Minister's Office Sent 📬 03/01/2019 28/01/2019
Attorney General's Office Acknowledged 👍 03/01/2019 28/01/2019
Cabinet Office Acknowledged 👍 FOI327406 03/01/2019 28/01/2019
Department for Business, Energy and Indust... Acknowledged 👍 FOI2019/00136 05/01/2019 01/02/2019
Department for Digital, Culture, Media and... Sent 📬 05/01/2019 01/02/2019
Department of Education Sent 📬 05/01/2019 01/02/2019
Department for Environment, Food and Rur...
Department for Exiting the European Union
Department for International Development
Department for International Trade
Department for Transport
Department for Work and Pensions
Department for Health and Social Care
Foreign and Commonwealth Office
HM Treasury
Home Office
Ministry of Defense
Ministry of Housing, Communities and Local...
Ministry of Justice
Northern Ireland Office
Office of the Advocate General for Scotland
Office of the Leader of the House of Commons
Office of the Leader of the House of Lords
Office of the Secretary of State for Scotland
Office of the Secretary of State for Wales
UK Export Finance

🔝 Back to Top

National and Regional Ambulance Services

Recipient Status Ref No. Date Sent Deadline Response
East of England Complete ✔️ 18862 13/12/18 ~16/01/19 03/01/2019
East Midlands Complete ✔️ FOI 18-785 13/12/18 ~16/01/19 11/01/2019
London Withheld 3366 13/12/18 ~16/01/19 03/01/2019
North West Complete ✔️ FOI1371 13/12/18 ~16/01/19 10/01/2019
North East Complete ✔️ FOI.18.316 13/12/18 ~16/01/19 14/0/2019
South Central Sent 📬 13/12/18 ~16/01/19
South East Coast Complete ✔️ FOI/18/12/29 13/12/18 ~16/01/19 11/01/2019
South Western Complete ✔️ FOI 2910 13/12/18 ~16/01/19 08/01/19
West Midlands Sent 📬 13/12/18 ~16/01/19
Yorkshire Acknowledged 👍 2018/19-346 13/12/18 ~16/01/19
Northern Ireland Not Held AD/IG/01(2)/197-18 13/12/18 ~16/01/19
Welsh Complete ✔️ 23918 13/12/18 ~16/01/19 15/01/2019
Scottish Acknowledged 👍 None given 13/12/18 ~16/01/19
Guernsey
Isle of Man
States of Jersey

Deadline dates are approximations due to difficulty calculating during Christmas holiday period.

Notes on National and Regional Ambulance Services Responses

🔝 Back to Top


The Data

Prime Ministers Office and Ministerial Departments

There are 24 Ministerial Departments within the UK Government along with the Prime Minister's Office[1].

Prime Ministers Office

Attorney Generals Office

Cabinet Office

Department for Business, Energy and Industrial Strategy

Department for Digital, Culture, Media and Sport

Department of Education

Department for Environment, Food and Rurual Affairs

Department for Exiting the European Union

Department for International Development

Department for International Trade

Department for Transport

Department for Work and Pensions

Department for Health and Social Care

Foreign and Commonwealth Office

HM Treasury

Home Office

Ministry of Defense

Ministry of Housing, Communities and Local Government

Ministry of Justice

Northern Ireland Office

Office of the Advocate General for Scotland

Office of the Leader of the House of Commons

Office of the Leader of the House of Lords

Office of the Secretary of State for Scotland

Office of the Secretary of State for Wales

UK Export Finance


National and Regional Ambulance Services

There are sixteen Ambulance Services within the United Kingdom; one each for Scotland, Northern Ireland, Wales, the Isle of Man, Jersey, Guernsey, and ten in England[2].

Engand

East of England Ambulance Service

Broad Category 2015/16 2016/17 2017/18
Computer Security £6,000 £6,000 £6,000
Network Security £11,000
Hardware & Associated Support £52,000 £52,000
Consultnacy £12,050

East Midlands Abmulance Service

Broad Category 2015 2016 2017 2018
Network Security £133,455.52† £1,275 £1,275 £111,182.50
Endpoint Security £25,416 £40,830 £22,987
Staffing £34,580 £34,580 £85,957 £85,957
Consultnacy £12,950.00†

Note the £133,455.52 spent on Network Security in 2015 also provided endpoint security. The consultancy that year was configuration of the purchase.

London Ambulance Service

LAS withheld the requested informaiton under the following two exemptions:

  • s.21 Information reasonably accessible to the applicant by other means. This refers to their annual accounts in which they break down their annual budget. However, this does not include all of the information requested, it contains data related to the broad category of IT. Additionally, this only includes expenditure over £25,000.

