# Policies & Guidance

C-TAG and other useful guidance

From the linked pages on the left, you can read and download various guidance and policy documents. These have either been produced directly by C-TAG or through the WARPs etc.

&#x20;Remote Working Guidance January 2023

{% file src="/files/X8bc1qsRxttWaSD3Yjpc" %}


# Local Authority Intelligence Requirements

#### Introduction

&#x20;

The digital infrastructure of United Kingdom local government has undergone a seismic shift, evolving from a back-office administrative support function into the primary engine for essential public service delivery. This “GovTech” transformation, characterised by the "Digital by Default" \[43] philosophy, has significantly expanded the attack surface of local authorities, rendering them susceptible to a spectrum of sophisticated cyber threats that range from opportunistic ransomware campaigns to targeted state-sponsored espionage.\[1, 2]

&#x20;

This proposes a holistic approach to understand, define and specify the cyber Intelligence Requirements for UK Local Authorities. This will help support those councils engaged in the  Local Government Reorganisation (LGR) \[44] work . This approach integrates identified threats in 2026,\[45] integrating the NCSC CAF \[46] and utilising the LACES framework \[47].

&#x20;

UK Local Authorities, do not have a common  understanding or approach, to define their “Intelligence Requirements”. Local governments increasingly adopt emerging “GovTech” technologies, such as artificial intelligence and cloud-based services, the requirement for a robust, intelligence-led approach to security becomes paramount.\[3, 4]&#x20;

&#x20;

The fundamental challenge lies not merely in the procurement of defensive technologies, but in the precise identification of Cyber Intelligence Requirements (CIRs) and the subsequent development of meaningful, outcome-oriented metrics that align technical performance with organisational mission and public value.\[2, 4] This view has been formed from observations over the past seven years, working closely with the UK Local Government community.

&#x20;

&#x20;

#### &#x20;

Table of Contents

[Introduction](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750486)

[The approach we took](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750487)

[The Evolving Cyber Threat Landscape and the Municipal Environment](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750488)

[Theoretical Foundations of Cyber Intelligence and the Public Sector](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750489)

[The Intelligence Cycle as an Operational Blueprint](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750490)

[Adaptation of Military Doctrine to Municipal Cyber Defence](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750491)

[Intelligence Preparation of the Digital Environment (IPDE)](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750492)

[The "Strategy House" for CTI Alignment](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750493)

[The NCSC Cyber Assessment Framework (CAF) as a Performance Enabler](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750494)

[Mapping the CAF to Intelligence and Metrics](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750495)

[Advanced Resilience Metrics for Cloud-and-AI-Enabled GovTech](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750496)

[The Unified Resilience Model for GovTech](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750497)

[The Human Element: Socio-Technical Metrics and Cultural Intelligence](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750498)

[Trust and Inclusion as Security Metrics](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750499)

[Implementation Strategy for UK Local Government Reorganisation (LGR)](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750500)

[Resource and Time Commitment Estimates](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750501)

[The LACES Framework: A Holistic Principles Led Approach for Local Government](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750502)

[Core Dimensions of the LACES Framework](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750503)

[Integration of Physical and Digital Domains](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750504)

[Integrating LACES into Cyber Strategy](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750505)

[Cyber Threat Horizon Scanning in 2026](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750506)

[Operationalising Cyber Intelligence: From Horizon Scanning to CAF Compliance](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750507)

[Conclusion and future work:](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750508)

[Toward an Intelligence-Led  Resilience Model to support civic society](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750509)

[Bibliography](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750510)

&#x20;

#### &#x20;

#### The approach we took

&#x20;

The research followed a practice based, ethnographic approach. The qualitative evidence base has been collected through observations over the past seven years from working with a number of UK WARPS (Warning, Advice and Reporting Points) \[48] and the CTAG (Cyber Technical Advisory Group) \[49]. Evidence comprises the authors personal notes, discussions, meeting agendas and minutes.  A literature review was undertaken to ensure current UK Government strategy and policy was reflected in this paper.&#x20;

&#x20;

#### The Evolving Cyber Threat Landscape and the Municipal Environment

&#x20;

The contemporary threat landscape for UK local authorities is marked by a widening gap between the complexity of digital threats and the defensive capabilities of organisations often burdened by legacy technology and constrained budgets.\[5] Recent survey data indicates that UK businesses, including those in the public sector, are among the most frequently targeted globally, with 65% of firms reporting at least one attack in the previous year.\[6] Within this context, local government operations represent a unique target profile due to the concentration of sensitive citizen data and the criticality of the services provided, such as social care, electoral management, and housing benefits.\[2, 7]. These key cyber threats are identified in Table1, this list reflects the primary attack vectors as examples where further intelligence collections would be useful. There are many other threats we could consider in the wider context of Information Assurance and Risk Management.&#x20;

&#x20;

&#x20;

| Threat Category           | Primary Driver           | Impact on Local Authority                                                                           |
| ------------------------- | ------------------------ | --------------------------------------------------------------------------------------------------- |
| Ransomware                | Financial Gain           | Disruption of essential services, data exfiltration, and financial loss from recovery costs.\[8, 9] |
| Business Email Compromise | Fraud / Financial Gain   | Diversion of public funds, identity theft of staff and residents.\[6, 10]                           |
| Cyber Espionage           | Geopolitical / Strategic | Loss of intellectual property related to urban planning or sensitive demographic data.\[8, 11]      |
| Supply Chain Attacks      | Indirect Access          | Compromise of trusted vendors leading to cascading failures across council systems.\[6, 12]         |

<p align="center">Table 1: Key Cyber Threat Categories (Source: Author)</p>

&#x20;

The rapid adoption of AI-driven tools further complicates this landscape. While AI offers opportunities for enhanced detection, it also enables adversaries to achieve greater scale and sophistication in phishing and social engineering attacks.\[3, 8] This environment necessitates a shift from reactive cybersecurity—focused on firewall blocks and antivirus alerts—to proactive cyber intelligence, which seeks to anticipate and mitigate threats "left of the hack".\[13, 14]&#x20;

&#x20;

There are many existing frameworks, that could be deployed, the Lockhead Martin Kill Chain, The NIST CSF, The Mitre ATT\&CK framework The CERT-EU Cyber Threat Intelligence Framework and many others. \[20] &#x20;

&#x20;

This paper proposes an approach suitable for UK Local Authorities and the Public Sector, to support the CAF version 4.0 Framework \[39] moving forward. The Whole area of Cyber Threat Intelligence is not well understood, from the anecdotal observations, through the regional WARPs (Warning, Advice and Reporting Points), \[48] over the past 20 years.&#x20;

&#x20;

#### Theoretical Foundations of Cyber Intelligence and the Public Sector

&#x20;

Defining the distinction between cybersecurity and cyber intelligence is a vital prerequisite for organizational maturity. Cybersecurity involves the protective practices used to ensure the confidentiality, integrity, and availability of systems.\[15, 16] Cyber intelligence, conversely, is the systematic process of acquiring, processing, analysing, and disseminating information that identifies, tracks, and predicts threats and opportunities to enhance strategic decision-making.\[17] For local government, this intelligence provides the context necessary to prioritise limited resources on the most significant threats.\[9, 18]. This is a core requirement of the NCSC (National Cyber Security Centre)  CAF (Cyber Assessment Framework).&#x20;

&#x20;

#### The Intelligence Cycle as an Operational Blueprint

&#x20;

The practice of cyber intelligence is governed by a repeatable workflow known as the Intelligence Cycle. This framework ensures that intelligence activities are purposeful and aligned with organizational needs.\[19, 20] The proposed intelligence cycle is shown in figure 1.

&#x20;

• Direction and Planning: Identifying key information assets, comprising systems, services and data, such as the electoral register or social care portals, and defining the specific questions that need answering to protect them.\[7, 9]

• Collection: Gathering raw data from internal system logs, open-source intelligence (OSINT), and shared threat feeds.\[19, 20]

• Processing: Filtering, normalising, and structuring raw data into a format suitable for analysis.\[9]

• Analysis: Transforming and enriching data into intelligence by identifying patterns, assessing threat actor intent, and correlating threats with local vulnerabilities.\[16, 19]

• Dissemination and Feedback: Delivering actionable insights to decision-makers and using their feedback to tune and refine future requirements.\[17, 19]

&#x20;

A significant portion of the intelligence needed by local government is available through open sources. Methodical Open-Source Intelligence (OSINT) collection—defined as the purposeful exploitation of publicly available information to fulfil an intelligence requirements which would allow councils to monitor the broader threat environment without significant financial investment.\[18, 20, 21] These core elements feed into the risk management and assurance process cycles.&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 1: The Intelligence Cycle (Source: Author)</p>

#### Adaptation of Military Doctrine to Municipal Cyber Defence

&#x20;

To achieve a sophisticated level of intelligence requirement identification, local government can adapt established military frameworks, such as Intelligence Preparation of the Battlefield (IPB) or Intelligence Preparation of the Environment (IPE).\[22, 23] These doctrines provide a systematic methodology for understanding the "terrain" of a digital city and the capabilities of the "enemy".\[22, 24] These approaches are widely understood in the both the military and intelligence communities. Cyber is acknowledged to be the fifth battle domain. \[50] The current global situation is manifesting through a number of cyber operations which are affecting the UK’s Critical National Infrastructure, which includes national and local government. The UK defence strategy, talks about the whole societal approach. \[51] This in turn supports the doctrine of having a resilient civic society. \[52]

&#x20;

#### Intelligence Preparation of the Digital Environment (IPDE)

&#x20;

The IPDE process involves four continuous steps that, when applied to local government, provide a comprehensive understanding of the risk landscape.\[22, 23]

1\. Define the Operational Environment: Identifying and mapping, the limits of the council’s digital footprint, including third-party cloud services, Internet of Things (IoT) infrastructure in smart cities, and remote access points for staff.\[22, 25]

2\. Describe Environmental Effects: Analysing how the digital terrain influences operations. For example, how a single point of failure in a shared authentication service could impact multiple council departments.\[4, 22]

3\. Evaluate the Threat: Creating threat models for specific actors, such as ransomware groups or hacktivists, and identifying their known tactics, techniques, and procedures (TTPs).\[9, 23]

4\. Determine Threat Courses of Action (COAs): Predicting the most likely and most dangerous actions a threat actor might take, such as disrupting the council’s ability to process council tax payments during a critical financial window.\[22, 23]

Once gaps in the council's knowledge of the environment and threat are identified, they become the foundation for initial intelligence requirements.\[22] This needs to be considered in conjunction with a sectoral risk assessment to develop a sectoral (Local Government) Threat Profile.&#x20;

&#x20;

#### Identification of Cyber Intelligence Requirements (CIRs)

&#x20;

Identifying Cyber Intelligence Requirements (CIRs) is an organisational responsibility that requires collaboration across various functions, including IT, finance, social services, and legal teams.\[7, 19] Requirements should not be technical "wish lists" but should be derived from the council's strategic goals and risk appetite.\[10, 26]

Priority Intelligence Requirements (PIRs) and Specific Intelligence Requirements (SIRs)

A structured approach involves the hierarchy of Priority Intelligence Requirements (PIRs) and Specific Intelligence Requirements (SIRs).\[19, 27] Table 2 illustrates a couple of PIR/SIR examples.&#x20;

&#x20;

&#x20;

• PIRs: High-level questions that a "Senior Leader" (e.g., a Chief Executive or Senior Information Risk Owner) needs answered to make a strategic decision.\[27, 28]

• SIRs: Granular, answerable questions derived from PIRs that direct the collection efforts of analysts.\[19, 29]

&#x20;

&#x20;

| Requirement Type | Example for Local Government                                                                                                  | Strategic Decision Informed                                                    |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
| PIR              | What is the likelihood of a state-sponsored actor disrupting local electoral systems during the 2025 cycle? \[13, 28]         | Allocation of emergency capital for electoral system hardening.\[2]            |
| SIR              | Are there active phishing campaigns targeting election officials that utilise TTPs associated with known APT groups? \[9, 19] | Implementation of targeted MFA and staff awareness training.\[7, 10]           |
| PIR              | Which of the council's third-party cloud providers pose the greatest risk to service continuity for social care? \[26, 30]    | Development of a multi-cloud strategy or exit plan for critical systems.\[4]   |
| SIR              | Have any recent data breaches been reported by Vendor X's other public sector clients in the last 6 months? \[6, 9]           | Activation of enhanced monitoring and audit of Vendor X's access logs.\[4, 31] |

<p align="center">Table 2: Example PIRs / SIRs</p>

&#x20;

&#x20;

&#x20;

<p align="center">Figure 2: Illustration of the Intelligence Hierarchy – (Source: Author).</p>

#### The "Strategy House" for CTI Alignment

&#x20;

The "Strategy House" model provides a visualisation of how cyber threat intelligence (CTI) activities support broader departmental goals.\[32] In this model, the foundation is the council’s mission (e.g., providing safe and efficient community services). The pillars represent the tactical and operational intelligence functions, while the roof represents the strategic intelligence that guides the Senior Management Team (SMT).\[28, 32]&#x20;

&#x20;

This alignment prevents "wasteful spending" by ensuring that CTI efforts are moored to business context rather than chasing irrelevant technical indicators.\[10, 32]

&#x20;

Developing Meaningful Cyber Security Metrics

&#x20;

Having defined intelligence requirements, local authorities must transition to quantifying their security posture through metrics that reflect outcomes rather than mere activity.\[2, 33] Traditional metrics, such as "number of firewall hits," are often insufficient as they fail to reveal whether security efforts are actually reducing risk or preparing the organization for resilience.\[33, 34]

&#x20;

The Goal-Question-Metric (GQM) Paradigm

&#x20;

The GQM approach is a widely recognised academic framework for developing purposeful measurements.\[35, 36] It assumes that an organization must specify goals, match those goals to operational questions, and then provide quantifiable metrics to answer those questions.\[35, 36]

&#x20;

&#x20;

1\. Conceptual Level (Goal): Defined for an object (e.g., a social care database) for a specific reason (e.g., ensuring data integrity) from a particular perspective (e.g., the Data Protection Officer).\[35, 36]

2\. Operational Level (Question): A set of questions that characterise the object of study. For example, "How frequently are unauthorised attempts to modify records detected?".\[25, 36]

3\. Quantitative Level (Metric): A set of data associated with every question. For instance, "Mean Time to Detect (MTTD) unauthorised database changes".\[2, 4]

&#x20;

The GQM paradigm is particularly effective for municipal organizations because it allows for the "quantitatively expressed reduction of uncertainty" in complex, data-heavy environments.\[36]

&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 3: The GQM Process – (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

| GQM Level | Example Application: Council Tax System                                                                        | Rationale                                                                                 |
| --------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Goal      | Ensure the resilience of tax collection against ransomware disruption.\[35, 36]                                | High-priority revenue driver and essential public service.\[7, 12]                        |
| Question  | How long can the system remain offline before the impact on the council’s liquidity becomes critical? \[2, 31] | Characterizes the "acceptable loss" threshold for resilience.\[34, 37]                    |
| Metric    | Percentage of backups successfully restored within the 4-hour recovery window.\[4, 34]                         | Provides an objective measure of the system's ability to "withstand and recover".\[4, 34] |

<p align="center">Table 3: Example GQM Levels and Application</p>

&#x20;

Internal Efficiency vs. External Effectiveness

&#x20;

Research into cyber security performance identifies a critical distinction between internal efficiency—how well the security function operates—and external effectiveness—how well security supports the council’s mission.\[38]

&#x20;

• Internal Efficiency Metrics: These measure the "maturity" of IT processes, such as the percentage of systems compliant with the Minimum Cyber Security Standard, patching frequency, and the cost per incident handled.\[32, 38] These are often of moderate interest to senior leaders.\[38]

&#x20;

• External Effectiveness Metrics: These focus on "public value" outcomes. Examples include service continuity scores for citizens, inclusion metrics to ensure vulnerable groups are protected, and the "trust level" reported by residents regarding the safety of their digital data.\[2]

&#x20;

For local government, the strategic integration of these two dimensions is necessary to justify cyber spending not as a "back-office" cost but as a "public value proposition".\[2, 38]

&#x20;

#### The NCSC Cyber Assessment Framework (CAF) as a Performance Enabler

&#x20;

The UK Government has set out plans to adopt the NCSC Cyber Assessment Framework (CAF) as the primary assurance framework for public sector resilience.\[7, 31] The CAF provides a systematic approach to assessing the extent to which risks to essential functions are being managed.\[31, 39]

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

#### Mapping the CAF to Intelligence and Metrics

&#x20;

&#x20;

&#x20;

<p align="center">Figure 4: Mapping the Intelligence Process to the  CAF (Source: Author)</p>

&#x20;

&#x20;

The CAF is built on four core objectives, which can be directly mapped to the intelligence requirements and metrics discussed previously.\[7, 31]

&#x20;

• Objective A: Managing Security Risk: Requires intelligence on organizational structure and the supply chain.\[39, 40] Metrics include the "percent of critical systems with validated system architecture diagrams".\[7]

• Objective B: Protecting Against Cyber Attack: Requires tactical intelligence on TTPs.\[9, 40] Metrics include the "frequency of identity and access control reviews" and "staff awareness reporting rates".\[40, 41]

• Objective C: Detecting Cyber Security Events: Requires operational intelligence on active campaigns.\[9, 40] Metrics include the "percent of anomalous activity identified by proactive security monitoring".\[4, 40]

• Objective D: Minimizing the Impact of Cyber Security Incidents: Requires strategic intelligence on business continuity.\[28, 40] Metrics include the "time-to-recovery for essential functions" and the "implementation rate of lessons learned from previous incidents".\[31, 34]

&#x20;

The CAF utilises Indicators of Good Practice (IGPs) to evaluate if outcomes are 'Achieved', 'Partially Achieved', or 'Not Achieved', providing a standardised "baseline" that local authorities must meet at specified frequencies.\[7, 31, 40]

&#x20;

#### Advanced Resilience Metrics for Cloud-and-AI-Enabled GovTech

&#x20;

As local authorities migrate to cloud-and-AI-enabled platforms, new vulnerabilities emerge that require specialised metrics.\[4] These platforms increase the "attack surface" and create high levels of interdependency between public systems.\[4]

&#x20;

#### The Unified Resilience Model for GovTech

&#x20;

A proposed resilience framework for GovTech platforms integrates technical, organizational, and legal dimensions.\[4] The proposed GovTech capability lays the foundation for the Local Government Reorganisation (LGR) work, as a number of councils will be affected by the LGR, standardised approaches which will be developed through the Cyber Technical Advisory Group (CTAG) \[49], will ensure shared learning and mitigation of key risks, especially through supply chain assurance. This starts to augment the utility of the LACES framework, \[47] through practical knowledge sharing (Phronesis). \[53] The 2026 Horizon Scanning report \[54], highlights a number of key risks, threats and vulnerabilities. The summary findings are explored later in this paper.&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 5: The "GovTech" Concept to model Cyber Intelligence Requirements (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

Key Performance Indicators (KPIs) in this model include:

&#x20;

• Zero Trust Maturity: Percent of micro-segmented workloads and the frequency of continuous authentication events.\[4, 25]

• AI Governance: Percent of production AI models with documented provenance and adversarial robustness test pass rates.\[4]

• Privacy-Preserving Computation: Usage scores for technologies like federated learning or homomorphic encryption when handling sensitive demographic data.\[4]

• Organizational Capacity: Number of full-time security staff per 100 IT staff and annual cybersecurity training hours per employee.\[4, 8]

&#x20;

These metrics allow governments to "operationalise resilience" rather than treating it as an abstract ideal.\[4]

&#x20;

#### The Human Element: Socio-Technical Metrics and Cultural Intelligence

&#x20;

Cybersecurity in local government is a "socio-technical" challenge that cannot be solved by technical controls alone.\[41, 42] The "human element"—including the cognitive biases and heuristics of decision-makers—plays a critical role in resilience.\[38, 42]

&#x20;

#### Trust and Inclusion as Security Metrics

&#x20;

In the public sector, cybersecurity is increasingly recognised as a matter of "social justice".\[2] If digital services are not secure, vulnerable populations may be disproportionately impacted or excluded from essential services.\[2]

&#x20;

• Trust Enabler Metrics: Tracking citizen confidence in the safety of digital services as a predictor of digital transformation success.\[2]

• Inclusion Metrics: Ensuring that security measures do not create barriers for citizens with low digital literacy or those relying on older, less secure devices.\[2]

Furthermore, internal "cultural intelligence" is vital. Organizations must measure the stress and burnout levels of their cyber teams, as high stress (reported by 39% of victims) and burnout (32%) lead to increased human error and higher security risk.\[6, 8]

&#x20;

&#x20;

#### Implementation Strategy for UK Local Government Reorganisation (LGR)

&#x20;

For a local authority to successfully define requirements and metrics, a collaborative governance structure is essential. This involves identifying core roles such as the CAF Lead (often a cyber security specialist) and the Approver (a senior leader like a SIRO or Head of IT).\[7]&#x20;

&#x20;

#### Resource and Time Commitment Estimates

&#x20;

Developing a robust intelligence and measurement framework is a significant undertaking. Estimates for local government CAF implementation provide a benchmark for the level of effort required \[7]:

&#x20;

• Preparation and Role Identification: \~45 hours.\[7]

• Scoping and Critical System Identification: \~35-40 hours.\[7]

• Organisational Self-Assessment (Objectives A & D): \~40 hours.\[7]

• Mapping Architecture of 3 Critical Systems: \~15-25 hours per system.\[7]

• Critical Systems Self-Assessment (Objectives B & C): \~60 hours per system.\[7]

&#x20;

&#x20;

These time commitments reflect the shift from "tick-box" exercises to actionable resilience planning that requires engagement from directors, service leads, procurement, and risk managers.\[7] These timescales especially apply to the assurance process relating to key suppliers. The author is not aware that this is actually happening at scale and it has been identified a  key priority for the CTAG 2026 work programme, to facilitate a project to define and refine a common approach for UK Local Government to follow.&#x20;

&#x20;

#### The LACES Framework: A Holistic Principles Led Approach for Local Government

Building upon the necessity for a strategic and intelligence-led cybersecurity posture, the **Local Authority Cyber Eco-System (LACES)** framework offers a comprehensive model designed specifically for the complexities of the UK public sector. Developed to address the limitations of rigid, policy-driven cybersecurity measures, LACES advocates for a **principles-led approach** that is better suited to managing dynamic threats and the evolving digital landscape. This supports the notion of a resilient civic society, in a digital and cloud first world. This reflects modern statecraft, understanding “Cyber” as the fifth battle domain in a “Post rules, Disinformation & Post-Truth “ era. These issues were identified and validated during the recent Chatham House 2026 Directors Lecture. \[52]&#x20;

While frameworks like the NCSC’s Cyber Assessment Framework (CAF) provide assurance mechanisms, LACES bridges the gap between technical controls and organisational science, ensuring that cybersecurity is treated as a holistic business issue rather than solely a technical function.

&#x20;

&#x20;

&#x20;

&#x20;

#### Core Dimensions of the LACES Framework

&#x20;

&#x20;

&#x20;

<p align="center">Figure 6: LACES Framework (Source: Author)</p>

&#x20;

&#x20;

The framework is structured around six interconnected variables that function as a cohesive ecosystem. These variables can be viewed through a "variable-centric" lens, allowing organisations to shift focus depending on the operational context while maintaining a holistic view.

1. **Governance:** This provides the overarching oversight and direction for the ecosystem. It involves establishing clear policies, risk appetite, and structures such as a Corporate Information Governance Group (CIGG) and Senior Information Risk Owner (SIRO) to ensure cybersecurity is integrated into strategic decision-making.
2. **Assurance:** This dimension validates the effectiveness of security controls and manages risk, including supply chain vulnerabilities. It moves beyond "tick-box" compliance to a robust assessment of threats and vulnerabilities, often utilising mechanisms like penetration testing and health checks.
3. **Processes:** This covers the workflows, systems, and procedures (both manual and automated) used to deliver services. It recognises that processes bridge the physical and digital domains and must be documented and managed to ensure secure data transfer and operational integrity.
4. **Data:** Considered the "life blood" of local authorities, this variable focuses on the protection, management, and governance of information throughout its lifecycle—from creation to destruction. It emphasises the confidentiality, integrity, and availability of data in compliance with regulations like GDPR.
5. **Resilience:** Going beyond protection, this focuses on the ability to withstand, respond to, and recover from incidents. It includes business continuity planning, disaster recovery, and the implementation of "break glass" policies to restore critical services during disruptions.
6. **Knowledge Sharing:** This is the critical enabler of the ecosystem. It emphasises collaboration, peer support, and the exchange of "phronesis" (practical wisdom) through networks such as Warning, Advice and Reporting Points (WARPs) and the Cyber Technical Advisory Group (CTAG). This feedback loop ensures continuous improvement and situational awareness across the sector.

#### Integration of Physical and Digital Domains

A distinct feature of the LACES framework is its recognition that the cyber ecosystem exists simultaneously in **physical** and **digital** domains.

* **Physical Domain (Place-based):** Includes organisational structures, hierarchies, physical security measures, personnel, and culture.
* **Digital Domain (Process-based):** Encompasses the intangible aspects such as software, data flows, logic, and virtual cloud-based information.

LACES encourages decision-makers to map these domains against the six variables. For example, under **Governance**, the physical domain might involve physical security audits and meeting locations for incident response, while the digital domain involves data protection policies and risk appetite statements.

#### Integrating LACES into Cyber Strategy

The LACES framework can be integrated into a local authority's cyber strategy to shift from a reactive compliance posture to a proactive, principles-led culture:

* **Strategic Alignment and Education:** LACES serves as an educational tool to help non-technical senior leaders (such as CEOs and elected members) conceptualise cybersecurity as a complex ecosystem rather than a niche IT problem. By presenting the six variables, leaders can better understand resource allocation needs across the organisation.
* **Complementing the CAF:** While the NCSC Cyber Assessment Framework (CAF) focuses on resilience and assurance, LACES provides the broader organisational context required to implement the CAF effectively. The six variables of LACES can be mapped directly to CAF objectives (e.g., LACES "Governance" aligns with CAF Objective A: Managing Security Risk), ensuring that compliance efforts are supported by robust organisational structures.
* **Operational Planning and Incident Response:** LACES can be used to structure incident response playbooks. For instance, during a Distributed Denial of Service (DDoS) attack, the framework guides the response by prompting specific actions across all variables—from invoking **Governance** protocols for communication to executing **Resilience** plans for service continuity and engaging in **Knowledge Sharing** with external bodies such as the regional warps and CTAG. .
* **Supply Chain Management:** In an era of cloud-first strategies and Zero Trust architectures, LACES assists in managing supply chain risks by ensuring that **Assurance** and **Governance** extends to third-party vendors and Software-as-a-Service (SaaS) providers, who are often outside direct control.

By adopting LACES, local authorities can standardise their approach, foster a culture of collaboration, and build a cyber posture that is resilient enough to adapt to emerging technologies like Artificial Intelligence and the evolving threat landscape.

#### Cyber Threat Horizon Scanning in 2026

&#x20;

<p align="center">Figure 7: Horizon Scanning Summary Threats (Source: Author)</p>

&#x20;

Introduction: The Tipping Point

As local government bodies refine their cyber intelligence capabilities, they must align their requirements not just with current threats, but with a rapidly solidifying "New Order" of geopolitical instability and technological acceleration. Horizon scanning indicates that by 2026, cybersecurity will transition from a niche technical concern to a fundamental pillar of organisational survival. The landscape is no longer defined merely by isolated malware incidents but by a professionalised, adaptive industry that exploits human trust and systemic fragility. Consequently, the identification of Cyber Intelligence Requirements (CIRs) must pivot to address a world where access to "compute"—the physical technologies and talent required to process data—has become a defining geopolitical risk.

The 2026 Threat Landscape: Deception and Speed To develop effective Priority Intelligence Requirements (PIRs), decision-makers must understand the five core trends expected to dominate the risk landscape:

1. AI-Driven Deception: Generative AI has enabled a new era of social engineering. Attackers now utilise "deceptive realism" to create hyper-realistic deepfakes of executives and suppliers. Intelligence requirements must specifically task analysts with monitoring for synthetic voice and video indicators that could facilitate fraud or reputational damage.
2. Machine-Speed Attacks: Adaptive malware is now capable of rewriting itself to bypass detection at speeds that outpace human-led security teams. This necessitates a shift in metrics from "time to respond" to "automation readiness" and the deployment of Managed Detection and Response (MDR) capabilities.
3. The Supply Chain as a Weapon: The "domino effect" has become a primary attack vector, where smaller, less protected vendors are breached to gain entry into major organisations. With only 14% of UK businesses currently reviewing supplier security, intelligence collection must expand to include the risk posture of the entire vendor ecosystem.
4. Triple Extortion: The threat of ransomware has evolved into multi-vector extortion, combining data encryption with theft, client harassment, and regulatory pressure.
5. OT and IoT Exposure: The push for internet connectivity into legacy Operational Technology (OT) and Internet of Things (IoT) devices has expanded the attack surface into physical infrastructure, creating pivot points for attackers to enter critical systems.

The Actor Profile: Proxies and Activated Societies The distinction between state-sponsored espionage and financial cybercrime is collapsing. Hostile states increasingly use networked criminal groups as "deniable proxies" to execute sabotage and intelligence gathering. Furthermore, local authorities face a new threat from "activated societies"—groups animated by social and political grievances who may utilise cyber tactics to target institutions they perceive as unaccountable. This includes "wild card" individuals radicalised by algorithmic echo chambers, escalating the risk of insider threats and physical-digital hybrid attacks.

Strategic Imperatives for Resilience Navigating this landscape requires a fundamental shift in governance and operational posture:

* Fiduciary Duty: Cybersecurity failure is now viewed as a failure of corporate governance. Boards must treat cyber resilience as a standing agenda item and a fiduciary duty, with Directors and Officers facing personal accountability for negligence.
* Zero Trust Architecture: The assumption that internal networks are safe is obsolete. Organisations must implement a "Zero Trust" baseline, requiring continuous verification of every user and device.

·       The "Golden Hour": Response planning must move from static documents to dynamic playbooks. The "Golden Hour" framework should be used to define critical first actions, empowering teams to make pre-authorised decisions during the onset of a crisis, through the use of break glass policies. \[53]

&#x20;

Applying the LACES Framework to Future Threats

The Local Authority Cyber Eco-System (LACES) framework remains the primary vehicle for managing these emerging risks, offering a holistic bridge between technical controls and organisational strategy.

* Governance & Assurance: To counter supply chain weaponisation, LACES mandates a move beyond "tick-box" questionnaires to continuous assurance. This includes requiring a Software Bill of Materials (SBOM) from critical vendors and establishing "right to audit" clauses. Governance structures must also address the "human in the loop" mandate for AI-driven decisions to prevent automated errors.
* Knowledge Sharing: In the face of "deceptive realism," formal policy updates are too slow. LACES emphasises the exchange of "Phronesis" (practical wisdom) through networks like Warning, Advice and Reporting Points (WARPs) to keep pace with rapidly evolving social engineering tactics.
* Resilience & Processes: To manage machine-speed attacks, LACES advocates for "Agile Assurance" and "Break Glass" policies. These protocols allow for the immediate isolation of compromised cloud segments or API credentials before a board meeting can be convened, preventing systemic failure.
* Data: With the rise of "triple extortion," the focus shifts to protecting the "enterprise knowledge fabric." This involves conducting Data Protection Impact Assessments (DPIAs) for all AI systems to ensure compliance and mitigate risks associated with large language models.

#### Operationalising Cyber Intelligence: From Horizon Scanning to CAF Compliance

**Introduction: Intelligence in the "New Order"** As the local government sector moves toward 2026, the threat landscape is defined by a volatile "New Order" characterized by the "War for Compute" and the weaponisation of trust. Horizon scanning indicates that cybersecurity has transitioned from a niche technical concern to a fundamental pillar of organisational survival, where failure is viewed as a breach of corporate governance. To navigate this, local authorities must move beyond static defence to a dynamic, intelligence-led posture. This chapter demonstrates how to apply the Intelligence Cycle to the specific threats identified in the 2026 landscape—such as AI-driven deception and supply chain contagion—and maps this process directly to the NCSC Cyber Assessment Framework (CAF). This is summarised in figure 8.

**The Intelligence Cycle in the 2026 Landscape** The Intelligence Cycle provides the operational blueprint for transforming raw data regarding the 2026 threat landscape into actionable resilience strategies.

1. **Direction (Requirements):** This phase translates the organisation's strategic risks into Priority Intelligence Requirements (PIRs). In the context of 2026, PIRs must pivot to address "deceptive realism"—the use of AI to create hyper-realistic deepfakes—and the "domino effect" of supply chain breaches.
2. **Collection:** This involves gathering data to answer the PIRs. In a "Zero Trust" era, collection must extend beyond internal logs to include Real-time Software Bill of Materials (SBOMs) from vendors and "phronesis" (practical wisdom) shared through Warning, Advice and Reporting Points (WARPs).
3. **Processing & Analysis:** Raw data is converted into intelligence. Analysts must now filter for "machine-speed" indicators, as adaptive malware can rewrite itself to bypass traditional detection.
4. **Dissemination & Feedback:** Intelligence is delivered to decision-makers (e.g., the SIRO) to trigger "Golden Hour" responses or inform long-term strategy.

<p align="center">Figure 8: Integrated Intelligence Cycle (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

**Worked Example:**&#x20;

**The "Domino Effect" Supply Chain Attack** The following example illustrates how a local authority applies the Intelligence Cycle to a specific 2026 threat scenario, utilizing the LACES framework to contextualise the response and the CAF to measure compliance.

**Scenario:** Horizon scanning identifies a high probability of "Triple Extortion" attacks where threat actors compromise minor vendors to gain entry into major public sector networks.

**Step 1: Direction (Defining the Requirement)**

The Chief Executive and SIRO establish a **Priority Intelligence Requirement (PIR):** *Which third-party suppliers possess high-level API access to critical council data and exhibit vulnerability to AI-driven social engineering?*.

* **CAF Alignment:** This fulfils **Objective A (Managing Security Risk)**, specifically Principle A2 (Risk Management), by identifying risks to essential functions.

**Step 2: Collection (Gathering the Data)**

The cyber intelligence team initiates collection:

* **Internal:** Mapping the "Information Asset Ecosystem" to identify all vendors with API integration.
* **External:** Requesting real-time Software Bill of Materials (SBOMs) from top-tier vendors.
* **Human Intelligence:** Monitoring WARP feeds for reports of "Vishing / Deep Fakes / Phishing" attacks targeting specific sectors (e.g., adult social care software providers).

**Step 3: Analysis (Correlating the Threat)**

Analysts correlate the collected data. They identify that "Vendor X," a payroll provider, uses a legacy authentication method vulnerable to AI-enhanced phishing and has recently reported a breach in a different region.

* **Risk Assessment:** The analysis confirms a high likelihood of a "domino effect" breach where Vendor X becomes a pivot point for "machine-speed" lateral movement into the council’s network.
* **CAF Alignment:** This supports **Objective C (Detecting Cyber Security Events)**, specifically C1 (Security Monitoring), by moving from reactive logging to proactive threat identification.

&#x20;

**Step 4: Dissemination (Triggering the Response)**

The intelligence is disseminated to the Crisis Management Team (CMT) with a clear assessment: *Imminent risk of supply chain compromise via Vendor X.*

* **Action:** The SIRO invokes the **"Golden Hour"** guide. The specific "Break Glass" policy is authorised, permitting the immediate revocation of Vendor X’s API credentials before a formal board meeting can convene.

**Step 5: Operationalising via CAF and LACES**

The intelligence cycle concludes by cementing the response into the organisation’s assurance framework. Table 4 provides some example linkages.&#x20;

| CAF Objective                    | Intelligence-Led Action (2026 Context)                                                                                                                                                                                                           | LACES Variable Applied                                                            |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------- |
| **A: Managing Security Risk**    | **Action:** Mandate "Right to Audit" clauses and SBOMs for all top 10 suppliers, moving beyond "tick-box" questionnaires. **Outcome:** Governance structures acknowledge supply chain fragility as a fiduciary duty.                             | **Governance & Assurance:** Ensuring oversight extends to third parties.          |
| **B: Protecting Against Attack** | **Action:** Implement a "Zero Trust" baseline. Enforce multi-person approval for financial transactions to counter deepfake (deceptive realism) fraud. **Outcome:**&#x48;ardening the attack surface against AI-driven social engineering.       | **Processes & Data:** Bridging physical checks with digital zero-trust protocols. |
| **C: Detecting Events**          | **Action:** Deploy Managed Detection and Response (MDR) to counter "machine-speed" attacks that outpace human monitoring. **Outcome:** Transitioning from "time to respond" to "automation readiness" metrics.                                   | **Assurance:** Validating controls against adaptive threats.                      |
| **D: Minimising Impact**         | **Action:** Rehearse "Rising Tide" scenarios using dynamic playbooks rather than static plans. Establish "Crash Gate" triggers for rapid escalation. **Outcome:**&#x45;nsuring "graceful degradation" of services rather than systemic collapse. | **Resilience:** Planning for recovery and continuity.                             |

<p align="center">Table 4 CAF Linkages to LACES (Source: Author)</p>

#### &#x20;

#### &#x20;

#### Conclusion

#### Toward an Intelligence-Led  Resilience Model to support civic society

&#x20;

The path toward cyber resilience in UK local government requires the strategic integration of intelligence requirement identification and meaningful performance quantification. By adopting established academic and professional frameworks—such as the GQM paradigm, the NCSC CAF, and military-derived IPDE processes—local authorities can move beyond a reactive posture.\[22, 31, 36]

&#x20;

Intelligence requirements must be become one foundational organisational goals, recognised as a corporate information risk. Every collection and analysis effort directly supports the continuity of essential public services.\[10, 32] Simultaneously, metrics must transition from measuring technical activity to measuring mission-centric outcomes, public value, and the "trust" that underpins the digital social contract between the state and its citizens.\[2, 4] This aspect of statecraft matters and supports a resilient civic society.&#x20;

&#x20;

Once a discovery process has been carried out and common local government intelligence requirements have been identified, they can the standardised, documented and shared as a polled data base of common risks, threats and vulnerabilities, affecting all UK local authorities. This artefact would be of great use as part of the LGR process and in turn support the effective managed of supply chain risk, an idented key threat to all local authorities and indeed, the wider public sector. Such a database of key threats, risks and vulnerabilities could be maintained nationally through a community peer support group such as CTAG. This also wholly supports the LACES Information and Knowledge Sharing approach.

&#x20;

As local governments navigate the "paradox" of adopting emerging technologies while managing legacy risks, the ability to "quantify what matters" will distinguish resilient organizations from those perpetually reacting to the latest crisis.\[8, 33] The ultimate goal is to reshape cybersecurity from a "necessary cost centre" into a strategic transformation enabler of speed, scale, and safety for the digital public square.\[2]

The World Economic Forum 2026 horizon scanning demands that local authorities and others transition from a posture of protection to one of resilience.\[55] This was a key message from the NCSC CyberUK 2026 conference. By integrating the LACES framework with the NCSC’s Cyber Assessment Framework (CAF), organisations can operationalise their intelligence requirements, turning abstract threats into manageable business risks. Whilst we cannot prevent cyber-attacks, careful planning and a intelligence led approach to threats, can help towards mitigating the impacts locally on what is likely to remain in the Cyber battle domain, a volatile world stage.&#x20;

<br>

&#x20;

#### Bibliography

&#x20;

1\. Publications | Local Government Association, [https://www.local.gov.uk/publications?sort\_order=ASC\&topic%5B5868%5D=5868\&sort\_by=title\&page=1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.local.gov.uk%2Fpublications%3Fsort_order%3DASC%26topic%255B5868%255D%3D5868%26sort_by%3Dtitle%26page%3D1)

2\. Rethinking Cyber Security as a Public Sector Value Proposition - Littlefish, [https://www.littlefish.co.uk/news-insights/cyber-security-services-public-sector-value-proposition/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.littlefish.co.uk%2Fnews-insights%2Fcyber-security-services-public-sector-value-proposition%2F)

3\. A UK Cyber Growth Action Plan - Imperial College London, [https://www.imperial.ac.uk/media/imperial-college/research-centres-and-groups/centre-for-sectoral-economic-performance/FINAL\_The\_UK\_Cyber\_Growth\_Action\_Plan\_Brochure\_RGB.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.imperial.ac.uk%2Fmedia%2Fimperial-college%2Fresearch-centres-and-groups%2Fcentre-for-sectoral-economic-performance%2FFINAL_The_UK_Cyber_Growth_Action_Plan_Brochure_RGB.pdf)

4\. Cyber-Resilient Public Infrastructure: Securing Government Systems ..., [https://journalwjarr.com/sites/default/files/fulltext\_pdf/WJARR-2025-2195.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fjournalwjarr.com%2Fsites%2Fdefault%2Ffiles%2Ffulltext_pdf%2FWJARR-2025-2195.pdf)

5\. Cyber resilience of UK digital infrastructure - UK Parliament, [https://researchbriefings.files.parliament.uk/documents/POST-PN-0753/POST-PN-0753.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fresearchbriefings.files.parliament.uk%2Fdocuments%2FPOST-PN-0753%2FPOST-PN-0753.pdf)

6\. Hiscox Cyber Readiness Report 2025, [https://www.hiscox.co.uk/cyberreadiness](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.hiscox.co.uk%2Fcyberreadiness)

7\. About the Cyber Assessment Framework for local government - UK ..., [https://www.security.gov.uk/policy-and-guidance/cyber-assessment-framework-caf-for-local-government/understand-the-cyber-assessment-framework/about-the-cyber-assessment-framework-for-local-government/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.security.gov.uk%2Fpolicy-and-guidance%2Fcyber-assessment-framework-caf-for-local-government%2Funderstand-the-cyber-assessment-framework%2Fabout-the-cyber-assessment-framework-for-local-government%2F)

8\. Global Cybersecurity Outlook 2025 - World Economic Forum: Publications, [https://reports.weforum.org/docs/WEF\_Global\_Cybersecurity\_Outlook\_2025.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Freports.weforum.org%2Fdocs%2FWEF_Global_Cybersecurity_Outlook_2025.pdf)

9\. Cyber Threat Intelligence 101: A Business Owner's Guide - TechBrain, [https://www.techbrain.com.au/cyber-security-threat-intelligence-101/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.techbrain.com.au%2Fcyber-security-threat-intelligence-101%2F)

10\. Orienting Intelligence Requirements to the Small Business Space ..., [https://www.huntress.com/blog/orienting-intelligence-requirements-to-the-small-business-space](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.huntress.com%2Fblog%2Forienting-intelligence-requirements-to-the-small-business-space)

11\. Cyber Resilience and Incident Response in Smart Cities: A Systematic Literature Review, [https://www.mdpi.com/2624-6511/3/3/46](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2624-6511%2F3%2F3%2F46)

12\. Cyber Threat Intelligence in a Business Context - Crest-approved.org, [https://www.crest-approved.org/wp-content/uploads/2022/04/CTI-in-Business-Context\_2021.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.crest-approved.org%2Fwp-content%2Fuploads%2F2022%2F04%2FCTI-in-Business-Context_2021.pdf)

13\. Strategic cyber intelligence - University of South Florida, [https://pure.lib.usf.edu/ws/portalfiles/portal/40770079/Strategic%20Cyber%20Intelligence%20-%20IMCS%20Journal-ArticlePageFirst.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpure.lib.usf.edu%2Fws%2Fportalfiles%2Fportal%2F40770079%2FStrategic%2520Cyber%2520Intelligence%2520-%2520IMCS%2520Journal-ArticlePageFirst.pdf)

14\. (PDF) Strategic Cyber Intelligence - ResearchGate, [https://www.researchgate.net/publication/279223723\_Strategic\_Cyber\_Intelligence](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F279223723_Strategic_Cyber_Intelligence)

15\. Cyber Intelligence Tradecraft Report - Software Engineering Institute, [https://www.sei.cmu.edu/documents/1589/2019\_011\_001\_546699.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.sei.cmu.edu%2Fdocuments%2F1589%2F2019_011_001_546699.pdf)

16\. Cyber Intelligence Tradecraft Report - DTIC, [https://apps.dtic.mil/sti/pdfs/AD1090501.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Fpdfs%2FAD1090501.pdf)

17\. Cyber Intelligence Tradecraft Report - DTIC, [https://apps.dtic.mil/sti/trecms/pdf/AD1133277.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Ftrecms%2Fpdf%2FAD1133277.pdf)

18\. Tactical Cyber Threat Intelligence: Identifying Maturity Development Successes and Complications - Techne, [https://www.techne.ac.uk/media/25340/article1\_project.pdf.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.techne.ac.uk%2Fmedia%2F25340%2Farticle1_project.pdf.pdf)

19\. Cyber Threat Intelligence Lifecycle: Answering the CTI Analyst Challenge - Medium, [https://medium.com/@s.lontzetidis/cyber-threat-intelligence-lifecycle-answering-the-cti-analyst-challenge-3ddf7e0be28c](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmedium.com%2F%40s.lontzetidis%2Fcyber-threat-intelligence-lifecycle-answering-the-cti-analyst-challenge-3ddf7e0be28c)

20\. Full article: The long history of OSINT - Taylor & Francis Online, [https://www.tandfonline.com/doi/full/10.1080/16161262.2023.2224091](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.tandfonline.com%2Fdoi%2Ffull%2F10.1080%2F16161262.2023.2224091)

21\. Open-source intelligence: a comprehensive review of the current state, applications and future perspectives in cyber security - NIH, [https://pmc.ncbi.nlm.nih.gov/articles/PMC10014398/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpmc.ncbi.nlm.nih.gov%2Farticles%2FPMC10014398%2F)

22\. FM 34-130 INTELLIGENCE PREPARATION OF THE BATTLEFIELD - Marines.mil, [https://www.marines.mil/Portals/1/Publications/FM%2034-130.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.marines.mil%2FPortals%2F1%2FPublications%2FFM%252034-130.pdf)

23\. ATP 2-01.3 Intelligence Preparation of the Battlefield Headquarters, Department of the Army, [https://home.army.mil/wood/application/files/8915/5751/8365/ATP\_2-01.3\_Intelligence\_Preparation\_of\_the\_Battlefield.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fhome.army.mil%2Fwood%2Fapplication%2Ffiles%2F8915%2F5751%2F8365%2FATP_2-01.3_Intelligence_Preparation_of_the_Battlefield.pdf)

24\. Joint Doctrine Publication 2-00 - GOV.UK, [https://assets.publishing.service.gov.uk/media/653a4b0780884d0013f71bb0/JDP\_2\_00\_Ed\_4\_web.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fassets.publishing.service.gov.uk%2Fmedia%2F653a4b0780884d0013f71bb0%2FJDP_2_00_Ed_4_web.pdf)

25\. Opportunities to Improve DoD Cyber Survivability - DAU, [https://www.dau.edu/sites/default/files/2024-09/DAU%20Zero%20Trust%20%20%20Cyber%20Survivable%20for%20Acq%20%20%2020240919%20%20REV1.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.dau.edu%2Fsites%2Fdefault%2Ffiles%2F2024-09%2FDAU%2520Zero%2520Trust%2520%2520%2520Cyber%2520Survivable%2520for%2520Acq%2520%2520%252020240919%2520%2520REV1.pdf)

26\. Mapping cyber governance code to NCSC Cyber Assessment Framework - GOV.UK, [https://www.gov.uk/government/publications/cyber-governance-mapping/mapping-cyber-governance-code-to-ncsc-cyber-assessment-framework](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fpublications%2Fcyber-governance-mapping%2Fmapping-cyber-governance-code-to-ncsc-cyber-assessment-framework)

27\. Priority Intelligence Requirement Answering and Commercial Question-Answering: Identifying the Gaps - DTIC, [https://apps.dtic.mil/sti/tr/pdf/ADA525251.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Ftr%2Fpdf%2FADA525251.pdf)

28\. Strategic Cyber Intelligence Overview | PDF | Threat (Computer) - Scribd, [https://www.scribd.com/document/254594111/Strategic-Cyber-Intelligence](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.scribd.com%2Fdocument%2F254594111%2FStrategic-Cyber-Intelligence)

29\. Homeland Security Advisory Council and Lessons Learned Information Sharing, [https://www.dhs.gov/xlibrary/assets/Final\_LLIS\_Intel\_Reqs\_Report\_Dec05.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.dhs.gov%2Fxlibrary%2Fassets%2FFinal_LLIS_Intel_Reqs_Report_Dec05.pdf)

30\. Contextualising and Aligning Security Metrics and Business Objectives: a GQM-based Methodology - Semantic Scholar, [https://www.semanticscholar.org/paper/Contextualising-and-Aligning-Security-Metrics-and-a-Philippou-Frey/b878bccc7f0d70bed5c193dd7d049b86c333f053](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.semanticscholar.org%2Fpaper%2FContextualising-and-Aligning-Security-Metrics-and-a-Philippou-Frey%2Fb878bccc7f0d70bed5c193dd7d049b86c333f053)

31\. Cyber Assessment Framework – Policy brief | Local Government ..., [https://www.local.gov.uk/our-support/cyber-digital-and-technology/cyber-digital-and-technology-policy-team/cyber-assessment](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.local.gov.uk%2Four-support%2Fcyber-digital-and-technology%2Fcyber-digital-and-technology-policy-team%2Fcyber-assessment)

32\. Cyber Threat Intelligence in Government: A Guide for Decision ..., [https://hodigital.blog.gov.uk/wp-content/uploads/sites/161/2020/03/Cyber-Threat-Intelligence-A-Guide-For-Decision-Makers-and-Analysts-v2.0.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fhodigital.blog.gov.uk%2Fwp-content%2Fuploads%2Fsites%2F161%2F2020%2F03%2FCyber-Threat-Intelligence-A-Guide-For-Decision-Makers-and-Analysts-v2.0.pdf)

33\. Cybersecurity Metrics That Matter: Building Automation Readiness and Resilience in Government - Papers, [https://papers.govtech.com/Cybersecurity-Metrics-That-Matter%3A-Building-Automation-Readiness-and-Resilience-in-Government-144049.html](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpapers.govtech.com%2FCybersecurity-Metrics-That-Matter%253A-Building-Automation-Readiness-and-Resilience-in-Government-144049.html)

