> For the complete documentation index, see [llms.txt](https://guidance.ctag.org.uk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guidance.ctag.org.uk/local-authority-intelligence-requirements.md).

# Local Authority Intelligence Requirements

#### Introduction

&#x20;

The digital infrastructure of United Kingdom local government has undergone a seismic shift, evolving from a back-office administrative support function into the primary engine for essential public service delivery. This “GovTech” transformation, characterised by the "Digital by Default" \[43] philosophy, has significantly expanded the attack surface of local authorities, rendering them susceptible to a spectrum of sophisticated cyber threats that range from opportunistic ransomware campaigns to targeted state-sponsored espionage.\[1, 2]

&#x20;

This proposes a holistic approach to understand, define and specify the cyber Intelligence Requirements for UK Local Authorities. This will help support those councils engaged in the  Local Government Reorganisation (LGR) \[44] work . This approach integrates identified threats in 2026,\[45] integrating the NCSC CAF \[46] and utilising the LACES framework \[47].

&#x20;

UK Local Authorities, do not have a common  understanding or approach, to define their “Intelligence Requirements”. Local governments increasingly adopt emerging “GovTech” technologies, such as artificial intelligence and cloud-based services, the requirement for a robust, intelligence-led approach to security becomes paramount.\[3, 4]&#x20;

&#x20;

The fundamental challenge lies not merely in the procurement of defensive technologies, but in the precise identification of Cyber Intelligence Requirements (CIRs) and the subsequent development of meaningful, outcome-oriented metrics that align technical performance with organisational mission and public value.\[2, 4] This view has been formed from observations over the past seven years, working closely with the UK Local Government community.

&#x20;

&#x20;

#### &#x20;

Table of Contents

[Introduction](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750486)

[The approach we took](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750487)

[The Evolving Cyber Threat Landscape and the Municipal Environment](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750488)

[Theoretical Foundations of Cyber Intelligence and the Public Sector](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750489)

[The Intelligence Cycle as an Operational Blueprint](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750490)

[Adaptation of Military Doctrine to Municipal Cyber Defence](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750491)

[Intelligence Preparation of the Digital Environment (IPDE)](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750492)

[The "Strategy House" for CTI Alignment](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750493)

[The NCSC Cyber Assessment Framework (CAF) as a Performance Enabler](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750494)

[Mapping the CAF to Intelligence and Metrics](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750495)

[Advanced Resilience Metrics for Cloud-and-AI-Enabled GovTech](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750496)

[The Unified Resilience Model for GovTech](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750497)

[The Human Element: Socio-Technical Metrics and Cultural Intelligence](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750498)

[Trust and Inclusion as Security Metrics](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750499)

[Implementation Strategy for UK Local Government Reorganisation (LGR)](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750500)

[Resource and Time Commitment Estimates](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750501)

[The LACES Framework: A Holistic Principles Led Approach for Local Government](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750502)

[Core Dimensions of the LACES Framework](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750503)

[Integration of Physical and Digital Domains](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750504)

[Integrating LACES into Cyber Strategy](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750505)

[Cyber Threat Horizon Scanning in 2026](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750506)

[Operationalising Cyber Intelligence: From Horizon Scanning to CAF Compliance](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750507)

[Conclusion and future work:](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750508)

[Toward an Intelligence-Led  Resilience Model to support civic society](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750509)

[Bibliography](applewebdata://97BD30DD-A2F4-4E81-A2E4-AF5C6AB6F559#_Toc229750510)

&#x20;

#### &#x20;

#### The approach we took

&#x20;

The research followed a practice based, ethnographic approach. The qualitative evidence base has been collected through observations over the past seven years from working with a number of UK WARPS (Warning, Advice and Reporting Points) \[48] and the CTAG (Cyber Technical Advisory Group) \[49]. Evidence comprises the authors personal notes, discussions, meeting agendas and minutes.  A literature review was undertaken to ensure current UK Government strategy and policy was reflected in this paper.&#x20;

&#x20;

#### The Evolving Cyber Threat Landscape and the Municipal Environment

&#x20;

The contemporary threat landscape for UK local authorities is marked by a widening gap between the complexity of digital threats and the defensive capabilities of organisations often burdened by legacy technology and constrained budgets.\[5] Recent survey data indicates that UK businesses, including those in the public sector, are among the most frequently targeted globally, with 65% of firms reporting at least one attack in the previous year.\[6] Within this context, local government operations represent a unique target profile due to the concentration of sensitive citizen data and the criticality of the services provided, such as social care, electoral management, and housing benefits.\[2, 7]. These key cyber threats are identified in Table1, this list reflects the primary attack vectors as examples where further intelligence collections would be useful. There are many other threats we could consider in the wider context of Information Assurance and Risk Management.&#x20;

&#x20;

&#x20;

| Threat Category           | Primary Driver           | Impact on Local Authority                                                                           |
| ------------------------- | ------------------------ | --------------------------------------------------------------------------------------------------- |
| Ransomware                | Financial Gain           | Disruption of essential services, data exfiltration, and financial loss from recovery costs.\[8, 9] |
| Business Email Compromise | Fraud / Financial Gain   | Diversion of public funds, identity theft of staff and residents.\[6, 10]                           |
| Cyber Espionage           | Geopolitical / Strategic | Loss of intellectual property related to urban planning or sensitive demographic data.\[8, 11]      |
| Supply Chain Attacks      | Indirect Access          | Compromise of trusted vendors leading to cascading failures across council systems.\[6, 12]         |

<p align="center">Table 1: Key Cyber Threat Categories (Source: Author)</p>

&#x20;

The rapid adoption of AI-driven tools further complicates this landscape. While AI offers opportunities for enhanced detection, it also enables adversaries to achieve greater scale and sophistication in phishing and social engineering attacks.\[3, 8] This environment necessitates a shift from reactive cybersecurity—focused on firewall blocks and antivirus alerts—to proactive cyber intelligence, which seeks to anticipate and mitigate threats "left of the hack".\[13, 14]&#x20;

&#x20;

There are many existing frameworks, that could be deployed, the Lockhead Martin Kill Chain, The NIST CSF, The Mitre ATT\&CK framework The CERT-EU Cyber Threat Intelligence Framework and many others. \[20] &#x20;

&#x20;

This paper proposes an approach suitable for UK Local Authorities and the Public Sector, to support the CAF version 4.0 Framework \[39] moving forward. The Whole area of Cyber Threat Intelligence is not well understood, from the anecdotal observations, through the regional WARPs (Warning, Advice and Reporting Points), \[48] over the past 20 years.&#x20;

&#x20;

#### Theoretical Foundations of Cyber Intelligence and the Public Sector

&#x20;

Defining the distinction between cybersecurity and cyber intelligence is a vital prerequisite for organizational maturity. Cybersecurity involves the protective practices used to ensure the confidentiality, integrity, and availability of systems.\[15, 16] Cyber intelligence, conversely, is the systematic process of acquiring, processing, analysing, and disseminating information that identifies, tracks, and predicts threats and opportunities to enhance strategic decision-making.\[17] For local government, this intelligence provides the context necessary to prioritise limited resources on the most significant threats.\[9, 18]. This is a core requirement of the NCSC (National Cyber Security Centre)  CAF (Cyber Assessment Framework).&#x20;

&#x20;

#### The Intelligence Cycle as an Operational Blueprint

&#x20;

The practice of cyber intelligence is governed by a repeatable workflow known as the Intelligence Cycle. This framework ensures that intelligence activities are purposeful and aligned with organizational needs.\[19, 20] The proposed intelligence cycle is shown in figure 1.

