Devon County Council embeds cyber security into its culture
Serving a county of 1.2 million people in south-west England, for years Devon County Council has been well aware of the growing importance of cyber security to keep its operations running smoothly. The most prudent approach was to move from an on-premises solution to the cloud.
Against a backdrop of more frequent and more damaging security incidents, particularly in the public sector among regional governments, the council proactively took steps to secure their organisation and the people, communities and businesses they serve. They realised it was probably only a matter of time before they’d be targeted by a cybercriminal group intent on encrypting or stealing their data, or both.
More intelligence and greater knowledge of their assets
So, a few years ago they installed Microsoft Defender tools to gain more intelligence about their IT estate and acquire the knowledge they needed to respond to security alerts. However, while all this information was clearly invaluable, it also presented a challenge.
“The ICT strategy at Devon County Council had determined that an enterprise licensing arrangement with Microsoft was the right approach for the authority, with the benefits of Defender’s extensive security tooling being an attractive element of the package,” says Robyn Dennis, Strategic Cyber Security Manager in the Digital & Technology Service at Devon County Council. “With over 5,000 internal staff we knew we needed comprehensive protection in place across the whole organisation.
“However, we also knew we didn’t have the capabilities, knowledge or capacity in-house to handle what we were seeing. We reached out to a couple of suppliers we’d previously worked with to run a Proof-of-Concept (POC) on Microsoft Sentinel to understand it better and consider what the architecture of a Security Operations Centre (SOC) would look like in the long run, and we discovered that a hybrid approach to the SOC would suit us best.”
Previously, the local authority had some out-of-hours security coverage but lacked 24*7 monitoring of their estate, which they knew was the minimum level of security to give them peace of mind every day.
Setting out on the next stage of their journey, they searched for the right partner to protect their organisation, which was when Microsoft suggested they talk to Quorum Cyber.
“We liked their ethos of helping good people win and with their Microsoft-first approach they seemed the right fit,” says Robyn, who has worked tirelessly to raise cyber security awareness in the council’s hierarchy and to convince the senior management and governing board that it should be part of their culture.
Swift onboarding to add a safety net
Onboarding to the Microsoft Sentinel Managed Detection & Response (MDR) service, run by the experienced SOC team, was swiftly achieved before the Christmas 2022 change freeze to give Robyn’s team a safety net and peace of mind during the festive season, which some threat actors see as an opportunity to target organisations whose teams are on annual leave.
“The 24*7 monitoring capability is a real plus point and gives me more assurance that we have the right capabilities in place to manage risks as best we can,” she says. “It frees a lot of our team up to take on other activities.”
In a relatively short time of working alongside Quorum Cyber, she’s happy with the continual improvement, the iterative reviews to assess the council’s security maturity, the guidance to navigate any incidents, and the ease of engaging with the SOC.
“The service gives us a lot more confidence and assurance that our systems are working and that any alerts will be picked up at an early stage,” says Robyn. “It gives us the confidence that we can deliver services to citizens. Our Sentinel and our analytics are being managed by experts in their field. We know that without this service, we’d struggle to recruit the same level of skilled professionals.”
Trust has grown so much that the partnership is now looking to set up delegation of authority so that the SOC team can fine-tune configurations without requesting permission from Robyn’s team on a case-by-case basis, which speeds up improvements to security.
Growing a cyber security culture
“Cyber security is now one of our highest corporate risks and high on the board’s list of priorities. I’m doing a piece of work so that our senior leadership team (SLT) always understands the cyber risks we face. I always tell the SLT about the positive news and the partnership definitely helps me with this. We need to keep progressing and it’s important that we don’t take any steps backwards. I’ve also spent some time telling our cabinet members and our scrutiny board to help them understand our current cyber security posture – what’s good and what’s bad. We’ve been on a journey of internal awareness of why cyber security is important. Years ago there was a perception that it could have been a blocker to operational activities, but we now see it as an enabler in the long term.”
The purpose-built customer dashboard is another plus point for Robyn. “Clarity is brilliant, the detail that goes into the tickets is really useful. I regularly take reports and the dashboard images to our Senior Information Risk Officer (SIRO). The dashboard images give us useful information and we see threat intelligence reports give us advanced warning of zero-days. Knowing that there’s someone in the background threat hunting in our environment gives us extra assurance.”
Teamwork solidifies South Ayrshire Council’s cyber defences
Scottish local authority continues its journey to reducing risk
With a population of around 112,000 people, South Ayrshire is one of 32 council areas in Scotland. South Ayrshire Council ensures that services run smoothly throughout the region, keeping the business community working, the economy flowing and making life easier for people’s everyday lives. It’s also a major employer, with more than 5,000 staff. So it’s no surprise that the local authority makes cyber security a top priority. Reducing the risk of services being disrupted or confidential data being stolen or leaked externally is essential – just as in any other public sector body.
Providing value for money for taxpayers is obviously crucial too. So the Council chooses to work with a cyber security partner for the expertise and resources it doesn’t have in-house.
The relationship began four years ago when Quorum Cyber helped with consultancy work that proved central to transitioning the Council’s connection to the Public Service Network (PSN) away from the use of a segregated enclave toward an organisational security posture that met PSN security compliance requirements.
South Ayrshire Council recognised that a strong partnership with cyber security experts was necessary to make such a transformational change in the cyber security posture.
“We needed a partner to help plan what that should look like and to help with advice and decision making that our operational teams needed to move forward with the cyber resilience programme,” explains Anne Yeo, Senior ICT Security Analyst at South Ayrshire Council.
