Company Details
office-for-budget-responsibility
52
1,703
92
obr.uk
0
OFF_1177795
In-progress

Office for Budget Responsibility Company CyberSecurity Posture
obr.ukThe Office for Budget Responsibility (OBR) was established in May 2010 to provide independent assessments of the economy, public finances and fiscal sustainability. We provide independent forecasts of the economy and public finances, examine the impact of the Government's policy decisions on the public finances, and assess the prospects for achieving the Government's fiscal targets and welfare cap. We publish reports on long-term fiscal sustainability, fiscal risks and trends in welfare spending, and produce papers on economic and fiscal issues. Contact us at [email protected] or 02033346117
Company Details
office-for-budget-responsibility
52
1,703
92
obr.uk
0
OFF_1177795
In-progress
Between 650 and 699

OBR Global Score (TPRM)XXXX

Description: The **Office for Budget Responsibility (OBR)**, the UK’s independent fiscal watchdog, suffered a **critical data breach** when its **full fiscal forecast and key budget measures** were **prematurely published online**—**30 minutes before Treasury Chief Rachel Reeves’ official announcement** in the House of Commons. The leak, attributed to a **‘technical error’**, exposed **sensitive economic projections, tax policies, and financial strategies** meant to remain confidential until the formal budget release. The incident occurred amid **political turmoil**, undermining public trust in the government’s ability to manage confidential information.The OBR acknowledged the **serious error**, pledging investigations and reports to relevant authorities, including the Treasury. The leak **disrupted market expectations**, risked **insider trading or speculative financial moves**, and **embarrassed the Labour government**, which was already grappling with **internal dissent, broken election pledges, and economic instability**. While no **direct financial theft or ransomware** was involved, the **unauthorized disclosure of high-stakes economic data**—critical to national fiscal policy—**threatened financial market stability** and **eroded institutional credibility**, with opposition parties demanding resignations over the **governance failure**.


Office for Budget Responsibility has 53.85% more incidents than the average of same-industry companies with at least one recorded incident.
Office for Budget Responsibility has 56.25% more incidents than the average of all companies with at least one recorded incident.
Office for Budget Responsibility reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
OBR cyber incidents detection timeline including parent company and subsidiaries

The Office for Budget Responsibility (OBR) was established in May 2010 to provide independent assessments of the economy, public finances and fiscal sustainability. We provide independent forecasts of the economy and public finances, examine the impact of the Government's policy decisions on the public finances, and assess the prospects for achieving the Government's fiscal targets and welfare cap. We publish reports on long-term fiscal sustainability, fiscal risks and trends in welfare spending, and produce papers on economic and fiscal issues. Contact us at [email protected] or 02033346117


France Travail est un acteur majeur du marché de l’emploi en France où il s’investit pour faciliter le retour à l’emploi des demandeurs d’emploi et offrir aux entreprises des réponses adaptées à leurs besoins de recrutement. Les 55 000 collaborateurs de France Travail œuvrent au quotidien pour êtr

Le canton de Vaud, c’est plus de 800 000 personnes vivant dans plus de 300 communes ! Rejoindre l’Administration cantonale vaudoise, c’est s’engager aux côtés de près de 40’000 personnes unies dans un même but : servir la population. Pourquoi nous suivre ? Dédiez votre quart d’heure vaudois aux o

The NSW public sector includes ten departments and many agencies and organisations working together to develop policy and deliver important services such as health, education, housing, transport and infrastructure across NSW. We are over 300,000 dedicated people who share the same values - making a

Welcome! We're the National Oceanic & Atmospheric Administration or NOAA. From daily weather forecasts, severe storm warnings and climate monitoring to fisheries management, coastal restoration and supporting marine commerce, our products and services support economic vitality and affect more than

EThekwini Municipality is a Metropolitan Municipality found in the South African province of KwaZulu-Natal. Home to the world-famous city of Durban. EThekwini is the largest City in the province and the third largest city in the country. It is a sophisticated cosmopolitan city of over 3 468 088 peop

State government is the largest employer in Tennessee, with approximately 43,500 employees in the three branches of government. The State of Tennessee has approximately 1,300 different job classifications in areas such as administrative, health services, historic preservation, legal, agriculture, co

O Instituto Nacional do Seguro Social (INSS) é uma autarquia do Governo Federal do Brasil que recebe as contribuições para a manutenção do Regime Geral da Previdência Social, sendo responsável pelo pagamento da aposentadoria, pensão por morte, auxílio-doença, auxílio-acidente, entre outros benefício

