NCSC releases Cyber Assessment Framework 4.0
CAF v4.0 responds to the growing threat, with new emphasis on threat understanding, secure software and AI-related risks.
Insights for the United Kingdom, including the Crown Dependencies.
CAF v4.0 responds to the growing threat, with new emphasis on threat understanding, secure software and AI-related risks.
The DUAA 2025 amends the UK GDPR, DPA 2018 and PECR, with changes commencing in stages.
A new UK code sets baseline security expectations for software vendors.
Updated Cyber Essentials requirements and the new Willow question set apply to assessments from today.
The UK Government has published a Cyber Governance Code of Practice setting out what boards and directors should do to govern cyber risk.
UK financial firms must now be able to remain within impact tolerances for their important business services.
The new UK public procurement regime is live, and Cyber Essentials requirements continue under PPN 014.
A new voluntary code sets baseline security principles across the AI lifecycle.
The Bank of England, PRA and FCA’s regime for critical third parties to the financial sector is now in force.
The first legally binding international AI treaty opens for signature, with the UK, EU and US among the first signatories.
The PSTI Act product security requirements now apply to consumer connectable (IoT) products sold in the UK.
Amendments to the Investigatory Powers Act 2016 introduce notification notices and update bulk data and communications data powers.