Summary

Why this case belongs in a risk and accountability file

Capita belongs in a risk and accountability file because outsourcing deliberately separates service ownership from operational execution. A local authority, pension trustee, government body, insurer, utility, healthcare customer, employer, or private client may retain legal obligations to people, but a supplier may control the platforms, staff workflows, credentials, file stores, call centers, administration systems, and recovery evidence. When the supplier is attacked, the affected person does not experience a clean boundary between private vendor and public duty. A pension member asks the scheme. A citizen asks the council.

A client asks Capita. A regulator asks all of them to show what happened.

Capita's own incident page at https://www.capita.com/about-us/responsible-business/cyber-incident-what-happened-and-how-we-responded says that in March 2023 the company experienced a cyber incident that led to unauthorized access to certain IT systems and disruption of some client services. Capita said the attack was interrupted on 31 March and services were restored shortly afterwards. The April 20 update at https://www.capita.com/news-and-insights/news/2023/update-cyber-incident said the investigation identified evidence of limited data exfiltration from the small proportion of affected server estate, and that Capita was working with specialist advisers and customers to investigate and notify where appropriate.

The later public record made the incident heavier. The ICO's October 2025 release at https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/capita-fined-14m-for-data-breach-affecting-over-6m-people/ said the regulator fined Capita plc and Capita Pension Solutions Limited a combined GBP 14 million for data protection failings after a cyber attack affecting more than 6 million people. The monetary penalty notice at https://ico.org.uk/media2/pv5nhks4/capita-plc-and-cpsl-monetary-penalty-notice.pdf sets out the regulator's findings, including unauthorized access, large-scale exfiltration, weaknesses in technical and organizational measures, and the role of Capita Pension Solutions Limited in pension-related data processing.

This article treats the company record, regulator record, pension-regulator record, client notices, annual report, and reputable reporting as different evidence layers. It does not claim access to Capita private forensic reports, full client-by-client files, law-enforcement records, complete recovery logs, or every affected service record. It also does not adopt public reporting about attacker identity as a company-confirmed fact.

The accountable facts are already serious without unsupported attribution: unauthorized access occurred, some services were disrupted, data was exfiltrated, many people were affected, and regulators later found data-protection failures.

The core question is practical. Who had control over outsourced-system segmentation, public-service continuity, affected-data scoping, client notification, recovery-cost disclosure, pension-record assurance, and evidence that a supplier incident did not become a public-sector blind spot? The answer starts with Capita because Capita controlled its core systems, incident response, client communications, pension administration environment, and evidence production. It does not end with Capita, because clients and trustees retained duties to their own populations.

The timeline turned a supplier outage into a data-scope problem

The earliest public problem was service disruption. The Guardian reported on April 3, 2023 at https://www.theguardian.com/business/2023/apr/03/capita-blames-cyber-attack-outage-it-systems that Capita had blamed a cyber attack for an outage as the company raced to restore IT systems. Capita's early public statement described disruption primarily around internal Microsoft Office 365 applications. That framing mattered because a supplier outage can be treated as an operations problem if services return quickly and data remains protected. Within weeks, however, the accountability question shifted toward exfiltration and client notification.

Capita's April 20 company update at https://www.capita.com/news-and-insights/news/2023/update-cyber-incident said the company had contained the attack, restored employee access to Microsoft Office 365, and found some evidence of limited data exfiltration from the affected server estate. The same day, The Guardian reported at https://www.theguardian.com/business/2023/apr/20/capita-admits-customer-data-may-have-been-breached-during-cyber-attack that customer, staff, and supplier data may have been accessed. The exact wording changed the accountability problem. A temporary outage asks: how quickly were services restored? Data exfiltration asks: whose personal data was copied, who was the controller or processor, what notices were required, and what evidence supports the answer?

Capita's May 10 update at https://www.capita.com/news-and-insights/news/2023/update-actions-taken-resolve-cyber-incident said it had taken extensive steps to recover and secure data within the affected server estate, remediate issues arising from the incident, and strengthen cyber defenses. It also gave a public cost range for specialist professional fees, recovery, remediation, and security investment. Public reporting at https://www.theguardian.com/business/2023/may/10/cyber-attack-to-cost-outsourcing-firm-capita-up-to-20m described that expected bill as GBP 15 million to GBP 20 million, and later reporting at https://www.theguardian.com/business/2023/aug/04/cyber-attack-to-cost-outsourcing-firm-capita-up-to-25m described an expected cost up to GBP 25 million.

