Public services can't close for maintenance. We help government, councils, education providers and arm's-length bodies modernise legacy systems, strengthen cyber resilience and build accessible services, in stages that fit your budget.
- Aligned to the Cyber Assessment Framework
- Accessible by design
- Staged, low-risk modernisation

28%
of central government systems were legacy technology in 2024, up from 26% a year earlier (State of digital government review)
The sector today
Doing more with systems built for another era
Public bodies are asked to deliver better digital services, defend against a severe cyber threat and adopt AI, often on technology that is decades old.

The UK public sector spends over £26 billion a year on digital technology, yet the government's own review found that almost half of central government services still have no digital route, and that legacy technology is growing as a share of the estate. Ageing systems are expensive to run, hard to secure and difficult to connect to anything new. They also hold some of the most important data in the country. The National Audit Office has described the cyber threat to government as severe and advancing quickly, and attacks on councils, libraries and health suppliers have shown how long recovery can take when the basics are missing.
Fixing this is rarely about one big replacement programme. The organisations making progress modernise in stages: stabilising and securing what they have, moving the right workloads to the cloud, building new services around user needs, and retiring old systems once the new ones have proved themselves. Skills are the other constraint, with digital and cyber roles hard to fill across central and local government. Anthrasec works alongside in-house teams to add that capacity, following the standards the public sector sets for itself: the Cyber Assessment Framework, the GOV.UK Service Standard, the Technology Code of Practice and the accessibility regulations.
£45bn
a year in savings and productivity benefits could be achieved by fully digitising public services
Source: DSIT, State of digital government review, January 2025
1 in 3
cyber security roles in central government was vacant or filled by temporary staff in 2023–24
Source: National Audit Office, Government cyber resilience, January 2025
30%
less spent on technology by the UK public sector than benchmark comparisons, at around £26 billion in 2023
Source: DSIT, State of digital government review, January 2025
2%
of local government staff work in digital and data roles, half the 4% benchmark
Source: DSIT, State of digital government review, January 2025
Nearly half of services still have no digital route
Where there is no digital pathway, people fall back on phone, post and paper, which is slower for citizens and more expensive to run. Most of the savings the review identified come from reducing that manual processing.
Source: DSIT, State of digital government review, January 2025
| Part of the public sector | Share |
|---|---|
| Central government | 47% |
| NHS | 45% |
Who we help
Support across the public sector
Every public body has its own duties, budgets and governance. We shape our services to fit.
Central government departments
Extra engineering capacity for modernisation, cyber resilience and service delivery, working to government standards.
Local authorities
Secure, joined-up systems for revenues, housing, social care and customer contact, sized for council budgets.
Arm's-length bodies and regulators
Modern platforms and proportionate security for smaller specialist teams.
Schools, colleges and universities
Protection for student data and research, and networks that cope with thousands of devices.
Emergency services and justice
Resilient, secure infrastructure for services where minutes matter.
Housing associations and charities
Dependable systems and good security for organisations serving residents and communities.
The pressures
Six risks public sector leaders ask us about
Each one is manageable with the right controls. Here is what's at stake, and how we respond.
Legacy technology
- The risk
- Unsupported systems are costly, fragile and hard to secure, yet critical services depend on them.
- Our response
- Staged modernisation: stabilise, secure, migrate and retire, with no big-bang cutover.
A severe cyber threat
- The risk
- Ransomware groups and state-linked attackers target public bodies, and recovery can take months.
- Our response
- Controls aligned to the Cyber Assessment Framework, 24/7 monitoring and rehearsed recovery.
Skills shortages
- The risk
- Digital and cyber roles are hard to fill, leaving teams stretched and reliant on contractors.
- Our response
- Specialists who work alongside your team and pass on knowledge as they go.
Accessibility duties
- The risk
- Public sector websites and apps must meet accessibility regulations, and many still fall short.
