Four decisions for building resilient, citizen-centred digital public services
Digital public services have advanced significantly in recent years and have become a standard channel for interaction between citizens and public administrations.
The challenge now is to continue improving the citizen experience by strengthening accessibility, usability and the ability of services to adapt to the different needs of the population, without compromising agility, efficiency or inclusion.
Based on this assessment, public administrations need to make four interconnected decisions about their digital services: how to ensure continuity, how to retain control over data and operations, how to design services around citizens, and how to preserve the knowledge needed to sustain them.
1. Protect information and maintain continuity
The first decision is how to ensure the continuity of increasingly digital services. Growing dependence on technology, data and connected infrastructure increases exposure to incidents, outages and operational failures. In this context, public administrations need to combine prevention, detection, response and recovery capabilities to maintain service availability and continue operating in adverse conditions.
The importance of these capabilities is also reflected in different regulatory and risk management frameworks. Although requirements vary between countries and jurisdictions, there is a common trend towards strengthening continuous risk management, operational continuity and incident response. In Spain, this approach is reflected, among other frameworks, in the National Security Scheme (ENS), while in the European Union the NIS2 Directive strengthens these obligations for entities within its scope.
■ Within this framework, automation and AI can support specific Cybersecurity operations, such as correlating signals, enriching alerts, prioritising incidents or speeding up responses in known, clearly defined scenarios. Their use requires clear policies, traceability and human oversight, particularly where critical systems or services are involved.
The security of a digital public service is demonstrated by its ability to anticipate, withstand and recover from disruption while continuing to deliver the service.
2. Sovereignty over data, operations and service providers
Maintaining control over data and critical services requires an understanding of where they are hosted, which jurisdiction applies, who can operate the systems and what dependencies exist. It also means planning portability and exit mechanisms that make it possible to change provider when necessary.
This control extends across every layer of the service: connectivity and processing at the network edge (Edge Computing), data centres and Cloud Computing, identities and encryption, and applications and their operation.
■ The decision is not about choosing an isolated technology, but about balancing resilience, portability, applicable jurisdiction and integration between providers. That balance affects internal operations as well as the availability, traceability and ease of access experienced by citizens.
Controlling a digital service means knowing where the data is located, who operates each layer and how to change provider without losing continuity or decision-making capability.
3. Simpler and more inclusive digital services
Public administrations serve a diverse population, with different levels of digital skills, abilities, needs and ways of accessing technology. This reality needs to be taken into account when designing inclusive digital services.
■ An effective digital public service allows people to start an administrative procedure, check its status and resolve issues without having to provide the same information unnecessarily. To move in that direction, public administrations can combine human-centred design, secure data sharing, process automation and multiple access channels.
—Self-service digital offices, for example, can complement face-to-face and online services and make administrative procedures more accessible to people with different levels of digital skills, resources or conditions for accessing services from home. These environments broaden access options when they provide clear instructions, meet accessibility requirements and remain available outside standard opening hours. They should also be integrated with support channels for cases that cannot be completed independently.
Digitalisation is not enough: the service needs to be understandable, accessible and usable by people with different capabilities, resources and circumstances
.
4. Generational change requires knowledge to be preserved
Generational change in the workforce presents a common challenge: bringing in new talent while enabling the transfer of accumulated operational knowledge. Planning both processes together helps preserve service continuity as the workforce changes. The arrival of new talent can be supported through training, documentation and knowledge transfer mechanisms.
■ Automation and managed services can also complement internal capabilities and free up time for higher-value activities, provided they address specific needs and do not introduce unnecessary complexity.
Renewing capabilities without losing knowledge requires workforce renewal, training and the transfer of operational experience to be planned together.
Cross-cutting capabilities for putting these decisions into practice
The four decisions outlined above (continuity, control, access and knowledge preservation) cannot be implemented through isolated initiatives. They require a combination of cross-cutting technological and organisational capabilities to translate them into services that are available, secure, efficient, interoperable and accessible to citizens.
These capabilities can be grouped into four complementary areas:
- infrastructure and connectivity;
- data and interoperability;
- security, identity and digital trust;
- service design and organisational capabilities.