  • s.43(2) Prejudice to commercial interests "in respect to information on expenditure within the categories you have highlighted and that is not already publicly available, we have carried out the public interest test and have concluded that disclosure of this information could prejudice the commercial interests of the Trust and, therefore, that the public interest in withholding this information outweighs the public interest in disclosure."

North West Abmulance Service

North East Abmulance Service

Broad Category 2015 2016 2017 2018
Network Security £4,175 £4,175 £57,375† £4,000
Staffing - - - -
Consultnacy £2,850 £3,110 £3,110 £5,700

Staffing figures not provided. Figures were provided in more specific categories. Figures mapped to appropriate broad categories.2017 includes capital expenditure for improvements to network permimeter security.

South Central Abmulance Service

South East Coast Abmulance Service

Financial Year Total
2015/16 £46,484
2016/17 £102,919
2017/18 £56,455
2018/19 £896,288†

2018/19 increase in investment due to funding secured from NHS Digital.

Data not provided in requested format of broad categories due to "To break this down as requested above would require a manual review of each invoice which would exceed 18 hours and is therefore exempt under Section 12- FOI".

South Western Abmulance Service

Financial Year Total
2015 £5k-10k
2016 £15k-20k
2017 £10k-15k
2018 £10k-15k

Data not provided in requested format of broad categories due to "The Trust considers that disclosing information regarding our IT systems could undermine the Trust’s security arrangements and that, in turn, this would be likely to endanger the safety of patient’s and Trust staff. As such, the Trust takes the view that, although we hold this information, it is exempt from disclosure under s38 of the Freedom of Information Act".

West Midlands Abmulance Service

Yorkshire Abmulance Service

Northern Ireland

Northern Ireland Ambulance Service does not hold the data in the format requested, nor is it readily or easily obtainable. I was referred to the Annual Accounts, as these hold broad expenditure on IT. This is far to vague to appear in this list.

If you wish to view this general informaiton you can find their Annual Reports & Accounts under Reports > Annual Reports & Accounts.

Northern Ireland Ambulance Service

Wales

Welsh Ambulance Service

Broad Category 2015/6 2016/7 2017/8
Information Security £6,076 £18,894 £20,403
Computer Security £13,200 £26,592 £28,581
Network Security £5,337 £46,947 £54,727
Total £24,613 £92,793 £103,256

Scotland

Scottish Ambulance Service

Islands

Guernsey Ambulance and Rescue Service

Isle of Man Ambulance Service

States of Jersey Ambulance Service

⬆️ Back to Contents


Copyright

The data contained within this repository was obtained via Freedom of Informaiton requests, as such the informaiton is within the public domain and free to use. Any images or such created by myself contained within this repository are also free to use.

Contact

You can contact me at: alt [dot] krisb [at] gmail [dot] com

References

  1. UK Government Departments, Agencies and Public Bodies
  2. Association of Ambulance Chief Executives (AACE): Map of Member Ambulance Services

Appendix

Freedom of Information Request Letter

This letter was sent to all Ambulance Services and the first three ministerial departments.

Dear [...],
I am writing to request specific information under the freedom of information act 2000.
Could the Service provide the total amount of money spent on Cyber Security within the service for the individual financial years from 2015 – 2018. If possible, segmented by broad categories such as those listed below.
Cyber Security can be a difficult term to define, in this case, please consider the term to encompass activities relating to information security, computer security and computer network security. Including staff training, consultant services, software and hardware.
Details on what training and consultant services were for would be useful. It is not advisable to disclose specific names or versions of software and hardware relating to security.
Thank you.
Kind Regards,
Kris Bolton

This letter was sent to the remaining ministerial departments, police forces and fire services.

To whom it may concern,
I am writing to request specific information under the freedom of information act 2000.
Could the Department provide the total amount of money spent on Cyber Security within the Department for the individual financial years from 2015 – 2018. If possible, segmented by broad categories such as those listed below.
Cyber Security can be a difficult term to define, in this case, please consider the term to encompass activities relating to information security, computer security and computer network security. Including staff training, consultant services, software and hardware. Details on what training and consultant services were for would be useful.
This information is in the public interest to ensure the Department is taking cyber security seriously and compare expenditure to other departments. Please consider this when reviewing this request. It is not advisable to disclose specific names or versions of software and hardware relating to security.
Thank you.
Kind Regards,
Kris Bolton

🔝 Back to Top


The Use of GitHub

GitHub is designed for software version control. Apart from its distributed nature allowing collaberation and redundancy, a main feature is the ability to log and view changes between additions (commits) and attribute them to a user. As a result GitHub, and other public distributed version control repositories are ideal for creating and storing datasets such as this one. Users can view every change from the projects creation. Commented and used well by the creator, the reason for each change is recorded.

Additionally, the use of GPG Keys can confirm the ID of the user committing changes to a repository.

To view the commit history click the number of commits listed on the main repository page

You can’t perform that action at this time.