Skip to main content

The content below has been generated by an AI model. If anything is unclear, check the source document (opens in new tab) .

Item: 5

Asset Management Sub-committee: 1 September 2026

Information Technology and Cyber Security Strategy – Delivery Plan

Report by Director of Neighbourhood Services and Infrastructure.

IMAGE: The Orkney Islands Council crest and the words “ORKNEY ISLANDS COUNCIL”.

1. Overview

1.1.

This report presents the six-monthly update on progress with the Information Technology and Cyber Security Strategy Delivery Plan, for members’ scrutiny.

1.2.

The Information Technology and Cyber Security Strategy is a technical plan which underpins and supports delivery of the Digital Strategy and focusses on improving and sustaining the Council’s IT systems and infrastructure. The Digital Strategy sets the vision and objectives through which all services across the Council will harness digital developments to provide improved, more efficient services for the public.

1.3.

On 28 January 2025, the Asset Management Sub-committee recommended that the Information Technology and Cyber Security Strategy, for the period 2025 to 2029, be approved.

1.4.

The Strategy groups actions under the following headings:

  • Cyber Security
  • Governance
  • Customer Focus
  • Digital Workforce
  • Infrastructure and system
  • Internal and external communications

1.5.

The Strategy seeks to:

  • Continue to improve the Council’s underlying infrastructure.
  • Provide the foundations for the rapidly moving shift towards digital delivery and support the objectives of the Digital Strategy.
  • Provide a Delivery Plan to ensure its successful delivery.

1.6.

Attached as Appendix 1 to this report is the IT and Cyber Security Delivery Plan update for the period up to March 2025.

2. Recommendations

2.1.

It is recommended that members of the Sub-committee:

  1. Scrutinise the updated Delivery Plan, attached as Appendix 1 to this report, in order to obtain assurance with regard to progress being made in implementing the Information Technology and Cyber Security Strategy.

For Further Information please contact: Thomas Aldred, Services Manager (ICT), extension 2152, Email: thomas.aldred@orkney.gov.uk.

Implications of Report

  1. Financial – Any costs arising from works associated with the delivery plan will require to be funded from within existing revenue or capital budget allocations, with any request for additional funding required to come forward as a separate report for consideration.
  2. Legal – None directly related to the recommendations in this report.
  3. Corporate Governance – None directly related to the recommendations in this report.
  4. Human Resources – None directly related to the recommendations in this report.
  5. Equalities – An Equality Impact Assessment is not required in respect of performance monitoring.
  6. Island Communities Impact – An Island Communities Impact Assessment is not required in respect of performance monitoring.
  7. Links to Council Plan: The proposals in this report support and contribute to improved outcomes for communities as outlined in the following Council Plan strategic priorities:
    • ☐ Growing our economy.
    • ☐ Strengthening our communities.
    • ☒ Developing our Infrastructure.
    • ☒ Transforming our Council.
  8. Links to Local Outcomes Improvement Plan: The proposals in this report support and contribute to improved outcomes for communities as outlined in the following Local Outcomes Improvement Plan priorities:
    • ☒ Cost of Living.
    • ☐ Sustainable Development.
    • ☒ Local Equality.
    • ☐ Improving Population Health.
  9. Environmental and Climate Risk – There are no environmental risks associated with this report.
  10. Risk – Not Applicable.
  11. Procurement – Not Applicable.
  12. Health and Safety – Not applicable.
  13. Property and Assets – Not applicable.
  14. Information Technology – Not applicable.
  15. Cost of Living – Not applicable.

List of Background Papers

  • Information Technology and Cybersecurity Strategy - Asset Management Sub-committee: 28 January 2025.

Appendix

  • Appendix 1 - IT and Cyber Security Delivery Plan update September 2026.

Appendix 1 - IT and Cyber Security Strategy Delivery Plan Update September 2026

1. Purpose

This Delivery Plan update provides information on the progress made in delivering each of the objectives of the IT and Cyber Security Strategy Delivery Plan 2025-2029.

2. Introduction

2.1.

The IT and Cyber Security Strategy Delivery Plan update is a technical plan which underpins and supports the IT and Cyber Security Strategy and aims to improve and maintain the Council’s IT infrastructure and systems.

2.2.

The table below set out the detail of how the IT and Cyber Security Strategy is being delivered. The IT and Cyber Security Strategy has a number of strategic targets, grouped into 6 themes. Objectives have been abstracted from the strategic targets in the strategy, and the table in sub-section of section 3 below, corresponds to a group of actions (one per row) contributing to that objective.

