You’ve completed your latest check-in against the National Cyber Security Centre’s (NCSC) Cyber Assessment Framework (CAF). You may also have attended the recent Ministry of Housing, Communities and Local Government (MHCLG) workshops.
For councils working through the CAF for local government, the next challenge is turning the findings of that assessment into practical improvements in cyber resilience.
So, what comes next?
As MHCLG’s supporting partner for the delivery of the CAF check-ins and workshops, UBDS Digital has had a valuable opportunity to see where councils are making progress - and where common challenges remain.
The check-ins highlighted some consistent themes: limited time and resources, competing priorities, the need for executive buy-in, and, critically, the challenge of turning plans and policies into capabilities that have been tested and proven in practice.
This was particularly evident across Objective D: Minimising the impact of cyber security incidents.
The NCSC’s CAF is not new. It has long been regarded as a comprehensive framework for assessing cyber resilience.
What has changed is the direction from MHCLG for local authorities to self-assess against it.
For many councils, this has created an immediate question: where should we focus first?
It is important to remember that the CAF is not simply a checklist or an IT security standard. It is a risk-based framework that considers the governance, leadership and organisational behaviours underpinning cyber resilience alongside technical controls.
That distinction matters.
The purpose of a CAF self-assessment is not simply to demonstrate that a policy or plan exists. It is to understand whether your organisation has the capability to put it into practice when it matters.
Our work supporting the check-ins highlighted four areas in particular where councils should now focus their attention.
One area that stood out consistently was Objective D1, which requires organisations to have plans in place to maintain essential services in the event of system failure or cyber compromise.
Most councils have Business Continuity Plans (BCPs). However, our check-ins showed that some had been written several years ago, reviewed periodically and tested primarily against physical disruption such as a fire, flood or power outage.
Cyber disruption presents a different challenge.
What happens when a council cannot access its digital systems for days or even weeks? Can essential services continue? Are manual fallback processes available? Can teams operate using paper-based workflows? Do staff know what to do when the systems and applications they rely on every day are unavailable?
These scenarios were not always reflected in existing plans and, importantly, had often not been tested in practice.
Recent ransomware incidents affecting local authorities have made this challenge very real. Organisations that are better able to manage disruption tend to be those that have considered a fundamental question in advance:
What would we do if we had no access to our systems for two weeks?
The CAF self-assessment is valuable because it helps expose these gaps.
Councils are better prepared when they have up-to-date plans, have tested those plans against realistic cyber scenarios and have ensured that people across the organisation understand their roles and responsibilities.
However, our check-ins showed that the implementation of these plans, and clear ownership of them, was not always sufficiently developed.
Objective D1: Response and Recovery Planning requires councils to establish an effective response and recovery capability, supported by the security monitoring covered under Objective C1.
That means having defined roles, clear escalation paths, communication protocols and tested playbooks covering the most likely attack scenarios.
One word became particularly important during our check-ins: tested.
Many councils could produce some form of Cyber Incident Response Plan. Far fewer could demonstrate that the plan had been exercised in realistic conditions.
Would staff understand their responsibilities under pressure? Has the escalation route to the Chief Executive and elected members been rehearsed? Does everyone know when the National Cyber Security Centre, Information Commissioner's Office (ICO) or MHCLG should be involved? And is there a clear plan for communicating with residents and the media during an active incident?
We identified several recurring practical issues: roles assigned on paper but not confirmed with the individuals concerned; plans referencing systems or tools that had since changed; and contact lists that were out of date.
Perhaps most importantly, many councils had yet to simulate a significant cyber incident through a tabletop exercise involving both senior leaders and technical teams.
The consequence is that, when an incident occurs, councils may be forced to improvise, not because they lack the knowledge, but because they lack the time, resources and supporting materials needed to put their plans into action effectively.
The CAF does not require perfection. But it does require evidence of a genuine capability that has been tested and exercised.
Objectives D1 and D2 together address the technical and organisational dimensions of recovery: the ability to restore systems and data to a known-good state within timeframes compatible with essential service delivery.
This requires defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), tested Disaster Recovery (DR) procedures and infrastructure capable of supporting them.
Our check-ins indicated that DR remains a significant challenge across local government.
