This report provides an update on the actions in progress to improve the Council’s policies, systems and processes around Information Governance.
Minutes:
The Committee considered a report outlining the action under way to improve the Council’s policies, systems and processes for Information Governance.
The report provided an update on: the action being taken to address the backlog of Subject Access Requests (SARs); the on-time responses to Freedom of Information (FOI) requests, which stood at 77.6% in Quarter 4 to date; Improvement Actions planned, including a comprehensive review of the processes for complaints, FOI requests and SARs; Data Transparency; the work of the Information Governance (IG) Board; the Information Management Strategy, whichset out the Council’s approach to information management and governance; and uptake of the compulsory Cyber Security and GDPR training for all staff and Members, which now stood at 90.28% and 91.5% compliance respectively with the IG Team carrying out bespoke training for colleagues without access to IT systems.
The report also contained further information on the cyber security programme, giving details of cyber incidents and security updates.
The report stated that the focus of the IG Team would be on:
· Identifying and implementing improvements to processes resulting from the review project
· Successful recruitment into vacant roles
· Further improvements to the Cyber Security and GDPR training content, for the coming year
· Procurement of new redaction software to support safe, effective and efficient SARs processing
· Recommencing work with the Data Stewards Network
It was queried what had caused the large number of inbound emails automatically blocked by cyber security tools in February 2025 (11m compared to usual monthly figures of around 3.5m). It was explained that the general increase between February and May 2025 might partially be explained by increased cyber-attack activity in the run up to the May elections, but the cause of the large number in February 2025 would need to be investigated.
Resolved:
(1) That the progress being made to improve the Council’s Information Governance be noted, and the future actions outlined in the report be endorsed;
(2) That officers investigate the cause of the large number of inbound emails automatically blocked by cyber security tools in February 2025 and include an update in the next report to the Committee.
Supporting documents: