Intelligent CISO Issue 101 | Page 19

talking

POINT

THE UK PUBLIC SECTOR MUST PRIORITISE DIGITAL SOVEREIGNTY BEFORE THE NEXT CRISIS

Richard Cassidy, CISO, Rubrik
Richard Cassidy, CISO, Rubrik, tells us why UK public sector leaders must move beyond traditional cyber-resilience strategies by embracing digital sovereignty, strengthening recovery capabilities and ensuring critical services remain under their control, even during the most challenging crises.

T he biggest cybersecurity risk facing the UK public sector is no longer just an attack, it is loss of control.

For years, security strategies have been shaped by criminal opportunism, ransomware, data theft and service disruption. However, that model is no longer sufficient. Today, the cyberthreat landscape is increasingly defined by geopolitics, where access to systems, data and infrastructure can be constrained or removed entirely by forces outside an organisation’ s control.
That distinction matters because most recovery strategies have not been built for it.
Cyberattacks on UK public sector organisations have risen 91 % yearon-year, but the nature of those attacks is also changing. Artificial Intelligence is accelerating intrusion cycles, lowering the barrier to entry and enabling threat actors to operate at a scale and speed that traditional defences were never designed to handle.
At the same time, the organisations being targeted hold some of the most sensitive data in the country, and the impact extends far beyond financial loss, but also affects public trust, national security and the continuity of essential services.
When recovery depends on someone else
This is when digital sovereignty becomes critical. In simple terms, sovereignty is about control: knowing where your data resides, which jurisdiction governs it and whether you can access and recover it under all conditions, not as a compliance tick-box, but as an operational reality.
Political decisions have begun to shape the availability of digital services and cross-border co-operation. The next major disruption affecting a UK public sector organisation may not be caused by malware, but by the sudden loss of access to a critical dependency – a cloud region, a vendor, a support function that is no longer available when needed most.
Most recovery strategies are built on assumptions that are becoming increasingly fragile: that cloud access will remain stable, vendor relationships will hold and geopolitical tensions will not interfere during a crisis. Leaders should ask whether their organisation could still recover if a key vendor or jurisdiction suddenly became unavailable. For many, there is no clear answer.
From resilience to sovereignty
Not every system needs to be completely independent or locally contained. It is not realistic. However, organisations must be aware of which systems and data are critical enough to remain recoverable, even if external support or access becomes constrained.
That’ s where the idea of Minimum Viable Sovereignty becomes helpful. It’ s about identifying what absolutely has to work and ensuring it can be restored within UK jurisdiction, without relying on conditions that may not hold in a crisis.
In practice, this shifts focus to actual execution and whether environments can be isolated, whether data is accessible and if recovery processes are sufficiently automated. Consequently, it demands rigorous testing through worst-case scenarios with limited access and broken dependencies, rather than controlled, ideal exercises.
Digital resilience must move up the agenda
We have to consider the scale of what is at stake. HMRC, the CPS and Companies House are all part of the operational infrastructure of the UK. If any of them were forced into a recovery scenario that exposed an unseen dependency on unavailable external support, the impact would be immediate and widely felt.
Supported by the Cyber Security and Resilience Bill, the UK has the capability to close this gap, but is held back by the assumption that the environment will remain stable when a crisis hits. Leaders can no longer plan for a stable world; they must build the capability to survive under constraint long before the disruption arrives.
WWW. INTELLIGENTCISO. COM 19