Latest insights and news relating to Public Sector Technology.

Trust but Verify: Why Transparency Matters in Public Sector Cyber Resilience

Written by Object First | Sep 9, 2026, 4:15:01 AM

Cybersecurity has always involved difficult decisions. Local authorities are expected to protect sensitive citizen data, maintain essential services and cost-effectively deliver new citizen self-service options, all while operating in an increasingly hostile threat landscape.

Yet one of the biggest challenges facing public sector technology leaders today isn't simply choosing the right cyber solutions. It's knowing which solutions to trust.

The volume and sophistication of cyberattacks targeting local government continue to rise. Ransomware incidents have disrupted planning systems, benefits services and social care operations, while government policy increasingly emphasises the importance of resilience, recovery and continuity of service.

In this environment, cyber resilience cannot be based on assumptions. It must be based on evidence.

The challenge with cybersecurity claims

Security technologies are often marketed using terms such as "secure", "immutable", "air-gapped", "Zero Trust" or "ransomware-proof".

The problem is that these terms are not always used consistently.

Two vendors may make very similar claims while implementing very different approaches behind the scenes. For an organisation evaluating technology, particularly in the public sector, this creates a challenge: how do you determine whether a product will perform as expected during a real cyber incident?

A solution that appears robust during a sales presentation may perform very differently when facing a threat actor armed with the highest-level administrative credentials and deep access into your IT environment.

That is why cyber resilience needs to be evaluated with a sceptical mindset: “show me the proof!”

The shift from prevention to recovery

For many years, cybersecurity strategies focused primarily on prevention.

That remains important, but recent events have demonstrated that even well-defended organisations can experience successful attacks. The question has evolved from "How do we prevent every breach?" to "What happens when one succeeds?"

This shift is reflected in government thinking and actions.

The UK Government's Cyber Action Plan places significant emphasis on response and recovery, recognising that public services must be demonstrably resilient even when preventative controls fail. At the same time, proposals to restrict ransomware payments by public sector organisations reinforce a broader message: recovery plans cannot assume that paying a ransom will be an option.

For local authorities, this has important implications.

The ability to restore critical services may ultimately depend on whether backup data remains available, accessible and trustworthy after an attack.

Transparency is critical

When evaluating cyber resilience technologies, organisations should seek clear answers to these fundamental questions:

  • How does the product enforce security controls?
  • What happens if administrative credentials are compromised?
  • Can security settings be modified or bypassed?
  • Has the product undergone independent testing?
  • Are security architectures publicly available for review?
  • If an attacker had access to all administrator credentials and other privileged information, could they perform destructive actions on our backups?
  • How can you prove it?

These questions are particularly relevant when considering technologies that support backup and recovery. After all, the purpose of a backup platform is to provide a trusted copy of data when everything else has gone wrong.

If the backups or the backup infrastructure itself can be altered, encrypted or deleted by an attacker, then recovery becomes significantly more complicated – if it is possible at all. Transparency from a backup infrastructure vendor allows organisations to understand exactly how products behave under adverse conditions, rather than relying on marketing language alone.

It all boils down to two questions that should be asked of backup infrastructure vendors:

Any organisation evaluating cyber resilience solutions should be able to obtain clear, evidence-based answers to both.

Independent validation builds confidence

One of the most effective ways to establish trust is through independent assessment.

Across the public sector, leaders are accustomed to external audit, assurance processes and standards-based validation. Cyber resilience should be no different.

Independent security testing, penetration assessments and architectural reviews can help organisations separate proven capabilities from unverified claims.

This becomes increasingly important as vendors introduce new capabilities and as cyber threats continue to evolve. With the evolving legislative focus on auditable resilience, and the changing threat environment, vendors should be expected to offer independent audit confirmation of their security claims.

A resilient organisation is not necessarily the one that buys the most security tools. It is the one that understands how those tools perform under pressure and has confidence in their ability to support recovery when it matters most.

Resilience requires evidence

For local authorities, cyber resilience ultimately comes down to maintaining services that communities rely upon every day. Technology decisions should therefore be grounded in transparency, verification and evidence.

As the industry continues to adopt approaches such as Zero Trust and cyber recovery planning, organisations must ask their vendors those tough questions, and demand evidence that supports a simple conclusion: We know this will work when we need it most.

To discuss the future of cyber resilience, recovery and secure backup infrastructure for local government, visit Object First at DigiGov Expo 2026.