Duolingo's owl scares me: An introduction to trauma-centred design

10 key cyber security questions for public sector leaders – Infographic

Part of the Public Sector Digital Trends collection

Authors and contributors: Socitm, Mark Brett

To assist in carrying out cyber resilience assessments, identifying improvement activities and ensuring an outcome-focused approach, here are key questions and action points that can help public sector leaders strengthen their cyber security posture.

View the Public Sector Digital Trends collection

Socitm infographic: 10 key cyber security questions for public sector leaders

To support public sector organisations in addressing cyber security challenges, the UK Government and National Cyber Security Centre (NCSC), along with local government organisations, have adapted the Cyber Assessment Framework (CAF) for use by councils.

The CAF offers a systematic approach to assessing how well an organisation manages cyber risks to its essential functions. It provides requirements, principles and outcomes to evaluate and improve cyber security.

Leaders should use the following questions to guide their evaluation and enhance their cyber resilience.

  1. Are you using the CAF to assist in cyber resilience assessments?
  2. Are you combining the CAF with existing cyber security standards?
  3. How are you using the CAF to identify effective activities for improving cyber security and resilience?
  4. How do you ensure your CAF approach is outcome-focused rather than a box-ticking exercise?
  5. Are your senior leaders and managers using the CAF to set meaningful security targets for the organisation to achieve?
  6. Is the CAF strengthening management policies, processes and procedures governing the security of your networks and information systems?
  7. Is your organisation using the CAF to identify, assess and understand security risks to essential functions?
  8. Is the CAF helping your organisation to understand and manage security risks arising from dependencies on partners and suppliers?
  9. How does the CAF help your organisation and its partners build system-wide resilience against cyber attacks and failures?
  10. Are you using the CAF to enhance the effectiveness of your organisation and partners’ capabilities to minimise the impact of cyber incidents and restore functions?