Protect the services citizens cannot get anywhere else.
An outage in a public service reaches citizens directly. We help public bodies meet GovAssure and NIS2 expectations, keep incidents away from citizen-facing services, and introduce AI with the transparency public decisions require. UK buyers can commission us through G-Cloud 15 and Digital Outcomes and Specialists 7.
Situations we help with
Across central government departments; arm's-length bodies and agencies; local government; and EU public administrations.
- Your GovAssure review against the Cyber Assessment Framework has identified gaps that need a funded, prioritised plan.
- Legacy systems and newer cloud services sit side by side, and ownership of the risk between them is unclear.
- Services depend on a small number of suppliers, and contracts do not give clear rights to evidence or incident notification.
- Teams are piloting AI for casework or correspondence, and there is no agreed approach to transparency or human review.
- Your board or audit committee has asked for cyber risk reporting it can challenge and act on.
The challenges
Legacy alongside cloud
Where long-established systems run alongside newer cloud services, risk can sit in the gaps between them, and a change to one can expose the other.
Supplier dependence
Services can depend on a small number of suppliers and platforms, so resilience depends on the contracts and assurance that govern them.
Assurance and accountability
Accounting officers, boards, and audit committees answer for cyber risk to ministers, auditors, and the public, and need assurance they can challenge.
Constrained budgets and skills
Security investment competes with frontline services for funding and specialist staff, so priorities need a clear case based on the services at risk.
ENISA's 2025 threat landscape identified public administration as the most targeted sector in the EU, accounting for 38.2% of recorded incidents, mostly low-impact denial-of-service attacks, with ransomware particularly affecting municipalities.
AI in the public sector
Casework and correspondence
- The value
- Faster responses to citizens and smaller backlogs.
- What needs governing
- Decisions affecting citizens need transparency, fairness, and a route to human review.
Policy and analysis
- The value
- Faster synthesis of evidence and consultation responses.
- What needs governing
- Sensitive information shared with tools the organisation has not approved, and outputs used without checking.
Citizen-facing assistants
- The value
- Help available outside office hours.
- What needs governing
- Incorrect guidance on entitlements or obligations, and unclear accountability when it is wrong.
AI Factory Design sets the rules for approval, transparency, and human review across these uses, so AI can scale across services with the accountability public decisions require. It is part of our AI Governance and Transformation practice.
Regulation that may apply
GovAssure (UK)
- Applies to
- Central government departments and their arm's-length bodies.
- What it asks
- Annual independent assurance reviews of critical systems against the Cyber Assessment Framework.
- Timing
- Introduced in April 2023 in support of the Government Cyber Security Strategy.
Government Cyber Security Strategy (UK)
- Applies to
- Government organisations across the public sector.
- What it asks
- Works towards the goal of all government organisations being resilient to known vulnerabilities and attack methods by 2030.
- Timing
- Covers 2022 to 2030.
NIS2 (EU)
- Applies to
- Public administration entities of central government, and at regional level where a Member State includes them.
- What it asks
- The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
- Timing
- Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.
Epitechnic has been named as a supplier on the Government Commercial Agency's G-Cloud 15 framework (Lot 3, Cloud Support) and Digital Outcomes and Specialists 7 framework (Lot 1, Digital Outcomes).
UK public sector buyers can commission our work through either framework, using the buying route each provides.
Discuss buying through a frameworkRecommended engagements
Zero Trust Transformation
Contains incidents across legacy and cloud estates before they reach citizen-facing services.
View engagementAI Factory Design
Sets the rules for transparency, approval, and human review as AI moves into casework and services.
View engagementNIS2 Readiness Diagnostic
Establishes the NIS2 position of EU public administration entities under each Member State's law.
View engagementCyber Governance Framework Design
Sets decision rights, accountability, and board oversight designed for GovAssure and audit scrutiny.
View engagement