Expert Cyber Consultancy for UK Policing

Meet NCSC CAF and NIS Directive requirements with a consultancy team that understands UK policing.

Speak to an expert

From NCSC CAF assessments for critical OES systems to National Policing Cybercrime Framework (NCF) strategy, we help UK police forces navigate complex regulatory requirements and secure mission-critical systems

NIS Directive OES Compliance Support
NCSC CAF Critical Systems Assessment
Supply Chain Cyber Essentials Guidance

NCSC Cyber Assessment Framework (CAF) for UK Police Forces

As Operators of Essential Services (OES) under the NIS Directive, police forces must protect their critical systems. Our experts provide end-to-end CAF consultancy, from gap analysis to implementation. We help you secure 999 call handling, command and control, and intelligence systems, ensuring you meet regulatory requirements and can prove your resilience to the NCSC and Home Office.

Achieve NIS Directive Compliance

National Policing Cybercrime Framework (NCF) Strategy

We align you with the National Policing Cybercrime Framework and then double down on capability building: our Black Hat-delivered cyber security and offensive hacking training equips your teams to investigate cybercrime and apply the 4 P’s—Pursue, Prevent, Protect, Prepare—against digital-age offending.

Enhance Your Cybercrime Capability

Cyber essentials & plus for Police & supply chain for Policing

Cyber Essentials is the fundamental baseline for security. We guide your force through certification to protect your own IT estate, and where a deeper level of assurance is needed, Cyber Essentials Plus adds an independent technical audit - simulating real-world attacks against your devices and external attack surface to prove your controls actually hold up, not just that they're documented.

Critically, we help you build a program to manage your third-party risk by ensuring your entire supply chain - from bodycam providers to software vendors - is Cyber Essentials certified, protecting you from data breaches.

Secure Your Supply Chain

Building Cyber Resilience & Incident Readiness for Policing

Meeting CAF requirements is the starting point, not the end goal. Once the gaps are identified and closed, the harder question is whether your force can actually detect and respond to an attack in progress - on 999 systems, case management platforms, or the third-party tools your force depends on day to day.

Our consultancy work feeds directly into your wider security posture. We help forces move from a point-in-time compliance assessment to an ongoing view of cyber maturity, so leadership can see not just where gaps exist today, but how resilience is tracking over time.

Where forces need continuous visibility rather than a periodic review, our Managed Detection and Response service extends that assurance into day-to-day monitoring. And because a strong CAF position depends on knowing your controls actually hold up under attack, our consultancy work is designed to complement - not duplicate - CREST-accredited penetration testing for UK police forces, which validates exactly the systems this consultancy work is built to protect.

Start Your Force's CAF Consultancy Programme

From gap analysis to remediation, our SC-cleared consultants help UK police forces close CAF gaps and meet NIS Directive requirements.

Plan Your CAF Programme

Or call us on 0330 390 0507

Cyber Consultancy Faqs for Policing

  • The CAF is the NCSC's framework for assessing the cyber resilience of Operators of Essential Services (OES). As OES, police forces use CAF to measure their security against a detailed set of principles, ensuring critical systems (like 999, Command and Control, and intelligence databases) are protected from sophisticated cyber attacks.

  • Yes. Under the Network and Information Systems (NIS) Directive, UK police forces are designated as Operators of Essential Services (OES). This legally requires them to take appropriate measures to manage risks to their network and information systems and to report significant incidents. The CAF is the NCSC's methodology for OES to demonstrate this compliance.

  • Cyber Essentials is a foundational, baseline certification that protects against the most common cyber threats. The CAF is a much more in-depth, risk-based framework specifically for Critical National Infrastructure (CNI), which includes essential police services. CAF is designed to protect against higher-level threats and is a regulatory requirement under the NIS Directive.

  • Our consultancy on the National Policing Cybercrime Framework (or Strategy) focuses on the investigative side of policing. We help your force build the strategic plan and capabilities to meet the "4 P's" (Pursue, Prevent, Protect, Prepare) and enhance your ability to respond to and investigate cyber-enabled and cyber-dependent crime.

  • Police forces rely on hundreds of third-party technology suppliers (e.g., for bodycams, forensic tools, or case management software). A cyber attack on one of these suppliers could compromise sensitive police data or critical systems. Mandating Cyber Essentials for your supply chain is a key control to manage this third-party risk.

  • A cyber maturity assessment looks beyond a single point-in-time compliance check to show how your force's security posture is developing over time — where controls are strengthening, where gaps are recurring, and where investment should go next. It's particularly useful for forces that have already completed a CAF assessment and want an ongoing view of progress, rather than waiting for the next scheduled review to find out if gaps have been closed.

  • CAF consultancy identifies and remediates gaps against the NCSC's framework; penetration testing then validates that the controls put in place actually hold up against a real attack. The two are complementary rather than overlapping — our penetration testing for UK police forces is CREST-accredited and specifically tests the mission-critical systems a CAF programme is designed to protect.

  • A CAF assessment is a structured review against a defined set of principles, typically carried out periodically. Cyber resilience is the broader, ongoing capability to detect, withstand, and recover from an attack between those assessments. Forces that treat CAF as an annual milestone rather than a continuous programme can pass an assessment and still be exposed the rest of the year — which is why we pair consultancy work with Managed Detection and Response for forces that want continuous visibility rather than a periodic snapshot.