The Cyber Assessment Framework covers a lot of ground. Four objectives, fourteen principles, dozens of indicators of good practice. Organisations working through it tend to spend their time on the areas where tooling already exists: endpoint protection, access control, incident response, security monitoring.
Transport-layer security rarely gets the same scrutiny. That is a problem worth understanding.
A note on terminology: routing and BGP operate at the network and control layers rather than OSI layer 4. Here, “transport-layer” is used in the broader operational sense of the infrastructure and paths that carry communications between endpoints.
What the CAF actually asks for
The CAF is structured around four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. Within “protecting against cyber attack,” the framework expects organisations to secure the networks and information systems that support their essential functions.
That language is broad enough to include transport-layer concerns. But in practice, many assessments interpret “network security” as firewall rules, segmentation, and access policy. The routing infrastructure underneath those controls, the paths data actually takes between endpoints, can be treated as a given.
For organisations in sectors like energy, transport, digital infrastructure, and government, that assumption deserves testing.
Where transport exposure hides
Three categories of transport-layer risk can fall outside standard assessment scope.
Metadata leakage through encrypted channels. Encryption protects content. It does not automatically conceal traffic timing, packet sizes, communication frequency, or endpoint relationships. For a sufficiently motivated adversary, these patterns can reveal operational tempo and organisational structure without ever breaking the cipher.
Routing predictability. Most enterprise networks rely on deterministic routing. Traffic follows the same paths between the same endpoints, session after session. An attacker with visibility into routing behaviour can map dependencies and identify chokepoints without touching a single payload.
Topology as intelligence. Even well-encrypted systems can expose which nodes talk to which other nodes, how often, and in what patterns. At the scale of critical national infrastructure, that topology map can become strategic intelligence. It may show where decisions flow, where redundancy exists, and where a disruption could cascade.
Running a transport-layer review against CAF objectives
If you are preparing for a CAF assessment, or revisiting one already completed, here is a practical way to evaluate transport-layer exposure against the framework’s own structure.
Objective A (Managing security risk). Map your transport dependencies the same way you map your information assets. Which transit providers carry your traffic? Where does your routing concentrate through single points? Document these as risks with the same rigour you apply to software vulnerabilities.
Objective B (Protecting against cyber attack). Test whether your network security controls extend below the application layer. Can you demonstrate that routing behaviour is monitored, that path diversity exists, and that metadata exposure has been assessed? Where the security architecture stops at the firewall, relevant outcomes may be insufficiently evidenced.
Objective C (Detecting cyber security events). Ask whether your monitoring covers transport-layer anomalies where they are relevant to essential functions. This may include routing changes, BGP announcements, or shifts in traffic patterns that indicate reconnaissance or pre-positioning.
Objective D (Minimising impact). Evaluate whether your incident response plans account for transport-layer compromise. If an adversary manipulates routing to intercept or redirect traffic, does your playbook cover that scenario? Can your essential functions survive a change in the paths their data travels?
The regulatory direction
The NCSC publishes guidance on the Cyber Assessment Framework, including how it supports organisations subject to the NIS Regulations and those within UK Critical National Infrastructure. The Cyber Security and Resilience (Network and Information Systems) Bill is currently before Parliament. The government’s summary of the Bill describes proposals to expand regulatory scope and strengthen the UK’s cyber resilience framework. As expectations develop, areas that assessments currently skip may become harder to justify leaving unaddressed.
Organisations that assess transport-layer exposure now may have less remediation work if new requirements take effect. Those that wait could be retrofitting controls under regulatory pressure.
Starting the work
A transport-layer review does not require rebuilding your network. Start with visibility: document your routing architecture, identify where metadata is observable, and map your dependency on specific transit paths. Compare what you find against the CAF objectives above.
Some organisations may discover that their controls are strong at the application layer and thin at the transport layer. That gap is not a failure of the CAF. The framework is broad enough to encompass these risks. It is a question of how assessments are scoped, and it is fixable.
The first step is deciding that routing, metadata, and topology belong on the same risk register as phishing and ransomware.
This article is general technical analysis, not legal or regulatory advice and not a CAF assessment. It does not claim that OmniMesh or any named organisation meets particular CAF outcomes.
Back to blog