Having been closely involved in our Police-Assured Secure Facilities (PASF) re-audit, I was keen to see the feedback we received In March 2026. Of everything in the report, one comment mattered more to me than the rest:
“A pleasing proactive security culture was evident across the business and employees.”
It’s easy to think about security in terms of technology: the systems you invest in, the certifications you achieve, and the policies you put in place.
Those things are important, of course. But the PASF process reminded me that, in the end, security is really about people and how teams embrace the measures we put in place.
Why it matters:
For policing organisations, PASF gives confidence that Data is stored and processed in trusted, secure environments, Third‑party suppliers meet policing security expectations and Risks around data loss, compromise, or unauthorised access.
What PASF actually assesses
Police Assured Secure Facilities (PASF) certification provides UK police forces with assurance that suppliers handling Official-Sensitive information have been independently assessed against policing-specific security requirements.
Importantly, it’s not something you complete by just filling in a questionnaire.
Datagraphic has held approved PASF status since 2022; we’re familiar with the level of scrutiny involved in the process. Our Auditor visits our site, reviews documentation, looks at physical security, and assesses technical controls. They ask questions because they want to understand what really happens day to day, not just what policies say should happen.
That means the assessment looks at a broad range of safeguards.
In our case, this includes a physical inspection of the facility itself, including the measures in place to deter, detect, and delay unauthorised access to protect people, information, and critical assets. Auditors review the procedural and environmental controls supporting our day-to-day operations, including data handling processes, backup arrangements, encryption practices, high-availability measures, and intrusion-detection and prevention capabilities.
Documentation also plays an important role
Our Information Security Management System’s policies and procedures are reviewed against national policing information risk management expectations, alongside evidence of the wider safeguards and certifications that support good practice.
From a people perspective, the auditor interviews formally appointed representatives and managers to explore how policies translate into practice.
Finally, our cybersecurity controls are evaluated to determine whether they align with the digital safeguards expected to preserve the confidentiality, integrity, and availability of shared police information as it is stored, processed, accessed, and transmitted.
Altogether, the process provides a comprehensive picture of how we protect sensitive information.
And that’s where culture comes into the picture.
While auditors can verify that policies exist and technologies are in place, they also gain insight into how security is understood and applied across the organisation.
Are processes followed consistently? Do people know why controls exist? If something doesn’t look right, would someone challenge it?
These are the sorts of questions that reveal whether security has become part of an organisation’s culture.
In short, PASF exists to provide assurance that a facility is secure enough to safely host and handle sensitive police information.
Why people matter in information security
You can invest in the latest security tools, but they only work if people use them correctly.
Security works best when it becomes part of everyone’s daily thinking rather than something that sits solely with an IT or information security team.
It happens when leaders make it a priority, when training is taken seriously, and when everyone across the organisation understands that safeguarding information is also their responsibility.
What the March PASF 2026 feedback told us
The PASF program is administered by the Police Digital Service (PDS), whose objective is to help ensure secure cloud computing facilities for UK law enforcement workloads. The purpose of PASF is to ensure that facilities handling police data meet strict security standards, particularly for sensitive or “Official‑Sensitive” information. The report pointed out several areas that demonstrate how strong information security is across Datagraphic.
It recognised our Continuous Security Testing programme, our expanded SIEM and EDR capabilities, tested incident response plans, high-availability networks and processing facilities, and our ongoing investment in business continuity and operational resilience.
But it was this comment that stayed with me:
“A pleasing proactive security culture was evident across the business and employees, something reinforced through mandatory security training and continuous staff engagement.” David Lisk, Force Information Risk Assurer Joint ICT HIOWC and Thames Valley Police
Culture isn’t something you can create just before an inspection. If it’s not already there, auditors will notice right away.
The behaviours the auditor saw were the result of people consistently doing the right things, asking questions, following set processes, and understanding why those processes matter.
The wider report also highlighted our focus on cyber resilience, including tested incident response plans, controlled endpoints, proactive threat hunting, formal change control processes, and the development of playbooks to support consistent responses to cyber threats.
These aren’t things we do for audits. They’re part of our ongoing commitment to strengthening our security and improving the way we work.