London Daily

Focus on the big picture.
Saturday, May 31, 2025

Bank of England audio leak followed loss of key cybersecurity staff

Bank of England audio leak followed loss of key cybersecurity staff

Exclusive: former employees say at least 20 security staff were reassigned or left in past year
The Bank of England restructured its security department and lost multiple senior employees in charge of protecting some of Britain’s most critical financial infrastructure shortly before it suffered a major breach, the Observer can reveal.

After the central bank admitted that hedge funds had gained early access to its market-moving press conferences via a backup audio feed, multiple former employees contacted the Observer to warn that the Bank was struggling with the departure of key staff responsible for protecting it against external threats.

The sources said at least 20 of the Bank’s staff tasked with information security had left or been reassigned elsewhere within the bank within the past year, raising questions over the protection of the nation’s payment systems and other critical infrastructure vital for the British financial system. The Observer was able to verify 13 of these departures using information from social media and other sources.

The revelations come at a sensitive time for the Bank as it prepares for the handover of power in March from Mark Carney, the outgoing governor, to Andrew Bailey, the current chief executive of the Financial Conduct Authority.

Threadneedle Street has also played a central role in efforts to improve the safety and integrity of the financial system since the 2008 banking collapse, including warning the industry to improve its cyber and information security operations. It is responsible for key parts of the nation’s critical infrastructure, including the payments systems that carry every bank transfer made in Britain, the wages of millions of people, cheques, and payments between businesses of all sizes. On an average day in 2018, the Bank’s real-time gross settlement system (RTGS) settled transactions worth £651bn.

According to the former employees, the Bank’s chief information security officer and two deputies have left in the past year.

Multiple former employees described the organisation as beset by budget cuts before Carney’s departure, against a backdrop of concerns over cost efficiency. They said there were problems with staffing given the departures and low staff morale.

Much of the disquiet stemmed from a move to dismantle the Bank’s “security and privacy” directorate, the people said. The team, part of the central services division, previously had oversight over cyber, personnel and physical security matters, as well as privacy. Staff and responsibilities were instead spread across other parts of the organisation.

It is understood that many of the people now sit under the Bank’s technology, security and risk directorates, in a move designed to make the organisation safer. The Bank has about 70 cybersecurity professionals.

A Bank of England spokeswoman said: “The Bank operates the highest standard of information security and is confident in our ability to recognise cyber threats and defend our systems appropriately. Earlier this year, the Bank completed a review of its central services target operating model and, as part of that, reinforced the arrangements for first- and second-line information security. This change was fully supported by the Bank’s audit and risk committee.”

The Bank admitted late on Wednesday night that it had suffered a security breach, with a provider of a backup audio feed of the governor’s market-sensitive press conferences selling early access to unnamed investors without its knowledge. Those investors could have used the few seconds’ advantage to profit.

It was alerted to the breach by the Times newspaper, conducted a rapid internal investigation and passed the matter to the FCA. The City watchdog has confirmed it is investigating the issue, and it is understood that Bailey will recuse himself from all discussions of the matter to avoid any suggestion of a conflict of interest.

The Bank’s chief operating officer, Joanna Place, is the most senior manager responsible for physical and information security, and faced calls to resign from a former member of the Bank’s monetary policy committee, Danny Blanchflower, following the breach. Place, who was appointed in July 2017, reports directly to the governor, and has an equal status to the Bank’s deputy governors.

Multiple sources said the Bank was under pressure to cut the budget of the central services division, which was managed by Place. They said the government spending watchdog, the National Audit Office, warned in December 2018 that the Bank needed to deliver better value for money.

Place told the Commons’ public accounts committee in January that the Bank did not “have any gaps in cybersecurity”. However, her chief information security officer, Cameron “Buck” Rogers, resigned little over a month later. Multiple other security experts followed him.

A spokeswoman for the Bank said Rogers resigned on 23 February and that Place was not aware he was going to quit when she gave evidence on 21 January.

At the hearing, Meg Hillier, the Labour chair of the committee, expressed surprise at Place’s answer, given the difficulties other public-sector organisations had with recruiting and retaining cyber security staff, and asked again if there were any vacancies.

Place responded: “Offhand, I do not know whether we have any vacancies, but we do not have a problem with recruiting and we do not have a problem with retention in cyber, either.”

There was widespread unease within the Bank following her testimony, multiple sources said, and in the months after her appearance the cybersecurity function suffered the outflow of staff.