&#x20;

• Direction and Planning: Identifying key information assets, comprising systems, services and data, such as the electoral register or social care portals, and defining the specific questions that need answering to protect them.\[7, 9]

• Collection: Gathering raw data from internal system logs, open-source intelligence (OSINT), and shared threat feeds.\[19, 20]

• Processing: Filtering, normalising, and structuring raw data into a format suitable for analysis.\[9]

• Analysis: Transforming and enriching data into intelligence by identifying patterns, assessing threat actor intent, and correlating threats with local vulnerabilities.\[16, 19]

• Dissemination and Feedback: Delivering actionable insights to decision-makers and using their feedback to tune and refine future requirements.\[17, 19]

&#x20;

A significant portion of the intelligence needed by local government is available through open sources. Methodical Open-Source Intelligence (OSINT) collection—defined as the purposeful exploitation of publicly available information to fulfil an intelligence requirements which would allow councils to monitor the broader threat environment without significant financial investment.\[18, 20, 21] These core elements feed into the risk management and assurance process cycles.&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 1: The Intelligence Cycle (Source: Author)</p>

#### Adaptation of Military Doctrine to Municipal Cyber Defence

&#x20;

To achieve a sophisticated level of intelligence requirement identification, local government can adapt established military frameworks, such as Intelligence Preparation of the Battlefield (IPB) or Intelligence Preparation of the Environment (IPE).\[22, 23] These doctrines provide a systematic methodology for understanding the "terrain" of a digital city and the capabilities of the "enemy".\[22, 24] These approaches are widely understood in the both the military and intelligence communities. Cyber is acknowledged to be the fifth battle domain. \[50] The current global situation is manifesting through a number of cyber operations which are affecting the UK’s Critical National Infrastructure, which includes national and local government. The UK defence strategy, talks about the whole societal approach. \[51] This in turn supports the doctrine of having a resilient civic society. \[52]

&#x20;

#### Intelligence Preparation of the Digital Environment (IPDE)

&#x20;

The IPDE process involves four continuous steps that, when applied to local government, provide a comprehensive understanding of the risk landscape.\[22, 23]

1\. Define the Operational Environment: Identifying and mapping, the limits of the council’s digital footprint, including third-party cloud services, Internet of Things (IoT) infrastructure in smart cities, and remote access points for staff.\[22, 25]

2\. Describe Environmental Effects: Analysing how the digital terrain influences operations. For example, how a single point of failure in a shared authentication service could impact multiple council departments.\[4, 22]

3\. Evaluate the Threat: Creating threat models for specific actors, such as ransomware groups or hacktivists, and identifying their known tactics, techniques, and procedures (TTPs).\[9, 23]

4\. Determine Threat Courses of Action (COAs): Predicting the most likely and most dangerous actions a threat actor might take, such as disrupting the council’s ability to process council tax payments during a critical financial window.\[22, 23]

Once gaps in the council's knowledge of the environment and threat are identified, they become the foundation for initial intelligence requirements.\[22] This needs to be considered in conjunction with a sectoral risk assessment to develop a sectoral (Local Government) Threat Profile.&#x20;

&#x20;

#### Identification of Cyber Intelligence Requirements (CIRs)

&#x20;

Identifying Cyber Intelligence Requirements (CIRs) is an organisational responsibility that requires collaboration across various functions, including IT, finance, social services, and legal teams.\[7, 19] Requirements should not be technical "wish lists" but should be derived from the council's strategic goals and risk appetite.\[10, 26]

Priority Intelligence Requirements (PIRs) and Specific Intelligence Requirements (SIRs)

A structured approach involves the hierarchy of Priority Intelligence Requirements (PIRs) and Specific Intelligence Requirements (SIRs).\[19, 27] Table 2 illustrates a couple of PIR/SIR examples.&#x20;

&#x20;

&#x20;

• PIRs: High-level questions that a "Senior Leader" (e.g., a Chief Executive or Senior Information Risk Owner) needs answered to make a strategic decision.\[27, 28]

• SIRs: Granular, answerable questions derived from PIRs that direct the collection efforts of analysts.\[19, 29]

&#x20;

&#x20;

| Requirement Type | Example for Local Government                                                                                                  | Strategic Decision Informed                                                    |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
| PIR              | What is the likelihood of a state-sponsored actor disrupting local electoral systems during the 2025 cycle? \[13, 28]         | Allocation of emergency capital for electoral system hardening.\[2]            |
| SIR              | Are there active phishing campaigns targeting election officials that utilise TTPs associated with known APT groups? \[9, 19] | Implementation of targeted MFA and staff awareness training.\[7, 10]           |
| PIR              | Which of the council's third-party cloud providers pose the greatest risk to service continuity for social care? \[26, 30]    | Development of a multi-cloud strategy or exit plan for critical systems.\[4]   |
| SIR              | Have any recent data breaches been reported by Vendor X's other public sector clients in the last 6 months? \[6, 9]           | Activation of enhanced monitoring and audit of Vendor X's access logs.\[4, 31] |

<p align="center">Table 2: Example PIRs / SIRs</p>

&#x20;

&#x20;

&#x20;

<p align="center">Figure 2: Illustration of the Intelligence Hierarchy – (Source: Author).</p>

#### The "Strategy House" for CTI Alignment

&#x20;

The "Strategy House" model provides a visualisation of how cyber threat intelligence (CTI) activities support broader departmental goals.\[32] In this model, the foundation is the council’s mission (e.g., providing safe and efficient community services). The pillars represent the tactical and operational intelligence functions, while the roof represents the strategic intelligence that guides the Senior Management Team (SMT).\[28, 32]&#x20;

&#x20;

This alignment prevents "wasteful spending" by ensuring that CTI efforts are moored to business context rather than chasing irrelevant technical indicators.\[10, 32]

&#x20;

Developing Meaningful Cyber Security Metrics

&#x20;

Having defined intelligence requirements, local authorities must transition to quantifying their security posture through metrics that reflect outcomes rather than mere activity.\[2, 33] Traditional metrics, such as "number of firewall hits," are often insufficient as they fail to reveal whether security efforts are actually reducing risk or preparing the organization for resilience.\[33, 34]

&#x20;

The Goal-Question-Metric (GQM) Paradigm

&#x20;

The GQM approach is a widely recognised academic framework for developing purposeful measurements.\[35, 36] It assumes that an organization must specify goals, match those goals to operational questions, and then provide quantifiable metrics to answer those questions.\[35, 36]

&#x20;

&#x20;

