Part of Objective A - Managing risk
Principle: A2 Risk management
A2.a Risk management process
“Your organisation has effective internal processes for managing risks to the security, resilience and governance of information, systems and networks related to the operation of your essential function(s), and communicating associated activities. This includes a process for data protection impact assessments (DPIAs).”
Overview
This contributing outcome is about ensuring your organisation has effective processes for managing risk.
Risk assessments
You should conduct risk assessments on a scheduled basis, at sufficient intervals,to ensure any new risks are identified without undue delay, and whenever significant changes occur to your organisational systems or processes.
The DSPT does not mandate a specific approach to risk assessment, however, it's important to consider:
- your organisation’s business priorities and objectives
- who or what those things should be protected from
- any legal and regulatory obligations that apply to your organisation
- the cyber security and information governance (IG) risk red lines your organisation will and won’t cross to complete the things it needs to do
For more information on understanding and managing risk from a cyber security perspective, see National Cyber Security Centre (NCSC) guidance on A basic risk assessment and management method. For information on managing IG risk, see Information Commissioner’s Office (ICO) guidance on risks and data protection impact assessments.
Linking risk assessment to controls
You should link your cyber security and IG controls to your risk assessments. Ways of clearly demonstrating links between controls and risks may include:
- listing controls against each risk in your risk register
- creating a controls catalogue which cross references each control against individual risks
This should help you ensure that your controls are sufficient and proportionate, and that time and resources are not being wasted on solutions that do not effectively contribute towards the management of cyber security and IG risk.
Data protection by design and by default
The requirements of data protection by design and by default should be clearly incorporated into your overall approach to cyber security and wider IG risk. Examples of where considerations should be made include when:
- developing new IT systems, services and processes that involve processing personal data
- developing organisational policies, processes and strategies that have IG or cyber security implications
- embarking on data sharing initiatives
- using personal data for new purposes
- changes to the scope or purpose of current processing activities
See ICO guidance on data protection by design and by default for more information.
Data protection impact assessments (DPIAs)
Data protection impact assessments (DPIAs) are a key way of putting data protection by design and by default into practice.
You should demonstrate that your organisation conducts DPIAs before beginning any type of processing which is "likely to result in a high risk to the rights and freedoms" of individuals. For a detailed list of situations where this applies, see guidance from the ICO. The DPIA process can also help you assess the level of risk associated with a project where this is not clear from the outset.
See NHS England’s universal IG templates page for a template DPIA document which you can use, or reference your own processes against, to ensure all appropriate bases are covered.
"Achieved" level
Adverse impacts
Your approach to risk should be focused on the possibility of adverse impact to your essential function(s). You should understand how this could happen through possible threat actor actions, and how the security of the information, systems and networks that support those functions could contribute to the impact.
This means linking each relevant risk to the techniques threat actors are likely to use (see Common types of cyber attacks in A2.b Understanding threat) and the controls you have in place to prevent or limit those techniques.
For example, if you identify device code phishing as a technique likely to be used against your organisation, you should be able to show that you have considered this risk, implemented appropriate controls such as disabling device code flow, and reassessed the residual risk in light of those controls.
Updating threat assumptions
You need to have a documented threat assessment where your assumptions cover a wide range of attackers and capabilities.
Your threat assumptions need to be continuously updated in response to changes in the threat landscape. These could include geo-political campaigns, significant data protection and security incidents in health and care, and the discovery of new vulnerabilities.
Your threat assumptions should also be informed by information sharing resources and initiatives. These might include threat intelligence and services provided by NCSC, forums and engagement with professionals in your industry.
Anticipating technological developments
A practical approach to anticipating technological developments as part of your risk assessment process is to carry out horizon scanning for emerging technologies and developments in attacker capabilities.
The resources you might use for this activity include:
- threat intelligence and alerts received from NHS England’s CSOC, including via Microsoft Defender for Endpoint
- signing up to NHS England’s Threat Intelligence Sharing Platform
- NHS England’s Cyber Associates Network
- NCSC reports and advisories
- major supplier security blogs and advisories, such as the Microsoft security blog
- system supplier bulletins and notices
- cyber agency alerts and advisories published by international agencies, such as CISA
- industry publications and threat intelligence reports from reputable security companies
Those developments which could affect your own information, systems and networks should be documented, with the results used to update relevant risk assessments.
