Preparing fpr disruption: Cyber risk as a service delivery issue Back
Print

In the public sector, expectations for digital services keep rising, even as budgets, resourcing and legacy environments can limit the pace of uplift. When disruption occurs - whether cyber-related or technology-driven- it often plays out publicly, putting immiediate pressure on operations, governance and communications.

Cyber risk is changing in two important ways. First, members are increasingly dependant on technology to deliver essential services, maintain stakeholder trust and meet governance expectations. Second, that technology is increasingly delivered through (or closely connected to) external providers - cloud platforms, managed service providers, software vendors and specialist partners. As a result, disruption can start from outside the organisation's control, even when internal teams are doing the right things.

In practice, cyber and tecnology disruption is not limited to malicious attacks. Members may also need to account for supplier outages, configuration errors, compromised credentials, delayed patching, weak access controls, or slow incident notifications. Any of these can rapidly flow into council operations- interrupting customer-facing services, creating compliance and reporting pressure, and triggering real-time communications decisions. The practical question is no longer only 'can we prevent incidents' but also 'can we respond and recover in a way that protects service continuity'

This is where the LGIS Cyber Uplift Program can help by providing a structured way for members to assess and strengthen cyber resilience. It is intended to support councils - particularly where internal capacity is limited and reliance on external providers is increasing. The focus is on whether arrangements will hold up in practice, including under time pressurem, with incomplete information, and where vendors need to be involved.

Through the Cyber Uplift Program, members can strengthen cyber resilience by focusing on three outcomes.

1. Understanding control maturity by checking whether key controls are operating effectively in practice, not just documented on paper. This helps identify control gaps, confirm where the current control environment is strong or weak, and establish a practical roadmap for uplifting controls over time.

2. Testing how an incident would be managed in practice. This helps clarify who is notified, who makes decisions, how communications are handled, and how quickly external providers can be brought in before a real event occurs.

3. Strengthening third-party and supply chain cyber risk management, alongside broader resilience practices. This helps members understand where external dependancies may create exposure, improve visibility of vendor risks, and ensure recovery and continuity arrangements remain realistic and ready to use when external parties are involved.

In the 8th JLT Risk Report (released in 2025), 64% of respondents ranked Technology & Data/providers' ability to proactively manage cyber security as their top concern., with cyber security failure (62%) and response capability (60%) close behind. As you prepare to complete the JLT Public Sector member survey (coming shortly), consider what has changed in your operating environment and whether your organisation's cyber resilience has improved.

To learn more about our Cyber Uplift Program, click HERE

For more information, or to arrange a scoping meeting please contact Liberty.Mudzamba@marsh.com or your account manager.

Back