- Zero Trust
- Identity
- Architecture
Zero Trust in a mixed public-sector estate
Most public-sector environments are not greenfield. A workable Zero Trust program starts with identity and device signals on the systems that already exist, then narrows access as visibility improves, rather than waiting for a full re-architecture.
Informed by NIST SP 800-207
- ITSG-33
- Assessment
- Governance
Making ITSG-33 tailoring useful rather than mechanical
Control profiles lose their value when they are copied without tailoring. Deciding early which controls are inherited, which are shared and which the system genuinely owns is what makes an assessment package readable and defensible.
Informed by CCCS ITSG-33 guidance
- Security operations
- SIEM
- Detection
Detection engineering usually beats more tooling
When alerts are noisy, the constraint is rarely the platform. Reviewing log source coverage, mapping detections to relevant ATT&CK techniques and retiring rules that never produce action delivers more than another product.
Informed by MITRE ATT&CK
- Cloud security
- Azure
- Microsoft 365
The cloud security decisions that are hard to reverse
Tenant boundaries, identity models, logging retention and privileged role design set the ceiling on what can be secured later. These are worth deliberate design time before workloads start moving.
General practice
- Identity
- Privileged access
- Compliance
Privileged access is the first question an audit asks
Standing administrative access is the most common finding we expect to see and the most tractable to fix. Time-bound elevation, an approval trail and a review cycle address it without disrupting operations.
General practice
- AI security
- Governance
- Risk
Governing AI adoption before it outpaces oversight
AI tools tend to arrive faster than the data handling and oversight practices around them. Use-case triage, a documented data boundary and mapping to an accepted risk framework keep adoption inside an approved perimeter.
Informed by the NIST AI Risk Management Framework