11 UK cyber entry points · 8 security priorities · 6 DEFONEOS MCPs · NCSC / CPNI / DSIT Cyber backbone
UK cyber security operations are governed by the National Cyber Security Strategy 2022-2030, the Network and Information Systems (NIS2) Regulations 2024, the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, the NCSC Cyber Assessment Framework (CAF) v3.2, and the 2025 Government Cyber Security Strategy. The National Cyber Security Centre (NCSC), CPNI (Centre for Protection of National Infrastructure), DSIT Cyber Division, and GCHQ deliver Active Cyber Defence, CNI protection, incident response, and cyber skills development. The 2025 ransomware strategy and the AI Cyber Security Code of Practice (2024) mandate BFT-governed incident evidence, SBOM provenance, and sovereign cyber posture monitoring. DEFONEOS delivers the UK's first open-source Sovereign Public Services OS purpose-built for cyber operations — BFT-governed incident evidence chains, CSPM cloud posture monitoring, sovereign key management, and independently verifiable security provenance.
All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from NCSC + CPNI + DSIT Cyber + GCHQ + HMGCC + Academic Centres of Excellence (2026-Q1).
| # | Entry point | Location | Function | DEFONEOS fit |
|---|---|---|---|---|
| E1 | National Cyber Security Centre (NCSC) | London / Cheltenham | National cyber authority · guidance · incident response | DEFONEOS MCPs: mcp-cspm · bft-council-probe — cloud posture + BFT governance |
| E2 | CPNI (Centre for Protection of National Infrastructure) | London | CNI physical & personnel security | DEFONEOS MCPs: mcp-cspm · sovereign-keystore — posture + key mgmt |
| E3 | DSIT — Cyber Security Division | London | Cyber policy · Product Security · PSTI enforcement | DEFONEOS MCPs: data-gov-uk-mcp · bft-council-probe — policy data + BFT |
| E4 | GCHQ — Industry Engagement | Cheltenham | SIGINT · cyber intelligence · SME outreach | DEFONEOS MCPs: gdelt-news-mcp · bft-council-probe — threat intel + BFT |
| E5 | HMGCC (Her Majesty's Government Communications Centre) | Milton Keynes | Secure comms · bespoke security engineering | DEFONEOS MCPs: sovereign-keystore · mcp-cspm — secure comms + posture |
| E6 | Joint Forces Cyber Group (JFCyG) | Cheltenham / Corsham | Military cyber operations · defensive cyber | DEFONEOS MCPs: mcp-cspm · bft-council-probe — defensive cyber + BFT |
| E7 | National Crime Agency — National Cyber Crime Unit (NCA NCCU) | London | Cybercrime investigation · takedowns | DEFONEOS MCPs: bft-council-probe · gdelt-news-mcp — investigation evidence + OSINT |
| E8 | Cyber Growth Action Partnership (CGAP) | London | Cyber sector growth · £8.9bn industry | DEFONEOS MCPs: companies-house-mcp · data-gov-uk-mcp — sector data |
| E9 | Academic Centres of Excellence in Cyber Security Research (ACE-CSR) | 20+ UK universities | Cyber research · EPSRC · innovation | DEFONEOS MCPs: data-gov-uk-mcp · gdelt-news-mcp — research + publication tracking |
| E10 | UK Cyber Security Council | London | Professional standards · chartered cyber professional | DEFONEOS MCPs: bft-council-probe — professional governance + BFT |
| E11 | CISP (Cyber Security Information Sharing Partnership) | NCSC-hosted / Nationwide | Threat intel sharing · public-private · 12,000+ members | DEFONEOS MCPs: gdelt-news-mcp · bft-council-probe — threat intel + BFT governance |
| # | Priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| P1 | NCSC Cyber Assessment Framework (CAF) compliance | NCSC / Regulators | mcp-cspm · bft-council-probe | CAF v3.2 · 14 principles · 39 outcomes · BFT-governed evidence |
| P2 | Active Cyber Defence (ACD) integration | NCSC | mqtt-bridge · mcp-cspm | ACD services · Protective DNS · takedown · mail check |
| P3 | Software Bill of Materials (SBOM) provenance | DSIT / NCSC | bft-council-probe · sovereign-keystore | SBOM mandate · NTIA minimum · supply chain · BFT evidence |
| P4 | Critical National Infrastructure (CNI) protection | CPNI / NCSC | mcp-cspm · mqtt-bridge | NIS2 Regulations · 13 CNI sectors · posture monitoring |
| P5 | Ransomware resilience & incident response | NCSC / NCA | bft-council-probe · gdelt-news-mcp | Ransomware strategy · BFT-governed incident evidence |
| P6 | Supply chain security & third-party risk | NCSC / Cabinet Office | companies-house-mcp · bft-council-probe | Supply chain guidance · supplier audit · BFT evidence |
| P7 | Zero-trust architecture & cloud security | NCSC / CDDO | mcp-cspm · sovereign-keystore | NCSC zero-trust principles · cloud security · key rotation |
| P8 | AI cyber security (defensive AI / AI Code of Practice) | DSIT / NCSC | bft-council-probe · mcp-cspm | AI Cyber Code of Practice 2024 · BFT governance · posture |
| # | MCP server | Category | Description |
|---|---|---|---|
| 1 | mcp-cspm | Cloud Security Posture Management | Continuous cloud posture monitoring · CAF alignment · NIS2 compliance · zero-trust verification · multi-cloud CSPM |
| 2 | bft-council-probe | BFT Governance | 33-agent BFT evidence chain for incident response · CAF compliance · ransomware forensics · audit trails |
| 3 | sovereign-keystore | Key Management | Ed25519 key rotation · HSM-backed key custody · PKI management · zero-trust identity keys |
| 4 | gdelt-news-mcp | Threat Intelligence / OSINT | Real-time cyber threat intel · vulnerability tracking · CISA KEV · dark web monitoring · actor tracking |
| 5 | mqtt-bridge | Security Telemetry / IoT | SIEM telemetry bridge · network sensor feeds · honeypot data · IoT device security monitoring |
| 6 | companies-house-mcp | Supply Chain Due Diligence | Supplier financial standing · beneficial ownership · sanctions screening · cyber supplier vetting |
The UK cyber security digital backbone spans the NCSC Active Cyber Defence platform (Protective DNS, Mail Check, Web Check, Host Based Capability), the CPNI CNI protection framework, the NIS2 Competent Authority network (regulators per CNI sector), the CISP threat-sharing platform (12,000+ members), the GCHQincident response capability, the NCA NCCU cybercrime intelligence system, the HMGCC secure communications engineering centre, and the 20+ Academic Centres of Excellence in Cyber Security Research. The 2025 Government Cyber Security Strategy mandates "defend as one" — all government departments meeting NCSC CAF by 2030. DEFONEOS integrates via BFT-governed incident evidence, CSPM cloud posture monitoring, sovereign key management, and supply chain provenance. All evidence is curl-verifiable at the protocol layer.
| Step | Action | Owner | Time | Evidence |
|---|---|---|---|---|
| 1 | Buyer identifies cyber security / CNI protection / incident response requirement | Buyer | — | Requirement document |
| 2 | CSOAI sends DEFONEOS cyber security operations pack + 30-day pilot pricing (T1 £2,840 / T2 £9,150 / T3 £28,400) | CSOAI | 1 hour | This page (curl-verifiable) |
| 3 | Buyer reviews BFT governance evidence + SBOM + NCSC/CPNI/DSIT alignment | Buyer | 2-4 hours | curl -s /health + cyber pack |
| 4 | Submit procurement request (G-Cloud 14 / DSP bid / NCSC framework) | Buyer | 1-2 hours | DSP tracker |
| 5 | CSOAI provisions cyber-operations sovereign VM + DEFONEOS substrate | CSOAI | <24 hours | AG-1: curl -s /health HTTP 200 |
⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No classified data. No offensive cyber operations (exploit development, attack infrastructure, C2 for offensive purposes). No mass surveillance of UK citizens. No personal-surveillance patterns. Cyber AI supports defensive monitoring, incident evidence aggregation, CAF compliance auditing, supply chain vetting, and ransomware resilience — never offensive operations, individual tracking, or bulk interception. All incident evidence is BFT-governed with 23/33 quorum and independently verifiable. DEFONEOS is strictly defensive and compliance-oriented.
| Buyer type | Entry point | Procurement vehicle | Security requirement | Pilot tier |
|---|---|---|---|---|
| NCSC / GCHQ | E1 / E4 | G-Cloud 14 / DSP / direct framework | OFFICIAL-SENSITIVE | T3 |
| CPNI / CNI operator | E2 | G-Cloud 14 / direct framework | OFFICIAL-SENSITIVE | T2/T3 |
| DSIT / Policy | E3 | G-Cloud 14 / DSP | OFFICIAL | T2 |
| NCA / Law enforcement | E7 | Home Office framework | OFFICIAL-SENSITIVE | T2/T3 |
| Sector regulator / Competent Authority | NIS2 CAs | G-Cloud 14 / DSP | OFFICIAL | T1/T2 |
| Academic / Research | E9 | UKRI / direct | OFFICIAL | T1 |