- Our response
- Design and testing to WCAG 2.2 AA, with accessibility statements kept accurate.
Budget pressure
- The risk
- Capital is scarce, and the running costs of old systems crowd out improvement.
- Our response
- Clear business cases, phased delivery and cloud costs that are measured and controlled.
Trust in AI and data
- The risk
- Citizens expect transparency about how automated tools and their data are used.
- Our response
- Human oversight, impact assessments and records that follow the Algorithmic Transparency Recording Standard.
What we deliver
Our services, applied to the public sector
One team covers security, software, infrastructure, cloud and AI, working alongside your own people.

01
Managed Cybersecurity
Resilience measured against government frameworks.
- Cyber Assessment Framework gap analysis
- 24/7 monitoring and incident response
- Penetration testing and vulnerability management
- Cyber Essentials readiness for you and your suppliers
02
Application Development
Services designed around the people who use them.
- Service design led by user research
- Builds to the GOV.UK Service Standard
- Accessibility to WCAG 2.2 AA
- Open standards and reusable components
03
Enterprise Infrastructure
Legacy estates made stable, then modern.
- Legacy system assessment and stabilisation
- Staged migration and decommissioning
- Resilient networks for offices and public sites
- Backup and recovery testing
04
Cloud Platforms
Cloud adopted securely and affordably.
- Migration in line with the cloud-first policy
- Secure foundations with built-in guardrails
- Cost management and reporting
- Data residency and classification controls
05
Modern Workplace
Productive, secure working for public servants.
- Microsoft 365 for hybrid public service teams
- Managed devices for office, home and field
- Secure sharing with partner organisations
- Identity and access management
06
AI & Automation
AI used openly and accountably.
- Enquiry triage and routing
- Casework and correspondence summaries
- Document search and data extraction
- Transparency records and impact assessments
AI in public services
AI in public services, done transparently
Government trials show that AI can return real time to public servants. Public trust depends on being open about where it is used and keeping people accountable for decisions.
26 min
saved per person per day in a three-month government trial of an AI assistant, involving more than 20,000 civil servants
Source: GOV.UK, Government trial of an AI assistant for civil servants, June 2025
Enquiry triage
Sorting and routing emails, forms and calls to the right team, with urgent cases flagged.
Safeguard: Staff can see how each item was classified, and correct it.
Casework support
Summarising long case files and correspondence, so officers can reach decisions faster.
Safeguard: Officers make every decision. AI output is advisory, and recorded as such.
Document search and extraction
Finding information across policies, records and scanned documents in seconds.
Safeguard: Access follows existing permissions and records management rules.
Drafting and consultation analysis
First drafts of routine letters, and themes drawn from large volumes of consultation responses.
Safeguard: Transparency records are published, and people review everything before it is issued.
When it matters most
Ransomware at a council: restoring services in order of need
Attacks on public bodies can disrupt services for months. This is how preparation and our response service are designed to shorten that.
Illustrative scenario showing how our service is designed to work. Response times are agreed with each client and set out in their service agreement.
Saturday 23:40
Detect
Monitoring raises an alert for mass file changes on a server. The on-call analyst confirms ransomware activity.
23:55
Contain
Affected servers are isolated and compromised accounts disabled. Backups, held separately and immutable, are untouched.
Sunday 01:00
Coordinate
Your incident lead convenes the response team. We help you report to the NCSC and, if personal data is at risk, to the ICO.
Monday
Prioritise
Services are restored in the order agreed in advance: safeguarding and social care systems first, then payments and customer contact.
First week
Communicate
Residents, councillors and partners get clear updates on what is working and what to do in the meantime.
Afterwards
Strengthen
A written review maps the lessons to the Cyber Assessment Framework and updates the recovery plan.
Standards and assurance
The standards the public sector sets for itself
We work to these standards and help you prepare the evidence each one asks for. Assessment and assurance decisions rest with the relevant authority.