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- procedures for identifying, analysing, prioritising and managing information governance (IG) and cyber security risk
- risk assessments
- data protection impact assessments (DPIAs)
- risk registers
- evidence of data protection by design and by default being incorporated into risk management processes
- evidence of data protection principles and relevant legislation being incorporated into risk management processes
- evidence of nature of information being considered as part of risk management processes
- evidence of vulnerabilities in systems and networks being considered as part of risk management processes
- procedures for communicating significant conclusions from risk management processes to accountable individuals
- evidence of threat intelligence being used for cyber risk management processes
- evidence of business impact evaluations for multiple scenarios
- threat assumptions and review process
- evidence of lessons learned from near misses being integrated into risk management processes
- evidence of dynamic risk assessments
- procedures for evaluation and improvement of risk management processes
- evidence of ongoing detailed threat analysis
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator(s) of good practice | Term | Interpretation |
|---|---|---|
|
PA#1 Your organisational process ensures that security and wider IG risks to information, systems and networks relevant to essential function(s) are identified, analysed, prioritised, and managed. This includes incorporating data protection by design and default into your process. |
'essential function(s)' |
Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. For more information, see guidance on scoping essential functions. |
|
PA#2 Your risk assessments are informed by an understanding of known and well understood threats and vulnerabilities in the systems and networks supporting your essential function(s), as well as your other data processing activities. |
'known and well understood threats' |
For cyber risk assessments, you should incorporate knowledge of threats including:
|
|
PA#5 You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat. |
'new or emergent technologies or a change in the cyber security threat’' |
New or emergent technologies: You need to appropriately risk assess new technologies adopted by your organisation. A change in the cyber security threat: New threats can affect previous risk assessments for existing products. For example, the growing ability of generative AI to quickly find and exploit vulnerabilities may impact your assessment of security risks that were previously considered low. |
|
PA#6 Your risk process clearly demonstrates how your organisation’s processing complies with data protection principles and relevant legislation, including the right to a private life. |
‘data protection principles and relevant legislation’ |
Principles and legislation which should be considered include:
|
|
A#2 Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible threat actor actions and the security properties of information, systems and networks supporting your essential function(s). |
'adverse impact' |
This term describes any effect on your essential functions that prevents you from delivering them effectively. |
|
A#7 Your risk assessments (including DPIAs) are dynamic and readily updated in the light of relevant changes which may include technical changes to systems and networks supporting your essential function(s), change of use, or processing, the introduction of new emergent technologies, or new threat information. |
‘[updating risk assessments for] new emergent technologies’ | Where new technologies are introduced into your organisation, you should review any existing risk assessments for systems or assets which might be impacted by the way the new technologies function on your network. |
National services
The following national services may help you meet the requirements of A2.a Risk management process:
- Training services | SIRO training
- Training services | Cyber Incident Response Exercise (CIRE)
- Security services | Vulnerability Monitoring Service (VMS)
- Security services | Bitsight
- Security services | Technical Remediation
- Security services | Cyber Assurance Service (CAS)
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Risk management
National Cyber Security Centre | Risk management - Introducing system and component driven risk management approaches
Information Commissioner’s Office | Risk and data protection impact assessments (DPIAs)
Information Commissioner’s Office | Data protection by design and by default
A2.b Understanding threat
"You understand the capabilities, methods and techniques of threat actors and what information, systems and networks they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.”
Overview
This contributing outcome is about understanding likely cyber threats and using that knowledge to strengthen your security controls.
Threat analysis
For cyber risk assessments, you should incorporate knowledge of threats including:
- current and emerging threats described in DHSC or NHS England's Cyber Security Strategy for Health and Care to 2030
- any threats which you have been contacted about directly by DHSC or NHS England
- threat intelligence and alerts received from NHS England's CSCOC, including via Microsoft Defender for Endpoint
Common types of cyber attacks
You should maintain an up to date understanding of common types of cyber attacks, including the method and techniques by which they might affect your organisation. You should ensure your understanding of threat is informed by common incidents.
For example, to defend against:
- phishing – you need to be aware of malicious links, attachments, spoofed emails and credential harvesting
- ransomware – you need to understand how this could happen downstream of phishing, unpatched systems or stolen credentials
- malware – you need to know how malicious code could be introduced through downloads, attachments, websites, removable media or compromised software
- credential attacks – you need to be aware of password spraying, brute force, credential stuffing and reuse of stolen passwords
- social engineering – you need to understand that attackers may manipulate staff by email, phone or messaging to bypass normal checks, disclose information or approve unsafe actions
- Denial of Service (DoS) / Distributed Denial of Service (DDoS) you need to know how public facing services, remote access and supplier-hosted systems could be overwhelmed and made unavailable
Your understanding of attacker methods and techniques should be reflected in your policies, procedures and risk assessments.
Anticipating targets for threat actors
Your organisation should use its understanding of current cyber threats to anticipate which systems, services or access routes are most likely to be targeted by threat actors. This is likely to include:
- user accounts and identities
- email and collaboration tools
- edge devices and other internet facing systems
- remote access services
You should be able to show that you have considered the likely methods of attack for these target areas and implemented proportionate controls to prevent or reduce the risk of successful compromise.
Applying threat analysis to risk management
You should apply your understanding of threat to inform your risk management decision making.
In practice, this could mean using your understanding of likely threats to:
- decide whether to mitigate or tolerate risks
- prioritise risk mitigations
- review whether existing mitigations remain proportionate
- decide where controls need to be strengthened
"Achieved” level 7
Threat analysis
Your threat analysis should be:
- detailed and comprehensive
- underpinned by a robust understanding of attacker tactics and techniques
- continuously updated in response to changes in the threat landscape such as geo-political campaigns, data protection and security incidents in health and care, and the discovery of new vulnerabilities
Capable and well resourced threat actors
A structured way of building a detailed understanding of threat, including the methods and techniques available to capable and well resourced threat actors, would be to sign up to receive briefings from NHS England’s CSOC.
