A small number of Dorset Council staff have not completed their required cyber security training, raising concerns about organisational risk.
The authority has acknowledged that, despite more than a year passing since the training became mandatory, some employees have still not taken part, even though it is a contractual obligation.
Independent audit and governance committee member Simon Roche expressed surprise that the issue remains unresolved, noting he had previously raised the matter and expected managers to ensure compliance given the potential risk of an IT breach.
Staff who have not completed the training have been asked to fill out a survey to explain their reasons, in an attempt to identify any barriers.
Councillor Jill Haynes suggested further investigation was needed to understand reluctance among some staff, commenting that some course content may be seen as irrelevant or demeaning.
The meeting also heard that a small number of officers working with vulnerable adults and children have not yet completed disclosure and barring checks, though they are supervised until the process is finished.
Corporate Director Sean Creamer said the council’s target for these checks remains one hundred percent, with delays mainly due to processing times.