1\. Conceptual Level (Goal): Defined for an object (e.g., a social care database) for a specific reason (e.g., ensuring data integrity) from a particular perspective (e.g., the Data Protection Officer).\[35, 36]

2\. Operational Level (Question): A set of questions that characterise the object of study. For example, "How frequently are unauthorised attempts to modify records detected?".\[25, 36]

3\. Quantitative Level (Metric): A set of data associated with every question. For instance, "Mean Time to Detect (MTTD) unauthorised database changes".\[2, 4]

&#x20;

The GQM paradigm is particularly effective for municipal organizations because it allows for the "quantitatively expressed reduction of uncertainty" in complex, data-heavy environments.\[36]

&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 3: The GQM Process – (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

| GQM Level | Example Application: Council Tax System                                                                        | Rationale                                                                                 |
| --------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Goal      | Ensure the resilience of tax collection against ransomware disruption.\[35, 36]                                | High-priority revenue driver and essential public service.\[7, 12]                        |
| Question  | How long can the system remain offline before the impact on the council’s liquidity becomes critical? \[2, 31] | Characterizes the "acceptable loss" threshold for resilience.\[34, 37]                    |
| Metric    | Percentage of backups successfully restored within the 4-hour recovery window.\[4, 34]                         | Provides an objective measure of the system's ability to "withstand and recover".\[4, 34] |

<p align="center">Table 3: Example GQM Levels and Application</p>

&#x20;

Internal Efficiency vs. External Effectiveness

&#x20;

Research into cyber security performance identifies a critical distinction between internal efficiency—how well the security function operates—and external effectiveness—how well security supports the council’s mission.\[38]

&#x20;

• Internal Efficiency Metrics: These measure the "maturity" of IT processes, such as the percentage of systems compliant with the Minimum Cyber Security Standard, patching frequency, and the cost per incident handled.\[32, 38] These are often of moderate interest to senior leaders.\[38]

&#x20;

• External Effectiveness Metrics: These focus on "public value" outcomes. Examples include service continuity scores for citizens, inclusion metrics to ensure vulnerable groups are protected, and the "trust level" reported by residents regarding the safety of their digital data.\[2]

&#x20;

For local government, the strategic integration of these two dimensions is necessary to justify cyber spending not as a "back-office" cost but as a "public value proposition".\[2, 38]

&#x20;

#### The NCSC Cyber Assessment Framework (CAF) as a Performance Enabler

&#x20;

The UK Government has set out plans to adopt the NCSC Cyber Assessment Framework (CAF) as the primary assurance framework for public sector resilience.\[7, 31] The CAF provides a systematic approach to assessing the extent to which risks to essential functions are being managed.\[31, 39]

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

#### Mapping the CAF to Intelligence and Metrics

&#x20;

&#x20;

&#x20;

<p align="center">Figure 4: Mapping the Intelligence Process to the  CAF (Source: Author)</p>

&#x20;

&#x20;

The CAF is built on four core objectives, which can be directly mapped to the intelligence requirements and metrics discussed previously.\[7, 31]

&#x20;

• Objective A: Managing Security Risk: Requires intelligence on organizational structure and the supply chain.\[39, 40] Metrics include the "percent of critical systems with validated system architecture diagrams".\[7]

• Objective B: Protecting Against Cyber Attack: Requires tactical intelligence on TTPs.\[9, 40] Metrics include the "frequency of identity and access control reviews" and "staff awareness reporting rates".\[40, 41]

• Objective C: Detecting Cyber Security Events: Requires operational intelligence on active campaigns.\[9, 40] Metrics include the "percent of anomalous activity identified by proactive security monitoring".\[4, 40]

• Objective D: Minimizing the Impact of Cyber Security Incidents: Requires strategic intelligence on business continuity.\[28, 40] Metrics include the "time-to-recovery for essential functions" and the "implementation rate of lessons learned from previous incidents".\[31, 34]

&#x20;

The CAF utilises Indicators of Good Practice (IGPs) to evaluate if outcomes are 'Achieved', 'Partially Achieved', or 'Not Achieved', providing a standardised "baseline" that local authorities must meet at specified frequencies.\[7, 31, 40]

&#x20;

#### Advanced Resilience Metrics for Cloud-and-AI-Enabled GovTech

&#x20;

As local authorities migrate to cloud-and-AI-enabled platforms, new vulnerabilities emerge that require specialised metrics.\[4] These platforms increase the "attack surface" and create high levels of interdependency between public systems.\[4]

&#x20;

#### The Unified Resilience Model for GovTech

&#x20;

A proposed resilience framework for GovTech platforms integrates technical, organizational, and legal dimensions.\[4] The proposed GovTech capability lays the foundation for the Local Government Reorganisation (LGR) work, as a number of councils will be affected by the LGR, standardised approaches which will be developed through the Cyber Technical Advisory Group (CTAG) \[49], will ensure shared learning and mitigation of key risks, especially through supply chain assurance. This starts to augment the utility of the LACES framework, \[47] through practical knowledge sharing (Phronesis). \[53] The 2026 Horizon Scanning report \[54], highlights a number of key risks, threats and vulnerabilities. The summary findings are explored later in this paper.&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

<p align="center">Figure 5: The "GovTech" Concept to model Cyber Intelligence Requirements (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

Key Performance Indicators (KPIs) in this model include:

&#x20;

• Zero Trust Maturity: Percent of micro-segmented workloads and the frequency of continuous authentication events.\[4, 25]

• AI Governance: Percent of production AI models with documented provenance and adversarial robustness test pass rates.\[4]

• Privacy-Preserving Computation: Usage scores for technologies like federated learning or homomorphic encryption when handling sensitive demographic data.\[4]

• Organizational Capacity: Number of full-time security staff per 100 IT staff and annual cybersecurity training hours per employee.\[4, 8]

&#x20;

These metrics allow governments to "operationalise resilience" rather than treating it as an abstract ideal.\[4]

&#x20;

#### The Human Element: Socio-Technical Metrics and Cultural Intelligence

&#x20;

Cybersecurity in local government is a "socio-technical" challenge that cannot be solved by technical controls alone.\[41, 42] The "human element"—including the cognitive biases and heuristics of decision-makers—plays a critical role in resilience.\[38, 42]

&#x20;

#### Trust and Inclusion as Security Metrics

&#x20;

In the public sector, cybersecurity is increasingly recognised as a matter of "social justice".\[2] If digital services are not secure, vulnerable populations may be disproportionately impacted or excluded from essential services.\[2]

&#x20;

• Trust Enabler Metrics: Tracking citizen confidence in the safety of digital services as a predictor of digital transformation success.\[2]

• Inclusion Metrics: Ensuring that security measures do not create barriers for citizens with low digital literacy or those relying on older, less secure devices.\[2]

Furthermore, internal "cultural intelligence" is vital. Organizations must measure the stress and burnout levels of their cyber teams, as high stress (reported by 39% of victims) and burnout (32%) lead to increased human error and higher security risk.\[6, 8]

&#x20;

&#x20;

#### Implementation Strategy for UK Local Government Reorganisation (LGR)

&#x20;

