Those working in the UK public sector have seen significant upheaval over the last decade thanks to a combination of the long-term efforts to relocate civil servants outside London and, in recent years, the swift adoption of hybrid work practices necessitated during the pandemic.
As a result, networks have expanded, the number of devices and endpoints to protect has grown considerably and potential vulnerabilities for attackers to target have increased. This has occurred against a backdrop of increasing global cybersecurity threats driven by geopolitical conflict heightening tensions between nations. As a result, there is a need, and expectation, for departments to take every step to build their cyber resilience against future threats.
Ignoring the debate
As they have in many sectors, remote and hybrid working models have become a contentious issue in the public sector, with conflicting opinions often shared between Government Ministers and civil servants about whether an increase in flexibility negatively impacts productivity. In the Paymaster General’s Civil Service People Plan at the start of this year, he committed the civil service to a minimum balance of 60% in-office working. Among local governments, hybrid working policies vary more widely to manage tight budgets and intense workloads. The use of private contractors has also become a significant component for many departments in need of that external expertise, but this also comes with a risk to data security.
For security leaders in these departments, the working practices debate is irrelevant; the data and infrastructure need to be protected wherever they are.
Secure flexibility
To protect data wherever it moves, you need to have the visibility and flexibility to adapt to the dynamic work environment. There are already frameworks in place to help administrators classify data into Official, Secret, and Top Secret categories, and provide guidelines as to what needs to be restricted to an on-premises instance and what can be more openly shared.
Let’s focus on the Official classification because it comprises the majority of information that is created, processed, sent or received in the public sector and by partner organisations. This category of data will be the target of a broad range of threat actors and needs to have adequate protections to ensure only appropriate people can access and use it. This is where specific policies based on zero trust