Project

Continuous Threat Exposure Management (CTEM) gap analysis

1 story · 1 council

Merton Council is addressing an increased cyber attack risk, which rose to red in November 2025, as it works to identify cybersecurity vulnerabilities.

Merton Council's cyber attack risk increased to red in November 2025, according to the Key Strategic Risk Register reviewed by the Governance Standards and Audit Committee. This rise from amber was attributed to a rise in cyber incidents targeting system disruption and third-party supply chains. The council's Continuous Threat Exposure Management (CTEM) gap analysis project aims to identify vulnerabilities in its cybersecurity posture.

The Key Strategic Risks Register Q1 2025-26 included 12 entries, with seven categorised as red, indicating a high priority for management. No further details on the CTEM gap analysis project or upcoming discussions were provided in the supplied material.

Key facts

  1. Merton Council's cyber attack risk increased from amber to red in November 2025. Source
  2. The Governance Standards and Audit Committee reviewed the Key Strategic Risk Register on 13 November 2025. Source
  3. The Key Strategic Risks Register Q1 2025-26 listed seven of 12 entries as red risks. Source
About this summary

This summary was written automatically from our published stories and the council meeting records they draw on. It describes what councils have discussed and decided; it does not take a view on any decision. Each key fact links to the story it comes from. Updated 30 September 2026. Spotted a mistake? Email community@opencouncil.network.

Latest stories

  1. Merton Council's Cyber Attack Risk Increases to Red Despite Mitigation Efforts Merton Council's risk of cyber attack has increased, according to the latest Key Strategic Risk Register (KSRR). The register, reviewed by the Governance Standards and Audit... Merton 17 November 2025