2.3.

Each action is owned by a specific member of staff, who is accountable for the correct and thorough completion of the task, and each is led by a specific member of staff who is responsible to the owner for the planning, execution and implementation of each necessary piece of work.

2.4.

For each action, progress will be reported, and an indication is given of the next steps planned. Where appropriate, an indication is given about where to find more information about the project or workstream.

3. Actions to Support IT Strategy Objectives

3.1. Cyber Security Objectives

We will maintain a secure physical and virtual environment, with a high degree of resilience and confidence, based on national standards to present a difficult target for all forms of attack and exploitation online. To achieve this will involve detecting, understanding, investigating and disrupting hostile action against us.

Objective 3.1.1

We will implement suitable security controls to present a difficult target for all forms of attack and exploitation online.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.1.1.1.
Public Services Network (PSN) accreditation.
Head of Property and Asset ManagementInformation Security and Assurance OfficerGreenCurrent accreditation is in place until 30 April 2027.Complete for this year.
3.1.1.2.
Build and Maintain IT Network defences following recognised (NCSC) security protocols.
Information Security and Assurance OfficerService Manager (ICT)GreenNetwork design is based on National Cyber Security Centre (NCSC) guidelines and security protocols. A review of network design to ensure it meets guidelines has found that some IT systems, while in a secure design do not meet current best practice. A review to move systems into secure network design has been completed with new infrastructure requirements being detailed purchased and installed. Services are in the process of being migrated to new infrastructure.Continue to migrate to best practice 2026-2029 where resources permit.
3.1.1.3.
Undertake an annual ITHC using an independent specialist
Head of Property and Asset Management / Information Security and Assurance OfficerService Manager (ICT)GreenA health check is conducted annually in October by an external accredited cyber security specialist. Any issues identified are programmed into an Action Plan that is worked through by IT and stakeholder services. Weekly internal checks are performed by the Information Security and Assurance Officer.Continuous review of internal checks.
3.1.1.4.
Support Systems Security
Information Security and Assurance OfficerSystem OwnersAmberSystems security is supported using multi-factor authentication, where technically possible, and use of password protocols with high entropy. This means reliance on password length rather than complexity as per NCSC guidelines. Systems have been reviewed to ensure they can operate with increased password length as per NCSC guidelines.Work with System Owners to introduce Muti-factor authentication on an ongoing basis. Implement new password policy.
3.1.1.5.
Train and educate users to defend against cyber threats
Information Security and Assurance OfficerOD/ Communications /IT SupportGreenRegular notification of new threats by bulletin email and SharePoint distribution. iLearn courses.Continue to develop ways of enhancing user participation.

Objective 3.1.2

We will develop a coordinated and tailored approach to risks and threats that we may encounter and mitigation of potential vulnerabilities.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.1.2.1.
Develop and maintain Cyber risk management framework.
Head of Property and Asset ManagementInformation Security and Assurance OfficerGreenInternal controls and governance for the prevention and detection of irregularities and fraud are in place.Continue to review and adjust controls, due end 2026.
3.1.2.2.
Ensure that major cyber security risks are present on the corporate risk register.
Head of Property and Asset ManagementInformation Security and Assurance OfficerGreenCyber security is currently recorded as a risk on the Corporate Risk Register.Ensure the cyber security risk register is reviewed and updated regularly. Ongoing
3.1.2.3.
Implement processes, procedures and controls to manage changes.
Head of Property and Asset ManagementInformation Security and Assurance Officer /Service Manager (ICT) /System adminsGreenChange Advisory Board (CAB) is in place.Generate assurance that changes are presented to the CAB. Continue to review 2026, with implementation also 2026 onwards.
3.1.2.4.
Review Process for Change management.
Head of Property and Asset ManagementInformation Security and Assurance Officer /Service Manager (ICT) /System adminsGreenIt is important that all significant System changes are documented and agreed. It is known that some system administrators commit unrecorded changes.Work with system owners to ensure changes are recorded and agreed before changes are made. Ongoing.
3.1.2.5.
Manage IT Infrastructure vulnerabilities that may allow an attacker to gain access to critical systems.
Information Security and Assurance OfficerService Manager (ICT)GreenInternal network is scanned on a weekly basis to capture the threat level and vulnerability position. Remediation is in place to correct vulnerability position.Continue to enhance remediation actions and reporting. Ongoing
3.1.2.6.
Manage third party system vulnerabilities that may allow an attacker to gain access to critical systems.
Information Security and Assurance OfficerSystem OwnersGreenInternal systems are scanned on a weekly basis to capture the threat level and vulnerability position. Remediation is only partly in place to correct vulnerability position as is reliance on suppling vendor to provide security updates.Continue to work with System Owners, System Administrators and supplying vendors to enhance patching regime and to ensure only fully supported systems are procured. Ongoing
3.1.2.7.
Operate a Council network penetration testing programme.
Information Security and Assurance OfficerService Manager (ICT)AmberPenetration testing is completed yearly on all systems. However, due to ever increasing criminal cyber incidents, penetration testing should be increased to match the threat.Develop a more robust testing regime. Continuous review and improvement.
3.1.2.8.
Upgrade all end user devices to latest operating system.
Service Manager (ICT)Team Manager: ICT OperationsBlueIT have completed working through an upgrade cycle of moving End-Of-Life (EOL) Windows operating systems. Over 2600 devices have been upgraded to Windows 11 both corporately and in Schools.Complete

Objective 3.1.3

We will increase defences to mitigate cyber risks as far as possible.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.1.3.1.
Develop a new web proxy system to ensure devices are always secured.
Information Security and Assurance OfficerService Manager (ICT)BlueRemote working has brought a new threat where devices not on the Council network are not protected by a Web Proxy. A new Web Proxy system has been procured and installation on all client devices is complete. This new system offers improved protection and covers the use of devices used at home and in Schools. As an added protection this will also be used on Council mobile devices when used for web browsing. Total devices numbering in the region of 2900.Complete
3.1.3.2.
Purchase, set up and run a security information and event management (SIEM) solution.
Information Security and Assurance OfficerService Manager (ICT)BlueNew SIEM infrastructure is now in place and fully operational – IT staff have been trained in its use. SIEM is a standard component in cybersecurity which reviews logs across multiple systems automatically generating a clear overview for IT security management purposes.Complete

Objective 3.1.4

We will develop a culture of security by raising awareness of personnel to vulnerabilities, risks and threats from cyberspace and the need to protect information systems.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.1.4.1.
Identify and implement measures to develop a culture of security.
Head of Property and Asset ManagementInformation Security and Assurance Officer.GreenInformation Governance Group owns and maintains standards. Use of regular all staff bulletins and email alerts to educate and inform. Information Security Officer developed content for mandatory online training courses for all staff, now delivered through iLearn. Close co-operation between Information Security Officer and Information Governance Officer, within Information Governance Group and operationally.Ongoing work to ensure high levels of security awareness remain.

3.2. Governance Objectives

We will report on progress and make sure that decision makers have the information they need to make sound decisions.

Objective 3.2.1

Regular reporting to Council Asset Management Sub-committee on the delivery of Digital & ICT Strategy, ICT Asset Management Plan and ICT Capital Programme.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.2.1.1.
Establish regular Asset Management Sub-committee reporting.
Head of Property and Asset ManagementService Manager (ICT)GreenReports to Asset Management Sub-committee are being submitted at least twice a year, either as stand-alone reports or included in broader financial reports.Continue to submit reports.

Objective 3.2.2

The Corporate Leadership Team reviews ICT Performance, considers significant change requests, agrees the ICT Capital Programme and ensure strategic fit working with the Council’s Asset Management Strategy.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.2.2.1.
Significant changes are reported to Corporate Leadership Team (CLT).
Head of Property and Asset ManagementService Manager (ICT)GreenReports to CLT are submitted in the form of briefings.Continue to ensure significant changes are reported to CLT on an ongoing basis.
3.2.3.1.
Ensure IT Capital Programme is strategically aligned to the Council’s Asset Management Strategy.
Head of Property and Asset ManagementService Manager (ICT)/ Information Security and Assurance OfficerGreenIT Capital Replacement Programme is approved by Asset Management Sub-committee, following oversight by CLT.Ensure reports are completed.

Objective 3.2.3

Establish and operate effective ICT infrastructure and systems to support delivery of the outcomes in the Digital Strategy.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.2.3.1.
Ensure full cooperation between IT and the Improvement and Performance team.
Head of Property and Asset ManagementService Manager (ICT)/ Information Security and Assurance OfficerGreenIT and the Improvement and Performance managers share information and developments on a regular basis to ensure continued cooperation and ensure the Council’s ICT and Digital Strategies are in alignment.Continue to enhance cooperation and systems to the benefit of the Council to ensure the ICT and Cyber Security Strategy aligns with the Digital Strategy.

3.3. Infrastructure

We will invest in and maintain the Council’s ICT assets, both physical and data, to ensure they remain fit for purpose, and we will ensure they are resilient, secure and available, as well as improving services, while supporting innovation and change.

Objective 3.3.1

We will ensure that the ICT asset base is available, resilient and effective.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.1.1.
Embed processes for annual review of the ICT asset base.
Head of Property and Asset ManagementService Manager (ICT)GreenThe annual ICT Capital Replacement Programme supports this objective by ensuring timely replacement of priority core infrastructure. The ICT Capital Replacement Programme for 2026/27 was approved by Asset Management Sub-committee in March 2026. The delivery programme is on target.Deliver 2026/27 ICT Capital Replacement Programme by 31 March 2027.
3.3.1.2.
Upgrade of infrastructure.
Service Manager (ICT)Team Manager: ICT InfrastructureAmberThere was little resilience in the Council webserver infrastructure, and the network design did not align with the National Cyber Security Centre’s recommendations. Therefore, a design was updated, and new Infrastructure has been procured and has been installed. Webservers are in the process of being migrated to the new infrastructure.Implementation of new webserver infrastructure while ongoing has been delayed due to workload. Completion is due for December 2026.
3.3.1.3
Replace Analogue Phone systems and lines.
Service Manager (ICT)Team Manager: ICT OperationsGreenThe analogue switch-off has been delayed from December 2025 until January 2027. It should be noted that BT are still not in the position to provide digital lines to 3 of these sites, North Ronaldsay, Papa Westray and North Walls schools. IT have therefore successfully investigated using Internet circuits and installations are therefore able to continue. In addition, the new Kirkwall Care home (Kirkjuvagr House) has a new digital phone system installed.Continue to migrate phone systems/lines as they become available.

Objective 3.3.2

We will ensure resilience is considered as part of project definition.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.2.1.
When new systems are put in place resilience is considered.
Head of Property & Asset ManagementService Manager (ICT)GreenWhen new systems are being considered resilience of the system is taken as a key priority.Consider resilience for main Internet feeds and webserver infrastructure.

Objective 3.3.3

We will seek to provide protection via good Disaster Recovery capability to support business continuity.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.3.1.
Disaster recovery project.
Service Manager (ICT)Team Manager: ICT SystemsGreenA new data centre has been implemented at the Harbour Master’s building at Scapa and is operational. This synchronises IT systems between Kirkwall and Scapa.Continue to increase resilience via disaster recovery including investigation of additional Internet feed.
3.3.3.2.
Immutable backups
Service Manager (ICT)Team Manager: ICT InfrastructureGreenInstallation of an enhanced backup solution designed with measures to protect against ransomware cyberattacks is underway at both the main Council datacentre and the disaster recovery data centre at the Harbour Master’s building at Scapa. This adds an additional layer of protection to systems and data if an attack was orchestrated against the Council.Continue to ensure system is updated and appropriate for needs.
3.3.3.3
Backup of MS Teams and OneDrive Storage
Service Manager (ICT)Team Manager: ICT OperationsBlueDue to the increased file storage in the cloud now reaching 5TB it has become apparent a system is required to restore lost files above that of the standard MS recovery systems and improve resilience. A system has been purchased and installed.Complete. Continue to regularly confirm backup is working by regular test restores.

Objective 3.3.4

We will support the innovation opportunities provided by developing a foundation for Business Intelligence and Data Warehousing to be explored and leveraged.

Work towards this objective will be done under Customer Focus Objective 3.3.

Objective 3.3.5

We will continue to harden our local core infrastructure to provide an accessible, secure and stable ICT platform for existing and future system requirements.

Work towards this objective will be done under Cyber Security Objectives 3.1 and Infrastructure and Systems Objective 3.5.

