{"id":464310,"date":"2026-06-06T18:07:28","date_gmt":"2026-06-06T18:07:28","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/464310\/"},"modified":"2026-06-06T18:07:28","modified_gmt":"2026-06-06T18:07:28","slug":"capita-launched-civil-service-pension-scheme-site-without-basic-web-security","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/464310\/","title":{"rendered":"Capita launched civil service pension scheme site without \u2018basic\u2019 web security"},"content":{"rendered":"<p>&#13;<\/p>\n<p>Capita was warned in December that the security of the web domain which manages the pensions of 1.7 million members of the Civil Service Pension Scheme (CSPS), lacked \u201cbasic controls\u201d.<\/p>\n<p>Only after the warning, through what Capita\u2019s chief information security officer (CISO) Luke Beeson acknowledged as a &#8220;responsible disclosure,&#8221; did Capita enable <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Protecting-the-DNS-protocol-How-DNSSEC-can-help\" rel=\"nofollow noopener\" target=\"_blank\">DNSSEC<\/a> on the CSPS domain.<\/p>\n<p>DNS hijacking\/DNS redirection is the biggest risk if DNSSEC is not enabled, meaning users could type the correct domain name and still go to a malicious site.\u00a0\u00a0<\/p>\n<p>Capita took over CSPS administration on 1 December last year, after a \u00a3239m contract was won in 2023. It has been beset by problems (<a href=\"#CSPS\">see box, below<\/a>).<\/p>\n<p> CSPS warning<\/p>\n<p>That same month, a warning to Capita from attack-surface management expert Andrew Jenkinson informed officials at the company, including CEO Adolfo Hernandez, that there were serious vulnerabilities in the CSPS domain. \u00a0<\/p>\n<p>In his initial contact on 6 December, soon after Capita took over CSPS administration, Jenkinson &#8211; an expert in areas including Domain Name System (DNS) and Public Key Infrastructure (PKI) security &#8211; wrote: \u201cNews of the CSPS issues prompted us to undertake some research as cited experts and the threat intelligence is simply too damning not to try and reach out to you all collectively.\u201d<\/p>\n<p>Jenkinson offers chargeable consultancy work to companies when he unearths security holes. \u201cWe identify vulnerabilities and share that information. Should a company want to take our consulting expertise that is discussed and agreed,\u201d he told Computer Weekly.<\/p>\n<p>The UK government encourages security experts to report any vulnerabilities they discover, with <a href=\"https:\/\/www.ncsc.gov.uk\/information\/vulnerability-disclosure-toolkit\" rel=\"nofollow noopener\" target=\"_blank\">advice on how to respond to such disclosures published by the National Cyber Security Centre<\/a>. Security researchers will often subsequently report those vulnerabilities publicly once they have been resolved by the affected company.<\/p>\n<p>In a follow-up email, Jenkinson told Capita CISO Beeson: \u201cThe report, like our expertise, are not a free service.\u201d Beeson replied: \u201cUnderstood, it would be very helpful to see the report when it\u2019s ready.\u201d<\/p>\n<p> Acted on warnings<\/p>\n<p>Beeson acknowledged in an email to Jenkinson that Capita enabled DNSSEC on the CSPS domain, along with other changes, after his warning.<\/p>\n<p>In an email to Beeson on 5 January this year, Jenkinson wrote: \u201cI am very pleased that following the threat intelligence we shared in December, DNSSEC has been implemented at the top-level domain for civilservicepensionscheme.org.uk, which addressed a key visibility and integrity gap.\u201d<\/p>\n<p>Beeson replied on 14 January: \u201cI\u2019m glad you spotted that we\u2019ve enabled DNSSEC on the CSPS domain.\u201d<\/p>\n<p>In another email to Jenkinson on 27 March, Beeson wrote: \u201cThank you again for all the responsible disclosures you\u2019ve shared. I can assure you that we\u2019re taking them seriously internally and acting on them where we can as we did with the CSPS DNSSEC implementation.\u201d<\/p>\n<p> Bare minimum<\/p>\n<p>Cindy Lawless, a US-based expert in cyber security quality, trust, and DNS security infrastructure, said failure to enable DNSSEC suggests a lack of skills.<\/p>\n<p>\u201cThis is pretty basic bare minimum stuff for managing a website,\u201d she told Computer Weekly. \u201cIt is a serious failure for a site that is financial in nature. Up until the time DNSSEC was enabled anyone could redirect that traffic and pretend to be the pension site. And the end-user wouldn\u2019t really know without digging,\u201d she added. \u201cIt\u2019s a huge blind spot.