Article Details
Scrape Timestamp (UTC): 2025-11-28 12:07:16.085
Source: https://www.theregister.com/2025/11/28/obr_ciaran_martin/
Original Article Text
Click to Toggle View
OBR drags in cyber bigwig after Budget leak blunder. Ex-NCSC chief Ciaran Martin asked to examine how forecast ended up online ahead of schedule. The Office for Budget Responsibility (OBR) has drafted in former National Cyber Security Centre (NCSC) chief Ciaran Martin to sniff out how its Budget day forecast wandered onto the open internet before the Chancellor had even reached the dispatch box. Earlier this week, the OBR's November 2025 Economic and Fiscal Outlook (EFO) was quietly uploaded to a publicly accessible server in advance of publication. While it wasn't actually linked or listed on the OBR website, reporters quickly discovered the file simply by guessing its URL, which was so similar to that of a previous official document that the only real cyber skill required was remembering how months work. The link, which was accessible 45 minutes before the Chancellor rose in the Commons, spilled the Budget's headline policies before she'd even announced them, marking a monumental cock-up that made the embargo optional. OBR chair Richard Hughes was quick to apologize, calling the leak "a serious error" and promising swift action. "I felt personally mortified by what happened," he told BBC Radio 4's Today program. "The OBR prides itself on our professionalism. We let people down... and we'll make sure it doesn't happen again." The budget watchdog has launched an investigation [PDF] into the blunder, to be published by December 1, that will be overseen by the OBR's Oversight Board, and guided by Martin as expert advisor, alongside Treasury IT and security specialists. Martin, who founded the NCSC before stepping down in 2020, is now a cybersecurity advisor across public and private sectors – though he probably never imagined being summoned for what feels like the IT equivalent of mislabeling a sandwich in the office fridge. Still, the brief is written in seriousness, even if the leak was not. The terms of reference require "establishing the events that made it possible to access the EFO early," and "determining the actions needed... to ensure no future breaches." Whether Martin can restore faith, or merely inspire more online comedy, remains to be seen – though the comedy section is already live. As one Reddit user tartly put it: "You've uploaded it early with an easily guessable name," while another said: "Calls in cyber expert? How much are they wasting on paying a cyber expert to tell them not to upload the fucking document until it's ready to be published?" But even satire has a serious backbone: the terms of reference for the investigation spell out that the review must uncover what made early access possible, assess the publication pipeline that enabled it, and recommend both corrective measures and a timeline for implementation. The irony, of course, is that journalists will probably read the findings before the civil servants do – by simply guessing the URL.
Daily Brief Summary
The Office for Budget Responsibility (OBR) inadvertently uploaded its Economic and Fiscal Outlook online before the official announcement, leading to an unintended early disclosure of budget details.
Reporters accessed the document by guessing its URL, which closely resembled previous official document links, exposing significant procedural oversight.
OBR Chair Richard Hughes expressed regret over the incident, labeling it a "serious error" and committing to prevent future occurrences.
Former NCSC chief Ciaran Martin has been appointed to lead an investigation, supported by Treasury IT and security experts, to identify the breach's root cause.
The investigation aims to establish how the early access occurred, evaluate the publication process, and propose corrective actions to safeguard future releases.
The findings of the investigation are set for publication by December 1, with recommendations expected to enhance OBR's document management protocols.
This incident underscores the importance of robust digital security practices, even in seemingly low-risk environments, to prevent unauthorized access and information leaks.