Objective 3.3.6

We will ensure that our network fully enables access to electronic resources such as the Scottish Educational Digital Network (GLOW), which supports employees working in more flexible and mobile ways.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.6.1.
Upgrade network capacity for access to cloud systems.
Service Manager (ICT)Team Manager: ICT SystemsGreenNetwork capacity has been upgraded to meet increased demands for access to cloud-based systems. SWAN2 has been fully implemented increasing the bandwidth at School Place from 500Mbps to 1Gbps. Other sites have also been brought online notably Stromness Academy and Stromness Primary having also benefited from a new 1Gbps link. 21 sites have been transitioned to SWAN2 and have benefited from increased bandwidth.Continue to make use of new bandwidth opportunities as resources become available.
3.3.6.2.
Upgrade core networking infrastructure to ensure bandwidth capacity across network.
Service Manager (ICT)Team Manager: ICT SystemsGreenCore network infrastructure is currently within bandwidth requirements for Council services. However, a number of core infrastructure devices are nearing End-Of-Life (EOL) within the next 12 months. Orders for replacement equipment have been placed. This includes the Councils datacentres, which has been installed, and Kirkwall Grammar School.Install new core networking infrastructure at Kirkwall Grammar School over October break. Continue to procure new infrastructure and install before EOL. This is part of the continuous upgrade programme.
3.3.6.3.
Make use of R100 infrastructure to enhance rural Wide Area Network (WAN) connections.
Head of Property and Asset ManagementService Manager (ICT)GreenMake use of the Scottish Government R100 infrastructure as and when it becomes available to enhance rural Wide Area Network (WAN) connections where suitable. Investigations are underway to improve bandwidth using R100 infrastructure in Stromness.Continue to review and make use of connections as required.

Objective 3.3.7

We will develop co-operative connectivity with public sector and third sector bodies.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.7.1.
Implement SWAN2 services.
Service Manager (ICT)Team Manager: ICT OperationsBlueThe Scottish Wide Area Network (SWAN) used by many councils and public sector organisations delivers connectivity to the Council headquarters and other Council sites (mainly outside Kirkwall and Stromness). The national contract for SWAN has ended and the procurement process for a successor (SWAN2) has now completed, with transitions to new circuits having been completed by March 2026.Complete. Continue to review and make use of new circuits as resources allow.
3.3.7.2.
Implement joint systems with NHS Orkney.
Team Manager: ICT OperationsTeam Manager: ICT OperationsGreenThe Scottish Government Digital Office Microsoft 365 collaboration project has been set up to create a Digital Partnership between Orkney Islands Council and NHS Orkney to recognise the transformational potential of using M365 as a collaboration platform between the two organisations to provide concrete deliverables.Waiting for Scottish Government Digital Office Phase 2 collaboration project.

Objective 3.3.8

We will introduce and promote the use of cloud technologies to enhance our ICT offerings to customers and staff on an enhanced expanded local to cloud-based network infrastructure.

Future work towards this objective will be done as part of Governance Objective 3.2 and Objective 3.3.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.8.1.
Develop appropriate cloud technologies.
Service Manager (ICT)Team Manager: ICT OperationsGreenMicrosoft Azure Virtual Desktop in place as is MS Teams. When systems are nearing End Of Life cloud options are reviewed.Continue to develop new technology as it becomes available and work with OIC Services to assist in moving appropriate systems to the cloud for better efficiencies.

Objective 3.3.9

We will work with staff and partners in meeting their expectations and needs through identifying what systems and equipment are required, and we will improve efficiencies by identifying and removing redundant systems on our infrastructure.

Work towards this objective will be done as part of Governance Objectives (technology standards) and Customer Focus Objectives (account management), as well as within projects under the Digital Strategy Delivery Plan.

Objective 3.3.10

We will ensure our ICT infrastructure represents value for money and supports the Council’s business objectives, including the objectives in the Digital Strategy.

Work towards this objective will be done as part of Governance Objective 3.2 above.

Objective 3.3.11

We will improve our publicising of our forward schedule of change to keep staff and customers informed.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.3.11.1.
Establish a process for keeping colleagues informed.
Service Manager (ICT)Team Manager: ICT OperationsGreenAlerts via email and SharePoint portal are in place.Develop a robust process. This is a continuous process when new systems become available.
3.3.11.2.
Implement a change management system for core corporate, and other sensitive and major systems.
Information Security and Assurance OfficerSystem OwnersAmberIT are working closely with stakeholders to ensure major/sensitive systems are upgraded in a controlled manner using recognised change and project management methodologies. Although project management processes are improving at present some systems are upgraded without change management in place.Cement robust processes with stakeholders. Review and implement changes from 2026 onwards.

Objective 3.3.12

We will ensure that our data holdings are secure, accurate and available to services to derive maximum value from the data we hold.