CSOC briefings provide information on sophisticated techniques and methods used by threat actors, which you can apply to your understanding of your own systems to identify the potential implications for your organisation.
You can learn more about these by contacting [email protected].
Threat modelling
You should apply a specific threat modelling framework such as STRIDE, Attack Trees or MITRE ATT&CK Mapping to analyse and examine threats to your information, systems and networks from a threat actor’s perspective.
You should prioritise threat modelling for systems and assets which you consider to be probable targets for capable and well resourced threat actors.
This should lead to a documented understanding of threat actors’ likely attack methods and techniques, their targets and objectives, and the different steps they would need to take to reach their probable targets on your networks.
Threat intelligence and proactive research
To maintain a detailed understanding of current threats, your threat intelligence and proactive research can involve resources such as:
- threat intelligence and alerts received from NHS England’s CSOC, including via Microsoft Defender for Endpoint
- signing up to NHS England’s Threat Intelligence Sharing Platform
- NHS England’s Cyber Associates Network
- NCSC reports and advisories
- major supplier security blogs and advisories, such as the Microsoft security blog
- system supplier bulletins and notices
- cyber agency alerts and advisories published by international agencies, such as CISA
- industry publications and threat intelligence reports from reputable security companies
The above resources should be used to help you regularly undertake horizon scanning for new vulnerabilities, attack trends, common threat actor techniques, and incidents affecting health and care organisations.
Documenting detailed threat analysis
You should document the steps your organisation takes to conduct your detailed threat analysis.
This means that your organisation has a structured local process underpinning your threat analysis, threat modelling, and the way your understanding of threats is applied to your management of risks.
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- procedures for identifying, analysing, prioritising and managing IG and cyber security risk
- risk assessments
- DPIAs
- risk registers
- evidence of up to date understanding of common types of cyber attacks
- evidence of information or assets being prioritised by likelihood of being targeted by threat actors
- evidence of use of a specific threat modelling framework
- evidence of sources used to maintain a detailed understanding of current threats
- procedures for doing threat analysis and threat modelling in a structured way and applying them to risk management
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator of good practice | Term | Interpretation |
|---|---|---|
|
PA#4 Your understanding of threat is informed by common incidents. |
'common incidents' |
An approach similar to the one outlined in the Common types of cyber attack section above would lead to an understanding of threat informed by common incidents. |
|
A#7 You apply your detailed understanding of threat to inform your risk management decision making. |
'detailed understanding of threat' | See Threat intelligence and proactive research section above. When you learn that ways of conducting cyber attacks are evolving, you should have a structured way of updating your internal controls to match your new understanding. |
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Building a Security Operations Centre (SOC) | Threat Intelligence
A2.c Assurance
“You have gained confidence in the effectiveness of your technology, people and processes relevant to the security and governance of information, systems and networks supporting your essential function(s).”
Overview
To meet this contributing outcome, your organisation needs to show that it tests the effectiveness of its cyber security and information governance (IG) controls for assurance.
Assurance
Assurance is about gaining confidence that your cyber security and IG controls are working effectively. To achieve this, you should use a variety of techniques to proactively review how your people, processes and technology are working in practice. Any weak points identified through your assurance activities should be documented and acted upon.
You should undertake your assurance activities at planned intervals that you can justify based on the risks being managed, to confirm that existing controls remain effective as circumstances and threats change.
See NCSC’s guidance on how to gain and maintain assurance for more information.
Understanding and reviewing assurance methods
You should understand the assurance methods that are available and review the ones you use to ensure they remain effective. This might mean, for example, optimising your vulnerability testing process or focussing your spot checks on specific areas or processes identified as weak points.
As part of your review, you may consider whether you are making most effective use of assurance activities such as:
- penetration testing
- behavioural testing, for example simulated phishing exercises
- spot checks of processes, for example joiner / mover / leaver procedures, checking new assets are being appropriately registered, responses to subject access requests
- spot checks of the premises, for example physical security of the building, locked cabinets, staff and visitor ID badges, paper waste, computer equipment
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- procedures for assurance of cyber security and IG controls
- evidence of validation and selection of assurance methods
- evidence of previous DSPT audits or equivalent independent assurance
- action plans for remediating deficiencies
- procedures for reviewing assurance methods
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator(s) of good practice | Term | Interpretation |
|---|---|---|
|
A#2 You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security and governance of information systems and networks |
'essential function(s)' |
Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. For more information, see guidance on scoping essential functions. |
National services
The following national services may help you meet the requirements of A2.c Assurance:
- training services - Board training
- training services | SIRO training
- training services | Cyber Incident Response Exercise (CIRE)
- training services | Keep IT Confidential
- security services | Secure Boundary
- security services | Vulnerability Monitoring Service (VMS)
- security services | Bitsight
- security services | Technical Remediation
- security services | Cyber Assurance Service (CAS)
- NCSC services | Early Warning
- NCSC services | Exercise in a box
- NCSC services | Check your cyber security
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Risk management - How to gain and maintain assurance
National Cyber Security Centre | Penetration testing
Last edited: 26 August 2026 11:47 am