“It turned into a partnership that offered much more. As we began to implement security solutions we discovered that zero-trust networking would strengthen the security profile and improve our entire corporate network. Quorum Cyber was able to validate some of the plans that our zero-trust partner had set up. Quorum Cyber took on much more of an auditing role in that partnership, as well as providing core functionality for some of the cyber security we needed. Both of those things were instrumental to getting us to where we are now.”
Working together
This early work laid a solid foundation for the Council to prepare to take on a round-the-clock monitoring and detection service.
“We found that Quorum Cyber’s Managed SOC solution was in line with the partnership view compared to other cyber security providers,” says Anne. The Council benefits by working together with Quorum Cyber to improve things and by taking a team approach, rather than having an external company coming in, delivering a fixed service and then walking away.
The Council is now protected with 24/7 security via Quorum Cyber’s Microsoft Sentinel Managed Detection & Response service, which is run by its experienced Security Operations Centre (SOC) team in the UK. “This service has changed the way we think about security here,” says Anne. “Twenty-four hour monitoring provides a reassurance that is hugely popular and very much worth the investment.”
In parallel, the Council’s ICT Security Team has made real improvements in cyber security awareness across the Council’s service teams during the past four years. Like in any organisation, employees form the frontline of defence against cyber threats, so the staff’s knowledge and understanding of how to identify and react is really important.
Quorum Cyber has recently provided other services, including Incident Response playbooks, to help thoroughly prepare in the event of a security incident.
Extending the cyber security team
“We’ve really felt that Quorum Cyber is part of the cyber team and the wider team,” explains Anne. “They’re happy to quickly advise on small matters or simple questions as well as get involved in the larger, more complicated projects. And we’ve found the personal relationships most valuable.”
Quorum Cyber continues to work closely with the local authority to ensure that they widen their focus and mature their cyber security posture in line with an ever-changing threat landscape.
Partnership approach key to success at Renfrewshire Council
For Renfrewshire Council, situated in central, west Scotland, cyber security is about people and partnerships first and foremost. Technology simply provides the tools for people to collaborate to protect its assets and data, and minimise risk. How partners work together on all levels is crucial to strengthening the cyber security posture for the Council which, like all public sector bodies, needs to continuously defend itself against today’s threats and any that are just over the horizon.
Renfrewshire Council’s cyber security partnership with Quorum Cyber has grown from strength to strength since it began in 2019. Then, all Local Authorities in the UK needed to complete an annual Public Services Network (PSN) compliance health check, which consisted of vulnerability management and penetration testing among other assessments. Originally seeking professional support to pass their PSN health check, Quorum Cyber have since successfully tendered for more one-off engagements including advisory services.
Growing and learning together
Collaboration on projects has worked well, with both sides contributing and learning from each other along the journey and culminated in Renfrewshire Council partnering with Quorum Cyber when they tendered for a Security Operations Centre (SOC) team to monitor and protect their IT estate and multi-cloud environment around the clock. Quorum Cyber implemented the Microsoft Sentinel Managed Detection and Response (MDR) service in September 2022. The SOC team runs the MDR service 24 hours a day, 365 days a year to provide comprehensive protection and peace of mind.
From day one of the relationship, the Council was clear that it wasn’t interested in a simple transactional service; it wanted to extend its security team to exchange ideas and knowledge, develop its own services and grow together with a partner it could trust and call upon at any time should a cyber security incident occur. They were attracted by Quorum Cyber’s fresh, honest approach to cyber security.
“Price is never the driving factor when it comes to security partners,” says Carol Peters, Cyber Security Architect at Renfrewshire Council. “It was important for us to join up with a company that was going to be a true partner and we wanted an interactive one that could react fast when necessary.
“That partnership was essential for us and we’ve always had a very good relationship with Quorum Cyber. They are willing to help us deal with any incidents quickly, even if they are out of scope of the contract, or out of hours.”
Serving around 180,000 citizens in west, central Scotland, Renfrewshire Council needs to keep its physical and digital operations running for schools, medical centres, transport, businesses and the whole community, without interruption.
Cyber security is a business issue
The Council shares Quorum Cyber’s belief that cyber security isn’t really a technology issue, but a business issue where risk needs to be managed holistically. In the event of a sudden, damaging cyber-attack, systems and tools could be taken out of action at very short notice, or no notice – it’s then an urgent problem for the business.
“It’s important that cyber security is seen to be a business enabler and my cyber security strategy is aligned to the Council’s,” says Carol. “Quorum Cyber knows our architecture, they know us and our approach to cyber security.”
Protecting the whole community
As in any organisation, while building a strong cyber security posture is important, people are often the greatest asset, but only if they understand cybercrime. Employees need to be trained in how to spot phishing emails, maintain good cyber hygiene and stay safe online. One click on a malicious email could open the door to a breach which, in turn, could result in a ransomware attack later on.
This is why the Council is serious about cyber security education and training. The Council partnered with Get Safe Online, the UK’s leading internet safety organisation and in 2019, the Council launched Ren Safe Online to teach citizens and employees about threats on the internet. The Council was also the first in Scotland to launch the Get Safe Online Ambassador training programme, training volunteers about online safety and how to recognise when someone is at risk of harm due to online threats such as scams or bullying. Ultimately, the Council’s long-term partnership with Quorum Cyber is a joint operation about protecting families, children and essential community services, and people’s data, identities and finances.






