
CASE STUDY — CENTRAL GOVERNMENT
A multi-year programme, a small team, and hundreds of competing demands on the same budget. The department is anonymised. The way of working isn't.
THE PROBLEM
?
"WHAT HAPPENS TO OUR CAF
POSITION IF WE CUT THIS?"
NOBODY COULD ANSWER IN THE ROOM.
A UK central government department, partway into a multi-year cyber transformation. The usual shape: a long list of candidate work, a fixed budget envelope, and a board that wanted to know — reasonably — what it was buying, what it was deferring, and what deferring it would cost.
The programme's answers lived in slide decks and spreadsheets, each assembled by hand, each slightly out of date by the time it was presented. When priorities shifted, the reasoning behind the old plan went with it. And when someone proposed dropping a work package to save money, nobody could say — in the meeting, with confidence — what that did to the department's position against the NCSC Cyber Assessment Framework.
WHAT WE DID
One OTB consultant, inside the small transformation team — same stand-ups, same deadlines, same tea rota. Not a reviewer at arm's length; a member of the team accountable for the plan being honest.
Every candidate work package scored for benefit and effort, with the weightings agreed openly — so "why is this above that?" always has an answer, and the answer isn't "because someone senior said so".
The baseline is the baseline. Every change to it is logged with a justification, so the programme's history reads as a series of decisions — not a series of surprises.
Each work package mapped to the CAF outcomes it supports. Propose cutting one, and the effect on the department's CAF position appears alongside the saving — before the decision, not after it.
Finance forecast against the budget envelope and benefits tracked to realisation, side by side — so "can we afford it?" and "is it working?" are answered from the same place.
Board reporting produced from the live programme data. The pack is a print-out of reality, not a fortnight of curation — and the meeting starts from the same numbers the team works from.
WHAT MADE IT DIFFERENT
WHERE IT STANDS
The programme is scoped, baselined and steered from a single live picture. Prioritisation arguments happen once, in the open, and stay settled — because the reasoning is written down where everyone can see it. Scope changes are decisions with justifications, not drift. And when the board asks what excluding a piece of work does to the department's CAF position, the answer is on the screen, not owed as an action.
Most of all: the people who own the risk can see the programme as it is, while there's still time to steer it.