CYBER SECURITY OPERATIONS PACK

11 UK cyber entry points · 8 security priorities · 6 DEFONEOS MCPs · NCSC / CPNI / DSIT Cyber backbone

11Cyber entry points
8Security priorities
6Cyber MCPs
CAFNCSC framework
£9,150T2 Cyber 30-day pilot

1. WHY CYBER SECURITY OPERATIONS GETS A DEDICATED DEFONEOS PACK

UK cyber security operations are governed by the National Cyber Security Strategy 2022-2030, the Network and Information Systems (NIS2) Regulations 2024, the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, the NCSC Cyber Assessment Framework (CAF) v3.2, and the 2025 Government Cyber Security Strategy. The National Cyber Security Centre (NCSC), CPNI (Centre for Protection of National Infrastructure), DSIT Cyber Division, and GCHQ deliver Active Cyber Defence, CNI protection, incident response, and cyber skills development. The 2025 ransomware strategy and the AI Cyber Security Code of Practice (2024) mandate BFT-governed incident evidence, SBOM provenance, and sovereign cyber posture monitoring. DEFONEOS delivers the UK's first open-source Sovereign Public Services OS purpose-built for cyber operations — BFT-governed incident evidence chains, CSPM cloud posture monitoring, sovereign key management, and independently verifiable security provenance.

All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from NCSC + CPNI + DSIT Cyber + GCHQ + HMGCC + Academic Centres of Excellence (2026-Q1).

2. THE 11 UK CYBER ENTRY POINTS × CONTACT × DEFONEOS FIT

#Entry pointLocationFunctionDEFONEOS fit
E1National Cyber Security Centre (NCSC)London / CheltenhamNational cyber authority · guidance · incident responseDEFONEOS MCPs: mcp-cspm · bft-council-probe — cloud posture + BFT governance
E2CPNI (Centre for Protection of National Infrastructure)LondonCNI physical & personnel securityDEFONEOS MCPs: mcp-cspm · sovereign-keystore — posture + key mgmt
E3DSIT — Cyber Security DivisionLondonCyber policy · Product Security · PSTI enforcementDEFONEOS MCPs: data-gov-uk-mcp · bft-council-probe — policy data + BFT
E4GCHQ — Industry EngagementCheltenhamSIGINT · cyber intelligence · SME outreachDEFONEOS MCPs: gdelt-news-mcp · bft-council-probe — threat intel + BFT
E5HMGCC (Her Majesty's Government Communications Centre)Milton KeynesSecure comms · bespoke security engineeringDEFONEOS MCPs: sovereign-keystore · mcp-cspm — secure comms + posture
E6Joint Forces Cyber Group (JFCyG)Cheltenham / CorshamMilitary cyber operations · defensive cyberDEFONEOS MCPs: mcp-cspm · bft-council-probe — defensive cyber + BFT
E7National Crime Agency — National Cyber Crime Unit (NCA NCCU)LondonCybercrime investigation · takedownsDEFONEOS MCPs: bft-council-probe · gdelt-news-mcp — investigation evidence + OSINT
E8Cyber Growth Action Partnership (CGAP)LondonCyber sector growth · £8.9bn industryDEFONEOS MCPs: companies-house-mcp · data-gov-uk-mcp — sector data
E9Academic Centres of Excellence in Cyber Security Research (ACE-CSR)20+ UK universitiesCyber research · EPSRC · innovationDEFONEOS MCPs: data-gov-uk-mcp · gdelt-news-mcp — research + publication tracking
E10UK Cyber Security CouncilLondonProfessional standards · chartered cyber professionalDEFONEOS MCPs: bft-council-probe — professional governance + BFT
E11CISP (Cyber Security Information Sharing Partnership)NCSC-hosted / NationwideThreat intel sharing · public-private · 12,000+ membersDEFONEOS MCPs: gdelt-news-mcp · bft-council-probe — threat intel + BFT governance

3. THE 8 CYBER SECURITY PRIORITIES × DEFONEOS MCP COVERAGE

#PriorityOwning bodyDEFONEOS MCP coverageAlignment cross-walk
P1NCSC Cyber Assessment Framework (CAF) complianceNCSC / Regulatorsmcp-cspm · bft-council-probeCAF v3.2 · 14 principles · 39 outcomes · BFT-governed evidence
P2Active Cyber Defence (ACD) integrationNCSCmqtt-bridge · mcp-cspmACD services · Protective DNS · takedown · mail check
P3Software Bill of Materials (SBOM) provenanceDSIT / NCSCbft-council-probe · sovereign-keystoreSBOM mandate · NTIA minimum · supply chain · BFT evidence
P4Critical National Infrastructure (CNI) protectionCPNI / NCSCmcp-cspm · mqtt-bridgeNIS2 Regulations · 13 CNI sectors · posture monitoring
P5Ransomware resilience & incident responseNCSC / NCAbft-council-probe · gdelt-news-mcpRansomware strategy · BFT-governed incident evidence
P6Supply chain security & third-party riskNCSC / Cabinet Officecompanies-house-mcp · bft-council-probeSupply chain guidance · supplier audit · BFT evidence
P7Zero-trust architecture & cloud securityNCSC / CDDOmcp-cspm · sovereign-keystoreNCSC zero-trust principles · cloud security · key rotation
P8AI cyber security (defensive AI / AI Code of Practice)DSIT / NCSCbft-council-probe · mcp-cspmAI Cyber Code of Practice 2024 · BFT governance · posture

