Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • Treat Ransomware Criminals Like Terrorists, House Subcommittees Advised
    • Federal Court Asked to Block DoJ’s Demands for State Voter Data
    • Justices Wrestle With Arguments in FCC Privacy Cases
    • Legislation to Speed Data Deletion Requests Advances in California
    • Polish Agency Rejects Privacy Consultation With Lawyers’ Group
    • Postal Service, Bank Fined Over Privacy Violations in Italy
    • Preliminary Comments Sought on Potential Changes to California Privacy Rules
    • Spanish Privacy Regulator Analyzes Data Protection Issues in AI Voice Transcription
    • U.K. Agency Calls for Organizations to Focus on Severe Cyber Threats
    • VoIP Provider Given 14 Days to Respond to FCC’s Robocall Order
    • W.D. Mo.: Court trims data-breach suit against women’s health provider
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, U.K. Agency Calls for Organizations to Focus on Severe Cyber Threats, (Apr 21, 2026)

    By Tony Foley

    The United Kingdom’s National Cyber Security Centre (NCSC) is urging organizations delivering critical services in the energy, transportation, health, communications, and financial sectors to assume leadership responsibility in preparing for p ...

    By Tony Foley

    The United Kingdom’s National Cyber Security Centre (NCSC) is urging organizations delivering critical services in the energy, transportation, health, communications, and financial sectors to assume leadership responsibility in preparing for potential cybersecurity incidents.

    In a blog post, NCSC said these sectors generally relied on uninterrupted digital operations, adding that disruptions in these operations were a business continuity and national resilience issue. “[H]ighly capable threat actors are increasing both their intent and their ability to target organisations of national economic significance, to cause real-world operational disruption,” NCSC said. “At the same time, new technologies—like frontier AI—risk increasing the speed, scale and ease of attacks.”

    The post describes situations posing a severe cyber threat, including those that lead to extended operational downtime with direct customer impact, significant financial loss, long-term reputational damage, and increased risks to public safety and national security. NCSC’s annual review in 2025 highlighted the widening gap between the rising pace of cyber threats and the U.K.’s collective resilience, leading the agency to emphasize that the time to act is now.

    NCSC said that getting an organization ready and building the required level of resilience required clear commitment for organizational leaders, organization-wide collaboration, engagement with suppliers and partners, and advance planning and action. Citing its recent guidance on how to prepare and plan for response to a severe cyber threat for critical national infrastructure, NCSC identified several key takeaways, including the following:

    1. Resilience beats prevention, because cyber threats are not always preventable, making it important for organizations to prepare to continue operations through disruption and to undertake recovery activities; and

    2. Preparing before the threat escalates, because many measures required during a severe cyber threat, like rapidly hardening defenses or isolating networks, are complex, costly, and carry business impacts that may make them disproportionate to implement and cannot be improvised under pressure.

    The agency’s guidance builds on its Cyber Assessment Framework (CAF), which is designed to help organizations achieve and demonstrate an appropriate level of cyber resilience, by focusing on how organizations should prepare for and respond to severe cyber threats.

    News: InternationalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use