
Plain-English definitions of the UK cyber security and assurance terms that matter to government, critical national infrastructure and their suppliers.
Written for people who need to understand what a term actually means — what it covers, what it does not, and where the official guidance sits.
A UK government approach requiring cyber security to be built into digital services from the outset and evidenced throughout their life, rather than assessed once before go-live.
Read the definitionThe UK government’s cyber assurance process, under which departments assess their most critical systems against the NCSC Cyber Assessment Framework.
Read the definitionThe NCSC framework of 14 principles across four objectives, used to assess the cyber resilience of organisations operating essential functions.
Read the definitionThe practice of assessing and monitoring the cyber security of third parties, so that risk introduced through the supply chain is understood and managed.
Read the definitionA UK government-backed scheme covering five technical controls that protect against the most common internet-based attacks.
Read the definitionThe EU directive strengthening cyber security obligations for essential and important entities, replacing the original NIS Directive.
Read the definition