The Houses of Parliament across the Thames at night

SECTOR — CENTRAL GOVERNMENT

For departments that can't outsource the accountability.

Departments, agencies and arm's-length bodies. GovAssure, the CAF and Secure by Design — delivered by people who've worked on the inside.

WHAT'S DIFFERENT IN GOVERNMENT

The risk carries a named owner.

In central government, cyber risk sits with named individuals — a senior responsible owner on each programme, an accounting officer above them. And GovAssure has changed what holding that risk means in practice: departments are now assessed against the NCSC Cyber Assessment Framework, and the review looks for evidence of outcomes where it once accepted a statement of policy.

That evidence has to come from a real estate. Most departments run legacy systems that have carried services for decades and can't simply be replaced, while their programmes are expected to follow the government's Secure by Design approach under sustained pressure to deliver. Add a supplier-heavy model — where much of the build and run sits with third parties — and a department can hold all of the accountability while holding very little of the day-to-day control.

Concrete facade of a brutalist civic building

Under GovAssure, assurance means evidence an assessor can test.

WHERE THE PRESSURE SHOWS

HOW WE HELP

THE RULES THAT APPLY TO YOU

The accountability is yours either way — the evidence can be ready.

Start a conversation
ALSO WORK IN Financial services → Critical infrastructure & OT →