The UK’s National Cyber Security Centre (NCSC) has unveiled Cyber Assessment Framework version 4.0 (CAF v4.0), developed in response to a ‘growing threat’ landscape faced by organizations.
Cyber Assessment Framework v4.0 aims to enhance cybersecurity and resilience through several significant updates. The framework provides a structured means for organizations to assess how effectively they manage cyber risks.
CAF v4.0 includes four major changes:
- A new section on building a deeper understanding of attacker methods and motivations to inform better cyber risk decisions.
- A new section on ensuring software used in essential services is developed and maintained securely.
- Updates to the section on security monitoring and threat hunting to improve the detection of cyber threats.
- Improved coverage of AI-related cyber risks throughout the Cyber Assessment Framework.
NCSC says that it is already looking ahead to future iterations of the Cyber Assessment Framework, “ensuring that it keeps pace with the regulatory proposals within the Cyber Security and Resilience Bill, which will be laid before parliament later this year.”
Industry comment
James Neilson, SVP International at OPSWAT told Resilience Forward:
“The NCSC’s updated CAF for UK CNI is a welcome step. Security teams within critical infrastructure sectors are often expected to manage unfamiliar systems, and few individuals possess deep expertise in both IT and OT, creating knowledge gaps in threat assessment and defence development.
“The updated CAF reflects a trend we’ve observed of cybercriminals increasingly using multi-layered threats designed to evade analysis and detection. An attacker’s aim is to evade and confuse, not overwhelm the network, meaning that threats are missed by legacy antivirus solutions and EDR stacks.
“We strongly recommend that critical infrastructure organizations review the NCSC’s updated CAF. However, they should also prioritise securing the data that moves in and out of their OT networks, an area often neglected by CNI organizations. IT systems, Internet connectivity, and transient devices remain major attack surfaces for ICS/OT infrastructure. By controlling data flows and scanning files in transit, organizations can detect and neutralise hidden malicious payloads before they infiltrate critical systems.”






