Site navigation

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Graham Turner

,

Police Scotland cyber centre
The plans emerge against a backdrop of existing cyber support provision in Scotland and a wider UK network of police-backed Cyber Resilience Centres operating across England and Wales.

Plans for a new Police Scotland-led cyber resilience centre have raised questions over service duplication, with the head of the Cyber and Fraud Centre Scotland saying the organisation was taken by surprise by the proposal.

Minutes from a meeting of the Scottish Government’s National Cyber Resilience Advisory Board (NCRAB) in June reveal that Police Scotland is exploring the establishment of a “police-led, not for profit Cyber Resilience Centre for Scotland”.

According to the minutes, the proposed centre would focus on “prevention, early intervention and accessible support”, particularly for Scotland’s SMEs.

However, Scotland already has an established organisation operating across many of these areas.

The Cyber and Fraud Centre – Scotland is a social enterprise providing cyber resilience services, incident response, training and fraud support to organisations and individuals across the country.

Police Scotland itself currently directs organisations affected by cybercrime to the Centre for assistance on getting operational again following a cyberattack.

In a statement, Jude McCorry, CEO of the Cyber and Fraud Centre – Scotland, said that the organisation had not been consulted about the proposal and had been unable to obtain further information about the plans.

“We at the Cyber and Fraud Centre – Scotland, along with others across the sector, were surprised to learn, through various sources following the publication of the Scottish Government National Cyber Resilience Board minutes from June 2026, of potential plans by Police Scotland to establish a ‘not-for-profit’ cyber resilience centre for SMEs in Scotland,” McCorry said.

“I have sought further information from both Police Scotland and the Scottish Government regarding the proposed centre as mentioned in the minutes, which, based on the description contained in the minutes, appears to duplicate many of the functions already delivered by the Cyber and Fraud Centre Scotland as a social enterprise.

“To date, I have received no information.”

Questions Over Existing Provision

The NCRAB minutes provide little detail about the proposed organisation beyond its intended focus.

Detective Chief Superintendent Andy Patrick provided the update to the board and agreed to share a Scottish Cyber Resilience Centre concept paper with the Scottish Government’s National Cyber Resilience Unit for circulation among members.

The minutes describe the centre as a “potential” development.

They also record NCRAB chair Maggie Titmuss offering the board’s support and agreeing to arrange a subsequent meeting with Patrick. At the beginning of the meeting, the minutes state that no conflicts of interest were noted.

The proposal comes despite the Cyber and Fraud Centre Scotland already delivering a range of services designed to improve cyber resilience among SMEs, charities and other organisations.

According to figures published by the Centre earlier this year, it reinvested more than £3 million into cyber resilience, community support and cyber skills initiatives during its first year operating under a social enterprise model.

This included more than £1.4m worth of free cyber training, over £500,000 of incident recovery support and more than £45,000 worth of free Cyber MOTs. The Centre said more than 50 SMEs had also received assistance through its free cyber incident response helpline.

McCorry said the existing model demonstrated that nationwide support could already be delivered without establishing a new organisation.

“The Cyber and Fraud Centre – Scotland has demonstrated that a sustainable, independent and impactful model already exists,” she said.

“Before public money, police resources or government support are directed towards creating a new organisation, there must be a clear explanation of why existing capability is being overlooked.

“Businesses, communities and taxpayers deserve transparency on what is being proposed, what gap it is intended to fill, and why that investment would be better directed towards a new entity rather than strengthening a Social Enterprise organisation that is already employing people, delivering results and supporting organisations across Scotland.”

There is also a wider UK context to the proposal.

Nine regional Cyber Resilience Centres currently operate across England and Wales through the National Cyber Resilience Centre Group (NCRCG), providing cyber security support to SMEs through a model combining policing, academia and private-sector partners.

That model itself has Scottish roots.

Dr Mandy Haeburn-Little, founder of consultancy BRIM and a senior figure within NCRCG, previously spent nine years as CEO of the Scottish Business Resilience Centre, the organisation that later became the Cyber and Fraud Centre – Scotland.

Haeburn-Little has previously said interest from policing and the Mayor of London’s office in the Scottish model ultimately led to the development of an “evolved” cyber resilience centre model. BRIM subsequently won a Home Office tender to begin rolling out what became the network of centres across England and Wales.

More recently, NCRCG noted that representatives met with Police Scotland and the Scottish Government Cyber Team at CyberUK in Glasgow earlier this year.

NCRCG said the discussions examined the CRC model and its ability to support SMEs, improve supply chain cyber resilience and support policing activity.

The meeting took place before the proposed Scottish centre appeared in the June NCRAB minutes.

No public information seen by DIGIT establishes whether NCRCG or BRIM has any formal involvement in the proposed Scottish centre.

However, Titmuss, who chairs NCRAB, is also listed as an Associate Partner at BRIM.


Recommended reading


The June minutes do not indicate that her association with BRIM was discussed when the proposed centre was raised, stating only that no conflicts of interest were noted at the meeting.

It is currently unclear what specific gap Police Scotland believes the new organisation would address, how it would differ from services already available through the Cyber and Fraud Centre Scotland, whether public funding would be required, or whether the proposed organisation would become part of the existing NCRCG network.

The Scottish Government did not provide further detail on the proposal, saying that the plans referenced in the June NCRAB minutes were “an operational matter for Police Scotland”.

McCorry also questioned the rationale for establishing a new organisation amid wider pressure on Scotland’s public finances and efforts to streamline public services.

“It is particularly surprising to hear of proposals for a new organisation at a time when the Scottish Government has stated, through the recent Programme for Government, its intention to reduce the number of public bodies and agencies,” she said.

“It is even more surprising that Police Scotland appears able to commit resource to exploring a new centre despite wider funding pressures, when the Cyber and Fraud Centre Scotland already provides these services across the country without receiving funding from either the Scottish Government or Police Scotland, but has supported and worked with both organisations over the years.”

For now, the proposal remains at the concept stage according to the most recently published NCRAB minutes.

DIGIT approached Police Scotland, the Scottish Government, the National Cyber Resilience Centre Group and BRIM for comment and clarification. The Scottish Government said the proposal was an operational matter for Police Scotland. No responses had been received from the other organisations at the time of publication.

Graham Turner

Sub Editor

Latest News

Cybersecurity Featured Security

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Cybersecurity Editor's Picks Events

Microsoft, NBCUniversal and Admiral Group Experts Set for CymruSec 2026

AI Business Editor's Picks

Salesforce Agentforce Bugs Exposed Wider AI Agent Risk, Research Finds

AI Cybersecurity

Despite AI Hype, Traditional Identity Fraud Prevails