Practical steps to help councils accelerate CAF improvement
CAF Support is a £6 million fund helping 52 councils that have completed a Cyber Assessment Framework (CAF) assessment to accelerate their cyber resilience improvements and strengthen resilience across local government.
Since our last blog post, we have provided technical guidance and wider support to CAF Support councils, including our first workshop on engaging senior leaders. We will share the workshop resources with all councils soon.
Subscribe to our cyber newsletter to receive the resources when they are published and stay up to date with our cyber news and updates.
This blog shares what is helping CAF Support councils to make progress and sets out practical steps that your council can take across four high impact areas.
What’s helping councils progress with the CAF
A consistent set of themes is emerging from the councils we have worked with so far:
- Progress is strongest where cyber is treated as a corporate priority, with visible senior ownership and regular governance engagement.
- Councils with clear roles and responsibilities move faster from assessment to implementation.
- Small, practical improvements are more effective than large-scale transformation, particularly in the early stages of CAF adoption.
- Councils benefit from sharing approaches, templates and lessons through existing networks and with peers.
- Linking cyber activity to wider organisational processes, such as risk, business continuity and asset management helps embed CAF into business-as-usual activity.
Practical steps and top tips from CAF Support councils
CAF Support is helping councils to implement priority actions from their improvement and implementation plans (IIPs) for objectives A and D.
Through this work, we’ve identified practical steps that can help other councils address the following four high impact areas:
Risk management
Once cyber risk was on the corporate risk register, the conversation shifted from technical detail to organisational impact.
- Engage risk colleagues early and involve non-cyber stakeholders. This broadens ownership and improves understanding of cyber risk across the council.
- Connect service-level and corporate risk. Linking operational risks to the corporate risk register makes escalation, ownership and decision-making clearer.
- Treat cyber as a corporate risk, not just an IT issue. Progress is strongest where there is clear senior ownership and support from the senior leadership team.
- Make cyber a recurring agenda item at governance boards or risk meetings, such as monthly or quarterly. Councils have found this improves senior engagement and decision making.
- Clarify ownership and accountability. Ensure key risks have named senior owners, such as the Senior Information Risk Owner, and reflect responsibilities in role descriptions where appropriate.
Asset management
Agreeing a single definition of ‘asset’ across the council was a simple step that unlocked clearer ownership.
- Agree what counts as an asset across the council, not just within technical teams.
- Develop an asset management policy or process that sets out ownership, timescales and lifecycle expectations.
- Prioritise high-risk or business-critical assets rather than trying to achieve full coverage from the outset.
- Record end-of-life dates where known so replacement and risk decisions can be made earlier.
- Recognise asset management is an organisational capability and an outcome of good cyber and service management practices.
Incident response planning
Having a clear ‘break-glass’ plan meant teams knew exactly what to do under pressure.
- Make sure there are clear roles and responsibilities for incident preparation and incident response. This reduces delays and confusion.
- Align cyber response plans with wider business continuity arrangements to help coordinate responses across the council.
- Review response and business continuity plans regularly and include a ‘break-glass’ section. Set out pre‑agreed emergency access or actions, with clear steps and key contacts, to use when normal administrative or decision-making routes are unavailable.
- Regularly test backup and restore procedures so recovery arrangements are proven, not assumed.
- Run incident debriefs after every significant event. Capture lessons learned from cyber incidents, outages and exercises to help improve plans and build confidence across teams.
- Keep contact lists up to date, including escalation contacts and supplier information.
Testing and exercises
Bringing non-technical teams into exercises made them far more realistic and improved preparedness.
- Involve teams from across the council and tailor exercises to different directorates.
- Use scenario-based exercises on real council services rather than generic cyber scenarios.
- Start with small, low-complexity exercises to build confidence and participation before scaling up.
- Use peer networks and local Warning, Advice and Reporting Point (WARP) groups to share materials and approaches where possible.
- Test little and often rather than waiting for large annual exercises.
- Capture actions and assign ownership immediately after every exercise. Improvements are more likely when actions are prioritised, assigned to named owners and tracked through governance meetings.
- Involve senior leaders in exercises to improve their understanding of organisational risks and support faster decision-making following.
You can implement these steps at any stage of your CAF journey.
Get started with the CAF for local government
Completing a CAF assessment and having it assured through our independent assurers will put your council in a stronger position to access future support.
If you’ve not started the CAF yet, you can:
- find out what the CAF is and how it can benefit your council
- learn what the assessment involves and how much time it takes
- prepare for the self-assessment
We know you still have questions about how to approach the CAF. We’ve published answers to common questions on our website.
If you have additional questions or need support, email [email protected].
Categories: Blog posts
Tags:
UK Ministry of Housing, Communities and Local Government (MHCLG) 