The public sector struggles to retain staff in cybersecurity roles because of intense competition from the higher-paying private sector. However, the reputation of the Bank and its important role in protecting financial stability are attractive for potential candidates, and the sources said they believed it was in the public interest to shed light on the problems it was facing.

A Bank of England spokesperson said: “The incident relating to the misuse of a backup audio feed from the Bank’s press conferences by a third-party supplier, which the Bank has referred to the Financial Conduct Authority for further investigation, was not a cyber security issue.”
Newsletter

Related Articles

0:00
0:00
Close
Satirical Sketch Sparks Political Spouse Feud in South Korea
Indonesia Quarry Collapse Leaves Multiple Dead and Missing
South Korean Election Video Pulled Amid Misogyny Outcry
Asian Economies Shift Away from US Dollar Amid Trade Tensions
Netflix Investigates Allegations of On-Set Mistreatment in K-Drama Production
US Defence Chief Reaffirms Strong Ties with Singapore Amid Regional Tensions
Vietnam Faces Strategic Dilemma Over China's Mekong River Projects
Malaysia's First AI Preacher Sparks Debate on Islamic Principles
White House Press Secretary Criticizes Harvard Funding, Advocates for Vocational Training
France to Implement Nationwide Smoking Ban in Outdoor Spaces Frequented by Children
Meta and Anduril Collaborate on AI-Driven Military Augmented Reality Systems
Russia's Fossil Fuel Revenues Approach €900 Billion Since Ukraine Invasion
U.S. Justice Department Reduces American Bar Association's Role in Judicial Nominations
U.S. Department of Energy Unveils 'Doudna' Supercomputer to Advance AI Research
U.S. SEC Dismisses Lawsuit Against Binance Amid Regulatory Shift
Alcohol Industry Faces Increased Scrutiny Amid Health Concerns
Italy Faces Population Decline Amid Youth Emigration
U.S. Goods Imports Plunge Nearly 20% Amid Tariff Disruptions
OpenAI Faces Competition from Cheaper AI Rivals
Foreign Tax Provision in U.S. Budget Bill Alarms Investors
Trump Accuses China of Violating Trade Agreement
Gerry Adams Wins Libel Case Against BBC
Russia Accuses Serbia of Supplying Arms to Ukraine
EU Central Bank Pushes to Replace US Dollar with Euro as World’s Main Currency
Chinese Woman Dies After Being Forced to Visit Bank Despite Critical Illness
President Trump Grants Full Pardons to Reality TV Stars Todd and Julie Chrisley
Texas Enacts App Store Accountability Act Mandating Age Verification
U.S. Health Secretary Ends Select COVID-19 Vaccine Recommendations
Vatican Calls for Sustainable Tourism in 2025 Message
Trump Warns Putin Is 'Playing with Fire' Amid Escalating Ukraine Conflict
India and Pakistan Engage Trump-Linked Lobbyists to Influence U.S. Policy
U.S. Halts New Student Visa Interviews Amid Enhanced Security Measures
Trump Administration Cancels $100 Million in Federal Contracts with Harvard
SpaceX Starship Test Flight Ends in Failure, Mars Mission Timeline Uncertain
King Charles Affirms Canadian Sovereignty Amid U.S. Statehood Pressure
Trump Threatens 25% Tariff on iPhones Amid Dispute with Apple CEO
Putin's Helicopter Reportedly Targeted by Ukrainian Drones
Liverpool Car Ramming Incident Leaves Multiple Injured
Australia Faces Immigration Debate Following Labor Party Victory
Iranian Revolutionary Guard Founder Warns Against Trusting Regime in Nuclear Talks
Macron Dismisses Viral Video of Wife's Gesture as Playful Banter
Cleveland Clinic Study Questions Effectiveness of Recent Flu Vaccine
Netanyahu Accuses Starmer of Siding with Hamas
Junior Doctors Threaten Strike Over 4% Pay Offer
Labour MPs Urge Chancellor to Tax Wealthy Over Cutting Welfare
Publication of UK Child Poverty Strategy Delayed Until Autumn
France Detains UK Fishing Vessel Amid Post-Brexit Tensions
Calls Grow to Resume Syrian Asylum Claims in UK
Nigel Farage Pledges to Reinstate Winter Fuel Payments
Boris and Carrie Johnson Welcome Daughter Poppy
×