Driven by escalating geopolitical tensions, legacy system reliance, and the rapid rise of artificial intelligence, public bodies now treat cyber resilience as a core foundation of modern governanceEvolution toward centralisation: Cybersecurity in the UK public sectorHistorically managed independently by individual departments, UK public sector cybersecurity underwent a fundamental realignment following the establishment of the National Cyber Security Centre (NCSC) in 2016 and the high-profile WannaCry ransomware attack. Between 2022 and 2024, the trajectory solidified under the Government Cyber Security Strategy 2022–2030, establishing centralised standards, strict accountability, and mandatory secure-by-design procurement. Unique public sector constraints and threat vectorsUnlike private enterprise, government cybersecurity directly safeguards critical national infrastructure, national security, and massive stores of sensitive citizen data:Sovereignty and data classification: Strict regulations dictate that sensitive defence and law enforcement data must remain within UK borders and approved environments. Targeted adversaries: Public infrastructure faces heightened exposure to nation-state actors and politically motivated adversaries seeking to steal state secrets, disrupt economic stability, or erode public trust. Emerging frontiers and future threatsLooking ahead, public sector resilience extends into several critical domains: