ResourcesCase studiesHow DSIT secured thousands of public sector organisations in the UK governments attack surface with Detectify

Customer story: GOV UK - DSIT

How DSIT secured thousands of public sector organisations in the UK governments attack surface with Detectify

The UK government runs thousands of public bodies, each with its own digital estate. That's tens of thousands of internet-facing domains, most of them outside any single team's line of sight. With a mission to provide secure, reliable services to millions of citizens, DSIT required a solution that could provide 24/7 visibility into its external attack surface and automate the discovery of exploitable vulnerabilities. That’s where Detectify comes in. 

Visibility with thousands of organisations

The UK public sector faces a dual challenge: a large, decentralised attack surface between thousands of organisations and an escalating threat landscape.

  • Estate Complexity: over a few thousand public organisations and tens of thousands of subdomains, many running on legacy technology. Organisations such as the NHS (National Health Service) and the Legal Aid Agency.
  • Shadow IT: new services are frequently spun up, often bypassing central security oversight.
  • Manual Bottlenecks: traditional point-in-time penetration testing could not keep pace with the speed of digital transformation or the frequency of new 0-day exploits, and with AI, this has also sped up.

Detectify’s outside-in hacker automation

To address these challenges, the government integrated Detectify’s Surface Monitoring and DAST into its newly launched Vulnerability Monitoring Service (VMS).

  • Continuous Asset Discovery: Detectify maps the government's entire attack surface, identifying forgotten subdomains as well as shadow IT and shadow AI before attackers can.
  • Alfred AI and Ethical Hacker Insights: by utilising a scanner powered by a global community of elite ethical hackers, DSIT receives high-fidelity alerts on vulnerabilities that are actually exploitable, reducing noise for security teams and helping to reduce triage time.
  • Seamless Integration: findings feed directly into the VMS dashboard, allowing DSIT to coordinate remediation across various departments and local councils through a centralised view.

A more resilient security posture with a significant reduction in fix times

Since implementing the automated scanning powered by Detectify, the UK government has seen a transformative shift in its security posture:

Domain-related (DNS) vulnerabilities
Before Detectify
Extended remediation times with weaknesses going unnoticed
After Detectify
Reduced time required to fix critical weaknesses
Critical vulnerability backlog
Before Detectify
Large accumulation of unaddressed risks
After Detectify
Significantly reduces and clears the backlog
Other cyber vulnerabilities
Before Detectify
Slower resolution across public sector systems
After Detectify
Reduced fix times across other vulnerability categories
Operational efficiency
Before Detectify
Manual testing bottlenecks unable to keep pace
After Detectify
Automated the resolution of confirmed vulnerabilities
Monitoring & visibility
Before Detectify
Limited line of sight and decentralised oversight
After Detectify
Provided continuous automated scanning and centralised visibility
"Detectify has transformed how quickly we can spot and fix weaknesses before they’re exploited. By automating our defences, we are reducing the risk to the essential services millions of people rely on every day."— Senior Technical Adviser

By partnering with Detectify, DSIT has moved from a reactive security model to a proactive, automated stance. This collaboration ensures that as the UK government continues to innovate, its attack surface remains resilient against the modern threat landscape, protecting both national security and citizen data.

If you’d like to learn more about the work between DSIT and Detectify, take a read below.

Know what's exposed. Fix what matters.

Start scanning to find exploitable vulnerabilities across your entire attack surface.