Skip to content

Cyber insights

Practical cybersecurity perspectives for public-sector teams.

Short notes on the security decisions we see teams wrestle with most. These are our own views, grounded in public guidance and general practice, with no client or project detail.

  • Zero Trust
  • Identity
  • Architecture

Zero Trust in a mixed public-sector estate

Most public-sector environments are not greenfield. A workable Zero Trust program starts with identity and device signals on the systems that already exist, then narrows access as visibility improves, rather than waiting for a full re-architecture.

Informed by NIST SP 800-207

  • ITSG-33
  • Assessment
  • Governance

Making ITSG-33 tailoring useful rather than mechanical

Control profiles lose their value when they are copied without tailoring. Deciding early which controls are inherited, which are shared and which the system genuinely owns is what makes an assessment package readable and defensible.

Informed by CCCS ITSG-33 guidance

  • Security operations
  • SIEM
  • Detection

Detection engineering usually beats more tooling

When alerts are noisy, the constraint is rarely the platform. Reviewing log source coverage, mapping detections to relevant ATT&CK techniques and retiring rules that never produce action delivers more than another product.

Informed by MITRE ATT&CK

  • Cloud security
  • Azure
  • Microsoft 365

The cloud security decisions that are hard to reverse

Tenant boundaries, identity models, logging retention and privileged role design set the ceiling on what can be secured later. These are worth deliberate design time before workloads start moving.

General practice

  • Identity
  • Privileged access
  • Compliance

Privileged access is the first question an audit asks

Standing administrative access is the most common finding we expect to see and the most tractable to fix. Time-bound elevation, an approval trail and a review cycle address it without disrupting operations.

General practice

  • AI security
  • Governance
  • Risk

Governing AI adoption before it outpaces oversight

AI tools tend to arrive faster than the data handling and oversight practices around them. Use-case triage, a documented data boundary and mapping to an accepted risk framework keep adoption inside an approved perimeter.

Informed by the NIST AI Risk Management Framework

Want to talk one of these through?

If one of these matches a decision you are working through, we are happy to discuss it against your own environment.

Engage

Strengthen your next cybersecurity initiative.

Connect with Frank Dolphins regarding cybersecurity requirements, subcontracting, teaming arrangements and professional-services opportunities.