Burnham’s Opportunity to Rethink Information Resilience
Repositioning DCMS as the lead for ‘information resilience’ online and offline provides coherence to a currently disparate portfolio, offering a rare opportunity to rethink how the government protects the UK from information threats.
Last week, Burnham’s government announced sweeping ‘machinery of government’ changes, including abolishing the Department for Science, Innovation and Technology (DSIT), established in 2023.
This decision sees DSIT’s portfolio – which aimed to drive growth and innovation by making the UK a science and technology powerhouse – redistributed across the Cabinet Office, Department for Business and Trade (now Business, Innovation and Trade, DBIT) and the Department for Culture Media and Sport (DCMS).
This reshuffling has garnered criticism from researchers, policy wonks and industry leaders who highlight that the reorganisation risks wasting time, deprioritising science and technology, and complicating industry’s relationship with government.
However, to those working on online safety and information threats, these machinery of government changes may be more welcome. Removing one of the seven departments responsible for this policy area is a simplification and an opportunity to establish more cross-Whitehall coherence.
Furthermore, articulating DCMS’ responsibility over 'information resilience –- which could be defined as securing the ability to access, assess and establish trust in information and its sources, despite threats and systemic challenges in the information environment – could allow HMG to develop a more strategic approach with online and offline resilience efforts driven by DCMS.
A Strategic Approach to ‘Information Resilience’
There is a growing consensus across Whitehall that information threats are a national security concern with, for instance, the 2025 National Security Strategy characterising disinformation and the malign use of social media as a threat to social cohesion and public trust.
Unlike cyber threats, which compromise technical systems to generate effects, many information threats instrumentalise the way platforms are designed to work, like algorithmic feeds
Events earlier this summer brought this into sharp relief. After footage of a stabbing in Belfast was posted online, disinformation and calls to action spread via social media and were amplified by figures like Elon Musk and Tommy Robinson, with the subsequent violence resulting in arrests and temporary displacement.
But the problem extends beyond information threats – defined as inauthentic or inaccurate information artificially promoted and amplified by adversary states, commercial operators and political actors – to systemic challenges relating to media literacy, social media platform design and ownership and new, relatively ungoverned, technologies such as AI. Unlike cyber threats, which compromise technical systems to generate effects, many information threats instrumentalise the way platforms are designed to work, like algorithmic feeds. These broader systemic factors shaping the UK's information resilience – or lack thereof – make a threat-focused approach myopic.
Recent governments have parcelled up and addressed this interwoven set of threats and challenges as a series of disparate policy areas, including social media regulation, online safety, foreign interference, AI harms and media literacy. Interventions have, as a result, been limited, not cohered and targeted predominantly low-hanging fruit in a broader policy area.
This year, the Electoral Commission led a pilot trial of deepfake detection software; DSIT proposed regulation to ban social media for under-16s; and the Ministry of Housing, Communities and Local Government tabled new rules on political financing without addressing how digital advertising spreads disinformation.
These technology or audience-specific interventions are not commensurate with the scope of the problem. What use is detecting deepfakes without, for instance, an effective enforcement mechanism to remove them, the communication architecture to contest them or the population-level awareness to make sense of these decisions?
What the UK government has lacked is both an overarching strategy towards information resilience and sufficiently empowered and informed civil servants and ministers to deliver it. In this context, the redistribution of DSIT’s share of this problem to an expanded DCMS gives government a clearer domestic home for information resilience and a chance to build a strategy spanning culture, media, technology and national security.
A Bolstered DCMS is Better Placed to Tackle Social Media Companies and Deliver the Online Safety Act
Under DSIT, responsibility for attracting investment from Big Tech, including from social media, sat alongside responsibility for mitigating threats on those same companies’ services. In practice, these objectives were conflicting and the task of confronting companies over data access, platform design and weak policy enforcement often lost out.
Separating investment promotion from social media governance, and uniting the latter with DCMS’ broader portfolio covering media regulation, should help the government develop and implement more effective policy in this area. DCMS should use its new position not merely to maintain relationships with platforms, but to conduct serious diplomacy: setting expectations, demanding transparency and applying sustained pressure.
The DSIT/DCMS repartition also left the Online Safety Act and Ofcom floundering between the two departments. The OSA was developed under DCMS, but by the time it passed in October 2023, its enforcement became the responsibility of the newly established DSIT – while DCMS retained traditional media regulation.
