Richmond upon Thames Council is shifting its approach to cyber security, moving from a traditional in-house team to a Cyber Security as a Service (CSaaS) model to address the increasing demands on its cyber resilience, driven by the pace of technological change, increasing reliance on data-driven service delivery, and the evolving threat landscape.

The council says the new model will provide 24/7 access to specialist cyber capabilities, threat intelligence, and incident response services, ensuring its defences remain agile, modern, and proportionate to the risk environment. It also includes access to a virtual Chief Information Security Officer (vCISO).

The Audit, Standards and Statutory Accounts Committee reviewed the change at their meeting on Tuesday, 1 July 2025, as part of the Review Of The Council's Governance Arrangements.

To ensure data privacy and compliance with regulations like GDPR under the CSaaS model, the council's systems and data handling processes continue to be regularly reviewed, both internally and through independent third-party assessments. The council remains compliant with the UK General Data Protection Regulation (GDPR) and the Data Protection Act (DPA) and retains its ISO27001 Certification.

Mandatory cyber and information security awareness training for all officers remains a key component of the council's defence in depth approach, reinforcing the shared responsibility of every officer to handle information securely.

The Audit, Standards and Statutory Accounts Committee is responsible for monitoring and providing independent assurance on the council's risk management framework and internal control environment.

Other significant governance issues detailed within the Annual Governance Statement are:

  • Knowledge management and agile working
  • Contract management
  • Major projects/project management
  • Risk management