\u201d<\/p>\n<p>Lawless said there is no way to have the chain of trust authentication without it: \u201cThis is the only way to prove the DNS records are genuine.\u201d<\/p>\n<p>One source told Computer Weekly that a high-threat domain like CSPS \u201cneeds belt and braces,\u201d which DNSSEC provides.<\/p>\n<p>\u201cIn this context not having it is a big red flag, but not catastrophic depending on what else you have next. If [architecture] professionals went to a government or financial services website and it wasn\u2019t there, they would switch it on, they would want belt and braces.\u201d<\/p>\n<p>Steve Forbes, a security expert at UK internet domain registrar Nominet, said: &#8220;DNSSEC is an important tool for strengthening domain authenticity and protecting against certain types of DNS tampering, but it also introduces additional operational complexity, so needs to be carefully managed to avoid unintended availability risks.\u201d<\/p>\n<p>Forbes said it should be seen as a single part of a broader security approach, rather than a universal one-size-fits-all solution.<\/p>\n<p>\u201cIt may not be suitable in all situations, and there are other security measures that could be used to reduce the risk of attacks like cache poisoning and tampering in transit &#8211; which are common attacks that DNSSEC is used to prevent,&#8221; he added.<\/p>\n<p> Responsible disclosure<\/p>\n<p>Beeson offered to pay Jenkinson\u2019s company for work already completed. \u201cWhat value would you place on the work done to date? I ask as we have benefited from your responsible disclosure and therefore, I think it\u2019s right that we pay for that. If you could share what your fee would be we can discuss and agree terms via procurement,&#8221; he wrote on 30 March. Jenkinson\u2019s colleague wrote back setting out a price for work done and the fee arrangement.\u00a0<\/p>\n<p>On 7 April, after receiving the fee outline Beeson wrote to Jenkinson: \u201cWe appreciate you reaching out to us to share your concerns regarding Capita\u2019s external security posture. I am also grateful to you for finding the time to offer your services and subsequently share details of your fees were Capita minded to engage you.\u00a0<\/p>\n<p>\u201cI have previously explained to you that I am content with our security posture, which is always under constant review, and improvement, where required. On this basis, I do not think it necessary that Capita engage you and your services.\u201d<\/p>\n<p>A few days later, Jenkinson informed Capita of his intention to release information about the original vulnerability to the regulators and press.<\/p>\n<p>Following this Capita, through its legal representative Eversheds Sutherland, wrote to Jenkinson. It said he had \u201cnot been engaged by Capita to carry out any work on its behalf, nor [had] Capita at any time agreed to pay [him] for any actions [he] may have chosen to take of [his] own volition.\u201d<\/p>\n<p>Computer Weekly asked Capita why DNSSEC was not enabled on the CSPS domain when it went live and why was it only enabled after being warned about vulnerabilities by Jenkinson? The company did not answer.<\/p>\n<p>Computer Weekly also asked why, after offering to pay Jenkinson for what Beeson described as \u201cresponsible disclosures\u201d and future work, did Capita decide not to work with him? The company did not answer.<\/p>\n<p>Capita said: \u201cCapita takes cyber security extremely seriously and we are confident in our security posture. We have a comprehensive, continuously monitored security framework in place, and work transparently with government clients and the National Cyber Security Centre. Our latest annual cyber security maturity assessment &#8211; conducted by reputable external independent assessors &#8211; assessed us favourably across all dimensions of the National Institute of Standards and Technology (NIST) cyber maturity framework.\u00a0<\/p>\n<p>\u201cOur security measures meet all contractual requirements, and we continually review and strengthen them to keep pace with the rapidly changing security environment.<\/p>\n<p>\u201cCapita received an unsolicited approach from Andrew Jenkinson; we decided not to work with him for multiple reasons.\u201d<\/p>\n<p>BCS, Chartered Institite of IT, Fellow and cyber security expert Daniel Card said: \u201cI can only assume that Capita enabled DNSSEC to respond to a brand and reputational threat\/risk.<\/p>\n<p>\u201cDNSSEC has a place in some rather niche scenarios but generally speaking I advise caution &#8211; as mirrored by NCSC guidance etc,\u201d he told Computer Weekly.