NCSC Cyber Assessment Framework and GovAssure
What it asks forOutcome-based objectives for cyber resilience. GovAssure applies them to central government's critical systems.
How we helpGap analysis, remediation and evidence against each objective.
GOV.UK Service Standard
What it asks forFourteen points covering user needs, accessibility, security, open standards and reliability.
How we helpResearch-led design and delivery that prepares services for assessment.
Technology Code of Practice
What it asks forCriteria for designing, building and buying technology, including cloud first and open standards.
How we helpArchitecture and procurement advice aligned to each point.
Public sector accessibility regulations
What it asks forWebsites and apps must meet WCAG 2.2 AA and publish an accessibility statement.
How we helpAudits, fixes, testing with assistive technology and help drafting your statement.
Algorithmic Transparency Recording Standard
What it asks forPublished records of how algorithmic tools are used in decisions that affect the public.
How we helpDocumentation of each tool's purpose, data, oversight and risks.
Cyber Essentials
What it asks forThe government-backed baseline, required of suppliers on many public contracts.
How we helpReadiness for your organisation, and assurance of your supply chain.
Our approach
Your first 90 days with Anthrasec
A typical first engagement for a public body. You see progress every fortnight, and you own everything we produce.

Weeks 1–2
Discover
We map your services, systems, data and suppliers, and review your position against the Cyber Assessment Framework.
You get: A clear picture of your estate and risks
Weeks 3–6
Secure the basics
Multi-factor authentication, patching, backups and monitoring are prioritised around your most critical services.
You get: Urgent gaps closed and monitoring live
Weeks 7–10
Deliver
We deliver the first agreed improvement, such as stabilising a legacy system, an accessible service or an AI pilot.
You get: A working improvement in live use
Weeks 11–13
Evidence and plan
We document controls, test recovery and agree a phased roadmap with costs for your business case.
You get: Assurance evidence and a costed roadmap
For your team
What each leader gets from working with us
Public sector programmes answer to many stakeholders. We make sure each of them has what they need.
Chief digital and information officers
Extra delivery capacity, a realistic modernisation roadmap and services that stay available.
Security leads and SIROs
Controls mapped to the Cyber Assessment Framework, tested response and clear risk reporting.
Service owners
Accessible, user-centred services built to the Service Standard and measured against outcomes.
Finance and commercial teams
Phased costs, transparent pricing and evidence for business cases.
Common questions
Public sector IT and security, answered
Can you modernise legacy systems without disrupting services?
Yes. We work in stages: first stabilise and secure the existing system, then move functions across one at a time, running old and new side by side until each part has proved itself. There is no single cutover, so services keep running throughout.
Do you build services to the GOV.UK Service Standard?
Yes. We start with user research, design for accessibility from the outset, use open standards and work in the open with your team, so the service is ready for assessment at each stage.
How do you help with the Cyber Assessment Framework?
We assess your current position against each objective, prioritise the gaps by risk, help you close them and gather the evidence. For central government systems, that supports your GovAssure review.
Can public bodies use AI responsibly?
Yes. We begin with low-risk administrative uses, complete data protection and equality impact assessments, keep officers responsible for decisions, and help you publish transparency records where the Algorithmic Transparency Recording Standard applies.
Will you work alongside our in-house team?
Yes. We join your team's ways of working, share documentation and pass on skills as we go, so you are not left dependent on us.
Do you work with smaller bodies such as schools and town councils?
Yes. Smaller public bodies face the same threats with far fewer specialists. We offer proportionate support, starting with the basics that prevent most attacks.
More sectors
Explore our other sectors
Work with us
Ready to work with Anthrasec?
Let's schedule a meeting.
Pick a time that suits you and tell us a little about what you need. We'll come prepared, with the right people in the room.
Step 1 of 4
Choose a date and time
October 2026
Checking availability…
Times are shown in UK time (London). Meetings are held on Microsoft Teams.
Available times
Choose a date to see available times.