34\. Cyber Resiliency Metrics, Measures of Effectiveness, and Scoring - The MITRE Corporation, [https://www.mitre.org/sites/default/files/2021-11/prs-18-2579-cyber-resiliency-metrics-measures-of-effectiveness-and-scoring.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mitre.org%2Fsites%2Fdefault%2Ffiles%2F2021-11%2Fprs-18-2579-cyber-resiliency-metrics-measures-of-effectiveness-and-scoring.pdf)

35\. Using Goal-Question-Metric (GQM) Approach to Assess Security in Cloud Storage, [https://www.researchgate.net/publication/315443218\_Using\_Goal-Question-Metric\_GQM\_Approach\_to\_Assess\_Security\_in\_Cloud\_Storage](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F315443218_Using_Goal-Question-Metric_GQM_Approach_to_Assess_Security_in_Cloud_Storage)

36\. Using Goal-Question-Metric (GQM) Approach to ... - ePrints Soton, [https://eprints.soton.ac.uk/411068/1/Using\_Goal\_Question\_Metric\_GQM\_Approach\_to\_Assess\_Security\_in\_Cloud\_Storage.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Feprints.soton.ac.uk%2F411068%2F1%2FUsing_Goal_Question_Metric_GQM_Approach_to_Assess_Security_in_Cloud_Storage.pdf)

37\. Strengthening the Resilience of Defence Critical Electric Infrastructure - Department of Energy, [https://www.energy.gov/sites/default/files/2022-03/FINAL%20Report%20-%20Strengthening%20DCEI%20Resilience.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.energy.gov%2Fsites%2Fdefault%2Ffiles%2F2022-03%2FFINAL%2520Report%2520-%2520Strengthening%2520DCEI%2520Resilience.pdf)

38\. Application of grounded theory in construction of factors of internal efficiency and external effectiveness of cyber security and developing impact models - Emerald Publishing, [https://www.emerald.com/ocj/article/3/1/41/305646/Application-of-grounded-theory-in-construction-of](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Focj%2Farticle%2F3%2F1%2F41%2F305646%2FApplication-of-grounded-theory-in-construction-of)

39\. Cyber Assessment Framework - NCSC.GOV.UK, [https://www.ncsc.gov.uk/collection/cyber-assessment-framework](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.ncsc.gov.uk%2Fcollection%2Fcyber-assessment-framework)

40\. CAF Cyber Assessment Framework Compliance - Armis, [https://www.armis.com/solutions/cyber-assessment-framework-caf/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.armis.com%2Fsolutions%2Fcyber-assessment-framework-caf%2F)

41\. Research Institute in Science of Cyber Security (RISCS) Phase 2 - GtR, [https://gtr.ukri.org/projects?ref=EP%2FN033396%2F1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fgtr.ukri.org%2Fprojects%3Fref%3DEP%252FN033396%252F1)

42\. Decision-Making under Constraints: A Behavioural Economics Perspective on Cyber-Related Heuristics and Biases, [https://bip.ug.edu.pl/sites/default/files/postepowania\_naukowe/117376/praca/rozprawa\_doktorska\_marc\_wilczek.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fbip.ug.edu.pl%2Fsites%2Fdefault%2Ffiles%2Fpostepowania_naukowe%2F117376%2Fpraca%2Frozprawa_doktorska_marc_wilczek.pdf)

43.<https://www.gov.uk/government/news/launch-of-gov-uk-a-key-milestone-in-making-public-service-delivery-digital-by-default>

44.<https://www.gov.uk/government/collections/local-government-reorganisation-policy-and-programme-updates>

45.<https://www.gov.uk/government/publications/government-cyber-action-plan/government-cyber-action-plan>

46\. <https://www.ncsc.gov.uk/collection/cyber-assessment-framework>

47\. <https://repository.londonmet.ac.uk/10935/>

48\. [https://nlawarp.net](https://nlawarp.net/)

49\. [https://www.ctag.gov.uk](https://www.ctag.gov.uk/)

50.<https://www.raf.mod.uk/what-we-do/centre-for-air-and-space-power-studies/aspr/apr-vol18-iss1-7-pdf/>

51.<https://assets.publishing.service.gov.uk/media/683d89f181deb72cce2680a5/The\\_Strategic\\_Defence\\_Review\\_2025\\_-\\_Making\\_Britain\\_Safer\\_-\\_secure\\_at\\_home\\_\\_strong\\_abroad.pdf>

52.<https://www.chathamhouse.org/events/all/standard-event/directors-annual-lecture-2026>

53\. <https://repository.londonmet.ac.uk/9559/>

54.<https://www.researchgate.net/publication/348931430_Horizon_Scanning_White_Paper>

55\. [https://reports.weforum.org/docs/WEF\_Global\_Cybersecurity\_Outlook\_2026.pd](https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf)


# Data Handling Guidelines Version 7

{% file src="/files/UrnbS63Mm3ubQ32tDIwB" %}

Local Public Services

Data Handling Guidelines

**Seventh Edition**

**October 2025**

<br>

## Data Handling and Information Governance Guidance for Local Public Services

&#x20;

Copyright © Dr. Mark Brett 2025

&#x20;

No part of this book may be reproduced or distributed in any form without prior written permission from the author, with the exception of non-commercial uses permitted by copyright law. No part of this book may be reproduced or transmitted by any means, except as permitted by UK copyright law or the author.<br>

&#x20;

Table of Contents

[Data Handling and Information Governance Guidance for Local Public Services](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759076)

[Chapter 1:  Information Governance: A Holistic Approach](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759077)

[Chapter 2. Artificial Intelligence (AI) and Information Governance](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759078)

[Chapter 3: Information Risk, Risk Management, Risk Appetite, and Assurance within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759079)

[3.1 Information Risk and Risk Management in the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759080)

[3.2 Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759081)

[3.3 Assurance within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759082)

[Chapter 4: Risk Assessments and Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759083)

[4.1 Risk Assessments within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759084)

[4.2 Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759085)

[Chapter 5: Incident Management, Reporting, and Incident Response within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759086)

[5.1 Defining and Preparing for Incidents](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759087)

[5.2 The Incident Response Process](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759088)

[5.3 Incident Reporting](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759089)

[5.4 Tools and Techniques for Incident Management](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759090)

[Chapter 6: The Cyber Assessment Framework (CAF), Stocktake, Key Lines of Enquiry (KLOEs), and Objectives & Key Results (OKRs) for Cyber Maturity](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759091)

[6.1 Understanding the Cyber Assessment Framework (CAF) for Local Government](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759092)

[6.2 Integrating a Stocktake Approach with the CAF](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759093)

[6.3 The Role of Key Lines of Enquiry (KLOEs)](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759094)

[6.4 Developing Objectives and Key Results (OKRs) to Support Cyber Maturity](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759095)

[Chapter 7: A Strategic Approach to Cyber Resilience using the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759096)

[7.1 The LACES Framework as a Strategic Integrator](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759097)

[7.2 A Ten-Step Implementation Guide using the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759098)

[Chapter 8: Statecraft and Resilience in the Context of Civil Society](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759099)

[8.1 Understanding Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759100)

[8.2 The Role of Statecraft in Fostering Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759101)

[8.3 Impact of Cyber Incidents on Civil Society](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759102)

[8.4 Leveraging the LACES Framework for Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759103)

[8.5 Conclusion](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759104)

[Chapter 9: Local Authority Devolution: Guidance for Enhanced Information Governance, Resilience, and Integration](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759105)

[9.1 Understanding Local Authority Devolution in England](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759106)

[9.2 Implications of Devolution for Information Governance](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759107)

[9.3 Enhancing Resilience in the Context of Devolution](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759108)

[9.4 Fostering Integration within Devolved Structures](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759109)

[9.5 Call to Action](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759110)

[9.6 Strategic Plan and Action Points](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759111)

&#x20;

&#x20;

&#x20;

Introduction

Welcome to this fully revised seventh edition. The Data Handling Guidelines were originally written in 2008, as a response to the HMRC CD’s going missing with huge amounts of personal information. The disappearance of the disks was never proven. At the time central government responded with a full data handling review. The Local government guidelines were written to support Local Government. We have since revised and updated the guidelines since. The latest edition has been fully revised to incorporate the information governance needs and the LACES (Local Authority Cyber Ecosystem Framework). LACES was developed during 2024 by the author and culminated in the publication of a PhD thesis. The LACES approach provides a holistic framework to understand and work with Cyber Information Governance. There are new sections covering Cyber Incident Response, the Cyber Assessment Framework (CAF), implications for Artificial Intelligence and the devolution process. These guidelines provide an approach and toolset for senior leaders in Local Public Services to help understand Cyber Security, Information Risk and governance.&#x20;

Information remains a critical asset for Local Public Services, fundamental to the efficient and effective delivery of public services. This guidance builds upon previous iterations, incorporating the latest developments in data protection legislation, notably the Data Protection Act 2018, and the evolving cyber threat landscape. It aims to provide a holistic framework for Information Management, Assurance, and Governance (IMAG™), enabling Local Public Services to build public confidence and ensure the professional and secure handling of personal data. This document recognises that Local Public Services are best placed to assess their own risk and implement necessary safeguards, serving as a guide highlighting best practices and referencing useful resources.&#x20;

<br>

&#x20;

## 1. Information Governance: A Holistic Approach

Information Governance is the framework for managing information assets effectively and securely to support an organisation's strategic goals. It encompasses policies, processes, people, and technology to ensure the confidentiality, integrity, and availability of information. A robust Information Governance regime is crucial for legal compliance, risk management, service delivery, and maintaining public trust. This guidance promotes Corporate Information Governance, integrating Corporate Risk Management and the protection of the supply chain, which is vital in today's cloud-first, internet-driven environment.

2\. The Corporate Information Governance Group (CIGG)

To ensure effective Information Governance, it is strongly recommended that a Corporate Information Governance Group (CIGG) is established, chaired by the Senior Information Risk Owner (SIRO). The CIGG should report back to senior management on a regular basis, at least quarterly.

Terms of Reference for the CIGG:

The CIGG will be responsible for:

* Overseeing the development, implementation, and maintenance of the organisation's Information Governance framework, policies, and procedures.
* Reviewing and monitoring compliance with data protection legislation, including the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
* Identifying, assessing, and managing information risks across the organisation.
* Reviewing and approving Corporate Information Risk Plans (both review and forward-looking) at least annually.
* Monitoring the implementation of the Corporate Information Governance work plan.
* Ensuring the organisation has a published, tracked, and monitored implementation plan for data protection.
* Overseeing the development and maintenance of a Register of Processing Activities (ROPA).
* Reviewing and monitoring data sharing agreements and practices.
* Promoting a culture that properly values, protects, and uses information for the public good amongst all staff, including suppliers.
* Developing mechanisms through which individuals may bring concerns about information risk to the attention of senior management and ensuring these concerns are taken seriously.
* Ensuring the organisation is a member of the Regional Local Authority WARP (Warning, Advice and Reporting Point) or the Cymru WARP in Wales.
* Reviewing and monitoring cyber resilience measures and incident response plans.
* Receiving reports from Information Asset Owners (IAOs) on the security and use of their information assets.

3\. Roles and Responsibilities in Information Governance

Effective Information Governance relies on clearly defined roles and responsibilities at all levels of the organisation.

3.1 The Senior Information Risk Owner (SIRO)

A Senior Manager must fulfil the function of Senior Information Risk Owner (SIRO) to ensure accountability for information risk. Even with the changes to the Public Services Network (PSN), the retention of the SIRO role is strongly recommended.

Responsibilities of the SIRO:

* Accountable for Risk Management within the organisation.
* Should be a senior manager who is appropriately trained and familiar with information risk and the organisation’s response.
* Provide written judgement of the security and use of business assets at least annually to support the audit process.
* Provide advice to the accounting officer on the content of their statement of internal control.
* Must be briefed and aware of Cyber Threats and Cyber Incident Coordination requirements.
* Must ensure their organisation has a regular Cyber Exercising regime in place.
* Should champion the establishment and chair the Corporate Information Governance Group (CIGG).
* Responsible for ensuring that Information Asset Owners (IAOs) are clearly identified and their responsibilities are set in line with SIRO requirements.
* Needs to understand where information is created, processed, stored, and finally destroyed.
* Will need to agree if a new system containing personal data is applicable to the organisation and within its risk appetite.
* Should complete a Corporate Information Risk Plan at least once a year, or nominate an individual to do so on their behalf.
* Needs to ensure the organisation has Business Continuity Plans in place and that an annual exercise is carried out.

3.2 Information Asset Owners (IAOs)

Information Asset Owners (IAOs) are responsible for specific information assets within the organisation.

Responsibilities of the IAO:

* Understanding fully where their information asset(s) is created, processed, stored, and finally destroyed. This includes cloud services.
* Ensuring that processes relating to the operation and interfacing of systems containing their information asset(s) are properly documented and kept up to date.
* Contributing to risk assessments related to their information asset(s).
* Checking that the use of their information asset(s) is being conducted properly, especially in respect of protected personal data.
* Working with the SIRO to ensure the security and appropriate use of their information asset(s).

3.3 Data Protection Officer (DPO)

Under the Data Protection Act, all public bodies such as Local Authorities will require a Data Protection Officer (DPO)to be appointed; however, for smaller public bodies, there can be shared Data Protection Officers. The DPO must be independent and can be shared by a number of organisations. The ICO expects all Local Authorities to have a DPO.

Responsibilities of the DPO (as per ICO Guidance):

* To inform and advise the organisation and its employees about their obligations under data protection law.
* To monitor compliance with data protection law and the organisation’s data protection policies.
* To provide advice regarding Data Protection Impact Assessments (DPIAs).
* To cooperate with the ICO.
* To be the first point of contact for the ICO and for individuals whose data is processed.

4\. The Cabinet Office Cyber Assessment Framework (CAF) and Data Handling

The UK Government has an "Internet First" approach, which will see a move towards processes supporting the Cabinet Office Cyber Assessment Framework (CAF) and the Local Government version of that, the LG-CAF. The formulation of the LG-CAF aims to provide a framework for cross-organisational assurance and act as a common currency for Information Sharing across the UK Public Sector.

Effective data handling, as outlined in this guidance, directly supports the objectives of the CAF and LG-CAF by ensuring:

* Secure data storage and processing: Adhering to principles of integrity and confidentiality.
* Robust access controls: Limiting access to personal data to authorised personnel.
* Proper data disposal: Securely destroying information when it is no longer needed.
* Effective incident management: Having plans in place to respond to and recover from data breaches and cyber incidents.
* Supply chain security: Ensuring third-party processors have adequate security measures.
* Awareness and training: Educating staff on their responsibilities for data protection and security.
* Risk assessment and management: Identifying and mitigating threats to information assets.

By implementing the data handling practices recommended in this guidance, Local Public Services will be better positioned to meet the requirements of the CAF and LG-CAF, demonstrating their commitment to cyber resilience and information assurance.

5\. Secure by Design

The principle of secure by design should be embedded in all processes relating to systems operation and interfacing. This means that security and data protection considerations are integrated into the design and development of systems and services from the outset.

Key aspects of secure by design include:

* Understanding information flows: Documenting where information is created, processed, stored, and destroyed.
* Risk assessment from the beginning: Identifying potential security and privacy risks early in the development lifecycle.
* Implementing appropriate security controls: Choosing and implementing technical and organisational measures to mitigate identified risks. This includes considering encryption, strong authentication, and access controls.
* Data minimisation: Ensuring that only necessary personal data is collected and processed.
* Privacy by default: Configuring systems and services so that the most privacy-protective settings are the default.
* Regular testing and review: Conducting penetration testing and vulnerability scanning to identify and address weaknesses.
* Considering the insider threat: Implementing measures to prevent data breaches caused by human error or malicious actions, including training and awareness raising.
* Following secure development practices: Adhering to secure coding standards and principles, especially when using agile development methodologies. When using agile, information risks must be fully understood and addressed at each release.
* Utilising Privacy Enhancing Technologies (PETs) where appropriate.

6\. Call to Action

Local Public Services are urged to adopt the principles and practices outlined in this enhanced guidance to strengthen their Information Governance regimes and ensure the secure and responsible handling of data. By prioritising these measures, organisations can enhance public trust, comply with legal obligations, and build resilience against the ever-evolving cyber threats.

7\. Ten Actionable Points

1. Establish or review your Corporate Information Governance Group (CIGG) with clear terms of reference and ensure it meets regularly.
2. Ensure a Senior Manager is appointed and actively fulfilling the role of Senior Information Risk Owner (SIRO) with clearly defined responsibilities.
3. Identify and clearly define the roles and responsibilities of Information Asset Owners (IAOs) for all key information assets.
4. Maintain a comprehensive and up-to-date Register of Processing Activities (ROPA) as required by the Data Protection Act 2018 and the UK GDPR.
5. Develop and implement a Corporate Information Risk Policy and corresponding Corporate Information Risk Plans, reviewed at least annually.
6. Embed the principles of "secure by design" into all new and existing systems and processes that handle personal data.
7. Develop, implement, and regularly exercise Cyber Incident Response Plans to prepare for and manage potential cyber attacks and data breaches.
8. Implement a comprehensive training and awareness program for all staff (including suppliers) on data protection, information security, and secure data handling practices. Keep records of all training.
9. Conduct regular risk assessments, including Data Protection Impact Assessments (DPIAs) for processing likely to result in high risk to individuals.
10. Review and update all Data Sharing Agreements to ensure they comply with the Information Commissioner’s Data sharing code of practice and include agreed terms for data sharing, security, and disposal.

By taking these actionable steps, Local Public Services can significantly enhance their data handling practices and strengthen their overall Information Governance framework.

&#x20;

&#x20;

<br>

&#x20;

### Chapter 1:  Information Governance: A Holistic Approach

Information Governance is the framework for managing information assets effectively and securely to support an organisation's strategic goals. It encompasses policies, processes, people, and technology to ensure the confidentiality, integrity, and availability of information. A robust Information Governance regime is crucial for legal compliance, risk management, service delivery, and maintaining public trust. This guidance promotes Corporate Information Governance, integrating Corporate Risk Management and the protection of the supply chain, which is vital in today's cloud-first, internet-driven environment.

Information remains a critical asset for organisations and is fundamental to effective service delivery. Protecting this information, especially personal data, is a legal requirement. Information Governance provides the necessary structure to meet these legal obligations and to safeguard this key business asset.

A holistic approach to Information Governance considers several key components:

* Policies: A comprehensive set of policies forms the heart of any Information Governance regime. These policies need to be monitored and audited to ensure they are effectively enacted. Local Public Services should implement a range of security policies to ensure compliance. Examples of policy areas include secure disposal and destruction of information assets, log management, disclosure of information, risk management, protective marking, and the use of personal devices. The Senior Information Risk Owner (SIRO) also oversees the development, implementation, and regular review of clear and comprehensive information security policies and procedures.
* Processes: All processes relating to systems operation and interfacing should be properly documented with up-to-date information and included in risk assessments. It is essential that the SIRO and Information Asset Owners (IAOs) fully understand where information is created, processed, stored, and finally destroyed, a challenge further highlighted by the use of cloud services. Implementing clear Data Handling Procedures encompassing people, places, policies, processes, and procedures is crucial. A standards-based approach to service management, such as the Information Technology Infrastructure Library (ITIL), is recommended to align IT services with business needs.
* People: All staff (including suppliers) should develop a culture that properly values, protects, and uses information for the public good. Local Public Services should reinforce that information is a key business asset, and its proper use is not simply an IT issue. Training and awareness programmes are essential to ensure employees understand data governance policies, AI ethics, and legal requirements. Governance roles and responsibilities must be clearly defined. A Senior Manager should fulfil the function of the SIRO to ensure accountability. Information Asset Owners (IAOs) are responsible for specific information assets. The establishment of a Corporate Information Governance Group (CIGG), chaired by the SIRO, is strongly recommended to oversee Information Governance.
* Technology: Technology plays a crucial role in enabling effective and secure information management. The principle of secure by design should be embedded in all processes relating to systems operation and interfacing, integrating security and data protection considerations from the outset. This includes understanding information flows, conducting risk assessments early, implementing appropriate security controls (including encryption and access controls), data minimisation, and regular testing. The increasing reliance on cloud services necessitates careful consideration of offshoring data and ensuring data is kept within appropriate jurisdictions, often requiring the use of model contract clauses.

Corporate Information Governance promotes the integration of Corporate Risk Management and the protection of the supply chain. In today's cloud-first, internet-driven world, managing information risk within the supply chain, ensuring suppliers adhere to appropriate security standards, is critical.

A robust Information Governance regime is crucial for several reasons:

* Legal Compliance: It ensures adherence to data protection legislation, such as the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). Compliance with these laws, overseen by the Information Commissioner's Office (ICO), is essential to avoid penalties and maintain legal standing. This includes principles like lawfulness, fairness, transparency, integrity, and confidentiality (security), as well as the accountability principle.
* Risk Management: It facilitates the identification, assessment, and mitigation of information risks across the organisation. This includes cyber security risks, data breaches, and risks associated with the use of new technologies like AI. The SIRO is accountable for risk management within the organisation. Conducting regular risk assessments, including Data Protection Impact Assessments (DPIAs) for high-risk processing, is a key aspect of this.
* Service Delivery: By ensuring the availability and integrity of information assets, effective Information Governance supports the efficient and effective delivery of public services. Accurate and accessible information is vital for informed decision-making and operational efficiency.
* Maintaining Public Trust: In the delivery of public services, building and maintaining public confidence is paramount. Ensuring that personal data is handled professionally, and that privacy is protected through robust Information Governance practices is essential for fostering this trust. Transparency regarding data handling practices and AI usage is also important for building public trust.

By embracing a holistic approach to Information Governance, organisations can effectively manage their information assets, mitigate risks, comply with legal obligations, and maintain the trust of the individuals they serve.

### Chapter 2. Artificial Intelligence (AI) and Information Governance

Building upon the foundational principles of Information Governance outlined in the previous chapter, the increasing adoption of Artificial Intelligence (AI) necessitates a significant expansion and adaptation of existing frameworks. AI, while offering tremendous potential for improving services and driving innovation, also introduces novel complexities and risks that must be addressed through a holistic and integrated Information Governance approach. This chapter will explore how the core components of Information Governance – policies, processes, people, and technology – are impacted and need to evolve in the age of AI.

Policies for AI Governance

The establishment of clear and comprehensive AI governance policies is paramount. These policies should align with existing information security and data handling policies but also address the unique challenges posed by AI systems.

* Ethical Considerations and Fairness: AI policies must explicitly address ethical considerations, ensuring that AI systems are fair, unbiased, and do not discriminate against any group. This includes guidelines on bias detection and mitigation, algorithmic fairness, and the responsible design and development of AI systems by applying the principles of privacy by default and privacy by design. Organisations should consider definitions of fairness appropriate to a system’s use and may need to establish independent ethics committees.
* Transparency and Explainability: Policies should mandate transparency regarding AI systems, including clear documentation of how they work, what data they use, and their limitations. Guidelines for achieving explainable AI (XAI), ensuring AI decisions are understandable to stakeholders, are essential. This includes algorithmic transparency and the auditability of systems.
* Accountability and Responsibility: Clear lines of accountability for AI-driven outcomes must be defined. Policies should designate individuals or teams responsible for each AI system, including the SIRO's role in championing the development of an AI governance framework. Mechanisms for audit, continuous monitoring, and impact assessment of AI systems should be established.
* Data Governance for AI: Specific policies are needed for the data used in AI, ensuring data is collected with proper consent, is relevant, and of sufficient quality, accuracy, and representativeness. Policies should cover data access controls, especially for sensitive information used in AI.
* Security and Privacy in AI: Given the risks AI introduces related to privacy and security, especially when handling sensitive data, policies must address these concerns. This includes guidelines on preventing unauthorised access, data breaches, and exposure of personally identifiable information (PII), aligning with regulations like GDPR and CCPA. Policies should also cover data masking, encryption, access controls, and regular audits.
* Compliance and Legal Framework: AI policies must ensure compliance with relevant legal frameworks, including the Data Protection Act 2018, UK GDPR, and potentially sector-specific regulations and the Equality Act 2010. The policies should reflect the ICO's guidance on AI and data protection.

Processes for AI Governance

Integrating AI considerations into existing organisational processes and establishing new AI-specific processes is crucial for effective governance.

* Data Audit with an AI Focus: Organisations should conduct data audits specifically focusing on the quality, accuracy, and representativeness of data used in AI training, identifying potential biases and assessing the security of sensitive data.
* Development and Deployment Lifecycle: Governance processes should be embedded throughout the AI system lifecycle, from design and data collection to deployment, operation, and decommissioning. This includes assessing and documenting the expected impacts on individuals and society at the beginning of an AI project and throughout its lifecycle.
* Procurement of AI Systems: All procurement processes must take AI into account from a risk and assurance viewpoint. Security and ethical considerations should be embedded in the procurement of AI systems, focusing on the often-opaque nature of AI supply chains. Due diligence processes should include evaluating trade-offs made by third-party AI providers.
* Risk Assessment and DPIAs for AI: Undertaking Data Protection Impact Assessments (DPIAs) is a key process for identifying and mitigating the data protection risks associated with AI. DPIAs for AI should be conducted at the earliest stages of project development and should consider the specific ways AI processing might pose high risks to individuals. This includes assessing risks of bias, inaccuracy, and automated decision-making.
* Bias Detection and Mitigation Processes: Implementing processes to regularly check AI models for bias and take corrective actions is essential. This may involve technical approaches to mitigate algorithmic bias and processing personal data for bias mitigation.
* Incident Response for AI: Organisations need to ensure they have plans to deal with any AI-related data breaches or security incidents. Existing incident response plans may need to be adapted to address the specific challenges posed by AI.
* Monitoring and Audit of AI Systems: Continuous monitoring and periodic review of oversight mechanisms for AI systems are necessary to ensure their proper functioning and adherence to policies. Audit trails of AI decisions and influencing factors should be maintained.
* Managing Automated Decision-Making: Clear processes must be in place for managing AI systems involved in solely automated decision-making that have legal or similarly significant effects on individuals, including providing safeguards and the right to contest such decisions. Meaningful human oversight should be ensured for such systems.

People and AI Governance

A strong culture of responsible AI adoption requires ensuring that all personnel, including leaders, technical teams, and general staff, understand their roles and responsibilities in governing AI.

* Leadership Engagement and Accountability: Senior management, including the SIRO and DPOs, are accountable for the governance and data protection risk management of AI systems. They should set a meaningful risk appetite for AI adoption and ensure AI initiatives align with organisational values and ethical principles.
* Specialised Expertise: Effective AI-driven data governance demands a coordinated approach involving business leaders, IT teams, and data teams. Organisations need to invest in both internal talent development and strategic external partnerships to gain the specialized knowledge and skills required for AI governance, including understanding concepts like explainability, bias mitigation, and model robustness. Upskilling data teams through training and mentorship programs is crucial.
* Awareness and Training: Investing in awareness raising, education, research, and training is vital to ensure a good level of information on and understanding of AI and its potential effects in society. Training programs should cover data governance policies, AI ethics, legal requirements, and the data protection implications of AI processing. Human reviewers of AI-assisted decisions require specific training to understand AI systems, identify potential errors, and exercise appropriate oversight.
* Clear Roles and Responsibilities: Governance roles and responsibilities related to AI must be clearly defined. This includes identifying Information Asset Owners (IAOs) for data used in AI systems and defining responsibilities for the development, testing, validation, deployment, and monitoring of AI.
* Stakeholder Engagement: Engaging with stakeholders, including individuals whose data is processed by AI systems and those potentially affected by AI outcomes, is crucial for ensuring responsible AI development and deployment. Seeking and documenting the views of individuals during the AI lifecycle, unless there is a good reason not to, is a good practice.
* Fostering a Culture of Responsibility: Organisations should foster a culture that values the ethical and responsible use of AI. This includes promoting collective and joint responsibility involving the whole chain of actors and stakeholders.

&#x20;

&#x20;

&#x20;

Technology for AI Governance

Technology plays an enabling role in implementing and enforcing AI governance policies and processes.

* AI Governance Tools: Adopting AI governance tools that automate tasks like data documentation and insight generation can ease the technical burden. AI-driven governance tools can continuously monitor data access, identify vulnerabilities, and protect sensitive information through methods like data masking.
* Data Catalogues: Investing in tools like Collibra or Alation helps organisations create and maintain an inventory of data assets, making it easier to track data lineage, manage metadata, and ensure consistent data usage across AI projects.
* Data Quality Management Tools: Tools for ensuring and monitoring the quality and accuracy of data used in AI systems are essential for mitigating bias and ensuring reliable outcomes.
* AI Fairness Toolkits: Implementing AI fairness toolkits can aid in bias detection, mitigation, and the evaluation of fairness in AI models.
* Explainable AI (XAI) Technologies: Investing in public and private scientific research on explainable artificial intelligence and deploying XAI techniques are crucial for improving the transparency and intelligibility of AI systems.
* Security Technologies for AI: Deploying specific security measures for AI systems is necessary to address the unique security challenges they present. This includes assessing the security of both in-house and externally maintained AI code and frameworks.
* Privacy-Enhancing Technologies (PETs): Exploring and implementing privacy-preserving techniques can help minimise the amount of personal data processed by AI systems and mitigate privacy risks.

Maintaining Legal Compliance, Managing Risk, and Building Public Trust in the Age of AI

The effective integration of AI into the Information Governance framework is fundamental for:

* Legal Compliance: A robust AI governance regime ensures adherence to data protection laws and other relevant legislation. By focusing on lawfulness, fairness, transparency, and accountability in AI systems, organisations can mitigate the risk of non-compliance and potential penalties from regulatory bodies like the ICO. Understanding the lawful basis for processing personal data in AI development and deployment is crucial.
* Risk Management: Addressing the emerging risks associated with AI, such as bias, lack of explainability, security vulnerabilities, and privacy breaches, is a core function of AI governance. A risk-based approach, including regular DPIAs, helps organisations identify, assess, and mitigate these risks effectively. Understanding and managing trade-offs between different objectives, such as accuracy and fairness, is also essential.
* Service Delivery: Well-governed AI systems can enhance the efficiency, effectiveness, and innovation of service delivery. By ensuring AI systems are robust, secure, accurate, and fair, organisations can leverage their benefits while minimising potential negative impacts on service users.
* Maintaining Public Trust: Transparency, fairness, and accountability in the use of AI are crucial for building and maintaining public trust. Clearly communicating how AI systems are used, ensuring decisions are explainable and fair, and providing mechanisms for redress when things go wrong are essential for fostering public confidence in AI-powered services.

In conclusion, as AI becomes increasingly integrated into organisational operations, a proactive and comprehensive approach to Information Governance is essential. By adapting policies, evolving processes, empowering people with the necessary skills and awareness, and leveraging appropriate technologies, organisations can harness the transformative power of AI responsibly and ethically, while safeguarding information, ensuring legal compliance, managing risks effectively, and ultimately maintaining the trust of the public they serve. The SIRO plays a vital role in championing this "AI readiness".

&#x20;

<br>

&#x20;

### Chapter 3: Information Risk, Risk Management, Risk Appetite, and Assurance within the LACES Framework

This chapter will explore the critical concepts of information risk, risk management, risk appetite, and assurance, and how these align with and are integral to the Local Authority Cyber Eco-System (LACES) framework. The LACES framework, with its six interconnected variables – Governance, Assurance, Processes, Data, Resilience, and Knowledge Sharing – provides a holistic model for understanding and managing cybersecurity within local authorities.

3.1 Information Risk and Risk Management in the LACES Framework

Information risk refers to the potential for loss or harm resulting from the compromise of confidentiality, integrity, or availability of information. This compromise can impact an organisation's ability to deliver vital services, lead to the loss of personal or sensitive data, and increase risks to compliance and legal standing. In the context of the LACES framework, information risk permeates all six variables.

Risk management is the systematic process of identifying, assessing, treating, and monitoring risks. It is a fundamental aspect of ensuring the security and responsible handling of data. Within the LACES framework:

* Governance sets the direction for risk management by establishing policies, responsibilities (e.g., SIRO, IAOs), and structures like the Corporate Information Governance Group (CIGG) to oversee information risks. Defining and communicating a clear information risk appetite is a fundamental governance activity.
* Assurance focuses on the mechanisms and activities that provide confidence that information risks are being effectively managed. This includes conducting regular risk assessments to identify vulnerabilities and threats in both physical and virtual domains, as well as implementing security audits and penetration testing for independent validation of security controls.
* Processes related to systems operation and interfacing should be properly documented and included in risk assessments. Understanding where information is created, processed, stored, and destroyed is essential for effective risk management. Secure by design principles should be embedded into all new and existing systems and processes that handle personal data.
* Data, being a key asset, is central to information risk management. The LACES framework aims to protect data, and risk management activities must consider the confidentiality, integrity, and availability of this data. Data protection impact assessments (DPIAs) are crucial for identifying and mitigating risks associated with processing personal data, particularly in AI systems.
* Resilience focuses on maintaining operational continuity in the face of cyber incidents or disruptions. This inherently involves managing the risks that could lead to such incidents through business continuity planning, disaster recovery, and incident response plans. Risk analysis is a key component of building resilience.
* Knowledge Sharing facilitates better risk management by enabling the exchange of information about threats, vulnerabilities, and best practices. Mechanisms for individuals to raise concerns about information risk and for these concerns to be taken seriously are vital.

A key aspect of risk management within LACES is understanding the threats and vulnerabilities that could exploit weaknesses. This process, involving risk, threat, and vulnerability assessments, helps focus resources effectively. The LACES framework itself can be used to assess and mitigate cyber risks associated with new technologies and the supply chain.

3.2 Risk Appetite within the LACES Framework

Risk appetite is the level of risk an organisation is willing to accept in pursuit of its objectives. Articulating and agreeing upon a shared understanding of information risks among senior managers and stakeholders is a crucial aspect of governance within the LACES framework.

* A clearly defined Information risk appetite is a fundamental governance activity, guiding decision-making related to information risk. Without a written, accepted, and understood risk appetite, an organisation cannot effectively understand its information risks, priorities, and where to invest time and budget.
* The risk appetite should reflect the need for a local authority to protect and manage the information it handles, as compromising its confidentiality, integrity, and availability can severely impact service delivery and compliance.
* The Senior Information Risk Owner (SIRO) is responsible for owning and annually reviewing the risk appetite. They must be informed of any residual risks affecting authority information systems and act as the final arbiter on these risks.
* When procuring new systems, it is important to consider whether they fall within the organisation's defined risk appetite. Furthermore, when deploying AI systems, the approach should align with the overall risk appetite from the outset.
* Documenting how final decisions fit within the overall risk appetite is an important aspect of accountability.

Articulating risk appetites for emerging technologies like AI is an evolving area. A potential approach involves modelling harm and consequences, similar to resilience and emergency planning.

3.3 Assurance within the LACES Framework

Assurance within the LACES framework focuses on providing confidence that information risks are being effectively managed. It encompasses a range of activities designed to verify the implementation and effectiveness of security controls and processes.

Key elements of Assurance within LACES include:

* Risk Assessment: Regularly identifying, assessing, and understanding security risks to personal data and the systems that process it. This is a core assurance activity.
* Auditing and Penetration Testing: Implementing security audits and penetration testing provides independent validation of security controls.
* Monitoring: Establishing robust monitoring systems (e.g., SIEM) and baselines for normal system loads to detect anomalies. Cyber hygiene monitoring is also crucial.
* Managing the Supply Chain: Ensuring that third-party suppliers and contractors are subject to the organisation’s policies and procedures, formalised in contracts.
* Ensuring Systems and Services are Secure and Robust: Implementing secure by design principles.
* Implementing a Defence in Depth Approach: Employing multiple layers of security controls.
* Exercising and Response Planning: Regularly rehearsing cyber incident response procedures to ensure preparedness.

The Assurance variable of the LACES framework is critical to ensuring that the Governance policies are being implemented effectively and that the Processes are operating securely to protect Data and maintain Resilience. Assurance findings and recommendations should be shared to improve security practices, contributing to Knowledge Sharing within the framework. Furthermore, in a principles-led approach, assurance is essential to provide cross-checks and balances within different professional disciplines.

In conclusion, information risk, risk management, risk appetite, and assurance are fundamental and interconnected concepts that are fully integrated within the LACES framework. By addressing these elements through the lens of Governance, Assurance, Processes, Data, Resilience, and Knowledge Sharing, local authorities can build a more robust and effective cybersecurity posture.<br>

### Chapter 4: Risk Assessments and Risk Appetite within the LACES Framework

Building upon the foundational concepts introduced in the previous chapters, this chapter will delve into two critical components of cybersecurity management within the context of the Local Authority Cyber Eco-System (LACES) framework: Risk Assessments and Risk Appetite. These elements are fundamental for understanding and mitigating cyber risks effectively and are deeply intertwined with the Assurance and Governance variables of the LACES framework.

4.1 Risk Assessments within the LACES Framework

Risk assessment is a systematic process employed to identify, evaluate, and mitigate risks to an organisation's information assets and operations. It is a core assurance activity within the LACES framework. Regular risk assessments are essential to identify vulnerabilities and threats in both the physical and virtual domains. These assessments should be a continuous process, especially in the dynamic landscape of cyber threats.

Within the LACES framework, risk assessments are integral to several variables:

* Assurance: Risk assessments are a primary mechanism for providing confidence that information risks are being effectively managed. They help to identify areas of vulnerability and inform the implementation of security controls.
* Processes: Risk assessments should consider the security of operational processes and how information is handled throughout its lifecycle. This includes understanding system interdependencies and data flows.
* Data: Protecting data is a central goal, and risk assessments are crucial for identifying risks to the confidentiality, integrity, and availability of data. Data Protection Impact Assessments (DPIAs) are a specific type of risk assessment focusing on the risks to individuals' rights and freedoms arising from the processing of personal data, particularly in the context of AI systems. DPIAs should objectively assess the likelihood and severity of risks and identify mitigation measures.
* Resilience: Understanding potential risks through risk assessments informs the development of effective business continuity and incident response plans. By testing risk assessments through assurance activities, deficiencies in plans can be understood, supporting a proactive approach to dealing with cyber incidents.
* Governance: Governance structures, such as the Corporate Information Governance Group (CIGG), oversee the risk assessment process and ensure its alignment with organisational objectives and risk appetite.

Various methodologies can be employed for risk assessments. The Silverthorn Method emphasises emergent threats and horizon scanning, explicitly incorporating the dynamic nature of the threat landscape. This distinguishes it from more traditional methods like NIST SP 800-30 and OCTAVE, which may not place the same emphasis on anticipating future risks. Horizon scanning is "the systematic examination of potential threats, opportunities and likely future developments which could be strategically important to an organisation".

A comprehensive risk assessment process should include:

* Risk Identification: Identifying potential hazards or threats that could compromise information assets. This can involve horizon scanning to anticipate emerging threats.
* Threat Assessment: Understanding the capabilities and intent of potential adversaries. Threat profiling helps to understand an organisation's susceptibility to attack.
* Vulnerability Assessment: Identifying weaknesses in systems, processes, or physical security that could be exploited by threats. Regular vulnerability scanning is a key practice.
* Risk Analysis: Evaluating the potential impact and likelihood of identified risks. Frameworks like MITRE ATT\&CK can be used for risk analysis and network defence. Qualitative risk analysis can be used to evaluate risks.
* Risk Prioritization: Focusing efforts on the most significant risks based on their potential impact and likelihood.
* Risk Treatment (Mitigation): Developing and implementing strategies to reduce the likelihood or impact of identified risks. This can include data minimisation techniques.
* Risk Monitoring and Review: Continuously monitoring the risk landscape and the effectiveness of implemented controls, and regularly reviewing and updating risk assessments. In an agile environment, a more iterative and cyclic approach to risk and threat management is necessary.

Risk assessments should consider the interconnectedness of physical and virtual domains and the potential impact of new technologies like AI. For AI systems, DPIAs are crucial for assessing risks to individuals' rights. Furthermore, risk assessments should inform the development and review of cyber resilience plans and incident response capabilities.

4.2 Risk Appetite within the LACES Framework

Risk appetite defines the level of risk an organisation is willing to accept in pursuit of its objectives. Defining and communicating a clear information risk appetite is a fundamental governance activity within the LACES framework.

Within the LACES framework, risk appetite is primarily linked to the Governance variable:

* Governance: Establishing and communicating the organisation's risk appetite is a core responsibility of senior management and is essential for guiding decision-making related to information risk. The Senior Information Risk Owner (SIRO) plays a key role in defining, owning, and annually reviewing the information risk appetite.
* The risk appetite acts as a guide for all other variables, influencing the level of investment in assurance activities, the stringency of processes, the security measures applied to data, the resources allocated to resilience, and the focus of knowledge sharing.

A well-defined risk appetite statement is crucial for several reasons:

* Guiding Decision-Making: It provides a framework for evaluating potential risks and determining whether they are acceptable.
* Resource Allocation: It helps in prioritising investments in security controls and risk mitigation efforts. An organisation should not typically spend significantly more to mitigate a risk than the potential loss associated with it.
* Accountability: It provides a benchmark against which risk management performance can be assessed. Documenting how final decisions align with the overall risk appetite is important for demonstrating accountability.
* Understanding Priorities: Without a written, accepted, and understood risk appetite, an organisation cannot effectively understand its information risks and priorities.

Articulating a risk appetite, especially for complex and evolving areas like AI, can be challenging. A suggested approach involves modelling potential harm and consequences, similar to methodologies used in resilience and emergency planning. The NIST AI risk framework offers a four-step approach to risk management: govern, map, measure, and manage, which can support the articulation of risk appetite for AI.

The risk appetite should reflect the specific needs and context of the local authority, considering its vital services, the personal and sensitive information it handles, and its legal and compliance obligations. Compromising the confidentiality, integrity, or availability of this information can have significant consequences, and the risk appetite should reflect the organisation's tolerance for such impacts. Ultimately, the risk appetite is central to the entire information security and assurance landscape, providing a crucial foundation for effective cybersecurity management within the LACES framework.

&#x20;

<br>

&#x20;

### Chapter 5: Incident Management, Reporting, and Incident Response within the LACES Framework

Building upon the previous chapters, this chapter will explore the critical aspects of Incident Management, Reporting, and Incident Response within the context of the Local Authority Cyber Eco-System (LACES) framework. Effective handling of security incidents is paramount for minimising disruption, mitigating potential damage, and maintaining public trust. This chapter will outline the key elements of a robust incident management framework, drawing upon the principles of LACES and the guidance provided in the sources.

5.1 Defining and Preparing for Incidents

An incident can be defined as an emergency or event that threatens to disrupt normal business activities. In the context of cybersecurity, this can range from data breaches and cyberattacks to system failures. Being prepared for such incidents is crucial, and this involves several key steps:

* Developing an Incident Management Plan: A comprehensive Cyber Incident Response Plan is essential. This plan should serve as a reference tool for the actions required during or immediately following an incident. It should outline steps for detecting, containing, and recovering from cyber incidents. The plan should be regularly reviewed and updated.
* Establishing an Incident Management Team (IMT): The Business Continuity Plan guidance highlights the need for an Incident Management Team (IMT) composed of applicable members of staff. This team will coordinate actions and manage communications during an incident. The responsibility for the initial response often lies with a designated role who will work with selected members to form the IMT.
* Defining Roles and Responsibilities: Clear roles and responsibilities within the incident response process are vital. A dedicated Cyber Response Coordinator plays a crucial role in coordinating the cyber incident response team once activated, acting as a liaison officer and ensuring effective communication. The Leggiest (Rapporteur) role, responsible for maintaining a decision log, is a novel addition to the internal cyber response team that has been adopted across Wales.
* Implementing Business Continuity and Disaster Recovery Plans: Alongside the incident response plan, organisations need Business Continuity Plans to maintain critical functions if primary systems become unavailable and Disaster Recovery Plans for restoring IT systems and data after a major incident. These plans should be regularly tested.
* Conducting Risk Assessments: As discussed in the previous chapter, regular risk assessments are essential for identifying potential threats and vulnerabilities that could lead to incidents. Understanding these risks informs the development of more effective incident response plans.
* Promoting a Security Culture and Training: Establishing and maintaining a robust Training & Awareness Programme is a key governance responsibility. All staff should understand their roles and responsibilities in protecting information and reporting incidents. Encouraging a culture where reporting incidents and "Near misses" is encouraged and not punished is crucial for early detection and effective response. Regular cyber exercising is also vital for testing policies and procedures and raising awareness at all levels. The PET (Analyse the Risks, Plan, Educate and Test) cycle should be continuously applied to enhance incident preparedness.

5.2 The Incident Response Process

The incident response process typically involves several stages:

* Detection and Initial Assessment: Recognising that an incident has occurred is the first step. This might involve monitoring systems for unusual activity. Once detected, the initial response checklist includes actions like following evacuation procedures, calling emergency services if necessary, ensuring the safety and welfare of all affected persons, and calling a meeting of the IMT. Establishing the situation by answering key questions (what happened, when, where, severity, impact, etc.) is crucial.
* Declaration and Communication: Once an incident is confirmed, it should be formally declared. Immediate communication to staff about the implications and requirements is necessary. If necessary, key partners and suppliers should also be informed. Internal communication channels for information sharing should be established. During an incident, the shift to "fast-time" communication using secure channels is essential for effective collaboration and coordination within the incident response team and with external partners.
* Containment: The goal of this phase is to limit the scope and impact of the incident. This might involve isolating affected systems or networks.
* Eradication: This involves removing the threat and restoring affected systems to a secure state.
* Recovery: The focus here is on restoring normal business operations. This includes recovering data from backups.
* Post-Incident Activities: After the immediate response, it is necessary to produce a summary report and transition to recovery. A post-incident debrief should be conducted to identify what worked well, what didn't, and what changes need to be made for the future. After-action reporting is necessary to summarise the initial response and transition to recovery. The review, lessons learned and improvement process afterwards is critical for enhancing future incident response capabilities. Lessons learned should be documented and shared internally and with external stakeholders where appropriate.

5.3 Incident Reporting

Effective incident reporting is crucial for situational awareness, collaboration, and compliance:

* Internal Reporting: Clear incident reporting mechanisms with defined escalation paths are essential. All staff should know how to report suspected incidents. A log of all emergency actions taken should be commenced. A Master Activity Log should be maintained, recording all actions, decisions, meetings, and briefing sessions.
* Reporting to Warning, Advice and Reporting Points (WARPs): Serious Security incidents should initially be reported to the Regional Local Authority WARP. WARPs play a key role in a collaborative approach to cyber incident response in the UK. Organisations should be members of their regional WARP.
* Reporting to the National Cyber Security Centre (NCSC): Serious network security incidents affecting specific government networks MUST be reported to NCSC(IM). The NCSC generally will only intervene at category 3 or above in their cyber incident categorisation system. Organisations need their own support arrangements for lower-level attacks.
* Reporting Personal Data Breaches to the Information Commissioner's Office (ICO): Significant, actual or potential losses of personal data should be notified to the Information Commissioner's Office (ICO) as soon as reasonably practicable. Failure to report a serious breach could risk immediate enforcement action. The notification should include details of the nature of the breach, the likely consequences, and the measures taken to address it. Information can be provided in phases if not all details are immediately available. Processors must communicate data breaches to the controller without undue delay. A record of all personal data breaches, regardless of whether they need to be reported, must be kept. The ICO also has a free helpline for advice on data protection compliance, including responses to data loss incidents.
* Reporting to Data Subjects: Incidents that pose a “high risk” to data subjects will need to also be reported to them directly.
* AI-related Incident Reporting: There is a growing recognition of the need for specific incident reporting categories for AI (LLMs) as part of cyber incident response and resilience. It is important to consider how AI systems themselves will identify and report incidents.

5.4 Tools and Techniques for Incident Management

Several tools and techniques can enhance incident management and response:

* Playbooks: Pre-agreed plans or playbooks should be enacted during incident response. These can document specific actions related to different incident scenarios, removing ambiguity and allowing for delegated actions.
* Golden Hour Guide: This provides a novel approach to inform initial actions when responding to cyber incidents. It emphasises the critical nature of the first hour in mitigating damage.
* Crash Gate Framework: This framework facilitates the definition of trigger points for escalation in cyber incident response planning and response. It uses variables like Consequence Scaling, Resilience Scoring, Applicability Scoring, Severity Scoring, and Harm Levels to enumerate an incident and build fast-time situational awareness.
* Information Asset Registers: Maintaining detailed documentation about systems, services, and networks, particularly through Information Asset Registers, is critical for effective incident response and recovery.
* Warning, Advice and Reporting Points (WARPs): These facilitate a collaborative approach to cyber incident response through information sharing.
* Security Information and Event Management (SIEM) Systems: These can be used for robust monitoring to detect unusual traffic patterns and resource usage.

Effective Incident Management, Reporting, and Response are integral to the Resilience variable of the LACES framework. By proactively preparing, having well-defined processes, understanding reporting obligations, and utilising appropriate tools, Local Public Services can significantly enhance their ability to handle cyber incidents effectively and maintain the security and integrity of their information assets.

&#x20;

<br>

&#x20;

### Chapter 6: The Cyber Assessment Framework (CAF), Stock take, Key Lines of Enquiry (KLOEs), and Objectives & Key Results (OKRs) for Cyber Maturity

This chapter will detail the Cyber Assessment Framework (CAF) for local government, explaining how it can be used in conjunction with a stocktake approach and Key Lines of Enquiry (KLOEs) to enhance cyber maturity. Furthermore, it will provide a detailed example of developing Objectives and Key Results (OKRs) to support the achievement of cyber maturity goals.

6.1 Understanding the Cyber Assessment Framework (CAF) for Local Government

The Cyber Assessment Framework (CAF) is a recognised National Cyber Security Centre (NCSC) framework specifically adapted for councils. It is designed to help local government organisations assess their current cyber resilience and identify and mitigate vulnerabilities that could disrupt their important services. The CAF is not intended as a tick-box exercise but rather requires cross-organisational collaboration.

