Public sector organisations are facing a cybersecurity challenge defined less by a single threat and more by sustained pressure from multiple directions at once. Attack volumes continue to increase as adversaries are becoming more organised, swiftly adopting AI into their strategies, and digital transformation programs are expanding the number of systems that must be secured.

The UK National Cyber Security Centre (NCSC) reported handling an average of four nationally significant cyber incidents each week in the 12 months to August 2025. A large share of these investigations involved Advanced Persistent Threat (APT) groups, including nation-state actors and highly capable criminal organisations, operating with patience and technical sophistication. Campaigns linked to groups such as Russia-aligned Midnight Blizzard demonstrated how attackers increasingly target identity infrastructure and cloud collaboration environments to maintain long-term access.
At the same time, government departments, local authorities and critical infrastructure operators are under growing pressure to digitise services and improve accessibility for citizens. This results in a widening gap between the pace of digital adoption and the resources available to secure it.
Modernisation under constraint
Security leaders across the public sector are being asked to modernise defences while managing legacy technology estates, complex procurement processes and ongoing skills shortages. Hiring experienced cybersecurity professionals remains difficult, and internal teams are often stretched across compliance, incident response and operational security responsibilities simultaneously.
When public services are disrupted or information is compromised, the implications can be devastating. The operational impact was visible in the cyber incident affecting the Royal Borough of Kensington and Chelsea and shared-service partners, first detected on 24 November 2025, with subsequent public communications warning that personal data may have been accessed.
Nevertheless, recent investment shows recognition of the scale of the challenge as the UK government has announced a £210 million commitment in January this year to strengthen public sector cyber resilience. The news arrives at a critical moment, with the financial and societal consequences of a breach in the public sector reaching $2.86 million on average in 2025.
Funding alone, however, does not immediately solve capability gaps. Therefore, organisations should reconsider how security testing is conducted.
Extending security through global expertise
Traditional security models such as annual pentesting, compliance-driven security audits and red team exercises often rely on scheduled assessments carried out once or twice a year. While valuable, these point-in-time exercises struggle to keep pace with environments that change continuously through software updates, cloud migrations and new digital services. This has led to organisations focusing on ongoing identification and validation of weaknesses across their attack surface rather than relying on periodic reviews, or, as the industry refers to it, Continuous Threat Exposure Management (CTEM).
Within this model, crowdsourced security is gaining traction as a practical way to expand defensive capacity without expanding permanent headcount. Crowdsourced security programs enable organisations to work with a vetted global community of ethical security researchers who test systems on an ongoing basis. Instead of relying solely on internal teams or limited external engagements, organisations gain access to thousands of specialists with different technical backgrounds and perspectives.
Structured initiatives such as bug bounty programs, vulnerability disclosure programs (VDPs) and continuous pentesting that combines AI with human validation allow researchers to responsibly report vulnerabilities as they are discovered. These programs led to the discovery of 85,000 valid vulnerabilities (of which 23,000 were high/critical severity), totaling $81 million in bounties paid for the year.
If you liked this content…
The approach changes how vulnerabilities are uncovered. Rather than following predefined checklists, researchers explore systems in ways that resemble real attackers, chaining together weaknesses, testing unconventional pathways and identifying issues automated tooling may overlook.
Implementation usually begins with defining scope and risk priorities. Security leaders determine which systems are in scope, what types of testing are permitted and how vulnerabilities will be evaluated. Once launched, researchers can submit findings for validation, and remediation teams can address confirmed issues. Over time, organisations can choose to expand or narrow their programs depending on their priorities and allowing testing intensity to increase during major technology rollouts.
To be effective in government environments, these programs need clear guardrails: explicit authorisation (including safe-harbour language), tight scoping to avoid safety-critical systems, defined severity and SLA expectations, and a triage/remediation workflow that won’t overwhelm already stretched teams. Without that operating model, more findings can simply translate into more backlog.
Why the public sector is paying attention
For resource-constrained organisations, the appeal lies in flexibility and scale. Crowdsourced models provide access to specialised skills that may not exist internally, including expertise in emerging areas such as AI systems, cloud architectures and data privacy vulnerabilities. Multiple researchers working at the same time can significantly accelerate vulnerability discovery, reducing the time attackers have to exploit weaknesses.
In addition, visibility is equally important. Security teams gain measurable insights into exposure levels, vulnerability trends and remediation performance. To help translate technical outcomes into metrics that leadership teams and boards can understand, many security leaders turn to frameworks such as Return on Mitigation (RoM), connecting security investment directly to risk reduction.
Complementing internal teams
Crowdsourced security does not eliminate the need for in-house expertise. Instead, it changes how internal teams operate. Security professionals can focus more on prioritisation, remediation and strategic planning while external researchers broaden testing coverage.
This collaborative model is particularly relevant for public sector environments where legacy systems coexist alongside modern cloud platforms. Continuous external testing helps identify risks earlier, before they develop into incidents that disrupt essential services and affect people’s daily lives.
As cyber threats continue to evolve, defensive strategies are also becoming more distributed. Public sector organisations are recognising that resilience depends not only on technology investment, but on expanding how expertise is applied.
The UK government itself already operates a public Vulnerability Disclosure Programme that allows security researchers to responsibly report potential vulnerabilities affecting government digital services, illustrating how structured disclosure can support collaborative security. In addition, organisations looking to establish structured disclosure processes can refer to the NCSC’s Vulnerability Disclosure Toolkit for practical guidance on how to design and operate a responsible program.
By combining internal knowledge with a global community of security researchers, organisations can align security efforts more closely with real-world attack behaviour and maintain oversight at a pace that reflects how modern digital services actually operate.








