Scotland’s new Cyber Resilient Scotland Action Plan, published on 24 February, turns a five-year strategic framework into a more concrete programme of work. For Scottish technology companies, it signals demand for cyber expertise across public services. It also raises the standard expected of every supplier that handles public data or supports an essential service.
The plan covers 2025 to 2030 and brings together government, the wider public sector, business, the third sector, education and individuals. Within public services, its direction is particularly practical: understand legacy risk, use secure-by-design and secure-by-default systems, strengthen incident readiness, improve supply-chain assurance and build professional capability.
This is not a niche agenda for security vendors. Cyber resilience now sits inside the definition of a good public service.
From annual assessment to targeted action
From 2026, Scottish public-sector organisations are expected to complete an annual Cyber Resilience Assessment through the Cyber Observatory. The intention is to build a clearer picture of maturity and risk, then use that evidence to target support.
That should help move the market away from generic claims of being “cyber secure”. Public bodies will need to understand their critical services, dependencies, controls and recovery capability. Suppliers that can help organisations measure risk, prioritise improvements and demonstrate progress will have a stronger proposition than those selling tools without context.
There are opportunities in asset discovery, risk and assurance platforms, security architecture, testing and reporting. Smaller firms may be especially valuable where they can turn complex guidance into proportionate action for councils, health bodies, colleges and third-sector providers with limited in-house capacity.
Legacy technology is an operational problem
The action plan requires public organisations to review their use of legacy systems, mitigate vulnerabilities in the short term and move towards secure-by-design alternatives over the longer term. This is one of the clearest commercial signals in the document.
Replacing an old system is rarely only a technical exercise. Data must be understood and migrated, integrations protected, services kept running and frontline staff supported through change. That creates work for Scottish companies in discovery, architecture, data engineering, identity, integration, migration and service redesign, as well as cyber security itself.
The strongest offers will recognise that immediate replacement is not always possible. Public bodies also need practical measures that reduce exposure while a transition is planned: better access control, network segmentation, monitoring, tested backups and clear ownership of risk.
Incident readiness has to be exercised
The plan asks public organisations to maintain incident-response plans, use secure logging, keep reliable backups and test their response at least annually against common attack scenarios.
For suppliers, this opens a market for exercises, managed detection, recovery testing, crisis communications and board-level simulations. It also changes what good service support looks like. Buyers will want to know how quickly a provider can detect and contain an incident, where responsibilities sit, how evidence will be preserved and how essential functions will be restored.
A certificate or policy document cannot answer all of those questions. Suppliers should be ready to show operational evidence: recent exercise results, recovery objectives, dependency maps, escalation routes and lessons that have been acted upon.
Supply-chain assurance reaches every GovTech company
Public services depend on software vendors, cloud platforms, support partners and specialist subcontractors. The action plan therefore calls for cyber assurance to be built into procurement and contract management.
For cyber businesses, that creates opportunities in third-party risk, continuous assurance and secure procurement. For the wider GovTech community, it creates an obligation. A supplier may be asked about its own controls, the services it depends on, vulnerability management, data locations, incident notification and what happens when the contract ends.
Small firms should not treat this as a reason to stay away from government work. They should treat it as product preparation. Clear answers, proportionate controls and transparent dependencies can become a competitive advantage. Cyber Essentials or Cyber Essentials Plus may form part of an assurance approach, but buyers will still need confidence in the risks specific to the service.
Design for resilience, not only prevention
No organisation can promise that an incident will never happen. Resilience means reducing the likelihood of disruption, limiting its impact and recovering well.
That principle should influence GovTech design from the beginning. Services should minimise unnecessary data, use strong identity and access controls, support meaningful logging and avoid single points of failure. Teams should know how to operate safely when a digital component is unavailable. Users should receive clear information during disruption, with alternative routes protected for people who cannot use digital channels.
This combination of security, continuity and inclusion is an area in which Scottish firms can build valuable intellectual property and exportable services. Governments everywhere are wrestling with legacy estates, constrained skills and complex supply chains.
A market signal with responsibilities attached
Scotland’s action plan creates a visible pipeline of need: assessment, legacy risk, incident exercises, supply-chain assurance, workforce development and secure service modernisation. Companies should map their capabilities to those outcomes, build evidence and engage through established public-sector routes.
But the bigger message is cultural. Cyber resilience is becoming part of how public value is judged. Scottish GovTech suppliers that make it integral to design and delivery will be better placed to win trust at home and compete abroad.
Want to strengthen your GovTech or cyber proposition for the public sector? Connect with the Scottish GovTech Cluster.