Cyber Security Strategy

Department for Transport

Highlights

Goaco have been a delivery partner with DFT Digital Services for over 5 years.
The DFT works with other agencies and partners to support the transport network.
The Security Improvement program was a departmental wide program to improve the control framework.

Project requirement

Robust security is required to evolve overtime to stay ahead of threats and challenges in the modern digital world. Government is not immune to these challenges, to ensure all systems and services have controls that are required by the NCSC and that a Cyber Assessment Framework review has been undertaken this programme of work was began. The SIP project garnered significant attention due to its high profile and faced regular updates that were not well-received by management. Upon assuming the role of programme oversight, the project manager found that the program was flagged in red for senior management reporting. The project had not been maintained with detailed updates for several months before the Goaco program manager took charge.

Goaco (previously known as Level 5) have been a digital delivery partner for DFT Digital Services for over 5 years.   Goaco team have been key in many project deliverables.  

The DFT works with our agencies and partners to support the transport network that helps the UK’s businesses and gets people and goods travelling around the country. At the DFT we plan and invest in transport infrastructure to keep the UK on the move.

The Security Improvement program was a departmental wide program to improve the control framework. Initially focusing on the Identification of assets, systems and services and ensuring that adequate up to date information was collected and collated about them. A second stage was to introduce detective controls to identify events and investigate potential incidents.

Goaco assisted with several workstreams for this period, turning the reporting from red (overdue) to green (on-track).

Our Solution

Ensuring accurate reporting, with sufficient information for decision-making, became crucial for developing a forward plan that could be agreed upon. The emphasis was on rectifying reporting discrepancies and providing comprehensive details so that the leadership team could make risk informed decisions. Quickly re-arranging the project to ensure workstreams that can be closed with the greatest risk reduction where primary focus. To streamline operations, the Goaco project manager took proactive measures, closing down longstanding workstreams by actively engaging and driving the work to a successful conclusion. Simultaneously, new workstreams were created to carry the project forward, recognising the dynamic nature of the security landscape that evolves over time.