For a local authority to successfully define requirements and metrics, a collaborative governance structure is essential. This involves identifying core roles such as the CAF Lead (often a cyber security specialist) and the Approver (a senior leader like a SIRO or Head of IT).\[7]&#x20;

&#x20;

#### Resource and Time Commitment Estimates

&#x20;

Developing a robust intelligence and measurement framework is a significant undertaking. Estimates for local government CAF implementation provide a benchmark for the level of effort required \[7]:

&#x20;

• Preparation and Role Identification: \~45 hours.\[7]

• Scoping and Critical System Identification: \~35-40 hours.\[7]

• Organisational Self-Assessment (Objectives A & D): \~40 hours.\[7]

• Mapping Architecture of 3 Critical Systems: \~15-25 hours per system.\[7]

• Critical Systems Self-Assessment (Objectives B & C): \~60 hours per system.\[7]

&#x20;

&#x20;

These time commitments reflect the shift from "tick-box" exercises to actionable resilience planning that requires engagement from directors, service leads, procurement, and risk managers.\[7] These timescales especially apply to the assurance process relating to key suppliers. The author is not aware that this is actually happening at scale and it has been identified a  key priority for the CTAG 2026 work programme, to facilitate a project to define and refine a common approach for UK Local Government to follow.&#x20;

&#x20;

#### The LACES Framework: A Holistic Principles Led Approach for Local Government

Building upon the necessity for a strategic and intelligence-led cybersecurity posture, the **Local Authority Cyber Eco-System (LACES)** framework offers a comprehensive model designed specifically for the complexities of the UK public sector. Developed to address the limitations of rigid, policy-driven cybersecurity measures, LACES advocates for a **principles-led approach** that is better suited to managing dynamic threats and the evolving digital landscape. This supports the notion of a resilient civic society, in a digital and cloud first world. This reflects modern statecraft, understanding “Cyber” as the fifth battle domain in a “Post rules, Disinformation & Post-Truth “ era. These issues were identified and validated during the recent Chatham House 2026 Directors Lecture. \[52]&#x20;

While frameworks like the NCSC’s Cyber Assessment Framework (CAF) provide assurance mechanisms, LACES bridges the gap between technical controls and organisational science, ensuring that cybersecurity is treated as a holistic business issue rather than solely a technical function.

&#x20;

&#x20;

&#x20;

&#x20;

#### Core Dimensions of the LACES Framework

&#x20;

&#x20;

&#x20;

<p align="center">Figure 6: LACES Framework (Source: Author)</p>

&#x20;

&#x20;

The framework is structured around six interconnected variables that function as a cohesive ecosystem. These variables can be viewed through a "variable-centric" lens, allowing organisations to shift focus depending on the operational context while maintaining a holistic view.

1. **Governance:** This provides the overarching oversight and direction for the ecosystem. It involves establishing clear policies, risk appetite, and structures such as a Corporate Information Governance Group (CIGG) and Senior Information Risk Owner (SIRO) to ensure cybersecurity is integrated into strategic decision-making.
2. **Assurance:** This dimension validates the effectiveness of security controls and manages risk, including supply chain vulnerabilities. It moves beyond "tick-box" compliance to a robust assessment of threats and vulnerabilities, often utilising mechanisms like penetration testing and health checks.
3. **Processes:** This covers the workflows, systems, and procedures (both manual and automated) used to deliver services. It recognises that processes bridge the physical and digital domains and must be documented and managed to ensure secure data transfer and operational integrity.
4. **Data:** Considered the "life blood" of local authorities, this variable focuses on the protection, management, and governance of information throughout its lifecycle—from creation to destruction. It emphasises the confidentiality, integrity, and availability of data in compliance with regulations like GDPR.
5. **Resilience:** Going beyond protection, this focuses on the ability to withstand, respond to, and recover from incidents. It includes business continuity planning, disaster recovery, and the implementation of "break glass" policies to restore critical services during disruptions.
6. **Knowledge Sharing:** This is the critical enabler of the ecosystem. It emphasises collaboration, peer support, and the exchange of "phronesis" (practical wisdom) through networks such as Warning, Advice and Reporting Points (WARPs) and the Cyber Technical Advisory Group (CTAG). This feedback loop ensures continuous improvement and situational awareness across the sector.

#### Integration of Physical and Digital Domains

A distinct feature of the LACES framework is its recognition that the cyber ecosystem exists simultaneously in **physical** and **digital** domains.

* **Physical Domain (Place-based):** Includes organisational structures, hierarchies, physical security measures, personnel, and culture.
* **Digital Domain (Process-based):** Encompasses the intangible aspects such as software, data flows, logic, and virtual cloud-based information.

LACES encourages decision-makers to map these domains against the six variables. For example, under **Governance**, the physical domain might involve physical security audits and meeting locations for incident response, while the digital domain involves data protection policies and risk appetite statements.

#### Integrating LACES into Cyber Strategy

The LACES framework can be integrated into a local authority's cyber strategy to shift from a reactive compliance posture to a proactive, principles-led culture:

* **Strategic Alignment and Education:** LACES serves as an educational tool to help non-technical senior leaders (such as CEOs and elected members) conceptualise cybersecurity as a complex ecosystem rather than a niche IT problem. By presenting the six variables, leaders can better understand resource allocation needs across the organisation.
* **Complementing the CAF:** While the NCSC Cyber Assessment Framework (CAF) focuses on resilience and assurance, LACES provides the broader organisational context required to implement the CAF effectively. The six variables of LACES can be mapped directly to CAF objectives (e.g., LACES "Governance" aligns with CAF Objective A: Managing Security Risk), ensuring that compliance efforts are supported by robust organisational structures.
* **Operational Planning and Incident Response:** LACES can be used to structure incident response playbooks. For instance, during a Distributed Denial of Service (DDoS) attack, the framework guides the response by prompting specific actions across all variables—from invoking **Governance** protocols for communication to executing **Resilience** plans for service continuity and engaging in **Knowledge Sharing** with external bodies such as the regional warps and CTAG. .
* **Supply Chain Management:** In an era of cloud-first strategies and Zero Trust architectures, LACES assists in managing supply chain risks by ensuring that **Assurance** and **Governance** extends to third-party vendors and Software-as-a-Service (SaaS) providers, who are often outside direct control.

By adopting LACES, local authorities can standardise their approach, foster a culture of collaboration, and build a cyber posture that is resilient enough to adapt to emerging technologies like Artificial Intelligence and the evolving threat landscape.

#### Cyber Threat Horizon Scanning in 2026

&#x20;

<p align="center">Figure 7: Horizon Scanning Summary Threats (Source: Author)</p>

&#x20;

Introduction: The Tipping Point

As local government bodies refine their cyber intelligence capabilities, they must align their requirements not just with current threats, but with a rapidly solidifying "New Order" of geopolitical instability and technological acceleration. Horizon scanning indicates that by 2026, cybersecurity will transition from a niche technical concern to a fundamental pillar of organisational survival. The landscape is no longer defined merely by isolated malware incidents but by a professionalised, adaptive industry that exploits human trust and systemic fragility. Consequently, the identification of Cyber Intelligence Requirements (CIRs) must pivot to address a world where access to "compute"—the physical technologies and talent required to process data—has become a defining geopolitical risk.

The 2026 Threat Landscape: Deception and Speed To develop effective Priority Intelligence Requirements (PIRs), decision-makers must understand the five core trends expected to dominate the risk landscape:

1. AI-Driven Deception: Generative AI has enabled a new era of social engineering. Attackers now utilise "deceptive realism" to create hyper-realistic deepfakes of executives and suppliers. Intelligence requirements must specifically task analysts with monitoring for synthetic voice and video indicators that could facilitate fraud or reputational damage.
2. Machine-Speed Attacks: Adaptive malware is now capable of rewriting itself to bypass detection at speeds that outpace human-led security teams. This necessitates a shift in metrics from "time to respond" to "automation readiness" and the deployment of Managed Detection and Response (MDR) capabilities.
3. The Supply Chain as a Weapon: The "domino effect" has become a primary attack vector, where smaller, less protected vendors are breached to gain entry into major organisations. With only 14% of UK businesses currently reviewing supplier security, intelligence collection must expand to include the risk posture of the entire vendor ecosystem.
4. Triple Extortion: The threat of ransomware has evolved into multi-vector extortion, combining data encryption with theft, client harassment, and regulatory pressure.
5. OT and IoT Exposure: The push for internet connectivity into legacy Operational Technology (OT) and Internet of Things (IoT) devices has expanded the attack surface into physical infrastructure, creating pivot points for attackers to enter critical systems.

The Actor Profile: Proxies and Activated Societies The distinction between state-sponsored espionage and financial cybercrime is collapsing. Hostile states increasingly use networked criminal groups as "deniable proxies" to execute sabotage and intelligence gathering. Furthermore, local authorities face a new threat from "activated societies"—groups animated by social and political grievances who may utilise cyber tactics to target institutions they perceive as unaccountable. This includes "wild card" individuals radicalised by algorithmic echo chambers, escalating the risk of insider threats and physical-digital hybrid attacks.

Strategic Imperatives for Resilience Navigating this landscape requires a fundamental shift in governance and operational posture:

* Fiduciary Duty: Cybersecurity failure is now viewed as a failure of corporate governance. Boards must treat cyber resilience as a standing agenda item and a fiduciary duty, with Directors and Officers facing personal accountability for negligence.
* Zero Trust Architecture: The assumption that internal networks are safe is obsolete. Organisations must implement a "Zero Trust" baseline, requiring continuous verification of every user and device.

·       The "Golden Hour": Response planning must move from static documents to dynamic playbooks. The "Golden Hour" framework should be used to define critical first actions, empowering teams to make pre-authorised decisions during the onset of a crisis, through the use of break glass policies. \[53]

&#x20;

Applying the LACES Framework to Future Threats

The Local Authority Cyber Eco-System (LACES) framework remains the primary vehicle for managing these emerging risks, offering a holistic bridge between technical controls and organisational strategy.

* Governance & Assurance: To counter supply chain weaponisation, LACES mandates a move beyond "tick-box" questionnaires to continuous assurance. This includes requiring a Software Bill of Materials (SBOM) from critical vendors and establishing "right to audit" clauses. Governance structures must also address the "human in the loop" mandate for AI-driven decisions to prevent automated errors.
* Knowledge Sharing: In the face of "deceptive realism," formal policy updates are too slow. LACES emphasises the exchange of "Phronesis" (practical wisdom) through networks like Warning, Advice and Reporting Points (WARPs) to keep pace with rapidly evolving social engineering tactics.
* Resilience & Processes: To manage machine-speed attacks, LACES advocates for "Agile Assurance" and "Break Glass" policies. These protocols allow for the immediate isolation of compromised cloud segments or API credentials before a board meeting can be convened, preventing systemic failure.
* Data: With the rise of "triple extortion," the focus shifts to protecting the "enterprise knowledge fabric." This involves conducting Data Protection Impact Assessments (DPIAs) for all AI systems to ensure compliance and mitigate risks associated with large language models.

#### Operationalising Cyber Intelligence: From Horizon Scanning to CAF Compliance

**Introduction: Intelligence in the "New Order"** As the local government sector moves toward 2026, the threat landscape is defined by a volatile "New Order" characterized by the "War for Compute" and the weaponisation of trust. Horizon scanning indicates that cybersecurity has transitioned from a niche technical concern to a fundamental pillar of organisational survival, where failure is viewed as a breach of corporate governance. To navigate this, local authorities must move beyond static defence to a dynamic, intelligence-led posture. This chapter demonstrates how to apply the Intelligence Cycle to the specific threats identified in the 2026 landscape—such as AI-driven deception and supply chain contagion—and maps this process directly to the NCSC Cyber Assessment Framework (CAF). This is summarised in figure 8.

**The Intelligence Cycle in the 2026 Landscape** The Intelligence Cycle provides the operational blueprint for transforming raw data regarding the 2026 threat landscape into actionable resilience strategies.

1. **Direction (Requirements):** This phase translates the organisation's strategic risks into Priority Intelligence Requirements (PIRs). In the context of 2026, PIRs must pivot to address "deceptive realism"—the use of AI to create hyper-realistic deepfakes—and the "domino effect" of supply chain breaches.
2. **Collection:** This involves gathering data to answer the PIRs. In a "Zero Trust" era, collection must extend beyond internal logs to include Real-time Software Bill of Materials (SBOMs) from vendors and "phronesis" (practical wisdom) shared through Warning, Advice and Reporting Points (WARPs).
3. **Processing & Analysis:** Raw data is converted into intelligence. Analysts must now filter for "machine-speed" indicators, as adaptive malware can rewrite itself to bypass traditional detection.
4. **Dissemination & Feedback:** Intelligence is delivered to decision-makers (e.g., the SIRO) to trigger "Golden Hour" responses or inform long-term strategy.

<p align="center">Figure 8: Integrated Intelligence Cycle (Source: Author)</p>

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

&#x20;

**Worked Example:**&#x20;

**The "Domino Effect" Supply Chain Attack** The following example illustrates how a local authority applies the Intelligence Cycle to a specific 2026 threat scenario, utilizing the LACES framework to contextualise the response and the CAF to measure compliance.

**Scenario:** Horizon scanning identifies a high probability of "Triple Extortion" attacks where threat actors compromise minor vendors to gain entry into major public sector networks.

**Step 1: Direction (Defining the Requirement)**

The Chief Executive and SIRO establish a **Priority Intelligence Requirement (PIR):** *Which third-party suppliers possess high-level API access to critical council data and exhibit vulnerability to AI-driven social engineering?*.

* **CAF Alignment:** This fulfils **Objective A (Managing Security Risk)**, specifically Principle A2 (Risk Management), by identifying risks to essential functions.

**Step 2: Collection (Gathering the Data)**

The cyber intelligence team initiates collection:

* **Internal:** Mapping the "Information Asset Ecosystem" to identify all vendors with API integration.
* **External:** Requesting real-time Software Bill of Materials (SBOMs) from top-tier vendors.
* **Human Intelligence:** Monitoring WARP feeds for reports of "Vishing / Deep Fakes / Phishing" attacks targeting specific sectors (e.g., adult social care software providers).

