Mission and accountability
- Which public services would cause the greatest harm if unavailable, manipulated or exposed?
- Does each material cyber risk have a named executive or business owner?
- Are security decisions connected to service outcomes, public trust and continuity?
- Which risks exceed approved tolerance, and what decision is required?
Architecture and dependency
- Are legacy platforms, cloud services, identities, networks and external dependencies mapped to essential services?
- Where could one supplier, credential, network path or facility create concentrated risk?
- Are technology modernisation and procurement programmes required to present security evidence before acceptance?
Detection and incident command
- Do priority systems produce usable logs and accountable alerts?
- Who may authorise containment when service availability and investigation needs conflict?
- Have leadership, technical, legal, privacy, communication and continuity roles exercised a realistic scenario?
- Can lessons from incidents be tracked through to completed changes?
Suppliers and programmes
- Are security, incident, access, data and exit requirements proportionate to supplier criticality?
- Does assurance evaluate evidence rather than only collect certificates?
- Can the institution continue or exit if a strategic supplier becomes unavailable?
Reporting and assurance
A useful executive view includes essential-service exposure, material incidents, overdue risk treatment, vulnerability and recovery themes, supplier concerns, exercise outcomes and decisions requiring authority or funding. Avoid dashboards dominated by tool activity with no connection to mission risk.
First 30-day action
- Select one essential service and map its accountable owner, systems, identities and suppliers.
- Test one plausible disruption scenario and record unresolved decisions.
- Review the five highest residual risks and approve owners and treatment dates.
- Define the evidence leadership expects at the next review.