Public sector

Protect the services citizens cannot get anywhere else.

An outage in a public service reaches citizens directly. We help public bodies meet GovAssure and NIS2 expectations, keep incidents away from citizen-facing services, and introduce AI with the transparency public decisions require. UK buyers can commission us through G-Cloud 15 and Digital Outcomes and Specialists 7.

Situations we help with

Across central government departments; arm's-length bodies and agencies; local government; and EU public administrations.

  • Your GovAssure review against the Cyber Assessment Framework has identified gaps that need a funded, prioritised plan.
  • Legacy systems and newer cloud services sit side by side, and ownership of the risk between them is unclear.
  • Services depend on a small number of suppliers, and contracts do not give clear rights to evidence or incident notification.
  • Teams are piloting AI for casework or correspondence, and there is no agreed approach to transparency or human review.
  • Your board or audit committee has asked for cyber risk reporting it can challenge and act on.

The challenges

Legacy alongside cloud

Where long-established systems run alongside newer cloud services, risk can sit in the gaps between them, and a change to one can expose the other.

Supplier dependence

Services can depend on a small number of suppliers and platforms, so resilience depends on the contracts and assurance that govern them.

Assurance and accountability

Accounting officers, boards, and audit committees answer for cyber risk to ministers, auditors, and the public, and need assurance they can challenge.

Constrained budgets and skills

Security investment competes with frontline services for funding and specialist staff, so priorities need a clear case based on the services at risk.

ENISA's 2025 threat landscape identified public administration as the most targeted sector in the EU, accounting for 38.2% of recorded incidents, mostly low-impact denial-of-service attacks, with ransomware particularly affecting municipalities.

Source: ENISA Threat Landscape 2025, October 2025

AI in the public sector

Casework and correspondence

The value
Faster responses to citizens and smaller backlogs.
What needs governing
Decisions affecting citizens need transparency, fairness, and a route to human review.

Policy and analysis

The value
Faster synthesis of evidence and consultation responses.
What needs governing
Sensitive information shared with tools the organisation has not approved, and outputs used without checking.

Citizen-facing assistants

The value
Help available outside office hours.
What needs governing
Incorrect guidance on entitlements or obligations, and unclear accountability when it is wrong.

AI Factory Design sets the rules for approval, transparency, and human review across these uses, so AI can scale across services with the accountability public decisions require. It is part of our AI Governance and Transformation practice.

Regulation that may apply

GovAssure (UK)

Applies to
Central government departments and their arm's-length bodies.
What it asks
Annual independent assurance reviews of critical systems against the Cyber Assessment Framework.
Timing
Introduced in April 2023 in support of the Government Cyber Security Strategy.

Government Cyber Security Strategy (UK)

Applies to
Government organisations across the public sector.
What it asks
Works towards the goal of all government organisations being resilient to known vulnerabilities and attack methods by 2030.
Timing
Covers 2022 to 2030.

NIS2 (EU)

Applies to
Public administration entities of central government, and at regional level where a Member State includes them.
What it asks
The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
Timing
Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.
How to buy

Epitechnic has been named as a supplier on the Government Commercial Agency's G-Cloud 15 framework (Lot 3, Cloud Support) and Digital Outcomes and Specialists 7 framework (Lot 1, Digital Outcomes).

Framework
G-Cloud 15
Lot 3, Cloud Support
Framework
Digital Outcomes and Specialists 7
Lot 1, Digital Outcomes
Certification
Cyber Essentials Plus
Required by some UK government contracts

UK public sector buyers can commission our work through either framework, using the buying route each provides.

Discuss buying through a framework

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.