Editorial

Think Digital Identity and Cybersecurity for Government 2026: 10 key takeaways

From the rollout of GOV.UK One Login and digital credentials to deepfakes, AI-enabled cyberattacks and the need to prepare public services for disruption, speakers at Think Digital Identity & Cybersecurity for Government set out some of the biggest challenges facing the public sector.

Posted 1 October 2026 by Christine Horton


Digital identity and cybersecurity are becoming increasingly intertwined as government moves more services online while facing faster moving and more sophisticated threats.

Think Digital Identity & Cybersecurity for Government brought together speakers from across central government, agencies, local government, the NHS, academia and industry to discuss how government can build trusted digital services while improving its ability to withstand attacks and disruption.

Here are 10 takeaways from the day.

1. Digital identity is becoming part of everyday government

GOV.UK One Login now has more than 23 million accounts and is used across 256 services, according to Natalie Jones, director for One Login and Verified Credentials at GDS.

The next phase extends beyond signing into government. Jones pointed to GOV.UK Wallet and verified credentials as ways for people to prove specific facts about themselves while sharing only the information required.

But inclusion remains critical. GDS is introducing more ways to prove identity, including using government-held information and, in future, open banking, while Jones stressed that alternative routes would remain necessary for people unable to use digital services.

2. A single front door isn’t the same as a single identity scheme

One Login provides a common route into central government services, but that’s different from creating a single identity scheme or identifier.

Dr Louise Maynard-Atem made that point during a panel alongside Post Office head of identity Jason Sheehy and Professor Edgar Whitley of the London School of Economics.

Whitley questioned whether enough attention is being given to redesigning the services behind the ‘front door’ of identity, while the panel highlighted interoperability between public and private sector identity services as important to avoiding another fragmented landscape.

3. Humans can no longer reliably spot deepfakes

Attendees heard how the growing sophistication of synthetic media means organisations can’t rely on people recognising when something is fake.

Zac Ghaffar of the Home Office’s Accelerated Capability Environment (ACE) said deepfakes have effectively crossed the “uncanny valley”, with synthetic content in some formats becoming imperceptible to humans.

Speakers from the Home Office, National Crime Agency and Ministry of Defence discussed threats ranging from synthetic identities and fraudulent documents to cyberattacks and misinformation. Their message was that technology alone won’t solve the problem: government also needs better threat intelligence, assurance, processes and layered controls.

4. Digital identity can reduce fraud – but it’s not a silver bullet

Identity verification can make fraud harder, but services also need to examine the processes surrounding it.

Andrew Williams of Companies House explained how identity verification is being used as part of efforts to prevent companies being used for fraud and economic crime.

Jeb Cordery of the Driver and Vehicle Standards Agency (DVSA) described fraud prevention as a “Swiss cheese” model in which different controls work together. Strong digital identity therefore needs to sit alongside appropriate processes, consistent assurance and customer support rather than being treated as a standalone answer.

5. AI is accelerating the cyber arms race

AI could fundamentally change the speed at which cyber attackers find and exploit vulnerabilities, according to Cameron Prescott-Young director of cyber advisory & assurance services at Atos.

He argued that existing vulnerability and patch management processes may struggle to keep pace with machine-speed attacks.

Atos is developing an approach that uses AI to model potential attacks, prioritise vulnerabilities and orchestrate remediation more quickly. Prescott-Young also stressed the risks associated with defensive AI itself, however, with human oversight remaining important where automated action could cause disruption.

6. Climate resilience is becoming part of digital resilience

The audience also heard how cybersecurity can’t be separated from the physical infrastructure on which digital services depend.

Ishmael Burdeau of DWP Digital and Ben Tongue of NHS England discussed how climate-related events can affect infrastructure, energy, supply chains, workplaces and ultimately public service delivery.

The discussion also highlighted the environmental impact of expanding digital infrastructure and AI. For public bodies, resilience increasingly means understanding both how environmental disruption affects technology and how technology itself contributes to environmental pressures.

7. Government is entering a ‘decade of resilience’

After years focused heavily on digital transformation, government now needs to think much more seriously about how services operate when things go wrong.

Breandán Knowlton-Hung, deputy government CISO, described the coming period as a potential “decade of resilience”.

That means designing for degraded circumstances, understanding dependencies and being able to restore interconnected services and data quickly under pressure. Rather than assuming disruption can always be prevented, resilience requires government to prepare for failure and limit its impact when it occurs.

8. ‘Defend as one’ has to extend beyond Whitehall

Government’s ambition to “defend as one” depends on shared cyber capabilities reaching local authorities, arm’s-length bodies and other smaller organisations.

CxB’s Jessica Figueras said access to capability remains one of the biggest barriers to improving cyber resilience, particularly for smaller organisations.

Alongside representatives from DWP and MHCLG, the discussion highlighted work to share intelligence, skills and lessons across organisational boundaries. The challenge is therefore not simply building central capabilities, but making sure organisations across the wider public sector know what support exists and can use it.

9. Secure by design should be an operating model, not a checkpoint

Security needs to become part of normal delivery rather than something applied towards the end of a project.

Dena Habashi-Ayub of HMRC described secure by design as an “operating model rather than a security checkpoint”, with security incorporated into architecture, APIs, platforms, engineering and deployment.

That also requires a culture in which teams can identify and raise risks early. Secure defaults and reusable patterns can reduce the burden on individual delivery teams while making security part of how services are built rather than an additional hurdle before launch.

10. Plan for operating through a crisis – not just recovering afterwards

The closing panel (pictured) brought many of the day’s themes together around a fundamental question: what happens when critical digital services are actually disrupted?

DVSA CDIO Tina Hibbett argued that organisations need to consider not only how technology will be restored, but how people and services will operate while disruption is happening.

With government increasingly dependent on interconnected identity, data, cloud and digital infrastructure, resilience planning must account for those dependencies. Speakers also stressed the value of sharing lessons from organisations that have already experienced cyber incidents rather than waiting to learn them again.

The message from across the day was that digital identity, cybersecurity and resilience can no longer be treated as separate disciplines. As public services become more connected, government needs to build trust into those services while preparing for the possibility that some of the systems they depend upon will fail.

Event Logo

If you are interested in this article, why not register to attend our Think Digital Identity and Cybersecurity for Government conference, where digital leaders tackle the most pressing issues facing government today.


Register Now