Issue - meetings

ICT Infrastructure Refresh Programme Capital Investment

Meeting: 04/08/2026 - Cabinet (Item 17)

17 ICT Infrastructure Refresh Programme Capital Investment pdf icon PDF 235 KB

Additional documents:

Minutes:

Background:

 

The report sought approval of a five-year capital programme to refresh Medway Council’s Information and Communications Technology (ICT) infrastructure between 2026 and 2031. A significant proportion of the Council’s current infrastructure was approaching or had reached end-of-life and no longer received vendor support, security updates or patches, which created increasing risks to service continuity, cyber security and operational resilience.

 

It was noted that in preparation for Local Government Reorganisation (LGR) in 2028, the ICT service had been engaging with neighbouring borough and district councils to help ensure that infrastructure procured through this programme was interoperable, scalable and capable of being used within the future authority structure. This was intended to future-proof the Council’s infrastructure and reduce the risk of duplicated investment during transition.

 

Decision

number: 

Decision:

 

113/2026

The Cabinet agreed Option 2, as set out in section 7 of the report, to implement a structured enterprise ICT infrastructure programme to ensure long-term compliance, stability, and cyber resilience, in line with the National Cyber Security Centre’s (NCSC’s) Cyber Essentials requirements.

114/2026

The Cabinet agreed to recommend to full Council the addition of £3,869,000 to the Capital Programme to be funded by prudential borrowing.

Reasons:

The programme will address key technical control areas outlined by the NCSC, including:

 

     Firewalls and boundary security: Ensuring all internet-connected devices are protected by properly configured firewalls

     Secure configuration: Replacing legacy systems with modern, securely configured hardware to reduce vulnerabilities.

     Access control: Enforcing least-privilege access and identity management across the infrastructure.

     Malware protection: Ensuring all endpoints and servers are protected with up-to-date anti-malware solutions.

     Patch management: Refreshing hardware to support timely updates and vendor support, reducing exposure to known exploits.

     Security Operations Centre (SOC) will provide 24/7 monitoring, threat detection, and incident response capabilities ensuring real-time protection of critical systems and data.

 

This investment is essential to maintain compliance with national standards, protect sensitive data, and support the Council’s digital transformation and LGR program. Without this refresh, ageing infrastructure will fall short of baseline security expectations, increasing the risk of service disruption, data breaches, and regulatory non-compliance.