**Step 3: Analysis (Correlating the Threat)**

Analysts correlate the collected data. They identify that "Vendor X," a payroll provider, uses a legacy authentication method vulnerable to AI-enhanced phishing and has recently reported a breach in a different region.

* **Risk Assessment:** The analysis confirms a high likelihood of a "domino effect" breach where Vendor X becomes a pivot point for "machine-speed" lateral movement into the council’s network.
* **CAF Alignment:** This supports **Objective C (Detecting Cyber Security Events)**, specifically C1 (Security Monitoring), by moving from reactive logging to proactive threat identification.

&#x20;

**Step 4: Dissemination (Triggering the Response)**

The intelligence is disseminated to the Crisis Management Team (CMT) with a clear assessment: *Imminent risk of supply chain compromise via Vendor X.*

* **Action:** The SIRO invokes the **"Golden Hour"** guide. The specific "Break Glass" policy is authorised, permitting the immediate revocation of Vendor X’s API credentials before a formal board meeting can convene.

**Step 5: Operationalising via CAF and LACES**

The intelligence cycle concludes by cementing the response into the organisation’s assurance framework. Table 4 provides some example linkages.&#x20;

| CAF Objective                    | Intelligence-Led Action (2026 Context)                                                                                                                                                                                                           | LACES Variable Applied                                                            |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------- |
| **A: Managing Security Risk**    | **Action:** Mandate "Right to Audit" clauses and SBOMs for all top 10 suppliers, moving beyond "tick-box" questionnaires. **Outcome:** Governance structures acknowledge supply chain fragility as a fiduciary duty.                             | **Governance & Assurance:** Ensuring oversight extends to third parties.          |
| **B: Protecting Against Attack** | **Action:** Implement a "Zero Trust" baseline. Enforce multi-person approval for financial transactions to counter deepfake (deceptive realism) fraud. **Outcome:**&#x48;ardening the attack surface against AI-driven social engineering.       | **Processes & Data:** Bridging physical checks with digital zero-trust protocols. |
| **C: Detecting Events**          | **Action:** Deploy Managed Detection and Response (MDR) to counter "machine-speed" attacks that outpace human monitoring. **Outcome:** Transitioning from "time to respond" to "automation readiness" metrics.                                   | **Assurance:** Validating controls against adaptive threats.                      |
| **D: Minimising Impact**         | **Action:** Rehearse "Rising Tide" scenarios using dynamic playbooks rather than static plans. Establish "Crash Gate" triggers for rapid escalation. **Outcome:**&#x45;nsuring "graceful degradation" of services rather than systemic collapse. | **Resilience:** Planning for recovery and continuity.                             |

<p align="center">Table 4 CAF Linkages to LACES (Source: Author)</p>

#### &#x20;

#### &#x20;

#### Conclusion

#### Toward an Intelligence-Led  Resilience Model to support civic society

&#x20;

The path toward cyber resilience in UK local government requires the strategic integration of intelligence requirement identification and meaningful performance quantification. By adopting established academic and professional frameworks—such as the GQM paradigm, the NCSC CAF, and military-derived IPDE processes—local authorities can move beyond a reactive posture.\[22, 31, 36]

&#x20;

Intelligence requirements must be become one foundational organisational goals, recognised as a corporate information risk. Every collection and analysis effort directly supports the continuity of essential public services.\[10, 32] Simultaneously, metrics must transition from measuring technical activity to measuring mission-centric outcomes, public value, and the "trust" that underpins the digital social contract between the state and its citizens.\[2, 4] This aspect of statecraft matters and supports a resilient civic society.&#x20;

&#x20;

Once a discovery process has been carried out and common local government intelligence requirements have been identified, they can the standardised, documented and shared as a polled data base of common risks, threats and vulnerabilities, affecting all UK local authorities. This artefact would be of great use as part of the LGR process and in turn support the effective managed of supply chain risk, an idented key threat to all local authorities and indeed, the wider public sector. Such a database of key threats, risks and vulnerabilities could be maintained nationally through a community peer support group such as CTAG. This also wholly supports the LACES Information and Knowledge Sharing approach.

&#x20;

As local governments navigate the "paradox" of adopting emerging technologies while managing legacy risks, the ability to "quantify what matters" will distinguish resilient organizations from those perpetually reacting to the latest crisis.\[8, 33] The ultimate goal is to reshape cybersecurity from a "necessary cost centre" into a strategic transformation enabler of speed, scale, and safety for the digital public square.\[2]

The World Economic Forum 2026 horizon scanning demands that local authorities and others transition from a posture of protection to one of resilience.\[55] This was a key message from the NCSC CyberUK 2026 conference. By integrating the LACES framework with the NCSC’s Cyber Assessment Framework (CAF), organisations can operationalise their intelligence requirements, turning abstract threats into manageable business risks. Whilst we cannot prevent cyber-attacks, careful planning and a intelligence led approach to threats, can help towards mitigating the impacts locally on what is likely to remain in the Cyber battle domain, a volatile world stage.&#x20;

<br>

&#x20;

#### Bibliography

&#x20;

1\. Publications | Local Government Association, [https://www.local.gov.uk/publications?sort\_order=ASC\&topic%5B5868%5D=5868\&sort\_by=title\&page=1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.local.gov.uk%2Fpublications%3Fsort_order%3DASC%26topic%255B5868%255D%3D5868%26sort_by%3Dtitle%26page%3D1)

2\. Rethinking Cyber Security as a Public Sector Value Proposition - Littlefish, [https://www.littlefish.co.uk/news-insights/cyber-security-services-public-sector-value-proposition/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.littlefish.co.uk%2Fnews-insights%2Fcyber-security-services-public-sector-value-proposition%2F)

3\. A UK Cyber Growth Action Plan - Imperial College London, [https://www.imperial.ac.uk/media/imperial-college/research-centres-and-groups/centre-for-sectoral-economic-performance/FINAL\_The\_UK\_Cyber\_Growth\_Action\_Plan\_Brochure\_RGB.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.imperial.ac.uk%2Fmedia%2Fimperial-college%2Fresearch-centres-and-groups%2Fcentre-for-sectoral-economic-performance%2FFINAL_The_UK_Cyber_Growth_Action_Plan_Brochure_RGB.pdf)

4\. Cyber-Resilient Public Infrastructure: Securing Government Systems ..., [https://journalwjarr.com/sites/default/files/fulltext\_pdf/WJARR-2025-2195.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fjournalwjarr.com%2Fsites%2Fdefault%2Ffiles%2Ffulltext_pdf%2FWJARR-2025-2195.pdf)

5\. Cyber resilience of UK digital infrastructure - UK Parliament, [https://researchbriefings.files.parliament.uk/documents/POST-PN-0753/POST-PN-0753.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fresearchbriefings.files.parliament.uk%2Fdocuments%2FPOST-PN-0753%2FPOST-PN-0753.pdf)

