Photo: Katie Moum / Unsplash

Case Study · Public Sector

Public Body Operating an Essential Service

  • NIS2
  • Zero Trust
  • Operational Continuity
  • 6 monthsFrom gap assessment to demonstrable compliance
  • 4Critical services under continuous monitoring
  • < 24hIncident notification aligned to obligations

The challenge

A public body operating an essential service fell within the scope of the NIS2 directive and had to demonstrate to the competent authority not merely that security measures existed, but that they were proportionate to the risk and verifiable. A service outage would have had a direct impact on citizens.

The threat picture was elevated: attempts attributable to state actors and risks along the technology supply chain. Legacy architectures, with flat networks and broad access, offered little assurance of containment in the event of compromise.

My approach

I began with a gap assessment against NIS2 obligations and real risk, translating the requirements into a prioritised plan that the body’s leadership could approve and fund, with accountability assigned at management level as the directive requires.

Technically I introduced Zero Trust principles: segmentation of critical services, explicit verification of every access, least privilege and continuous monitoring. Supply-chain security was addressed through contractual requirements and assessments of the most critical technology suppliers.

On continuity I defined and tested response and recovery plans, with notification duties aligned to the regulatory deadlines. The result is a body of evidence — policies, logs, test outcomes — that makes the assurance given to the authority demonstrable rather than declared.

A similar situation?

Start with a confidential briefing.

Book a consultation