Key benefits of using the CAF for local government include:

* Assessing the current cyber resilience of your organisation.
* Identifying cyber risks that could disrupt your most important services.
* Improving resilience to potential cyber-attacks.
* Knowing what areas to prioritise through actionable recommendations, leading to efficient spending of time and money.
* Understanding your cyber posture against a national benchmark.
* Embedding a culture of cyber security across the whole organisation, not just IT teams.
* Building a strong foundation of resilience to understand and manage risk appropriately.
* Serving as a method for good risk management at a local authority level when used routinely.
* Complementing existing cyber plans or acting as a tool to start conversations around cyber security.
* Aligning with UK government cyber security policy.

&#x20;

&#x20;

The CAF is based on four objectives that build good cyber resilience:

* Managing security risks (Objective A). This objective focuses on ensuring the security of essential network and information systems through governance, risk management, asset management, and supply chain management strategies.
* Protecting against cyber-attack (Objective B). This objective requires organisations to meet principles such as service protection policies and processes, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.
* Detecting cyber security events (Objective C). This involves having security monitoring processes in place.
* Minimising the impact of cyber security incidents (Objective D). This objective involves response and recovery planning and a 'lessons learned' function.

To achieve these objectives, the CAF uses a structure of principles, contributing outcomes, and Indicators of Good Practice (IGPs). The framework focuses on what needs to be achieved (outcomes) rather than a checklist of what needs to be done.

6.2 Integrating a Stocktake Approach with the CAF

A stocktake approach, such as the one used to benchmark and track cyber posture maturity in Welsh Local Authorities, can be effectively integrated with the CAF. The stocktake often involves asking a series of questions related to cybersecurity practices. These questions can be mapped directly to the CAF objectives and principles, allowing an organisation to understand its current state of cyber resilience against the framework.

By using a stocktake questionnaire aligned with the CAF, councils can:

* Systematically assess their alignment with the CAF objectives and principles.
* Identify areas where they meet the contributing outcomes and indicators of good practice, and areas where improvements are needed.
* Gain a baseline understanding of their cyber security maturity against a framework recognised by the NCSC.
* Track progress over time by repeating the stocktake and comparing results, as demonstrated by the Welsh experience.

The "Comprehensive Mapping of CAF Objectives and Principles to Stocktake Questions" provides a clear example of how this alignment can be achieved. It links specific stocktake questions to the relevant CAF objective and principle, offering insights into the rationale and importance of each question based on the sources. This mapping helps ensure that the self-assessment process is structured and directly relevant to the CAF requirements.

&#x20;

6.3 The Role of Key Lines of Enquiry (KLOEs)

Key Lines of Enquiry (KLOEs) can be a valuable tool within the CAF and stocktake process. Originating from audit practices, KLOEs represent key questions that help assess performance and identify areas for further investigation. In the context of the CAF, KLOEs can be developed to:

* Drill down into the contributing outcomes and IGPs associated with each CAF principle.
* Provide a more granular level of assessment than broad stocktake questions.
* Guide internal audits and reviews of specific cybersecurity controls and processes.
* Help in gathering evidence to support the self-assessment and any independent assurance reviews.
* Focus attention on specific aspects of cyber risk management that are deemed critical for the local authority.

For example, under CAF Objective A (Managing Security Risk) and Principle A1 (Governance), a stocktake question might be "How often are cybersecurity matters reported to the board?". A related KLOE could be: "What specific information is included in the cybersecurity reports presented to the board, and how is this information used to inform strategic decision-making?" \[implied].

The LACES framework also suggests the use of Key Lines of Enquiries (KLOEs) to be integrated with the CAF as part of an ongoing stocktake approach.

6.4 Developing Objectives and Key Results (OKRs) to Support Cyber Maturity

Objectives and Key Results (OKRs) are a goal-setting framework that helps organisations define ambitious goals (Objectives) and track their progress through measurable results (Key Results). When applied to cyber security, OKRs can provide a clear roadmap for improving cyber maturity in alignment with the CAF.

Here is a detailed example of developing OKRs to support cyber maturity, linked to CAF Objective A: Managing Security Risk:

Objective: Enhance the management of cyber security risks across the council to improve overall cyber resilience. (Aligned with CAF Objective A)

&#x20;

&#x20;

&#x20;

&#x20;

Objectives & Key Results:

* OKR1: Develop and approve a documented cybersecurity risk appetite statement by \[Date]. (Supports CAF Principle A1: Governance).
* *Rationale:* A documented risk appetite is fundamental for informed decision-making and resource allocation.
* *Measurement:* Completion and formal approval of the risk appetite document by the specified date.
* OKR2: Update the council's risk register to include cybersecurity risks, ensuring all critical systems are identified and risk-assessed by \[Date]. (Supports CAF Principle A2: Risk Management and CAF requirement to identify critical systems).
* *Rationale:* Maintaining a risk register incorporating cybersecurity is crucial for identifying, assessing, and managing potential threats. Identifying critical systems allows for targeted protection.
* *Measurement:* Completion of the updated risk register with identified critical systems and associated risk assessments.
* OKR3: Implement minimum cybersecurity standards for \[X]% of high-risk third-party vendors by \[Date], including evidence of enforcement for \[Y]% of these vendors. (Supports CAF Principle A4: Supply Chain).
* *Rationale:* Establishing and enforcing cybersecurity standards for third parties is crucial for managing supply chain risks.
* *Measurement:* Percentage of high-risk vendors with implemented minimum standards and percentage of those vendors with evidence of enforcement (e.g., audit logs, contractual clauses).
* OKR4: Achieve a "\[Target Percentage]" completion rate for the self-assessment of critical systems against CAF Objective A contributing outcomes by \[Date]. (Supports the CAF self-assessment process).
* *Rationale:* Conducting the self-assessment helps identify areas of strength and weakness against the CAF's requirements for managing security risks.
* *Measurement:* Percentage of critical systems that have completed the self-assessment for CAF Objective A.

Further Considerations for Developing Cyber Maturity OKRs:

* Alignment with CAF Objectives: Ensure your Objectives directly support one or more of the four CAF objectives.
* Specificity and Measurability: Key Results should be specific, measurable, achievable, relevant, and time-bound (SMART). Use quantifiable metrics where possible.
* Ambitious but Achievable: OKRs should stretch the organisation but remain within the realm of possibility given available resources. The draft CAF profile was noted as challenging but not disproportionate.
* Cross-Organisational Collaboration: Recognise that achieving cyber maturity requires effort across different teams. Involve relevant stakeholders in the OKR setting process.
* Regular Review and Adjustment: OKRs should be reviewed regularly (e.g., quarterly) to track progress and make adjustments as needed. Lessons learned from incidents and exercises should inform these adjustments.
* Link to Improvement Plans: OKRs should drive the creation and implementation of improvement plans to address identified vulnerabilities.

By strategically using the CAF, incorporating a stocktake approach, leveraging KLOE’s & OKR’s for deeper insights, and driving progress with well-defined OKRs, local government organisations can systematically enhance their cyber maturity and build greater resilience against the ever-evolving cyber threat landscape.

<br>

&#x20;

### Chapter 7: A Strategic Approach to Cyber Resilience using the LACES Framework

This chapter will explain how the **Local Authority Cyber Eco-System (LACES) framework** can be used as a **strategic approach to enhance cyber resilience**, effectively joining together the concepts discussed in the previous chapters, including the Cyber Assessment Framework (CAF), stocktake methodologies, Key Lines of Enquiry (KLOEs), and Objectives and Key Results (OKRs). It will conclude with a ten-step implementation guide for leveraging the LACES framework.

#### 7.1 The LACES Framework as a Strategic Integrator

The **LACES framework** is a **holistic model for cyber resilience** designed to enhance the understanding and implementation of cybersecurity measures within local government. It moves beyond traditional policy-driven approaches to a more adaptable, **principles-based approach**. The framework integrates **six interconnected variables**: **Governance**, **Assurance**, **Processes**, **Data management**, **Resilience**, and **Knowledge sharing**. Any one of these can be the central focus, with the others acting as satellites to ensure a comprehensive perspective.

The LACES framework provides a **structured approach** that can be used to understand complex situations, aid in learning and teaching, and provide a common language for both technical and non-technical practitioners. It is not intended to be a compliance or assurance framework itself, but rather an **educational tool** that supports the development of policies, processes, and procedures.

**Brining it all together:**

·       **Cyber Assessment Framework (CAF):** The LACES framework can be used as a **complementary tool** to the CAF. While the CAF details what good cyber resilience looks like through objectives and principles, LACES provides a **holistic lens** through which to understand and address these requirements. The variables of LACES (Governance, Assurance, etc.) align with many of the principles and contributing outcomes within the CAF objectives. For example, CAF Objective A (Managing Security Risk) aligns strongly with LACES Governance and Assurance variables.

·       **Stocktake Approach:** A stocktake, which assesses current cybersecurity practices, can be **structured around the LACES framework**. Questions within the stocktake can be mapped not only to the CAF but also to the specific variables of LACES, providing a broader understanding of strengths and weaknesses across governance, assurance, processes, data management, resilience, and knowledge sharing. This allows for a more nuanced analysis of cyber maturity.

·       **Key Lines of Enquiry (KLOEs):** KLOEs, used to drill down into specific areas, can be developed to explore each of the LACES variables in greater detail. For instance, under the LACES Governance variable, KLOEs could focus on the roles and responsibilities of the SIRO and CIGG. Similarly, under the Resilience variable, KLOEs could investigate the effectiveness of cyber incident response plans. LACES provides a **contextual structure** for formulating relevant KLOEs.

·       **Objectives and Key Results (OKRs):** When developing OKRs to enhance cyber maturity, the **LACES framework can inform the strategic Objectives**. For example, an Objective to "Strengthen our cyber governance" directly aligns with the LACES Governance variable. The Key Results to achieve this objective can then be linked to specific actions that address CAF principles or identified gaps from a LACES-aligned stocktake. The variable-centric approach of LACES allows for the prioritisation of specific areas when setting OKRs.

#### 7.2 A Ten-Step Implementation Guide using the LACES Framework

The following ten steps provide a strategic approach for local government organisations to implement and leverage the LACES framework to enhance their cyber resilience:

1\.        **Establish a Corporate Information Governance Group (CIGG) and Appoint a Senior Information Risk Owner (SIRO):** Ensure clear **governance** structures are in place with defined roles and responsibilities for information security oversight. The SIRO plays a central role in championing information resilience.

2\.        **Conduct a Baseline Assessment (Stocktake) Aligned with LACES and CAF:** Undertake a comprehensive assessment of the organisation's current cyber security posture. **Map stocktake questions to both the CAF objectives and the six variables of the LACES framework** to identify strengths and weaknesses across governance, assurance, processes, data management, resilience, and knowledge sharing.

3\.        **Define Key Lines of Enquiry (KLOEs) for Each LACES Variable:** Develop **granular KLOEs** to further investigate areas identified in the baseline assessment. These KLOEs should probe deeper into the contributing outcomes and indicators of good practice within the CAF, viewed through the lens of each LACES variable.

4\.        **Develop Objectives and Key Results (OKRs) Informed by LACES and Addressing CAF Requirements:**  Based on the findings of the stocktake and KLOE analysis, set **strategic Objectives** aligned with the LACES variables that need strengthening. Define **measurable Key Results** that will contribute to achieving these Objectives and address specific CAF principles and identified vulnerabilities.

5\.        **Embed "Secure by Design" Principles Across Processes:** Integrate **security and data protection consideration** into the design and development of all systems and services from the outset. This aligns with the LACES Processes and Assurance variables.

6\.        **Develop and Regularly Exercise Cyber Incident Response Plans:** Strengthen the **Resilience** variable by creating comprehensive cyber incident response plans and conducting regular exercises to test their effectiveness. This should include consideration of fast-time communication strategies.

7\.        **Implement a Comprehensive Training and Awareness Programme:** Enhance the **Knowledge Sharing** variable by providing regular training to all staff (including suppliers) on data protection, information security, and secure data handling practices. Foster a **culture of reporting** incidents and near misses.

8\.        **Conduct Regular Risk Assessments and Data Protection Impact Assessments (DPIAs):** Strengthen the **Assurance** variable through regular risk assessments, including DPIAs for processing likely to result in high risk to individuals.

9\.        **Review and Update Data Sharing Agreements:** Ensure all data sharing agreements comply with relevant guidance and include agreed terms for data sharing, security, and disposal. This aligns with the **Data management**and **Governance** variables.

10\.  **Foster Knowledge Sharing and Continuous Improvement:** Actively participate in **knowledge sharing networks** such as WARPs and CTAG. Use lessons learned from incidents, exercises, and peer engagement to continuously improve the organisation's cyber resilience posture across all six LACES variables. The SIRO should champion this culture of continuous improvement and learning.

By adopting this strategic approach using the LACES framework, local government organisations can move towards a more **holistic and resilient cybersecurity posture**, effectively integrating various tools and frameworks to protect their essential services and data.<br>

### Chapter 8: Statecraft and Resilience in the Context of Civil Society

This chapter will explore the intricate relationship between **statecraft** and **cyber resilience** within the broader context of **civil society**, particularly as it pertains to local government. Building upon the strategic application of the **LACES framework** outlined in the previous chapter, we will examine how the actions of the state, particularly at the local level, can foster a more cyber-resilient civil society and how cyber incidents can impact this crucial sphere.

#### 8.1 Understanding Civic Cyber Resilience

**Civic cyber resilience** refers to **the ability of individuals, communities, and organisations within a society to withstand and recover from cyberattacks**. It necessitates a **whole-of-society approach**, involving collaboration between governments, businesses, and citizens. This concept recognises that cyber resilience is not solely the responsibility of technical teams within organisations but requires a broader understanding and engagement across all sectors of society.

The **Local Authority Cyber Eco-System (LACES) framework**, while primarily focused on local government organisations, has a significant role to play in understanding and enhancing civic cyber resilience. The framework's emphasis on **Knowledge sharing** highlights the importance of disseminating information about cyber threats and best practices to the wider community. Furthermore, the **Resilience** variable extends beyond organisational recovery to consider the impact on the services delivered to citizens.

#### 8.2 The Role of Statecraft in Fostering Civic Cyber Resilience

**Statecraft in the digital age** involves nations utilising cyber capabilities to achieve their political objectives and ensuring the security and well-being of their citizens in the digital realm. For local government, as a key component of the state, this translates into a responsibility to foster cyber resilience within their communities.

·       **Protecting Essential Services:** Local authorities deliver critical services to citizens. Ensuring the **cyber resilience**of these services is paramount to maintaining societal order and welfare. Disruptions caused by cyberattacks can have a huge financial cost and threaten the delivery of these vital services to citizens. The **Cyber Assessment Framework (CAF) for local government** can help councils identify cyber risks that could disrupt their most important services and improve their resilience to potential cyber attacks.

·       **Building Public Trust and Confidence:** If Local Public Services are to deliver efficient and often shared services, they need to **build public confidence** and ensure that the public trust that their privacy is protected and their personal data is handled professionally. Cyber incidents can erode this trust. By adopting strong information governance practices and demonstrating a commitment to cyber security, local authorities contribute to a more resilient and trusting relationship with their citizens. Publishing an **information charter** setting out how information is handled can further enhance transparency and public confidence.

·       **Promoting Public Awareness and Education:** A key element of civic cyber resilience is **educating citizens about cyber threats and best practices for online safety**. Local authorities can play a role in raising public awareness through campaigns and by providing accessible information on cyber security. The "Think Cyber Think Resilience" work implemented by MHCLG aimed to help organisations prepare for cyber attacks, and a good starting point is the strategy report produced as part of the programme.

·       **Facilitating Information Sharing and Collaboration:** **Encouraging collaboration between government agencies, businesses, and individuals to share information about cyber threats and vulnerabilities** is crucial for a whole-of-society approach. Local Resilience Forums (LRFs) are increasingly focusing on planning for cyber incidents, and local authority security officers are strengthening their ties with LRFs. Initiatives like WARPs (Warning, Advice and Reporting Points) facilitate the dissemination of knowledge and co-learning, improving resilience from a cybersecurity viewpoint.

·       **Developing Incident Response Capabilities:** **Developing and testing plans for responding to cyber incidents, including coordinating efforts between different stakeholders**, is essential. Local authorities need to have **Cyber Incident Response Plans** and regularly exercise them. The **LACES framework's** emphasis on **Processes** supports the development of effective incident response mechanisms.

#### 8.3 Impact of Cyber Incidents on Civil Society

Cyberattacks are no longer just isolated incidents; they are now tools of geopolitical influence with the potential to disrupt economies, undermine national security, and sow discord among nations. At the local level, cyber incidents can directly impact civil society in several ways:

·       **Disruption of Essential Services:** As highlighted earlier, attacks on local government systems can disrupt vital services relied upon by citizens, such as social care, waste management, and council tax processing. The inability to access these services can have significant consequences for individuals and communities.

·       **Erosion of Trust:** Data breaches and cyberattacks can lead to the compromise of citizens' personal information, eroding trust in public institutions and their ability to protect sensitive data. Maintaining trust with citizens is paramount.

·       **Impact on Democratic Engagement:** Cyberattacks can target activities that support or promote democratic engagement. Securing local democracy through the protection of local and national elections is a priority area.

·       **Financial Costs:** Cyber attacks can have a huge financial cost for local authorities, which ultimately impacts the resources available for public services. Local Public Services will still face the full financial penalties for any breaches.

#### 8.4 Leveraging the LACES Framework for Civic Cyber Resilience

The **LACES framework** can be a valuable tool for local authorities in their efforts to enhance civic cyber resilience:

·       **Governance:** Establishing clear governance structures that include consideration of the wider community impact of cyber security decisions. This involves the SIRO championing cyber resilience not just within the council but also in its interactions with citizens.

·       **Assurance:** Conducting risk assessments that consider the potential impact of cyber threats on the community and ensuring that security measures are proportionate to the information risk.

·       **Processes:** Developing and implementing incident response plans that include communication strategies for informing and supporting affected citizens during a cyber incident.

·       **Data Management:** Implementing robust data protection measures to safeguard citizens' personal information and maintain their trust.

·       **Resilience:** Focusing on the ability to maintain operation of essential services in the face of cyber attacks, ensuring that business continuity plans consider the needs of the community.

·       **Knowledge Sharing:** Actively engaging with the public to raise awareness about cyber threats and providing guidance on how individuals can protect themselves online.

#### 8.5 Conclusion

Fostering **cyber resilience** within **civil society** is a crucial aspect of modern **statecraft**, particularly for local government. By prioritising the security of essential services, building public trust, promoting awareness, facilitating collaboration, and developing robust incident response capabilities, local authorities can contribute to a more resilient society. The **LACES framework** provides a holistic lens through which to understand and address these multifaceted challenges, ensuring that cyber security efforts extend beyond the boundaries of the council to protect the communities they serve. The increasing convergence of the physical and digital realms necessitates a proactive and adaptive approach to cyber resilience that embraces a whole-of-society perspective.

<br>

&#x20;

### Chapter 9: Local Authority Devolution: Guidance for Enhanced Information Governance, Resilience, and Integration

This chapter provides detailed guidance on **Local Authority devolution** in England, building upon the principles of **Information Governance**, **resilience**, and **integration** discussed in previous chapters, particularly Chapter 8 on statecraft and resilience in civil society. It aims to equip Local Authorities with a strategic understanding and actionable steps to navigate the evolving devolved landscape while ensuring the secure and effective management of information and the resilience of essential services.

#### 9.1 Understanding Local Authority Devolution in England

The UK Government is actively pursuing a policy of **widening and deepening devolution** across England. This involves granting local leaders and communities greater powers and funding to drive growth and raise living standards. The **English Devolution White Paper**, "Power and Partnership: Foundations for Growth," outlines the government’s plans to empower local leaders, particularly through **mayoral-led strategic authorities**, and to reform local government structures.

Key aspects of this devolution agenda include:

* **Creation of Strategic Authorities:** The government is legislating to create a concept of "**Strategic Authorities**" with increasing levels of duties and powers. These include "**Foundation Strategic Authorities**" (non-mayoral combined authorities and combined county authorities) and "**Mayoral Strategic Authorities**," with "**Established Mayoral Strategic Authorities**" at the highest tier based on specific criteria.
* **Increased Powers for Mayors:** The devolution proposals significantly enhance the powers and functions of **metro mayors**, granting them greater control over areas such as strategic planning, housing, transport, skills, and potentially health and net zero. Mayors may also be able to appoint remunerated "**Commissioners**" to support the delivery of key functions.
* **Devolution Framework:** The government intends to enshrine a new "**Devolution Framework**" in statute, making it easier to grant new powers and simplifying devolution processes. There is a preference for all strategic authorities to be led by mayors.
* **Funding Reforms:** The funding of combined authorities is being reformed, with "**Integrated Settlements**" granted to the most established Mayoral Strategic Authorities, providing greater flexibility in allocating resources. The government also aims to reduce competitive bidding and rationalise funding pots.
* **Local Government Reorganisation:** A programme of local government reorganisation is underway to replace two-tier county and district councils with single-tier "**unitary**" authorities. This aims to simplify the local government landscape and improve public service performance.
* **Focus on Growth and Public Service Reform:** The devolution agenda is presented as a means to unlock regional growth, deliver on the government’s Plan for Change, and improve public services through better integration at a local level.

This significant shift towards devolution presents both opportunities and challenges for Local Authorities, particularly in relation to **Information Governance**, **resilience**, and the **integration** of services and systems across potentially larger and more complex strategic authorities.

#### 9.2 Implications of Devolution for Information Governance

The evolving devolution landscape has significant implications for how Local Authorities manage and protect information:

* **Expanded Data Sharing:** The drive for integrated services and strategic planning across larger areas governed by Strategic Authorities will necessitate **increased data sharing** between constituent councils and potentially with new mayoral bodies. This must be undertaken in accordance with **data protection legislation**, including the Data Protection Act 2018 and the UK GDPR. Authorities should **review and update all Data Sharing Agreements** to ensure compliance with the Information Commissioner’s data sharing code of practice, including agreed terms for data sharing, security, and disposal. As a data sharing practitioner, clarity about legal powers, consistency in information about these powers, and a focus on using existing legal gateways are crucial.
* **Accountability and Governance:** The creation of new Strategic Authorities, especially those led by mayors, requires clear **accountability frameworks** and robust **governance structures** for information. The ICO’s DPA/THE DATA PROTECTION ACT guidance on accountability should be followed, stressing the controller’s responsibility to implement appropriate technical and organisational measures to ensure and demonstrate compliance. Establishing or reviewing the **Corporate Information Governance Group (CIGG)** with clear terms of reference and ensuring the active role of the **Senior Information Risk Owner (SIRO)** are essential.
* **Data Protection by Design and Default:** As new devolved structures and integrated services are designed, the principle of "**secure by design**" should be embedded from the outset. Security and data protection considerations must be integrated into the design and development of all systems and services that handle personal data.
* **Transparency and Public Trust:** In a devolved system with potentially new layers of governance, maintaining **transparency** with the public about how their data is handled is paramount for building and sustaining **public trust**. Publishing an **information charter** outlining data handling practices and how concerns can be addressed remains a key recommendation.
* **Record of Processing Activities (ROPA):** Local Authorities within devolved structures must maintain a **comprehensive and up-to-date Register of Processing Activities (ROPA)**, detailing all processing activities of personal data, including those related to shared services and strategic authority functions.

#### 9.3 Enhancing Resilience in the Context of Devolution

Devolution necessitates a coordinated approach to **cyber resilience** across potentially larger and interconnected strategic authority areas:

* **Cyber Assessment Framework (CAF) and LG-CAF:** Local Public Services should utilise frameworks like the **Cyber Assessment Framework (CAF)** and the developing **Local Government CAF (LG-CAF)** to identify and address cyber risks in a proportionate way. Implementing data handling practices recommended in guidance will better position authorities to meet the requirements of these frameworks.
* **Cyber Incident Response Planning:** Each Local Authority within a devolved structure must have a robust and regularly exercised **Cyber Incident Response Plan**. These plans should consider the interconnected nature of services within a strategic authority and outline clear protocols for communication and coordination during a cyber incident. The ability to respond to cyber incidents remotely and testing this capability are increasingly crucial.
* **Risk Management:** Councils need to maintain a **risk register that includes cybersecurity** and articulate a documented **cybersecurity risk appetite** at the board level. This is crucial for informed decision-making and resource allocation in the context of devolved responsibilities. The SIRO plays a key role in owning and reviewing the information risk appetite.
* **Security Standards for Third Parties:** As Strategic Authorities and constituent councils may increasingly rely on shared services and third-party vendors, establishing and enforcing **minimum cybersecurity standards for third parties** is vital for managing supply chain risks. This includes conducting risk assessments of vendors, ensuring stringent security requirements in contracts, and auditing suppliers for compliance.
* **Network Security and Segmentation:** Implementing practices like **network segmentation** and segregating internet services from internal systems remain essential for limiting the impact of potential cyberattacks across the devolved landscape.
* **Staff Training and Awareness:** Comprehensive **cybersecurity training and awareness programs** for all staff and councillors are crucial for building a security-conscious culture across all levels of the devolved structure. This includes training on data protection and secure data handling practices, with records of all training maintained. Conducting phishing tests for staff and councillors can help assess and improve awareness.
* **Information Sharing through WARPs:** Active participation in regional **Warning, Advice and Reporting Points (WARPs)** facilitates the sharing of threat intelligence and best practices across Local Authorities, enhancing collective resilience within devolved areas.

#### 9.4 Fostering Integration within Devolved Structures

Effective **integration** of information governance and resilience practices is crucial for the success of devolution:

* **Collaborative Governance:** Strategic Authorities should establish clear mechanisms for **collaborative governance** of information, involving representatives from all constituent councils. This ensures a consistent and coordinated approach to data protection and cybersecurity across the devolved area.
* **Shared Policies and Procedures:** Where appropriate and feasible, Strategic Authorities should aim to develop **shared information governance policies and procedures**, such as data sharing protocols, security standards, and incident response frameworks, to ensure consistency and interoperability.
* **Integrated Risk Management:** A coordinated approach to **risk management**, including cybersecurity risks, should be adopted at the Strategic Authority level. This involves sharing risk registers, conducting joint risk assessments, and developing overarching risk mitigation strategies.
* **Joint Training and Awareness Initiatives:** Strategic Authorities can leverage their scale to deliver **joint cybersecurity training and awareness initiatives** for staff and councillors across the devolved area, promoting a unified security culture.
* **Shared Security Monitoring and Incident Response Capabilities:** Exploring the potential for **shared security monitoring tools and incident response capabilities** across a Strategic Authority could enhance efficiency and effectiveness in detecting and responding to cyber threats. Initiatives like a Security Operations Centre (SOC) style tooling, and aggregating and analysing system logs can be beneficial.
* **Alignment with National Frameworks:** Devolved structures must ensure their information governance and resilience practices align with national frameworks such as the **Cyber Assessment Framework (CAF)** and guidance from the **Information Commissioner’s Office (ICO)** and the **National Cyber Security Centre (NCSC)**.

#### 9.5 Call to Action

The move towards greater Local Authority devolution in England presents a significant opportunity to empower local communities and drive growth. However, to realise the full benefits of devolution while safeguarding public trust and ensuring the continuity of essential services, Local Authorities must **prioritise and strengthen their Information Governance and cyber resilience capabilities within these new devolved structures.**

**We urge all Local Authorities to proactively engage with the devolution agenda and to take immediate steps to integrate robust information governance and resilience practices into their strategic planning and operational delivery.** Failure to do so could expose devolved areas to increased data security risks, potential service disruptions, and a loss of public confidence.

#### 9.6 Strategic Plan and Action Points

To effectively navigate the devolved landscape and enhance Information Governance, resilience, and integration, Local Authorities should adopt the following strategic plan with actionable points:

**Strategic Goal 1: Establish Robust Information Governance Frameworks within Devolved Structures**

* **Action 1.1:** Within six months of the establishment of a new Strategic Authority or significant expansion of mayoral powers, convene a cross-authority **Information Governance Steering Group** to oversee the development and implementation of coordinated information governance strategies.
* **Action 1.2:** Conduct a comprehensive review of existing **Data Sharing Agreements** between constituent councils and identify any new data sharing requirements arising from devolved functions. Update agreements to ensure legal compliance and robust security measures within twelve months.
* **Action 1.3:** Develop a **Strategic Authority-level information charter** outlining how data is handled across the devolved area and how citizens can raise concerns, to be published within nine months.
* **Action 1.4:** Ensure the **Senior Information Risk Owner (SIRO)** roles within constituent authorities have clear lines of communication and collaboration with any relevant roles established at the Strategic Authority level. Define responsibilities for information risk management across the devolved structure within three months.
* **Action 1.5:** Maintain a comprehensive and accessible **Register of Processing Activities (ROPA)** that accurately reflects data processing activities within the context of devolved functions and shared services, reviewed and updated at least annually.

**Strategic Goal 2: Enhance Cyber Resilience Across Devolved Areas**

* **Action 2.1:** Within three months, conduct a joint **cyber risk assessment** across the Strategic Authority area, utilising the **Cyber Assessment Framework (CAF)** or equivalent, to identify shared vulnerabilities and interdependencies.
* **Action 2.2:** Develop and implement a **coordinated Cyber Incident Response Plan** that outlines protocols for communication, collaboration, and recovery across the Strategic Authority in the event of a significant cyber incident, to be tested annually through joint exercises.
* **Action 2.3:** Establish **minimum cybersecurity standards for all third-party vendors** providing services to the Strategic Authority and constituent councils, ensuring these are incorporated into contracts and regularly audited for compliance within twelve months.
* **Action 2.4:** Implement and maintain **network segmentation** and other appropriate security controls to limit the potential impact of cyber incidents across the devolved infrastructure.
* **Action 2.5:** Deliver **joint cybersecurity training and awareness programs** for staff and councillors across the Strategic Authority area at least annually, tailored to the specific risks and responsibilities within the devolved context. Increase the frequency of phishing tests.
* **Action 2.6:** Actively participate in regional **WARP (Warning, Advice and Reporting Point)** initiatives and establish clear channels for sharing threat intelligence across the Strategic Authority.

**Strategic Goal 3: Foster Integration of Information Governance and Resilience Practices**

* **Action 3.1:** Establish a **joint working group** comprising information governance and cybersecurity professionals from across the Strategic Authority to promote collaboration and the integration of their respective strategies and plans within three months.
* **Action 3.2:** Identify opportunities for **shared security monitoring tools and incident response capabilities** at the Strategic Authority level, conducting a feasibility study within twelve months.
* **Action 3.3:** Develop **joint policies and procedures** for key areas such as data breach notification, acceptable use of technology, and secure remote working that are applicable across the Strategic Authority, where appropriate.
* **Action 3.4:** Conduct **regular reviews and audits** of information governance and resilience practices across the devolved area to ensure consistency, effectiveness, and alignment with national guidance and legislation.
* **Action 3.5:** Share **lessons learned** from any security incidents or data breaches across the Strategic Authority to promote continuous improvement and collective resilience.

By implementing this strategic plan and prioritising these actionable points, Local Authorities in England can effectively navigate the opportunities and challenges of devolution, ensuring the secure and responsible management of information and the resilience of vital public services for the benefit of their communities.


# Supply Chain Security             July 2026

CTAG Supply Chain Security Resources

Approach to Third Party (Supply Chain) Risks, their Identification and mitigation derived from UK Public Sector fieldwork.

&#x20;

The **Integrated Supply Chain Security and Assurance Framework** structures supply chain risk into several core pillars, moving from evidence-based threat profiling to legal procurement controls and maturity tracking.                &#x20;

1\.     **Strategic Foundation and Threat Profiling** The framework is built on an evidence-based approach that mandates analysing historical supplier data breaches and attacks to inform dynamic threat profiles. These threat profiles prioritise public internet-facing services, which carry the highest risk of compromise. It identifies Identity and Access Management (IAM) exposure, Shared Responsibility Mapping (SRM) across cloud and on-premises deployment, and broader geopolitical risks. The  SRM is a key component as client organisations must fully understand where the supplier responsibility ends and their consumer responsibility starts. This is critical for good governance and data protection.  Table 4 summarises these risks.

&#x20;

&#x20;**Approach to Supply Chain Mapping**

| Threat Profile Priority                       | Description & Focus Area                                                                                                                                              |
| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Public Internet-Facing Services               | Identifies and profiles suppliers with services exposed to the public web, treating them as high-priority risk vectors.                                               |
| Identity and Access Management (IAM) Exposure | Analyses the risks associated with service-to-service authentication and human administrative access within the supply chain.                                         |
| Shared Responsibility Mapping                 | Distinguishes and clarifies risk ownership across different deployment scenarios, including on-premises, Software as a Service (SaaS), and cloud-native environments. |
| Geopolitical Risks                            | Factors broader political and economic stability contexts into the overall supplier risk scoring. This includes where data is processed & stored.                     |

Key software service Threat profiles and  Risks (Source: Author).

## &#x20;**Centralised Supplier Repository / Information Asset Register**&#x20;

A dynamic, relational **Central Supplier Catalogue** serves as the primary resilience tool, accommodating both standardised data and free-text fields. The catalogue/register is the absolute core of any supply chain security programme of work. The real power of this approach, comes when the community / eco-systems share them. Within a Local Authority in the UK, there could be upwards of 750 systems and services. This is highly complex and generates a mountain or lake of data. Where Councils share he same supplier, knowing which other Councils share that supplier and having a detailed inventory of that suppliers’ components, and versions can really help during an incident, immediately alerting who would be affected by an exploit. This is key to the “Defend as One” Programme of work. \[67] Table 5, provides an information asset template . This can be formatted as XML or other metadata to allow easy electronic sharing. The version number will ensure consistent mapping of any version changes I the structure. This template could become a standard for use within UK Local Government, this would facilitate information sharing and Cyber Incident Response. Th version number included to reflect this is the initial version 1.0 suggestion as of July 2026. There will need to be an accessible repository for the standard, such as the CTAG Guidance repository&#x20;

&#x20;

Information Asset Register (IAR) Template (Version 1.0 July 2026)

| Field Category           | Field Name                                                                        | Description                                                                                                                                                                                                                                                                    |
| ------------------------ | --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Framework Mandated       | Date entry created                                                                | The date the Asset record was created.                                                                                                                                                                                                                                         |
| Framework Mandated       | Date entry updated / reviewed                                                     | The Asset Record must be reviewed at least annually.                                                                                                                                                                                                                           |
| Framework Mandated       | Unique Supplier ID (Unique Key)                                                   | A unique identifier that programmatically links the information asset to the Central Supplier Catalogue.                                                                                                                                                                       |
| Framework Mandated       | Processing / Hosting Supplier                                                     | Explicitly identifies the third-party supplier that is responsible for processing, managing, or hosting the information asset.                                                                                                                                                 |
| Framework Mandated       | Product / Service version number                                                  | This is the product / service version number (Patch level).                                                                                                                                                                                                                    |
| Framework Mandated       | Suppler Assertion Verification                                                    | Indicates whether the asset has been verified using automated discovery tools to validate the supplier's claims. Or that a CAF or similar audit exists                                                                                                                         |
| Framework Mandated       | Supplier Cyber Essentials / Plus – or ISO 27001 etc. status recorded and verified | <p>Record and verify the asserted security certifications  held by the supplier. </p><p>(Review annually during contract)</p>                                                                                                                                                  |
| Framework Mandated       | DPIA Status                                                                       | Tracks whether a standardised Data Protection Impact Assessment (DPIA) has been completed for the asset, particularly regarding supply chain changes. Whilst only mandated for complex systems, this is a very robust way to assure personal data, being processed and stored. |
| *Standard Best Practice* | *Asset ID / Reference Number*                                                     | *A unique internal alphanumeric identifier assigned to the specific asset.*                                                                                                                                                                                                    |
| *Standard Best Practice* | *Asset Name & Description*                                                        | *A clear title and brief summary of what the information asset is and its business purpose (e.g., "Customer Payment Gateway").*                                                                                                                                                |
| *Standard Best Practice* | *Information Asset Owner (IAO)*                                                   | *The internal role, department, or individual who is ultimately accountable for the asset's security and lifecycle. A named individual is best, by default it will be the service owner.*                                                                                      |
| *Standard Best Practice* | *Data Classification*                                                             | *The sensitivity level of the data contained in the asset (e.g., Public, OFFICIAL, Internal, Confidential, Restricted).*                                                                                                                                                       |
| *Standard Best Practice* | *Format and Location*                                                             | *Where and how the asset is stored (e.g., AWS Cloud, On-Premises Server, Physical Records).*                                                                                                                                                                                   |
| *Standard Best Practice* | *Business Criticality (CIA)*                                                      | *An assessment of the impact on the business if the asset's Confidentiality, Integrity, or Availability is compromised.*                                                                                                                                                       |
| *Standard Best Practice* | *Modelling harm*                                                                  | *Understand the harm caused in the event of a data breach, to an individual, community or other group, includes, physical, financial, reputational. This can align with the UK Data Classification Guidelines.*                                                                |
| *Standard Best Practice* | *Retention Period & Disposal*                                                     | *The required legal or operational lifespan of the data and the approved method for secure disposal at the end of its lifecycle. Remember data isn’t gone until the last backup is deprecated.*                                                                                |

&#x20;Information Asset Register Template (Source: Author)

&#x20;

Suppliers must actively maintain standardised assertions \[63]  regarding their patching status, encryption protocols, compliance certificates, and product liability. To ensure transparency, suppliers are also required to have a formal **Vulnerability Disclosure Policy (VDP)**  so the organization is alerted to critical bugs before exploitation.\[65] There are a number of commercial tools available that do this.

**Technical Architecture and Asset Management**&#x20;

Scalable, real-time assurance is achieved through an **API-driven architecture** where either the organisation pulls data from supplier endpoints, or suppliers push updates to a central API. The architecture also explores using **blockchain** for non-repudiation, utilizing immutable timestamps to prevent suppliers from backdating compliance evidence after an incident.

Furthermore, an **Information Asset Register (IAR)** must be programmatically linked to the supplier catalogue using a Unique Supplier ID. An integrated Assurance Toolkit leverages open-source automated discovery tools to verify local network assets against supplier claims, establishing a "ground truth".

**Governance and Compliance Alignment** Policy governance is driven by the **LACES** framework (Local Authority Cyber Eco-System). \[66] Supplier risks—such as IAM exposure and service criticality—are formally tracked in a dedicated Supply Chain Risk Register. To avoid "compliance fatigue," the framework maps requirements to a targeted, risk-proportional subset of the **NCSC Cyber Assessment Framework (CAF)** and **EU NIS/NIS2** regulations. \[63]&#x20;

**Procurement and Legal Integration** Security is embedded into the procurement lifecycle using model contract clauses, rigorous tender questionnaires, and structured dropdown answers to enable automated scoring. Crucially, the framework enforces **Legally Binding Assertions (LBAs)**, which tie a supplier's security claims directly to contractual limits of liability and insurance recourse. \[64]&#x20;

**Maturity Modelling and Implementation** Organisations evaluate their supplier assurance capabilities on a **0-to-5 maturity scale**, progressing from non-existent/reactive checks (0-1) up to full lifecycle automated assurance and predictive risk modelling (5). The framework concludes with a four-phase roadmap for operationalisation, spanning research, tooling development, governance drafting, and alignment with GDS/DCMS architecture standards.

## **References:**

1. Integrating Machine Learning and Business Intelligence into Supply Chain Risk Management for a Comprehensive Cybersecurity Framework: A Systematic Literature Review - MDPI, [https://www.mdpi.com/2227-7080/14/4/194](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2227-7080%2F14%2F4%2F194)
2. Third-Party Risk Management: Ensuring Vendor and Partner Compliance with Data Protection Laws - ResearchGate, [https://www.researchgate.net/publication/395476764\_Third-Party\_Risk\_Management\_Ensuring\_Vendor\_and\_Partner\_Compliance\_with\_Data\_Protection\_Laws](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F395476764_Third-Party_Risk_Management_Ensuring_Vendor_and_Partner_Compliance_with_Data_Protection_Laws)
3. Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports, [https://www.researchgate.net/publication/351567274\_Cyber\_Third-Party\_Risk\_Management\_A\_Comparison\_of\_Non-Intrusive\_Risk\_Scoring\_Reports](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F351567274_Cyber_Third-Party_Risk_Management_A_Comparison_of_Non-Intrusive_Risk_Scoring_Reports)
4. Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports - Scholars Archive, [https://scholarsarchive.library.albany.edu/cgi/viewcontent.cgi?article=1002\&context=ehc\_fac\_scholar](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fscholarsarchive.library.albany.edu%2Fcgi%2Fviewcontent.cgi%3Farticle%3D1002%26context%3Dehc_fac_scholar)
5. The development of supply chain management cybersecurity risks: What past incidents - Iowa State University, [https://dr.lib.iastate.edu/bitstreams/bbbea3cc-d43d-4b13-ab44-51c2e7a78eb8/download](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdr.lib.iastate.edu%2Fbitstreams%2Fbbbea3cc-d43d-4b13-ab44-51c2e7a78eb8%2Fdownload)
6. Deciphering the Supply Chain Chessboard: The Science of Decision-Making in Risk Management - CyberRisk Alliance, [https://www.cyberriskalliance.com/blog/deciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.cyberriskalliance.com%2Fblog%2Fdeciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management)
7. Supply chain cybersecurity & compliance - Star | Global, [https://star.global/posts/supply-chain-cybersecurity-compliance/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fstar.global%2Fposts%2Fsupply-chain-cybersecurity-compliance%2F)
8. NIST 800-161: Cybersecurity Supply Chain Risk Management Steps - ComplianceForge, [https://complianceforge.com/compliance/nist-800-161-compliance](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fcomplianceforge.com%2Fcompliance%2Fnist-800-161-compliance)
9. Third-Party Risk Statistics 2026: Vendor & Supply Chain Risk - DeepStrike, [https://deepstrike.io/blog/third-party-risk-statistics](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdeepstrike.io%2Fblog%2Fthird-party-risk-statistics)
10. Supply Chain Risk Management: A Strategic Guide for Modern Resilience - Panorays, [https://panorays.com/blog/supply-chain-risk-management-strategies/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpanorays.com%2Fblog%2Fsupply-chain-risk-management-strategies%2F)
11. Third-Party Risk Management in Cybersecurity Reference | Advanced Security Authority, [https://advancedsecurityauthority.com/third-party-risk-management-reference/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fadvancedsecurityauthority.com%2Fthird-party-risk-management-reference%2F)
12. What Is Third Party Risk Management? 2025 Complete Guide - Isora GRC, [https://www.saltycloud.com/blog/third-party-risk-management/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.saltycloud.com%2Fblog%2Fthird-party-risk-management%2F)
13. TPRM Maturity Model for Third-Party Risk: Complete Guide \[2026] | Isora GRC, [https://www.saltycloud.com/blog/tprm-maturity-model/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.saltycloud.com%2Fblog%2Ftprm-maturity-model%2F)
14. Third-Party Risk Management Frameworks: The Guide - Mitratech, [https://mitratech.com/resource-hub/blog/third-party-risk-management-frameworks/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmitratech.com%2Fresource-hub%2Fblog%2Fthird-party-risk-management-frameworks%2F)
15. Supply Chain Risk Management: Best Practices - Drata, [https://drata.com/learn/tprm/supply-chain-best-practices](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdrata.com%2Flearn%2Ftprm%2Fsupply-chain-best-practices)
16. A Multicriteria Decision-Making Approach to Building Resilience Along the Indian Medical Equipment Supply Chain | Request PDF - ResearchGate, [https://www.researchgate.net/publication/389302015\_A\_Multicriteria\_Decision-Making\_Approach\_to\_Building\_Resilience\_Along\_the\_Indian\_Medical\_Equipment\_Supply\_Chain](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F389302015_A_Multicriteria_Decision-Making_Approach_to_Building_Resilience_Along_the_Indian_Medical_Equipment_Supply_Chain)
17. Key Practices in Cyber Supply Chain Risk Management: Observations from Industry - NIST Technical Series Publications, [https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fnvlpubs.nist.gov%2Fnistpubs%2Fir%2F2021%2FNIST.IR.8276.pdf)
18. The Anatomy of a Good Concept: A Systematic Review on Cyber Supply Chain Risk Management - MDPI, [https://www.mdpi.com/2071-1050/18/3/1151](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2071-1050%2F18%2F3%2F1151)
19. Conduct an Effective Supply Chain Cybersecurity Risk Assessment - Onspring Technologies, [https://onspring.com/resources/blog/conduct-an-effective-supply-chain-cybersecurity-risk-assessment/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fonspring.com%2Fresources%2Fblog%2Fconduct-an-effective-supply-chain-cybersecurity-risk-assessment%2F)
20. SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties, [https://arxiv.org/html/2406.10109v1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Farxiv.org%2Fhtml%2F2406.10109v1)
21. Defending Against Software Supply Chain Attacks - CISA, [https://www.cisa.gov/sites/default/files/publications/defending\_against\_software\_supply\_chain\_attacks\_508.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2Fdefending_against_software_supply_chain_attacks_508.pdf)
22. The Benefits of a Software Bill of Materials Program at Nuclear Facilities - INL Digital Library - Idaho National Laboratory, [https://inldigitallibrary.inl.gov/sites/sti/sti/Sort\_65326.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Finldigitallibrary.inl.gov%2Fsites%2Fsti%2Fsti%2FSort_65326.pdf)
23. Organisation-Level SCF Certifications | SCF CAP Guide, [https://securecontrolsframework.com/scf-certified/organisation-level-scf-certifications](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsecurecontrolsframework.com%2Fscf-certified%2Forganization-level-scf-certifications)
24. A Complete Guide to Third-Party Security Assessment - SPOG, [https://blog.spog.ai/a-complete-guide-to-third-party-security-assessment/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fblog.spog.ai%2Fa-complete-guide-to-third-party-security-assessment%2F)
25. (PDF) Information Security Risk Management Model for Big Data - ResearchGate, [https://www.researchgate.net/publication/362562040\_Information\_Security\_Risk\_Management\_Model\_for\_Big\_Data](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F362562040_Information_Security_Risk_Management_Model_for_Big_Data)
26. Modelling the conundrums to cyber-risks management in logistics firms for supply chain social sustainability - Emerald Publishing, [https://www.emerald.com/jeim/article/37/6/1885/1227695/Modelling-the-conundrums-to-cyber-risks-management](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Fjeim%2Farticle%2F37%2F6%2F1885%2F1227695%2FModelling-the-conundrums-to-cyber-risks-management)
27. A Supply Chain Game Theory Framework for Cybersecurity ..., [https://supernet.isenberg.umass.edu/Articles/SupplyChain-Cybersecurity-Investments-Network-Vulnerability.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupernet.isenberg.umass.edu%2FArticles%2FSupplyChain-Cybersecurity-Investments-Network-Vulnerability.pdf)
28. Assured Cyber Supply Chain Provenance Using Permissioned Blockchain, [https://iti.illinois.edu/credc/researchactivity/assured-cyber-supply-chain-provenance-using-permissioned-blockchain](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fiti.illinois.edu%2Fcredc%2Fresearchactivity%2Fassured-cyber-supply-chain-provenance-using-permissioned-blockchain)
29. Managing cyber risk in supply chains: A review and research agenda, [https://researchportal.hw.ac.uk/files/25264894/SCMIJ\_AAP.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fresearchportal.hw.ac.uk%2Ffiles%2F25264894%2FSCMIJ_AAP.pdf)
30. Cyber Risks: Systematic Literature Analysis - International Institute of Informatics and Cybernetics, [https://www.iiisci.org/journal/PDV/sci/pdfs/SA153UQ24.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.iiisci.org%2Fjournal%2FPDV%2Fsci%2Fpdfs%2FZA153UQ24.pdf)
31. Cyber Supply Chain Risk Management: From Threats to Treatment | Scilit, [https://www.scilit.com/publications/e3d0699efee879e39d63eabe9a91a08a](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.scilit.com%2Fpublications%2Fe3d0699efee879e39d63eabe9a91a08a)
32. The relationship between cybersecurity awareness, cybersecurity supply chain risk management and firm performance - Emerald Insight, [https://www.emerald.com/scm/article/30/5/497/1265668/The-relationship-between-cybersecurity-awareness](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Fscm%2Farticle%2F30%2F5%2F497%2F1265668%2FThe-relationship-between-cybersecurity-awareness)
33. CyberSecurity Readiness: A Model for SMEs based on the Socio-Technical Perspective, [https://www.researchgate.net/publication/367645669\_CyberSecurity\_Readiness\_A\_Model\_for\_SMEs\_based\_on\_the\_Socio-Technical\_Perspective](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F367645669_CyberSecurity_Readiness_A_Model_for_SMEs_based_on_the_Socio-Technical_Perspective)
34. Full article: A combined Blockchain and sero-knowledge model for healthcare B2B and B2C data sharing - Taylor & Francis, [https://www.tandfonline.com/doi/full/10.1080/25765299.2023.2188701](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.tandfonline.com%2Fdoi%2Ffull%2F10.1080%2F25765299.2023.2188701)
35. The MARISMA- CPS pattern - Essex Research Repository, [https://repository.essex.ac.uk/33036/1/1-s2.0-S0166361522001129-main.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Frepository.essex.ac.uk%2F33036%2F1%2F1-s2.0-S0166361522001129-main.pdf)
36. Evaluation of the Feasibility of Utilising a Low-Cost UWB Radar for Hardware Implant & Counterfeit Device Detection - INFO - Oak Ridge National Laboratory, [https://info.ornl.gov/sites/publications/Files/Pub182146.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Finfo.ornl.gov%2Fsites%2Fpublications%2FFiles%2FPub182146.pdf)
37. Proceedings of the Cyber Supply Chain Risk Management for Critical Systems (CySCRM '24) - Pacific Northwest National Laboratory, [https://www.pnnl.gov/sites/default/files/media/file/Final%20CySCRM%20Proceedings.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.pnnl.gov%2Fsites%2Fdefault%2Ffiles%2Fmedia%2Ffile%2FFinal%2520CySCRM%2520Proceedings.pdf)
38. Cyber Supply Chain Risk Management in the Netherlands ..., [https://essay.utwente.nl/fileshare/file/96796/weiss\_MA\_eemcs.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fessay.utwente.nl%2Ffileshare%2Ffile%2F96796%2Fweiss_MA_eemcs.pdf)
39. DORA: Managing Third-Party Risk in the Supply Chain | Eraneos, [https://www.eraneos.com/articles/the-digital-operational-resilience-act-dora-and-the-management-of-third-party-risks-in-the-supply-chain-part-3/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.eraneos.com%2Farticles%2Fthe-digital-operational-resilience-act-dora-and-the-management-of-third-party-risks-in-the-supply-chain-part-3%2F)
40. Key Strategies for Managing Third-Party Risk Under DORA - Omada, [https://omadaidentity.com/resources/blog/strategies-third-party-risk-dora/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fomadaidentity.com%2Fresources%2Fblog%2Fstrategies-third-party-risk-dora%2F)
41. Digital Operational Resilience Act (DORA) - eiopa - European Union, [https://www.eiopa.europa.eu/digital-operational-resilience-act-dora\_en](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.eiopa.europa.eu%2Fdigital-operational-resilience-act-dora_en)
42. Third-Party Risk Management under DORA | SAP LeanIX, [https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.leanix.net%2Fen%2Fwiki%2Ftrm%2Fthird-party-risk-management-under-dora)
43. DORA Third-Party Risk Management Compliance | Prevalent - Mitratech, [https://mitratech.com/resource-hub/rc-use-case/eu-digital-operational-resilience-act-compliance/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmitratech.com%2Fresource-hub%2Frc-use-case%2Feu-digital-operational-resilience-act-compliance%2F)
44. CMMC 2.0 Compliance Templates - ComplianceForge, [https://complianceforge.com/compliance/cmmc-compliance-dfars-252-204-7021](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fcomplianceforge.com%2Fcompliance%2Fcmmc-compliance-dfars-252-204-7021)
45. BOMs Away! Inside the Minds of Stakeholders:A ... - Oscar Chaparro, [https://ojcchar.github.io/files/27-icse24-sboms.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fojcchar.github.io%2Ffiles%2F27-icse24-sboms.pdf)
46. How to choose mitigation measures for supply chain risks | Request PDF - ResearchGate, [https://www.researchgate.net/publication/265557093\_How\_to\_choose\_mitigation\_measures\_for\_supply\_chain\_risks](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F265557093_How_to_choose_mitigation_measures_for_supply_chain_risks)
47. (PDF) Risk‑Based Counterparty Due Diligence Framework for the Crude Segment: Case Study of PT Pertamina (Persero) - ResearchGate, [https://www.researchgate.net/publication/401940558\_Risk-Based\_Counterparty\_Due\_Diligence\_Framework\_for\_the\_Crude\_Segment\_Case\_Study\_of\_PT\_Pertamina\_Persero](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F401940558_Risk-Based_Counterparty_Due_Diligence_Framework_for_the_Crude_Segment_Case_Study_of_PT_Pertamina_Persero)
48. A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability, [https://supernet.isenberg.umass.edu/visuals/POMS-May%202016.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupernet.isenberg.umass.edu%2Fvisuals%2FPOMS-May%25202016.pdf)
49. Cybersecurity and Supply Chain Risk Management Are Not ... - RAND, [https://www.rand.org/content/dam/rand/pubs/research\_reports/RRA500/RRA532-1/RAND\_RRA532-1.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.rand.org%2Fcontent%2Fdam%2Frand%2Fpubs%2Fresearch_reports%2FRRA500%2FRRA532-1%2FRAND_RRA532-1.pdf)
50. Multi-criteria risk classification to enhance complex supply networks performance - PMC, [https://pmc.ncbi.nlm.nih.gov/articles/PMC8561686/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpmc.ncbi.nlm.nih.gov%2Farticles%2FPMC8561686%2F)
51. Risk assessment of maritime container shipping blockchain-integrated systems: An analysis of multi-event scenarios | Request PDF - ResearchGate, [https://www.researchgate.net/publication/360935055\_Risk\_assessment\_of\_maritime\_container\_shipping\_blockchain-integrated\_systems\_An\_analysis\_of\_multi-event\_scenarios](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F360935055_Risk_assessment_of_maritime_container_shipping_blockchain-integrated_systems_An_analysis_of_multi-event_scenarios)
52. Blockchain based cyber supply chain provenance, [https://ws.engr.illinois.edu/sitemanager/getfile.asp?id=3163](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fws.engr.illinois.edu%2Fsitemanager%2Fgetfile.asp%3Fid%3D3163)
53. Third-Party Risk in 2026: The Hidden Cyber Threat - SureCloud, [https://www.surecloud.com/blog-hub/third-party-risk-cybersecurity-2026](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.surecloud.com%2Fblog-hub%2Fthird-party-risk-cybersecurity-2026)
54. NCSC Supply Chain Risk <https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies>
55. &#x20;MDB Fast time comms paper \[xxxxx]&#x20;
56. UK Energy Cyber attacks. \[xxxxxxx]&#x20;
57. Practise Based Research <https://www.creativityandcognition.com/wp-content/uploads/2011/04/PBR-Guide-1.1-2006.pdf>
58. CTAG [https://www.ctag.gov.uk](https://www.ctag.gov.uk/)
59. &#x20;NLAWARP [https://www.nlawarp.net](https://www.nlawarp.net/)
60. NFCC WARP: <https://nfcc.org.uk/our-services/ddat/>
61. Socitm Supply Cain Risk: <https://socitm.net/resource-hub/webinars/260513-gca-hardware-market-volatility/>
62. [https://www.essexdigitalpartnership.org.uk](https://www.essexdigitalpartnership.org.uk/)
63. NCSC CAF: <https://www.ncsc.gov.uk/collection/cyber-assessment-framework>
64. <https://www.gov.uk/government/publications/supplier-code-of-conduct/supplier-code-of-conduct-html>
65. Vulnerability Disclosure Policy: <https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit>
66. LACES: <https://hstalks.com/article/10273/a-holistic-approach-to-cyber-security-in-local-gov/>
67. <https://www.localdigital.gov.uk/cyber/defend-as-one/>

