Skip to content

Public sector

Meet the mandate with the team you actually have.

The framework is not optional and the headcount is not growing. Automation has to close that gap without creating a system nobody can audit.

The pressure

Pressures specific to this sector

Every sector has pressures. These are the ones that change what a security programme is allowed to do here.

  1. Frameworks that are mandated rather than chosen.

    You do not get to descope the expensive part, and the deadline is somebody else's.

  2. Headcount that cannot scale with the threat or the estate.

    Automation is the only lever left, which means it has to be one you can defend in public.

  3. Procurement and transparency requirements on every tool you adopt.

    A tool that cannot explain its own decisions is a tool that will not clear procurement.

  4. Public accountability when something goes wrong.

    Every automated action eventually becomes a question somebody has to answer on the record.

The constraint

The constraint

Any automation you adopt has to be explainable to somebody who does not work in security.

Frameworks

What you are measured against, and what we actually do about it.

Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.

  • NIST CSF 2.0

    Scored

    All 106 controls across six functions, with a maturity score, a gap register and an export built the way an assessor asks for it.

  • CIS Controls v8

    Scored

    153 safeguards, scoped by implementation group, with the scoping decisions recorded in the export so a reader can see what was excluded and why.

  • ISO 27001

    Evidenced

    No agent assesses it. The control evidence the two assessments collect overlaps heavily with what an ISO audit asks to see.

  • NIS2

    Evidenced

    No agent assesses it. Incident records, response times and the approvals behind each action come out of the audit trail as a by-product.

Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.

The answer

How the platform works around it.

Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.

  1. See

    Mandated controls, measured

    Assessment against the frameworks you are held to, scored control by control, with the method that answered each one recorded rather than assumed.

  2. Decide

    Automation you can explain

    Every automated decision carries its reasoning, its confidence and the features behind it, so the automation itself is auditable rather than a box you have to defend.

  3. Act

    Gated where it matters

    Anything destructive waits for a person, the approval is part of the record, and the rollback was written down before the action ran.

Questions

The things this sector asks first.

  • Can we explain an automated decision to a non-technical reviewer?

    Every classification exposes the features that drove it, its confidence, and the technique it mapped to. Phishing and identity incidents additionally carry a plain-language rationale. The point of the design is that the reasoning is checkable rather than asserted.

  • What does the platform do without extra headcount?

    It removes volume before a person reads anything, and it answers the controls that map to telemetry without asking a colleague for a screenshot. What it does not do is decide anything destructive on its own: that still needs a person, by design.

  • How is data handled, for a procurement questionnaire?

    Encrypted in transit with TLS 1.3 and at rest with AES-256, access controlled by role and enforced at the route on both client and server, with every sensitive action written to an audit log. Connector credentials stay in your own key vault rather than in our database.

  • Does it work if we only turn on part of it?

    Yes. Each agent owns its job end to end with its own pipeline and its own integrations. A connector configured for one is available to the others, so adding a second agent later is configuration rather than a second project.