Almost three years after the Act’s passing, enforcement has been slow at best, with confusion over ministerial responsibility for enforcement. Rehousing responsibility for enforcing the OSA within DCMS – coupled with articulating this as a priority for the Secretary of State – might help resolve this.
However, scope and enforceability are as much an issue as responsibility. The OSA does little to address information manipulation and influence campaigns directly, and even those provisions which did survive the watering down of the Act – such as the priority offence of foreign interference online – are impracticable. According to the Foreign Affairs Committee, the high evidentiary threshold for establishing the foreign power condition under this offence creates a ‘loophole’ which hostile states can exploit.
DCMS is the appropriate home for an expanded strategy focused on building resilience
The Secretary of State should use the return of responsibility for Ofcom and the OSA to DCMS as a moment to reinvigorate the Act’s enforcement and to expand its scope to tackle information manipulation directly, in line with DCMS’ responsibility for information resilience.
Delivering an ‘Information Resilience’ Strategy Across Whitehall
Therefore, repositioning DCMS as the lead for a holistic approach to ‘information resilience’ has advantages. It offers an opportunity to reframe government policy, articulate a broader strategic vision and consolidate leadership over key areas, increasing the prospects for more effective policy delivery. Doubts about the department’s Whitehall weight notwithstanding, DCMS is the appropriate home for an expanded strategy focused on building resilience.
But if information resilience means securing the UK’s ability to access, assess and establish trust in information and its sources, despite threats and systemic challenges, then a credible strategy to achieve this will require both threat-centric and system-centric pillars. System-centric pillars might include securing access to trustworthy information, improving media literacy and tackling systemic challenges through legislation and diplomacy. These can appropriately be led by DCMS.
But counter-threat pillars will be key too, namely the detection, assessment and disruption of threats. This function had been delivered primarily by teams across DSIT, the Home Office (for domestic threats) and Foreign Office (for overseas threats); these disparate elements must now be effectively further coalesced.
As noted in the recent Rycroft Review, the division of work along domestic/foreign lines is ‘almost completely irrelevant in dealing with this problem’. Sophisticated information threats blur the lines according to which government and industry response has been siloed: they blend online and offline activities, spread across closed and open groups and involve a mix of authentic and inauthentic users based in the UK and abroad. Whitehall has the collective capability to tackle threat actors but not, at present, the cohesion or cross-domain approach.
In the face of sustained efforts by malign actors, the UK is overdue a more strategic and effective approach to securing access to trusted information, particularly online
To deliver on a national strategy for information resilience spanning both systemic challenges and acute threats, the government should establish a new unit, body or agency focused on information threat detection, assessment and response.
This entity – whether a new statutory body or a cross-Whitehall unit drawing on sponsoring departments’ powers – must leverage requisite legislation (such as the Regulation of Investigatory Powers Act), share intelligence across the Home Office, FCDO and intelligence agencies, and have the authority and agility to communicate rapidly and publicly about threats. Finally, it must also be a suitable home for both the private sector and civil society to share intelligence, best practice and build nationwide capability, as the National Cyber Security Centre has been for cyber threats.
The rehousing of DSIT’s portfolio to DCMS is a first step towards much-needed coherence for the government’s information resilience agenda. DCMS should decisively embrace this new role, adopting a definition of information resilience which can act as an organising principle – building towards a national strategy – for supporting efforts across government departments. In addition, the government should explore options for centralising the threat-centric pillars of response via a new dedicated unit or body.
In the face of sustained efforts by malign actors, the UK is overdue a more strategic and effective approach to securing access to trusted information, particularly online. With the next general election up to three years away, the new government has a window of opportunity and the institutional building blocks to strengthen the UK’s information resilience and embed this as a core function of the state.
© RUSI, 2026.
The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.
For terms of use, see Website Terms and Conditions of Use.
Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.
WRITTEN BY
Sophie Williams-Dunning
Research Analyst
Cyber and Tech
Andy Pryce
RUSI Associate Fellow, Cyber and Tech
Jamie MacColl
Senior Research Fellow
Cyber and Tech
- Jim McLeanMedia Relations Manager+44 (0)7917 373 069JimMc@rusi.org