Some councils are operating with ageing on-premises infrastructure, limited offsite backup capability and recovery procedures that have not been tested end-to-end. Budget pressures can defer necessary investment, creating a gap between perceived recovery capability and what can actually be achieved during a major incident.
Cloud migration has added another layer of complexity.
Many councils now operate hybrid environments, with some workloads in the cloud, others on-premises, and additional systems delivered through shared-service arrangements or third-party providers.
These environments have not always been mapped comprehensively from a disaster recovery perspective.
Which systems can be recovered? From where? In what sequence? Within what timeframe? And which third parties or shared-service partners need to be involved?
These questions become particularly important where dependencies cross organisational boundaries and may not be fully visible to any single council.
The CAF requires councils to be realistic about this. Self-assessment against D2 means identifying where recovery capability falls short, not simply confirming that backups exist.
None of these challenges exists in isolation.
Many local authorities are approaching CAF self-assessment while under significant resource pressure. IT teams are balancing day-to-day operational demands with cyber resilience priorities, while specialist expertise in areas such as Governance, Risk and Compliance (GRC) and cyber governance can be difficult to maintain in-house.
Supply-chain risk compounds the challenge.
A significant proportion of local government IT is delivered through third-party suppliers, managed service providers, cloud platforms and specialist application providers.
Yet councils do not always have complete visibility of the security and resilience of the organisations on which they depend.
Objective A4: Managing Supply Chain Risk was therefore another area where self-assessment frequently exposed gaps.
The broader risk is that, under pressure, CAF self-assessment becomes a documentation exercise rather than a genuine assessment of capability.
Policies may exist on paper, but that does not necessarily mean they are understood, implemented or tested in practice.
The CAF is designed to expose that gap. Its Indicators of Good Practice (IGPs) focus on evidence of genuine capability rather than documented intent alone.
The priority now is to turn the findings of your CAF self-assessment into practical action.
That means understanding where your greatest risks sit, prioritising remediation, assigning clear ownership, and critically testing whether your plans and processes actually work in practice.
For councils facing competing priorities, limited resources or specialist skills gaps, knowing where to begin can be difficult.
This is where UBDS Digital can help.
As a supporting partner to MHCLG in the delivery of the CAF check-ins and workshops, we combine our understanding of the framework with practical experience of the challenges councils face in implementing it.
Our focus is not simply on helping councils document compliance. It is on helping them build demonstrable cyber resilience.
Know where your biggest gaps are
Our CAF readiness assessments provide an evidence-based view of where your council stands and where practical improvements are needed.
More importantly, we help translate the findings into a prioritised roadmap, identifying the actions, resources and evidence needed to close the most important gaps.
For Business Continuity, we help councils develop and test plans against realistic cyber scenarios and the applications and services specific to their organisation.
Our Cyber Incident Exercises (CIEs) include facilitated tabletop exercises and scenario walkthroughs with senior leadership and technical teams, helping build organisational capability, knowledge and confidence.
For Incident Response, we help develop plans with clearly defined responsibilities, escalation paths, communications protocols and tested playbooks tailored to the council.
We then use incident response and simulation exercises to test those plans under realistic pressure, identify weaknesses and support remediation, ensuring elected members, senior officers and technical teams understand the roles they will need to play.
For Disaster Recovery, we provide strategic advice on DR architecture across hybrid and cloud environments, help define and document RTOs and RPOs, and support councils in building the evidence of tested recovery capability that the CAF requires.
Where shared services and third-party providers are involved, we can also assess dependencies and DR implications across organisational boundaries, supporting stronger supply-chain assurance.
For councils requiring ongoing expertise rather than point-in-time support, our fractional Chief Information Security Officer (CISO) and GRC services provide experienced practitioners on a flexible basis.
Our wider cybersecurity services give council teams access to specialist knowledge and additional capacity without the cost and commitment of a permanent hire.
The MHCLG requirement presents an opportunity to move beyond documented plans and towards cyber resilience that can be demonstrated, tested and continually improved.
Your CAF check-in provides the starting point. The next step is turning those findings into a practical, prioritised plan, and building the evidence that your council can respond, maintain essential services and recover when it matters.
Completed your CAF check-in and wondering what comes next?
Talk to the UBDS Digital team about your findings, your priority gaps and the practical steps you can take to strengthen your council's cyber resilience.