

Silverthorn Associates, led by Mark Brett, delivers comprehensive cyber resilience auditing aligned with the NCSC's Cyber Resilience Audit scheme. As an NCSC Assured Service Provider, we transform cyber audits from compliance exercises into valuable tools for strengthening your organisation's security posture.
Led by Mark Brett, whose research focuses on principles-led information assurance rather than policy-driven compliance, creating a holistic approach to cyber resilience.
Fully aligned with the NCSC Cyber Resilience Audit scheme, providing consumers with confidence in our independent cyber audit capabilities.
Extensive experience across public sector organisations including central, devolved and regional government, Local Authorities, Health and Fire & Rescue.
We begin by thoroughly assessing your current cyber security landscape, infrastructure, and governance frameworks to establish a clear baseline.
Using the Cyber Assessment Framework (CAF) or other applicable standards, we perform rigorous evaluations of your systems, processes, and policies.
Our audit reports provide clear, prioritised recommendations focused on genuine improvement rather than mere compliance checkboxes.
Silverthorn Associates meets the stringent NCSC standards for delivering independent cyber audits, demonstrating our technical competence and organisational commitment.
While initially based on the Cyber Assessment Framework (CAF), our audits can be adapted to evaluate compliance against any recognised Cyber Security Standard.
We understand the requirements of Cyber Oversight Bodies and ensure all relevant Scheme Partner standards are comprehensively addressed in our audit approach.
Grounded in Mark Brett's academic research in Cyber Security Policy & Governance
Developer of the LACES (Local Authority Cyber Eco-System) framework
Active leadership in Cyber Security Community WARP groups and CTAG
Our approach to cyber resilience auditing is continuously refined through academic research, practical framework development, and active involvement in professional cyber security communities.
Comprehensive assessment against relevant frameworks and standards
Deep analysis of vulnerabilities and resilience gaps
Prioritised, actionable improvement strategies
Guidance on implementing continuous security enhancement
Tailored audit approaches addressing the unique security considerations of government bodies at all levels, from national departments to regional authorities.
Specialist expertise in local government cyber challenges, supported by Mark Brett's development of the LACES framework specifically for the local authority context.
Comprehensive understanding of the critical security requirements for health sector organisations, including patient data protection and clinical system resilience.
Specialised knowledge of emergency services' cyber requirements, ensuring resilient communications and operational systems during critical incidents.
As an NCSC Assured Service Provider, we combine official recognition with Mark Brett's extensive experience across public sector organisations. Our approach moves beyond compliance checklists to delivering meaningful security improvements based on research-informed principles.
Our audit methodology is fully aligned with the NCSC's Cyber Resilience Audit scheme, initially based on the Cyber Assessment Framework (CAF) but adaptable to any recognised Cyber Security Standard. This ensures our clients meet all Scheme Partner requirements.
Beyond compliance certification, you'll receive actionable insights prioritised by impact, a clear roadmap for security improvements, and the confidence that comes from a thorough, principles-led assessment of your cyber resilience posture.
Get in touch: contact@silverthorn.info