&#x20;


# AI Note Taking Assistance - Security Considerations

Security, Assurance, and Governance Framework for AI Meeting Assistants in the UK Public Sector

&#x20;

{% file src="/files/hcg1gyfCOfld8OmNmCkq" %}

Version: 01 Initial Draft for Comment

Date:       27<sup>th</sup> July 2026

&#x20;

**This is an incomplete initial Draft guidance note please suggest additional contents required.**&#x20;

&#x20;

&#x20;

## Background&#x20;

&#x20;

The rapid integration of artificial intelligence (AI) meeting assistants across public sector organisations in the United Kingdom has created a complex intersection of productivity benefits and severe information security, assurance, and governance vulnerabilities.\[1, 2] Tools such as Otter.ai, Fireflies.ai, and Read.ai utilise automated software bots that automatically connect to synchronized calendars, join virtual meetings, record audio, transcribe conversations, and generate summaries using cloud-hosted large language models (LLMs).\[2, 3, 4]

&#x20;

While the productivity gains are documented—highlighted by a landmark UK government trial involving 20,000 civil servants across 50 departments where generative AI tools (such as Microsoft 365 Copilot) saved users an average of 26 minutes per day, equating to nearly two working weeks per person annually—the unmanaged deployment of these technologies introduces acute security risks.\[5, 6, 7]&#x20;

&#x20;

This organic, employee-led adoption occurs primarily as "Shadow AI," where staff authorize third-party calendar integrations or install browser extensions without corporate procurement, IT approval, or Data Protection Officer (DPO) oversight.\[2] Consequently, highly sensitive, legally privileged, or protected public sector data is exfiltrated to external infrastructures, raising critical questions regarding data sovereignty, legal compliance, and network integrity.\[1, 2, 4]

&#x20;

&#x20;

Technical Mechanisms and Information Assurance Vulnerabilities

&#x20;

The architectural design of third-party AI meeting assistants fundamentally alters the security perimeter of virtual communications.\[4] Once authorized via a user’s calendar or invited via a meeting link, these bots act as unverified participants, capturing and streaming live media to external cloud servers.\[4, 8] This ingestion process creates several primary technical and assurance vulnerabilities:

* Creation of an External Corporate Memory: Spoken conversations regarding policy formulation, legal strategies, financial budgets, and personal health data are converted into highly structured, indexable, and searchable text databases hosted on servers outside the control of the hosting public body.\[4] While raw audio files are computationally difficult to exploit at scale, structured text transcripts make it trivial for threat actors to identify strategic vulnerabilities, internal conflicts, or sensitive administrative plans if the third-party provider suffers a data breach.\[4]

&#x20;

&#x20;

* Agentic AI System Exposure:  Many contemporary meeting tools are evolving into agentic AI systems that possess autonomous capabilities, such as scanning user calendars, reading corporate directories, sending automated summaries, and executing API-driven workflows across connected business applications.\[9, 10, 11] If these agents are granted over-privileged access or interact with compromised external networks, a single point of failure can lead to cascading security incidents, such as unauthorized data manipulation or lateral movement within public sector tenants.\[9]

&#x20;

* Input Validation and Infrastructure Gaps: Unvetted meeting bots often bypass strict software risk assessments (SRAs), operating with default, insecure configurations.\[1, 12] The NCSC highlights that organizations deploying unverified AI capabilities remain vulnerable to prompt injection attacks, where malicious instructions embedded in a participant's shared screen or chat messages are processed by the AI bot, causing unexpected behaviours or data exposure.\[12]

&#x20;

* NHS\_mail and Shared Tenancy Risks: In shared cloud environments such as the NHS, where there are over 1.2 million active users on NHS\_mail, improper configuration of video-conferencing files can have massive consequences.\[13] For instance, if the privacy settings of a Microsoft Teams recording or transcript are changed from "Private" to "Public," the content immediately becomes accessible and editable to all NHSmail users, illustrating how easily automated outputs can scale human errors.\[13]

&#x20;

UK Legal, Data Protection, and Regulatory Landscape

&#x20;

Public sector organizations must operate in strict compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA), and the Data (Use and Access) Act (DUAA).\[14, 15, 16, 17] The deployment of AI meeting assistants creates distinct compliance challenges under these legislative frameworks:

&#x20;

Lawful Basis and Public Task

&#x20;

Under UK GDPR Article 6, public bodies typically process personal data under the lawful basis of "public task" to fulfil their statutory duties.\[16, 18] Relying on an AI tool to transcribe a meeting does not require a new lawful basis if the underlying purpose of the processing remains unchanged.\[16] However, a separate lawful basis is required if the data is shared with the AI vendor for secondary purposes, such as product improvement or model training.\[16] Because many consumer-grade platforms reserve the contractual right to utilize customer transcripts to train their foundation models, public sector bodies are frequently in violation of UK GDPR when deploying unassured tools.\[1, 2, 19]

&#x20;

The Data (Use and Access) Act

&#x20;

The Data (Use and Access) Act 2025 (DUAA)\* reshapes how automated decision-making (ADM) and profiling are handled.\[15, 20] While the Act stream-lines legitimate interests and reduces restrictions on purely automated decisions in standard B2B contexts, these flexibilities are strictly prohibited when processing "special category" data, such as health, racial origin, or biometric information.\[15, 20] Because meeting discussions in public sectors (especially within the NHS, local authorities, or law enforcement) routinely touch upon special category details, any ADM or profiling driven by AI meeting transcripts remains subject to rigorous Article 22 restrictions, requiring human oversight, the right to contest decisions, and clear explanations of the logic involved.\[15, 16, 21]

&#x20;

\*(<https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/>)

&#x20;

Biometric Data and Voiceprints

&#x20;

Advanced speech diarisation models analyse vocal characteristics—such as pitch, tone, and pacing—to attribute spoken text to specific individuals.\[21, 22] When these voice characteristics are processed to identify an individual, they constitute biometric data.\[21] Under UK GDPR and international frameworks, the creation and storage of "voiceprints" require explicit, written consent.\[21] The unauthorized generation of voiceprints by AI meeting bots has triggered substantial class action litigation under biometric privacy acts, highlighting a severe litigation risk for organizations that allow these bots to record meetings unchecked.\[21, 23]

&#x20;

Wiretapping and Electronic Recording Laws

&#x20;

Under the post-Brexit regime, the legal requirement for consent remains a cornerstone of recording communications.\[10, 24, 25] In jurisdictions requiring all-party consent, deploying a bot that automatically records a meeting without obtaining explicit, opt-in confirmation from every single participant violates electronic recording laws, exposing the hosting organization to civil and, in severe cases, criminal liabilities.\[2, 10, 21]

&#x20;

Covert Device Capture and International Sub-processors

&#x20;

Tools like "Granola" operate on a "bot-free" model, meaning they do not join calls as visible participants.\[26] Instead, they capture the host's microphone and system audio directly via device-level drivers.\[26] While this model avoids the disruption of visible bots, it presents severe compliance hazards.\[26] Because there is no visible bot in the meeting room, other participants receive no automatic notification that recording is occurring.\[26] In many jurisdictions, such as Germany under § 201 StGB\* (violation of the confidentiality of the spoken word), covert recording of non-public spoken words carries a criminal penalty of up to three years' imprisonment.\[26] Furthermore, Granola relies on US-based sub-processors (such as Deepgram and AssemblyAI for transcription, and OpenAI and Anthropic for summaries), meaning transcripts are transferred to the United States.\[26] This triggers the requirement for a complete Transfer Impact Assessment under UK GDPR Schrems II principles to evaluate the risks of US intelligence surveillance laws.\[26]

&#x20;

\*(<https://www.gesetze-im-internet.de/englisch\\_stgb/englisch\\_stgb.html>)

&#x20;

&#x20;

Case Studies and Institutional Responses

&#x20;

Institutional audits across the UK and internationally reveal a consistent pattern of restrictive actions against unassured AI transcription services for example:

&#x20;

&#x20;

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Institution</td><td valign="top">Technical Measures Implemented</td><td valign="top">Policy and Enforcement Stance</td><td valign="top">Approved Alternatives</td></tr><tr><td valign="top">University of Oxford [8]</td><td valign="top"><p>• Blocked Single Sign-On (SSO) registrations for unapproved AI bots.</p><p>•Revoked calendar access and Teams meeting permissions.</p><p>• Restricted automation on an individual app-by-app basis.</p></td><td valign="top"><p>•Categorical ban on unapproved Teams meeting bots.</p><p>• Mandatory security assessments required before any enablement.</p><p>•Explicit warning that Otter.ai is not approved for personal data.</p></td><td valign="top">•Corporately managed, paid version of Microsoft 365 Copilot.</td></tr><tr><td valign="top">Bournemouth University [11]</td><td valign="top"><p>• Configured Teams to prevent unapproved bots from joining automatically.</p><p>• Enforced the disablement of auto-join and calendar sync on personal tools.</p></td><td valign="top"><p>• Compulsory IT team assessment required before using any assistant.</p><p>• Mandatory policy to decline proceeding with meetings if an external bot is active.</p></td><td valign="top">• None; cases evaluated individually by IT Services.</td></tr><tr><td valign="top">Loughborough University [1]</td><td valign="top"><p>• Multi-stage Software Risk Assessment (SRA) process.</p><p>• Mandatory Data Protection Impact Assessment (DPIA) if sharing personal data.</p></td><td valign="top"><p>• Formal prohibition of unvetted external transcription platforms.</p><p>• Compulsory review of vendor data-sharing and model-training clauses.</p></td><td valign="top">• Native Microsoft Teams and Microsoft Word transcription features.</td></tr><tr><td valign="top">US Universities(Washington, Chapman, UC Riverside) [23]</td><td valign="top"><p>• Blocked Read AI, Otter.ai, and other non-native bots at the tenant level</p><p>• Restricting all non-native bots across their video conferencing estates.</p></td><td valign="top">• Strict institutional bans due to data privacy and corporate copyright risks.</td><td valign="top">• Platform-native enterprise transcription tools.</td></tr></tbody></table>

&#x20;

&#x20;

&#x20;

&#x20;

In the legal and corporate domain, the class action lawsuit *Brewer v. Otter.ai* (consolidated in the Northern District of California) serves as a benchmark.\[2, 10, 23] The plaintiff, a non-user of Otter, alleged that the platform recorded, transcribed, and analysed his private conversations without his knowledge or consent when he attended meetings hosted by Otter users.\[2, 10] The complaint asserts that Otter routinely ingested these private conversations to train its machine learning and speech-recognition models, violating wiretapping statutes and consumer protection laws.\[2, 10, 27]

&#x20;

In clinical and healthcare settings, the reliability of AI transcription is of paramount concern.\[1, 2, 28] A comparative study on the clinical accuracy of LLM-generated medical documentation evaluated transcription error rates across prominent models:

&#x20;

&#x20;

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Platform / Model</td><td valign="top">Total Word Error Rate (% of Target Words)</td><td valign="top">Misattributed Speaker Word Error Rate (%)</td><td valign="top">Operational and Clinical Implications</td></tr><tr><td valign="top">NotebookLM[28]</td><td valign="top">4.0%</td><td valign="top">3.6%</td><td valign="top">Lowest overall error rate; demonstrates superior contextual language processing.</td></tr><tr><td valign="top">AssemblyAI[28]</td><td valign="top">10.4%</td><td valign="top">1.4%</td><td valign="top">Lowest speaker misattribution rate; highly effective for multi-speaker diarisation.</td></tr><tr><td valign="top">Otter.ai [28]</td><td valign="top">18.5%</td><td valign="top">8.9%</td><td valign="top">Highest error rates; significant risk of medical terminology errors and incorrect speaker turn-taking.</td></tr></tbody></table>

&#x20;

&#x20;

These clinical findings indicate that even modest transcription errors can distort patient documentation, introduce dangerous medical terminology hallucinations, and lead to incorrect clinical decisions, underscoring why fully autonomous note generation remains unsafe for clinical deployment.\[1, 2, 28]

&#x20;

Public Sector Assurance Frameworks and Guidelines

&#x20;

The UK Government Digital Service (GDS) and the Department for Science, Innovation and Technology (DSIT) have established clear guardrails under the "AI Playbook for the UK Government," which updates and expands upon the 2024 Generative AI Framework.\[29, 30, 31] The playbook defines ten core principles to guide the safe, responsible, and effective deployment of AI in government \[29, 32]:

&#x20;

&#x20;

&#x20;

&#x20;

* Principle 1: You know what AI is and what its limitations are.\[29, 32] Public bodies must recognize that generative AI systems lack reasoning and contextual awareness, frequently introducing inaccuracies, biases, and hallucinations.\[29, 32]
* Principle 2: You use AI lawfully, ethically and responsibly.\[29, 32] AI applications must align with the Civil Service Code and data protection legislation, ensuring that diverse participation is built into the project lifecycle.\[29, 32, 33]
* Principle 3: You know how to use AI securely.\[29, 32] Organizations must enforce strict information security protocols to prevent data leakage and privacy violations.\[12]
* Principle 4: You have meaningful human control at the right stages.\[29, 32] Fully autonomous AI operations that lead to irreversible actions (such as altering records or sending communications) are strictly prohibited; human verification is mandatory.\[12]
* Principle 5: You understand how to manage the full AI life cycle.\[29, 32] Public sector entities must maintain end-to-end traceability, asset management, and secure decommissioning of AI models.\[34]

These national standards are supported by the NCSC's Agentic AI security guidance, which warns that the autonomy and complexity of agentic systems make them particularly prone to unpredictable behaviour and over-privileged access.\[9] The NCSC advises public sector bodies to apply the principle of least privilege, restrict agent capabilities to tightly bounded pilots, avoid long-lived credentials, and establish robust kill-switch mechanisms.\[9]

&#x20;

Furthermore, public sector bodies must align with the international ETSI EN 304 223 standard for AI cybersecurity, which establishes a technical baseline for securing AI data supply chains, managing model dependencies, and mitigating model drift and prompt injection risks.\[9, 14, 34]

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

Corporately Assured Implementations

&#x20;

To reconcile the demand for productivity with strict security requirements, the UK public sector has pursued two parallel, assured deployment tracks:

* The i.AI "Minute" Tool: Developed by the Cabinet Office’s Incubator for AI (i.AI), "Minute" is a custom-built, secure meeting transcription, minuting, and summarization tool deployed within the government’s secure network boundaries.\[7, 35] It eliminates external cloud exposure and ensures that government discussions remain protected under public sector sovereignty.\[7, 35]

&#x20;

* ICO's Secure Microsoft 365 Copilot Deployment: The Information Commissioner's Office (ICO) utilizes Microsoft 365 Copilot for summarizing Teams meetings, transcripts, and emails under the lawful basis of "public task".\[18] To maintain compliance, the ICO enforces strict technical safeguards: all processed data remains within the ICO's secure UK Microsoft 365 and Azure tenants, ensuring that customer data is never utilized to train external foundation models.\[18] Furthermore, audio recordings and generated transcripts are subjected to a mandatory auto-deletion policy after 21 days, and all outputs are verified by human operators to mitigate hallucinations.\[18]

&#x20;

&#x20;

Technical Hardening of Virtual Meeting Platforms

&#x20;

To defend public sector communications against unauthorised AI bots, IT administrators must implement rigorous technical hardening across Microsoft Teams, Zoom, and Google Meet.\[3, 36, 37]

&#x20;

Microsoft Teams Hardening

&#x20;

Microsoft Teams features native admin controls to intercept and block external bots before they enter a live session.\[3, 23] Under Microsoft Message Centre notice MC1251206\*, Teams automatically flags external third-party bots as "Unverified" in the meeting lobby, requiring explicit organiser approval.\[23] To achieve absolute protection, administrators should configure the ExternalBotAccessMode attribute, which is managed via the Teams Admin Centre (TAC) or PowerShell \[3]:

&#x20;

\*(<https://mc.merill.net/message/MC1251206>)

* Open the Teams Admin Center and navigate to *Meetings -> Meeting Policies*.
* Locate the Meeting Join & Lobby section.
* Under Manage external bots and their access to meetings, select the appropriate policy:
* AllowAllBots: Admits all third-party bots without restriction.\[3]
* RequireApprovalWhenDetected: Sends detected bots to the lobby, where they await host admission (Default).\[3]
* BlockDetectedBots: Automatically turns unapproved bots away at the door, preventing them from entering the lobby or the meeting.\[3]

Administrators can enforce this globally or target specific user groups using the PowerShell cmdlet \[3]:

Set-CsTeamsMeetingPolicy -Identity "Global" -ExternalBotAccessMode BlockDetectedBots

&#x20;

This configuration ensures that standard guest access remains open to human participants, while uninvited third-party bots (such as Otter or Fireflies) are blocked.\[3] Additionally, Teams default transcript retention should be audited; transcripts are stored in the host's OneDrive (for ad-hoc meetings) or the channel’s SharePoint folder (for channel meetings), with a default expiration period of 60 days that should be adjusted to align with organizational data retention policies.\[1]

&#x20;

Zoom Hardening

&#x20;

To prevent unapproved bots from accessing Zoom meetings, administrators must implement multi-layered domain and application blocks.\[36, 38, 39]

&#x20;

&#x20;

Domain-Level Blocking

&#x20;

Administrators can configure domain blocks via the Zoom Admin Portal \[36, 38]:

* Navigate to *Account Management -> Account Settings -> Meeting*.
* Under Security, locate the setting Block users in specific domains from joining meetings and webinars and toggle it to On.\[36, 38]
* Click the edit icon and input known AI bot domains, separated by commas: otter.ai, read.ai, fireflies.ai, meetgeek.com, fathom.video.\[36, 38]
* Save the changes to apply the block across all scheduled and ad-hoc meetings.\[36, 38]

App Marketplace Restricting

&#x20;

To prevent internal employees from authorizing integrations that bypass domain blocks, administrators must restrict the Zoom App Marketplace \[39]:

* Sign in as an administrator at marketplace.zoom.us.\[39]
* Click Manage in the upper-right corner and select Admin App Management -> Apps on Account.\[39]
* Locate third-party transcription apps (such as Otter.ai) and click Disable or Remove.\[39]
* Navigate to Admin App Management -> Permissions and disable App Requests.\[39] This forces all application installations to undergo administrator review, preventing users from authorizing automatic calendar syncs with external services.\[39]

In-Meeting Safeguards

Hosts should be trained to apply immediate in-meeting controls \[38]:

* Enable the Waiting Room feature to manually verify and admit every participant.\[38]
* Toggle on Only authenticated meeting participants can join, which forces attendees to sign in via verified Zoom accounts, blocking anonymous bot connections.\[38]
* Once all expected human participants have joined, click the Security icon and select Lock Meeting to prevent late-arriving bots from entering.\[38]

*Note on Zoom AI Companion:* Unlike third-party bots, the native Zoom AI Companion is integrated directly into the Zoom platform.\[23] Zoom’s terms of service guarantee that customer meeting content is not utilized to train its AI models without explicit, opt-in host consent, offering a compliant native alternative if authorized by the organization’s DPO.\[23]

&#x20;

&#x20;

Google Meet Hardening

&#x20;

Google’s 2026 security screening update implements a risk-based classification model that automatically routes unverified external bots, anonymous joiners, and unfamiliar connection patterns into a high-risk queue.\[40] These entities are flagged with a red "potential risk" warning banner in the lobby.\[40] To secure Google Meet environments, administrators and hosts must apply both console and in-meeting configurations \[40, 41, 42]:

* Host Access Control and Knocking Disablement: During meeting scheduling in Google Calendar or inside an active session, hosts should access Host Controls and navigate to Meeting Access.\[43] Choose the Restrictedaccess level (available for Workspace enterprise editions) and uncheck the box next to Anyone can ask to join.\[43] This action disables "knocking" for the entire meeting.\[43] Any anonymous user or external third-party bot attempting to join via "Ask to join" is automatically denied entry without requiring manual host rejection.\[40, 43]
* Google Admin Console Hardening: IT administrators must enforce domain-level restrictions by logging into the Google Admin Console and navigating to *Menu -> Apps -> Google Workspace -> Google Meet -> Meet Safety Settings*.\[41, 42] Under Incoming Call Restrictions, set the switch to Only contacts & in-domain users.\[41, 42] This prevents external Google accounts or automated dialers from directly calling internal users, severely restricting the lateral join path utilized by calendar-scraping bots.\[40, 41]

&#x20;

Suggested Actions and Governance Framework

&#x20;

To establish a comprehensive posture against the threat of unassured AI meeting assistants, UK public sector organizations should implement a multi-tiered governance framework.\[1, 2, 10]

&#x20;

Phase 1: Policy Formulation and Acceptable Use

Public sector bodies must draft and publish clear internal policies defining which recording and transcription services are authorized and the conditions under which they may operate.\[10]

* Mandatory SRA and DPIA: No transcription tool should be deployed without completing a Software Risk Assessment (SRA) to verify alignment with Cyber Essentials requirements, and a Data Protection Impact Assessment (DPIA) to evaluate privacy risks.\[1]
* Contractual Verification: Organizations must verify that vendor contracts include explicit "no training" commitments, ensuring that public data is never utilized to improve external models.\[16, 19, 44]
* Mandatory Human-in-the-Loop: Policy must mandate that all AI-generated meeting notes and transcripts undergo human verification for accuracy before being saved or distributed, mitigating the risks of transcription errors and hallucinations.\[1, 2, 18]

Phase 2: Technical Enforcement and App Blocking

IT departments must execute domain blocks and SSO restrictions to eliminate the use of unassured consumer-grade tools.\[8, 39]

* SSO Access Revocation: Disable the ability for employees to sign up or log into services like Otter.ai, Read AI, or Fireflies.ai using their corporate Google Workspace or Microsoft Entra ID credentials.\[8]
* Active Endpoint and Network Scanning: Deploy network monitoring and endpoint controls to identify unauthorized browser extensions, local device capture tools (such as Granola), or active API connections to unapproved AI domains.\[2, 45]
* Tenant-Level Blocking: Enforce the platform-specific hardening steps outlined below to ensure that uninvited bots are turned away at the door.\[3, 36, 43]

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Platform</td><td valign="top">Recommended Administrative Configuration</td><td valign="top">Technical Verification Method</td></tr><tr><td valign="top">Microsoft Teams</td><td valign="top"><p>• Set ExternalBotAccessModeto BlockDetectedBots.[3]</p><p>• Configure standard transcript retention to 21 days or less.[18]</p></td><td valign="top">• Execute PowerShell: Get-CsTeamsMeetingPolicy | Select Identity, ExternalBotAccessMode.[3]</td></tr><tr><td valign="top">Zoom</td><td valign="top"><p>• Enforce manual domain blocklist for otter.ai, read.ai, fireflies.ai.[36, 38]</p><p>• Disable unapproved integrations in Zoom App Marketplace.[39]</p></td><td valign="top">• Audit marketplace logs at marketplace.zoom.usfor unauthorized user installs.[39]</td></tr><tr><td valign="top">Google Meet</td><td valign="top"><p>• Enforce Restricted meeting access and disable external knocking.[43]</p><p>• Set Incoming Call Restrictions to "Only contacts &#x26; in-domain".[41]</p></td><td valign="top">• Verify Workspace Admin Console under <em>Meet Safety Settings</em>.[41, 42]</td></tr></tbody></table>

&#x20;

&#x20;

Phase 3: Employee Training and External Engagement Rules

Public sector employees must be trained to recognize and handle AI bots, particularly when participating in external meetings hosted by third parties.\[11, 12, 24]

* Lobby Verification: Meeting hosts must verify the identity of all attendees in the lobby before granting entry, stating clearly at the start of the call that the use of third-party AI transcription tools is prohibited.\[12, 46]
* Declining External Bot Participation: If an employee joins an external meeting and observes an active third-party AI bot, they should politely request its deactivation.\[11] Bournemouth University suggests the following standard phrasing:
* Enforcing Incident Reporting: If an unapproved AI bot silently joins a meeting or distributes an unauthorised summary containing sensitive public data, employees must report the incident to their DPO as a potential personal data breach under UK GDPR.\[8, 11]

<br>

&#x20;

Bibliography

1. 2026 | Data protection, information security and data privacy ..., [https://www.lboro.ac.uk/data-privacy/announcements/listing/2026/news---26-02-06---ai-transcription-tools-a-time-saver-or-security-risk.html](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.lboro.ac.uk%2Fdata-privacy%2Fannouncements%2Flisting%2F2026%2Fnews---26-02-06---ai-transcription-tools-a-time-saver-or-security-risk.html)
2. AI Ethical Breaches: The Risks of Inviting AI into your Meeting Room - DPEX Network, [https://www.dpexnetwork.org/articles/ai-ethical-breaches-the-risks-of-inviting-ai-into-your-meeting-room](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.dpexnetwork.org%2Farticles%2Fai-ethical-breaches-the-risks-of-inviting-ai-into-your-meeting-room)
3. Teams to Block External AI Bots - UC Today, [https://www.uctoday.com/unified-communications/microsoft-teams-to-block-external-bots-automatically-as-ai-notetaker-crackdown-hardens/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.uctoday.com%2Funified-communications%2Fmicrosoft-teams-to-block-external-bots-automatically-as-ai-notetaker-crackdown-hardens%2F)
4. Your AI Meeting Assistant Might Be the Biggest Security Risk in Your Office | by Len Noe, [https://medium.com/@len213noe/your-ai-meeting-assistant-might-be-the-biggest-security-risk-in-your-office-4cf7c2f63edf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmedium.com%2F%40len213noe%2Fyour-ai-meeting-assistant-might-be-the-biggest-security-risk-in-your-office-4cf7c2f63edf)
5. Landmark government trial shows AI could save civil servants nearly 2 weeks a year, [https://www.gov.uk/government/news/landmark-government-trial-shows-ai-could-save-civil-servants-nearly-2-weeks-a-year](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fnews%2Flandmark-government-trial-shows-ai-could-save-civil-servants-nearly-2-weeks-a-year)
6. UK Public Sector AI Case Studies - Cube8, [https://www.cube8.co.uk/case-studies.php](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.cube8.co.uk%2Fcase-studies.php)
7. AI in UK government departments - UK Parliament, [https://researchbriefings.files.parliament.uk/documents/CBP-10236/CBP-10236.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fresearchbriefings.files.parliament.uk%2Fdocuments%2FCBP-10236%2FCBP-10236.pdf)
8. Are your online meetings safe from third party AI bots? | Information ..., [https://www.infosec.ox.ac.uk/article/are-your-online-meetings-safe-from-third-party-ai-bots](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.infosec.ox.ac.uk%2Farticle%2Fare-your-online-meetings-safe-from-third-party-ai-bots)
9. NCSC Publishes Guidance on Securing Agentic AI Use - Infosecurity Magazine, [https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-securing/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.infosecurity-magazine.com%2Fnews%2Fncsc-publishes-guidance-securing%2F)
10. AI Note-Takers at Work: The Silent Threat to Privacy and ..., [https://www.socialeurope.eu/ai-note-takers-at-work-the-silent-threat-to-privacy-and-compliance](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.socialeurope.eu%2Fai-note-takers-at-work-the-silent-threat-to-privacy-and-compliance)
11. Use of AI meeting assistants at BU | Bournemouth University, [https://www.bournemouth.ac.uk/news/2025-07-07/use-ai-meeting-assistants-bu](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.bournemouth.ac.uk%2Fnews%2F2025-07-07%2Fuse-ai-meeting-assistants-bu)
12. Security and risks - AI Knowledge Hub, [https://ai.gov.uk/knowledge-hub/how-to/security](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fai.gov.uk%2Fknowledge-hub%2Fhow-to%2Fsecurity)
13. Using video conferencing and consultation tools guidance for IG professionals - NHS Digital, [https://digital.nhs.uk/data-and-information/information-governance/guidance/using-video-conferencing-and-consultation-tools/guidance-for-ig-professionals](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdigital.nhs.uk%2Fdata-and-information%2Finformation-governance%2Fguidance%2Fusing-video-conferencing-and-consultation-tools%2Fguidance-for-ig-professionals)
14. AI Security in the UK: The Cost of Getting It Wrong in 2026 - Appinventiv, [https://appinventiv.com/blog/ai-security-in-uk/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fappinventiv.com%2Fblog%2Fai-security-in-uk%2F)
15. Recent UK legal and regulatory developments on AI and automated decision-making, [https://www.kennedyslaw.com/en/thought-leadership/article/recent-uk-legal-and-regulatory-developments-on-ai-and-automated-decision-making/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.kennedyslaw.com%2Fen%2Fthought-leadership%2Farticle%2Frecent-uk-legal-and-regulatory-developments-on-ai-and-automated-decision-making%2F)
16. AI Note Taking Tools and GDPR: Do You Need a New Lawful Basis? - Measured Collective, [https://measuredcollective.com/ai-note-taking-tools-and-gdpr-do-you-need-a-new-lawful-basis/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmeasuredcollective.com%2Fai-note-taking-tools-and-gdpr-do-you-need-a-new-lawful-basis%2F)
17. How do I work from home securely? | ICO - Information Commissioner's Office, [https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/working-from-home/how-do-i-work-from-home-securely/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fico.org.uk%2Ffor-organisations%2Fuk-gdpr-guidance-and-resources%2Fsecurity%2Fworking-from-home%2Fhow-do-i-work-from-home-securely%2F)
18. Microsoft 365 Copilot | ICO - Information Commissioner's Office, [https://ico.org.uk/global/privacy-notice/microsoft-365-copilot/?search=recording](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fico.org.uk%2Fglobal%2Fprivacy-notice%2Fmicrosoft-365-copilot%2F%3Fsearch%3Drecording)
19. Avoid These Security and Compliance Traps When Implementing a Notetaker - Read AI, [https://www.read.ai/articles/avoid-these-security-and-compliance-traps-when-implementing-a-notetaker](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.read.ai%2Farticles%2Favoid-these-security-and-compliance-traps-when-implementing-a-notetaker)
20. AI marketing in the UK: 2026 guide to trends, tools & regulations, [https://uk.cyberclick.net/digital-growth-playbook/ai-marketing-in-the-uk-guide-to-trends-tools-regulations](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fuk.cyberclick.net%2Fdigital-growth-playbook%2Fai-marketing-in-the-uk-guide-to-trends-tools-regulations)
21. AI Transcription Tools Under Scrutiny: Navigating Privacy Risks and Practical Mitigation Strategies | Insights & Resources | Goodwin, [https://www.goodwinlaw.com/en/insights/publications/2026/04/alerts-practices-dpc-ai-transcription-tools-under-scrutiny](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.goodwinlaw.com%2Fen%2Finsights%2Fpublications%2F2026%2F04%2Falerts-practices-dpc-ai-transcription-tools-under-scrutiny)
22. AI Meeting Assistant Development Services | Neurotrack UK, [https://neurotrack.uk/ai-meeting-assistant-development/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fneurotrack.uk%2Fai-meeting-assistant-development%2F)
23. Microsoft, Zoom and Google Tighten Meeting Bot Controls as Otter Case Nears Hearing, [https://www.uctoday.com/security-compliance-risk/ai-meeting-bots-controls-microsoft-zoom-google/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.uctoday.com%2Fsecurity-compliance-risk%2Fai-meeting-bots-controls-microsoft-zoom-google%2F)
24. The rise of video conferencing – what the ICO And NCSC want you to watch out for, [https://kempitlaw.com/insights/the-rise-of-video-conferencing-what-the-ico-and-ncsc-want-you-to-watch-out-for/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fkempitlaw.com%2Finsights%2Fthe-rise-of-video-conferencing-what-the-ico-and-ncsc-want-you-to-watch-out-for%2F)
25. AI in Client Meetings: Helpful Assistant or Hidden Ethical Risk? - North Carolina Bar Association, [https://www.ncbar.org/2026/01/30/ai-in-client-meetings-helpful-assistant-or-hidden-ethical-risk/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.ncbar.org%2F2026%2F01%2F30%2Fai-in-client-meetings-helpful-assistant-or-hidden-ethical-risk%2F)
26. Granola Alternative: the GDPR Comparison - Sally AI, [https://www.sally.io/blog/granola-alternative](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.sally.io%2Fblog%2Fgranola-alternative)
27. AI notetakers: Legal privilege & data protection risks - Browne Jacobson LLP, [https://www.brownejacobson.com/insights/otter-chaos-issues-with-using-ai-notetakers](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.brownejacobson.com%2Finsights%2Fotter-chaos-issues-with-using-ai-notetakers)
28. Accuracy of large language model transcription of simulated physician-patient verbal interactions - PMC, [https://pmc.ncbi.nlm.nih.gov/articles/PMC13088782/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpmc.ncbi.nlm.nih.gov%2Farticles%2FPMC13088782%2F)
29. Artificial Intelligence Playbook for the UK Government - GOV.UK, [https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI\_Playbook\_for\_the\_UK\_Government\_\_12\_02\_.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fassets.publishing.service.gov.uk%2Fmedia%2F67aca2f7e400ae62338324bd%2FAI_Playbook_for_the_UK_Government__12_02_.pdf)
30. AI Playbook for the UK Government - GOV.UK, [https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fpublications%2Fai-playbook-for-the-uk-government)
31. Artificial Intelligence Playbook for government published | Practical Law, [https://uk.practicallaw.thomsonreuters.com/w-045-8067?transitionType=Default\&contextData=(sc.Default)](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fuk.practicallaw.thomsonreuters.com%2Fw-045-8067%3FtransitionType%3DDefault%26contextData%3D\(sc.Default\))
32. Artificial Intelligence Playbook for the UK Government (HTML) - GOV.UK, [https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fpublications%2Fai-playbook-for-the-uk-government%2Fartificial-intelligence-playbook-for-the-uk-government-html)
33. Generative AI policy - GCS - Government Communication Service, [https://www.communications.gov.uk/publications/gcs-generative-ai-policy/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.communications.gov.uk%2Fpublications%2Fgcs-generative-ai-policy%2F)
34. Securing AI Adoption in the Public Sector - NCSC Ireland, [https://www.ncsc.gov.ie/pdfs/NCSC\_Secure\_AI\_Adoption\_2026.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.ncsc.gov.ie%2Fpdfs%2FNCSC_Secure_AI_Adoption_2026.pdf)
35. UK Government calling on AI 'Humphrey' to fix outdated technology - OmniCyber Security, [https://www.omnicybersecurity.com/uk-government-ai-outdated-tech/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.omnicybersecurity.com%2Fuk-government-ai-outdated-tech%2F)
36. Preventing 3rd Party AI Tools From Accessing Your Meetings, [https://it.stonybrook.edu/help/kb/preventing-3rd-party-ai-tools-your-meetings](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fit.stonybrook.edu%2Fhelp%2Fkb%2Fpreventing-3rd-party-ai-tools-your-meetings)
37. How to Block all Otter ai - Google Meet Community, [https://support.google.com/meet/thread/369917295/how-to-block-all-otter-ai?hl=en](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupport.google.com%2Fmeet%2Fthread%2F369917295%2Fhow-to-block-all-otter-ai%3Fhl%3Den)
38. How to Prevent and Remove Unapproved AI bots from Zoom Meetings - Rice University KB, [https://kb.rice.edu/149886](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fkb.rice.edu%2F149886)
39. How do I disable AI Notetakers (otter.ai, read.ai, fireflies.ai, etc.) from joining our meetings - Zoom Community, [https://community.zoom.com/meetings-2/how-do-i-disable-ai-notetakers-otter-ai-read-ai-fireflies-ai-etc-from-joining-our-meetings-17388](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fcommunity.zoom.com%2Fmeetings-2%2Fhow-do-i-disable-ai-notetakers-otter-ai-read-ai-fireflies-ai-etc-from-joining-our-meetings-17388)
40. How to prevent custom Google Meet bot from being flagged as "Potential Risk"?, [https://support.google.com/meet/thread/438497815/how-to-prevent-custom-google-meet-bot-from-being-flagged-as-potential-risk?hl=en](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupport.google.com%2Fmeet%2Fthread%2F438497815%2Fhow-to-prevent-custom-google-meet-bot-from-being-flagged-as-potential-risk%3Fhl%3Den)
41. Restrict who can call my organization's users with Google Meet, [https://knowledge.workspace.google.com/admin/meet/restrict-who-can-call-my-organizations-users-with-google-meet](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fknowledge.workspace.google.com%2Fadmin%2Fmeet%2Frestrict-who-can-call-my-organizations-users-with-google-meet)
42. Manage Meet settings (for admins) - Google Workspace Help, [https://knowledge.workspace.google.com/admin/meet/manage-meet-settings](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fknowledge.workspace.google.com%2Fadmin%2Fmeet%2Fmanage-meet-settings)
43. Tips to control meeting access and participation - Google Workspace Learning Centre, [https://support.google.com/a/users/answer/11989526?hl=en](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupport.google.com%2Fa%2Fusers%2Fanswer%2F11989526%3Fhl%3Den)
44. AI notetaker security and privacy checklist - Avoma, [https://www.avoma.com/blog/ai-notetaker-security-features](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.avoma.com%2Fblog%2Fai-notetaker-security-features)
45. Best AI Meeting Assistant for Enterprise 2026 - SOC2, HIPAA, SSO, Admin Controls, [https://summarizemeeting.com/en/faq/best-ai-meeting-assistant-for-enterprise](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsummarizemeeting.com%2Fen%2Ffaq%2Fbest-ai-meeting-assistant-for-enterprise)
46. General app guidance, [https://security-guidance.service.justice.gov.uk/general-user-video-and-messaging-apps-guidance/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsecurity-guidance.service.justice.gov.uk%2Fgeneral-user-video-and-messaging-apps-guidance%2F)

&#x20;


# Cyber Incident Response Primer

{% file src="/files/-MeUpbwgnoMd0btsQuRP" %}
Incident Primer
{% endfile %}

**Background**

Things go wrong in ICT systems, either accidentally, a wrong parameter or filename used or a deliberate act of maleficence, to cause harm to the system, such as an attack, often through the Internet which we now refer to as a Cyber Attack.

Modern computer networks and system, can be defended automatically to deal with the majority of low level attacks, where these attacks are mitigated and solved, they are referred to as events. Where an attack or event actually causes a physical outcome (System crash, malware infection etc.), that leads to an Incident. The overall monitoring systems for dealing with systems and networks is referred to as a SEIM (Security Event & Incident Monitoring) system.

**Prerequisites**

Before you can do anything, you must ensure your network have a consistent and stable network time source This is a requirement for the PSN code of Connection, as without it you cannot normalise data of correlate logfiles. The [NCSC Logging Made Easy \[14\]](https://www.ncsc.gov.uk/blog-post/logging-made-easy) will help with some of this work. The NCSC produce other I[ncident Management information](https://www.ncsc.gov.uk/section/about-ncsc/incident-management) \[15] that should be read and adhered to. You must have up to date detailed and accurate [network diagrams](http://networkdiagram101.com/) \[16] and systems documentation. There are plenty of [drawing tools](https://www.lucidchart.com/blog/network-diagramming-best-practices) to help you do so \[17]. Without neither you or an external Network response company will be able to help you, valuable time and resources will be wasted. The NCSC has a scheme [(Certified Incident Response CIR)](https://www.ncsc.gov.uk/information/cir-cyber-incident-response) and list of trusted companies that can help \[18]. The Scottish Government has also published a [Cyber Resilience and Response Guide](https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-guidance/documents/cyber-resilience-resource-toolkit/cyber-resilience-resource-toolkit/govscot%3Adocument/Cyber%2BResilience%2BResource%2BToolkit.pdf) \[19]. There is also a Scottish Government [Cyber Playbook](https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-incident-management/documents/cyber-incident-response-denial-of-service-playbook/cyber-incident-response-denial-of-service-playbook/govscot%3Adocument/Cyber%2BCapability%2BToolkit%2B-%2BCyber%2BIncident%2BResponse%2B-%2BDenial%2Bof%2BService%2BPlaybook%2Bv2.3.pdf) that can be downloaded and customised \[20]. Asset registers are critical to success and will be the subject of a future C-TAG guide.

!\[A close up of a newspaper

Description automatically generated]\(/files/-MeUnacB0GxN-xGMEANT)

**Defining Incident Response**

We’ve discussed events and what leads to an incident. When an incident happens, the first thing that needs to happened is to actually be aware of the attack. Some attacks can go undetected for months. This is why we ensure that systems are secure by design, this is the who purpose of Information Assurance and Risk Management. The only objective of Incident Response is to get to the make safe point, where the unwanted systems / network behaviour is stopped in its tracks. Once at make safe, the next and longer phase is Incident Recovery. The objective of the recovery phase itself is to get the system / network back to a stable state, that is how the network or system was at the point the incident happened. Incident recovery is not about improvement. Both Incident response and Incident recovery have clearly defined boundaries.

An incident can be thought of as a fast time resource intensive project. and if thought of as such, with a start, middle and end it becomes far easier to know when and incident is concluded. Open ended Incidents are not good practice and allow non-incident related issues to be introduced, causing complications and additional complexities.

**Where to start?**

**Planning**

There is an ISO standard for Incident response [ISO 27035](https://www.iso27001security.com/html/27035.html) \[1] as with all standards, it details an approach and linked nicely with ISO 27001, ISO 27035 with it’s five stage approach;

1. **Plan and prepare:** establish an information security incident management policy, form an **I**ncident **R**esponse **T**eam *etc.*
2. **Detection and reporting:** someone has to spot and report “events” that might be or turn into incidents;
3. **Assessment and decision:** someone must assess the situation to determine whether it is in fact an incident;
4. **Responses:** contain, eradicate, recover from and forensically analyze the incident, where appropriate;
5. **Lessons learnt:** make systematic improvements to the organization’s management of information risks as a consequence of incidents experienced.

!\[A close up of a logo

Description automatically generated]\(/files/-MeUnacCDhwA4wsIwwY4)

Source: [Ref \[22\]](https://reader.elsevier.com/reader/sd/pii/S0022000014000178?token=72CB49E33BA036F64029D966A5BC2CB02456594BD3A5B09EAFC789998EFCCD71706931C52714D11AC8F73B72855E8798)

The figure above shows the types of attack vectors, how the malicious code / data gets into the network / system.

There's also the American NIST Incident handling guide \[2] [NIST SP800-61 revision 2](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf). This dates back to 2012, but does contain a lot of useful advice and guidance. For specific cloud related guidance the Cloud Security Alliance has an [incident response guide](https://cloudsecurityalliance.org/research/working-groups/cloud-incident-response/) \[26].

The NIST approach discusses;

* Preparation (Planning)
* Detection and Analysis (Response)
* Containment (Make safe)
* Post-incident action (Recovery)

The Erez Dasa table above shows how these can map across to technologies in the cloud.

!\[A screenshot of a cell phone

Description automatically generated]\(/files/-MeUnacD9jRZOp17AJw1)

Source: [Ref \[22\]](https://reader.elsevier.com/reader/sd/pii/S0022000014000178?token=72CB49E33BA036F64029D966A5BC2CB02456594BD3A5B09EAFC789998EFCCD71706931C52714D11AC8F73B72855E8798)

Some very good examples of incident playbook (think of plans or recipes as we’re in a cook book), can be found [here \[3\]](https://www.incidentresponse.com/playbooks/) the approach is very good. Whilst Forensics are out of scope for this paper, there is an excellent primer and source of information from SANS to be found [here \[4\]](https://www.giac.org/paper/gcfa/283/forensic-investigation-plan-cookbook/108356). Sans also produces an incident handlers guide that can be found [here \[5\].](https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901)

**Exercising**

We have discussed exercising, the MHCLG [Pathfinder programme](https://www.local.gov.uk/cyber-pathfinder-training-scheme) delivered a number of Cyber Exercises \[6]. The NCSC have produced the [Exercise in a box](https://www.ncsc.gov.uk/information/exercise-in-a-box) suite, that can be freely downloaded and contains all of the materials needed to plan and run a successful cyber exercise \[7]. For really in depth guidance the [Mitre Exercise planning guide](https://www.mitre.org/sites/default/files/publications/pr_14-3929-cyber-exercise-playbook.pdf) is a comprehensive and authoritative guide \[8].

