UK Cyber Policy Continuity: Burnham Reappoints Lloyd Amid Ministry Overhaul
New UK Prime Minister Andy Burnham has reappointed Liz Lloyd to a junior ministerial post, retaining her cybersecurity portfolio despite a sweeping cabinet reshuffle that dissolved the department previously overseeing Britain's cyber policy. Lloyd, who has led on cyber since September 2025 and sits in the House of Lords as Baroness Lloyd of Effra, now holds dual roles at the Department for Digital, Culture, Media and Sport (DCMS) and the renamed Department for Business, Innovation, Science and Trade (DBIST). Her reappointment cuts against Burnham's broader purge of allies tied to his predecessor Keir Starmer, making her a notable continuity figure in the new administration.
Lloyd's retention is closely tied to the progress of the Cyber Security and Resilience Bill, which cleared its second reading in the House of Lords earlier this month with cross-party backing. The legislation replaces 2018-era rules and significantly expands Britain's regulatory perimeter, pulling data centers and managed service providers into scope for the first time while imposing stricter incident reporting deadlines on operators of essential services in energy, water, and healthcare. Line-by-line scrutiny of the bill begins in September, and replacing the minister at this critical juncture would have forced fresh briefings and risked delaying passage. The bill also grants ministers authority to amend regulations and issue national security directions to private companies — a powerful tool that organizations can begin assessing against their compliance posture using resources like our SSL/TLS checker to verify baseline cryptographic hygiene.
The reshuffle breaks up the Department for Science, Innovation and Technology, which had overseen cyber policy since 2023. Its functions are split three ways: cyber policy and government digital services move to DCMS, science functions transfer to DBIST, and artificial intelligence policy — including the AI Security Institute — moves to the Cabinet Office. Lloyd was also the minister overseeing a controversial decision to weaken proposed cybersecurity protections for telecoms networks, measures originally developed in response to the Salt Typhoon state-sponsored espionage campaign, after operators lobbied against them on cost and practicality grounds. That retreat drew criticism from cybersecurity professionals who warned it left critical communications infrastructure exposed to advanced persistent threats.
Beyond the ministerial reshuffle, the bill's expanded incident reporting regime and national security directions framework represent the most significant upgrade to UK cyber regulation in years. Organizations newly brought into scope — particularly data center operators and managed service providers — should begin mapping their regulatory obligations and assessing their exposure. IT teams can start with a thorough privacy and security checkup to identify gaps before the new requirements take full effect.