By Bernard Baker, 4Secure
The UK Government’s latest National Risk Register presents a country facing risks that are both of an unprecedented nature and scale.
Geopolitical instability, terrorism, extreme weather and biological threats remain prominent. But the 2026 edition also gives much greater attention to the systems and infrastructure on which modern life depends: energy, water, communications, transport, data and essential public services.
Having recently joined 4Secure to support its defence customers, I have been looking closely at what the updated register tells us about the UK’s changing risk landscape, and what it means for those responsible for protecting Critical National Infrastructure.
What has changed?
The National Risk Register is the public-facing version of the classified National Security Risk Assessment. It describes “reasonable worst-case scenarios”: not predictions, but plausible events against which government, infrastructure operators and other organisations should prepare.
Eight risks have been added in 2026:
- Digital resilience failure
- Cyber attack on data infrastructure
- National disruption to data infrastructure
- Cyber attack on water infrastructure
- Cyber attack on police systems
- Significant disruption to the criminal justice system
- Accidental damage to the National Gas Transmission Network
- Interference in the UK democratic process
Five of these additions relate directly to the security or resilience of digital systems and data infrastructure. That is significant.
Cyber risk is no longer treated simply as an IT issue. The scenarios described in the register show how the compromise or failure of digital systems can quickly become a national resilience issue, affecting the delivery of physical services and, ultimately, people’s safety.
From digital disruption to physical consequences
The new water infrastructure scenario provides one of the clearest examples.
It considers an advanced cyber actor infiltrating the operational technology used by a water company. Malware erases critical data and disables components responsible for essential operational functions, leaving the operator without visibility or control.
In the reasonable worst-case scenario, more than one million people are affected. Restoring full functionality could take several months because specialist OT components may need to be replaced or reconfigured, while operators must also establish that the attacker has been completely removed.
The register identifies similar dependencies across energy, transport, telecommunications, healthcare and other essential services.
The lesson is straightforward: connectivity creates operational value, but it must be introduced without surrendering control of critical systems.
Data infrastructure is now CNI
Data centres were designated as a Critical National Infrastructure subsector in 2024. The new register reflects this by introducing separate scenarios for a cyber attack and a wider national disruption to data infrastructure.
This recognises that data centres do not simply store information. They underpin healthcare records, financial services, communications, government systems and the operation of other CNI sectors.
The register’s cyber scenario considers an attack against one or more UK colocation data centres. Although the initial attack may last between two and seven days, disruption could continue for months and complete restoration could take years.
It is a powerful illustration of systemic risk. An incident affecting one provider, facility or shared dependency can spread far beyond its original boundary.
Failure does not have to be malicious
The addition of “digital resilience failure” is equally important.
Based partly on lessons from the global IT outage in July 2024, this scenario considers a faulty software update disrupting critical servers across multiple sectors. Communications, emergency services, transport, financial systems and border controls could all be affected simultaneously.
This changes the resilience conversation.
Organisations must prepare not only for deliberate attacks, but also for software errors, supply-chain failures, misconfiguration and the concentration of critical services among a relatively small number of providers.
In highly connected environments, trusted technology can still fail. Resilience therefore depends on limiting the potential blast radius and retaining safe, tested ways to continue operating.
What should CNI organisations take from the register?
The individual scenarios vary, but several common requirements emerge:
- Understand the dependencies connecting IT, OT, cloud and third-party services.
- Control how data moves between systems of different sensitivities.
- Reduce the routes through which an attacker or software failure can propagate.
- Apply policy enforcement, verification and transformation to data in transit.
- Maintain trusted recovery paths and test them regularly.
- Design for degraded operation, not only prevention.
- Treat resilience as an operational and organisational responsibility, rather than a purely technical one.
For many organisations, complete isolation is neither practical nor desirable. Operational teams need information. Partners need to collaborate. Decision-makers need timely data from multiple environments.
The challenge is enabling that exchange without creating uncontrolled connections between critical systems.
That is where well-designed Cross Domain architecture plays an important role. Secure data exchange can allow information to move between networks while enforcing precisely what can pass, in which direction, under what conditions and with what level of verification.
Resilience begins before the incident
The 2026 National Risk Register does not suggest that every organisation will experience one of these precise scenarios. It shows that the consequences of digital compromise and failure now reach deep into the physical world.
For organisations operating within defence and Critical National Infrastructure, resilience cannot begin when an incident is detected. It must be designed into the architecture, exercised through realistic scenarios and maintained as systems and threats evolve.
I am delighted to have joined 4Secure at a time when these questions are becoming increasingly important. I look forward to working with defence organisations, partners and infrastructure operators to understand their operational requirements and help them exchange information securely across complex and sensitive environments.

Bernard Baker
Bernard has recently joined 4Secure as a Defence Consultant. He boasts a wealth of experience helping Defence find answers to questions that had previously seemed impossible to answer.
Connecting The Disconnected
Copyright © 4Secure Ltd.
All rights reserved
Company
About
Clients
News
Insights
Privacy Policy
Solutions
Components
Software
Cross-Domain
Solutions
Consulting