6\. Hiscox Cyber Readiness Report 2025, [https://www.hiscox.co.uk/cyberreadiness](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.hiscox.co.uk%2Fcyberreadiness)

7\. About the Cyber Assessment Framework for local government - UK ..., [https://www.security.gov.uk/policy-and-guidance/cyber-assessment-framework-caf-for-local-government/understand-the-cyber-assessment-framework/about-the-cyber-assessment-framework-for-local-government/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.security.gov.uk%2Fpolicy-and-guidance%2Fcyber-assessment-framework-caf-for-local-government%2Funderstand-the-cyber-assessment-framework%2Fabout-the-cyber-assessment-framework-for-local-government%2F)

8\. Global Cybersecurity Outlook 2025 - World Economic Forum: Publications, [https://reports.weforum.org/docs/WEF\_Global\_Cybersecurity\_Outlook\_2025.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Freports.weforum.org%2Fdocs%2FWEF_Global_Cybersecurity_Outlook_2025.pdf)

9\. Cyber Threat Intelligence 101: A Business Owner's Guide - TechBrain, [https://www.techbrain.com.au/cyber-security-threat-intelligence-101/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.techbrain.com.au%2Fcyber-security-threat-intelligence-101%2F)

10\. Orienting Intelligence Requirements to the Small Business Space ..., [https://www.huntress.com/blog/orienting-intelligence-requirements-to-the-small-business-space](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.huntress.com%2Fblog%2Forienting-intelligence-requirements-to-the-small-business-space)

11\. Cyber Resilience and Incident Response in Smart Cities: A Systematic Literature Review, [https://www.mdpi.com/2624-6511/3/3/46](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2624-6511%2F3%2F3%2F46)

12\. Cyber Threat Intelligence in a Business Context - Crest-approved.org, [https://www.crest-approved.org/wp-content/uploads/2022/04/CTI-in-Business-Context\_2021.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.crest-approved.org%2Fwp-content%2Fuploads%2F2022%2F04%2FCTI-in-Business-Context_2021.pdf)

13\. Strategic cyber intelligence - University of South Florida, [https://pure.lib.usf.edu/ws/portalfiles/portal/40770079/Strategic%20Cyber%20Intelligence%20-%20IMCS%20Journal-ArticlePageFirst.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpure.lib.usf.edu%2Fws%2Fportalfiles%2Fportal%2F40770079%2FStrategic%2520Cyber%2520Intelligence%2520-%2520IMCS%2520Journal-ArticlePageFirst.pdf)

14\. (PDF) Strategic Cyber Intelligence - ResearchGate, [https://www.researchgate.net/publication/279223723\_Strategic\_Cyber\_Intelligence](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F279223723_Strategic_Cyber_Intelligence)

15\. Cyber Intelligence Tradecraft Report - Software Engineering Institute, [https://www.sei.cmu.edu/documents/1589/2019\_011\_001\_546699.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.sei.cmu.edu%2Fdocuments%2F1589%2F2019_011_001_546699.pdf)

16\. Cyber Intelligence Tradecraft Report - DTIC, [https://apps.dtic.mil/sti/pdfs/AD1090501.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Fpdfs%2FAD1090501.pdf)

17\. Cyber Intelligence Tradecraft Report - DTIC, [https://apps.dtic.mil/sti/trecms/pdf/AD1133277.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Ftrecms%2Fpdf%2FAD1133277.pdf)

18\. Tactical Cyber Threat Intelligence: Identifying Maturity Development Successes and Complications - Techne, [https://www.techne.ac.uk/media/25340/article1\_project.pdf.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.techne.ac.uk%2Fmedia%2F25340%2Farticle1_project.pdf.pdf)

19\. Cyber Threat Intelligence Lifecycle: Answering the CTI Analyst Challenge - Medium, [https://medium.com/@s.lontzetidis/cyber-threat-intelligence-lifecycle-answering-the-cti-analyst-challenge-3ddf7e0be28c](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmedium.com%2F%40s.lontzetidis%2Fcyber-threat-intelligence-lifecycle-answering-the-cti-analyst-challenge-3ddf7e0be28c)

20\. Full article: The long history of OSINT - Taylor & Francis Online, [https://www.tandfonline.com/doi/full/10.1080/16161262.2023.2224091](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.tandfonline.com%2Fdoi%2Ffull%2F10.1080%2F16161262.2023.2224091)

21\. Open-source intelligence: a comprehensive review of the current state, applications and future perspectives in cyber security - NIH, [https://pmc.ncbi.nlm.nih.gov/articles/PMC10014398/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpmc.ncbi.nlm.nih.gov%2Farticles%2FPMC10014398%2F)

22\. FM 34-130 INTELLIGENCE PREPARATION OF THE BATTLEFIELD - Marines.mil, [https://www.marines.mil/Portals/1/Publications/FM%2034-130.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.marines.mil%2FPortals%2F1%2FPublications%2FFM%252034-130.pdf)

23\. ATP 2-01.3 Intelligence Preparation of the Battlefield Headquarters, Department of the Army, [https://home.army.mil/wood/application/files/8915/5751/8365/ATP\_2-01.3\_Intelligence\_Preparation\_of\_the\_Battlefield.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fhome.army.mil%2Fwood%2Fapplication%2Ffiles%2F8915%2F5751%2F8365%2FATP_2-01.3_Intelligence_Preparation_of_the_Battlefield.pdf)

24\. Joint Doctrine Publication 2-00 - GOV.UK, [https://assets.publishing.service.gov.uk/media/653a4b0780884d0013f71bb0/JDP\_2\_00\_Ed\_4\_web.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fassets.publishing.service.gov.uk%2Fmedia%2F653a4b0780884d0013f71bb0%2FJDP_2_00_Ed_4_web.pdf)

25\. Opportunities to Improve DoD Cyber Survivability - DAU, [https://www.dau.edu/sites/default/files/2024-09/DAU%20Zero%20Trust%20%20%20Cyber%20Survivable%20for%20Acq%20%20%2020240919%20%20REV1.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.dau.edu%2Fsites%2Fdefault%2Ffiles%2F2024-09%2FDAU%2520Zero%2520Trust%2520%2520%2520Cyber%2520Survivable%2520for%2520Acq%2520%2520%252020240919%2520%2520REV1.pdf)

26\. Mapping cyber governance code to NCSC Cyber Assessment Framework - GOV.UK, [https://www.gov.uk/government/publications/cyber-governance-mapping/mapping-cyber-governance-code-to-ncsc-cyber-assessment-framework](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fpublications%2Fcyber-governance-mapping%2Fmapping-cyber-governance-code-to-ncsc-cyber-assessment-framework)

27\. Priority Intelligence Requirement Answering and Commercial Question-Answering: Identifying the Gaps - DTIC, [https://apps.dtic.mil/sti/tr/pdf/ADA525251.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fapps.dtic.mil%2Fsti%2Ftr%2Fpdf%2FADA525251.pdf)

28\. Strategic Cyber Intelligence Overview | PDF | Threat (Computer) - Scribd, [https://www.scribd.com/document/254594111/Strategic-Cyber-Intelligence](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.scribd.com%2Fdocument%2F254594111%2FStrategic-Cyber-Intelligence)

