Skip to main content
Anthrasec

Public services can't close for maintenance. We help government, councils, education providers and arm's-length bodies modernise legacy systems, strengthen cyber resilience and build accessible services, in stages that fit your budget.

  • Aligned to the Cyber Assessment Framework
  • Accessible by design
  • Staged, low-risk modernisation
A Victorian town hall with a domed clock tower against a clear blue sky

28%

of central government systems were legacy technology in 2024, up from 26% a year earlier (State of digital government review)

The sector today

Doing more with systems built for another era

Public bodies are asked to deliver better digital services, defend against a severe cyber threat and adopt AI, often on technology that is decades old.

Two Union flags flying from a classical stone government building

The UK public sector spends over £26 billion a year on digital technology, yet the government's own review found that almost half of central government services still have no digital route, and that legacy technology is growing as a share of the estate. Ageing systems are expensive to run, hard to secure and difficult to connect to anything new. They also hold some of the most important data in the country. The National Audit Office has described the cyber threat to government as severe and advancing quickly, and attacks on councils, libraries and health suppliers have shown how long recovery can take when the basics are missing.

Fixing this is rarely about one big replacement programme. The organisations making progress modernise in stages: stabilising and securing what they have, moving the right workloads to the cloud, building new services around user needs, and retiring old systems once the new ones have proved themselves. Skills are the other constraint, with digital and cyber roles hard to fill across central and local government. Anthrasec works alongside in-house teams to add that capacity, following the standards the public sector sets for itself: the Cyber Assessment Framework, the GOV.UK Service Standard, the Technology Code of Practice and the accessibility regulations.

Nearly half of services still have no digital route

Where there is no digital pathway, people fall back on phone, post and paper, which is slower for citizens and more expensive to run. Most of the savings the review identified come from reducing that manual processing.

Share of services that still lack a digital pathway

Source: DSIT, State of digital government review, January 2025

Part of the public sectorShare
Central government47%
NHS45%

Who we help

Support across the public sector

Every public body has its own duties, budgets and governance. We shape our services to fit.

  • Central government departments

    Extra engineering capacity for modernisation, cyber resilience and service delivery, working to government standards.

  • Local authorities

    Secure, joined-up systems for revenues, housing, social care and customer contact, sized for council budgets.

  • Arm's-length bodies and regulators

    Modern platforms and proportionate security for smaller specialist teams.

  • Schools, colleges and universities

    Protection for student data and research, and networks that cope with thousands of devices.

  • Emergency services and justice

    Resilient, secure infrastructure for services where minutes matter.

  • Housing associations and charities

    Dependable systems and good security for organisations serving residents and communities.

The pressures

Six risks public sector leaders ask us about

Each one is manageable with the right controls. Here is what's at stake, and how we respond.

  • Legacy technology

    The risk
    Unsupported systems are costly, fragile and hard to secure, yet critical services depend on them.
    Our response
    Staged modernisation: stabilise, secure, migrate and retire, with no big-bang cutover.
  • A severe cyber threat

    The risk
    Ransomware groups and state-linked attackers target public bodies, and recovery can take months.
    Our response
    Controls aligned to the Cyber Assessment Framework, 24/7 monitoring and rehearsed recovery.
  • Skills shortages

    The risk
    Digital and cyber roles are hard to fill, leaving teams stretched and reliant on contractors.
    Our response
    Specialists who work alongside your team and pass on knowledge as they go.
  • Accessibility duties

    The risk
    Public sector websites and apps must meet accessibility regulations, and many still fall short.
    Our response
    Design and testing to WCAG 2.2 AA, with accessibility statements kept accurate.
  • Budget pressure

    The risk
    Capital is scarce, and the running costs of old systems crowd out improvement.
    Our response
    Clear business cases, phased delivery and cloud costs that are measured and controlled.
  • Trust in AI and data

    The risk
    Citizens expect transparency about how automated tools and their data are used.
    Our response
    Human oversight, impact assessments and records that follow the Algorithmic Transparency Recording Standard.

What we deliver

Our services, applied to the public sector

One team covers security, software, infrastructure, cloud and AI, working alongside your own people.

Two colleagues discussing plans at a whiteboard

AI in public services

AI in public services, done transparently

Government trials show that AI can return real time to public servants. Public trust depends on being open about where it is used and keeping people accountable for decisions.

26 min

saved per person per day in a three-month government trial of an AI assistant, involving more than 20,000 civil servants

Source: GOV.UK, Government trial of an AI assistant for civil servants, June 2025

  • Enquiry triage

    Sorting and routing emails, forms and calls to the right team, with urgent cases flagged.

    Safeguard: Staff can see how each item was classified, and correct it.

  • Casework support

    Summarising long case files and correspondence, so officers can reach decisions faster.

    Safeguard: Officers make every decision. AI output is advisory, and recorded as such.

  • Document search and extraction

    Finding information across policies, records and scanned documents in seconds.

    Safeguard: Access follows existing permissions and records management rules.

  • Drafting and consultation analysis

    First drafts of routine letters, and themes drawn from large volumes of consultation responses.