Costs matter, but they are not the same as repair. A large recovery bill can indicate serious work, but it does not prove segmentation, least privilege, monitoring, client-specific scoping, or member notice quality. Capita's 2023 Annual Report and Accounts at https://www.capita.com/dam/documents/investors/results-reports-presentations/2023/full-year-results-2023/Capita-plc-Annual-Report-and-Accounts-2023.pdf is useful because it places the incident inside company risk, remediation, cost, and transformation context. Investors needed to know financial impact. Clients needed to know service and data impact. Affected people needed to know personal impact. Those are related but not identical records.

The forensic timeline later described by the ICO made the service-restoration narrative incomplete. The ICO monetary penalty notice includes a more detailed regulator view of access, detection, response, account controls, data exfiltration, and affected people. The important accountability point is not to narrate every technical step as if public readers can validate it independently. It is to observe that a supplier's first operational update rarely contains the full data-risk picture. Outsourcing customers therefore need contracts and incident playbooks that assume the first update is provisional and require later evidence.

Outsourcing moves control, not public duty

Public-service outsourcing is attractive because specialist firms can run administration, customer contact, payment processes, pension platforms, casework, technology support, and back-office workflows at scale. That scale can improve cost, staffing, and automation. It can also concentrate risk. If one supplier's core systems, identity model, file stores, or security monitoring are weak, many public and private bodies may discover their exposure at the same time.

Capita's business model put that concentration in plain view. Its annual report describes a group providing business process services, customer experience, digital, software, and public-service support across sectors. The public did not need to understand every contract to grasp the dependency. The April 2023 outage immediately raised concern because Capita was associated with services touching local authorities, health, defense, education, pensions, and private clients. Reputable public reporting, including The Guardian's April article and BBC reporting at https://www.bbc.com/news/technology-65746599 on organizations reporting data breaches to the ICO, captured how quickly the incident moved from company disruption to downstream institution concern.

The accountability issue is that a public body cannot outsource its public relationship. A council can contract with a supplier, but a citizen still asks the council why a service was unavailable or why personal data was exposed. A pension scheme can use an administrator, but a member still asks the trustee what happened to their record. A government department can rely on an outsourcing chain, but Parliament, auditors, regulators, and service users still judge the public outcome. The supplier may have operational control, while the public body retains legitimacy risk.

This is why procurement evidence matters before the incident. Clients should know which Capita systems hold their data, which Capita entities process it, whether data is segregated by client, which privileged accounts can reach it, how security alerts are triaged, how backups are protected, where data is stored, whether subcontractors are involved, how incident notices are issued, and what independent assurance is available. If those questions are first asked after a breach, the client has already ceded too much control.

The same is true for service continuity. Public-sector continuity is not measured only by whether Capita restores its own internal applications. It is measured by whether people can still access services, whether call centers work, whether pension calculations continue, whether local-government processes are delayed, whether health or benefit workflows are affected, whether staff can use fallback procedures, and whether clients can explain the disruption. A supplier incident can become a public-service blind spot if continuity metrics stay inside the supplier.

Pension records made the evidence chain visible

Pensions became one of the clearest public examples because pension schemes have identifiable trustees, administrators, members, regulators, and data duties. The Pensions Regulator's intervention report at https://www.thepensionsregulator.gov.uk/en/document-library/enforcement-activity/regulatory-intervention-reports/capita-cyber-security-incident-regulatory-intervention-report says it worked with Capita to assess risk to pension schemes and members following the cyber security incident and set out lessons for trustees. That report is important because it treats the incident not only as a Capita event, but as a scheme-governance event.

USS's member hub at https://www.uss.co.uk/for-members/capita-cyber-incident-hub said Capita formally informed USS on May 11, 2023 that USS member data had been accessed, and USS began informing members from May 12. USS said it used Capita's Hartlink platform to support in-house pension administration processes, and that the data concerned was in files generated by Capita from Hartlink and held separately on Capita servers for operational processes. That is exactly the kind of dependency chain an affected member cannot see without the scheme and supplier explaining it.