**Responding**

Responding to Cyber incidents will always be different to what you’ve planned for. The idea of planning is more about trying to understand the decisions, line of communications and the team building experience. Plans make you think about scenarios, which can be exercised. All incidents will need resources. The FT produced a useful report [“Surviving a Cyber Incident”](https://ig.ft.com/sites/special-reports/cyber-attacks/) containing a lot of sage advice \[9]. For information, have a look at the Golden Hour Guide which is described in the [Cyber Incident Framework \[10\]](https://www.researchgate.net/publication/336400438_Cyber_Incident_Approach_Framework_for_Local_Government_-_Cyber_Incident_Approach_Framework_for_Local_Government?_sg=Taclsita6Hon2gGdDjBteXausg6PNB0yu-xqJAexI5wsTzTFqV_ZT0Wl0w9EkDrUvLjsf4ci2OTfSa-g5l88_n5GaG_iZewJT--Y_75O.0d9BAxpf-wvDoDCxlO3U5A4FJXRIcJkIWAQh9TzMa2s6I11LsfQNCzsJVctLXO6ZrzSwvHOK3FRtXA2zzej8RQ) the paper also contains a number of useful case studies and other information.

The guide also discusses the NLAWARP / Silverthorn SIRO Risk framework © , with it’s six stages, mapping

1. Identify and map out key systems / services /suppliers
2. Identifying how we get assurance for key systems services / suppliers
3. Identifying Key Information Risks (to develop Key Risk Indicators (KRIs)
4. Articulating Information Risk Statements (Risk / Threat/ Vulnerability/Exploit)

5\) Defining [Risk Appetite](https://www.ascentor.co.uk/2015/07/10-top-tips-writing-information-risk-appetite-statements/) \[25] (Taking 1-4 above identifying assurance gaps).

6\) Articulating a Risk Appetite (Using business language \[[User Stories](https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/risk-management-in-agile-projects)] \[23])

User stories are incredible powerful for Risk Management, Cyber Exercising and for testing assumptions. [Risk Poker](https://www.tmap.net/wiki/risk-poker) \[24] is another useful way to articulate the risks.

!\[A screenshot of a cell phone

Description automatically generated]\(/files/-MeUnacElLTzwdZlU5U8)

Source Isaca \[23]

!\[A screenshot of a cell phone

Description automatically generated]\(/files/-MeUnacFrGBup-leWPjA)

Source: Figure 1 above and table below; Cyber Incidents: Uma, M. and Padmavathi Ganapathi. “A Survey on Various Cyber Attacks and their Classification.” *I. J. Network Security* 15 (2013): 390-396. [Ref \[21\]](https://www.semanticscholar.org/paper/A-Survey-on-Various-Cyber-Attacks-and-their-Uma-Ganapathi/ba7b234738e80b027240e9bfd837bfba61c13e17)

!\[A screenshot of text

Description automatically generated]\(/files/-MeUnacGxk4723yzQkNQ)

**Recovering**

Do not underestimate the amount of time a Cyber attack will take to resolve. As we said earlier the incident part only goes as far as “Making Safe”, (Containment). The hard works starts with the recovery phase. It could take weeks, months or years to completely get back to normal. You need to plan for that and have that as a [“Planning Assumption”](https://www.ncsc.gov.uk/collection/board-toolkit/collaborating-with-suppliers-and-partners). The NCSC list some helpful context about planning assumptions in dealing with suppliers \[11]. You need to undertake [Horizon scanning](https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/674209/futures-toolkit-edition-1.pdf) \[12] and a Risk Assessment with a Threat analysis, the UK space Agency has produced a useful [Cyber Toolkit](https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/885869/Space_cyber_toolkit_final_v4.pdf) which explores these areas \[13]. so that you can prioritise your planning assumptions.

Procuring help to recover from an incident (NE WARP Case study)

our objectives:

* To have a ready-to-go incident response service to hand for whenever required
* To have the option of annual readiness check in terms of required documentation etc. that would be requested by an incoming response service

options:

* procure up front and have on standby
* procure at the time of need
* use CCS (Crown Commercial Services) dynamic purchasing system for cyber which includes NCSC CIR (Cyber Incident Response) providers
* conduct a local procurement

In the event of a critical incident requiring incident response it is likely emergency procurement would be possible.  However, we’d still need to find and identify potential suppliers, explain our situation and what we think we need, enquire of their availability and costs.

Preferred route – CCS DPS&#x20;

CCS DPS has minimum 10-day turnaround, clearly not appropriate for Incident Response at the time of need.  NE WARP is looking to discuss with suppliers to agree to reduce this.

\
Buyers would need to follow the DPS buying process, complete necessary documents and be happy with the 'legal basis'- this would require procurement resource at the time of need - however templates etc could be developed. This is something that needs to be factored in to the planning assumptions.

**References**

1 ISO 27035: <https://www.iso27001security.com/html/27035.html>

2 NIST Incident Handling Guide: <https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf>

3 Incident Playbook examples: <https://www.incidentresponse.com/playbooks/>

4 Sans Forensics Planning Guide: <https://www.giac.org/paper/gcfa/283/forensic-investigation-plan-cookbook/108356>

5 Sans Incident Handlers Guide: <https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901>

6 MHCLG PAthfinder Programme: <https://www.local.gov.uk/cyber-pathfinder-training-scheme>

7 NCSC Exercise in a box: <https://www.ncsc.gov.uk/information/exercise-in-a-box>

8 Mitre Exercise Planning Guide: <https://www.mitre.org/sites/default/files/publications/pr_14-3929-cyber-exercise-playbook.pdf>

9 FT Guide to Cyber Incident Survival: <https://ig.ft.com/sites/special-reports/cyber-attacks/>

10 Cyber Golden Hour Guide: [https://www.researchgate.net/publication/336400438\_Cyber\_Incident\_Approach\_Framework\_for\_Local\_Government\_-\_Cyber\_Incident\_Approach\_Framework\_for\_Local\_Government](https://www.researchgate.net/publication/336400438_Cyber_Incident_Approach_Framework_for_Local_Government_-_Cyber_Incident_Approach_Framework_for_Local_Government?_sg=Taclsita6Hon2gGdDjBteXausg6PNB0yu-xqJAexI5wsTzTFqV_ZT0Wl0w9EkDrUvLjsf4ci2OTfSa-g5l88_n5GaG_iZewJT--Y_75O.0d9BAxpf-wvDoDCxlO3U5A4FJXRIcJkIWAQh9TzMa2s6I11LsfQNCzsJVctLXO6ZrzSwvHOK3FRtXA2zzej8RQ)

11 Cyber Planning Assumptions: <https://www.ncsc.gov.uk/collection/board-toolkit/collaborating-with-suppliers-and-partners>

12 Horizon Scanning Toolkit: <https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/674209/futures-toolkit-edition-1.pdf>

13 UK Space Agency Cyber Toolkit: <https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/885869/Space_cyber_toolkit_final_v4.pdf>

14 NCSC Logging Made Easy: <https://www.ncsc.gov.uk/blog-post/logging-made-easy>

15 NCSC Incident Management guidance: <https://www.ncsc.gov.uk/section/about-ncsc/incident-management>

16 Network Diagrams blog: <http://networkdiagram101.com/>

17 Network Diagram tools: <https://www.lucidchart.com/blog/network-diagramming-best-practices>

18 NCSC Certified Incident Response Companies: <https://www.ncsc.gov.uk/information/cir-cyber-incident-response>

19 Scottish Government Guide: <https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-guidance/documents/cyber-resilience-resource-toolkit/cyber-resilience-resource-toolkit/govscot%3Adocument/Cyber%2BResilience%2BResource%2BToolkit.pdf>

20 Scottish Govt Cyber Playbook template: <https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-incident-management/documents/cyber-incident-response-denial-of-service-playbook/cyber-incident-response-denial-of-service-playbook/govscot%3Adocument/Cyber%2BCapability%2BToolkit%2B-%2BCyber%2BIncident%2BResponse%2B-%2BDenial%2Bof%2BService%2BPlaybook%2Bv2.3.pdf>

21 Catergorising Cyber Incidents: Uma, M. and Padmavathi Ganapathi. “A Survey on Various Cyber Attacks and their Classification.” *I. J. Network Security* 15 (2013): 390-396.

22 Emergent Cyber Threats: <https://reader.elsevier.com/reader/sd/pii/S0022000014000178>

23 Risk in user stories: <https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/risk-management-in-agile-projects>

24 Risk Poker: <https://www.tmap.net/wiki/risk-poker>

25 Articulating Risk Statements: <https://www.ascentor.co.uk/2015/07/10-top-tips-writing-information-risk-appetite-statements/>

26 Cloud Security Alliance Incident response: <https://cloudsecurityalliance.org/research/working-groups/cloud-incident-response/>


# Information Asset Registers

{% file src="/files/-MeUpQf--08nSYYsjlqD" %}
Asset Reg
{% endfile %}

**Introduction**

Information Asset Registers are nothing new, the original concepts go back to the ICL 2900 series mainframes under VME/B and the ICL Data Dictionary model \[5]. The Data dictionary was revolutionary as it recorded both the physical real world practices and procedures and mapped them to their logical programs and processes. This meant that Business analysts could design systems and services seamlessly in the real world, then map the data attributes into data schemas and taxonomies.

We focus on confidentiality, we're always thinking about access control and encryption. When we talk about integrity, we're thinking about the information on the systems and services being accurate, not tampered with and non-repudiation. And when we're thinking about availability, this is actually about availability of systems and services, which covers the areas around backups, disaster, recovery, and disaster recover. In pulling together asset registers, we are also concerned with network components with manufacturers. We things like operating system types, versions and patch levels within them. We further need to consider how long it is since the configuration information has been updated, if indeed an information asset register exists in the organisation.

We need to understand how long it will be until these systems are due to be replaced. The main reason for wanting this is that if we find a particular vulnerability or exploit appertaining to a certain manufacturer or type of kit, Knowing who has that specific equipment and what the patching level, will help quickly determine if an organisation is at risk of a systems breach or comprise is attacked with a certain exploit. If they are adequately patched, they may not be vulnerable.

Knowing the profile of equipment deployed and the relevant patching and software versions and how they configured will help network defenders. Also those challenged with national network defence will be able to quickly and efficiently contact those organizations and tell them about vulnerabilities and provide actionable intelligence to help them defend their networks and infrastructure.

**Context**

The main international standard for Information Security is ISO27001, which covers a number of domains relating to Information Security. We must however consider other aspects such as Information Risk Management, Assurance and Governance. Other ISO standards cover these areas and so even the standards are many and complex. There is a hierarchy which covers elements from the physical network, through to servers, operating systems, applications, data and access control. These elements are all interlinked and it is proposed that you should consider them in isolation. This paper proposes an approach and flags some of the core issues and questions.

This paper is also a foundation for further research in the area and explores a novel deployment of some social science research methods and approaches. The overall information system, comprises all of the components (attributes) necessary for it’s operation, the hub of the system is the server which hosts the application. There will be a number of supporting components, including the file storage, the access control system and the supporting operating system.

Many systems today are run and supported on databases. Servers themselves need to be accessed. In the old days terminals were hard wired to servers. Today, we generally access a server through a network. This can be a local network (LAN) or a wide area network (WAN). Today, we tend to use the Internet as an integrated part of the Corporate infrastructure, by deploying VPNs (Virtual Private Networks). These VPNs then connect to either on-premises servers or to cloud services, such as Amazon, Microsoft or Google. There is an emergent theme of multi-cloud and hybrid cloud (both on premises and Public Cloud based). \[7] When we mention Public Cloud we mean a Virtual Private Cloud (VPC). \[8].

All of the network and infrastructural components need to be identified, quantified, risk assessed and assured. This is especially important in the context of Zero Trust Computing and as an aid to Operational Cyber Resilience and Response planning and coordination.

This paper proposes an approach to identify, quantify and report on the components in an organisations infrastructure. The proposed approach covers both the hardware (whether logical, physical or conceptual) and the software systems, to provide a heterogeneous taxonomy, for planning, Cyber defence, assurance and incident management.

The reason for this type of granular consideration is to ensure all components of the system are taken into account, because attackers will try to exploit any available attack vector. Whilst most attacks are predicated through emails, websites and direct attacks on Internet facing servers. Good documentation and asset registers will enable rapid identification of vulnerable information assets. We refer to network and infrastructure equipment as information assets as they are configurable and therefore can be assessed against Confidentiality, Integrity, Avaibility and Non-Repudiation.

**Asset Descriptions and Registers**

Information Asset Registers have been in use for some time, they are acknowledged by the Information Commissioners Office (ICO) \[1]. In the context of this paper, we propose a wider and deeper use of Information Asset Registers to annotate and record the network and Infrastructure components deployed within an organisation. The concept was first explored by the author in a previous paper in 2021 \[2].

**Methodology**

There are a number of academic research methodologies that are useful in this space and an mixed-methods approach is being taken to undertake and understand this work. The overarching approach is to use qualitative methods within a practice based research framework \[15].

As the actual project around the replacement of the PSN (Public Sector Network) compliance is a effectively a live real world problem, requiring tools and techniques to understand, analyse and work towards solving the problem. An Agile approach to the process is being used, whilst not a formal research method, it does provide a useful for context and will foster better understanding of the constructs and issues by stakeholders, namely Local Authority compliance and security managers.

The Agile methodology is widely used an understood in central and local government in England and Wales\[9]. MHCLG Digital \[10] use agile as their delivery method, so any proposals we make will be of greater use if they interface with agile. The NCEF (NLAWARP Cyber Exploitation Framework), developed and presented at the Cyber Practitioners Conference in York 2017, is one such Conceptual Framework, which acts as an aide memoir to security architects and network defenders in an agile environment. These frameworks were developed after consulting with a number of regional WARPs (Warning, Advice and Reporting Points) from 2013-17 \[51].

![](/files/-MeUoG6A1e_s0qEhpHX0)

**Figure 1 The NCEF Framework**

The NCEF framework is predicated on a number of questions to help shape and refine the infrastructure design. This approach helps walk the architect or agile product designer through the landscape to build a profile and ensure all necessary steps are covered to form an holistic approach to zero trust design from a information security / assurance perspective.

NCEF1 What does the network look like, discovery, diagrams and documentation?

NCEF2 What's happening on the network, logs and monitoring?

NCEF3 What does normal network traffic look like (SIEM)?

NCEF4 What bad stuff is out there on the network (detection)?

NCEF5 Do we have bad stuff? - Use tools for NCEF3 & Mitre Att\&ck Framework

NCEF6 How do we remove our bad stuff from the network?

NCEF7 How do we keep bad stuff out of the network?

NCEF8 How do we respond to the bad staff, through incident response (Develop playbooks)?

NCEF9 How do we report bad activity (Security Incident & Event Management (SIEM)?

NCEF10 How do we prepare and practice dealing with bad stuff (Cyber Resilience Exercising)?

© NLAWARP 2017-21

Figure 2. NCEF enquiry questions

A Conceptual Framework\[11] is a way of mapping and showing the relationship between a collection of variables, some are fixed and some are dynamic. In this case the variables are network components and information governance issues. Once you’ve identified your variables, they can be assembled, mapped and clustered together. This clustering starts to show relationships and help the formation of categories. Using Grounded Theory\[12], to produce data clusters. Management students will be familiar with the Business Model Canvas \[13] and the similar canvasses and approaches \[16]. Many modern tools, such as the agile “Kanban” \[17] approach, software like Trello \[18] and MIRO\[19] all fit beautifully with Grounded Theory and conceptual frameworks. These in turn fit with Systems Thinking \[20], Wicked Problems \[21], Wardley Maps \[22] and weak signals \[23], which in Grounded Theory are outlier variables. I’ve explored some of there issues in a paper on Horizon Scanning \[24].

Quantification of information assets, using Grounded Theory \[25], allows for the categorisation of Information Assets in a way that Grounded Theory allows for the categorisation of issues within a community. It is hoped that the introduction of these Social Science research methodologies \[27] into areas traditionally serviced by Software engineering \[28] and other Computer Science methodologies \[29] will prove innovative and useful to other researchers. In developing this work I’ve been influenced by the Deep Work approach\[30] \[31] and the ZettleKasten \[32] which has helped to shape the structure. I believe this approach, brings a whole range of Qualitative Social Science tools into play in a novel and innovative way that not only helps map the landscape, but also helps to identify some of the soft cultural issues that affect information management and governance. The Covid-19 pandemic of 2020/21 has forced many organisations to work from home and to collaborate and operate in a virtual environment.

**The SCRAPE Framework**

It is contented that Information Asset Registers are an essential part of Cyber Security, Information Assurance and Cyber Incident Response moving forward. There is anecdotal evidence in some Local Authorities that Information Asset Registers do not exist for this purpose. This view has been formed over the past few years, through discussions with Local Authorities during Cyber Incidents, through on-line forum discussions and during Cyber Incident Response Training.

Therefore the proposal is to offer an approach to Local Authorities, to develop an Information Asset Register approach and to implement it as part of their Cyber Incident Response Planning.

As we are advocating an approach to move from static plans to dynamic playbooks, Information Asset Registers will be a very useful planning and response tool.

Whilst thinking about this problem and a practical approach to implementation,

* Systems
* Cartography
* Registers
* Attributes
* Patterns
* Ethics

**Systems**

When we talk about systems in this context, we are referring to the discrete system for instance Housing Benefits, Council Tax. The Systems can also be a service, such as Microsoft 365. Systems and services will be made up of a number of elements, for instance servers, Operating System, Data Base, Programming language, scripting, configuration files, data files. The systems f today are very different in their composition than those of twenty years ago. The most simple Information Asset Register will comprise a series of linked records, which describe the functional layout and composition of the system. This could physically be a text document, spreadsheet or database.

We must think about the not only the structure and layout of the Information Asset Register, but how it will be constituted, stored and published. These Information Asset Registers could potentially be a valuable asset for attackers and those who wish to cause harm or disruption.

Thought must therefore be given to the creation, storage, publication and use of these Information Asset Registers.

There are a number of useful descriptors and approaches that may be of use to researchers in this field and could be the subject of further research and reporting, these include;

* Systems Thinking \[20]
* Complexity \[33]
* Weak Signals \[23]
* Nudge Theory \[34]
* Cynefin \[35]
* Wicked Problems \[21]
* Wardley Maps \[22]

**Cartography**

When the term cartography is used in this context we mean mapping, that is the visual and textual documentation, illustration and recording of the Physical, Logical and Conceptual layout of the information that forms the Focus of Interest, in this case the Service of System, being documented in the Information Asset Register. Some very useful work in this area is the Domain Based Security, referred to as “DBSy” \[14], a process extensively used in the Ministry of Defence and although now thought of a legacy approach it is still worth reading and understanding.

Mapping complex interlinked systems is even more important as we move to a cloud based eco system, which can comprise a hybrid multi cloud approach, that is components of physical servers on premise, inter-linked with public cloud services of multiple different vendors. Mapping these interconnections and keeping the documentation up to date, ideally this is done automatically through the use of metadata and automated module communication.

Many systems components can be open source and these utilise platforms and tools such as GitHub. The modern systems development process, referred to as “DevOps” ,in the agile world \[36] also has a security approach called DevSecOps (Development, Security Operations) \[37] these processes in turn mean that program code is developed, tested and deployed through a federated approach called CI (Continuous Integration). Much of this is automated and te whole code to production (Live running and Operations), is carried out at scale and often is fully automated.

There are a number of concepts and approaches that have formed the thinking around the Cartography element of this model, these are worth further investigation;

* Mind Maps
* Architectural Diagrams
* Symbols & Lexicons
* Systems Mapping
* Documentation
* Domain based security.
* Security Domain and mapping.

**Registers**

Because of the federated nature of agile cloud based systems, it is necessary to have authoritative lists of data items, some of which are fixed for instance recognised countries of the would used by the banks: <https://bank-code.net/iban/country-list> also country prefixes for international telephone dialling, there are also registers on the .gov.uk website at are definitive;

[https://www.registers.service.gov.uk](https://www.registers.service.gov.uk/) Registers are therefore an approach and worth consideration in the context of Information Asset Registers. We must however be mindful of the security implications and the “Equity” (The usefulness for a hacker), so these register entries will need to be pseudo-anonymised. To facilitate pseudo-anonymisation, we propose a CUON (Cyber Unique Organisational Number), which would be randomly allocated to an organisation in a similar way to a private and public key.

Registers are also extensible, like postcodes. Once components have been declared, other organisations with the same components would be able to copy the entries, this would speed up the whole process up enabling fast and accurate data base population of asset components. This would in turn lead to a standardisation of threat profiles and compensating controls and architectural patterns. This could make a huge difference to local authorities, through standard threat profiles. The contention being all Council Tax Systems have the same data and asset value. Once a systems has been profiled, all councils would be able to use the same profile. Any variations would also be recorded and a huge amount of effort can be saved. Defining and saving these threat profiles and in time asset register entries in XML or similar makes them machine readable and this opens the possibilities for further work to look at the use of agent and API based automated approaches.

**Attributes**

The mapping of attributes will it is contended be a journey of iteration. To start with key components will be identified to form the core of a taxonomy. For instance;

Application Servers

Web Servers

Mail Servers

Firewalls

Routers

Proxy Servers

Active Directory Servers

Network Area Storage Devices

A detail of this approach is laid out in the NIST SP 1800-5 document:

<https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-5.pdf>

**Taking a firewall as an example;**

**CUON:** 654/21/9874

**Entity:** Firewall

**Owner:** ICT Network Team / Team Leader Ext 5434 <ICTNetork@dovedale.gov.uk>

**Location:** Server Room 102b

**Asset number:** 21/45634

**Classification Level:** OFFICIAL

**Manufacturer:** Cyber Sure

**Model:** 345/t

**Build level:** 34.9.8.7

**Last patched:** 12/02/2021

**IP Address or identifier:** 10.3.4.56

**Record Date:** 210215

**Record version** 1.0

**Notes**

**Figure 3 Example Information Asset Register record format**

The above is a simple example but it means there is a definitive record for the asset.

The CUON being: \[654] The organisation ID \[21] Year of allocation \[9874] the unique reference number for the firewall. The key being that a CERT or other authorised entity, could search for

Cyber Sure model 345/t firewalls and find all of the organisations that have them recorded. A further refined search could be on build level \[34.9.8.7], that could be an old build and subject to a zero day CVE exploit.

This would save a lot of time and effort. Using an agent based system for instance HUGINN <https://github.com/huginn/huginn> The agent based approach is a push/pull system. The updated contents of a database wait until polled for an update. Bespoke workflows are put together. This node based store and forward approach could be incorporated into a CERT (Computer Emergency Response Tram) or as part of a hierarchic network for instance linking all of the Local Authorities in Wales, through regional based nodes. This was discussed in a CSIRT paper, referencing Cybershare as model that could achieve this \[38].

this type of asset register could be automated and integrated into a STIX and TAXII type infrastructure: [https://stixproject.github.io](https://stixproject.github.io/) – however as previously discussed the issue of security and pseudo-anonymisation has to be considered.

Other areas for further consideration are;

Taxonomy of Physical components for this I would consider: <https://www.opensecurityarchitecture.org/cms/index.php>

Data Dictionary example: <https://www.usgs.gov/products/data-and-tools/data-management/data-dictionaries>

Cataloguing Functional and non-functional requirements.

<https://qracorp.com/functional-vs-non-functional-requirements/>

**Patterns**

When we discuss patterns in this context we propose that a pattern show the linkages between elements of an Information Asset Register and how the individual components form a coherent system or service. The DBSy references \[14] previously discussed and the Data Dictionary reference \[39] are both good examples of elemental linkages. The rationale for needing these descriptors is that ultimately we need to follow the data \[40]. A Data Protection Impact Assessment (DPIA) may well have a diagram showing the flow of information through a system. Service.

Service Transaction Mapping <https://insidegovuk.blog.gov.uk/2018/02/07/how-we-approached-service-mapping/> Is a good example of how this looks in practice. We contend this is valuable in working through Cyber Resilience Planning as has immediate utility for Cyber Incident Response when you are making sense of what has happened after an attack.

When systems were written in house, it was possible for the programmer to understand the entire system. Today systems are far more complex and can be distributed and inter-linked. This is why documentation is so important.

There are various standards and approaches to security architecture that may be of interest for further research;

SABSA <https://sabsa.org/sabsa-executive-summary/>

Zackman <https://www.zachman.com/about-the-zachman-framework>

TOGAF <https://www.opengroup.org/togaf>

**Ethics**

Following on from the authors Dec 2020 Horizon Scanning paper \[53] which referenced the work of William Barker \[54] describing the implications for Digital Ethics we need to consider these in the context of information assets and Cyber Security.

The UK is playing through official bodies like the Office for Artificial Intelligence, Centre for Digital Ethics and Information Commissioner's Office are working closely with Digital Ethics Lab, Alan Turing Institute, Open Data Institute and Digital Catapult in championing digitally ethical practice across the UK public sector.

Most recently GCHQ has published an ethics strategy paper, [**The Ethics of AI: Pioneering a New National Security**](https://www.gchq.gov.uk/files/GCHQAIPaper.pdf),[\[1\]](broken://pages/-MeUoG680zOHq_-Ll_l7#footnote-1) which looks at the future ethical role of the technology in dealing with crimes such as child abuse and human trafficking, and threats from disinformation. Similarly, in the wake of Covid 19 the NHS AI Lab is introducing the [**AI Ethics Initiative**](https://www.nhsx.nhs.uk/ai-lab/ai-lab-programmes/ethics/)[\[2\]](broken://pages/-MeUoG680zOHq_-Ll_l7#footnote-2) to ensure that AI products used in the NHS and care settings will not exacerbate health inequalities.

Taken together, we are seeing an emerging set of common core values or attributes that built upon the combined disciples of bioethics and responsible AI (see Fig 4 below) that can inform wider digital and cyber ethical practice:

!\[Diagram

Description automatically generated]\(/files/-MeUoG6BfxAjAAHtkvS0)

Figure 4 Ethics Framework (Barker 2020)

* **Beneficence:** do good. Benefits of work should outweigh potential risks.
* **Non-maleficence:** do no harm. Risks and harms need to be considered holistically, rather than just for the individual or organisation.
* **Autonomy:** preserve human agency. To make choices, people need to have sufficient knowledge and understanding.
* **Justice:** be fair. Specific issues include algorithmic bias and equitable treatment.
* **Explicability**: operate transparently so as to explain systems working and its outputs

**A further exploration of Architectural patterns**

Pulling this all together, the mapping of components, their inter relationship, implementation, configuration and protective controls can all be pulled together in the form of a security architectural pattern.

The NCSC have written a useful set of guidance: <https://www.ncsc.gov.uk/blog-post/secure-systems-design--new-guidance-now-available>

One of the best ways to ensure good security practices is to observe bad ones, this is where Security “Anti-Practices” come in useful; <https://www.ncsc.gov.uk/whitepaper/security-architecture-anti-patterns>

A good example of a pattern for the safe import and export of data can be found at: <https://www.ncsc.gov.uk/guidance/design-pattern-safely-exporting-data>

**The Information Asset Eco system**

Back in 2017, some work was undertaken to consider the key questions relating to network protection and defence. These questions were designed to be an aide memoir for Information Governance professionals to understand Information Assurance issues. This has how been developed on to help visualise what an information asset eco system may look like.

!\[Shape

Description automatically generated with low confidence]\(/files/-MeUoG6CiheQuZRQNzGZ)

**Figure 5 Information Asset Eco-System**

**Lego building Blocks**

It is even possible to use Lego bricks to develop physical representations of networks and architectures: [https://www.decisions-disruptions.org](https://www.decisions-disruptions.org/)

This approach is very good for explaining to senior leaders and non technical people how components link together. This can be used for Risk Management modelling and as an planning aide for Cyber Security exercises \[41].

ISACA have also published a useful article that discusses the use of Lego models for Cyber decision making and risk management \[42].

**Implementation Approach The 5 D’s**

This methodology was developed by the author and was tested by a group of London Boroughs in 2009 \[43] through the LGA. The approach take you through Information Asset Identification and classification. This helps determine the relative value of an Information Asset.

**© Mark Brett 2009-21**

**Figure 6 The 5 D’s of Information Asset Registers**

**Discovery**

* A trawl of Information Assets – This is the difficult bit and the SCRAP process already discussed can help with this.
* What assets exist. You need to understand what you have and how they physically or logically exist, where are they and if they are backed up against cyber-attack.
* What are their inputs / outputs. Asset and Systems linkages are critical to enabling incident managed and recovery. Linked assets need to be viable, that is all of their linked parts exist and are accessible.
* What linkages exist, without the linkages, you can’t restore a working system.

**Determination**

* Who owns the asset? Every Information Asset must have an owner. The acid test is, who would miss it most if it were permanently destroyed?
* Who is responsible for the asset? As above, along with the Owner is the team responsible for it’s maintenance, operation and use.
* Who controls the asset? How is it delivered, through a system or service.?
* Who can authorise the processing and disclosure?

**Decision**

* What is the business impact level of the asset? That means if it’s lost how much “harm” would it cause? \[REF] to Harm modelling….
* What is it’s Data Protection Status? Does the Asset contain Personal Data?
* Who is authorised to process the asset? Again Data Protection status.
* What protective measures are required? This is about the Information Assurance of the asset.

**Deployment**

* Where will the asset be created, stored and processed?
* Will the asset be transmitted?
* Will the asset be copied?
* Will the asset be controlled?
* Who will process it?
* Where?
* How?
* Compliance/monitoring/audit regime??

**Destruction**

* Who will authorise the destruction of the asset?
* How will you know if all copies are destroyed?
* Do you need to retain a copy for legal/compliance purposes?
* How will you destroy the asset?

**Linking Information Risk, Information Assurance and Incident Management**

These tools and techniques are part of wider Cyber Incident Management, a detailed approach is explored in the authors incident response policy primer and guide \[44]. The SCRAP approach previously discussed provides a practical framework and approach to facilitate the scoping and identification phase to enable Cyber Incident Planning. Likewise the 5Ds provides a structured approach to augment Cyber Incident planning and management. Public Sector organisations can make full use of the National Cyber Security Centre (NCSC) Active Cyber Defence (ACD) tools and services \[45].

**Logs / Time Sources / Network Diagrams / Documentation**

The SCRAPE approach above was devised to draw together the key non-functional requirements for Cyber Indent Managing and Response. Making artefacts unique (Developing a descriptive Taxonomy for asset identification, version control and management). Further applications for Incident reporting. These are discussed in detail in the NIST incident Response Guide \[46]. Once you have identified the assets and catalogued them, you can then start to evaluate the Assets and their inter relationship. All of the attributes are as discussed, causal variables. Identifying and documenting the attributes, will lead to the creation of. Taxonomy \[47] and the NSIT Asset implementation guide \[48] , which can then be mapped against the Mitre Att\&ck Framework \[49], which will expose the vulnerabilities and attack vectors that can be exploited through the Cyber kill chain \[50]. We mitigate these attack vectors through compensating controls \[51].

**Conclusion**

Information Asset Registers aren’t new, the Data Protection Act, The Freedom of Information Act and the work of the Information Commissioners Office has highlighted the need for them. The ITIL framework too has a asset registers at its heart. Many Councils claim to have them, yet they are not understood. We believe they are highly valuable artefacts to better understand Information Risk, Assurance and to aid incident response. Automated discovery tools such as NMAP & Spiceworks \[56] can help make the job a lot easier.

**Future Work**

The next article will explore an approach to address the changing dynamic and need to remote coordination and response.

Future studies may well confirm an acceleration towards cloud provisioned software and zero trust computing services. I am also concerned with the need to review and change Cyber resilience plans, Incident response and Crisis Management may well need to be delivered remotely rather than in the traditional face to face manner. There is a need to understand fast time communications, using various channels and software applications. An approach to fast time communications for incident response and Cyber resilience in the context of UK Local Government will be discussed in the article. This will concentrate on the formation of Cyber Technical Advisory Cells (C-TACs) and an exploration of adapting the JESIP Framework \[55] to Cyber.

**References (All accessed April 2021)**

\[1] <https://ico.org.uk/for-organisations/accountability-framework/records-management-and-security/information-asset-register/>

\[2] Brett(2021) **An overview of current issues and practice relating to local government cyber security in England and Wales** Henry Stewart Publications ***Cyber Security: A Peer-Reviewed Journal*****&#x20;Vol. 4, 4** 1–13

\[3]IMAG:<https://www.researchgate.net/publication/342804953\\_An\\_Overview\\_of\\_Local\\_Government\\_Cyber\\_Security\\_in\\_England\\_and\\_Wales\\_Emergent\\_Threats\\_and\\_Practice>

\[4] ITIL CMDB: <https://www.axelos.com/best-practice-solutions/itil/what-is-itil>

\[5] Data Dictionary (ICL IDMS Design {1987} Page 1-6: <http://www.computinghistory.org.uk/downloads/32270>

\[6] GDS Service Design Manual: <https://www.gov.uk/service-manual>

## \[7] Mulder J. (2020) Multi-Cloud Architecture and Governance, Packt Publishing

\[8] Shrivastwa A. (2018) Hybrid cloud for Architects, Packt Publishing

\[9] Agile Methodology in UK Govt: <https://www.gov.uk/service-manual/agile-delivery>

\[10] MHCLG Cyber: <https://mhclgdigital.blog.gov.uk/category/cyber/>

\[11] Miles, Huberman & Saldana Qualatative Data analysis, Sage, 2018 <https://uk.sagepub.com/en-gb/eur/qualitative-data-analysis/book246128>

\[12] Grounded Theory: <http://www.groundedtheoryonline.com/what-is-grounded-theory/>

\[13] <https://www.strategyzer.com/canvas/business-model-canvas>

\[14] DBSy: S. Katam, P. Zavarsky and F. Gichohi, "Applicability of Domain Based Security risk modeling to SCADA systems," *2015 World Congress on Industrial Control Systems Security (WCICSS)*, London, UK, 2015, pp. 66-69, doi: 10.1109/WCICSS.2015.7420327.

\[15] <https://www.creativityandcognition.com/resources/PBR%20Guide-1.1-2006.pdf>

\[16] <https://www.strategyzer.com/canvas>

\[17] <https://kanbanize.com/kanban-resources/getting-started/what-is-kanban>

\[18] [https://trello.com](https://trello.com/)

\[19] [https://www.miro.com](https://www.miro.com/)

\[20] <https://thesystemsthinker.com/systems-thinking-what-why-when-where-and-how/>

\[21] <https://www.wickedproblems.com/1_wicked_problems.php>

\[22] [https://learnwardleymapping.com](https://learnwardleymapping.com/)

\[23] [https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/the-strength-of-weak-signals#](https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/the-strength-of-weak-signals)

\[24] <https://www.researchgate.net/publication/348931430_Horizon_Scanning_White_Paper>

\[25] Strauss, A., Corbin, J.M.: Basics of Qualitative Research: Grounded Theory Procedures and Techniques. Sage Publications, Inc. (1990)[Google Scholar](https://scholar.google.com/scholar?q=Strauss%2C%20A.%2C%20Corbin%2C%20J.M.%3A%20Basics%20of%20Qualitative%20Research%3A%20Grounded%20Theory%20Procedures%20and%20Techniques.%20Sage%20Publications%2C%20Inc.%20%281990%29)

\[26] <https://www.forbes.com/sites/forbestechcouncil/2016/06/01/how-to-use-ethnographic-research-to-help-your-business/>

\[27] <https://esrc.ukri.org/public-engagement/social-science-for-schools/resources/what-is-social-science-research/>

\[28] <https://www.freecodecamp.org/news/computer-science-vs-software-engineering-which-one-is-a-better-major-88482c38446b/>

\[29] <https://cgi.csc.liv.ac.uk/~ullrich/COMP516/notes/lect06.pdf>

\[30] <https://thebookofsarah.com/deep-work-rules-focused-success-distracted-world-summary/>

\[31] Newport C. (2016) Deep Work. Rules for Focused Success in a Distracted World, Grand Central Publishing

\[32] <https://zettelkasten.de/posts/overview/>

\[33] <https://research-information.bris.ac.uk/en/publications/what-is-a-complex-system>

\[34] <https://www.imperial.ac.uk/nudgeomics/about/what-is-nudge-theory/>

\[35] <https://hbr.org/2007/11/a-leaders-framework-for-decision-making>

\[36] <https://www.gov.uk/guidance/development-operations-devops-engineer#introduction-to-the-role-of-development-operations-devops-engineers>

\[37] <https://www.redhat.com/en/topics/devops/what-is-devsecops>

\[38] iStand UK Cyber (Cybershare) <https://istanduk.org/wp-content/uploads/2019/08/Cyber-Emergency-Response-BRT-002.pdf>

\[39] <https://www.fujitsu.com/uk/Images/ICL-Technical-Journal-v04i02.pdf>

\[40] <https://ico.org.uk/for-organisations/accountability-framework/records-management-and-security/information-asset-register/>

\[41] <http://www.toknowpress.net/ISBN/978-961-6914-26-0/57.pdf>

\[42] ISACA Lego Article: <https://www.isacajournal-digital.org/isacajournal/2020_volume_4/MobilePagedArticle.action?articleId=1598518#articleId1598518>

\[43] 5 D’s (2009) LGA <https://slideplayer.com/slide/6407124/>

\[44] <https://www.researchgate.net/publication/342898805_Cyber_Incident_Response_-Working_Paper>

\[45] <https://www.ncsc.gov.uk/section/products-services/active-cyber-defence>

\[46] NIST Incident Response Guide: <https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf>

\[47] NIST Asset Registers: <http://doi.org/10.6028/NIST.SP.1800-5>

\[48]<https://www.nccoe.nist.gov/library/it-asset-management-nist-sp-1800-5-practice-guide>

\[49] [https://attack.mitre.org](https://attack.mitre.org/)

\[50] <https://www.sans.org/security-awareness-training/blog/applying-security-awareness-cyber-kill-chain>

\[51] OSA Taxonomy: [https://www.opensecurityarchitecture.org/cms/foundations/osa-taxonomy<br>](https://www.opensecurityarchitecture.org/cms/foundations/osa-taxonomy)

\[52] [https://www.nlawarp.net](https://www.nlawarp.net/)

\[53] <https://www.researchgate.net/publication/348931430_Horizon_Scanning_White_Paper>

\[54] <https://www.wired-gov.net/wg/news.nsf/articles/Bridging+the+ethical+divide+25092020130500?open>

\[55] [https://www.jesip.org.uk](https://www.jesip.org.uk/)

\[56] <https://www.spiceworks.com/free-pc-network-inventory-software/>

1.


# Post PSN Assurance Process (P2AP) - Strawman

{% file src="/files/-MeUoffErrbvdfmM\_hZr" %}
Post PSN Strawman
{% endfile %}

June 2021 Version 0.6 – Status: DRAFT FOR COMMENT – NOT POLICY

**Background**

The Local Government Information Assurance regime has its roots in the GSi Code of Connection which goes back over fifteen years. The world has moved on towards using the Internet \[1] and the government policy is now Internet First\[2], with a move away from the PSN, which is now considered a legacy network.

Traditional ICT is also moving to a cloud first approach \[3]. Cyber related assurance is also moving to the Minimum Cyber Security Standard (MCSS) \[12] owned by Government Security Group in Cabinet Office\[3a] which will replace Local Government Information Assurance for central government departments connected to PSN by April 2023.\[11]

At some point in the future PSN will no longer be used, therefore Local Government Information Assurance will no longer exist and the standard for cyber will be the MCSS. In the meantime there are opportunities to prepare the local sector for this eventuality and one such opportunity is to take on responsibility, through a local body, for Local Government Information Assurance whilst the PSN is still operational as a stepping stone for moving towards MCSS

This is a component part of a bigger picture which covers the whole legacy ICT issue, which is being driven by the Cabinet Office for Central Government, that will in due course impact on Local Government. Todays leading edge technology will become tomorrows legacy. We are also now seeing the introduction of both hybrid and multi-cloud technologies and approaches being introduced in organisations. \[10]

**Issue**

The Compliance at present is gained through a code of connection submission, which comprises a network diagram detailing what is in scope, a penetration test, a remedial action plan and a statement of compliance, being a set of assertions, detailing how the Local Government Information Assurance conditions are met through the code of connection. This process is a compliance regime, not an assurance regime.

The current process is still time intensive to administer and is being used by other government bodies, the police and NHS as a level of assurance to facilitate a baseline on which they share information and interact. The current approach is a once a year snapshot, like the MOT on a car. Taxis and other police vehicles have a different regime, which is on-going. Police vehicles are constantly services and reviewed. Police Traffic cars have their speedometers calibrated and are subject to stringent checks\[13].

Network and systems assurance is only one component of a wider requirements. There are issues around legacy ICT systems, where the platforms, applications and operating systems are being legacy, (deprecated and going obsolete.) This paper can only focus on this aspect, it is however an integral part of the whole. There needs to be consideration for applications which rely on components that are obsolete, that is no longer supported \[5] (old JAVA / FLASH, Internet Explorer etc.).

Councils with legacy equipment are likely to be subjected to more cyber attacks. This increases their need to be even more vigilant in protecting their network boundaries, running their platforms and supporting their applications. Local Authorities are all sovereign democratic entities. Any directed government intervention is termed as a “new burden” \[6], there is a mechanism to do it but the cost would need to be picked up by central government. This is further complicated by devolution.

**An alternative Local Government Information Assurance process**

**Background**

In an ideal world all PSN connected organisations would have the whole network and infrastructure assured through ISO 27001. This is however very expensive and would

not be cost effective, if however Councils have ISO 27001 covering the required scope,

that would be acceptable to cover 1 & 3 below, subject to scope.

This process below will address the interim requirements as an alternative to PSN code of connection compliance and pave the way to post-PSN assurance supporting the Future Networks for Government (FN4G) Programme. The current Local Government Information Assurance regime is explained at: <https://www.gov.uk/guidance/public-services-network-psn-compliance>

The PSN network is designed for the OFFICIAL level within the HMG protective marking scheme \[9] the threat profile and risk appetite of the PSN is OFFICIAL, using the baseline security controls that reflect commercial good practice. The same applies to the baseline encryption where applicable being commercial good practice.

Currently the PSN relies on an historic penetration testing regime, historically was called an Information Technology Health Check (ITHC), this is an independent penetration test carried out annually. Over the past few years a whole industry has grown up to mechanize and automate this process, using freely available tools and techniques. The NCSC CHECK scheme, when used for this purpose is robust, and fit for purpose, but is also expensive. The monthly scanning requirements will highlight issues in a more effective way than a single annual test. We continue advocate penetration testing for applications and infrastructure as best practice.

**Greyscale approach to Threat Profiles at OFFICIAL**

All of this approach for use across either just Local Government or the Wider Public Sector (WPS) will be at the OFFICIAL protective marking level. The OFFICIAL level has a grey scale from unclassified white to the more sensitive Black end of the slider within OFFICIAL, often wrongly referred to as OFFICIAL-SENSAITIVE being a separate level “Stripping OFFICIIAL”, that’s not the case. OFFICIAL\_SENSITIVE is a handling caveat, not a separate level however there is a need for nomenclature to describe the top end of the OFFICIAL protective marking which is still below the threshold for SECRET. We therefore need to think of the sliding grey scale as a useful analogy.\[14] The point being OFFICIAL-SENSATIVE can be used for need to know where the threat profile is towards the unclassified end of the scale, (say a Personnel issue or investigation etc.) not just at the High Treat end. SECRET is a whole different tier. The

Problem was caused in 2014, when the Asset Classification Scheme went from six to three levels, loosing CONFIDENTIAL that was used extensively by the Police and others. The move has since been to use “OFFICIAL-SENSITIVE” as a proxy for CONFIDENTIAL, below SECRET.

!\[Graphical user interface, text, application

Description automatically generated]\(/files/-MeUomA3snUmnwj0INsZ)

**Suggested approach (Requirements) requiring evidence and assertions**

The proposed alternative process will require a number of components which will provide

An equivalent to the existing PSN code of connection.

The Post PSN Assurance Process (P2AP) would comprise of:

1\) IASME Cyber Essentials Plus as a minimum covering.

1.1 The Corporate ICT Core Network

1.2 The Social Care systems

1.3 The Corporate CRM System

1.4 The Corporate websites

1.5 Corporate email

1.6 remote network access services

1.7 Wireless network access

1.8 BYOD

1.9 Remote (Home) working

2\) Adherence to and reporting on the Minimum Cyber Security Standard \[8]

3\) Adherence to and reporting on NCSC legacy guidelines: <https://www.gov.uk/guidance/managing-legacy-technology>

3\) Monthly internal vulnerability scans of the core network and servers.

&#x20;Ensuring core network components are not legacy, especially firewalls.

&#x20;Scanning all core network devices;

&#x20;3.1 Firewalls including configuration, patching, whitelists and rulesets.

&#x20;3.2 Core routers, configurations and patching.

&#x20;3.3 Ensuring servers are properly managed (if legacy) and patched.

4\) Monthly external network scans of websites, services and publicly exposed

Endpoints, including API endpoints.

5\) Monthly scanning and reporting of;

5.1 All digital certificates in use.

5.2 The DNS servers, services and configurations.

6\) Deployment, reporting and active use of NCSC Active Cyber Defense (ACD);

&#x20;6.1 Webcheck

&#x20;6.2 Mailcheck

&#x20;6.3 PDNS (or acceptable alternative if not technically possible).

&#x20;6.4 NEWS Network Early Warning Service

&#x20;6.5 Logging Made Easy (or Acceptable alternative)

&#x20;6.6 Have an NCSC point of contact (POC) email box in place.

&#x20;6.7 Have an active NCSC CISP account.

7\) Have carried out a Cyber Incident exercise within the last twelve months.

8\) Have suitable Information Governance, training and awareness regime in place

8.1 SIRO/ IAO / DPO appointed.

8.2 Adherence to the Local Public Services Data Handling Guidelines Version 6.

8.3 Member of Regional WARP.

9\) Documented Cyber Incident Response process and plan in place.

10\) Key data backup / isolation processes in place.

**The proposed process**

1. Continue to accept the PSN community documents including the code of connection.
2. Provide evidence of Cyber Essentials Plus.
3. Provide evidence of monthly internal and external scans with an agreed mitigation plan and evidence of improvement against the plan through the monthly scans evidencing the patching and other compensating controls and mitigations are in place and being implemented.
4. Evidenced return against the Minimum Cyber Security Standard.
5. Evidence of information governance regime.
6. Evidence of NCSC ACD take up.
7. Evidence of Cyber exercise.
8. Evidence of key data backup compensating controls.

**Supporting future Strategy**

This process will encourage a move towards proactive information assurance and cyber resilience. We are encouraging the take up of the NCSC ACD and supporting the minimum cyber security standard. Monthly vulnerability scanning will drive improvement and encourage a robust patching regime. Focusing on the automation of scanning and reporting will eventually get to a point of near real time reporting and posture checking.

**Glossary**

DWP Department of Work and Pensions

LDS CIC Local Digital Services Community Interest Company

LGD Lead Government Department

ICT Information and Communications Technology

MOU Memorandum of Understanding

New Burdens - Where central government instruct a local authorities to do something and picks up the associated costs for doing it.

NHS National Health Service

**References (Accessed February 2021)**

\[1] <https://www.gov.uk/government/speeches/the-future-of-the-internet>

\[2] <https://www.gov.uk/guidance/moving-away-from-legacy-networks>

\[3] <https://www.gov.uk/guidance/use-cloud-first>

\[3a] <https://www.gov.uk/government/publications/the-minimum-cyber-security-standard>

\[4] [https://www.legislation.gov.uk/ukpga/2006/32/notes/data.xht](https://www.legislation.gov.uk/ukpga/2006/32/notes/data.xht?view=snippet\&wrap=true)

\[5] <https://www.gov.uk/guidance/managing-legacy-technology>

\[6]<https://www.gov.uk/government/publications/new-burdens-doctrine-guidance-for-government-departments>

\[7] <https://iasme.co.uk/>

\[8] <https://www.gov.uk/government/publications/the-minimum-cyber-security-standard>

\[9] <https://www.gov.uk/government/publications/government-security-classifications>

\[10] <https://www.packtpub.com/product/multi-cloud-architecture-and-governance/9781800203198>

\[11] <https://technology.blog.gov.uk/2020/09/08/the-road-to-closing-down-the-psn/>

\[12] <https://www.gov.uk/government/publications/the-minimum-cyber-security-standard>

\[13] <https://www.mylondon.news/news/north-london-news/police-speed-vans-need-mot-15916667>

\[14] <https://www.sans.org/reading-room/whitepapers/ActiveDefense/sliding-scale-cyber-security-36240>


# Local Authority Cyber Resilience Planning Guide

This guide is to assist managers in preparing and implementing Business Continuity Plans, to aid Cyber Resilience.

{% file src="/files/-MeUroxhznp9lEdgeFHf" %}
PlanningGuide
{% endfile %}

**(C) 2003-2021Mark Brett**

**June 2021 Version 3**

**Background**

Following the events of 11th September 2001, and the London bombings of 7th July 2005, and the WannaCry malware incidents across the NHS, have caused many organisations to consider an annual review process for their Business Continuity Planning.

The guide aims to mitigate the impact of unforeseen events on the business. Subsequently, the Civil Contingencies Act 2004 and the events of 7thJuly 2005 have also heightened the need for a robust Business Continuity planning framework. In todays interconnected Internet driven world such planning is even more important. The shift to Cloud computing is making this even more difficult.

This guide was originally written in 2003 and has been updated over the years. The approach is still sound and this is continued work in progress.

Mark Brett MRes CITP CMngr FICPEM FBCS FCMI MCIIS MEPS MSyI

Honorary Visiting Fellow (Cyber Security)

Cyber Centre London Metropolitan University

© Mark Brett 2003-2021

Your welcome to make use of the contents of this document for non-commercial purposes including Public Sector use. However I would ask that you acknowledge the fact in your derived work.

**INTRODUCTION**

Every year unforeseen emergencies take their toll on business and industry -- in lost business and escalated costs. Something can be done. Business and industry can limit the impact and losses, returning quickly to normal operations if they plan ahead.

This guide provides step-by-step advice on how to create and maintain a comprehensive Business Continuity Planning Programme.

