ProBackend
cloud security incidents
1 day ago6 min read

Security & Compliance in the Whitehall Shuffle: Burnham's Tech Split and the AI-Legacy Schism

How Andy Burnham's dissolution of the technology minister role and fragmentation of DSIT across three Whitehall departments creates incoherence between AI strategy and practical security & compliance governance.

Security & Compliance in the Whitehall Shuffle

Andy Burnham's made his mark on Whitehall's machinery of government, and the scars are already showing. The UK's seventh Prime Minister in a decade just dissolved the dedicated technology minister role, scattered DSIT's responsibilities across three departments, and left public sector tech leaders wondering which way's up. For anyone tracking security & compliance across government systems, this isn't just bureaucratic rearranging — it's a fundamental fracture in how the UK manages its digital estate, vendor relationships, and the AI ambitions that were supposed to save £45 billion in efficiency savings.

Let's be honest: throwing a spanner into the works of government tech delivery doesn't exactly inspire confidence. But Burnham's reorganisation goes beyond mere confusion. It creates a structural schism between AI strategy and the practical reality of managing legacy systems, procurement, and vendor lock-in that could haunt the government for years.

The Great Whitehall Scramble: Three Departments, Zero Clarity

Burnham's decision to break up DSIT and distribute its responsibilities across the Cabinet Office, the Department for Business, Innovation, Science and Trade (BIST), and the Department for Digital, Culture, Media and Sport (DCMS) wasn't subtle. It was a full-blown reorganisation that left everyone playing catch-up.

The Government Digital Service — created in 2011 under David Cameron's Conservative government, moved to DSIT in 2024 by Keir Starmer, and now shuffled a third time to DCMS under Burnham — has been on a merry-go-round that would make any security & compliance officer's head spin. GDS now shares DCMS with the Digital Commercial Centre of Excellence, which Starmer's government designed to help public sector organisations stand up to global tech giants like Microsoft, Amazon, and Oracle.

Here's the problem: Ian Murray, DCMS's only "digital" minister, doesn't hold a Cabinet position. His brief has been squeezed between digital inclusion, online harms, and actual government technology delivery. These aren't trivial issues, but they're wildly different from making the government's ailing legacy systems work. And they're far more emotive, far noisier in terms of media attention.

Any changes Murray tries to drive through have to contend with Dame Antonia Romeo, appointed Cabinet Secretary and Head of the Civil Service on 19 February 2026. People with close knowledge of Whitehall aren't rating his chances.

Vendor Lock-In: The Problem Nobody's Fixing

In April 2024, The Register reported on documents from the Cabinet Office's Central Digital & Data Office warning that the government's commercial dealings with dominant cloud vendors risked "concentration and vendor lock-in that inhibit the UK government's negotiating power." That was two years ago. The problem hasn't gone away — if anything, it's gotten worse.

Consider this: the UK tax collector awarded £3.8 billion to three incumbent tech suppliers in January 2025 alone, including £591 million without any outside competition. These were part of a £10 billion deal from 2004 that was only supposed to last ten years. Ten years. We're now dealing with the aftershocks of contracts signed when social media was still figuring out whether it was going to be a thing.

The government's £9 billion agreement with Microsoft only deepened the problem, with enterprise deployments like Microsoft 365 locking departments into single-vendor ecosystems. These centralization pressures are comparable to modern cloud security dynamics highlighted in Microsoft's agentic defense strategy. Meanwhile, the government frequently awards billions in IT contracts to incumbent tech giants, apparently through lack of investment in commensurate internal technical and commercial skills.

Anyone expecting DCMS to suddenly develop the muscle to negotiate better terms with Microsoft, Amazon, or Oracle is going to be disappointed. Those responsibilities now sit within a department already juggling BBC oversight, Premier League decisions, and online harms policy. Good luck with that.

AI at the Table, Legacy Systems on the Curb

Enter Kanishka Narayan, the new AI minister appointed to work jointly with the Cabinet Office and BIST and attend Cabinet meetings. His mandate: lead an AI Taskforce housed in the Office for the Prime Minister and the Cabinet to "drive the government's overall strategy on AI and unlock the opportunities it holds for growth, prosperity and public sector transformation." The taskforce also reports to Romeo and is supposed to "deliver the Prime Minister's AI agenda."

Sounds ambitious. It is. The problem is that responsibility for getting to grips with legacy systems, public sector data, and commercial relationships with tech giants now sits entirely apart from the mission to use AI to transform the public sector. Unless leadership aligns governance with broader organizational oversight, such as building board capabilities in an AI era, these initiatives will flounder.

This schism is the heart of Burnham's mistake. You can't build effective AI strategy on top of broken infrastructure. You can't negotiate vendor contracts while simultaneously promising £45 billion in efficiency savings through automation and AI — a claim that experts met with skepticism and MPs described as a distraction.

Peter Kyle's agreement with Google last year, aimed to "upskill up to 100,000 civil servants in the latest tech by 2030," turned out to have no contractual teeth. That's the kind of publicity hit tech companies love, but it's not the kind of commitment that builds real capability.

What This Means for a Security & Compliance Analyst

For any security & compliance analyst monitoring government systems, Burnham's reorganisation raises several urgent questions:

Where does accountability sit now? With GDS, the Digital Commercial Centre of Excellence, and the AI Taskforce all potentially operating in different silos, who's actually responsible when something goes wrong? The answer, currently, appears to be "nobody's clear," which is every security officer's worst-case scenario.

How does vendor management work across departments? When three departments (Cabinet Office, BIST, DCMS) share responsibility for technology decisions, procurement coordination becomes nearly impossible. You've got competing priorities, competing ministerial attention, and no single authority making the calls.

What happens to the £45 billion efficiency savings promise? The previous government made this commitment in January, promising to find those savings through automation and AI. With the machinery of government now scattered, the roadmap for modern digital government — which promised to transform how "the whole of the public sector" uses technology — faces serious delivery risk.

Can the government actually stand up to its cloud providers? The Central Digital & Data Office's 2024 warning about concentration and vendor lock-in remains unaddressed. If anything, splitting responsibilities makes it harder, not easier, to develop the kind of technical and commercial capability needed to negotiate better terms with Microsoft, Amazon, Oracle, and the big four consultancies.

The Silver Lining (Small as It Is)

Burnham did cancel plans for a national digital ID scheme. That was an uncosted solution looking for a problem, and scrapping it saves money and privacy concerns alike. Small victories count, even when they're the only ones available.

But something is missing at the heart of these changes. Responsibility for getting to grips with legacy systems, public sector data, and commercial relationships with tech giants now sits entirely apart from the mission to use AI to improve prosperity and transform the public sector. Unless the government addresses that schism, Burnham's decision to throw a spanner in the machinery of government could come back to haunt him — and the security & compliance implications are already visible to anyone paying attention.

The question isn't whether this reorganisation creates confusion. It clearly does. The question is whether anyone in Whitehall has the political will to fix it before the next prime minister gets elected.

Security & Compliance in the Whitehall Shuffle: What Burnham's Tech

More blogs