---
title: "NCSC CNI Severe Threat Guide: explained | Firevault"
description: "An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide#webpage",
      "url": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide",
      "name": "NCSC CNI Severe Threat Guide: explained",
      "description": "An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NCSC CNI Guide: Severe Cyber Threats",
          "item": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "NCSC CNI Guide: Severe Cyber Threats",
      "description": "An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective framework for cyber resilience.",
      "url": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/og-cached/649ad906347d6f17.png",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-01-30T00:00:00.000Z",
      "dateModified": "2026-01-30T00:00:00.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/knowledge/ncsc-cni-severe-cyber-threat-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Knowledge",
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Overview

Understanding the NCSC FrameworkWhat Constitutes a Severe Cyber …Objective A: Managing Security R…Objective B: Protection Through …Objective C: Detection and the L…Objective D: Withstanding and Re…The WannaCry Lesson: Interconnec…Implementing Physical Disconnect…Regulatory Context and Future Di…ConclusionMore

[Knowledge Vault](/learn/knowledge)/ Knowledge 

Knowledge · 30 January 2026 · 7 min read 

# NCSC CNI Guide: Severe Cyber Threats

An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective framework for cyber resilience.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fncsc-cni-severe-cyber-threat-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fncsc-cni-severe-cyber-threat-guide&text=NCSC%20CNI%20Guide%3A%20Severe%20Cyber%20Threats%0A%0AAn%20authoritative%20guide%20aligned%20with%20NCSC%20recommendations%20for%20Critical%20National%20Infrastructure.%20How%20physical%20disconnection%20supports%20the%20four-objective%20framework%20for%20cyber%20resilience.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fncsc-cni-severe-cyber-threat-guide)[](mailto:?subject=NCSC%20CNI%20Guide%3A%20Severe%20Cyber%20Threats&body=An%20authoritative%20guide%20aligned%20with%20NCSC%20recommendations%20for%20Critical%20National%20Infrastructure.%20How%20physical%20disconnection%20supports%20the%20four-objective%20framework%20for%20cyber%20resilience.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fncsc-cni-severe-cyber-threat-guide)

10 sections· 7 min read 

Knowledge #OSSOffline Secure Storage® 

**On this page**[01 Understanding the NCSC Framework](#section-0)[02 What Constitutes a Severe Cyber …](#section-1)[03 Objective A: Managing Security R…](#section-2)[04 Objective B: Protection Through …](#section-3)[05 Objective C: Detection and the L…](#section-4)[06 Objective D: Withstanding and Re…](#section-5)[07 The WannaCry Lesson: Interconnec…](#section-6)[08 Implementing Physical Disconnect…](#section-7)[09 Regulatory Context and Future Di…](#section-8)[10 Conclusion](#section-9)

The National Cyber Security Centre has published comprehensive guidance for Critical National Infrastructure operators on preparing for and responding to severe cyber threats. This guidance, aligned with the Cyber Assessment Framework, provides a structured approach to building organisational resilience. This article examines how [offline secure storage](/offline-secure-storage) supports each element of the NCSC framework.

## Understanding the NCSC Framework

The NCSC Cyber Assessment Framework is built around four high-level objectives that together provide comprehensive cyber resilience:

-   **Objective A: Managing Security Risk**: Appropriate organisational structures, policies, and processes to understand, assess, and systematically manage security risks
    
-   **Objective B: Protecting Against Cyber Attack**: Proportionate security measures to protect systems and data from cyber attack
    
-   **Objective C: Detecting Cyber Security Events**: Capabilities to detect cyber security events affecting, or with the potential to affect, essential functions
    
-   **Objective D: Minimising Impact of Incidents**: Capabilities to minimise the adverse impact of a cyber security incident on the operation of essential functions
    

Each objective contains detailed principles and indicators of good practice. Critically, the framework is outcome-focused rather than prescriptive, allowing organisations to select appropriate controls for their risk profile.

## What Constitutes a Severe Cyber Attack

The NCSC defines severe cyber attacks as those with potential to cause:

-   **Significant disruption to essential services**: Attacks that prevent the delivery of critical functions to the public or other organisations
    
-   **Substantial financial impact**: Losses that threaten organisational viability or require significant recovery investment
    
-   **National security implications**: Compromise of systems or data with broader security consequences
    
-   **Cascading effects**: Incidents that propagate through supply chains or interconnected infrastructure
    

For CNI operators, the WannaCry attack of 2017 demonstrated how rapidly cyber incidents can escalate. NHS services were disrupted across England and Scotland, forcing staff to revert to manual processes while critical systems remained encrypted. The interconnectedness of modern infrastructure means that attacks on one organisation can quickly affect many others.

## Objective A: Managing Security Risk with Physical Disconnection

The NCSC emphasises that security risk management must be owned at board level, with clear accountability for cyber resilience decisions. For organisations handling the most sensitive data, this creates a fundamental question: what level of risk exposure is acceptable?

Traditional security architectures accept network connectivity as a given, then attempt to manage the resulting risks through layers of controls. Physical disconnection through Offline Secure Storage changes this calculus entirely by removing the most critical data from the attack surface.

Key indicators of good practice under Objective A include:

1.  Understanding which data and systems are genuinely critical to essential functions
    
2.  Assessing threats and vulnerabilities with appropriate rigour
    
3.  Making risk-informed decisions about protective controls
    
4.  Maintaining oversight and review of security posture
    

For [crown jewel data](/oss-for-business), the risk assessment often concludes that no level of network-based protection provides acceptable residual risk. Offline storage addresses this by eliminating network exposure entirely, a risk treatment option that demonstrates board-level commitment to protecting essential functions.

## Objective B: Protection Through Physical Isolation

The NCSC framework includes multiple principles addressing protection, from access control and data security to secure configuration and staff awareness. A critical principle often overlooked is B.4: System Security, specifically the resilience of systems to cyber attack.

Physical disconnection provides protection that no software-based control can match:

-   **No remote attack vector**: Systems without network interfaces cannot be attacked over networks, regardless of vulnerability status
    
-   **No credential compromise risk**: Stolen credentials cannot grant access to systems that are not connected
    
-   **No lateral movement pathway**: Attackers who compromise connected systems cannot reach air-gapped storage
    
-   **No zero-day exposure**: Unknown vulnerabilities in connected systems do not create risk to offline assets
    

This is not about replacing other protective controls. Network perimeter security, endpoint protection, and access management remain essential for connected systems. Offline storage adds a layer of protection for data that warrants the highest level of assurance.

## Objective C: Detection and the Limits of Monitoring

The framework rightly emphasises detection capabilities, including security monitoring, proactive security event discovery, and anomaly detection. However, sophisticated attackers increasingly evade detection, sometimes operating within networks for months before discovery.

The NCSC notes that state actors and advanced persistent threats specifically target [critical infrastructure](/control-for-critical-infrastructure) with techniques designed to avoid detection. For CNI operators, this creates an uncomfortable reality: detection capabilities, however sophisticated, cannot guarantee that compromise will be identified before damage occurs.

Offline secure storage complements detection strategies by ensuring that even if attackers achieve undetected access to networks, the most critical data remains beyond reach. This is not a substitute for detection, it is recognition that detection alone is insufficient for the highest-value assets.

## Objective D: Withstanding and Recovering from Incidents

The fourth NCSC objective addresses incident response, [business continuity](/solutions/oss), and recovery. Key principles include:

-   **D.1 Response and Recovery Planning**: Documented plans to respond to and recover from incidents
    
-   **D.2 Lessons Learned**: Processes to learn from incidents and improve resilience
    

The NCSC specifically addresses scenarios where severe attacks overwhelm normal recovery capabilities. In these circumstances, the ability to restore from known-good, uncompromised backups becomes critical.

