As public sector technology professionals, we’re operating on the front lines of what is now definitively the fifth battle domain: cyber.
Alongside land, sea, air, and space, the cyber domain is experiencing constant, low-level activity punctuated by major, headline-grabbing attacks.
Navigating this fifth battle domain
I was recently reminded of this reality at the CityForum Cyber Security Summit in London.

Discussions centred heavily on resilience and the absolute necessity of trust. Trust has underpinned the WARP (Warning, Advice, and Reporting Points) initiative for the past 20 years.
The threat landscape has shifted dramatically.
Recently, 2 teenagers were imprisoned for attacking Transport for London (TfL) and Oyster Card systems. They caused massive disruption, not for financial gain, but simply for “online notoriety”.
From BBC News: Teen hackers who live streamed cyber-attack on TfL jailed
When young people, with minimal technology, can cause millions of pounds’ worth of damage, and honeypot servers are bombarded with thousands of login attempts mere seconds after going live, the threat to local authorities and public organisations is undeniable.
To effectively fortify local government we must rethink our strategies
Building upon recent guidance and real-world incidents here are:
5 key cyber resilience actions every local public sector Socitm member should prioritise
1. Secure the edge and demand supply chain assurance
The National Cyber Security Centre (NCSC), in conjunction with major NATO and Five Eyes intelligence organisations, recently issued critical guidance on securing edge devices, such as firewalls and routers.
However, securing your own perimeter is not enough.
You must mandate that your supply chain has, at a bare minimum, Cyber Essentials.
- Small suppliers without protection are prime targets for attackers looking for a backdoor into larger networks.
- Do not treat this as a one-off tick-box exercise. You should trigger an automated annual request for suppliers to reconfirm their compliance and patching policies.
- When orchestrating multiple cloud-based services, you must fully understand your liability protection and ensure you have compensating controls if a supplier’s service fails.
2. Shift from an IT problem to a business continuity issue
Cyber security is absolutely a business issue.
If a major multi-vector attack takes out key data providers or mobile networks, outside help likely isn’t coming. You must be prepared to act on your own to make systems safe and recover services.
- Make sure you have robust business continuity plans, featuring manual fallback processes that are tested through exercises at least annually.
- Implement pre-authorised “break-glass” policies as part of a “golden hour” guide, empowering staff to incur costs and take immediate action to protect information while keeping services running.
If you’re attacked, your organisation is a victim of crime. Itโs not an ICT failure.
3. Adopt least privilege and dual control
The recent TfL attack succeeded because attackers compromised the help desk into changing the Chief Information Security Officer (CISO)’s password.
This begs a critical question: Does your strategic CISO actually need operational access and passwords?
- Strategic managers should have their administrative access restricted to an absolute bare minimum.
- For major network changes or high-threat tasks, redesign your processes to require dual-control.
- Create and maintain clear network diagrams so you can quickly identify and use physical isolation points to contain breaches.
Take advantage of the NCSC High Risk Individual protection service.
4. Maximise automated threat sharing for local government
You do not have to fight these battles in isolation. There’s a wealth of free threat intelligence available to the public sector.
- Ensure your organisation is utilising automated threat sharing systems such as OTX and the Project Tarragon security feeds.
- Wherever you are in the UK, find and use everything you can from free-to-consume NCSC active cyber defence services to:
- England: use all of the MHCLG Defend as One service
- Northern Ireland: use the NI Cyber Security Centre
- Scotland: use CyberScotland and guidance and resources from the Scottish Cyber Coordination Centre (SC3)
- Wales: all CymruSOC member bodies also benefit from a Cyber Incident Response Service.
5. Cultivate leadership support and a blame-free culture
Recent Cyber Assessment Framework (CAF) pilots conducted by the MHCLG found that the best-performing councils are those with strong, top-down support from senior leadership.
- Brief your senior executives on current cyber threats so they can properly support mitigation efforts. This is a whole organisation business issue.
- Alongside this leadership buy-in, we must foster a blame-free culture. Organisations subject to cyber attacks are victims of crime.
- The focus must remain on sharing information, mitigating harm, and keeping essential public services running rather than pointing fingers.
Cyber attacks aren't going to stop, but we can make them significantly more difficult to execute.
Take action now
- Review your manual fallback processes and ask yourself: when did you or someone in your team last practically test them?
- Brief your senior leadership team on these 5 priorities.
- Involve your Emergency Planning Officer, most believe itโs not an issue for them!
- How resilient is your supply chain, and when did you last verify their Cyber Essentials status?
You might also like to read and/or use:
- Cyber@Socitm
- Case studies about cyber security
- Infographic: 10 key cyber security questions for public sector leaders
- Public Sector Digital Trends 2026: Cyber Security
- Watch: cyber security-themed webinars [members-only]