Work towards this objective will be done as part of Customer Focus Objective 3.6 and above.

3.4. Internal and External Customer Communication

We will communicate effectively with our customers, partners and staff, and where appropriate with citizens of Orkney and visitors; we will find way continuously to improve our services, especially when resources are limited to the benefit of the Orkney Community.

Objective 3.4.1

We will continuously improve the Council’s digital communications infrastructure and encourage its use, through providing facilities to support Council employees and customers to work and interact in a more flexible and mobile way, supporting sustainable communities.

Work towards this objective will be done as part of other objectives above, especially Governance Objective 3.2 and Customer Focus Objectives 3.6.

Objective 3.4.2

We will actively participate in national initiatives for sharing intelligence.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.4.2.1.
Identify and implement measures to participate in national intelligence sharing initiatives.
Head of Property and Asset ManagementInformation Security and Assurance Officer.BlueThe Council participates in intelligence sharing organisations such as the National Cyber Security Centre (NCSC), Scottish Cyber Coordination Centre (SC3), Government Cyber Coordination Centre (GC3), and Cyber Scotland. The Council also participates in Cyber Resilience Partnerships including Cyber intelligence matters.While action complete IT will continue to work with our partners and will continue to develop our Cyber robustness.

Objective 3.4.2

We will introduce and promote digital document and record management to support secure document creation and storage.

Work towards this objective will be done as part of Digital Objective 3.5.

Objective 3.4.3

We will ensure easy access for staff and customers to information and meet our legislative data management requirements.

Work towards this objective will be done as part of Cyber Security Objectives and Customer Focus Objectives.

Objective 3.4.4

We will roll out enhanced desktop communications tools in keeping with our Microsoft 365 digital and governance strategies, as and when available, e.g., video, email, instant messaging, telecommunications, document and records management.

Work towards this objective will be done as part of Customer Focus Objective 3.6.

Objective 3.4.5

We will review our use of technology and work towards using systems that are used by others, where possible.

Work towards this objective will be done as part of Governance Objective 3.2 above.

Objective 3.4.6

We will work proactively with partner organisations and other councils to achieve the best fit technologies for our customers, and so that we do not re-invent the wheel; this will include support for the ‘Empowering Communities’ programme.

Work towards this objective will be done as part of other objectives above, especially Governance Objective 3.2.

Objective 3.4.7

We will improve fault reporting, ICT status information and staff communications through the ICT Helpdesk, Customer Services announcements, and creation of staff self-help.

Work towards this objective will be done as part of Customer Focus Objective 3.6.

3.5. Digital Objectives

We will embrace emerging technology and deliver a service that meets our customer expectations, also supporting our workforce to develop their own digital skills and implementing hardware that supports a more digital approach.

Objective 3.5.1

We will support the introduction of new streamlined electronic processes and collaborative communications through the use of available interactive technologies.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.5.1.1.
Provide IT support to the Electronic Document and Records Management (EDRMS) project.
Service Manager (ICT)Team Manager: ICT OperationsGreenIT are working with Council services where there are transitions to be completed to ensure data to be moved to SharePoint with appropriate retention periods being set up.Continue to work with the Council’s data governance team as required.
3.5.1.2.
Upgrade of systems.
Service Manager (ICT)Team Manager: ICT InfrastructureAmberSome systems procured and used by Services have been identified in the latest IT Health Check as requiring immediate upgrade. Two systems need upgrade. Iken which is used by our legal team and is in the process of being moved to an OIC SharePoint space. A new system to replace the StaffPlan system, which is used by OHAC home carers, is in the process of being evaluated.IT will continue to work with System Owners to identify new replacement systems that meet PSN and NCSC security guidelines.

Objective 3.5.2

We will demonstrate leadership behaviour that supports and fuels a digital culture among staff and customers.

Work towards this objective is being done as part of the Digital Strategy Delivery Plan objectives, under the theme of Digital.

Objective 3.5.3

We will listen to and support staff on how to get the best from digital systems.

Work towards this objective is being done as part of Customer Focus Objectives, at Objective 3.6, and within implementation projects described elsewhere in this plan, and in the Digital Strategy Delivery Plan.

Objective 3.5.4

We will improve and develop our staff’s digital competency.

Work towards this objective is being done as part of the Digital Strategy Delivery Plan objectives, under the theme of Digital.

