Skip to main content

Health-ISAC Hacking Healthcare 8-15-2025

Hacking Healthcare logo featuring a computer mouse, hacker hat icon, and medical cross.

This week, Health-ISAC®’s Hacking Healthcare® examines the recent publication of a new version of the United Kingdom’s (U.K.) National Cyber Security Centre (NCSC) developed Cyber Assessment Framework (CAF). Join us as we briefly explain what the CAF is, what the new framework version provides, why it’s being updated, how it fits into the planned U.K. Cyber Security and Resilience Bill, and what it all might mean for the healthcare sector in the U.K. and abroad.

As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)

 

PDF Version: TLP WHITE Hacking Healthcare 8.15.2025
Size : 526.5 kB Format : PDF

 

Text Version:

Welcome back to Hacking Healthcare®.

U.K. Cyber Assessment Framework v4.0 Published

What is the CAF and what is it used for?

On August 6, the U.K. NCSC published version 4.0 of the CAF, a “collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the U.K. with a focus on essential functions.”[i]

Initially published in April of 2018, the CAF is currently described by the U.K. NCSC as “a tool to help organisations assess and improve their cyber security and resilience, managing cyber risks and protecting essential services from cyber threats,” and it is “primarily designed for organisations operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government.”[ii]

That may sound familiar to anyone using the National Institute of Standards and Technology (NIST) developed Cybersecurity Framework (CSF), and much like the CSF, the core of the CAF is meant to be non-prescriptive and sector agnostic. While the two are generally well aligned, they do take different approaches and formats. This most recent CAF version is divided into 4 high-level objectives and 14 principles that “are written in terms of outcomes, i.e. specification of what needs to be achieved rather than a checklist of what needs to be done.”[iii]

In terms of its use, the NCSC is not a regulatory body, but the CAF was designed with the expectation that U.K. regulatory entities would use it to support their own missions and responsibilities. The NCSC states that nearly all U.K. cyber regulators make use of the CAF, and this includes the National Health Service (NHS). In particular, the CAF is meant to help organizations meet requirements like the NIS directive or the upcoming successor being introduced through the Cyber Security and Resilience Bill.

 

What has changed in the new version?

Citing increasing threats to Critical National Infrastructure (CNI),[iv] and the need to “[keep] pace with the evolution of attack methods,” the CAF v4.0 brings 4 notable changes:[v]

We will explore how this all affects the health sector and the broad cybersecurity policy environment in the below analysis section.

 

Action & Analysis 
**Included with Health-ISAC Membership**

 

[i] https://www.ncsc.gov.uk/collection/cyber-assessment-framework

[ii] https://www.ncsc.gov.uk/collection/cyber-assessment-framework

[iii] https://www.ncsc.gov.uk/files/NCSC-Cyber-Assessment-Framework-4.0.pdf

[iv] As defined by the National Protective Security Authority of the U.K., CNI are “are those critical elements of infrastructure whose loss or compromise could severely impact the delivery of essential services or have significant impact on national security, national defence, or the functioning of the state. It also includes some functions, sites and organisations which are not critical to the maintenance of essential services, but which need protection due to the potential danger to the public (civil nuclear and chemical sites, for example).” Health and Emergency Services are considered to be CNI sectors, although not all entities within a CNI sector are necessarily deemed to be “critical”. https://www.npsa.gov.uk/about-npsa/critical-national-infrastructure

[v] https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat

[vi] https://www.ncsc.gov.uk/files/NCSC-Cyber-Assessment-Framework-4.0.pdf

[vii]https://www.gov.uk/government/publications/cyber-security-and-resilience-bill-policy-statement/cyber-security-and-resilience-bill-policy-statement

[viii]https://www.gov.uk/government/publications/cyber-security-and-resilience-bill-policy-statement/cyber-security-and-resilience-bill-policy-statement