29\. Homeland Security Advisory Council and Lessons Learned Information Sharing, [https://www.dhs.gov/xlibrary/assets/Final\_LLIS\_Intel\_Reqs\_Report\_Dec05.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.dhs.gov%2Fxlibrary%2Fassets%2FFinal_LLIS_Intel_Reqs_Report_Dec05.pdf)

30\. Contextualising and Aligning Security Metrics and Business Objectives: a GQM-based Methodology - Semantic Scholar, [https://www.semanticscholar.org/paper/Contextualising-and-Aligning-Security-Metrics-and-a-Philippou-Frey/b878bccc7f0d70bed5c193dd7d049b86c333f053](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.semanticscholar.org%2Fpaper%2FContextualising-and-Aligning-Security-Metrics-and-a-Philippou-Frey%2Fb878bccc7f0d70bed5c193dd7d049b86c333f053)

31\. Cyber Assessment Framework – Policy brief | Local Government ..., [https://www.local.gov.uk/our-support/cyber-digital-and-technology/cyber-digital-and-technology-policy-team/cyber-assessment](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.local.gov.uk%2Four-support%2Fcyber-digital-and-technology%2Fcyber-digital-and-technology-policy-team%2Fcyber-assessment)

32\. Cyber Threat Intelligence in Government: A Guide for Decision ..., [https://hodigital.blog.gov.uk/wp-content/uploads/sites/161/2020/03/Cyber-Threat-Intelligence-A-Guide-For-Decision-Makers-and-Analysts-v2.0.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fhodigital.blog.gov.uk%2Fwp-content%2Fuploads%2Fsites%2F161%2F2020%2F03%2FCyber-Threat-Intelligence-A-Guide-For-Decision-Makers-and-Analysts-v2.0.pdf)

33\. Cybersecurity Metrics That Matter: Building Automation Readiness and Resilience in Government - Papers, [https://papers.govtech.com/Cybersecurity-Metrics-That-Matter%3A-Building-Automation-Readiness-and-Resilience-in-Government-144049.html](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpapers.govtech.com%2FCybersecurity-Metrics-That-Matter%253A-Building-Automation-Readiness-and-Resilience-in-Government-144049.html)

34\. Cyber Resiliency Metrics, Measures of Effectiveness, and Scoring - The MITRE Corporation, [https://www.mitre.org/sites/default/files/2021-11/prs-18-2579-cyber-resiliency-metrics-measures-of-effectiveness-and-scoring.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mitre.org%2Fsites%2Fdefault%2Ffiles%2F2021-11%2Fprs-18-2579-cyber-resiliency-metrics-measures-of-effectiveness-and-scoring.pdf)

35\. Using Goal-Question-Metric (GQM) Approach to Assess Security in Cloud Storage, [https://www.researchgate.net/publication/315443218\_Using\_Goal-Question-Metric\_GQM\_Approach\_to\_Assess\_Security\_in\_Cloud\_Storage](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F315443218_Using_Goal-Question-Metric_GQM_Approach_to_Assess_Security_in_Cloud_Storage)

36\. Using Goal-Question-Metric (GQM) Approach to ... - ePrints Soton, [https://eprints.soton.ac.uk/411068/1/Using\_Goal\_Question\_Metric\_GQM\_Approach\_to\_Assess\_Security\_in\_Cloud\_Storage.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Feprints.soton.ac.uk%2F411068%2F1%2FUsing_Goal_Question_Metric_GQM_Approach_to_Assess_Security_in_Cloud_Storage.pdf)

37\. Strengthening the Resilience of Defence Critical Electric Infrastructure - Department of Energy, [https://www.energy.gov/sites/default/files/2022-03/FINAL%20Report%20-%20Strengthening%20DCEI%20Resilience.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.energy.gov%2Fsites%2Fdefault%2Ffiles%2F2022-03%2FFINAL%2520Report%2520-%2520Strengthening%2520DCEI%2520Resilience.pdf)

38\. Application of grounded theory in construction of factors of internal efficiency and external effectiveness of cyber security and developing impact models - Emerald Publishing, [https://www.emerald.com/ocj/article/3/1/41/305646/Application-of-grounded-theory-in-construction-of](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Focj%2Farticle%2F3%2F1%2F41%2F305646%2FApplication-of-grounded-theory-in-construction-of)

39\. Cyber Assessment Framework - NCSC.GOV.UK, [https://www.ncsc.gov.uk/collection/cyber-assessment-framework](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.ncsc.gov.uk%2Fcollection%2Fcyber-assessment-framework)

40\. CAF Cyber Assessment Framework Compliance - Armis, [https://www.armis.com/solutions/cyber-assessment-framework-caf/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.armis.com%2Fsolutions%2Fcyber-assessment-framework-caf%2F)

41\. Research Institute in Science of Cyber Security (RISCS) Phase 2 - GtR, [https://gtr.ukri.org/projects?ref=EP%2FN033396%2F1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fgtr.ukri.org%2Fprojects%3Fref%3DEP%252FN033396%252F1)

42\. Decision-Making under Constraints: A Behavioural Economics Perspective on Cyber-Related Heuristics and Biases, [https://bip.ug.edu.pl/sites/default/files/postepowania\_naukowe/117376/praca/rozprawa\_doktorska\_marc\_wilczek.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fbip.ug.edu.pl%2Fsites%2Fdefault%2Ffiles%2Fpostepowania_naukowe%2F117376%2Fpraca%2Frozprawa_doktorska_marc_wilczek.pdf)

43.<https://www.gov.uk/government/news/launch-of-gov-uk-a-key-milestone-in-making-public-service-delivery-digital-by-default>

44.<https://www.gov.uk/government/collections/local-government-reorganisation-policy-and-programme-updates>

45.<https://www.gov.uk/government/publications/government-cyber-action-plan/government-cyber-action-plan>

46\. <https://www.ncsc.gov.uk/collection/cyber-assessment-framework>

47\. <https://repository.londonmet.ac.uk/10935/>

48\. [https://nlawarp.net](https://nlawarp.net/)

49\. [https://www.ctag.gov.uk](https://www.ctag.gov.uk/)

50.<https://www.raf.mod.uk/what-we-do/centre-for-air-and-space-power-studies/aspr/apr-vol18-iss1-7-pdf/>

51.<https://assets.publishing.service.gov.uk/media/683d89f181deb72cce2680a5/The\\_Strategic\\_Defence\\_Review\\_2025\\_-\\_Making\\_Britain\\_Safer\\_-\\_secure\\_at\\_home\\_\\_strong\\_abroad.pdf>

52.<https://www.chathamhouse.org/events/all/standard-event/directors-annual-lecture-2026>

53\. <https://repository.londonmet.ac.uk/9559/>

54.<https://www.researchgate.net/publication/348931430_Horizon_Scanning_White_Paper>

55\. [https://reports.weforum.org/docs/WEF\_Global\_Cybersecurity\_Outlook\_2026.pd](https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://guidance.ctag.org.uk/local-authority-intelligence-requirements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