Overview The Texas Health and Human Services Commission (HHSC) is an agency within the Texas Health and Human Services System. In September 2016, Texas began transforming how it delivers health and human services to qualified Texans, with a goal of making the Health and Human Services System more ef

Montréal est la plus grande ville francophone d’Amérique et elle se distingue par sa vitalité culturelle exceptionnelle et des forces créatrices reconnues mondialement. Elle se développe un peu plus chaque jour en une ville contemporaine, inclusive et dynamique sur les plans économique, culturel
.png)
An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was leaked...
Richard Hughes, head of Office for Budget Responsibility, says he has apologised to chancellor for 'letting people down'
The OBR was left humiliated on Wednesday when it prematurely published its latest fiscal outloook before the Chancellor's Budget.
The Office for Budget Responsibility (OBR) has hired a cybersecurity expert as part of its investigation into the UK's budget leak,...
An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was...
An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was...
OBR chairman Richard Hughes tells Radio 4's Today: 'It appears there was a link that someone was able to access - an external person'
Richard Hughes said he took full responsibility, adding: 'On behalf of the OBR I regret the deep disruption that it caused to the...
The document revealed the contents of Rachel Reeves' Budget and was accidentally published half an hour before the Chancellor announced the...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Office for Budget Responsibility is https://obr.uk/.
According to Rankiteo, Office for Budget Responsibility’s AI-generated cybersecurity score is 684, reflecting their Weak security posture.
According to Rankiteo, Office for Budget Responsibility currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Office for Budget Responsibility is not certified under SOC 2 Type 1.
According to Rankiteo, Office for Budget Responsibility does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Office for Budget Responsibility is not listed as GDPR compliant.
According to Rankiteo, Office for Budget Responsibility does not currently maintain PCI DSS compliance.
According to Rankiteo, Office for Budget Responsibility is not compliant with HIPAA regulations.
According to Rankiteo,Office for Budget Responsibility is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Office for Budget Responsibility operates primarily in the Government Administration industry.
Office for Budget Responsibility employs approximately 52 people worldwide.
Office for Budget Responsibility presently has no subsidiaries across any sectors.
Office for Budget Responsibility’s official LinkedIn profile has approximately 1,703 followers.
Office for Budget Responsibility is classified under the NAICS code 92, which corresponds to Public Administration.
No, Office for Budget Responsibility does not have a profile on Crunchbase.
Yes, Office for Budget Responsibility maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/office-for-budget-responsibility.
As of November 27, 2025, Rankiteo reports that Office for Budget Responsibility has experienced 1 cybersecurity incidents.
Office for Budget Responsibility has an estimated 11,098 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes (obr acknowledged error and committed to reporting to authorities), and containment measures with obr removed prematurely published content; issued public apology, and remediation measures with obr pledged internal review; report to treasury and relevant authorities, and communication strategy with rachel reeves labeled the leak 'deeply disappointing and a serious error' in parliament, communication strategy with obr issued a public statement attributing the leak to a 'technical error'..
Common Attack Types: The most common types of attacks the company has faced is Breach.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Economic Policy Documents, Taxation Plans, Fiscal Forecasts, Welfare Reforms and .
Incident Response Plan: The company's incident response plan is described as Yes (OBR acknowledged error and committed to reporting to authorities).
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: OBR pledged internal review; report to Treasury and relevant authorities, .
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by obr removed prematurely published content; issued public apology and .
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Associated Press (AP)Date Accessed: 2024-11-06.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Rachel Reeves Labeled The Leak 'Deeply Disappointing And A Serious Error' In Parliament and Obr Issued A Public Statement Attributing The Leak To A 'Technical Error'.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Rachel Reeves' Statement In House Of Commons; Obr Public Apology.
Most Recent Incident Detected: The most recent incident detected was on 2024-11-06.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-11-06.
Most Significant Data Compromised: The most significant data compromised in an incident were Budget fiscal forecasts, Tax policy details (e.g., income tax threshold freezes, mansion tax, capital gains tax changes), Welfare policy changes (e.g., child benefit restrictions lifted), Economic growth projections, Public finance buffers (£22 billion) and .
Most Significant System Affected: The most significant system affected in an incident was Office for Budget Responsibility (OBR) website.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was OBR removed prematurely published content; issued public apology.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Public finance buffers (£22 billion), Welfare policy changes (e.g., child benefit restrictions lifted), Economic growth projections, Tax policy details (e.g., income tax threshold freezes, mansion tax, capital gains tax changes) and Budget fiscal forecasts.
Most Recent Source: The most recent source of information about an incident is Associated Press (AP).
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (OBR internal review announced).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Rachel Reeves' statement in House of Commons; OBR public apology, .
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.