Their relative importance and combination depend on the criticality of the service, the data being processed, the operating model and user needs.
Infrastructure and connectivity
Modernisation needs to keep critical services available while legacy systems, networks, data centres, Cloud Computing and edge processing evolve. Combining these resources makes it possible to modernise gradually and place each workload according to its requirements for capacity, latency, connectivity, data processing and continuity. This means that public administrations do not need to replace every component at the same time.
Resilience requires secure connectivity combined with redundancy, backups, disaster recovery, observability and orchestration.
Data and interoperability
Data spaces combine infrastructure, governance and interoperability so that different organisations can share information under common access and usage rules.
In areas such as healthcare, employment, mobility and education, data spaces can enable information to be reused without each participant losing control over the data it contributes. This requires governance rules, access permissions, security mechanisms and records that make it possible to determine who uses each piece of data and for what purpose. Their value does not lie in concentrating information, but in enabling reliable, secure and traceable use to improve services and processes.
On this basis, AI can help automate certain processes and support decision-making. Its adoption requires appropriate data, clearly defined responsibilities, traceability, continuous assessment and human oversight, particularly when its outputs affect access to services, rights or administrative decisions.
Security, identity and digital trust
Cyber resilience combines prevention, detection, response and recovery to maintain operations during incidents. This capability is built on day-to-day risk management and helps sustain services when disruption occurs.
This operational dimension is complemented by digital identity, which involves securely managing the entire access lifecycle: provisioning, authentication, attribute updates, delegation and revocation.
The European Digital Identity framework, which updates the eIDAS Regulation on electronic identification and trust services, provides for Member States to make European Digital Identity Wallets available. These wallets will allow citizens, residents and businesses to identify themselves and prove certain attributes when accessing public and private services. For public administrations, deployment requires decisions on how to ensure interoperability, protect privacy, preserve user control and integrate wallets with existing identification systems.
The protection of digital identity and trust services also depends on cryptographic mechanisms that can evolve over time. The transition to post-quantum cryptography (designed to withstand attacks from future quantum computers) starts with an inventory of algorithms, certificates, software libraries and systems. This inventory makes it possible to prioritise migration according to risk, the criticality of each system and how long the data needs to remain protected. The US National Institute of Standards and Technology (NIST) recommends identifying vulnerable algorithms and planning their gradual replacement.
Crypto-agility complements this approach by enabling cryptographic mechanisms to be updated in a controlled way, without turning every change into a standalone project or disrupting operations.
Service design and organisational capabilities
Human-centred design needs to be embedded throughout the service lifecycle: from identifying needs and barriers to user testing, accessibility, multichannel service delivery and evidence-based improvement.
Turning technology into lasting outcomes also requires preparing the teams responsible for managing it, through continuous training, up-to-date documentation, knowledge transfer and clearly defined roles.
These practices support adoption, reduce dependence on isolated pockets of knowledge and help ensure that new processes become part of day-to-day work without introducing unnecessary complexity.
Decisions only translate into better services when infrastructure, data, digital trust, design and organisation move forward in a coordinated way.
An integrated transformation focused on public-service delivery
Transforming public administrations is not about accumulating technologies. It is about coordinating the decisions that underpin each service: ensuring continuity, retaining control over data and operations, making services easier for citizens to access and developing the capabilities needed to improve them.
Infrastructure, data, security, design and knowledge are part of the same system.
The difference lies in making decisions based on explicit criteria: clear priorities, defined responsibilities, robust governance and indicators for assessing the availability, adoption, quality and evolution of each service. When these decisions translate into reliable, understandable and accessible services, they can help strengthen citizens' trust in public institutions.
The difference lies in digitalising in a way that connects each technology decision more closely to a specific public-service objective.
■ At Telefónica, we support public administrations in the design and operation of digital services through connectivity, infrastructure, data, Cybersecurity and operational capabilities aligned with the needs, existing systems and requirements of each public-sector organisation. Find out more about our capabilities for the public sector →
______
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities