The Greenwich Pension Fund faces a Significantly High Risk
from cyber security threats, according to the latest Pension Fund Risk Register. The Royal Borough of Greenwich Pension Board discussed the risk at its meeting on Monday, 15 September 2025.
The high-risk assessment is driven by several factors, including:
- Varying methods of accessing the Royal Borough of Greenwich's (RBG) ICT infrastructure, both internally and via public channels.
- An increasing number of over-privileged users across internal RBG teams and third-party suppliers.
- A lack of in-house cyber security and technical expertise to address system misconfigurations or malicious use.
The Royal Borough is aware of the potential consequences of cyberattacks, which include threat actors gaining access to council data and systems, temporary or permanent data loss, sensitive data exposure, reputational damage, financial penalties, and disconnection from the Public Sector Network (PSN).
The board reviewed the section of the Pension Fund risk register that covers liabilities and other risks. The Accountancy and Business Change Manager explained that the risk register is a tool for managing the fund's exposure to risk, assessing the likelihood and impact of potential risk events, outlining controls, and providing an overall risk score. The risk register is a live document
and is updated accordingly as the review progresses. The full risk register was agreed by the Investment and Administration Panel ('the Panel') at its March 2025 meeting. The register is split up into sections and reviewed and agreed at each quarterly meeting by the Board.
The register typically covers seven categories of risk:
- Administrative risk
- Compliance/Regulatory risk
- Employer risk
- Investment Risk
- Liability Risk
- Reputational Risk
- Skill Risk
To mitigate these cyber security risks, senior management is implementing several controls, including:
- Technical training for ICT staff
- Annual PSN accreditation and penetration testing
- User awareness programs on phishing emails and ransomware
- Separation of standard and administrative user accounts
- Limiting membership in the super-privileged Domain Admins security group
- Web and email filtering
- Patch management
- Review and implementation of specialist technology to enhance security posture.
- A Cyber Security Operations Centre (CSOC) monitoring the RBG environment 24x7.
- A modern backup solution with immutability and faster restore capabilities.
- Building a Cyber Security Incident Response Team (CSIRT) and enhancing cyber security expertise within ICT teams.
- Developing a Role Based Access Control Matrix to enforce the principle of least privilege.
- Council user education and awareness programs to foster a security-conscious culture.
- Collaboration with the National Cyber Security Centre (NCSC) and other local authorities to implement best practices and enable early alerting.
- Evaluating the feasibility of using Network Detection and Response tooling.
The register also addressed regulatory changes and cyber security, with the latter risk (O1) receiving a risk score of 16, categorising it as a Significantly High Risk
that requires senior management monitoring.
The board noted the section of the Pension Fund risk register that covers Liabilities and Other Risks, which is available to view on the council website.
The agenda and reports pack for the meeting are available online.