To begin, you need not have in-depth knowledge of Cyber Resilience. What you need is the authority to create a plan and a commitment from the Chief Officer to make Business Continuity Planning part of the corporate culture If you already have a plan, use this guide as a resource to assess and update your plan. The guide is organised as follows:

**Section 1:** 4 Steps in the Planning Process -- how to form a planning team; how to conduct a vulnerability analysis; how to develop a plan; and how to implement the plan. The information can be applied to virtually any type of business or industry.

**Section 2:** Business Continuity Planning Considerations -- how to build such Business Continuity Planning capabilities as Health & Safety, Property Protection, Communications and Community Outreach.

**Section 3:** Hazard-Specific Information -- technical information about specific hazards your building or site may face.

**Section 4:** Information Sources -- where to turn for additional information.

**Appendix A** BCM plan and risk assessment toolkit

**What Is an Emergency?**

An emergency is any unplanned event that can cause disruption or significant injuries to employees, customers or the public; or that can shut down your business, disrupt operations, cause physical or environmental damage, or threaten the facility's financial standing or public image. Obviously, numerous events can be "emergencies," including:

1.Fire 

2.Hazardous materials incident 

3.Flood or flash flood 

4.Terrorist Incident 

5\. Malicious Incident (public or Employee)

6.Winter storm (Weather) 

7.Communications failure 

8.Civil disturbance (Transport strikes) 

9.Loss of key supplier or customer 

10.Explosion (Gas etc)

The term "disaster" has been left out of this document because it lends itself to a preconceived notion of a large-scale event, usually a "natural disaster." In fact, each event must be addressed within the context of the impact it has on the authority and the community. What might constitute a nuisance to the Council in general could be a "disaster" to a section or department.

**What Is Cyber Resilience?**

**Cyber Resilience** is the process of ; preparing for, mitigating, responding to and recovering from an emergency, which involves Cyber, that is a system or service, which is delivered by a network or the Internet, to a remote device, often through a web browser.

Business Continuity Planning is a dynamic process. Planning, though critical, is not the only component. Training, conducting exercises, testing equipment and co-ordinating activities with the community are other important functions.

**Making the "Case" for Cyber Resilience**

To be successful, Business Continuity Planning requires senior management support. The chief executive sets the tone by authorising planning to take place and directing senior management to get involved.

When presenting the "case" for Cyber Resilience, avoid dwelling on the negative effects of an emergency (e.g., deaths, fines, and criminal prosecution) and emphasise the positive aspects of preparedness. For example:

1\. It helps the Council fulfill its’ moral responsibility to protect employees, the community and the environment.

2\. It facilitates compliance with regulatory requirements such as Health & Safety.

3\. It enhances the Council’s ability to recover from financial losses, regulatory fines, complaints from members and the public, damage to equipment and business interruption.

4\. It reduces exposure to civil or criminal liability in the event of an incident.

5\. It enhances the Council’s image and credibility with employees, customers, suppliers and the community.

**SECTION 1**

**4 STEPS IN THE PLANNING PROCESS**

**Having established what your planning for (the scope)**

**Step 1 -- Establish a Planning Team** 

**Step 2 -- Analyse Capabilities and Hazards**

**Step 3 -- Develop the Plan** 

**Step 4 -- Implement the Plan**

## STEP 1 -- ESTABLISH A PLANNING TEAM.

![](/files/-MeUr__eMMhiNap0wGT3)

**There must be an individual or group in charge of developing the Business Continuity Plan. The following is guidance for making the appointment.**

**1. Form the Team.**

The size of the planning team will depend on the department’s operations, requirements and resources. Usually involving a group of people is best because:

a. It encourages participation and gets more people invested in the process. b. It increases the amount of time and energy participants are able to give. c. It enhances the visibility and stature of the planning process. d. It provides for a broad perspective on the issues.

Determine who can be an active member and who can serve in an advisory capacity. In most cases, one or two people will be doing the bulk of the work.

Some of the planning and co-ordination, could be out sourced to the Emergency Planning .At the very least, you should obtain input from all functional areas. Remember:

1. Senior management  
2. Line management  
3. Personnel and Occupational Health  
4. Engineering and maintenance  
5. Health & Safety  

f. Public information officer (Press & Publicity)

1. Security  
2. Community relations and groups  
3. &#x20;Councillors as appropriate  
4. Departmental Representatives (Operational Service Delivery)  
5. Legal Services  
6. Finance and purchasing  

Have participants appointed in writing by senior management. Their job descriptions could also reflect this assignment and extra duties.

**2. Establish Authority.**

Demonstrate management's commitment and promote an atmosphere of empowerment by "authorising" the planning group to take the steps necessary to develop a plan. The Chief Officer or the Business Unit Manager should lead the group. Establish a clear line of authority between group members and the group leader, though not so rigid as to prevent the free flow of ideas.

**3. Issue a Mission Statement – Which quantifies the purpose and scope of the plan.**

Have the Chief Executive or Service/Business Unit Manager issue a mission statement to demonstrate the authority’s commitment to Cyber Resilience. The statement should:

Define the purpose of the plan and indicate that it will involve the entire organisation. Define the authority and structure of the planning group

**4. Establish a Schedule and Budget**

Establish a work schedule and planning deadlines. Timelines can be modified as priorities become more clearly defined.

Develop an initial budget for such things as research, printing, seminars, consulting services and other expenses that may be necessary during the development process.

## STEP 2 -- ANALYSE CAPABILITIES AND HAZARDS.

This step entails gathering information about current capabilities and about possible hazards and emergencies, and then conducting a vulnerability analysis to determine the facility's capabilities for handling emergencies.

**1. WHERE DO YOU STAND RIGHT NOW? Establishing a baseline**

Review Internal Plans and Policies. Documents to look for include:

a. Evacuation plan

1. Fire protection plan  
2. Health \&Safety procedures  

d Environmental policies

1. Security procedures  
2. Insurance programs  
3. Finance and purchasing procedures  
4. Quality Procedures  
5. Personnel Handbook  
6. Internal SLAs and External Contracts.  
7. Health & Safety risk assessments  
8. Risk management plan  

m Capital improvement program n. Mutual aid agreements

Business Continuity Planning Guide

**2. Establish Partnerships**

Meet with external agencies, community organisations and utilities. Ask about potential emergencies and about their plans and available resources for responding

Sources of information include:

* Local Resilience Forum Cooridnator
* Emergency Planning Officer
* Local Hospital 
* Local Community
* Liaison Groups Fire Brigade
* Local Police Ambulance Emergency Planning Officer 
* Telecommunications Companies
* Cellular providers
* Electric,
* Gas and Water Utilities 
* Neighbouring Authorities 

Web sites see: <http://www.ukresilience.info/contingencies/cont\\_index.htm> Business Continuity Institute see: [www.thebci.org](http://www.thebci.org) Association of Local Authority Risk Managers <http://www.alarm-uk.com/> Society of Information Technology Management SOCITM: [www.socitm.net](http://www.socitm.net/)

Emergency Planning Society :<http://www.emergplansoc.org.uk/>

**3. Identify Codes and Regulations**

Identify applicable legislation and local regulations such as:

Occupational Health & Safety regulations Environmental regulations Fire procedure codes Corporate policies

**4. Identify Critical Services and Operations**

You'll need this information to assess the impact of potential emergencies and to determine the need for backup systems. Areas to review include:

1. Council services and the facilities and equipment needed to produce them  
2. Products and services provided by suppliers, especially sole source vendors  
3. Lifeline services such as electrical power, water, sewer, gas, telecommunications  and transportation  
4. Operations, equipment and personnel vital to the continued functioning of the  facility  

**5. Identify Internal Resources and Capabilities**

Resources and capabilities that could be needed in an emergency include:

**a. Personnel** -- Fire, Police and Ambulance Council Emergency services response team, security, Business Continuity Planning group, Fire wardens, First Aid, Public Information Officers. Computer Emergency Response Team

**b. Equipment** -- fire protection and suppression equipment, communications equipment, first aid supplies, emergency supplies, warning systems, emergency power equipment.

**c. Facilities** – Establish a Crisis Management Centre (, media briefing area, survivor reception centres, first-aid stations. Communications point, internal and external. An emergency website, either part of the corporate one or separate. Make sure people know the address of it.

**d. Organisational capabilities** -- training, evacuation plan, employee support system (Counselling)

**e. Backup systems** -- arrangements with other facilities to provide for: Identify your Business critical processes and systems.

* (1)  Payroll  
* (2)  Communications  
* (3)  Production  
* (4)  Customer services  
* (5)  Post room services and receiving i.e. CFM print runs  
* (6)  Information systems support  
* (7)  Emergency power  
* (8)  Recovery support  

**6. Identify External Resources**

There are many external resources that could be needed in an emergency. In some cases, formal agreements may be necessary to define the facility's relationship with the following:

1. Local Resilience Forum (LRF) 
2. Fire Brigade  
3. Hazardous materials Health & Safety Executive  
4. Emergency medical services
5. Hospitals  
6. Local Police liaison
7. Community service organisations  
8. Utilities  
9. Key Contractors & Suppliers

**7. Suppliers of emergency equipment**

Insurance companies

**Do an Insurance Review**

Meet with Insurance Officer (Finance Dept) to review all policies and cover. (See Section 2: Recovery and Restoration.) Insurance is not a substitution to proper planning and preparedness.

**8. Conduct A Vulnerability (Risk) Analysis**

The next step is to assess the vulnerability of your site -- the probability and potential impact of each emergency. Use the Vulnerability (Risk) Analysis Chart in the appendix section to guide the process, which entails assigning probabilities, estimating impact and assessing resources, using a numerical system. The lower the score the better.

**9. Brainstorm Potential Emergencies & Scenarios to plan for**

In the first column of the chart, list all emergencies that could affect your department, including those identified by the Emergency Planning officer. Consider both:

a. Emergencies that could occur within your Site / Department b. Emergencies that could occur in your community

**Historical** -- What types of emergencies have occurred in the community, at this facility and at other facilities in the area?

a. b. c. d. e. f. g. h.

Fires Severe weather Hazardous material spills Transportation accidents Bomb threats

Transport strikes Terrorism and Industrial action

Utility outages

**Geographic** -- What can happen as a result of the facility's location?

Keep in mind:

1. Proximity to flood spots, electrical lines, railways, major roads etc.  
2. Proximity to companies that produce, store, use or transport hazardous material  
3. Proximity to major transportation routes and airports  
4. Proximity to terrorist targets.  

**Technological** -- What could result from a process or system failure? Possibilities include:

1. Fire, explosion, hazardous materials incident - storage batteries  
2. Safety system failure  
3. Telecommunications failure  
4. Computer system failure  
5. Power failure  
6. Heating/cooling system failure  
7. Emergency notification system failure  

**Human Error** -- What emergencies can be caused by employee error? Are employees trained to work safely? Do they know what to do in an emergency? Human error is the single largest cause of workplace emergencies and can result from:

1. Poor training  
2. Poor maintenance  
3. Carelessness  
4. Misconduct  
5. Substance abuse  

f. Fatigue

**Physical** -- What types of emergencies could result from the design or construction of the facility? Does the physical facility enhance safety? Consider:

a. The physical construction of the facility b. Hazardous processes or by-products c. Facilities for storing combustibles 

d. Layout of equipment

e. Lighting

1. Evacuation routes and exits  
2. Proximity of survivor reception centres  

**Regulatory** -- What emergencies or hazards are you regulated to deal with? Analyse each potential emergency from beginning to end. Consider what could happen as a result of:

1. Prohibited access to the facility  
2. Loss of electric power  
3. Communication lines down  
4. Ruptured gas mains  
5. Water damage  
6. Smoke damage  
7. Structural damage  
8. Air or water contamination  
9. Explosion  
10. Building collapse  
11. Trapped persons  
12. Chemical release  

**10. Estimate Probability**

In the Probability column, rate the likelihood of each emergency's occurrence. This is a subjective consideration, but useful nonetheless. Use a simple scale of 1 to 5, with 1 as the lowest probability and 5 as the highest.

**11. Assess the Potential Human Impact (HARM Modelling)**

Analyse the potential human impact of each emergency -- the possibility of death or injury.

Assign a rating in the Human Impact column of the Vulnerability Analysis Chart. Use a 1 to 5 scale with 1 as the lowest impact and 5 as the highest.

**12. Assess the Potential Property Impact**

Consider the potential property for losses and damages. Again, assign a rating in the Property Impact column, 1 being the lowest impact and 5 being the highest. Consider:

1. Cost to replace  
2. Cost to set up temporary replacement  
3. Cost to repair  

**13. Assess the Potential Business Impact**

Consider the potential loss of market share. Assign a rating in the Business Impact column. Again, 1 is the lowest impact and 5 the highest. Assess the impact of the following. This applies to your Department and your external (CCT) suppliers if applicable. Check your SLA’s and Contracts.

1. Business interruption  
2. Employees unable to report to work  
3. Customers unable to reach facility  
4. Authority in violation of contractual agreements  
5. Imposition of fines and penalties or legal costs  
6. Interruption of critical supplies  
7. Interruption of Service Delivery  

**14. Assess Internal and External Resources**

Next assess your resources and ability to respond. Assign a score to your Internal Resources and External Resources. The lower the score the better. To help you do this, consider each potential emergency from beginning to end and each resource that would be needed to respond. For each emergency ask these questions:

**Do we have the needed resources and capabilities to respond?**

Will external resources be able to respond to us for this emergency as quickly as we may need them, or will they have other priority areas to serve?

If the answers are yes, move on to the next assessment. If the answers are no, identify what can be done to correct the problem. For example, you may need to:

1. Develop additional emergency procedures  
2. Conduct additional training  
3. Acquire additional equipment  
4. Establish mutual aid agreements  
5. Establish agreements with specialised contractors

**15. Add the Columns**

Total the scores for each emergency. The lower the score the better. While this is a subjective rating, the comparisons will help determine planning and resource priorities -- the subject of the pages to follow.

## STEP 3 -- DEVELOP THE PLAN

You are now ready to develop a Business Continuity Planning plan. This section describes how.

**PLAN COMPONENTS**

Your plan should include the following basic components.

**1. Executive Summary**

The executive summary

Gives management a brief overview of the purpose of the plan Details the Business Continuity Planning policy Authorises the facilities and responsibilities of key personnel; Details the types of emergencies that could occur

Explains how and where response operations will be managed.

 **2. Business Continuity Planning Elements** This section of the plan briefly describes the facility's approach to the core elements

Cyber Resilience, which are:

Command and control Communications Life and Limb - protecting your staff and the public. Property protection Community outreach Recovery and restoration Administration and logistics.

These elements, which are described in detail in Section 2, are the foundation for the emergency procedures that your facility will follow to protect personnel and equipment and resume operations.

**3. Emergency Response Procedures**

The procedures spell out how the facility will respond to emergencies. Whenever possible, develop them as a series of checklists that can be quickly accessed by Senior Management, Department heads, response personnel and employees.

Determine what actions would be necessary to:

1. Assess the situation  
2. Protect employees, customers, visitors, equipment, vital records and other  assets, particularly during the first phase of the emergency  
3. Get the business back up and running.  

Specific procedures might be needed for any number of situations such as bomb threats or fire, and for such functions as:

Warning employees and customers Communicating with personnel and community responders Conducting an evacuation and accounting for all persons in the facility Managing response activities Activating and operating an emergency operations centre Fighting fires Shutting down operations Protecting vital records Restoring operations

**4. Support Documents**

Documents that could be needed in an emergency include:

Emergency call lists -- lists (wallet sized if possible) of all persons on and off site who would be involved in responding to an emergency, their responsibilities and their 24-hour telephone numbers.

Building and site maps that indicate:

1. Utility shutoffs  
2. Water hydrants  
3. Water main valves  
4. Water lines  
5. Gas main valves  
6. Gas lines  
7. Electrical cut-offs  
8. Electrical substations  
9. Storm drains  
10. Sewer lines  
11. Location of each building (include name of building, street name and number)  
12. Floor plans  
13. Alarm and communicators  
14. Fire extinguishers  
15. Fire suppression systems  
16. Exits  
17. Stairways  
18. &#x20;Designated escape routes  
19. Restricted areas  
20. &#x20;Hazardous Materials (including cleaning supplies and chemicals)  
21. Copies of building plans  
22. Copies of telecommunication route plans (Telephone and fibre cables)  
23. Location of High-value items; (Deeds, Bonds, Contracts, evidence etc.)  

**5.Resource lists**

Lists of major resources (equipment, supplies, and services) that could be needed in an emergency; mutual aid agreements with other companies and government agencies.

1. Emergency escape procedures and routes  
2. Procedures for employees who perform or shut down critical operations before an evacuation  
3. Procedures to account for all employees, visitors and contractors after an evacuation is completed  
4. Rescue and medical duties for assigned employees  
5. Procedures for reporting emergencies  
6. Names of persons or departments to be contacted for

**THE DEVELOPMENT PROCESS**

The following is guidance for developing the plan.

**1. Identify Challenges and Prioritise Activities**

Determine specific goals and milestones. Make a list of tasks to be performed, by whom and when. Determine how you will address the problem areas and resource shortfalls that were identified in the vulnerability analysis.

**2. Write the Plan**

Assign each member of the planning group a section to write. Determine the most appropriate format for each section.

Establish an aggressive timeline with specific goals. Provide enough time for completion of work, but not so much as to allow assignments to linger. Establish a schedule for:

1. First draft  
2. Peer review (include other sections)  
3. Second draft  
4. Tabletop exercise (invite other sections/departments to participate)  
5. Final draft  
6. Printing  
7. Distribution publish widely including intranet – share best practise  
8. Amendments procedures  

**3. Establish a Training Schedule**

Have one person or department responsible for developing a training schedule for your facility. For specific ideas about training, refer to Step 4.

**4. Coordinate with Outside Agencies and Organisations**

Meet periodically with other government agencies and community organisations. Inform appropriate government agencies that you are creating a Business Continuity plan. While their official approval may not be required, they will likely have valuable insights and information to offer.

Determine central government and local requirements for reporting emergencies, and incorporate them into your procedures. Appoint a ‘logist’ to keep detailed records of all executive orders, actions and operations. Number and time record all options. This will include actions, outcomes and costs incurred, along with details of who authorised the actions.

### Trigger Points and Protocols

The CRASH Gates Protocol Trigger Points can be thought of a pre-defined Consequence Relevance Acceleration Severity and Harm (CRASH) Gates.

The CRASH Gate model for assessing Cyber incident trigger points;

**Consequence Scaling**

1. Locally contained within the Organisation at a Sub-Departmental / Directorate Level
2. Locally contained within the Organisation at Departmental / Directorate Level
3. Local contained within the Organisation
4. Affecting multiple Organisations Sub-Regionally
5. Affecting multiple Organisations Regionally
6. Affecting multiple Organisations Nationally

**Relevance Scoring**

1. We do not have this technology in our infrastructure
2. We have this technology, we are fully patched.
3. We have this technology, we are partially patched
4. We have this technology, we are not patched
5. We have this technology, we are compromised

**Severity Scoring**

1. Not affecting our infrastructure directly
2. Affecting some of our infrastructure
3. Affecting most of our infrastructure
4. Affecting all of our infrastructure
5. Our infrastructure is over run and non-functioning

**HARM Levels**

1. The organisation is unaffected
2. The organisation is affected, but fully operational
3. The organisation is affected, and is partially operational
4. The organisation is compromised essential services still functioning
5. The organisation is compromised essential services lost.

**Determine protocols and trigger points for turning command and control of a response over to outside agencies.**

Some details that may need to be worked out are:

1. Which gate or entrance will responding emergency service units use?  
2. Where and to whom will they report?  
3. How will they be identified? How will they know you? (tabards/ID)  
4. How will facility personnel communicate with outside responders?  
5. Who will be in charge of response activities?  

Determine what kind of identification authorities (Police/Fire) will require to allow your key personnel into your facility during an emergency. Develop and agree special ID cards and tabards etc. Ensure everyone is thoroughly briefed.

Produce A4 laminated cards which detail the key roles and responsibilities for each job.

Produce a pocket size card, with emergency contact numbers, and the five major points of the job role, where to report to etc.

Determine the needs of disabled persons and non-English-speaking personnel. For example, a blind employee could be assigned a partner in case an evacuation is necessary.

A disabled person is anyone who has a physical or mental impairment that substantially limits one or more major life activities, such as seeing, hearing, walking, breathing, performing manual tasks, learning, caring for oneself or working.

Be mindful of language barriers, written and verbal.

Your emergency planning priorities may be influenced by government regulation. To remain in compliance you may be required to address specific Business Continuity Planning functions that might otherwise be a lower priority activity for that given year.

**5. Maintain Contact with Other Departments**

Communicate with other offices and departments within the authority to learn:

1. Their emergency notification requirements 
2. The conditions where mutual assistance would be necessary 
3. How offices will support each other in an emergency 
4. Names, email, telephone numbers and mobile numbers of key personnel Incorporate this information into your procedures.

**6. Conduct Training and Revise plans and procedures as necessary.**

Share review information with other Departmental representatives. Use the Intranet server to publish timely information

Distribute the first draft to group members for review. Revise as needed.

For a second review, conduct a tabletop exercise with management and personnel who have a key Business Continuity Planning responsibility. In a conference room setting, describe an emergency scenario and have participants discuss their responsibilities and how they would react to the situation. Based on this discussion, identify areas of confusion and overlap, and modify the plan accordingly.

**7. Seek Final Approval**

Arrange a briefing for the Chief Officer and Senior Management and obtain written approval.

**8. Distribute the Plan**

Place the final plan in four-ring binders and number all copies and pages. Document control procedures are essential for quality and auditing.

Each individual who receives a copy should be required to sign for it and be responsible for posting subsequent changes.

Ensure the plan is published on the Intranet and kept up to date. Consider storing the plan on a secure Internet facility, this will ensure authorised people can access the plan from anywhere.

Determine which sections of the plan would be appropriate to show to other agencies (some sections may refer to Confidential Corporate or Departmental Information or include private listings of names, telephone numbers or access codes and passwords). Distribute the final plan to:

1. Chief Officers and Senior Managers  
2. Key members of the authority's emergency response organisation  
3. Chief Executives Office,  
4. Emergency Planning Unit.  
5. Community emergency response agencies (appropriate sections)  
6. Key external suppliers. Ensure you figure in their emergency plans.  

Have key personnel keep a copy (paper or electronic) of the plan in their homes? Inform employees about the plan and

Consolidate emergency plans for better co-ordination. Stand-alone plans, such as Computer Disaster Recovery Plans, Fire Protection plan or Health and Safety plan, should be incorporated into one comprehensive plan.

## STEP 4 -- IMPLEMENT THE PLAN

Implementation means more than simply exercising the plan during an emergency. It means acting on recommendations made during the vulnerability analysis, integrating the plan into authority operations, training employees and evaluating the plan.

**INTEGRATE THE PLAN INTO DEPARTMENTAL OPERATIONS**

Emergency planning must become part of the corporate culture.

Look for opportunities to build awareness; to educate and train personnel; to test procedures; to involve all levels of management, all departments and where appropriate the community in the planning process; and to make Business Continuity Planning part of what personnel do on a day-to-day basis.

Include the emergency procedures into induction training. Ensure the emergency procedures are discussed at a quarterly management

meeting as an agenda item. Build the process into all project plans.

**Test how Completely the Plan has been Integrated by Asking**:

![](/files/-MeUr__fj1ZV5sZRyk8p)

How well does senior management support the responsibilities outlined in the plan?

Have emergency planning concepts been fully incorporated into the Department’s accounting, personnel and financial procedures?

How can the Council’s processes for evaluating employees and defining job classifications better address Business Continuity Planning responsibilities?

Are there opportunities for distributing emergency preparedness information through corporate newsletters, employee manuals or employee mailings?

What kinds of safety posters or other visible reminders would be helpful? Do personnel know what they should do in an emergency? 

**CONDUCT TRAINING, EXERCISES AND EXERCISES**

Everyone who works at or visits (Contractors) the site requires some form of training. This could include periodic employee discussion sessions to review procedures, technical training in equipment use for emergency responders, evacuation exercises and full-scale exercises. Below are basic considerations for developing a training plan.

**1. Planning Considerations**

Assign responsibility for developing a training plan. Consider the training and information needs for employees, contractors, visitors, managers and those with an emergency response role identified in the plan. Determine for a 12 month period:

1. Who will be trained?  
2. Who will do the training?  
3. What training activities will be used?  
4. When and where each session will take place?  
5. How the session will be evaluated and documented?  

Use the Training Exercises and Exercises Chart in the appendix section to schedule training activities or create one of your own.

Consider how to involve community responders in training activities. Conduct reviews after each training activity. Involve both personnel and community responders in the evaluation process.

**2. Training Activities**

Training can take many forms:

**a. Orientation and Education Sessions (Discussion Exercises)** These are regularly scheduled discussion sessions to provide information, answer questions and identify needs and concerns.

**b. Tabletop Exercise** -- Members of the Business Continuity Planning group meet in a conference room setting to discuss their responsibilities and how they would react to emergency scenarios. This is a cost-effective and efficient way to identify areas of overlap and confusion before conducting more demanding training activities.

**c. Walk-through Exercise** -- The Business Continuity Planning group and response teams actually perform their emergency response functions. This activity generally involves more people and is more thorough than a tabletop

**d. Functional Exercises** -- These exercises test specific functions such as medical response, emergency notifications, warning and communications procedures and equipment, though not necessarily at the same time. Personnel are asked to evaluate the systems and identify problem areas.

**e. Evacuation Exercise** -- Personnel walk the evacuation route to a designated area where procedures for accounting for all personnel are tested. Participants are asked to make notes as they go along of what might become a hazard during an emergency, e.g., stairways cluttered with debris, smoke in the hallways. Plans are modified accordingly.

**f. Full-scale Exercise** -- A real-life emergency situation is simulated as closely as possible. This exercise involves authority emergency response personnel, employees, management and community response organisations.

**3. Employee Training**

General training for all employees should address:

1. Individual roles and responsibilities  
2. Information about threats, hazards and protective actions  
3. Notification, warning and communications procedures  
4. Means for locating family members in an emergency  
5. Emergency response procedures  
6. Evacuation, shelter and accountability procedures  
7. Location and use of common emergency equipment  
8. Emergency shutdown procedures  

The scenarios developed during the vulnerability analysis can serve as the basis for training events.

**4. Evaluate and Modify the Plan**

Conduct a formal audit of the entire plan at least once a year. Among the issues to consider are:

1. How can you involve all levels of management in evaluating and updating the plan?  
2. Are the problem areas and resource shortfalls identified in the vulnerability analysis being sufficiently addressed?  
3. Does the plan reflect lessons learned from exercises and actual events?  
4. Do members of the Business Continuity Planning group and emergency response team understand their respective responsibilities? Have new members been trained?  
5. Does the plan reflect changes in the physical layout of the facility? Does it  reflect new facility processes?
6. &#x20;Are photographs and other records of facility assets up to date?  
7. Is the facility attaining its training objectives?  
8. Have the hazards in the facility changed? (H\&S Risk Assessments)  
9. Are the names, titles and telephone numbers in the plan current?  
10. Are steps being taken to incorporate Business Continuity Planning into the business processes?  
11. Have community agencies and organisations been briefed on the plan? Are they involved in evaluating the plan?  

**In addition to a yearly audit, evaluate and modify the plan at these times:**

1. After each training exercise  
2. After each emergency  
3. When personnel or their responsibilities change  
4. When the layout or design of the facility changes  
5. When policies or procedures change  
6. Remember to brief personnel on changes to the plan.  

**Audit:**

Conduct a formal audit of the entire plan at least once a year

Appendix A

&#x20;![](/files/-MeUr__ggWVpleH-mYTS) ![](/files/-MeUr__hu7Y-ODBg5olX)

Business Continuity Planning Toolkit with Risk Assessment diagnostics

&#x20;![](/files/-MeUr__irtOF189Mecpk) ![](/files/-MeUr__jnjMLhj0wn-C2)

![](/files/-MeUr__kiKmzSVqyWNxB)

**Organisation Name \[BUSINESS CONTINUITY PLAN COMPONENTS]**

**\[Change all headings as required]**

**Directorate / Department:**

**Contact Name:** 

**E-Mail:**

1. **Business Continuity Planning Outline**  
2. **Business Continuity Plan Template**  

**III. Business Continuity Plan Worksheets A. Checklist**

**B. Business Process Template C. Recovery Procedures Template D. Risk Assessment Worksheets**

**Date Completed:**

**Phone:**

**Written by: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_Date:\_\_\_\_\_\_\_\_\_\_\_\_ Written by: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_Date:\_\_\_\_\_\_\_\_\_\_\_\_**

**Review Date: \[. ]**

## **I. Business Continuity Planning Outline Phase One**

* &#x20; Identify Current Mission-Critical Business Processes (See Operations Plan for starting point)  
* &#x20; Assess Impact or Importance of Business Processes, considering:  
* &#x20; Health and Safety  
* &#x20; Revenue or Cash Flow (Treasury) implications  
* &#x20; Number of Citizens, Businesses, or Employees Impacted  
* &#x20; Central Government Reporting Requirements  

Public Perception

* &#x20; Identify Resources and Dependencies  
* &#x20; Evaluate Risk or Likelihood of Failure  
* &#x20; Application Systems and Interfaces  
* &#x20; IT Infrastructure  

Third Party Products

* &#x20; Supply Chain  
* &#x20; Infrastructure (Facilities, Telecom, Utilities)  

Establish Priority Based upon Impact and Risk

## **Phase Two**

Develop Business Continuity Plan Based upon Available Resources and Time Make Assumptions to Focus Plan

Devise Alternatives to Complete Core Business Processes, considering: Roles & Responsibilities Communication Channels Manual Work arounds

Triggering Events Who Invokes the Plan Required Training & Preparation How & Who Maintains the Plan Needed Supplies & Equipment Additional Staffing Needs What Ends the Plan Clean-Up

Review for Completeness

## **Phase Three**

Exercise the Plan Make Modifications as Needed

**II. Business Continuity Plan Template**

The following sections are included in a Contingency Plan Template. It is a sample template, therefore, sections may be added or deleted as appropriate.

**Phase I**

PROCESS: Provide the name and a brief overview of the critical business function as it

currently exists. PRIORITY:

Determine the priority of this contingency plan relative to the other contingency plans, if multiple failures occur within an authority. *Use this section if applicable.*

RISK DESCRIPTION:

* &#x20; Describe in simple terms the risk concern and the impact to the authority. Include the nature and likelihood of expected disruptions or impacts. *For example:*- *Electrical power is unavailable. If processing cannot be resumed within 3 days, Client checks will be late.*  
* &#x20; Describe briefly any significant dependencies or linkages of the business process with programs within the authority, with other authorities, or with other parties either inside or outside of central or regional or place based partnership  
* &#x20; State explicitly any assumptions, which your Directorate or Business Unit is making in this contingency plan.  MITIGATING STRATEGIES:  

![](/files/-MeUr__lvkskiHtIKirJ)

Provide a brief conceptual description of how the contingency plan for the business process is intended to work.

*For example:- Conduct additional quality assurance review of documents prior to mailing.*

*Set up account in advance with alternate supplier(s) and establish procedures for using the alternate supplier.*

*Investigate feasibility and cost of an uninterruptible power supply.*

Describe the level of services to be provided during the disruption.

*For example:*

*Provide continuation of normal operations.*

*Provide continuation of service in a degraded mode.*

*Provide complete departure from normal functions as quickly*

Business Continuity Planning Guide

![](/files/-MeUr__mfbS11usHtTYx)

**Phase 2**

**ACTIVATION TRIGGER(S):** Describe the specific events or conditions that will trigger or invoke the plan.

*For example:*

*Employees can’t access building entry via electronic access cards or tokens.*

**RECOVERY PROCEDURES:**

* &#x20; Describe the expected life or duration of the contingency plan.  *For example: How long it might be necessary to operate under the plan.*  *Any special timing-related constraints, e.g., back-up batteries need re-charging after 10 hours.*  
* &#x20; Provide detailed, step-by-step procedures for initiating and executing contingency operations, and for transitioning back to normal (non-contingency) operations with the names of the persons who are to serve specific roles regarding the plan.  *For example: Initiate internal and vendor list notification procedures – Responsibility: Ms. X Get backup listings from off-site storage – Responsibility: Mr. Y Contact alternate supplier to provide needed supplies – Responsibility:*  

**IMPLEMENTATION:**

Name BCP Coordinator and Team

Provide the name and contact information of the person who will give the order to invoke the plan.

Provide the name of the person who will give the order to return to normal operations.

Provide a brief description of significant resources needed to implement, execute, and transition out of contingency operation. Also identify the person who is responsible for acquiring these resources, as events may warrant.

*For example: Staffing and scheduling of personnel. Equipment, temporary hardware and software, forms and supplies, etc. Possible temporary working facilities. Communications, both verbal and data.*

**Phase 3**

Provide a brief description of any training or exercising of the plan that will be necessary.

*For example: Perform a structured walk-through to ensure that all the processes will work as expected.*

*Perform an exercise or “dry-run” to ensure that all the processes work.*

*Perform a “mock” exercise with required staff and vendors on a non-work day.*

In continuity planning, the maintenance process ensures that people and process aspects of the plan which need additional work are properly addressed and corrected.

The following types of maintenance should be conducted for every business continuity plan in your Directorate or Business Unit:

o Scheduled o Unscheduled o Post exercised

## **BUSINESS CONTINUITY PLANNING WORKSHEETS**

**A. Checklist** 

**B. Business Process Template** 

**C. Recovery Procedures Template**

**D. Risk Assessment Worksheets**

**COMPONENTS OF A Cyber Resilience Plan**

***CHECKLIST***

![](/files/-MeUr__nf5tFY1lf6vgR)

**Checklist Components**

**AUTHORITY: Authority Name \* PROCESS: Business Process Name \*** Business Process Overview **PRIORITY:**

Priority within authority

**RISK DESCRIPTION:**

Risk Description Impact of Risk on Authority Nature and likelihood of disruptions Dependencies upon business process Assumptions **MITIGATING STRATEGIES:** Mitigating Strategies description Level of service to be provided

**ACTIVATION TRIGGER(S): Activation Trigger(s) \*** 

**RECOVERY PROCEDURES:** Duration of contingency plan **Recovery Procedures/Work-Around \*** Responsible person for each action

**IMPLEMENTATION:** Person invoking plan Person ordering return to normal operations **Resources Required \***

**MAINTAINING/EXERCISING PLAN** Training Required Exercising Required Person responsible to obtain resources Maintenance Required

![](/files/-MeUr__oxMFvxjwG0Kbr) ![](/files/-MeUr__p6cTTTliv5Wkw) ![](/files/-MeUr__qjrlNN06pKUC6) ![](/files/-MeUr__rJ3miITrykSzs) ![](/files/-MeUr__sHyuCmin7Cv89) ![](/files/-MeUr__tWl2Almt7pWA3) ![](/files/-MeUr__uEFNsvSxAlULZ) ![](/files/-MeUr__vEgdfoK_4I1Ii) ![](/files/-MeUr__wYiioJxnnzExT) ![](/files/-MeUr__xABWyjjLfkWsy) ![](/files/-MeUr__yr7NCdbPWAAIO) ![](/files/-MeUr__z9sFPHbYuBP7y) ![](/files/-MeUr_a-N6djIbI9jzbC) ![](/files/-MeUr_a0GvnBlC0UDsyT) ![](/files/-MeUr_a1I2ZUQx6h-aqi) ![](/files/-MeUr_a2tphRYkqKQ9En) ![](/files/-MeUr_a38OH-p19M_ZMH) ![](/files/-MeUr_a4CD-GYIetN0wd) ![](/files/-MeUr_a5ltTx4tBrQm0Q) ![](/files/-MeUr_a6SiyTtZPdzNeX) ![](/files/-MeUr_a7qGL08mgk9sNY) ![](/files/-MeUr_a8cbMNIWgv2Vlp) ![](/files/-MeUr_a9Rgoa6nHTW_Ur) ![](/files/-MeUr_aAp99Q4GmEPmxe) ![](/files/-MeUr_aBT-is3zMlhpUP) ![](/files/-MeUr_aCSBtPIqiFQ14S) ![](/files/-MeUr_aDl3MFvdfqZ42I) ![](/files/-MeUr_aEhKCWWnIBNlc8) ![](/files/-MeUr_aFdWwe2SowPrRS) ![](/files/-MeUr_aGz0nzM4bo3NZb) ![](/files/-MeUr_aH1jt1MCSTXnf2) ![](/files/-MeUr_aIvRc3rZnOlct1) ![](/files/-MeUr_aJc0YzCISRdUxt) ![](/files/-MeUr_aKbN9exrKtS1Be) ![](/files/-MeUr_aLwVU0L5qfu3NP) ![](/files/-MeUr_aM511eJwBBocUF) ![](/files/-MeUr_aNUdzdeOMEx2eD) ![](/files/-MeUr_aOIrzLF7GYlFUu) ![](/files/-MeUr_aPoFxySM9Tllda)

![](/files/-MeUr_aQ6MUhmJmZATSm)

**Business Process \[Title]**

**Process**:

**Priority**:

**Risk Description:**

**Mitigating Strategies:**

**Activation Trigger(s):**

**CONTINGENCY PLAN**

![](/files/-MeUr_aRhWnW1yws-37Q)

**RECOVERY PROCEDURE ACTION PLAN Recovery Procedures (Action Plan)**:

**Duration:**

**Implementation**: **Person Responsible:**

**Invokes Plan:**

**Return to Normal Operations:**

**Resources Required:**

*(Staff, supplies, etc.)*

![](/files/-MeUr_aSahqOjignN_j2)

| **Procedures Responsibility**                                                   |
| ------------------------------------------------------------------------------- |
| **1.**                                                                          |
| **2.**                                                                          |
| <p><strong>3.</strong></p><p><img src="/files/-MeUr_aT58Min-CwWCrQ" alt=""></p> |
| **4.**                                                                          |

![](/files/-MeUr_aUvmP0T3o5SUKk)

## **Sample Risk Assessment Worksheet**

Purpose and Directions Purpose:

This worksheet is intended to provide a framework for answering the following questions for a particular business process:

1. Where could a potential failure occur?  
2. Does it impact this business process? If so, how much?  
3. What has been done or is in progress to mitigate the threat of a failure?  

*Based on the answers to the above questions:* 4. What is the remaining risk?

By answering the last question, you should be in a better position to focus your contingency planning efforts, particularly which business processes are most in need of contingency planning and what specific failures do the contingency plans need to address and at what level of detail.

Directions:

1\.

2\.

3\.

4\.

5\.

6\.

Choose a particular business process.

Review the areas of concern to determine if any need to be added or expanded upon that are specific to the business process. Modify spreadsheet as

appropriate. Note: the Remediation or Mitigation Status Values are stored in columns E-I, which are hidden.

For each area of concern, assign a level of dependency of High, Medium, Low, or Not Applicable (or blank).

Choose from the drop-down list of choices for the Remediation or Mitigation Status. This information will most likely come from the individuals within your authority that are responsible for status reports. If the choices do not properly reflect your status, type in your own status description.

Based on the level of dependency and the remediation or mitigation status, assess the remaining risk and assign a value of High, Medium, or Low. Alternatively, you may choose to comment on your analysis rather than assign a specific level of risk.

Once you have determined the highest remaining risk areas, focus your Contingency Planning initiative to address the risk areas. This would include which business processes need contingency plans, how detailed the plans should be, and

**RISK ASSESSMENT WORKSHEET**

Directorate/ Business Unit

![](/files/-MeUr_aVvLKO9ASaffKR)

**Business Process:**

**Areas of Concern Mitigation status**

**Risk Assessment (H/M/L)**

**Level of Dependency (H/M/L)**

![](/files/-MeUr_aW-iwzntZGPFSZ)

| APPLICATION SYSTEMS | ![](/files/-MeUr_aXy9-xjIOkB-Wr) ![](/files/-MeUr_aYX0IYrKZ-miMH) |
| ------------------- | ----------------------------------------------------------------- |

Hardware Operating System 

Third Party Software 

Utilities/Macros Date-Impacted

Custom Source Code/SCL 

Internal Interfaces 

External Interfaces (Banks, Government Agencies, Other NC)

Shared Data  Communications/Network

Hardware Operating System Third Party Software

Telephone Switches

Voice Mail Voice Response Units Customer Service Centre reliance Mobile Phones Pagers Fax

Power Water/Sewer Fire Alarm Systems Security Systems Building Control Systems Parking Control Systems

Application Interfaces Hardware Infrastructure Supplier Support

![](/files/-MeUr_aZecxbGqkJaz9F) ![](/files/-MeUr_a_EmJW8RDX7SF_) ![](/files/-MeUr_aaQkAbPpX7HubB) ![](/files/-MeUr_abveFZfUIUD_uK) ![](/files/-MeUr_acFQRk-48CfBC5) ![](/files/-MeUr_adTUrwisEnxV99) ![](/files/-MeUr_ae6eT6vhFrg1qI) ![](/files/-MeUr_afvQKkUf8aXIAh) ![](/files/-MeUr_ag5QfhGIQ_QHBe) ![](/files/-MeUr_ahqp0RXzgcybtZ) ![](/files/-MeUr_aiszE_RLppLtO8) ![](/files/-MeUr_ajbyU3psVi1j5q) ![](/files/-MeUr_aku6yW9o-4Da9e) ![](/files/-MeUr_al8u6NY1rpgJHz) ![](/files/-MeUr_am1Pei9NwFgLSf) ![](/files/-MeUr_an2sJgl5px9ksa) ![](/files/-MeUr_ao9fRuik2o5Ruy) ![](/files/-MeUr_ap-msKJci9GDCE) ![](/files/-MeUr_aq1jAiRQrQwj1N) ![](/files/-MeUr_arf7B5NcdnOSZj)

PC/LAN

![](/files/-MeUr_asODdZFi8342mE) ![](/files/-MeUr_atRWjXdds7XMNM) ![](/files/-MeUr_auTwwtYv_GV676) ![](/files/-MeUr_av6TPFPeC7T0Aa) ![](/files/-MeUr_awZAXykmz5bN-w) ![](/files/-MeUr_axf_MVTEFbCYtB) ![](/files/-MeUr_ayBsUVZp-IHhjJ) ![](/files/-MeUr_azP7AxTc69rT5s) ![](/files/-MeUr_b-SDoDPfm59vEX) ![](/files/-MeUr_b0qsusTPzlRJjz)

COMMUNICATIONS

![](/files/-MeUr_b1QU4ViEvUogiC) ![](/files/-MeUr_b211HPocY6TEBF) ![](/files/-MeUr_b35tcom0eIRMI_) ![](/files/-MeUr_b4w-68uYiG_5_V) ![](/files/-MeUr_b5Hy0jH7g3zwU9) ![](/files/-MeUr_b6X7iVEZklIekT) ![](/files/-MeUr_b7nU5YD5FQqp8j) ![](/files/-MeUr_b8aFiV_B-5Z8Bh) ![](/files/-MeUr_b9xnDwTkq3GYQ2) ![](/files/-MeUr_bAbmFBwWzLNVRr) ![](/files/-MeUr_bBED9-G932Cc9x) ![](/files/-MeUr_bC55S36tbaWGjx) ![](/files/-MeUr_bDbNz9TCC-QWAS) ![](/files/-MeUr_bEpCdlnVKMsFj-) ![](/files/-MeUr_bFNPRoq8pxxiBo) ![](/files/-MeUr_bG3loh8hz5ttT0) ![](/files/-MeUr_bHku9Ep65DtbWX) ![](/files/-MeUr_bI_sfTfLjrwV4m)

FACILITIES

![](/files/-MeUr_bJ73YTrtOVaGzd) ![](/files/-MeUr_bK0sTFlthobZFw) ![](/files/-MeUr_bLbJIffQvCUs5n) ![](/files/-MeUr_bM12BbyZcYV7lg) ![](/files/-MeUr_bN9TjPhDZQzFI_) ![](/files/-MeUr_bOP7DbRCFuKu_m) ![](/files/-MeUr_bPZMOXkURdFWsP) ![](/files/-MeUr_bQJUNduVZ3Ff0S) ![](/files/-MeUr_bRusRqlHJqFVLU) ![](/files/-MeUr_bS0Mx5nw4P--bJ) ![](/files/-MeUr_bTfnOUAUkejZgD) ![](/files/-MeUr_bUaJjfG5Fsrmzn) ![](/files/-MeUr_bVJ0OA4fWQelhz) ![](/files/-MeUr_bWfbDvTYltlox1) ![](/files/-MeUr_bXhLI1JgYjomZy)

DEPENDENCIES

![](/files/-MeUr_bYbYYt3fauhfqa) ![](/files/-MeUr_bZOgGAaKWSL3Sk) ![](/files/-MeUr_b_P9htESsRhcnK) ![](/files/-MeUr_basSlCpvTN1ECf) ![](/files/-MeUr_bbLpNZRlcpH-kD) ![](/files/-MeUr_bc1-cR5KsgQQxH) ![](/files/-MeUr_bdMn1BkPtMPP9m) ![](/files/-MeUr_beAId_OrF9vLm-) ![](/files/-MeUr_bftRmosrGMEW7h)


# Fast Time Cyber Collaboration & Communications

This paper brings together some concepts and ideas to support organisations in implementing Cyber Incident collaboration and Coordination, focussing on the need for fast time communications.

{% file src="/files/-MeiGOFH9LBd1ii0bciK" %}
Socitm Fast Time
{% endfile %}

{% file src="/files/-MeUuO7Rwv350G5NDeJz" %}
Fast Time Comms
{% endfile %}

**Fast Time Cyber Collaboration & Communications**

### **Background**

&#x20;This prime contains a wide range of references to be used in preparing your own plans, processes and approaches. The approach is aligned to ISO27010:2015\[80].

### **Fast time collaboration context**

This paper highlights outputs from the Welsh Government Cyber Security work programme (2017-2020) and augments them with reflections on the Fast Time Communications required to coordinate a multiagency cyber incident within the Wider Public Sector these approaches support ISO 27010, the standard for sharing information security advice and guidance, which is also supported by MISP\[ 80].

A Cyber Incident, its planning, response and recovery can be treated and operated as an unplanned project, therefore we contend project planning methods and approaches can be applied to Cyber Incident Response, this covers complex large scale enterprise project planning, using PRINCE\[77], through to the dynamic iterating approach of agile\[78]. Likewise Emergency Planners gain a lot of their insight and thought processes from Military Planners, which explains why military Planning and doctrine isn’t just applicable in warfare, it also works in other situations such as Cyber incident Response \[79] and as seen during the logistical planning of the Covid-19 pandemic.

### **Understanding the context for fast time collaboration**

Cyber Incidents are fast moving, dynamic and complex. Your often trying to resolve a situation without know what has actually happened and what it actually is. You find yourself responding to the symptoms, trying to stop the outbreak spreading, against a backdrop of continued operational service delivery. In short you want help, often peer support “Phone a friend”, through your WARP or similar. The NCSC will advise and assist, they have to focus on their “C3” and above type incidents, this means you need to put your own measures and coordination in place.

Systems Dynamics have been successfully used as an approach and methodology for mapping complex cyber attacks and to understand the evolving “Battle Space” of a Cyber incident. \[9,10,11]. Cyber is referred to as the fifth battle domain of armed conflict, as far back as 2011, \[13] even though most cyber attacks are against businesses, we mustn’t lose sight of the fact that nation states do now have cyber offensive capabilities \[14].

Cyber attacks are fast moving dynamic and remotely orchestrated. The initiating actors, could be on the other side of the world and can instantly initiate a polymetric attack from multiple locations, this in itself can cause confusion and necessitate the need for a Common Operating Picture \[15]. To build a common operating picture, requires all of the actors, operations, locations, techniques and processes to be quantified and documented. This approach allows for Situational Awareness to be developed, quantified, prioritised and communicated \[16].

### **Slow-time V Fast Time**

The heart of the collector-funnel model is the 2x2 grid that considers Slow time / Fast time communications coupled with Manual and Automated interventions. This we’ve called the Temporal Actions Matrix. This paper is focussing on the fast time aspects of communications, which can be thought of as dynamic and evolving. Slow time is often referred to a Busines As Usual “BAU”. Fast time operations and response are more dynamic, less predictable and may even mean that you can’t use your normal ICT channels as they are themselves affected.

!\[Diagram

Description automatically generated]\(/files/-MeUu6eQAbbBJqaSmLDy)

Figure 1 © Author NLAWARP Information Flow Funnel showing the embedded Temporal Actions Matrix

!\[Diagram

Description automatically generated]\(/files/-MeUu6eRM09iNSDw7Nw6)

Figure 2. The slow time / fast time event matrix

## **Planned Unplanned event matrix**

This work was started in the London Resilience team in 2003. The main point of this whole paper is to understand the two distinct modes of operation. That is business As Usual (BAU), which we refer to as *slow time* and when we “Flip the Switch or Push the Big RED Button”, which takes us into *fast time* response mode. It is also useful to think about planned and unplanned events and how those affect the response to a Cyber Incident. This is where Systems Dynamics can also help being able to produce causal maps to show interventions in Cyber Incident response and to be able to map out the causal variables and how they apply to systems, services, and processes \[9]. Most business entities and organisations are accustomed in to dealing with ad hoc incidents. The Emergency Services (Often referred to as “Blue Light Services”, in the UK are accustomed to flipping constantly from BAU to Incident Response, every time they get an emergency call. IT departments are dealing with incidents on a daily basis. For the purposes of this paper, we are talking about larger tangible incidents, their response and mitigation. Fast Time Communications in the context of this paper are talking about groups of individuals and organisations outside of a single entity \[29]. This phenomenon is looking at a “Trans Boundary Crisis” \[29]. The response to a trans boundary crisis is often referred to as “Crisis Management” in businesses and “Major Incidents” in the Emergency Services. The Emergency Services have a standardised approach to a Major Incident, it is clearly defined \[24];

“An event or situation with a range of serious consequences which requires special arrangements to be implemented by one or more emergency responder agency”.

