Decision
Analysis
outcome: The Cabinet approved the annual Senior Information Risk Officer report for 2024/25, supported investment in enhanced cybersecurity services, initiated a procurement process, covered incident response costs using grant funding, and funded ongoing security monitoring costs from existing reserves.
summary: Enhancing cyber resilience and information risk management for the Borough Council
topline: The Cabinet has decided to enhance cyber resilience and information risk management for the Borough Council.
reason_contentious: This issue may be contentious as it involves financial considerations, risk assessment, and legal implications which could impact the overall operations of the Borough Council.
affected_stakeholders: ["Borough Council", "Senior Information Risk Officer", "Cybersecurity service providers"]
contentiousness_score: 5
political_party_relevance: There are no mentions or implications of political parties or political influence on the decision.
URL: https://democracy.tmbc.gov.uk/ieDecisionDetails.aspx?ID=1883
Decision Maker: Cabinet
Outcome:
Is Key Decision?: No
Is Callable In?: Yes
Purpose:
Content: Consideration was given to the recommendations of the Finance, Regeneration and Property Scrutiny Select Committee in respect of the new Annual Senior Information Risk Officer report for 2024/25, which provided a comprehensive overview of the key activities, achievements and challenges faced by the Borough Council over the past year. Due regard was given to the views of the Scrutiny Select Committee, the financial and value for money considerations, the assessment of risk and the legal implications outlined in the report. The proposals to enhance cyber resilience were welcomed as the importance of ensuring the Borough Council was adequately equipped to address current threats was recognised. Cllr proposed Boughton, Cllr Coffin seconded and Cabinet RESOLVED: That (1) the annual report (attached at Annex 1) providing strategic oversight and assurance on organisational information risk and digital resilience be noted; (2) the proposed investment in enhanced cybersecurity services be supported and a procurement process be initiated; (3) the associated costs for incident response to be covered using available grant funding; and (4) the ongoing operational costs for security monitoring be funded from existing reserves initially and incorporated into the core budget in future financial years.
Date of Decision: September 2, 2025