Cyber security and local government: insights from St Helens Council
St Helens council joined us at an Ask the Expert LGIU members’ discussion to share learnings from their response to a major cyber incident that the council had to deal with.
This article is part of LGIU’s new Future Local Lab – a holistic programme of resources aimed at helping you to prepare for and respond to the emerging challenges facing local government everywhere.
This session explored best practice and lessons emanating from experience in local government in managing and mitigating cyber threats. As digital transformation accelerates in the public sector, so too does the scale and sophistication of cyber attacks. The impact of these attacks is felt most acutely at the local level, where critical services and resident trust are at stake.
LGIU’s Ask the Expert session for members on 4 June was lucky enough to have Steve Sharples, Assistant Director of ICT and Digital Delivery, St. Helens Council, as guest speaker. Ste was part of the team at St Helens that had to deal with a major cyber incident a few years ago.
LGIU members can access a recording of the session and supporting materials in their member resource pack. We have distilled five key lessons from the discussion
Five key takeaways
- Cybersecurity is no longer just an IT issue
Opening the session, Jonathan Carr-West, Chief Executive of LGIU, emphasised that cybersecurity is a critical risk that touches every part of council operations. It’s a leadership issue, a governance issue, and ultimately a service delivery issue. Councils must shift from viewing cyber threats as technical anomalies to seeing them as fundamental risks to public trust and operational continuity. - Local governments are prime targets and resilience matters most
Steve Sharples, Assistant Director of ICT and Digital Delivery at St. Helens Council, explained how his council had responded to the major cyber attack and noted, “It’s not a question of if, but when.” St. Helens’ experience highlights the importance of building organisational resilience, including strong response protocols, data recovery plans, and regular scenario testing, which were key to the council’s successful recovery. - Staff awareness is a frontline defence
A recurring theme was the need to engage the entire workforce in cyber preparedness. Phishing and social engineering attacks often rely on human error. Building a culture of vigilance across all departments, providing regular training, and embedding cyber hygiene in day-to-day practice were seen as essential actions. - Recovery is a long road – communication is crucial
Recovery from a cyber incident isn’t instantaneous. Ste talked about how communication, both internal and external, played a critical role in managing the impact. Clear updates to staff, councillors, residents and partners helped manage expectations, reduce panic, and support coordinated recovery efforts. Transparency, even during a crisis, helps build trust. - Collaboration is key to protection and learning
Local authorities should not face these challenges in isolation. Peer networks, regional cyber support partnerships, and knowledge-sharing events like the LGIU’s are vital. As threats evolve rapidly, collective learning is the most effective way to stay ahead. Councils should really be investing in external audits, joining sector resilience networks, and learning from each other’s experiences.
Join the discussion. Book your spot on one of our upcoming member-only Executive Live Panels.
- Growing the local economy – 22 July
- Tackling the housing and homelessness crisis – 25th Sept
Not sure if you’re a member – check our list of members here.
Looking for more?
Explore LGIU’s new Future Local Lab – a holistic programme of resources aimed at helping you to prepare for and respond to the emerging challenges facing local government everywhere.
Was this article helpful or relevant for you?
Future Local Lab
Local Government Explained
Local Elections England: 2026