Strategic framework for cyber intelligence requirement identification and performance quantification in local government
Abstract
The digital infrastructure of UK local government has undergone a seismic shift, evolving from a back-office administrative support function into the primary engine for essential public service delivery. This GovTech transformation, characterised by the ‘digital by default’1 philosophy, has significantly expanded the attack surface of local authorities, rendering them susceptible to a spectrum of sophisticated cyber threats that range from opportunistic ransomware campaigns to targeted state-sponsored espionage.2,3 This paper proposes a holistic approach to understand, define, and specify the cyber intelligence requirements (CIRs) for UK local authorities, which will help to support those councils engaged in the Local Government Reorganisation4 work. This approach tackles identified threats in 20265 by integrating the National Cyber Security Centre Cyber Assessment Framework6 and the Local Authority Cyber Eco-System framework.7 As local authorities increasingly adopt emerging GovTech technologies, such as artificial intelligence and cloud-based services, the requirement for a robust, intelligence-led approach to security becomes paramount.8,9 The fundamental challenge lies not merely in the procurement of defensive technologies but in the precise identification of CIRs and the subsequent development of meaningful, outcome-orientated metrics that align technical performance with organisational mission and public value.10,11 This view has been formed from the author’s observations over the past seven years, working closely with the UK local government community. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Mark Brett, PhD, MRes, ChCSP, CMngr, CITP, FBCS, FCMI, FCIISec, holds a portfolio of part-time and pro-bono roles, which includes Director of Policy, Programme and Research for CTAG, the UK Cyber Technical Advisory Group for Local Public Services and Socitm. He also runs several cyber security community of practice Warning, Advice and Reporting Points (WARP) groups. Previously Mark worked part-time in the Cabinet Office, Ministry of Justice, Ministry of Housing, Communities and Local Government (MHCLG), and as Cyber Adviser to the Welsh Government Local Authority Cyber Programme. He has a number of published papers covering open-source intelligence, information governance, resilience, and artificial intelligence. Mark is a Fellow and honorary Life Member of and Associate Director of Socitm, and a visiting Fellow in Cyber Security at London Metropolitan University, where he recently completed his PhD in cyber security policy and governance. He has also been appointed by De Montfort University as a visiting Associate Professor of practice in cyber security and resilience.