The USS frequently asked questions at https://www.uss.co.uk/for-members/capita-cyber-incident-hub/frequently-asked-questions added practical detail for members, including categories of data and guidance on protective steps. USS's response to The Pensions Regulator report at https://www.uss.co.uk/for-members/capita-cyber-incident-hub/response-to-the-report placed the incident into a trustee response and lessons-learned frame. The Guardian's May 12 report at https://www.theguardian.com/business/2023/may/12/capita-cyber-attack-uss-pension-fund-members-details-may-have-been-stolen described member data risk and Capita's advice to work on the assumption that data had been accessed or copied where confirmation was not definitive.

This is the outsourcing accountability problem in miniature. Capita controlled the administration platform and files. USS had duties to members. Members had the least information and the most personal exposure. The regulator had to assess trustee response and broader scheme lessons. The question is not only whether one file was copied. It is whether the system of supplier, trustee, regulator, and member communication worked fast enough and specifically enough.

Pension data is not ordinary contact data. It can include names, dates of birth, National Insurance numbers, addresses, salary, employment, benefits, membership status, and retirement planning context. It can be used for identity risk, financial targeting, social engineering, and long-tail anxiety. A pension member may not be an active employee anymore. They may be retired, ill, dependent on benefits, or difficult to contact. Notice design has to account for that population, not only for digitally confident workers.

Confirmed facts, supported inference, and unknowns must stay separate

The confirmed public facts are substantial. Capita disclosed unauthorized access to certain IT systems and disruption of some client services. It later disclosed evidence of limited data exfiltration from a small proportion of affected server estate. The ICO fined Capita plc and Capita Pension Solutions Limited after finding data-protection failings affecting more than 6 million people. The Pensions Regulator issued a report on the cyber security incident and pension scheme lessons. USS and other public notices confirmed member-notification activity. Capita disclosed recovery and remediation costs.

These facts are enough to support a risk-accountability case.

Supported inference is also clear but should stay bounded. It is reasonable to infer that many clients could not independently determine data scope without Capita because the relevant files and systems were inside Capita-controlled environments. It is reasonable to infer that pension trustees needed supplier evidence before issuing precise member notices. It is reasonable to infer that outsourcing concentration increased coordination complexity because many clients and schemes were dependent on one supplier's investigation.

It is reasonable to infer that weak privileged-account or monitoring controls can turn an initial endpoint incident into broader data exposure if the regulator's findings show those weaknesses.

Unknowns remain. The public record does not provide every client contract, every affected file, every affected data subject, every service outage detail, every private incident bridge, every law-enforcement contact, every forensic artifact, every restore log, every customer-specific notification packet, or every remediation proof artifact. It does not prove that every affected person's data was misused. It does not prove that every Capita service was affected. It does not support naming an attacker group as a confirmed company fact in this article. The accountability record is stronger when unknowns are not disguised as facts.

That distinction is especially important in public services. If officials or suppliers overstate certainty, they may under-notify people. If they overstate harm, they may create avoidable panic. A good notice should say what is confirmed, what is assumed for safety, what is still under investigation, what the person can do, what the supplier is doing, what the client is doing, and when the next update will arrive. Capita's case shows that clients need the contractual right to demand those categories from suppliers.

The same discipline applies to regulator findings. The ICO notice is authoritative evidence for UK data-protection enforcement. It is not a substitute for client-by-client operational records. The Pensions Regulator report is authoritative evidence for pension-scheme oversight and lessons. It is not a full public forensic report. The Capita annual report is authoritative company evidence for financial and risk context. It is not enough to tell a member whether their exact record was copied. Each source has a role.

Enterprise software automation can hide common-mode risk

Capita's incident belongs in the enterprise software automation topic because outsourced administration is often automated through shared platforms, file-generation processes, workflow tools, identity services, call-center systems, and reporting jobs. Automation reduces manual cost. It also creates common-mode risk when multiple clients depend on the same architecture. A weakness in a privileged account, file store, monitoring process, or alert workflow can affect many clients before any single client sees the full pattern.

The ICO's monetary penalty notice is useful because it treats security controls as organizational measures, not isolated technical settings. It discusses Capita group-wide responsibility, Capita Pension Solutions Limited processing, security policies, internal auditing, privileged access, penetration testing, alert handling, and response. This is the right level for outsourcing accountability. A client does not only buy a software function. It buys the supplier's governance over that function.

