Surrey Councils Face Growing Cyber Attack Risk Ahead of 2027 Merger
Why This Matters to Guildford and Surrey Residents
If you live in Guildford, Woking, Dorking, Horsley, or East Horsley, a cyber attack on your local council could directly affect the services you rely on daily. Your council manages everything from planning applications to waste collection, housing benefits, and business licences. A successful ransomware attack could freeze these essential services, leaving residents without access to critical information or unable to submit applications for weeks. The latest risk assessment flagged by Guildford Borough Council shows that cyber threats aren’t theoretical—they’re an active, growing challenge facing local authorities nationwide. The council’s audit and risk committee is now reviewing comprehensive updates to its corporate risk register, which tracks all major operational dangers. What makes this particularly urgent is the timing. Next spring, Surrey’s local government structure undergoes a historic transformation, with two new unitary councils replacing the current county and district arrangement. This merger creates what officials describe as “further complexity” in IT security during a period when hackers often target organisations in transition.
The Real Risks: What Could Go Wrong
Cyber attacks on local councils take many forms, and understanding them helps residents grasp why this threat is rated as a “significant strategic risk.” Ransomware attacks lock council staff out of systems until money is paid to criminals—imagine trying to get your business rates bill or planning permission while everything’s encrypted. Data breaches could expose personal information residents have shared with the council. Distributed Denial of Service attacks flood council websites and systems, making them completely unusable. For a growing area like Guildford, where new developments require planning scrutiny and building control oversight, losing access to these systems would create real problems for residents and local businesses alike. kitchen renovation companies, bathroom fitters, and bathroom refurbishment specialists all depend on council building control approvals. A cyber attack could delay projects across Surrey’s communities. The council acknowledges the threat “remains above appetite”—meaning the current risk level exceeds what they’re comfortable with. What’s particularly concerning is that most threat activity sits completely outside the council’s control; criminals constantly develop new tactics faster than defences can be built.
What Guildford and Surrey Are Doing—And What Happens Next
Guildford Borough Council isn’t sitting idle. They’re actively investing in preventative cyber security measures and coordinating with IT professionals across all Surrey councils to ensure systems remain secure through the 2027 transition. This cross-council collaboration is crucial because when East and West Surrey Councils launch next spring, their combined IT infrastructure must be bulletproof from day one. The council has confirmed it takes IT security “very seriously” and provides councillors with regular updates on security measures—though they wisely keep specific technical details private (telling hackers exactly where weaknesses are would be counterproductive). For residents, the key takeaway is simple: councils are aware of the danger and investing resources to address it. However, you should also protect yourself. Use strong, unique passwords for any online council accounts, enable two-factor authentication where available, and report suspicious emails claiming to be from the council. If you’re a local business owner—whether you run a bathroom fitters operation, manage kitchen renovation projects, or any other enterprise—stay alert to phishing scams targeting business licences or council correspondence. Vigilance at every level strengthens Surrey’s digital resilience.
Source: Cyber security threats remain ‘strategic risk’ to Surrey councils, report says