Objective 3.5.5

We will continue to identify Account Managers for digital technologies, to encourage our stakeholders to work with these Account Managers to discuss their issues and any planned ICT developments; we will ensure that account managers are visible, knowledgeable, proactive in communicating with stakeholders, and effective in receiving and acting on feedback.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.5.5.1.
Identify IT technology specialism teams.
Service Manager (ICT)Team Manager: ICT OperationsGreenIT specialism team leader roles are clearly visible within IT however work to defined specialisms within other departments is ongoing to enable proactive communication with stakeholders enabling effective action being taken on feedback received.Create a stronger working relationship with System Owner specialists. On an ongoing basis. Instil a process of change management.

Objective 3.5.6

We will use technology (where available and appropriate) and user workshops to train and inform staff on our service technologies.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.5.6.1.
Creation of video files within MS Teams for training purposes
Service Manager (ICT)Team Manager: ICT OperationsGreenWork is underway to trial the recording of Teams sessions as a resource to be used in specific application areas.Will continue to develop further training videos as required.

Objective 3.5.7

We will concentrate on developing and updating user guidance with the aim to make our staff more technically skilled and independent with the systems they use.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.5.7.1.
Develop and update user guidance.
Service Manager (ICT)Team Manager: ICT OperationsGreenGuidance is issued to staff as and when needed, generally when a project moves into the delivery phase.SharePoint site to house all guidance in a user-friendly way. This is a moving and ongoing project.

3.6. Customer Focus Objectives

We will use our experience to work with all Council services to introduce ICT systems with a stronger citizen/customer focus: any new system will meet the needs of users within the Council, and also those outside the Council who use it in any way; system design will take the needs of all these users into account at as early a stage as possible.

Objective 3.6.1

We will continue to implement collaborative technologies.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.6.1.1.
Enhance the use of Microsoft technologies.
Service Manager (ICT)Team Manager: ICT OperationsGreenIT has continued to develop further the adoption and use of Microsoft 365. However, a roadmap should be defined to ensure the Council is making best use of its investment in Microsoft technologies. This along with Artificial Intelligence (AI) should include licensing options, partnership access, Schools, and field workers.Create a Microsoft roadmap and include new Microsoft releases as they become available. Continue to work with Performance and Business Support Service in AI policy and Co-Pilot trials.
3.6.1.3.
Enhance technology use between corporate and School staff
Information Security and Assurance Officer /Information Governance OfficerSchoolsGreenMany school staff now have access to corporate email and Microsoft teams. There is however a need to increase its use to ensure sensitive data is not held in GLOW systems.Continue to develop, support and promote use of M365 in schools.

Objective 3.6.2

We will review our Service Charter and introduce new targets as appropriate to support our changing business needs.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.6.2.1.
Review IT Service Charter.
Head of Property and Asset ManagementService Manager (ICT)GreenThe ICT Service Charter was last reviewed in June 2019. Individual Service Charter highlighting Service Level Agreement for the Orkney and Shetland Valuation Joint Board has been developed and shared.Review IT Service Charter during 2026.

Objective 3.6.3

We will work to improve internal fault reporting and service delivery through the use of various software tools to ensure that important information is communicated effectively and clearly.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.6.3.1.
Power BI for clear reporting.
Service Manager (ICT)Team Manager: ICT OperationsGreenMicrosoft Power BI software enables reporting business intelligence (BI) data to be visualised. Reporting utilisation needs enhancement by greater rollout of tools across the Council.Enhance processes on an ongoing basis and continue to support BI use by services.
3.6.3.2.
We will encourage our stakeholders to work with us to discuss their issues and any planned ICT development.
Head of Property and Asset ManagementService Manager (ICT)GreenIT meet with key stakeholders find way for recording portfolio.Enhance meeting schedules on an ongoing basis.

Objective 3.6.4

We will use opportunities within the ICT team to train staff to cover across more than one system, thus moving away from the risk inherent in specialised, singleton posts.

ActionOwnerLeadBRAGCurrent position, September 2026Next Steps
3.6.4.1.
Ensure more than one member of IT staff is trained and allocated to provide support for each supported system.
Service Manager (ICT)Team Manager: ICT OperationsGreenWork is underway to ensure that sufficient staff have the skills and experience to cover the support of all main systems and infrastructure. Many training courses, including by external providers, have been delivered to IT staff. Focus has now moved from general training to specific system training.Continue to review training needs for IT staff. Also include system owners.