    Safeguard: Transparency records are published, and people review everything before it is issued.

When it matters most

Ransomware at a council: restoring services in order of need

Attacks on public bodies can disrupt services for months. This is how preparation and our response service are designed to shorten that.

Illustrative scenario showing how our service is designed to work. Response times are agreed with each client and set out in their service agreement.

  1. Saturday 23:40

    Detect

    Monitoring raises an alert for mass file changes on a server. The on-call analyst confirms ransomware activity.

  2. 23:55

    Contain

    Affected servers are isolated and compromised accounts disabled. Backups, held separately and immutable, are untouched.

  3. Sunday 01:00

    Coordinate

    Your incident lead convenes the response team. We help you report to the NCSC and, if personal data is at risk, to the ICO.

  4. Monday

    Prioritise

    Services are restored in the order agreed in advance: safeguarding and social care systems first, then payments and customer contact.

  5. First week

    Communicate

    Residents, councillors and partners get clear updates on what is working and what to do in the meantime.

  6. Afterwards

    Strengthen

    A written review maps the lessons to the Cyber Assessment Framework and updates the recovery plan.

Standards and assurance

The standards the public sector sets for itself

We work to these standards and help you prepare the evidence each one asks for. Assessment and assurance decisions rest with the relevant authority.

  • NCSC Cyber Assessment Framework and GovAssure

    What it asks forOutcome-based objectives for cyber resilience. GovAssure applies them to central government's critical systems.

    How we helpGap analysis, remediation and evidence against each objective.

  • GOV.UK Service Standard

    What it asks forFourteen points covering user needs, accessibility, security, open standards and reliability.

    How we helpResearch-led design and delivery that prepares services for assessment.

  • Technology Code of Practice

    What it asks forCriteria for designing, building and buying technology, including cloud first and open standards.

    How we helpArchitecture and procurement advice aligned to each point.

  • Public sector accessibility regulations

    What it asks forWebsites and apps must meet WCAG 2.2 AA and publish an accessibility statement.

    How we helpAudits, fixes, testing with assistive technology and help drafting your statement.

  • Algorithmic Transparency Recording Standard

    What it asks forPublished records of how algorithmic tools are used in decisions that affect the public.

    How we helpDocumentation of each tool's purpose, data, oversight and risks.

  • Cyber Essentials

    What it asks forThe government-backed baseline, required of suppliers on many public contracts.

    How we helpReadiness for your organisation, and assurance of your supply chain.

Our approach

Your first 90 days with Anthrasec

A typical first engagement for a public body. You see progress every fortnight, and you own everything we produce.

A presenter showing charts on a large screen to colleagues in a meeting room
  1. Weeks 1–2

    Discover

    We map your services, systems, data and suppliers, and review your position against the Cyber Assessment Framework.

    You get: A clear picture of your estate and risks

  2. Weeks 3–6

    Secure the basics

    Multi-factor authentication, patching, backups and monitoring are prioritised around your most critical services.

    You get: Urgent gaps closed and monitoring live

  3. Weeks 7–10

    Deliver

    We deliver the first agreed improvement, such as stabilising a legacy system, an accessible service or an AI pilot.

    You get: A working improvement in live use

  4. Weeks 11–13

    Evidence and plan

    We document controls, test recovery and agree a phased roadmap with costs for your business case.

    You get: Assurance evidence and a costed roadmap

For your team

What each leader gets from working with us

Public sector programmes answer to many stakeholders. We make sure each of them has what they need.

Common questions

Public sector IT and security, answered

Can you modernise legacy systems without disrupting services?

Yes. We work in stages: first stabilise and secure the existing system, then move functions across one at a time, running old and new side by side until each part has proved itself. There is no single cutover, so services keep running throughout.

Do you build services to the GOV.UK Service Standard?

Yes. We start with user research, design for accessibility from the outset, use open standards and work in the open with your team, so the service is ready for assessment at each stage.

How do you help with the Cyber Assessment Framework?

We assess your current position against each objective, prioritise the gaps by risk, help you close them and gather the evidence. For central government systems, that supports your GovAssure review.

Can public bodies use AI responsibly?

Yes. We begin with low-risk administrative uses, complete data protection and equality impact assessments, keep officers responsible for decisions, and help you publish transparency records where the Algorithmic Transparency Recording Standard applies.

Will you work alongside our in-house team?

Yes. We join your team's ways of working, share documentation and pass on skills as we go, so you are not left dependent on us.

Do you work with smaller bodies such as schools and town councils?

Yes. Smaller public bodies face the same threats with far fewer specialists. We offer proportionate support, starting with the basics that prevent most attacks.

More sectors

Explore our other sectors

Compare all sectors

Work with us

Ready to work with Anthrasec?

Let's schedule a meeting.

Pick a time that suits you and tell us a little about what you need. We'll come prepared, with the right people in the room.

Step 1 of 4

Choose a date and time

October 2026

Checking availability…

Times are shown in UK time (London). Meetings are held on Microsoft Teams.

Available times

Choose a date to see available times.