Firevault Storage supports Objective D by providing:

-   **Immutable backup copies**: Data stored offline cannot be modified by ransomware or other malware
    
-   **Guaranteed recovery point**: Known-good data that enables restoration regardless of network compromise scope
    
-   **Air-gapped evidence preservation**: Forensic data protected from tampering during incident investigation
    
-   **Business continuity assurance**: Certainty that critical data survives even sophisticated, persistent attacks
    

## The WannaCry Lesson: Interconnectedness and Resilience

The WannaCry incident highlighted several insights directly relevant to CNI operators:

-   **Speed of propagation**: The virus spread through NHS networks with unprecedented speed, demonstrating how quickly attacks can escalate
    
-   **Interconnectedness vulnerability**: Organisations that believed they were isolated discovered connections they had not anticipated
    
-   **Service delivery impact**: Critical healthcare services were disrupted, with patients turned away from hospitals
    
-   **Basic hygiene gaps**: Many affected systems lacked patches that had been available for months
    

The NCSC response elevated cyber as a board-level risk across the public sector. But the fundamental lesson remains: systems that are connected can be compromised, and recovery depends on having assets that attackers cannot reach.

## Implementing Physical Disconnection for CNI

For CNI operators considering offline secure storage as part of their NCSC alignment strategy, implementation should address:

1.  **Asset identification**: Determine which data and systems are essential to critical functions and warrant air-gapped protection
    
2.  **Access workflow design**: Establish procedures for [controlled access](/news/controlled-access-buyers-guide-offline-secure-storage) that balance security with operational requirements
    
3.  **Integration with incident response**: Incorporate offline assets into recovery playbooks and business continuity plans
    
4.  **Testing and assurance**: Regularly verify that offline storage functions as intended and supports recovery objectives
    

Firevault Platform provides the infrastructure to implement physical disconnection at enterprise scale, with Super Admin controlled access windows, comprehensive audit logging, and integration capabilities for existing backup workflows.

## Regulatory Context and Future Direction

The NCSC guidance exists within a broader regulatory framework that is evolving rapidly. The [Cyber Security and Resilience Bill](https://www.gov.uk/government/publications/cyber-security-and-resilience-bill-policy-statement/cyber-security-and-resilience-bill-policy-statement) will expand mandatory security requirements for CNI operators, while sector-specific regulators increasingly reference the Cyber Assessment Framework in their oversight.

Organisations that implement physical disconnection now position themselves ahead of regulatory requirements while addressing the genuine threat landscape that NCSC guidance reflects. As the NCSC notes, cyber represents a principal and growing disruptive threat to Critical Infrastructure. The question is not whether to enhance resilience, but how quickly and comprehensively to act.

## Conclusion

The NCSC framework for CNI cyber resilience provides a comprehensive, outcome-focused approach to managing severe cyber threats. Physical disconnection through Offline Secure Storage supports all four objectives, from risk management decisions through to recovery assurance.

For organisations responsible for essential functions, the framework creates clear accountability for cyber resilience at board level. Demonstrating that appropriate measures are in place requires controls that match the severity of potential impact. For the data that would cause the most harm if compromised, Firevault provides the physical disconnection that makes those controls genuinely effective.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

**The Firevault view**

Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.

[Why #OSS →](/why-oss)

Where Firevault fits

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Keep reading

## You may also find these useful

[Explainer 

### Offline Secure Storage: everything you need to know

Offline Secure Storage® is dedicated physical storage that has no network path to it until an authorised out-of-band command creates one. This explainer sets out what it is, how it differs from air gaps, tape and immutable cloud storage, what the standards and insurers expect, how access actually works and how to choose the right instance.

](/learn/knowledge/offline-secure-storage-everything-you-need-to-know)[Explainer 

### Everything finance leaders should know about Offline Secure Storage

A CFO-level explainer on Offline Secure Storage®: how to build the loss model before the control decision, what cyber insurance genuinely transfers, how to treat the cost of a physically isolated copy, and the financial records that need to survive a compromised estate.

](/learn/knowledge/offline-secure-storage-for-finance-leaders)[Explainer 

### Everything technology leaders should know about Offline Secure Storage

A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.

](/learn/knowledge/offline-secure-storage-for-technology-leaders)