Local government reorganisation turns your IT roadmap into someone else’s deadline. Merging into a new unitary council means merging networks, identity systems, supplier contracts and security postures, on a political timetable rather than a technical one. Nine in ten council leaders now expect the transition to increase cyber risk if it isn’t managed carefully, according to a survey reported by the District Councils’ Network.

What’s changing under local government reorganisation, and by when?

The English Devolution and Community Empowerment Act 2026 received Royal Assent on 29 April 2026. It replaces the two-tier structure of district and county councils with new unitary authorities, starting with the first-wave areas identified under the Devolution Priority Programme: Cumbria, Surrey, Hampshire, Essex, Kent and Sussex. The government has set a minimum population of 500,000 for a new unitary, with some flexibility case by case. Most of the new councils go live on vesting day in April 2028; Surrey moves a year earlier, in 2027, with shadow elections in May 2027 across most areas to match. For an IT function, that is a fixed date to inherit someone else’s network, someone else’s supplier contracts and someone else’s case management systems, whether or not the technical integration work is finished.

Why does local government reorganisation raise IT risk?

Merging councils means merging their differing approaches to cyber hygiene, and that gap is where the risk lives. Predecessor councils rarely share the same patching cadence, the same multi-factor authentication coverage or the same privileged access controls, and reorganisation forces them onto shared infrastructure before anyone has had time to check the other side’s estate properly. The Local Government Association’s own guidance on reorganisation now treats cyber, digital, data and technology as a named workstream in its own right, not a subsection of the finance and people integration plan. Shared or federated identity between councils that are still legally separate, ahead of vesting day, widens the attack surface at exactly the point when attention is split across a dozen other integration questions.

What does council IT consolidation actually involve?

Four things move at once: the network, so every site can reach every system; identity, collapsing several directories into one instead of several; supplier contracts, rationalising overlapping agreements into one; and the case management and finance applications that frontline staff use every day. None of it can wait for a quiet week, because a new unitary council still has to issue EHCPs, process adult social care assessments and answer FOI requests on day one under its new name. Sequencing matters more than speed. Identity and network access underpin everything else, so they need to be right before applications migrate onto them, not after.

We have run this kind of consolidation before it had this name attached to it. Agilisys has migrated or managed Microsoft 365 identities for more than 130,000 council users, and we already have AI running in production across 40 councils. We say that as the partner with an obvious interest in the answer, not from the sidelines: we would rather be chosen deliberately than inherited by default. Either way, we build your capability, not your dependency, so the merged team can run its own estate long after the vesting day announcement has faded from the local paper.

How long does council IT consolidation take?

A single application migration can be finished in months. A full council IT consolidation, covering network, identity, contracts and applications together, runs over multiple years, delivered in phases rather than one cutover. That gap between the political vesting date and the technical finish line is exactly why inter-authority agreements matter: they set out, in writing, who runs a shared service, who pays for it and how disputes get resolved while two or more legacy councils still depend on each other’s systems. Councils that treat vesting day as the finish line, rather than the start of a phased programme, are the ones still running dual identity systems and unreconciled contracts a year later.

Key takeaways

  • The English Devolution and Community Empowerment Act 2026 (Royal Assent 29 April 2026) puts most first-wave unitary councils live on vesting day in April 2028, with Surrey a year earlier in 2027.
  • Nine in ten council leaders expect reorganisation to raise cyber risk, largely because predecessor councils rarely share the same security posture before they are forced onto one network.
  • Network, identity, contracts and applications all move together, but identity and network access need to be right first, since everything else migrates onto them.
  • A full consolidation typically runs over multiple years in phases, so inter-authority agreements for shared services matter as much as the target architecture.
  • Vesting day is a legal cutover, not a technical one. Plan the IT programme to run longer than the political timetable, not to match it.

Frequently asked questions

When do new unitary councils go live in England?

Most areas in the first wave of local government reorganisation, including Cumbria, Hampshire, Essex, Kent and Sussex, move to new unitary councils on vesting day in April 2028. Surrey goes a year earlier, in 2027. Shadow elections take place in May 2027 for most areas, and in 2026 for Surrey, ahead of each area’s vesting day.

What IT systems need to be consolidated during local government reorganisation?

Four things move together: the council network, so every site can reach every system; identity, moving several directories to one; supplier contracts, collapsing overlapping agreements into one; and the case management and finance applications frontline staff use daily. Identity and network access need to be settled first, since everything else migrates on top of them.

Does local government reorganisation increase cyber security risk?

Yes, according to council leaders themselves. A District Councils’ Network-reported survey found that 90.3% expect reorganisation to raise cyber risk if it isn’t managed carefully, largely because merging councils rarely share the same patching, multi-factor authentication or privileged access standards before they are combined onto one network.

Sources