<\/p>\n<p>\u201cThe technical threat presented to Capita seems overplayed, their response seems like a PR move more than a technical one, and I don&#8217;t blame them, they probably felt they had no choice.\u201d<\/p>\n<p> Data breaches<\/p>\n<p><a>In late March, <\/a>the CSPS scheme experienced<a href=\"https:\/\/www.computerweekly.com\/news\/366641501\/Capitas-troubled-Civil-Service-Pension-Scheme-hit-by-data-breach\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0a minor data breach<\/a> affecting 138 members. According to the outsourcer, the issue led to scheme members being able to view personal annual benefit statements that were not their own. Computer Weekly has seen no evidence to suggest this was related to flaws identified by Jenkinson.\u00a0<\/p>\n<p>Separately to CSPS, last year the <a href=\"https:\/\/www.computerweekly.com\/news\/366632591\/ICO-fines-Capita-14m-after-ransomware-caused-major-data-breach\" rel=\"nofollow noopener\" target=\"_blank\">Information Commissioner\u2019s Office (ICO) fined Capita \u00a38m<\/a> and Capita Pension Solutions \u00a36m for failing to ensure the security of processing of personal data, which left it at significant risk. The ICO added that the company did not have the \u201cappropriate technical and organisational measures\u201d to respond effectively.<\/p>\n<p>The fine came after a <a href=\"https:\/\/www.computerweekly.com\/news\/365534245\/Three-day-Capita-outage-was-result-of-cyber-attack\" rel=\"nofollow noopener\" target=\"_blank\">Black Basta ransomware cyber attack<\/a> in March 2023 that affected several Capita clients, including the London boroughs of Barnet, and Barking and Dagenham. The ICO said six million people had been affected by the data breach, with the information stolen including pension and staff records and details of Capita\u2019s customers.<\/p>\n<p>After settling the fine with the ICO last year, Capita CEO Hernandez, said: \u201cWhen I joined as CEO the year after the attack I accelerated our cyber security transformation, with new digital and technology leadership and significant investment. As a result, we have hugely strengthened our cyber security posture, built in advanced protections and embedded a culture of continuous vigilance.&#8221;<\/p>\n<p> Regulators in the loop<\/p>\n<p>Jenkinson informed the Cabinet Office, which owns the CSPS, and the ICO, giving a detailed outline of the security issues he identified.<\/p>\n<p>On 20 April, Jenkinson emailed them, along with other government organisations, under the heading: \u201cSystemic cyber security failures impacting 1.7 million civil servants \u2013 immediate regulatory intervention required.\u201d<\/p>\n<p>He wrote: \u201cI am writing to formally escalate a matter of urgent national significance concerning systemic cyber security failures within the CSPS, currently administered by Capita plc since 1 December 2025.\u201d<\/p>\n<p>In response to a Computer Weekly question about this, the Cabinet Office said: \u201cWe remain in close contact with Capita on the wider security of the CSPS.\u201d<\/p>\n<p>The ICO was asked what, if any, action it would take in regard to Jenkinson\u2019s email. It sent Computer Weekly a statement about the cyber attack that hit the CSPS in March. Repeated attempts to get a response about Jenkinson\u2019s disclosure resulted in the ICO stating it had nothing to add to the statement about the earlier breach, to which the question was not related.<\/p>\n<p>According to figures from Tussell, Capita currently has 199 public sector contracts worth a combined\u00a0\u00a37.9bn.<\/p>\n","protected":false},"excerpt":{"rendered":"&#13; Capita was warned in December that the security of the web domain which manages the pensions of&hellip;\n","protected":false},"author":2,"featured_media":464311,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[138,246,111,139,69,244,245],"class_list":["post-464310","post","type-post","status-publish","format-standard","has-post-thumbnail","category-personal-finance","tag-business","tag-finance","tag-new-zealand","tag-newzealand","tag-nz","tag-personal-finance","tag-personalfinance"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/464310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=464310"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/464310\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/464311"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=464310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=464310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=464310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}