Health-ISAC Hacking Healthcare 8-15-2025

This week, Health-ISAC®’s Hacking Healthcare® examines the recent publication of a new version of the United Kingdom’s (U.K.) National Cyber Security Centre (NCSC) developed Cyber Assessment Framework (CAF). Join us as we briefly explain what the CAF is, what the new framework version provides, why it’s being updated, how it fits into the planned U.K. Cyber Security and Resilience Bill, and what it all might mean for the healthcare sector in the U.K. and abroad.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
PDF Version: TLP WHITE Hacking Healthcare 8.15.2025
Size : 526.5 kB Format : PDF
Text Version:
Welcome back to Hacking Healthcare®.
U.K. Cyber Assessment Framework v4.0 Published
What is the CAF and what is it used for?
On August 6, the U.K. NCSC published version 4.0 of the CAF, a “collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the U.K. with a focus on essential functions.”[i]
Initially published in April of 2018, the CAF is currently described by the U.K. NCSC as “a tool to help organisations assess and improve their cyber security and resilience, managing cyber risks and protecting essential services from cyber threats,” and it is “primarily designed for organisations operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government.”[ii]
That may sound familiar to anyone using the National Institute of Standards and Technology (NIST) developed Cybersecurity Framework (CSF), and much like the CSF, the core of the CAF is meant to be non-prescriptive and sector agnostic. While the two are generally well aligned, they do take different approaches and formats. This most recent CAF version is divided into 4 high-level objectives and 14 principles that “are written in terms of outcomes, i.e. specification of what needs to be achieved rather than a checklist of what needs to be done.”[iii]
In terms of its use, the NCSC is not a regulatory body, but the CAF was designed with the expectation that U.K. regulatory entities would use it to support their own missions and responsibilities. The NCSC states that nearly all U.K. cyber regulators make use of the CAF, and this includes the National Health Service (NHS). In particular, the CAF is meant to help organizations meet requirements like the NIS directive or the upcoming successor being introduced through the Cyber Security and Resilience Bill.
What has changed in the new version?
Citing increasing threats to Critical National Infrastructure (CNI),[iv] and the need to “[keep] pace with the evolution of attack methods,” the CAF v4.0 brings 4 notable changes:[v]
- A new section on building a deeper understanding of attacker methods and motivations to inform better cyber risk decisions.
- A new section on ensuring software used in essential services is developed and maintained securely.
- Updates to the section on security monitoring and threat hunting to improve the detection of cyber threats.
- Improved coverage of AI-related cyber risks throughout the CAF.
We will explore how this all affects the health sector and the broad cybersecurity policy environment in the below analysis section.
Action & Analysis
**Included with Health-ISAC Membership**
[i] https://www.ncsc.gov.uk/collection/cyber-assessment-framework
[ii] https://www.ncsc.gov.uk/collection/cyber-assessment-framework
[iii] https://www.ncsc.gov.uk/files/NCSC-Cyber-Assessment-Framework-4.0.pdf
[iv] As defined by the National Protective Security Authority of the U.K., CNI are “are those critical elements of infrastructure whose loss or compromise could severely impact the delivery of essential services or have significant impact on national security, national defence, or the functioning of the state. It also includes some functions, sites and organisations which are not critical to the maintenance of essential services, but which need protection due to the potential danger to the public (civil nuclear and chemical sites, for example).” Health and Emergency Services are considered to be CNI sectors, although not all entities within a CNI sector are necessarily deemed to be “critical”. https://www.npsa.gov.uk/about-npsa/critical-national-infrastructure
[v] https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat
[vi] https://www.ncsc.gov.uk/files/NCSC-Cyber-Assessment-Framework-4.0.pdf
- Related Resources & News
- Threat Actor Playbook: Conversational Social Engineering in Care Settings
- The Human Risk Layer of AI
- Cybersecurity in the Lab
- Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience
- What’s in America’s Code?
- Introducing AI Agents to Your Identity Fabric
- Cyberattacks on Healthcare Sector Jumped 14% in First Half of 2026
- What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
- Continuous attack surface monitoring and sophisticated social engineering assessment
- Hospital Networks are Becoming Targets in Cyberwarfare, and They’re Unequipped to Deal With It