---
title: Cyber security isn’t about proving you followed the rules. It’s about proving you can recover
description: "The NCSC has just issued a fresh alert regarding Russian-aligned hacktivists, and it carries a warning that caught my eye: a shifting focus toward 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗧𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝘆 (𝗢𝗧)"
---

[All Insights ](https://blog.methods.co.uk/en/all-insights)

# [Cyber security isn’t about proving you followed the rules. It’s about proving you can recover](https://blog.methods.co.uk/en/all-insights/accelerating-cyber-defence-the-need-for-resilience-by-design-clone)

 Written by [Mike Boreham](https://blog.methods.co.uk/en/all-insights/author/mike-boreham) | Feb 13, 2026 4:16:05 PM

### **From compliance to threat-informed resilience **

The introduction of the Cyber Assessment Framework (CAF)v4.0 by the National Cyber Security Centre (NCSC) last August has fundamentally changed the way we need to look at the cyber world. It changes how public sector bodies need to think about cyber resilience. It moves the paradigm:

- **From**  
  *“Are we compliant?”*
- **To**  
  *“Are we prepared for the adversaries most likely to target us?”*
- **From**  
  *“Do we have monitoring?”*
- **To**  
  *“Do we proactively hunt for malicious behaviour across our environment?”*
- **From**  
  *“Do our teams follow policies?”*
- **To**  
  *“Are our governance, architecture and culture aligned to rapid detection, containment and recovery?”*

### Why listen?

CAF v4.0 is not just another pile of red tape waiting to be obeyed and the NCSC is not just a think tank with grandiose philosophical ideas. The framework is the best of current thinking from the pick of current experts in the field of cybersecurity. CAF 4.0 transforms compliance conversations into the strategic resilience actions that the NCSC and UK government policy signal as the way ahead for the coming decade.

In short, CAF is no longer just an assessment framework. it is becoming the **operating system for UK public‑sector resilience**.

### What does CAF4.0 tell us?

CAF’s structure hasn’t changed. It still centres on **4 objectives** and **14 principles**.  
In v4.0, however, the substance within those objectives has transformed to:

1. **A threat‑informed model**
2. **Integration of AI‑related security risks**
3. **Secure software by design**
4. **Proactive threat hunting**

CAF v4.0 requires organisations to explicitly consider an **attacker perspective** that models likely adversaries, their capabilities, and their known tactics and techniques. This moves the framework from generic risk awareness to **threat‑specific defence**.

For the first time, CAF includes guidance on:

- The safety of AI models,
- Protection of training data pipelines
- The governance of AI‑assisted decisions.

As AI becomes integral to defence and operations, CAF embeds resilience into both the models and the data ecosystems powering them.

CAF v4.0 strengthens expectations across the entire secure software development lifecycle (SDLC). Regardless of whether software is built in‑house or delivered by third parties, **supply chain scrutiny is now central, not optional**.

Monitoring has evolved from logging and responding to events to **active hunting**.  
Organisations must demonstrate capability in:

- Behavioural analytics
- Telemetry interpretation
- Proactive identification of hostile activity
- Rapid validation of anomalies

### CAF v4.0: The four objectives

The four objectives, laid out in CAF 4.0, are designed to help organizations to assess and improve their cyber resilience against a range of threats, rather than just acting as a "tick-box" compliance exercise.

**Objective A — Managing security risk**

CAF v4.0 reinforces governance and risk accountability, including:

**Objective B — Protecting against cyber attack**

Strengthened expectations include:

**Objective C — Detecting cyber security events**

This is where v4.0 makes its biggest leap to:

**Objective D — Minimising impact**

CAF also reinforces the importance of:

CAF 4.0 connects operational resilience, cyber security and business continuity into a single leadership responsibility model.

### What does this mean for the UK public sector in 2026?

**Local Government: Moving to a modern, consistent approach**

Local authorities are being moved away from manual, spreadsheet‑based CAF assessments to platforms that:

For councils that historically struggled with fragmented approaches and/or limited cyber capacity, CAF v4.0creates a clearer pathway forward.

**NHS & Healthcare: CAF becomes a formal requirement**

The NHS is tightening expectations from the Data Security and Protection Toolkit (DSPT), with larger organisations already aligning to CAF v4.

For a sector with life‑critical systems, this raises the bar from “cyber hygiene” to measurable operational resilience.

**Critical National Infrastructure (CNI): From guidance to obligation**

The upcoming Cyber Security &Resilience Bill is set to change CAF from something organisations *should *follow to something they *must* follow.

Under this legislation:

In short: 2026 is the year CAF transitions from an advisory framework to a mandatory expectation across critical services and wider public‑sector bodies**.**

### How Methods helps organisations navigate CAF v4.0

Methods has supported UK public‑sector organisations in designing and delivering resilience aligned to NCSC priorities for many years now. Our work spans:

In short, Methods acts as a **“translation layer” **between national priorities and actionable organisational plans.

### What will we be discussing at CyberUK 2026?

Methods will be on hand at CyberUK2026 to host senior discussions on:

We look forward to exploring this with you at **CyberUK2026, Stand F29**.

 

[View full post](https://blog.methods.co.uk/en/all-insights/accelerating-cyber-defence-the-need-for-resilience-by-design-clone)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mike Boreham"
  },
  "dateModified" : "2026-03-06T11:04:25.722Z",
  "datePublished" : "2026-02-13T16:16:05Z",
  "headline" : "Cyber security isn’t about proving you followed the rules. It’s about proving you can recover",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1068,
    "url" : "https://143189852.fs1.hubspotusercontent-eu1.net/hubfs/143189852/Evolving%20your%20cyber%20strategy.png",
    "width" : 2158
  },
  "mainEntityOfPage" : "https://blog.methods.co.uk/en/all-insights/accelerating-cyber-defence-the-need-for-resilience-by-design-clone",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "All Insights"
  }
}
```