Cyber Incidents do not have such a clear definition. The NCSC defines a cyber incident as \[25];

“A breach of a system's security policy in order to affect its integrity or availability and/or the unauthorised access or attempted access to a system or systems; in line with the Computer Misuse Act (1990).In general, types of activity that are commonly recognised as being breaches of a typical security policy are:

**1. Attempts to gain unauthorised access to a system and/or to data.**&#x20;

**2. The unauthorised use of systems for the processing or storing of data.**&#x20;

**3. Changes to a systems firmware, software or hardware without the system owners consent.**&#x20;

**4. Malicious disruption and/or denial of service.”**

(It should be noted the Computer Misuse Act(1990), is under review as of June 2021 \[26].

This is linked to the Integrated Review \[27], which is a review of Defence, including Cyber, reviewing the Computer Misuse Act will be a key to the next Cyber Strategy for the UK \[28], due in Autumn 2021, which must include further defence measures. The need for Fast time communications policy and guidance for Public Sector Organisations in the UK is therefore a requirement. This will include the development of Cyber Specific Guidance to support the Doctrine element of JESIP framework \[28] to enable it to be used for Incident Response in support of the Emergency Services.

## **Anatomy of a Cyber Incident**

You cannot control every element of a cyber attack. However, having good asset registers and diagrams, understanding your environment and being able to quantify what you can deal with goes a long way.

For instance, if you lose access to a system or service through a communications network outage, then you may be wholly reliant on an external utility provider to be able to restore the service for you. If you were notified about planned maintenance a week in advance, it would be a planned slow time event, whilst the actual outage would still likely present some unforeseen issues to be resolved. Knowing who is critical in a process and who has to be informed, goes a long way towards lowering the impact of an incident. This is where the RACI matrix comes in useful. \[17]

## **The use of the RACI Matrix**

The acronym RACI stands for

**Responsible** - these people undertake the work. They complete the task or objective or make the decision.

**Accountable** - the “owner” of the work. They sign off or approve when the task, objective or decision is complete. They make sure that responsibilities are assigned in the matrix for all related activities. One person is accountable.

**Consulted** - the people who need to give input before the work can be done and signed-off on. These people are active participants.

**Informed** - these people need to be kept “in the picture.” They need updates on progress or decision, but they do not need to be formally consulted, nor do they contribute directly to the task or decision.

The RACI approach has been used successfully to develop Incident Play books, in a dynamic fast time environment. It is contended the RACI Matrix can improve fast time communications during an incident and the mitigation of threats \[20]. Being able to triage ahead of time WHO needs to be told WHAT, WHEN, HOW and WHY will same precious time and encourage effective Crisis Management.

One of the first actions in responding to an incident is to establish the facts, at that time, understand the damage to date, and to mitigate further damage. Ahead of an incident happening we achieve this through careful planning and communication, especially through articulating and agreeing a shared understanding and acceptance of the Information risks. \[17]

Next being able to analyse, quantify and record those information risks amongst the senior managers in the organisation. Next to articulate, brief and communicate the information risks, including the business impacts and the mitigations to all stakeholders \[10]. This has to be done in slow time as part of the Education and Training regime with key stakeholders ahead of any cyber incident happening. This approach will put the Board and the whole organisation in a better place. The amount of resource, training and communication carried out is proportionate to the understanding, analysis, and articulation of the risk appetite \[18]\[19]. Likewise, the better prepared an organisation is through training and exercising, the more effective and efficient the Crisis Management Response will be \[29].

Organisational structures, need to be defined and understood, one way of to do this is through block diagrams, depicting formal and informal hierarchies and relationships. Design Science \[30] and Systems Dynamics are particularly useful to enable this, these are a set of Variables to decide where you are in the equation \[21]. Causal variables are used widely in Systems Dynamics and Grounded Theory \[22]. We explored the use of variables to describe Information Assets in the authors Previous paper \[23]. These aspects of planning contribute to the efficiency and effectiveness of fast time communication.

## **Scoping Fast Time Communications**

The approach is offered in the context of Cyber incident coordination and the need for Fast time secure information sharing, collaboration and coordination. The contents of this document could be useful for other applications but they are outside of the scope and detail of this report. Cyber Incidents are not permanent situations, they can therefore be thought of as fast time projects, with a start, middle and an end.

### Scoping a Cyber Incident

Incident scope and severity, who is affected, how many people need to be on the Incident call? Consider activating the Local Cyber Coordination Cell (LCCC), this is the internal team, which provides coordination and initial analysis for Cyber Incident Response team. We have adapted this in the CRASH Gate approach detailed later in the paper.

!\[Text

Description automatically generated]\(/files/-MeUu6eSeh6Opd9gFEtj)

Source: Scope Patterns for Projects Modelled as Sociotechnical Systems Bryan R Moser (MIT) \[8]

### Fast Time Comms and Collaboration Tools to consider

There are many software communications tools in use. Many of these software products are available in both desktop and portable mobile/tablet versions. Some are free and some are subscription / licence based and many have a “free tier”. The most common ones from our research through the Cyber Technical Advisory Group (CTAG) and from work conducted by the Local Government Association (LGA) are (in no particular order are;

SLACK/WhatsApp/Signal/Mobile text messaging/ Instant Messenger. Common video conferencing tools are also being used, Microsoft Teams, Zoom, Google hangouts, Cisco WebEx. Other products are by Adobe \[35], Amazon Web Services \[36] and Zello \[37], which have some limited use. From our findings, the preference is for WhatsApp \[38] and Teams \[39]. However, there is a lot of unease about perceived security configuration issues with WhatsApp, with Signal \[40] being app of choice for the savvier technical users.

C-TAG provides a SLACK feed through the NLAWARP and has a facilitated C-TAG node on the NCSC CISP platform. The NCSC provides a web form for reporting Cyber incidents;

[**https://report.ncsc.gov.uk**](https://report.ncsc.gov.uk/)

Likewise if you’ve been a victim of Cyber Crime, you should report the incident to Action Fraud: <https://www.actionfraud.police.uk/reporting-fraud-and-cyber-crime>

If you’ve had or suspect a Data Breach, likewise inform the Information Commissioners Office: <https://ico.org.uk/for-organisations/the-guide-to-nis/incident-reporting/>

Microsoft Teams is their Walkie Talkie app \[41], which is very much like Zello \[37], to enable a push to talk broadcast capability, turning the mobile phone into a Push to Talk (PTT) radio handset using Wi-Fi/4G networks (it is consuming 4G data when being used). The PTT approach gives an always on capability, to listen and monitor an audio channel. There is specific Android type hand held radios \[42], which we believe will proved very useful to Cyber Incident Responders. This enables mesh and point to point communication in a way that is more flexible than the use of mobile phones, giving the capability of hand held radios to non-technical users.

The use of mobile devices utilising the mobile phone and internet networks greatly extends the reach of these emergency communications. This means that Teams is readily available and is pervasive. As we have discussed there is a real issue that if the MS365 tenant is not available, there has to be an alternative, this would normally be regarded as “Shadow IT” \[46] which is where an alternative toolset for emergency communications should be available.

### Types and format of text and documents required

We have found that the norm is in slow time to monitor a WhatsApp group then move to a more appropriate secure channel of communications such as Signal. There is a distinct need to have multiple comms which we describe as;

1. Instant unstructured messaging – ephemeral text in WhatsApp / Txt / Instant Messenger.
2. More structure text communications with email / Slack / Chat in Teams
3. Video / Voice Communications via Teams / Zoom
4. Decision recording templates in Teams using OneNote as a primary tool.
5. Decision logs maintained by structure reference numbers stored locally and a central permanent record which all key decisions comprising Data/timestamp/reference etc/.
6. Document repositories such as NCSC CISP \[51] Resilience Direct \[52], other private group collaboration platforms which include KHUB\[53].

The overarching finding of the desk research and ad hoc enquiries through the Cyber Technical Advisory Group (CTAG) \[54] has been that there are multiple platforms and repositories in existence managed and maintained by various groups and entities. We content this is fine, so long as there is a standard template approach for interoperability between templates, message structures and referencing.

### Templates and updates

The authors Cyber Golden Hour Guide \[73] details the roles and responsibilities required to effectively coordinate a Cyber Incident within and organisation. This paper is focussing on the next level down, below the Governance and coordination or Crisis Management into the tactical tools and techniques that can be used by Incident Coordination Teams (Cyber Coordination Cell) or Fusion Cell.

Many organisations do not have staff trained to respond. In Wales, the Welsh Government Cyber Programme funded a serios of Cyber Exercises and tactical training workshops. The Lessons learned from live incidents, exercises and the tactical workshops clearly demonstrate that whilst exercising, training and awareness raising help, they do not completely solve the problem. Apart from responding to campaigns (common Cyber attacks at a given time, like WannaCry and the Microsoft Exchange attacks\[71]), all other incidents are different depending on the infrastructure in place. Therefore the approach needs to be generic, supported by specific playbooks. \[72]

## An example set of initial questions to help a first responder

1\) What is the believed nature of the incident?\
2\) How many locations (Sites/Schools etc) do you believe are affected at this time.\
3\) Which of these locations are directly maintained and supported by internal ICT?\
4\) When was the incident first detected?\
5\) How was it detected?\
6\) What mitigations have been implemented already?\
7\) Do you believe the incident is contained?\
8\) Have you prepared press, media and PR lines? \
9\) What are your planned next actions\
10\) Have you established a timeline and decision log?

### **National Cyber Security Centre (NCSC) Cyber Incident Categories**

The NCSC have defined six categories of Cyber Incident \[70].

Category 1 National cyber emergency

Category 2 Highly significant incident

Category 3 Significant incident

Category 4 Substantial incident

Category 5 Moderate incident

Category 6 Localised incident

The NCSC generally will only intervene at category three or above. Organisations will need to make their own support arrangements and work with partners for lower level attacks. The approaches in this paper would be useful for localised attacks from categories 6-4. Much effort goes into planning for very serious attacks, whereas lower level attacks at category 5/4 can still be debilitating for organisations.

### **Trigger Points in Cyber Incident Escalation and Fast Time Communication**

The work to date has highlighted a the need for pre-agreed ”Trigger Points”, especially for the lower NCSC categories above covering categories 6/5/4. In the context of Cyber Incident Response and the need for Fast time Communications, many incidents are known as “Rising Tide Events” \[63]. This means that the impact, severity and harm of the initial incident isn’t always obvious. Understanding Cyber Incidents in terms of Harm \[64] \[68] is a valuable way to gauge the possible final damage state of and incident. As further intelligence is received, through shared situational awareness, from differing sources, multiple organisations of through proliferation of a threat vector, (such as WannaCry in 2017) \[61], the situation increases in seriousness, where it may not be immediately apparent locally. This is where, Filtered Warnings, Advice Brokering and Trusted Information Sharing \[65] the key WARP (Warning, Advice & Reporting Point \[66] services come into their own.

Trigger Points \[32] can be thought of a pre-defined Consequence Relevance Acceleration Severity and Harm “CRASH” Gates. A gate in this context being a phase or stage where an incident escalates to the next level. The key being the baseline starting position that can be quickly and easily identified through honestly and objectively completed the CRASH index.

Ticking the Boxes on the CRASH Index Matrix gives an immediate baseline to help Situational Awareness, impending shifts in the threat profile and is especially useful in a Dynamic Rising Tide event scenario as described in the JESIP doctrine used by the Emergency Services\[67].

One of the areas organisation struggle with in writing plans is the definition of trigger points and their articulation. They are discussed in medical and paramedic literature \[74], however they are sparse in

## **The CRASH Gate matrix model for assessing Cyber incident escalation (Trigger Points)**

**Consequence Scaling**

1. Locally contained within the Organisation at a Sub-Departmental / Directorate Level
2. Locally contained within the Organisation at Departmental / Directorate Level
3. Local contained within the Organisation
4. Affecting multiple Organisations Sub-Regionally
5. Affecting multiple Organisations Regionally
6. Affecting multiple Organisations Nationally

**Resilience Scoring**

1. We are fully prepared and have exercised in the last six months
2. We are fully prepared and have exercised in the last 12 months
3. We have some plans in place and have not exercised recently.
4. We have few plans in place some training no exercising.
5. We have few plans haven’t trained or exercised in over 12 months.

**Applicability Scoring**

1. We do not have this technology in our infrastructure
2. We have this technology, we are fully patched.
3. We have this technology, we are partially patched
4. We have this technology, we are not patched
5. We have this technology, we are compromised

**Severity Scoring**

1. Not affecting our infrastructure directly
2. Affecting some of our infrastructure
3. Affecting most of our infrastructure
4. Affecting all of our infrastructure
5. Our infrastructure is over run and non-functioning

**HARM Levels**

1. The organisation is unaffected
2. The organisation is affected, but fully operational
3. The organisation is affected, and is partially operational
4. The organisation is compromised essential services still functioning
5. The organisation is compromised essential services lost.

The “CRASH Gate” matrix model, provides a granular set of indicators that can be used like the 5x5 intelligence model \[33] to instantly give a significance score to a situation.

### **Example CRASH Gate matrix trigger point annotation**

**C (1)** Locally contained within the Organisation at a Sub-Departmental / Directorate Level

**R (3)** We have some plans in place and have not exercised recently.

**A (4)** We have this technology, we are not patched

**S (2)** Affecting some of our infrastructure

**H (2)** The organisation is affected, but fully operational

Looking at the example above you would write a plan or playbook with particular actions relating to the narrative in the CRASH Gate statements above. This remove ambiguity and allows for delegated actions, to be clearly documented and authorised. In the example above a change especially for (C1) to (C2) and H(2) to H(3) would both be of huge concern. Whilst action to move from A(4) to A(2) would greatly reduce the risk. As a tool for Situational Awareness sharing a CRASH Gate Status (CGS) string of: CGS1,3,4,2,2 transmitted or shared as: CGS13422 If this was prefixed with a Cyber Unique Organisation Reference Number (CUON)\[34]

Example CCGS (CUON Crash Gate Status) 654/21/9874/13422

The above is a simple example but it means there is a definitive record for a shared CRASH Gate status for the current situation .The CUON being: 654 (The organisation ID) \[21] Year of allocation \[9874] the unique reference number for the CRASH Gate 13422 so if intercepted, the CRASH Gate status could be decoded but the organisation number could not be traced back and the validation code of 9874 would be updated during the acknowledgement. By

Parsing the CRASH Gate trigger status a search for those with A4/5 would be the organisations requiring priority support. This system of simple numeric reporting wholly relies on the honesty, truthfulness and transparency of participating organisations to be of use for information sharing. As an internal planning tool for baselining, it would be of value.

### [**ISO/IEC 27010:2015**](https://www.iso.org/standard/68427.html?browse=tc) **— Information technology — Security techniques — Information security management for inter-sector and inter-organisational communications (second edition)**

This standard provides guidance in relation to sharing information about information risks, security controls, issues and/or incidents that span the boundaries between industry sectors and/or nations, particularly those affecting “critical infrastructure”. ISO/IEC 27010 \[81] provides guidance on information security interworking and communications between industries in the same sectors, in different industry sectors and with governments, either in times of crisis and to protect critical infrastructure or for mutual recognition under normal business circumstances to meet legal, regulatory and contractual obligations.  Sometimes it is necessary to share confidential information regarding information-related threats, vulnerabilities and/or incidents between or within a community of organizations, for example when private companies, governments, law enforcement and CERT-type bodies are collaborating on the investigation, assessment and resolution of serious pan-organizational and often international or pan-jurisdictional cyberattacks.

Such information is often highly sensitive and it may need, for example, to be restricted to certain individuals within the recipient organizations. Information sources may need to be protected by remaining anonymous. Such information exchanges typically happen in a highly charged and stressful atmosphere under intense time pressures - hardly the most conducive environment for establishing trusted working relationships and agreeing on suitable information security controls. The standard should help by laying out common ground-rules for security.

The standard provides guidance on methods, models, processes, policies, controls, protocols and other mechanisms for the sharing of information securely with trusted counterparties on the understanding that important information security principles will be respected. ISO/IEC 27010 was first published in 2012 then minor editorial changes were made to align the standard with the 2013 editions of [ISO/IEC 27001](https://www.iso27001security.com/html/27001.html) and [27002](https://www.iso27001security.com/html/27002.html). The current second edition was published in **2015**. It was ratified by SC 27 in 2021 for a further 5 years.

## **References: (All references accessed July 2021)**

\[1] <https://www.local.gov.uk/sites/default/files/documents/C-TAG%20Guidance%20Document%20-%20Managed%20Tunnels%20for%20the%20Deployment%20of%20Microsoft%20365.pdf>

\[2]<https://www.researchgate.net/publication/342804953\\_An\\_Overview\\_of\\_Local\\_Government\\_Cyber\\_Security\\_in\\_England\\_and\\_Wales\\_Emergent\\_Threats\\_and\\_Practic>

\[3]<https://www.gartner.com/en/documents/3975373/market-guide-for-workstream-collaboration>

\[4] Incident Planner: <https://cydea.tools/ir-plan/>

\[5] NCSC Incident Response Process: <https://www.ncsc.gov.uk/collection/incident-management/cyber-incident-response-processes>

\[6] Noun Project Copywriting Icons: <https://thenounproject.com/term/copywriting/>

\[7] Scottish Govt Incident Framework: <https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-incident-management/documents/cyber-incident-response-plan-template/cyber-incident-response-plan-template/govscot%3Adocument/Cyber%2BCapability%2BToolkit%2B-%2BCyber%2BIncident%2BResponse%2B-%2BPublic%2BSector%2BCyber%2BIncident%2BResponse%2BPlan.docx>.

\[8] Scope Ref: [Concurrent Engineering in the 21st Century: Foundations, Developments and Challenges (pp.197-220)](https://www.researchgate.net/publication/publication/269403139_Concurrent_Engineering_in_the_21st_Century_Foundations_Developments_and_Challenges)

\[8a]<https://www.researchgate.net/publication/271272896_Design_of_Complex_Programs_as_Sociotechnical_Systems>

\[9]<https://www.researchgate.net/publication/267972043\\_System\\_Dynamics\\_Based\\_Insider\\_Threats\\_Modelin>

\[10] Stakeholder mapping (Systems Dynamics Approach): <https://resources.sei.cmu.edu/asset_files/WhitePaper/2005_019_001_53387.pdf>

\[11] **2014 6th International Conference on Cyber Conflict**

P.Brangetto, M.Maybaum, J.Stinissen (Eds.) 2014 © NATO CCD COE Publications, Tallinn

<https://core.ac.uk/download/pdf/29139555.pdf>

\[12] Sytems Dynamic Apporach to Cyber Conflict: <http://www.fortoo.eu/m/page-media/4/A_System_Dynamics_Model_of_Cyber-conflict.pdf>

\[13] <https://www.ida.org/-/media/feature/publications/2/20/2011-cyberspace---the-fifth-operational-domain/2011-cyberspace---the-fifth-operational-domain.ashx>

\[14] <https://rusi.org/commentary/offensive-uk-new-cyber-force>

\[15] <https://www.jesip.org.uk/common-operating-picture>

\[16] <https://www.msema.org/wp-content/uploads/2018/10/05_sm_awarecop_dec2012.pdf>

\[17] <https://www.mckinsey.com/~/media/McKinsey/McKinsey%20Solutions/Cyber%20Solutions/Perspectives%20on%20transforming%20cybersecurity/Transforming%20cybersecurity_March2019.ashx>

\[18] <https://www.rsa.com/content/dam/en/white-paper/cyber-risk-appetite.pdf>

\[19] <https://www.theirm.org/media/4666/0926-irm-risk-appetite-12-10-17-v2.pdf>

\[20] <https://www.ncsc.gov.uk/news/rusi-lecture>

\[21] <https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6655636/>

\[22] <https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4545354/pdf/hesr0050-1195.pdf>

\[23] Brett M 2021 \[Information Assets paper from previous journal edition]

\[24] <https://www.jesip.org.uk/definitions>

\[25] <https://www.ncsc.gov.uk/information/what-cyber-incident>

\[26] <https://www.gov.uk/government/consultations/computer-misuse-act-1990-call-for-information>

\[27] <https://www.gov.uk/government/publications/global-britain-in-a-competitive-age-the-integrated-review-of-security-defence-development-and-foreign-policy>

\[28] <https://www.jesip.org.uk/doctrine>

\[29] Backman 2020 (Wiley) [**https://doi.org/10.1111/1468-5973.12347**](https://doi.org/10.1111/1468-5973.12347)

\[30] DOI: <https://doi.org/10.1017/dsj.2020.6>

\[31] Onwubiko, Cyril and Ouazzane, Karim (2019) SOTER Cyber Playbook <http://repository.londonmet.ac.uk/5358/>

\[32] DOI: [10.13140/RG.2.2.19037.13282](http://dx.doi.org/10.13140/RG.2.2.19037.13282) <https://www.researchgate.net/publication/352690198_Local_Authority_Cyber_Resilience_Planning_Guide?channel=doi&linkId=60d34d3b299bf1fe4698a680&showFulltext=true>

\[33] <https://www.gov.uk/hmrc-internal-manuals/money-laundering-regulations-compliance/mlr3c14000>

\[34]<https://www.researchgate.net/publication/349320224_Information_Asset_Registers_for_Cyber_Security>

\[35] <https://www.adobe.com/uk/products/adobeconnect.html>

\[36] <https://aws.amazon.com/chime/>

\[37] [https://zello.com](https://zello.com/)

\[38] <https://www.whatsapp.com/?lang=en>

\[39] <https://www.microsoft.com/en-gb/microsoft-teams/group-chat-software>

\[40] <https://signal.org/en/>

\[41] <https://docs.microsoft.com/en-us/microsoftteams/walkie-talkie>

\[42] <https://zello.com/accessories/network-radios/>

\[43] [https://secure.echolink.org](https://secure.echolink.org/)

\[44]<http://www.arrl.org/files/file/Public%20Service/Emergency%20Radio%20Internet%20Linking%20System%20for%20web%20%282%29.pdf>

\[45] [http://cmolegionoffrontiersmen.info](http://cmolegionoffrontiersmen.info/)

\[46] <https://www.cio.com/article/3314738/shadow-it-the-cio-s-perspective.html>

\[47] <https://www.redcross.org.uk/about-us/what-we-do/we-speak-up-for-change/people-power-in-emergencies>

\[48] <https://sites.google.com/view/brccr/home?mc_cid=3b7e5aee98&mc_eid=4a05e96ee8>

\[49] <https://cybervolunteers.wordpress.com/volunteering/>

\[50] <https://istanduk.org/wp-content/uploads/2019/08/Cyber-Emergency-Response-BRT-002.pdf>

\[51] <https://www.ncsc.gov.uk/section/keep-up-to-date/cisp>

\[52] <https://www.gov.uk/guidance/resilient-communications>

\[53] [https://khub.net](https://khub.net/)

\[54] [https://www.ctag.org.uk](https://www.ctag.org.uk/)

\[55] [https://www.actionfraud.police.uk](https://www.actionfraud.police.uk/)

\[56] <https://www.anomali.com/resources/what-are-stix-taxii>

\[57] [https://www.misp-project.org](https://www.misp-project.org/)

\[58] <https://bestpractical.com/rtir>

\[59] [https://attack.mitre.org](https://attack.mitre.org/)

\[60] <http://www.stgeorgeshouse.org/wp-content/uploads/2016/04/Local-Leadership-in-Cyber-Society-Report.pdf>

\[61] [https://www.enisa.europa.eu/publications/good-practice-guide-for-incident-management/at\_download/fullReport i](https://www.enisa.europa.eu/publications/good-practice-guide-for-incident-management/at_download/fullReport%20i)

\[62] <https://www.england.nhs.uk/wp-content/uploads/2018/02/lessons-learned-review-wannacry-ransomware-cyber-attack-cio-review.pdf>

\[63] <https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/913502/NRS_for_LRFs_V3.0__Aug2020.pdf>

\[64] <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2828646>

\[65] <https://www.nlawarp.net/warp-services/>

\[66] <https://www.ncsc.gov.uk/information/what-warp>

\[67] <https://www.jesip.org.uk/uploads/media/pdf/Joint%20Doctrine/JESIP_Joint_Doctrine_Document.pdf>

\[68] <https://academic.oup.com/cybersecurity/article/4/1/tyy006/5133288>

\[69] <https://www.ncsc.gov.uk/news/new-cyber-attack-categorisation-system-improve-uk-response-incidents>

\[70] <https://www.ncsc.gov.uk/news/new-cyber-attack-categorisation-system-improve-uk-response-incidents>

\[71] <https://www.ncsc.gov.uk/news/security-updates-released-microsoft-exchange-server>

\[72] <https://www.gov.scot/binaries/content/documents/govscot/publications/advice-and-guidance/2019/10/cyber-resilience-incident-management/documents/cyber-incident-response-malware-playbook/cyber-incident-response-malware-playbook/govscot%3Adocument/Cyber%2BCapability%2BToolkit%2B-%2BCyber%2BIncident%2BResponse%2B-%2BMalware%2BPlaybook%2Bv2.3.pdf>

\[73]<https://www.researchgate.net/publication/336400438_Cyber_Incident_Approach_Framework_for_Local_Government_-_Cyber_Incident_Approach_Framework_for_Local_Government>

\[74] <https://www.nap.edu/read/18338/chapter/4>

\[75] <https://mhclgdigital.blog.gov.uk/2020/08/25/key-findings-and-recommendations-from-the-cyber-security-discovery/>

\[76] <https://www.gov.uk/guidance/local-resilience-forums-contact-details>

\[77] <https://www.prince2.com/uk/prince2-methodology>

\[78] <https://www.agilealliance.org/agile101/>

\[79]<https://www.ccdcoe.org/uploads/2012/01/3_2_LilesDietzRogersLarson_ApplyingTraditionalMilitaryPrinciplesToCyberWarfare.pdf>

\[80] <https://www.misp-project.org/compliance/ISO-IEC-27010/>

\[81] <https://www.iso.org/standard/68427.html>


# Cyber Incident Response Playbooks

Attached are a series of Incident Response Playbooks that were created on behalf of C-TAG

{% file src="/files/-MfXCLd7oDElN-zWs3\_R" %}
Malware Action Card&#x20;
{% endfile %}

{% file src="/files/-MfXCJ6U0gi1hPaI7TNn" %}
Phishing Action Card
{% endfile %}

{% file src="/files/-MfXCHdXqbxwNDeFt6As" %}
Ransomware Action Card&#x20;
{% endfile %}

{% file src="/files/-MfXCG4DoEAHfAFr-187" %}
DdoS Action Card&#x20;
{% endfile %}


# ChatGPT & AI

{% file src="/files/HLcfT93OgG1oeiYXU0zm" %}
Download the ChatGPT / AI Paper
{% endfile %}

Chat-GPT is an example of an Artificial Intelligence “AI” programme. These “Large Language Models” (LLMs) are continuing to develop at an ever-accelerating rate. There are several key issues to consider.  The UK Government AI Strategy is a good starting point to understand the context and background \[5]. It’s also very useful to understand where AI fits into the wider Data Science and Information Management disciplines \[6].&#x20;

**Key issues to consider**

·       Ethics

·       Bias

·       Privacy

·       Copyright infringement

·       Extensibility

·       Secondary mining of the Metadata

·       Access Control

·       Consistency of output

·       Data Protection (GDRR) – Giving the right to query automated decisions.

·       The right to be forgotten.

·       Legal implications – vicarious responsibility for Chatbot-GPT generated answers and advice.&#x20;

&#x20;

**A few initial thoughts**

·      AI is the single most exciting and terrifying technology to emerge for some time.

·      Whilst AI has been around for years, there is a paradigm shift underway.&#x20;

·      The machine learning models bring a whole new meaning to “Built on the shoulders of giants”. LLM’s will multiply, the pervasiveness of AI will be logarithmic.&#x20;

·      Consider AI, it in terms of AI & Moore’s Law. We’ve saturated CPU growth, we’ve increased power of processors, made RAM and storage cheaper. Energy costs are the limiting factor!

·      As the LLM & AI snowball starts, the momentum will exponentially accelerate, potentially in a logarithmic fashion.&#x20;

·      We may not be ready for it.&#x20;

·      Think Blue/Red=Purple Teaming, consider both the opportunities and the threats.

&#x20;

ChatGPT is a chatbot powered by Generative Pre-trained Transformer 3 (GPT-3), which is a deep-learning language model. The release of ChatGPT took the world by storm in November 2022 due to its impressive ability to write in a human-like way.\[3]

Artificial intelligence (AI) powered chatbot ChatGPT is being used for a wide range of applications that require natural language processing and text-based conversation. The large-scale language model developed by OpenAI uses deep learning techniques to generate human-like responses to text-based conversations. It can be used as Chatbot, virtual assistant, language translation, content creation, educational resource, solving complex problems, and evening writing codes.&#x20;

However, there have been instances when ChatGPT’s servers have been overloaded with users. This has locked users out of using the bot. On February 27th February 2023, , ChatGPT reportedly went down for over three hours.&#x20;

OpenAI said that the outage was due to “database instabilities,” and it started rolling out a couple of hours after the servers were taken offline.

This is the second major outage ChatGPT has seen in the last 90 days. The service experienced another outage on February 21, which brought down the chatbot for four and a half hours. With increasing popularity and user base these outages may become a regular occurrence. With the increasing need for AI writing tools like ChatGPT, people are looking for ChatGPT alternatives to help them be more creative. \[1]

We’ll consider some of the issues and key questions. Is this a useful new technology, something to be trusted? Here to stay of. Passing trend.&#x20;

Cyber Risks & Cyber Opportunities

So some interesting issues around Chat-GPT and inputting sensitive data – beware, understand any data protection concerns and other privacy, copyright type issues.  How do we assess the risks (Confidentiality, Integrity, and Availability)? The technologies use is currently novel, just like when WhatsApp appeared and other Cloud Software as a Service (SaaS) applications. When you ask it questions, are those questions then processed on and stored? Adding to the collective consciousness. How will be known about innate bias in the questions or mor importantly, the intrinsic bias built into the answers, who controls those? The issues of ethics will be a real concern.

As the name indicates, Open AI is an open platform that millions of users from all over the world use. This carries several security risk. For one, it gathers a lot of personal data that users, unassumingly, might provide. This, in turn, makes ChatGPT very attractive for hackers. While one could argue that private users interact with ChatGPT at their own risk, as a company, you could become liable.

After all, you have to ensure user data privacy. If your customers’ personal data somehow because public through ChatGPT, you’re not only in violation of privacy laws. It can also damage the trust customers put in your company.

In addition, depending on what type of information you put into ChatGPT, you run the risk of making sensitive company information public. For instance, if your marketing team is playing around with the chat technology to come up with a good copy for sending out a customer e-mail about a new product that hasn’t been released yet, this information might become public before you even launch the product.

Or, ChatGPT might come up with a text that is protected by copyright laws. If your marketing team then uses this text, you could face legal charges.

Summing up, ChatGPT is a very promising and enticing technology, but it’s not quite ready for business use yet. However, there are safer alternatives!

Security Implications

“Just weeks after ChatGPT debuted, Israeli cybersecurity company Check Point [demonstrated](https://research.checkpoint.com/2022/opwnai-ai-that-can-save-the-day-or-hack-it-away/) how the web-based chatbot, when used in tandem with OpenAI’s code-writing system Codex, could create a phishing email capable of carrying a malicious payload. Use cases like this illustrate that ChatGPT has the potential to significantly alter the cyber threat landscape, adding that it represents another step forward in the dangerous evolution of increasingly sophisticated and effective cyber capabilities. Check Point also recently [sounded the alarm](https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/) over the chatbot’s apparent ability to help cybercriminals write malicious code. The researchers say they witnessed at least three instances where hackers with no technical skills boasted how they had leveraged ChatGPT’s AI smarts for malicious purposes. One hacker on a dark web forum showcased code written by ChatGPT that allegedly stole files of interest, compressed them, and sent them across the web. Another user posted a Python script, which they claimed was the first script they had ever created. Check Point noted that while the code seemed benign, it could “easily be modified to encrypt someone’s machine completely without any user interaction.”&#x20;

Unsurprisingly, news of ChatGPT’s ability to write malicious code furrowed brows across the industry. It’s also seen some experts move to debunk concerns that an AI chatbot could turn wannabe hackers into full-fledged cybercriminals.&#x20;

“ChatGPT and AI in Cyber Security&#x20;

Here are five key areas of cyber security that ChatGPT and AI could impact, for better and worse.&#x20;

1 - High-Volume Spear Phishing

Spear phishing emails are malicious emails targeted at a specific person or organisation. Threat actors often deploy this social engineering technique to gain access to an account or initiate fraudulent transactions. A large variety of online sources, from company websites to social networking platforms, arm attackers with useful information about people and companies that can help them craft more convincing spear phishing emails.

The targeted nature of these emails normally makes them hard to scale to the level of normal email spam. Part of the reason for this lack of scalability is the research required, but it’s also that increased levels of cyber security awareness make people more likely to spot obvious signs of mass email phishing, such as spelling errors or clunky language. And with many hackers not hailing from native-English destinations, these mistakes appear often in the mass phishing emails that they write.

However, advanced chatbots like Chat-GPT could change the game and enable high-volume, targeted, and effective spear phishing email campaigns. Research carried out separately by two different security companies in December 2022 found ChatGPT could write a plausible and well-written phishing email impersonating a web hosting company and a CEO.

&#x20;

Asking ChatGPT to write a phishing email now gets flagged as unethical activity, which suggests OpenAI paid attention to the concerns of security researchers. But similarly advanced AI text-based tools will likely emerge, and not all of them will flag requests or queries as unethical. Scaling these difficult-to-detect spear phishing emails might become far more feasible for hackers in the not-too-distant future.&#x20;

&#x20;

2 - Malware-as-a-Service

ChatGPT’s programming prowess sets a worrying precedent in lowering the barriers to creating malware. It’s trivial, for example, to get ChatGPT to write VBA code that downloads a resource from a specified URL any time an unsuspecting user opens an Excel workbook containing that code. Such a request would make it very easy to weaponise a phishing email with a malicious Excel attachment without requiring in-depth skills or knowledge.

The resource downloaded onto an end user’s computer could be a keylogger or a remote access trojan that provides access to a system or network and sensitive assets. Some security researchers were even able to get the bot to write malicious PowerShell scripts that delivered post-exploitation payloads (ransomware).

While ChatGPT’s coding skills are a concern, it still requires at least some degree of cyber security knowledge to manipulate queries in a way that produces working malicious code. A perhaps more pressing issue is that generating malware from text commands alone opens up more opportunities for malware-as-a-service. Cybercriminals with real hacking skills could easily use ChatGPT to automate the creation of working malware and sell the end product as a scalable service.&#x20;

3- Propagating Fake News

With its impressive writing abilities, ChatGPT comes with a lot of abuse potential in the context of spreading fake news. Eloquent yet false stories can be generated with a simple sentence prompt. Media outlets such as Sky have already experimented with letting ChatGPT write articles.

Fake news stories about personal data breaches or security vulnerabilities could be written by malicious insiders or published by hackers that infiltrate journalists’ or users' accounts at high-profile publications and organisations. While unlikely, the possibility of this Orwellian outcome of not being able to decipher fact from fiction would lead to chaos and a loss of trust. At worst, a complete undermining of consumer confidence in the digital economy could ensue.&#x20;

4 - Enhanced Vulnerability Detection

Turning to a more positive perspective, ChatGPT (and AI in general) show great promise in improving vulnerability detection. Try the following experiment: copy a snippet of code from this Github page of vulnerable code snippets and ask ChatGPT to examine the code for security vulnerabilities. You’ll notice that the tool quickly flags whatever happens to be wrong with the code and even suggests how to fix the security weaknesses.

Turning to the broader field of AI rather than just ChatGPT, the powerful machine learning models that underscore these technologies can also enhance vulnerability detection. As a network and the number of endpoints on it grows, detecting anomalies and weaknesses becomes more challenging. AI-powered tools are far more effective at unearthing vulnerabilities because they can use enormous sets of training data to establish what’s normal while reducing the time to find what is abnormal on a network.

5 - Automating Security Team Tasks&#x20;

Cyber security skills gaps continue to place an excessive burden on security teams. The UK government’s 2022 report found 51 per cent of businesses have a basic skills gap in tasks like configuring firewalls, and detecting and removing malware. This skills gap places a heavy burden on existing teams to the point where alert fatigue and burnout are common issues.

Automation has a critical role to play in easing the impact of cyber skills shortages and helping security teams defend their organisations in today’s threat landscape. ChatGPT excels at rapidly writing programs and code that could prove beneficial for automating a range of security tasks. As an example, it takes a few seconds to produce a simple Python program that will scan for open ports on a given hostname.

You’re aware by now that ChatGPT can be manipulated to write malicious code, but the flip side of this is its usefulness in analysing malicious code to help figure out what it does. From explaining how various Windows registry keys can be used by malware to describing what large chunks of malicious code are attempting to do on a system, speeding up and strengthening the tricky area of malware analysis is invaluable for many organisations.

Getting prepared&#x20;

While it’s still early days in understanding the full implications of ChatGPT and AI in cyber security, the ideas here offer a snapshot of what’s possible. Getting prepared for both the good and the bad of AI requires a smart cyber security strategy that accounts for these technologies’ increasing influence.” \[3].

&#x20;

Annex A

A few of the alternatives:

ChatSonic

India's Chatsonic can be one of the alternatives to ChatGPT. It was introduced in 2021, far earlier than Open AI's ChatGPT. Contrary to ChatGPT, ChatSonic incorporates text-to-speech and Google Search into its operation, making it effective enough to provide the most recent responses to your inquiries. processing to provide accurate summaries of current events, trends, and conversations.

Jasper AI

The Jasper AI programme, originally known as Jarvis, is one of the best AI writing tools. It is a recent addition to the Large Language models-based AI chatbot. It is an AI writing assistant that is powered by OpenAI's GPT-3.5 model. month or $588 per year. The creation of Jasper AI enables individuals and teams to scale their content initiatives using AI.&#x20;

Jasper claims that because it has read the majority of the public internet, it is fluent in over 25 languages and is knowledgeable about almost every niche. It makes the claim that it can assist users with translating the text as well as writing "blog articles, social media postings, marketing emails, and more." Jasper also promises to deliver content that is “word-by-word original” and “plagiarism-free”.

Authoring services like Headline and Shortly AI have been acquired by Jasper. These programmes aim to be fully integrated with Jasper, however, they are currently standalone solutions. In Jasper AI, the content is produced for you when you select a topic and fill out a form with the necessary information.

Bard AI

Like ChatGPT, Bard AI, Google's newest and most innovative AI-powered chatbot, is being developed on the company's LaMDA AI platform. It is an experimental conversational AI service that is expected to have a significant impact on the AI industry.

LaMDA eliminates the limitation of having data confined to a specific year and revolutionises Bard's natural language processing capabilities by enabling it to interpret and respond to human input with more precision. Google claims that Bard can generate texts and answer questions. This new conversational AI chatbot project by Google is also known to summarize texts. The company began testing the bot on February 6, 2023.&#x20;

&#x20;

Microsoft Bing AI

Recently, Microsoft added artificial intelligence to their search engine, which is now referred to as Bing AI. The OpenAI large language model, which is far more potent than ChatGPT and GPT-3.5, is the foundation of Bing AI, which was created with the express purpose of elevating search to a new level. It has been optimised to maximum speed, accuracy, and efficiency. To guarantee customers receive the greatest results, it makes advantage of the important developments and lessons learned from its forerunners.

Microsoft unveiled new, AI-enhanced features for their Edge browser called "Chat" and "Compose." In addition to their current Bing feature, this development. Additionally, Microsoft just released Bing and Edge mobile apps for iOS and Android users.

Bing gives users the ability to ask queries with up to 1,000 words and get AI-powered responses. Its capacity to process complex inquiries makes looking up information faster. If ChatGPT-powered Bing can't provide a direct response to your query, it will give you a selection of related results. Bing AI as of now has no upfront cost. 1000 transactions are free per month.

DialoGPT

Microsoft's DialoGPT is a large-scale pre-trained dialogue response generation model specifically built for multi-turn conversations. DialoGPT is a significant pre-trained system for producing replies that can be used in multiple dialogue exchanges. It was trained using a massive dataset of 147 million multi-turn discussions extracted from Reddit discussion threads between 2005 and 2017.

Similar to the outputs of GPT-2, the sentences that DialoGPT generates are astonishingly diverse and include information that relates to the initial prompt. According to Microsoft, DialoGPT is more conversational, animated, frequently lighthearted, and generally extremely dynamic — qualities that might be appropriate for the use you're considering. DialoGPT, however, does not offer voice search, voice response, or personalities. Since this is a brand-new launch, there is no specific information about the pricing structure available.

NeevaAI

NeevaAI combines the efficiency and most recent data of the Neeva search engine with the strength of ChatGPT and other large language models.

Two former technology executives, Vivek Raghunathan, vice president of monetization at YouTube, and Sridhar Ramaswamy, former senior vice president of ads at Google, designed the search engine.

The system developed by NeevaAI is capable of searching and sorting through hundreds of millions of web pages to produce a single, comprehensive response that includes pertinent sources. Neeva can be compared to a search engine that has been given AI enhancements, but it is not yet a fully functional chatbot that is powered by AI. Neeva AI also provides references in its outcomes.&#x20;

CoPilot

If you've been creating codes on ChatGPT and want to look at websites that provide the same or even better results, you can check out GitHub’s CoPilot. CoPilot, uses the GPT-3 model from OpenAI Codex for auto-completion.

This application supports various well-known coding environments, including VS Code, Neovim, and JetBrains. It also supports cloud workflows via GitHub Codespaces. It can produce syntax in up to 12 languages, including JavaScript, Go, Perl, PHP, Ruby/Swift/TypeScript, and BASH. In addition, it supports multi-language scripting, and the model is powered by trillions of lines of open-source code from the public domain, such as those found on GitHub repositories.

Character AI

Character AI is based on neural language models and has been trained from the ground up with conversations in mind. Instead of talking with a single AI chatbot, Character AI allows users to select from a variety of personas. Elon Musk, Tony Stark, Socrates, Joe Biden, and Kanye West are just a few of the many characters and people that may be found on the home page. The AI adjusts its conversational style according to the person you selected, which is the finest part. Creating a character is quite fun as you can go along, designing it according to yourself.

The AI has a built-in image generator for avatar creation. Once done, you can start chatting right away and even share it with others. Character AI is free to use, but you do need to make an account since the chat gets locked after a few messages.

YouChat

Another conversational AI model called YouChat was introduced by the search engine You.com. It functions similarly to ChatGPT and essentially performs what other generic chatbots do.

Artificial intelligence and natural language processing are used by YouChat's AI to mimic human speech. It can create emails, write code, translate, summarise, and react to general inquiries. It offers average responses because it is still in the development phase.

While you can just talk to it, YouChat can also write code, give advice, break down complicated concepts, summarize books, and a lot more. It claims to provide the latest information; however, it sometimes commits errors there as well. YouChat is completely free to use, so you need only visit the website and start chatting.

Elsa Speak

Elsa Speak is a language-learning programme powered by AI. It analyses the user's voice using AI and creates a set of tasks that are simple for the user to understand. Elsa Speak is thus another of the best ChatGPT alternatives to consider.

Elsa as an English-speaking speech assistant may aid you in translating between many tongues and English. The AI system used by ELSA was developed using voice recordings of English speakers with a variety of accents. This gives ELSA an advantage over most other voice recognition algorithms by allowing it to recognise the vocal patterns of people who do not speak with a native level of ability.

&#x20;

&#x20;

Useful additional background articles and resources

&#x20;

<https://www.digitaltrends.com/computing/how-to-use-openai-chatgpt-text-generation-chatbot/>

&#x20;

<https://www.digitaltrends.com/computing/google-launches-chatgpt-rival-bard-ai/>

&#x20;

<https://www.digitaltrends.com/computing/the-best-chatgpt-alternatives-according-to-chatgpt/>

&#x20;

<https://www.digitaltrends.com/computing/microsoft-chatgpt-bing-launch/>

&#x20;

<https://www.nytimes.com/2023/01/12/technology/microsoft-openai-chatgpt.html>

&#x20;

<https://www.digitaltrends.com/computing/microsoft-might-put-chatgpt-ai-into-outlook-word-powerpoint/>

&#x20;

Other outcomes, novel applications:

&#x20;

Voice actors <https://www.digitaltrends.com/computing/voice-actors-seeing-an-increasing-threat-from-ai/>

&#x20;

<https://medium.com/@colin.fraser/chatgpt-automatic-expensive-bs-at-scale-a113692b13d5>

&#x20;

<https://www.darkreading.com/endpoint/scammers-mimic-chatgpt-steal-business-credentials>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

References

&#x20;

\[1] <https://news.abplive.com/technology/chatgpt/bored-of-chatgpt-here-are-10-alternatives-worth-checking-out-1585230>

&#x20;

\[2] <https://techcrunch.com/2023/04/17/chatgpt-everything-you-need-to-know-about-the-ai-powered-chatbot/>

&#x20;

\[3] <https://www.tmc3.co.uk/insights/what-could-chatgpt-and-ai-mean-for-cyber-security>

&#x20;

\[4] <https://www.ncsc.gov.uk/blog-post/chatgpt-and-large-language-models-whats-the-risk>

&#x20;

\[5] <https://www.gov.uk/government/publications/national-ai-strategy>

&#x20;

\[6]<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/850129/The_Dstl_Biscuit_Book_WEB.pdf>

&#x20;

&#x20;


# Horizon Scanning 2026

Overview of current issues relevant to the Wider Public Sector

{% file src="/files/QFHhTBZApncvFC6Fcw9k" %}

**Introduction**

Horizon Scanning Definition:

**Horizon scanning** is a technique for detecting early signs of potentially important developments through a systematic examination of potential threats and opportunities, with emphasis on new technology and its effects on the issue at hand.

Source: <https://www.oecd.org/site/schoolingfortomorrowknowledgebase/futuresthinking/overviewofmethodologies.htm>

Horizon Scanning exists with a proper method that gets used within the commercial world, in the Government \[1], Health \[2], Military \[4] and Intelligence communities.

We’ve seen a lot of this work during the COVID-19 pandemic in the Health sector, referenced in \[2] above, it’s a valid and useful model, for planning and understanding the word and the surrounding complexity.

There is an excellent detailed handbook on Horizon Scanning \[3], which will help you if you wish to dive deeper into the subject.

You can't do horizon scanning within the constructs of a static system, it is dynamic thing. It is a moving fluid events driven paradigm and things change. So what does this mean on a day-to-day basis?  That means monitoring what's on the news, the big global and macro issues;

&#x20;The War in Ukraine

The Energy Crisis / Prices&#x20;

Cost of Living Concerns

&#x20;Climate Change,

On-Going Cyber Threats & Scams

Tiger Economies in Asia \[5], trade and Global Economies of China, Russia, the US, and Asia-Pacific Countries.

There are the issues raised in the Green Economy, new emergent issues like Doughnut Economics \[6].

These are all things, which have nothing to do with Cyber Security and Resilience, but everything to do with the economy and the way the criminals, hackers and foreign hostile states think. Foreign states and even our own all driven by a “Doctrine” \[7]. This includes the UK Cyber Doctrine \[8], that drive the military objectives, which on the civic side through the work of the Cabinet Office National Cyber Security Programme \[9], and the NCSC \[10]. Making sure you've got a good source of rich knowledge in terms of newsfeeds blogs, push content (Podcasts / blogs/ news feeds) notes and qualitative research memos\[11] from conversations, things you come across, reports that get written and just generally understanding your environment.&#x20;

Horizon scanning can take account of major news events and things happening in the country and globally. Obviously, you can’t track everything, but you’ll develop a set of “Lenses”, we refer to as Contexts. A few big issues to consider that could affect Cyber Security are

&#x20;• global warming

&#x20;• pandemics political elections,&#x20;

&#x20;• political takeovers in countries,

&#x20;• insurrections,&#x20;

&#x20;• civil unrest,&#x20;

Things that are going on within the environment of your own organisation. Horizon scanning is about looking at asset & risk management, threats,

facilities, vulnerabilities and exploits. Risk analysis and risk management and risk planning is all about understanding the current threats that you're facing vulnerabilities and In a complex computer system, there might be 50 vulnerabilities, but 49 of those vulnerabilities, remain unexploited. However, if more of those vulnerabilities start to get exploited. we often refer to zero-day exploits, that means someone has&#x20;

taken a theoretic vulnerability and turned it into an actual exploit and have been able to affect

the cause that they were seeking to do in relation to that vulnerability. that's when you've got a problem,&#x20;

that's when companies like Microsoft, Amazon, Google, release patches against current detected and reportedbvulnerabilities, hopefully before they become exploitable, but sometimes an exploit happens and it quickly industry has to move to patch that vulnerability.&#x20;

This has happened recently for instance attacks on Citrix and VM-ware, it is these are zero day (unpatched) vulnerabilities that are dangerous. Sometimes known vulnerabilities are kept secret and these are known as “equities”\[12], which can be used by foreign state actors for cyber-attacks, surveillance and espionage.

We can change our world view\[13] when new information comes to light. In fact refusing to change your worldview for political or organisational reasons in the light of new knowledge and information can lead to real world problems.

There is much to learn from Systems Theory\[14] and complex systems that can inform the horizon scanning process and approach.

We're constantly retraining, rechecking, reassessing, everything that's going on. We don't often know&#x20;

how critical a vulnerability, or a thing is. So, what we do is we use a five-by-five classification approach to help inform the process. The 5x5 intelligence classification system\[15] is used widely in the Police and Intelligence services.

These are known as sometimes as intelligence assessments\[16] or referred to as an Intelligence Estimate, by our American colleagues. An output from the intelligence process, becomes a product\[17], it means&#x20;

it's gone through the whole assessment machinery.

Part of that assessment machinery is the horizon scanning and validation of facts. So, using a five-by-five matrix gives a level of confidence and these assessments are constantly changing as well. So, I hope&#x20;

that basic introduction to riser scanning has been useful. And we will look at some of these areas now in more detail.

As we move into 2026, cybersecurity has transitioned from a niche technical concern to a fundamental pillar of organisational survival and national prosperity. The landscape is no longer defined by isolated malware attacks but by a professionalised, adaptive industry that exploits human trust, regulatory gaps, and systemic fragility. We have reached a tipping point where organisations that rethink their operating models will succeed, while those remaining reactive will face disproportionate harm.

Cybersecurity failure is now viewed as a failure of corporate governance. Regulators are shifting focus toward holding Directors and Officers personally accountable for data security negligence. Boards are now expected to treat cybersecurity as a fiduciary duty, ensuring it is a standing item on every agenda. Furthermore, cyber insurance is moving from a "nice to have" to a mandatory requirement for doing business, with insurers demanding demonstrable evidence of active monitoring and incident response capabilities.

**Digital Ethics**

Digital Ethics\[53] are something you might not consider. It might not have heard of, but it is&#x20;

really important. Why are  ethics so important then? Ultimately ethics define the moral boundaries that we need to stay within, through policy and consideration of societal acceptability. We all know about Human Rights, well that’s what ethics are. My philosophy has always been “At what price?” That relates to how badly you want something and the lengths your prepared to go to get them, “At what cost” to friends, relationships and consequences. The law also reflects a set of societal norms, in terms of our criminal laws and the punishments we have for breaking them. There are many ethical concerns at this time around Covid-19, Social distancing, lock downs, the acceptable way to behave and of course the vaccines being developed, who get them first, prioritisation and the order of events, these are all ethically driven \[54]decisions. That set’s the context for ethics, as we turn to digital ethics, they are the rules and algorithms that drive machine learning and artificial intelligence\[55]. We are getting use to the idea of driverless autonomous cars and vehicles, we hope they are programmed to do the right thing. Would we be as happy knowing a car had a peace and as war mode?....

When cybernetics first started and robots were the stuff of science fiction  stuff, right back in the days&#x20;

of guy Norbert Wiener\[29] a brilliant MIT Student in the 1950’we know that some of you might never&#x20;

have heard about him, he was an MIT student and went on to doing some of the founding work&#x20;

on cybernetics. It was always the intention to design machines that must not hurt the creator\[56].&#x20;

So if you think about the Terminator film and the robots, not to destroy their creators. That's called non malfeasance, do no harm. Digital Ethics is looking at how machine learning and artificial

intelligence is actually helping shape how these things work, Tesla cars, you don't own the software, you licence it. I'll talk about it more a bit later, but you're actually licensing the software. So when you get&#x20;

into a car and it's driving itself, it's been driven by algorithms. The algorithms get to make we hope ethical decisions all the time about what to do and what not to do. Is it a good thing trusting our lives to hope? you really need to have an understanding about digital ethics.&#x20;

**Smart Cities**

Smart Cities\[57]. Again, it's something that's emerging is bringing all the bits together. Because if you look at the internet of things, that's given us far more contextual information.&#x20;

If you look at some machine learningartificial intelligence and algorithms it, then culminates in what we're doing is smart cities . Aren't anything new, but bringing them all together actually is we're getting

&#x20;far more integrated around our  CCTV and transport networks. We've got travel cards.&#x20;

It's the Oyster card down in London.&#x20;

There are lots of other travel cards. Now, bike hire school, scooter hire all those fobs. Every time you get&#x20;

one of these higher bikes out, you “touch-in” your smart token on NFID device (such as your smart phone). Your then charged through your user account. But that token and account is tracking where you&#x20;

got the bike/scooter from, where you started your journey at what time, where you checked the bike/scooter back in (your Destination), the duration of your travel and likely through Geo-tracking technology in the bike/scooter, your route. This Geo-Temporal information is you leaving a deep, rich, digital footprint everywhere you go. Your journeys are being tracked so this is where ethics and privacy come into play in this poor wifi smart roadsigns smart motorways. It's all really joining everything up. A person, event, location and time. The Law Enforcement, Military and intelligence Agency dream.\[58]

People will know where you are, what you're doing. Data protection, privacy and Civil Liberty, and freedom, and everything is going to go far beyond where we've been in the past. In the past, it's all been&#x20;

about geo temporal information, but in the future, it's all about geospatial information as well. So the&#x20;

world is moving on at pace, but all of these disparate things are building up into a layered taxonomy. Now through cloud, through the software defined networks, zero trust the algorithms, digital ethics, and then&#x20;

culminates in smart cities. Not just what building you were in, but the floor, desk and device locations too.

Good security network architectural design, understanding that there are work flows following the&#x20;

data which we've always been doing with data protection and data privacy impact assessments.&#x20;

But you do need to understand your suppliers and your third parties, especially those processing your data that they are doing so in an ethical way.&#x20;

You do need to understand your supply chain, what kit you're buying works come from. Have they tested itYou do need to have dynamic business continuity. Now you need to start making staff aware of all this&#x20;

new technology and how it affects them. And if you need to have really good detailed documentation and&#x20;

you need to have a really good detailed diagrams and configuration, that's really important.

**Section 2 - Emergent Threats – What we’re seeing on the radar**

**Introduction**

Emerging threats again are some familiar topics that are today coming to the forefront of the threats we are facing on and seeing in our networks and on the Internet. Many of these you will know about, we aim to give you a better context. A quick recap on what we talk about as information assurance.\[59]

* **Confidentiality**, keeping information safe and secure accessible to those who are authorised
* **Integrity** – Ensuring the Information is accurate and hasn’t been altered.
* **Availability** – The ability to ensure we can access these systems and services when we need to.

**Virtualization.**&#x20;

Virtualization issues haven't gone away. The technology has been with us around forty years, going back to mainframes. The VMware sever is a great product, but it's got to be properly configured it can still be compromised. We need to make sure that the management layer is all completely locked down and is

being monitored. Understanding who's got access to it and all the different workloads are properly segmented and configured \[60].

Having remote suppliers providing technical via VPN connections into your network, is fine, but do you monitor their activities and ensure their sessions are terminated and logged afterwards? This issue has been with us for the past fifty years, going back to the days or remote mainframe access via remote dial up terminals and even teletypes, yet in this automated digital Internet, mobile device age, it is still a current problem!

If they're looking after, a server farm on your premises and keep using a VPN to gain access, especially working from home, do you close that session down afterwards? Technical Support with Remote Desktop Access enabled, are the remote access sessions monitored and recorded? &#x20;

Containers as a technology have been used for a long time, but it's only just beginning to find&#x20;

its way into local government circles, but certainly been in central government for the past eight years and all the digital transformation stuff we're doing now, as you moved towards cloud and everything,&#x20;

it's becoming to be very, very pervasive, but a badly configured Docker container is a very dangerous thing

you need to do code reviews and smoke tests. Only then can you trust the container configuration for automated continuous integration and deployment.

I've been playing around with some security tools, which are on Git Hub and downloading other people's&#x20;

Docker containers. If you're going to play with stuff make sure you trust the source code, use a sandbox machine and monitor what he containers are doing on your systems.

I was looking at some particular containers and what was going on inside it looking at what was going on&#x20;

behind the scenes, via a command line terminal as they're spinning up, there were all sorts of erroneous

bits of code being spun up in the background. That wasn't necessarily part of the thing that the container&#x20;

was being used for. So when you start getting into these things, make sure you understand how it works&#x20;

and make sure you do code reviews and smoke testing and monitoring of the traffic and know what data is going into the containers and what's coming out of it. Continuous integration is the orchestration layer I&#x20;

was talking about earlier. Software like Jenkins and chef and lots of other new tools that are coming along.

Virtualization you really need to understand it. Quizzing your suppliers on the assurance side, might&#x20;

not only show you understand your supply chain security. might show, you know, what's happening.&#x20;

**Phishing**

Phishing might seem like it was yesterday's news, but it isn't. At the moment, it is the single biggest attack&#x20;

vector and the problem with phishing is that getting more and more sophisticated, starting to introduce&#x20;

primary, secondary and tertiary types of attack vectors. You may get an email that might also get an SMS message. You might even get a voice call and an awful lot of financial fraud is happening as the criminals themselves are going on-line because of the Covid restrictions and change of opportunities.

For instance, in the banking sector. Now you're getting it all followed up with a phone call. You're on a&#x20;

telephone to somebody and their say about this problem, you’re your bank account or they have detected a virus remotely on your computer. It's getting very, very sophisticated.&#x20;

We're actually seeing things out there now where you're getting SIM takeovers, so they can make their mobile phone look like your to the bank. Spoofing you number or that of your banks.

So you can't even rely on the phone number to be truthful. There is fraud utilising the SIPP IP Protocol, spoofing messages and contact centre details.

SIP is the voiceover IP protocols being used in some of this stuff\[61]. And the other thing that's starting&#x20;

to emerge with phishing attacks, I'm afraid issues and things like that. teams. So even Microsoft Teams\[63], is now becoming an attack vector\[64]. You need to bear in mind that these attackers

are getting more and more sophisticated. Make sure you are talking to our staff and doing awareness

raising because partially it's it's high, but awareness raising campaigns are the best line of defense. You've got the next slide please.

Blended attacks, are where you're starting to see attackers as I was just saying with phishing building&#x20;

stuff up. So NCSC National Cyber Security Centres, active cyber defence, ACD tools, come in really useful. The public DNS service (PDNS) \[65]  is available to all public sector bodies&#x20;

free of charge. The only problem with not using PSNs is of you running things like Cisco umbrella because NCSC are aware of incompatibilities. But when I was talking about, security zoning and domains earlier on, you might even want to think about splitting up some of your and IP ranges for different parts of

what you're doing and using PDNS, which when connected immediately flags malicious activities.

You have to remember is that the criminals now all starts in with their own pyramid of pain, because a lot of the, people deploying EMOTET\[64] at the bottom of the pyramid , the bottom level of these attacks&#x20;

are script kiddies, low value attackers and hackers. But the minute a machine beacons out after a successful takeover,  phone's back and says, yep, I've got into that network. They are then selling those credentials on those IP addresses to the next level of criminals up. Finally that's when you get in a tight spot of really&#x20;

serious people doing the malware attacks. And there has been a massive prevalence of malware and the

ransomware as an attack vector, especially since we've experienced the Covid lockdown and are working from home. The criminals are sitting at home plenty of time on their hands and they follow the money.&#x20;

**PROINT (Protected Information Intelligence)**

A new Provence is Protected Information Intelligence. This is where criminals are trying to steal&#x20;

protected, credential information, credit card information, you private identity information.&#x20;

But apart from these identities, the other stuff you've got to be aware of now is location information is becoming to be valuable because criminals know where you are.“I know you're not at home”. That is scary that you need to think through where this stuff's all going and biometric data as well. Biometric facial recognition say for mobile phone or laptop login. It's all new types of information and&#x20;

credentials that criminals are after.&#x20;

So you need to think that now it's all about passwords to biometrics, putting multiple lives, the text, Memphis there's personal information and privacy, all the same thing that you've got to remember that youngsters have a very different feel about privacy. And the fact that sometimes convenience can override privacy&#x20;

and they don't necessarily have the same view about this as we do in our generation.

So you need to bear that in mind, protected information is what people are after, because that's where the money is, wearables, body networks, smartphones, Fitbits etc. It's collecting all sort of information,&#x20;

proximity networks as well. Cars now have wifi networks or their own Bluetooth. It's always on, it's a new world we're moving into, but the really exciting stuff.&#x20;

The core of this whole talk for this second part of emerging threats, everything we do, which gives us an&#x20;

opportunity, brings me challenges and attack vectors. We've augmented reality now (Some will have seen tee new EE mobile phone advert for the iPhone 12) which shows an augmented reality scene over the roof tops of the city of London.

It is as much about geospatial information, not just knowing where you are, but what floor you're on, what&#x20;

office you're in. You're in, within a building, what shop you're in, in, within a shopping center, it's tracking these metrics. In time as we get more into this augmented reality and Facebook, Google, Apple, they're all working on new sets of super specs. The age of Joe 90 really is upon us.

A whole new world that is going to be a very different place in the next couple of years, what life&#x20;

boundaries are going to get blurred and working from home is going to be the new normal. So you need to think these issues through. Oculus has now been bought out by Facebook. You can't use the new Oculus&#x20;

Quest 2 devices unless you've got Facebook account. I've started doing some research on all of this&#x20;

right now, and it's going to take me a while to synthesize it all. Believe me, sitting there with a virtual&#x20;

reality headset on and doing work and coming up with all these computer screens from the fiscal world,&#x20;

moving into that new, augmented reality and virtual reality is going to be a way that if we're going to be&#x20;

working from home, someone's going to have the bright idea of, Oh, you won't be just about  MS teams&#x20;

anymore.

Should we use the, the new Facebook infinity office that, Facebook's working on right now. If you&#x20;

haven't do it, go and have a look, but that's where ethics come in. New personas. Will you have a different view for work and virtual reality to your persona at work and in our climate, in the real world, all you start to think about, especially with data protection, for the right speed forgotten. It's a new world of pain trying to manage multiple personas because Facebook won't let you do that. You've got to use your real personal Facebook account with your real personal identity to use the virtual reality stuff. Interesting times ahead.&#x20;

The global situation in 2026 is marked by a definitive shift from the old order to a more volatile "new order". Key factors influencing this include:

•           Opportunistic Aggression: Geopolitical rivalries, including the ongoing war in Ukraine and rising tensions between global powers, have normalised infrastructure failures and extreme economic uncertainty.

•           The War for Compute: Access to the physical technologies and talent required to process data—"compute"—has become a defining geopolitical risk. Access to this infrastructure is increasingly controlled by states, leading to stepped-up regulation and strategic competition.

•           Organised Crime as a Proxy: Hostile state actors are increasingly using networked criminal groups as proxies to exploit geopolitical rivalries. These groups operate with high reach and low cost, often targeting business processes rather than just computer systems.

•           Social and Political Grievances: Growing polarisation and "democratic backsliding" are eroding trust in institutions, leading to faster, more intense social unrest that can ignite with little warning.

&#x20;

**Dominant Trends and Emerging Threats**

Five core trends will dominate the risk landscape for UK organizations this year:

1\.        AI-Driven Deception at Scale: Generative AI has enabled "deceptive realism". Attackers now create hyper-realistic impersonation attempts via synthetic voice calls and deepfake videos that mimic executives or suppliers with near-perfect accuracy.

2\.        Machine-Speed Attacks: AI-powered reconnaissance and adaptive malware now rewrite themselves to bypass detection at "machine speed," easily outpacing traditional human-led security teams.

3\.        The Supply Chain as a Weapon: Smaller vendors have become the preferred entry point for attackers. Taking down a single crucial vendor can stop the operations of a global brand, creating a "domino effect" across the ecosystem.

4\.        Digital Extortion Beyond Ransomware: Threat actors have shifted to multi-vector extortion, combining data theft, regulatory pressure, and operational disruption. In the UK, new legislation prohibits publicly funded entities from paying ransoms, forcing a rapid shift toward robust resilience rather than negotiation.

5\.        OT and IoT Exposure: Manufacturers are pushing internet-connected features into legacy Operational Technology (OT) and Internet of Things (IoT) devices without adequate security, expanding the attack surface into physical infrastructure such as healthcare, transport, and utilities.

&#x20;

&#x20;

**Actionable Insights for Senior Leaders**

To navigate 2026, the following strategic actions are recommended:

•           Implement a Zero-Trust Baseline: Remove the assumption that anything inside your network is safe. Continuous verification of every user and device must become the norm.

•           Map and Assess Third-Party Risk: Only 14% of UK businesses currently review their supplier security. Leaders must move beyond this, ranking suppliers by risk level and setting clear rules in contracts.

•           Shift from Protection to Resilience: Recognise that a breach is probable. Invest in Managed Detection and Response (MDR) to provide the automated analysis required to counter real-time threats.

•           Institutionalise Red Teaming: Regularly simulate real-world attacks to test the effectiveness of decision-making processes and identify procedural blind spots.

•           Fix Broken Policies for AI: AI can drive efficiency, but automating bad processes only accelerates failure. Fix organisational policies before embedding AI agents into daily operations.&#x20;

&#x20;

&#x20;

&#x20;

**References: (All accessed July 2026)**

\[1] <https://www.gov.uk/government/groups/horizon-scanning-programme-team>

\[2] <http://portal.healthworkforce.eu/what-is-horizon-scanning-and-why-is-it-useful/>

\[3] <https://www.theirm.org/media/7423/horizon-scanning_final2-1.pdf>

\[4] <https://www.rand.org/blog/2019/02/how-horizon-scanning-can-give-the-military-a-technological.html>

\[5] <https://www.kent-life.co.uk/people/the-global-business-forecaster-kent-s-richard-scase-1-4435705>

\[6] <https://www.kateraworth.com/doughnut/>

\[7] <https://www.gov.uk/government/collections/joint-doctrine-publication-jdp>

\[8]<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/549291/20160720-Cyber_Primer_ed_2_secured.pdf>

\[9] <https://www.nao.org.uk/report/progress-of-the-2016-2021-national-cyber-security-programme/>

\[10] [https://www.ncsc.gov.uk](https://www.ncsc.gov.uk/)

\[11] <https://study.sagepub.com/sites/default/files/Birks_2008.pdf>

\[12] <https://www.ncsc.gov.uk/blog-post/equities-process>

\[13] <https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6735033/>

\[14] <https://uk.sagepub.com/sites/default/files/upm-binaries/49393_Walker,_Chapter_One.pdf>

\[15] <https://www.app.college.police.uk/app-content/intelligence-management/intelligence-report/>

\[16] <https://www.justsecurity.org/68075/three-things-to-look-for-in-the-2020-worldwide-threat-assessment-from-the-u-s-intelligence-community/>

\[17] <https://www.app.college.police.uk/app-content/intelligence-management/intelligence-products/>

\[18] <https://sloanreview.mit.edu/article/how-to-make-sense-of-weak-signals/>

\[19]<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/311572/20110830_jdp2_00_ed3_with_change1.pdf>

\[20] <https://worldview.stratfor.com/article/practical-guide-situational-awareness>

\[21] <https://hbr.org/2014/09/contextual-intelligence>

\[22] <https://azure.microsoft.com/en-gb/overview/what-is-cloud-computing/>

\[23] <https://www.redhat.com/en/topics/cloud-computing/what-is-cloud-infrastructure>

\[24] <https://www.gov.uk/government/publications/essential-digital-skills-framework/essential-digital-skills-framework>

\[25] <https://link.springer.com/chapter/10.1007/978-3-319-77839-6_3>

\[26] <https://www.ibm.com/uk-en/cloud/learn/iaas-paas-saas>

\[27] <https://www.cisco.com/c/en_uk/solutions/software-defined-networking/overview.html>

\[28] <https://docs.microsoft.com/en-us/azure/devops/learn/what-is-infrastructure-as-code>

\
\[29] <https://mitpress.mit.edu/books/norbert-wiener-life-cybernetics>

\
\[30] <https://aws.amazon.com/cloudhsm/>

\[31] <https://www.cbronline.com/feature/punched-tape-ukkpa>

\[32] <http://www.serverspace.co.uk/blog/containerisation-vs-virtualisation-whats-the-difference>

\[33] <https://codeship.com/continuous-integration-essentials>

\[34] <https://cyclr.com/orchestration-layer>

\[35]<https://www.researchgate.net/publication/319487635_Research_of_Penetration_Testing_Technology_in_Docker_Environment>

\[36] <https://www.infoq.com/articles/practices-better-code-reviews/>

\[37] <https://docs.microsoft.com/en-us/azure/aks/operator-best-practices-multi-region>

\[38] <https://www.ncsc.gov.uk/blog-post/zero-trust-architecture-design-principles>

\[39] <https://www.wandera.com/zero-trust-security/>

\[40] <https://www.ncsc.gov.uk/collection/mobile-device-guidance/infrastructure/network-architectures-for-remote-access>

\[41] <https://www.cyber.gc.ca/en/guidance/network-security-zoning-design-considerations-placement-services-within-zones-itsg-38>

\[42] <https://www.zachman.com/ea-articles-reference/58-conceptual-logical-physical-it-is-simple-by-john-a-zachman>

\[43] <https://www.opengroup.org/togaf>

\[44] [https://sabsa.org](https://sabsa.org/)

\[45] <https://livebook.manning.com/book/microservices-security-in-action/chapter-1/1>

\[46] <https://www.microsoft.com/en-gb/security/business/zero-trust>

\[47] <https://www.pwc.com.au/pdf/essential-8-emerging-technologies-internet-of-things.pdf>

\[48] <https://www.i-scoop.eu/internet-of-things-guide/>

\[49] <https://csrc.nist.gov/CSRC/media/Projects/Supply-Chain-Risk-Management/documents/briefings/Workshop-Brief-on-Cyber-Supply-Chain-Best-Practices.pdf>

\[50] <https://www.thethingsnetwork.org/docs/lorawan/>

\[51] <https://www.ncsc.gov.uk/section/advice-guidance/all-topics?topics=artificial%20intelligence>

\[52] <https://www.ncsc.gov.uk/section/products-services/active-cyber-defence>

\[53] <https://socitm.net/wp-content/uploads/2020/10/Digital-ethics-table.pdf>

\[54] [https://www.moralmachine.net](https://www.moralmachine.net/)

\[55] <https://plato.stanford.edu/entries/ethics-ai/>

\[56] <https://www.newscientist.com/article/2175195-robot-laws-5-new-rules-that-could-save-human-lives-at-least-on-tv/>

\[57] <https://www.centreforcities.org/reader/smart-cities/what-is-a-smart-city/>

\[58] <https://fas.org/irp/agency/nga/doctrine-2018.pdf>

\[59] <https://www.theguardian.com/government-computing-network/2011/jun/13/local-cio-council-information-assurance-strategy-mark-brett>

\[60]<https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/network_segmentation.pdf>

\[61] <https://link.springer.com/chapter/10.1007/978-3-642-11530-1_10>

\[62] <https://secureteam.co.uk/news/microsoft-office-files-increasing-used-as-attack-vector/>

\[63] <https://resources.infosecinstitute.com/topic/hacking-microsoft-teams-vulnerabilities-a-step-by-step-guide/>

\[64] <https://www.ncsc.gov.uk/news/ryuk-advisory>\[65] <https://www.ncsc.gov.uk/information/pdns>

!\[Shape

Description automatically generated]\(/files/-Mj9At5Ly8WUs9ySWcAy)

![](/files/-Mj9At5Mjojm6TXqX2gQ) [www.nlawarp.net](http://www.nlawarp.net/) @nlawarp

!\[A picture containing logo

Description automatically generated]\(/files/-Mj9At5N33UXOWKn-khq)

<https://www.londonmet.ac.uk/research/centres-groups-and-units/cyber-security-research-centre/>


# The Cyber Maturity Journey

This page explores a suggested approach to Cyber Maturity planning for Local Authorities, using a progressive journey metaphor. This DRAFT work as of November 2021

{% file src="/files/2m26QMrxCW1B8NRrqU2E" %}
Cyber Journey version 4 (November 2021 downloaqd file
{% endfile %}

&#x20;**DRAFT for Comment – Not Policy until approved.**&#x20;

When we first looked at this as a pure Cyber Maturity Modelling exercise, it was a perceived to be a move through the traditional maturity modelling approach. However, when we further explored the problem and what we were being asked to do, it became clear it was actually about mapping out pathways to a destination which was an agreed level of Cyber Maturity. &#x20;

&#x20;

This journey then is not necessarily linear in a straight line, but more about different pathways and routes with waypoints and bridges to the same destination. For some the journey will be short for others long. There is also the issue of budget and resource, whether you are walking, hitch hiking, taking public transport or being chauffeur driven.&#x20;

&#x20;

The language of a journey, pathways, and routes, mean that in some cases an organisation may be mature and experienced, further along the pathway while others have barely started out. The length of the journey and some of the route and maybe the transport method will be determined by the relevant profiles discussed later. Part of the journey maybe common to all provided by free public transport in the vestige of taking up and deploying the NCSC Active Cyber Defence programme resources that are free to consume.  The last part of the journey for some may be into uncharted territory on foot, of a regional Shared Cyber Operations Centre for instance.&#x20;

&#x20;

The original thought was a Cyber Maturity Model, however the tasking is to consider the Cyber maturity pathways, to define a journey towards having Cyber especially the defence and resilience aspects fully optimised in the organisation. If we take the journey analogy forwards, the quote from Alice in Wonderland seems apt.&#x20;

&#x20;

"If you don't know where you're going, **any road will take you there**." This oft-cited but not-quite-accurate quote is from the Lewis Carroll's classic children's tale, Alice in Wonderland.\[1] What’s required at each level? - Why are we doing this in the first place? (The Shared Cyber Doctrine)\[2]; &#x20;

&#x20;

To keep the organisations information safe, secure, accurate and available. This is the overarching strategy, that supports a higher shared UK doctrine, the real “Why & How”, things like protecting our freedoms and democracy, keeping the UK safe from Cyber Attacks so that it is a good place to live and transact business using Cyber to do so. This UK Cyber Doctrine, then translates into the UK defence and UK Cyber Strategy, which underpins the entire approach for how we do things. &#x20;

It is suggested to start with a baseline, a checklist approach for expediency, then the initial findings are baselined and the next steps and gaps can be identified, along with acknowledging good practice that’s already in place.&#x20;

Deploying through life measures, through the metaphor of a journey, so the language, approach and idiom must use the language of dynamic risk and movement. Language can influence communications immensely, which is the basis of NLP (Neuro Linguistic Programming) \[3].&#x20;

The use of Weak Signals \[4] , to pick out the threads of improvement already exist and can be built up, will ensure goal based momentum to the initiative. The use of Nudge \[5] to shape all training, education and awareness raising to highlight the good things that exist and then to highlight and clearly focus and re-enforce constantly the areas that need additional work. Nudge is all about constant almost subliminal communication, using briefings, messaging, incorporation into routine communications and social media. We could think of this as a broad-spectrum holistic approach, taking every opportunity. A Rich Picture \[6] can help articulate the vision in a visual way. A Wardley Map \[7] can help to capture the key steps and stages. Defining the needs and outcomes in terms of a Wicked Problem \[8] and Soft systems methodologies and also help \[9]. The whole point being this is really a transformational change journey, needing alternative pathways, depending on need. Having these pathways clearly articulated before engagement, then facilitates a predefined set of options that a practitioner can then analyse and apply as appropriate. &#x20;

Keeping with the journey analogy, the destination is mapped, however it may be necessary to complete some waypoint journeys along the way, these diversions, from the main path will ensure consistency. There is a very famous saying I like from NLP, “The Map is not the Territory” \[10]. Using metaphor, stories and parables enables communication of quite poignant technical issues in a simple understandable way. 90% of communication is about knowing the audience and adapting the same massaging to a diverse audience. &#x20;

&#x20; **“Profiles Principles, Pillars and Pathways”**&#x20;

## Profiles&#x20;

&#x20;

One size does not fit all. UK Councils vary in size and remit. Their common traits are that they administer their locality and are sovereign democratic entities by statue. Their size, systems and services can be quite different. There are other causal variables as well, their political direction, whether they have outsourced their ICT services etc. Therefore, we need several agreed profiles. The Cyber journey through to the destination must be achievable by all organisations regardless of type and size. Appropriateness of the wording of the expectations to realise the required effects are the key. &#x20;

&#x20;

&#x20;

## Principles&#x20;

&#x20;

The principles detail the outcomes the “Effects” required. The use of “Effects” is a particular phrase that resonates in the Resilience, Cyber and Military world, for instance if COBR/A requires an action to take place, during an emergency or crisis, they will not be prescriptive how it is done, they will however articulate “Required effect” \[11]  this is the required outcome. &#x20;

&#x20;

This in turn is a parallel to the articulation of principles, which themselves are stating the actual problem to be solved with a hint (nudge) towards the outcome and how to achieve it. In agile, we use “User Stories”, this too would work well in this part of the journey. Using the previously referenced P3T (Personnel, Physical, Procedural & Technical) approach, which we have updated to a “P4T  Model ©” to now include Profiles, which enables organisation specific approaches, according to the type and size of organisation.  The Personnel aspect here would be behavioural, I refer to it as “Behaviour Shaping”, that ultimately, the effect we are trying to achieve. &#x20;

&#x20;

**P4T (C)2020/21**

•       Personnel

•       Physical

•       Profiles

•       Procedures

•       Technical

&#x20;

## Pillars&#x20;

&#x20;

The Pillars are the cyber domains, sometimes referred to as the Underpinning Cyber Aspects (UCA’s) which are detailed below. In articulating to an organisation what good looks like, the UCA’s present several areas and aspects that are tangible and can be measured. This means they can be based-lined and then reported on. This compliance approach would utilise a phrase well known in Local Government Audit, that of Key lines of Enquiry (KLOEs).  The pillars support the entire eco system model. They are the supports that hold up the building above (Think of a tower block, the underground car part always has the supporting pillars, holding up the structure above. The building in this case is the network, the systems, services, and data that underpin the organisation and the business. Never forget the overarching objective of all of this is the protection, integrity, and availability of the organisation’s information. &#x20;

&#x20;

## Pathways&#x20;

&#x20;

The pathways are the route plans for each of the UCAs, The WHAT we need to achieve (The effect), and the HOW we get there. Think of them as a branch line off a main rail link. With a set of points at certain waypoints. The question at that point is “Does the desired effect at the appropriate level for this part of the journey exist? Yes or No”, if “yes” continue on the main pathway forward, if “No”, then switch to the branch line, carry out the required actions to complete that waypoint and return to the main line to continue. This then becomes an iterative continuous improvement process. &#x20;

&#x20;

## Levelling Up&#x20;

&#x20;

C-TAG were using the phrase an approach recently coined in mainstream politics of “Levelling up” back in the Summer, so we will continue to talk about levelling up., as it describes the effect we want. Levelling up in this context is not having to “Assume” that every Council in the UK is at a certain level of Cyber Maturity on a certain point on the Cyber Resilience Journey, we need to safely “Expect” that is the case. We’ve already discussed and descoped the idea of a level zero “Unknown status, not engaged and unable to contact the organisation to find out”. This means we expect all Councils have made some progress towards Cyber Resilience and the immediate expectation of a baseline starting point is clearly articulated. &#x20;

&#x20;

Using the Underpinning Cyber Aspects C-TAG and NCSC need to agree what level one looks like. This may be through the work of the LGA Cyber Programme or the combined efforts of the Department of Levelling up, Communities & Housing (DLUCH) along with  the Devolved Administrations.&#x20;

&#x20;

Level or step one, must be a unified agreed and accepted minimum baseline across the UK.  Level one will be predicated on statutory and legal requirements such as the Data Protection Act, which cannot be argued against and therefore the “Checklist” will be a baseline that is reasonable to expect any organisation to have in place and at no additional cost. The Roles and responsibilities are a statement of roles being in place that is someone carrying out the function. The NCSC Active Cyber Defence systems and services are available for all UK Local Authorities to consume at no cost, so that is reasonable to expect etc. &#x20;

&#x20;

The subsequent stages on the journey can be subject to agreement and debate. By the time we are discussing the destination it will require an articulation of what good looks like and a mixture of case studies exemplars, tools, and approaches to agree those principle led effects.&#x20;

&#x20;

## Learning Organisations and Continuous improvement&#x20;

&#x20;

The last thing we want to do is create a new set of burdens for any organisation. This approach is about being a Learning Organisation \[xxx], using proven methodologies such as double loop-learning \[xx] which fosters a culture of continuous improvement. Once the momentum is there especially through peer support afforded by the WARPs and C-TAG it becomes easier as the successes and failures are shared with peers in a safe place afforded by the WARPs and C-TAG. Where there are obvious wide gaps identified within specific or general profiles, additional workshops, tools, templates, and good practice sharing can be facilitated. We are familiar with the 1-9-90 social collaboration model \[xx] mentioned before, the WARPs especially foster this approach where the WARP is led by a Subject Matter Expert who acts as a trusted catalyst to bring learning and advisory to the group. The group then owns and adapts that learning and the suggested approaches into their own organisations. As far back as the 90’s there were the European Quality Assurance Framework (EQAF) model \[12] and the McKinsey MIT 90’s model \[13] both of which helped shape collaboration and learning. This was picked up by Osbourne and Gaebler \[14] in their work on re-inventing Government and subsequent research undertaken by the author \[15] which provided some of the original catalyst ideas that helped form the original WARP services in 2004/5. The work of Senge and his book the Fifth Discipline and its workbook \[16] also helped shape a lot of these innovations and the approach discussed by Tom Peters around organisations and innovation “In Search of Excellence” \[17]. The LGA has always proposed peer support as a catalyst to service improvements. The introduction of profiles, will help shape what success looks like and set acceptable expectations. &#x20;

The main thing to get right is what we call each of these labels. The idea of something like “initial” or “Preparing” for stage/level/way point one. The first label needs to reflect the start of the journey. The destination itself, needs to intermate, both arrival at the destination and the continuance of the journey as one thing we know about Cyber is that it’s evolving, dynamic and continuous. Attacks, subversion, and threats are going nowhere.&#x20;

&#x20;

Cyber Attacks and disruptions, will be a constant moving forward and are likely to increase as the global players realise Cyber Offensive campaigns are highly effective and likely are good value for money, with the real costs of Cyber coming from the Defensive side. &#x20;

&#x20;

**Preparing / Preventing / Progressing / Protecting / Progressive** &#x20;

The above is a throw away thought, not even a suggestion. We need each stage point to have a good narrative to explain that way point. The hard work starts on populating the staps and stages with the Underpinning Cyber Aspects (UCAs). Some of the way points will be hard stops. For instance, you can’t go beyond stage/level/point three, until you’ve all NCSC ACD products and Services in place and progression beyond four requires you have an active trained internal Cyber Coordination Cell to support the LRF CTAC etc. &#x20;

&#x20;

&#x20;

## The need for an Integrated Approach&#x20;

&#x20;

There is a lot of conflation between Risk Management, Information Security, Information Assurance, and Incident Response. This is where the profiles will come in useful, to shape the different UCAs. &#x20;

&#x20;

These issues are well documented and well understood. We do not need another maturity model, framework or standard, but a way in which we can match stakeholder engagement and take-up of the various Cyber Programmes and initiatives. Where there are gaps, the journey approach will be able to signpost relevant materials, templates and guidance to help the organisation move forward.&#x20;

&#x20;

The use of Profiles to provide a meaningful set of metrics, will be useful for strategic decision support in knowing which organisations have a well-developed understanding of Cyber Security according to their appropriate profile.&#x20;

&#x20;

Having a UK wide Local Authority view  will help shape investment and more importantly where gaps exist requiring interventions. &#x20;

&#x20;

&#x20;At all levels, we propose a set of profiles, reflecting needs, experience, and knowledge in the people as much as the technology.  (In no particular order of precedence);&#x20;

&#x20;

•       Members (Councillors) – The Board in a private organisation &#x20;

•       Senior Management, Corporate Management Team&#x20;

•       Services Consumers \[Users in old money] &#x20;

•       Suppliers – supply chain elements.&#x20;

•       Security / ICT Practitioners within the organisation&#x20;

•       Service Managers the SIRO & Information Asset Owners&#x20;

&#x20;

We must include suppliers and Councillors, especially for the higher maturity tiers as they must be informed and aware.&#x20;

&#x20;

Services users & suppliers, practitioners & Service Managers (Information Asset Owners) ,&#x20;

Senior Management (SIRO) and the Corporate Management Team and the Councils Members (Councillors). We must include suppliers and Councillors, especially for the higher maturity tiers as they must be informed and aware. The RACI approach \[18], is also useful for analysing the internal communications and posture of Organisations. &#x20;

&#x20;

For each of the waypoints we propose a set of metrics and measurements that can be clearly articulated across the RACI domains (responsibl&#x65;**, accountable, consulted, informed).** We also recommend pseudo-anonymisation of organisation details and names, with appropriate NCSC facilitates FOI exemption for this information. &#x20;

&#x20;

Each of the five levels can have a RAG Status as an organisation could be green at level 3 say but be amber at elements of 5 & 5, therefore an improvement plan is possible.&#x20;

&#x20;

## The Underpinning Cyber Aspects (UCAs) – (Subject to agreement and alteration.)&#x20;

&#x20;

•       Engagement / communications status &#x20;

•       Take up of ACD&#x20;

•       Member of NCSC CISP&#x20;

•       Member of Regional WARP&#x20;

•       Active in C-TAG/ Local CIO Council / Local Delivery Council&#x20;

•       Have a Cyber email address?&#x20;

•       Good Web/email Security&#x20;

•       Good Back UP strategy (Which has been tested!!)&#x20;

•       Cyber Essentials / PSN Compliance&#x20;

•       Following Data Handling guidelines&#x20;

•       Named SIRO / IAOs &#x20;

•       Corporate Information Governance Group meets.&#x20;

•       Suppliers are assessed (Cloud Principles) and aware of their responsibilities&#x20;

•       Regular Cyber Exercising&#x20;

•       Regular vulnerability Scanning &#x20;

•       Written and articulated Risk Appetite Statement • Information Risks part of Corporate Risk Register.&#x20;

•       OWASP Framework used to protect Website.&#x20;

•       MITRE ATT\&CK framework used for Risk Analysis ./ network defence. &#x20;

•       Contributions to National Policy etc. &#x20;

&#x20;

&#x20;

## Next Steps&#x20;

&#x20;

1\)The next stage is to agree the Cyber Underpinning Aspects (CUAs) and then defining them with a narrative against step/stages or waypoints 1-5 (zero having been excluded from the conversation, so zero is also one). Define the differences in the profiles (District/Unitary/County Council, Shared Service Partnership, Insourced/outsourced ICT etc. &#x20;

&#x20;

2\)Define a set of profile appropriate user stories or personas, so that the attainment statements are clear and measurable with either assertions (that can be evidenced) or through monitorable artefacts (ACD Take-up, email posture web site security / digital certificates etc). OWASP….&#x20;

&#x20;

3\) Refine the Draft spreadsheet Matrix of levels and CUAs with Narrative and then adapt the matrix for each profile.&#x20;

&#x20;

4\) Agree the labels for the level and the language to be used. &#x20;

&#x20;

5\) Undertake a pilot with the initial artefacts and journey map.

&#x20;           &#x20;

**References:**

\[1] Alice in Wonderland: <https://eric.ed.gov/?id=EJ997652>

&#x20;

\[2] Joint Doctrine <https://www.gov.uk/government/collections/joint-doctrine-publicationjdp>

&#x20;

\[3] NLP  <https://www.nlpacademy.co.uk/what\\_is\\_nlp/>

&#x20;

\[4] Weak Signals <https://sloanreview.mit.edu/article/how-to-make-sense-of-weak-signals/>

&#x20;

\[5] Nudge <https://www.imperial.ac.uk/nudgeomics/about/what-is-nudge-theory/>

&#x20;

\[6] Rich Picture <http://systems.open.ac.uk/materials/T552/pages/rich/richAppendix.html>

&#x20;

\[7] Wardley Maps <https://learnwardleymapping.com>

&#x20;

\[8] Wicked Problem <https://www.stonybrook.edu/commcms/wicked-problem/about/Whatis-a-wicked-problem>

&#x20;

\[9] Soft systems methodology &#x20;

<https://www.open.edu/openlearn/ocw/mod/oucontent/view.php?id=65641\\&section=6>

&#x20;

\[10]        Map is not the Territory  <https://conceptually.org/concepts/the-map-is-not-theterritory>

&#x20;

\[11]COBR/A Effects&#x20;

<https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment\\>\_ data/file/192425/CONOPs\_incl\_revised\_chapter\_24\_Apr-13.pdf

&#x20;

\[12] EQAF&#x20;

<https://eua.eu/component/attachments/attachments.html?task=attachment\\&id=1746>

&#x20;

\[13] MIT 90s Model <https://www.mckinsey.com/business-functions/people-andorganizational-performance/our-insights/the-organization-of-the-90s>

&#x20;

\[14] Reinventing government  <https://files.eric.ed.gov/fulltext/ED367424.pdf>

&#x20;

\[15] MBrett MRes (1999)&#x20;

<https://www.researchgate.net/publication/268517871\\_User\\_Led\\_Innovation\\_in\\_Local\\_Gov> ernment\_Service\_Delivery\_September\_1999

&#x20;

\[16] Senge (Fifth Discipline)  <https://mitsloan.mit.edu/faculty/directory/peter-m-senge>

&#x20;

\[17] Tom Peters In Search Of Excellence & Agile&#x20;

<https://blog.crossknowledge.com/excellence-according-to-tom-peters/>

&#x20;

\[18] RACI <https://www.cio.com/article/2395825/project-management-how-to-design-asuccessful-raci-project-plan.html>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;


# Digital Ethics and Data Handling

This discussion shows the linkages to the Digital Ethics Framework and the Data Handling Guidelines

{% file src="/files/YElNIQMgyrckWAFCt5Ow" %}

**Background & Context**

The relationship between data ethics and data handling may not be immediately obvious. However. Over the last few years. A lot has changed with automation. Machine learning. and other aspects, we have started to think about a new model that explains what this looks like. The work carried out by William Barker has developed the Digital Ethics model;

The principles of Digital Ethics;

&#x20;

·      **Beneficence:** do good. Benefits of work should outweigh potential risks.&#x20;

·      **Non-maleficence:** do no harm. Risks and harms need to be considered holistically, rather than just for the individual or organisation.&#x20;

·      **Autonomy:** preserve human agency. To make choices, people need to have sufficient knowledge and understanding.&#x20;

·      **Justice:** be fair. Specific issues include algorithmic bias and equitable treatment.&#x20;

·      **Explicability**: operate transparently so as to explain systems working and its outputs

&#x20;

The latest version of the Data Handling Guidelines includes a more expansive description of this work.&#x20;

&#x20;

There are a number of conceptual and logical aspects that need to be taken into account traditionally in ICT we started to think about the strategy, which defines the overall objectives and vision and the mission, that is their normally encompassed through policy.&#x20;

&#x20;

A set of principles or a more defined and specific policy gives us the handrails and defines both the scope and the exclusions (red lines) relating to that policy. A policy when properly defined should always use action centred language, that is verbs and actions, which can then be quantified and turned into key lines of enquiry and measured through defined metrics.&#x20;

&#x20;

&#x20;

&#x20;

Figure 2. The new Integrated Approach © M Brett 2021&#x20;

&#x20;

The next stage of the Data Handling Guidelines lead to the processes and procedures. The operational aspects of ICT and finally the tactical aspects, which are about keeping the service running, and dealing with things when they go wrong. The resilience and incident response aspects pick those up.&#x20;

&#x20;

We have considered the supporting aspects of that traditional view of strategy, policy operations and tactical.  This part of the conversation also includes  information governance. Information governance is where the data handling guidelines really start. It has become more and more apparent over the last couple of years, with the emergence of artificial intelligence especially, and that being embedded in a number of devices through the Internet to things.&#x20;

&#x20;

An emergent theme is that of Physical Cyber Systems(PCS). PCS reflects  operational capabilities. Digital ethics are  now absolutely critical. The Digital Ethics Principles themselves support strategic decision making through the ethics embedded in algorithms and Machine Learning. &#x20;

&#x20;

The in-built decision logic or machine leaning frameworks have to have gone through an ethical check as many PCSs will be deployed as “Fire and Forget” , maybe in service for many years, sitting in the corner, doing what they are doing without any further though or intervention.&#x20;

&#x20;

&#x20;We have to make sure that data. Is accurate, relevant and timely which has always been supported through information assurance(IA). Information Assurance has always considered the confidentiality, integrity, and availability of information. The ethical dimensions make sure that the information does not cause harm and actually protects the individual.&#x20;

&#x20;

Artificial intelligence generally is encompassed in algorithms, and even the UK Data Protection Act has now got specific protections for citizens, businesses and data users. around the right to challenge automated. Decisions made on your behalf. These aspects having been enshrined in data protection law. These subtle nuances are often miss understood by lay people as to their significance.&#x20;

&#x20;

To help articulate this the handling guidelines is a good framework, in so far as its overarching principles, which have always been based around people. Places, policies, processes and procedures. The dates handling guidelines were originally written back in 2008, in response to the loss of two data CDs, maintaining a huge UK wide data set.&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

![](blob:https://app.gitbook.com/3468cd26-55d4-4f8d-8d80-d1c41834f4ed)

Figure 3. Data Handling Guidelines Over-arching domains © Mark Brett 2021

&#x20;

&#x20;

&#x20;

&#x20;

**People**

&#x20;

The people aspect reflects the fact that people are often the weakest link in the process, whether that's maliciously or through mistakes and errors.&#x20;

&#x20;

**Places**

&#x20;

The places looks at physical security and of course places now is also around smart technologies, place based technology and the like.&#x20;

&#x20;

**Policy**

&#x20;

Policy remains the heart and central aspect of the titanium guidelines because from the previous model, that is how we actually hook together the world of strategy in the strategic and the vision driven things to the world of the operational and tactical things.&#x20;

&#x20;

**Processes**

&#x20;

The process is aspect is how we engage with the exchange of information exchange of data within systems. Systems are all woven together and interlinked. There are always data flows and that is picked up through data schemas. Information taxonomies and metadata. The interfaces. Likewise, data handling and the Data Protection Act look at cloud based systems as much as they do physical on premise systems. So the process aspect of the Data Handling Guidelines  pick up all of the data flows in information flows between systems and technologies.&#x20;

&#x20;

**Procedures**

&#x20;

The procedures are the final gritty part where things get. Written down and actually followed and taken on the customer journey. Under the Data Protection Act, we need to have data processing impact assessments and these DPS themselves are the logical. Journey the customer journey through the data sets, so there should always be a data flow diagram.&#x20;

&#x20;

As we said earlier on if these things are being automated through the through, the Internet of Things (IOT), which encompass Cyber Physical Systems (CPS), then ethics has to come in right at the start, so the contention now is the data. Ethics is as important as information security and assurance in making sure that a system is safe and secure and fit for purpose. In order to facilitate this, a C-TAG paper we  produced around information assets has explains the “SCRAPE” framework.&#x20;

&#x20;

&#x20;

![](blob:https://app.gitbook.com/5ff9d540-1e28-4374-b72a-8559e3b6b64b)

Figure 4. SCRAPE Framework © Mark Brett 2021

&#x20;

**Systems**

&#x20;

&#x20;

The systems aspect, to make sure that we undertake. Risk assessments and understand the value of the data and completely layout how a system looks both at the physical and logical level in his components. These are known as high level and low level designs and these are articulated through functional and non functional requirements.&#x20;

&#x20;

**Cartography**

&#x20;

This leads onto cartography. Which is basically about diagramming, and making sure that the whole of the data flows, the taxonomy is and the information scheme as a rule map town.&#x20;

**Registers**&#x20;

&#x20;

Register's consider how the information is put together, and you've then got orthogonal data sources that immutable. For instance, if you have a look on the gov.uk website, there is an immutable list of all of the countries that are officially recognised on the planet. That list needs to be. Immutable because it needs to be a final point. It needs to be a single resource of the truth, so we need registers to say what the truth looks like, and then that can be applied against information integrity to make sure that stuff is not been altered.&#x20;

&#x20;

**Attributes**

&#x20;

Attributes which looks at information attributes and the way that information is structured, both in terms of. Confidentiality, integrity and availability, but ethical dimensions need to be put in place across the top of those as well.&#x20;

&#x20;

**Patterns**

&#x20;

Patterns. When we talk about pattern, that's something like a an architectural diagram or a pattern for actually doing something in a set way. This is going to be especially useful for the Internet of Things, and likewise how not to do things, and those are called anti patterns. So under agile, by putting together user stories. An architectural patterns gives you a rich picture on how to design things, time and time again to make sure that they are safe and secure, and this will be especially useful for the Internet of Things.&#x20;

&#x20;

**Ethics**

&#x20;

Ethics. Taking the ethical principles and laying those over. the top of the data and information that needs onto the asset Discovery framework. Which is based around five domains being;

&#x20;

&#x20;

&#x20;

![](blob:https://app.gitbook.com/534a062a-f641-4c31-a36a-00c8819570f8)

Figure 5. The 5 D Information Asset Management Model © Mark Brett 2009-2021

&#x20;

&#x20;

**Decision**

&#x20;

Decision is to look at whether the information asset needs to exist in the first place.&#x20;

&#x20;

**Discovery**

&#x20;

Discovery is working out how the information asset is going to be deployed, where it fits in, and how its integrated.

&#x20;

**Determination**

&#x20;

Determination is to value it in terms of harm ethics and its information risk and assurance.&#x20;

Deployment then is about how the information is configured and actually put into the systems and how it will be used on the daily basis. So in other words, that's looking at data protection. Impact assessments. so who's going to have the information where the information is going to be listed and live what it's going to be used for how it's going to be used on why exists in the first place.

&#x20;

**Destruction**

&#x20;

We should always start with destruction, the end game, after necessary retention, how will you ensure the data is safely and appropriately destroyed, including all backup copies. Remember it may take a year or longer after destruction for all of the backups to be cycled off and destroyed. &#x20;

&#x20;

Finally we consider the “Underpinning Cyber Aspects” have been developed as a way of mapping through a journey path to look at all of these different things because it's just as important to make sure that information is properly resilient but that goes back to the tactical aspects of Cyber Resilience and Cyber Incident Response.

&#x20;

&#x20;

![](blob:https://app.gitbook.com/57c2652e-f4d2-4a58-a682-e1e265226209)

&#x20;

Figure 6. Underpinning Cyber Aspects © Mark Brett 2021

&#x20;

&#x20;

**References**

&#x20;

Source documents referred to in this paper are available at: [https://guidance.ctag.org.uk](https://guidance.ctag.org.uk/)

&#x20;

Some of these issues are also discussed in a recent article:

<https://socitm.net/resource-hub/blog/cyber-what-has-socitm-ever-done-for-us/>

&#x20;

&#x20;

[www.ctag.org.uk](http://www.ctag.org.uk/)

[www.nlawarp.net](http://www.nlawarp.net/)

&#x20;

&#x20;


# Security Vendors of Concern (SVoC)

The world of cyber security and information security has become a global interest. “Security Vendors of Concern (SVoC)”,  are those who may be under the control or influence of hostile states or organ

{% file src="/files/KcXy6T2kMaP8MJB4qmZb" %}


