
In a significant move to strengthen the UK’s cyber resilience, the National Cyber Security Centre (NCSC) has launched Version 4.0 of its Cyber Assessment Framework (CAF).
This update, a direct response to the escalating sophistication of cyber threats, provides a new blueprint for organisations – particularly those operating critical national infrastructure (CNI) – to manage their cyber risks. The new framework is already being adopted by nearly all UK cyber regulators and the government’s own GovAssure scheme.
The core of CAF v4.0 introduces four major changes designed to keep pace with the modern threat environment:
Deeper Understanding of Attackers: A new section on understanding attacker methods and motivations aims to inform better, intelligence-led cyber risk decisions. This is crucial for organisations to anticipate and counter emerging threats.
Secure Software Development: The framework now includes a dedicated section on the secure development and maintenance of software used in essential services, emphasising the need for secure coding practices from the outset.
Enhanced Threat Detection: Updates to the security monitoring and threat hunting section improve an organisation’s ability to proactively identify threats through behavioural analysis and anomaly detection.
Addressing AI-Related Risks: A key new focus is the enhanced guidance on managing AI-related cyber risks. This ensures organisations are prepared for both the opportunities and threats posed by AI technologies.
The NCSC developed this new framework in full consultation with cyber regulators. It is also designed to be forward-looking, with future iterations planned to align with the regulatory proposals within the upcoming Cyber Security and Resilience Bill, which is expected to be introduced to Parliament later this year. By adopting CAF 4.0, organisations can strengthen their defences and stay ahead of both regulatory and technological developments.

© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543