Skip to content
Use case 076

Government Employee Secure Workstations

A deployment concept for government departments, agencies, councils, public servants and managed service providers.

Proposed deployment · Compatibility assessment required
Government, Public Safety and Defence

Why this environment matters

Security for government employee secure workstations starts with the system's role: it supports everyday access to departmental records, email, portals and line-of-business applications. A key concern is that phishing, malicious documents and credential theft can expose sensitive citizen information or establish long-lived persistence. NØNOS offers a potential architecture based on signed capsules, explicit capabilities and strong isolation.

The security challenge

The practical concern is that phishing, malicious documents and credential theft can expose sensitive citizen information or establish long-lived persistence. Public-sector systems hold authoritative records and powers that affect identity, liberty, property, emergency response and national security. Endpoint compromise can therefore create consequences far beyond data loss. The attack surface may include remote support, software updates, removable media, third-party libraries, public input or misused operator credentials. The security design therefore needs containment as well as prevention.

How the capsule model could help

The proposed deployment pattern is to run risky content, privileged applications and departmental services in separate signed capsules with disposable user sessions. NØNOS would use attestation for privileged actions and controlled removable media as the trust foundation, then apply disposable trusted sessions and signed application allow-lists around higher-risk functions. Logs or proofs could record which approved capsule performed a privileged action without retaining unnecessary user data.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

Government deployment would require formal accreditation, identity and records integration, accessibility testing, procurement assurance and controls appropriate to the information classification and public function.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

Who could buy or integrate it?

  • Central government departments purchasing managed employee device fleets
  • Local authorities procuring secure desktop services for public servants
  • Government IT contractors integrating applications and supporting endpoint rollouts

Industry examples: HM Revenue & Customs, Department for Work and Pensions. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$37.2 billion

Endpoint security

Global · 2025 · annual market estimate

Solutions and services protecting endpoints across industries; includes application control and managed security, not a government workstation subtotal.

Modelled global devices
7M–56M

Candidate OS endpoints

Source-anchored modelled range · 2025

Low to medium confidence: sourced population data with assumed coverage and suitability. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$420M–$11.2B

USD / year at full model coverage

Device scenario × assumed US$60–$200 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Global model: rounded reference of 1.4 billion monthly active Windows devices in June 2025 (Microsoft reports more than 1.4 billion) × assumed 0.5–4% government administrative-workstation allocation = 7–56 million candidate workstations. The allocation is a planning assumption and excludes public schools and hospitals. Microsoft does not provide this sector breakdown. It does not imply replacement compatibility or migration demand. Modelled candidate endpoints, not measured NØNOS deployments. Hardware eligibility and adoption are unverified. Overlaps other cases.

Microsoft, Stay secure with Windows 11, Copilot+ PCs and Windows 365 ↗

Vendor active-device denominator anchor. More than 1.4 billion monthly active Windows devices in June 2025. Rounded reference; no sector or technical compatibility breakdown.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.