NCSC guidance on mitigating malware and ransomware at https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks, preventing lateral movement at https://www.ncsc.gov.uk/guidance/preventing-lateral-movement, and supply-chain security at https://www.ncsc.gov.uk/collection/supply-chain-security provides public control language for this case. Those sources do not make findings about Capita. They define the control expectations clients should care about: reducing attack surface, separating networks, protecting privileged access, monitoring activity, rehearsing incident response, and managing supplier risk.

In an outsourcing environment, automation evidence should include client data maps, privileged-account inventories, logging coverage, alert triage records, vulnerability closure, penetration-test remediation, backup validation, segmentation diagrams, access reviews, and service-continuity tests. A supplier can say services were restored, but a client needs proof that restoration did not simply reconnect vulnerable systems. A supplier can say data exfiltration was limited, but a client needs proof that the limit was established through evidence rather than absence of complaints.

The challenge is that some evidence cannot be published in detail. A supplier should not put sensitive architecture diagrams into a public notice. But it can give clients and regulators structured assurance: what system classes were affected, what data categories were in scope, what controls failed, what controls held, what was rebuilt, what accounts were rotated, what monitoring changed, what independent review occurred, and how future alerts will be escalated. That is the difference between secrecy for security and opacity for convenience.

Client notification is a shared duty with an evidence bottleneck

Client notification in a supplier incident has at least four layers. First, the supplier must tell clients what happened and what might involve their data or services. Second, the client must decide whether it has a personal data breach, service continuity issue, contractual notice duty, or regulator duty. Third, affected people need understandable notices. Fourth, regulators and trustees need evidence that the response was adequate.

Capita's case shows how quickly those layers multiply. The Guardian reported on May 30, 2023 at https://www.theguardian.com/business/2023/may/30/capita-cyber-attack-data-breaches-ico that about 90 organizations had reported breaches of personal information held by Capita to Britain's data watchdog. BBC reporting at https://www.bbc.com/news/technology-65746599 reported the same basic public concern. The exact number of notifications is less important than the structure: one supplier incident generated many client decisions.

The evidence bottleneck sits with the supplier. Clients need to know whether their data was in affected systems, whether it was accessed or copied, what categories were involved, whether data was encrypted, how long the attacker had access, whether backups or logs are reliable, whether system restoration changed the risk, and what protective measures are appropriate. If the supplier gives only generic statements, clients either delay notices or over-notify. Both can harm trust.

This is where contract design matters. Supplier contracts should define rapid incident notice triggers, data-scope obligations, regulator cooperation, client-specific reports, audit rights, privileged-access expectations, data-segregation requirements, retention limits, backup and restoration evidence, and communication responsibilities. They should also define who pays for extraordinary response work and affected-person support. Waiting until after an incident to negotiate evidence access is a poor control.

The Pensions Regulator's report makes the trustee dimension concrete. Trustees should understand where scheme data is held, what suppliers do with it, how incidents will be escalated, and how to notify members. The cyber incident did not remove trustee duty. It tested whether trustees had enough supplier governance to meet that duty under pressure. That lesson applies beyond pensions to local authorities, health-adjacent services, government contractors, and private-sector clients that hold public-like obligations to vulnerable populations.

Recovery cost is not the same as public accountability

Capita's recovery and remediation costs were material. The May 2023 company update and public reporting described expected specialist, recovery, remediation, and cyber-defense costs. The August reporting described higher expected costs. The annual report places the incident inside financial reporting and risk management. Investors needed those numbers because cyber incidents affect cash, margins, insurance, claims, client trust, and future contract risk.

But cost is not proof. Spending money on specialists does not prove data was accurately scoped. Buying tools does not prove alerts are triaged. Paying compensation does not prove recurrence risk is controlled. Restoring systems does not prove they were restored into a safer architecture. A supplier can absorb a financial hit while clients and affected people still lack the evidence they need. Conversely, a company can implement strong repairs that are not visible in a headline cost number.

Public accountability requires outcome evidence. Were services restored to agreed levels? Were data subjects notified accurately? Were regulators satisfied with the evidence? Were privileged access paths changed? Were penetration-test findings closed? Were affected business units audited? Were client data stores mapped? Were backup and restoration processes tested? Were customer-specific reports delivered? Did clients change their own governance? Those are the questions that turn expense into repair.

The ICO's penalty record makes this distinction sharp. A fine in 2025 does not itself repair the 2023 incident. It states findings, imposes consequences, and signals the standard that was missed. Capita's public response to the ICO outcome is part of the later record, but the accountability file should ask what artifacts now prove sustained control. The affected people do not need only a fine. They need assurance that the supplier and clients learned the operational lesson.

Cost allocation also matters. If a supplier incident forces local authorities, pension schemes, employers, or public bodies to spend staff time, legal fees, call-center effort, monitoring support, and communications money, those costs can be displaced from the supplier to the public-service ecosystem. A full accountability file should identify not only Capita's costs, but also client costs and affected-person burdens. The market headline may stop at Capita's remediation bill. The public-service cost often continues elsewhere.

Data sovereignty and locality are operational controls

Data sovereignty in this case is not only about where a server sits. It is about who controls pension records, employee data, citizen data, benefit records, call-center notes, identity fields, and service histories; which UK GDPR roles apply; which client is controller or processor; which Capita entity processes which data; which regulators oversee which duties; and which affected people receive notice under which legal framework. The ICO and The Pensions Regulator records show why these questions are operational, not academic.

The ICO's ransomware and data protection guidance at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ransomware-and-data-protection-compliance/ is useful because it treats ransomware and cyber incidents as personal data protection events where confidentiality, integrity, availability, notification, and evidence all matter. Again, the guidance is not a Capita-specific finding. It is a framework for understanding why outsourced systems that hold personal data require more than IT restoration.

Locality also matters to affected people. A pension member may be in the UK, retired abroad, no longer working for the original employer, or connected to a scheme through historical service. A citizen's data may be held by a council that uses a contractor. A public-body employee may have staff records processed by an outsourced administrator. Notices must reach people through real channels, not only through a contract owner. Data locality includes communication locality: who can find and inform the person whose data was exposed?

The supplier's data map is therefore part of public-sector continuity. It should show where records are held, which clients own them, which systems generate files for operational processing, how long files are retained, whether temporary extracts exist, who can access them, which backups contain them, and how deletion works. The USS disclosure about files generated from Hartlink and held separately on Capita servers is a useful example because it explained an otherwise invisible operational data path.

Members could see that the risk was not simply "the pension system" in the abstract; it involved generated files held by a supplier.

Data minimization is part of this. If files are generated for operational reasons, they should not remain available longer than necessary. If privileged accounts can reach large data stores, they should be restricted, monitored, and segmented. If alerts are raised, they should be processed quickly. If penetration tests identify risky configurations, remediation should be tracked. The ICO record connects those control points to personal data protection. That is what makes locality a control system rather than a slogan.

Public buyers need evidence before renewal

The Capita case also shows why public buyers, pension trustees, and regulated clients should not wait for a breach before asking how supplier evidence will be produced. Renewal is the moment when a client can turn incident lessons into contract controls. If the client renews on price, service level, and broad reputation alone, it may preserve the same evidence gap that made the incident difficult to manage. A public-service contract should define how data maps, security attestations, incident reports, privileged-access reviews, and service-continuity evidence will be produced during normal operations.

That evidence should be practical. A local authority does not need every firewall rule. It needs to know which systems hold its residents' data, how those systems are segmented from other clients, how administrator access is approved and reviewed, how generated files are stored and deleted, how quickly high-risk security alerts are escalated, and what report it will receive if an incident affects its data. A pension trustee needs similar evidence for member records, benefit calculations, address files, payroll feeds, mortality checks, call-center notes, and document stores.

The client should be able to explain the supplier dependency to an affected person before the supplier fails.

Renewal evidence should also include exercises. A paper incident plan is weak if the supplier, client, trustee, legal team, communications team, and regulator-contact process have never been tested together. A table-top exercise can ask simple questions: who receives the first supplier alert; who decides whether members or citizens are notified; what minimum data fields are needed for a lawful notice; who answers media questions; how service fallbacks are activated; how client-specific evidence is preserved; and who signs off that recovery is complete. Those questions are operational, not theatrical.

They decide whether a supplier event becomes a coordinated response or a week of improvised messages.

The renewal process should also include exit planning. Outsourcing can create lock-in when the supplier holds legacy files, workflow history, user knowledge, and integrations that are hard to move. If a cyber incident causes a client to reconsider the relationship, the client still needs clean data extraction, transition support, and evidence that old supplier copies are deleted or lawfully retained. Without exit evidence, the client may remain exposed to a supplier environment even after changing strategy.

For pension schemes, this is particularly important because members may remain in a scheme for decades. Administration suppliers may change, platforms may be migrated, and employers may restructure, but member records persist. Trustees should therefore treat supplier cyber assurance as part of fiduciary discipline. It is not enough to ask whether the administrator can calculate benefits. The administrator must be able to protect, locate, explain, and recover the data used to calculate those benefits.

Public bodies face the same durability problem. Citizens may interact with a council service once, then have their data retained in a supplier workflow for years. A service user may not remember the contractor's name. If the contractor is breached, the public body must still explain the exposure. Renewal controls, data minimization, audit rights, and tested notice pathways are how the public body avoids discovering its dependency only after citizens are already affected.

What durable repair should prove

Durable repair after the Capita incident should prove eight things. First, it should prove scope. Capita and clients should know which systems, business units, clients, files, records, service lines, and affected-person categories were involved. Scope should distinguish disruption from exfiltration, possible access from confirmed copying, and Capita data from client data.

Second, it should prove segmentation. Outsourced service platforms, pension files, corporate systems, client environments, privileged accounts, backup systems, and operational file stores should not be reachable through one weak path. If segmentation failed, repair should show what changed. If segmentation held, repair should show what evidence supports that conclusion.

Third, it should prove privileged-access control. The ICO record makes privileged access a central issue. A durable repair file should include account inventory, least-privilege changes, service-account restrictions, monitoring, alert rules, authentication strength, and exception governance. Privileged accounts are public-service risk when they control outsourced records.

Fourth, it should prove alert and response discipline. Alerts should not sit unprocessed while an attacker moves. Security operations should have triage standards, escalation thresholds, staffing coverage, incident bridge rules, and evidence preservation. The supplier should be able to explain how a future alert would be handled differently.

Fifth, it should prove client notification quality. Clients should receive timely, specific, data-category-based reports that allow lawful notices and practical guidance. Generic statements are not enough when pension members, citizens, employees, and service users need to know what happened.

Sixth, it should prove public-service continuity. Restoration should be measured against services people use, not only internal application availability. If a client service was degraded, the file should record duration, fallback, affected users, reconciliation, and recovery.

Seventh, it should prove retention and file-generation control. Generated files, operational extracts, historic records, backups, and temporary processing stores should have deletion schedules and access controls. Data that exists only because a process is convenient can become breach inventory.

Eighth, it should prove governance after enforcement. The ICO fine, TPR report, annual-report disclosures, and client notices should feed into board oversight, supplier assurance, procurement standards, trustee governance, and independent review. Repair should be durable across leadership changes and contract renewals.

Accountability follows the outsourced control surface

The final allocation follows practical control. Capita controlled affected systems, security operations, recovery work, data scoping, client communications, remediation evidence, and many operational platforms. Clients controlled their contract governance, data choices, public duties, and notices to their populations. Pension trustees controlled member-facing accountability and supplier oversight. Regulators controlled enforcement and lessons. Affected people controlled only limited protective actions after they were told enough to act.

That allocation does not mean Capita is responsible for every downstream harm alleged in public debate. It means the supplier with operational control had the strongest duty to produce evidence quickly and accurately. It also means public bodies and trustees cannot treat outsourcing as an accountability shield. If a public-service supplier is a critical dependency, oversight of that supplier is part of the service.

The Capita case remains important because it exposes a recurring public-sector problem. Outsourcing can make services look administratively efficient while hiding the technical control surface that holds citizen and member data. When that control surface fails, the affected person experiences one event: a service they depend on and data they did not personally place with the supplier are suddenly uncertain. The legal contracts may divide responsibility, but the public experience does not.

The durable lesson is that supplier cyber risk must be governed as public-service continuity risk. Contracts should demand evidence before incidents. Incidents should produce structured, client-specific proof. Regulators should test both supplier controls and client oversight. Trustees and public bodies should explain dependency chains before members and citizens are forced to learn them through breach notices. Capita's 2023 cyber incident became a public-services accountability test because the real question was not only whether a private outsourcer recovered.

It was whether the people dependent on outsourced services could see, verify, and trust the recovery evidence.