The first Andy Burnham cyber policy signal is continuity, with the new prime minister reappointing Liz Lloyd to a government role even as he dismantles the department that previously housed the brief.
Lloyd was named late Thursday to a junior ministerial post at the Department for Digital, Culture, Media and Sport, while also keeping a second role at the renamed Department for Business, Innovation, Science and Trade. Her exact duties have not been formally published, but Whitehall sources said she is expected to continue handling cybersecurity.
That makes Lloyd a conspicuous survivor of Burnham’s first reshuffle. Burnham removed several figures associated with former Prime Minister Keir Starmer and promoted people linked to Starmer’s political fall. Lloyd had been close to Starmer, serving as his director of policy delivery, and sits in the House of Lords as Baroness Lloyd of Effra rather than as an elected MP.
Burnham was asked by King Charles III on Monday to form a government after Starmer resigned following a Labour Party leadership election. One of Burnham’s early structural changes was to break up the Department for Science, Innovation and Technology, which had been responsible for cyber policy since 2023.
What changed for UK cyber policy under Andy Burnham?
Burnham split the former science and technology department’s work across three places. Cyber policy and government digital services moved to DCMS, science went to the business department, and artificial intelligence policy, including the AI Security Institute, moved to the Cabinet Office.
The change separates AI security from the cyber brief for the first time. Industry figures warned that the split removes the previous department’s combined handling of data, digital capability and AI. Cyber now sits in a department that also carries politically loaded files including online safety and the BBC Charter renewal.
Whitehall sources said Susannah Storey, the permanent secretary at DCMS, has significant cyber experience. They also said officials would still need ministerial backing, which helps explain why replacing Lloyd six weeks before detailed scrutiny of a major bill would have been a nuisance with consequences.
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is the government’s main legislative vehicle for updating cyber rules first set in 2018. It would widen the number of regulated organizations, bring data centers and managed service providers into scope, and set incident reporting deadlines for operators of essential services such as energy, water and health care.
The bill would also give ministers powers to alter the rules and issue directions to companies on national security grounds. Lloyd has been steering it through the House of Lords, where it passed second reading earlier this month with cross-party support. Line-by-line examination is due to begin in September, and the government wants the legislation passed this year.
Lloyd’s cyber record is not only about tighter regulation. She was also the minister responsible when the government moved to soften proposed telecoms cybersecurity measures that had been developed after the Salt Typhoon espionage campaign. Telecoms companies had pushed back against those protections, citing cost and practicality.
Lloyd has also promised a National Cyber Action Plan, a strategy covering how the wider economy should defend itself against criminal and state-backed hacking. Its publication had been expected earlier in July, but was delayed after Starmer’s resignation.
A government spokesperson said cybersecurity was part of daily life and that ministers were acting to improve resilience across the economy. The spokesperson said DSIT’s former functions had been moved to departments where they could have “the most direct impact,” arguing that technology now underpins industry, culture and public service delivery.
This story draws on original reporting from The Record.