4. 6 DEFONEOS CYBER SECURITY MCPs

#MCP serverCategoryDescription
1mcp-cspmCloud Security Posture ManagementContinuous cloud posture monitoring · CAF alignment · NIS2 compliance · zero-trust verification · multi-cloud CSPM
2bft-council-probeBFT Governance33-agent BFT evidence chain for incident response · CAF compliance · ransomware forensics · audit trails
3sovereign-keystoreKey ManagementEd25519 key rotation · HSM-backed key custody · PKI management · zero-trust identity keys
4gdelt-news-mcpThreat Intelligence / OSINTReal-time cyber threat intel · vulnerability tracking · CISA KEV · dark web monitoring · actor tracking
5mqtt-bridgeSecurity Telemetry / IoTSIEM telemetry bridge · network sensor feeds · honeypot data · IoT device security monitoring
6companies-house-mcpSupply Chain Due DiligenceSupplier financial standing · beneficial ownership · sanctions screening · cyber supplier vetting

5. CYBER SECURITY DIGITAL BACKBONE

The UK cyber security digital backbone spans the NCSC Active Cyber Defence platform (Protective DNS, Mail Check, Web Check, Host Based Capability), the CPNI CNI protection framework, the NIS2 Competent Authority network (regulators per CNI sector), the CISP threat-sharing platform (12,000+ members), the GCHQincident response capability, the NCA NCCU cybercrime intelligence system, the HMGCC secure communications engineering centre, and the 20+ Academic Centres of Excellence in Cyber Security Research. The 2025 Government Cyber Security Strategy mandates "defend as one" — all government departments meeting NCSC CAF by 2030. DEFONEOS integrates via BFT-governed incident evidence, CSPM cloud posture monitoring, sovereign key management, and supply chain provenance. All evidence is curl-verifiable at the protocol layer.

6. 5-STEP ENGAGEMENT WORKFLOW

StepActionOwnerTimeEvidence
1Buyer identifies cyber security / CNI protection / incident response requirementBuyerRequirement document
2CSOAI sends DEFONEOS cyber security operations pack + 30-day pilot pricing (T1 £2,840 / T2 £9,150 / T3 £28,400)CSOAI1 hourThis page (curl-verifiable)
3Buyer reviews BFT governance evidence + SBOM + NCSC/CPNI/DSIT alignmentBuyer2-4 hourscurl -s /health + cyber pack
4Submit procurement request (G-Cloud 14 / DSP bid / NCSC framework)Buyer1-2 hoursDSP tracker
5CSOAI provisions cyber-operations sovereign VM + DEFONEOS substrateCSOAI<24 hoursAG-1: curl -s /health HTTP 200

7. RED-LINE: NO OFFENSIVE CYBER OPERATIONS, NO MASS SURVEILLANCE

⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No classified data. No offensive cyber operations (exploit development, attack infrastructure, C2 for offensive purposes). No mass surveillance of UK citizens. No personal-surveillance patterns. Cyber AI supports defensive monitoring, incident evidence aggregation, CAF compliance auditing, supply chain vetting, and ransomware resilience — never offensive operations, individual tracking, or bulk interception. All incident evidence is BFT-governed with 23/33 quorum and independently verifiable. DEFONEOS is strictly defensive and compliance-oriented.

8. CYBER SECURITY BUYER-TYPE MATRIX

Buyer typeEntry pointProcurement vehicleSecurity requirementPilot tier
NCSC / GCHQE1 / E4G-Cloud 14 / DSP / direct frameworkOFFICIAL-SENSITIVET3
CPNI / CNI operatorE2G-Cloud 14 / direct frameworkOFFICIAL-SENSITIVET2/T3
DSIT / PolicyE3G-Cloud 14 / DSPOFFICIALT2
NCA / Law enforcementE7Home Office frameworkOFFICIAL-SENSITIVET2/T3
Sector regulator / Competent AuthorityNIS2 CAsG-Cloud 14 / DSPOFFICIALT1/T2
Academic / ResearchE9UKRI / directOFFICIALT1