What is the Cybersecurity National Action Plan: how the US, the UK, and the EU build national cybersecurity action plans and what lessons Ukraine can draw from them.
Cybersecurity National Action Plan (CNAP) is a term that first entered the official US lexicon in 2016, but today it describes a whole class of government documents: structured action plans through which countries turn the abstract goal of "strengthening cybersecurity" into concrete budgets, accountable officials, deadlines, and measurable outcomes. Such plans have already been adopted by the United States, the United Kingdom, the European Union, and Ukraine — and despite different names and contexts, they share a common logic: cybersecurity is no longer a matter for individual agencies but a national project managed centrally. In this article we break down how a national cybersecurity action plan is structured, how the approaches of the US, the UK, and the EU differ, what Ukraine is doing, and what lessons business can draw from it.
What is a Cybersecurity National Action Plan and why it is more than a US program
Strictly speaking, the "Cybersecurity National Action Plan" is the proper name of the American program announced by the Barack Obama administration on February 9, 2016. In practice, however, the term has long since become generic: it denotes any national action plan that turns a cybersecurity strategy into a set of executable measures. What distinguishes such a plan from an ordinary "strategy" is that it contains explicitly fixed money, roles, deadlines, and accountability mechanisms.
The common core of such documents usually consists of several elements. First, modernizing government IT infrastructure — most often through a dedicated fund that finances the replacement of outdated systems. Second, appointing a responsible leader — a national or government chief information security officer. Third, developing talent — from educational programs to university grants. Fourth, strengthening the resilience of critical infrastructure and establishing clear incident-response protocols. This framework repeats from country to country because it answers the same systemic problems.
CNAP 2016: how the US first systematized national cybersecurity
The American Cybersecurity National Action Plan became the starting point for the entire class of documents. It was announced as the "culmination" of seven years of the administration's work on cybersecurity — following the passage of the Cybersecurity Act of 2015, which simplified the sharing of cyber-threat information between private companies and the government.
The key element of the plan was the Information Technology Modernization Fund — a revolving IT modernization fund of $3.1 billion. Its logic: agencies receive funds up front to replace outdated, vulnerable systems, and then repay them from the savings generated by more efficient infrastructure. This allows the fund to operate as a self-financing "revolver". According to White House estimates, the initial $3.1 billion was expected to unlock modernization projects worth up to $12 billion over ten years.
The second pillar was the creation of the first-ever position of Federal Chief Information Security Officer — a federal CISO responsible for policy, planning, and coordination of cybersecurity across the entire federal government. Before this, cybersecurity was the responsibility of scattered structures without a single leader. The plan also provided for the establishment of the Commission on Enhancing National Cybersecurity (Executive Order 13718) and investments in cyber education — from school programs to university grants.
Overall, the cybersecurity budget in fiscal year 2017 grew to more than $19 billion — an increase of roughly 35% compared with the previous year. Tellingly, the plan combined both short-term measures and a long-term strategy: quick actions delivered visible results immediately, while the modernization fund laid the foundation for years ahead.
Government Cyber Action Plan: the new British approach (2026)
The freshest example is the British Government Cyber Action Plan, published on January 6, 2026 by the Department for Science, Innovation and Technology (DSIT). The plan, worth more than £210 million, was a response to a series of high-profile incidents in the public sector: the attack on the pathology services supplier Synnovis caused the delay of more than 11,000 outpatient and elective appointments, and the Legal Aid Agency incident compromised personal data and paralyzed the processing of applications.
The core of the British model is the Government Cyber Unit (GCU), headed by a government CISO and housed in DSIT. It is a central coordinating body that moves the state from a model of "every organization defends itself" to a model of "the government defends itself as one whole". The plan is built around four strategic goals: better visibility of cybersecurity risks, countering sophisticated and serious threats, faster response to events, and rapidly raising resilience across the whole of government.
These goals are delivered through five strands: accountability (clear responsibilities and mandatory requirements), support (guidance, technical advice, commercial frameworks), services (a single range of scalable services — from risk measurement to threat detection and response), respond and recover (a collective response to incidents), and skills (a centralized cyber profession with scalable training programs). The technical authority is the National Cyber Security Centre (NCSC), and the plan was published alongside the second reading of the Cyber Security and Resilience Bill.
European action plan for hospitals and healthcare providers (2025)
The European Union took a sectoral path. On January 15, 2025, the European Commission launched the European action plan on the cybersecurity of hospitals and healthcare providers — the first sectoral initiative in EU history to apply the full set of the Union's cybersecurity tools to a single sector. It was announced as a priority of the first 100 days of the new Commission mandate, recorded in the political guidelines of Ursula von der Leyen.
The logic is clear: healthcare facilities are increasingly targeted by ransomware, and the consequences of attacks are measured not only in money but in patients' lives — as in the Synnovis case in Britain, which the European Commission cites directly as an argument. The plan is built on four pillars. The first is Prevent: preparedness, risk management, and cyber training for medical staff. The second is Detect: improving threat detection, including a Europe-wide early warning system for the health sector to be deployed by 2026. The third is Respond and recover: access to the EU Cybersecurity Reserve, incident-response services, and national cyber exercises. The fourth is Deter: deterring attackers, notably through cyber-diplomacy tools.
Tellingly, the European approach is not "yet another strategy" but a set of concrete actions rolled out in stages throughout 2025–2026 in cooperation with member states, healthcare providers, and the cyber community. It gives hospitals practical guidance, tools, services, and training rather than just general recommendations.
The Ukrainian dimension: Ukraine's Cybersecurity Strategy
Ukraine has its own counterpart. On August 26, 2021, Presidential Decree No. 447/2021 enacted the decision of the National Security and Defence Council "On the Cybersecurity Strategy of Ukraine" — a document titled "A Secure Cyberspace is the Key to the Country's Successful Development", running through 2021–2025. The strategy defines the priorities of national interests, goals, and tasks for building the national cybersecurity system.
The coordinating role in its implementation is assigned to the National Cybersecurity Coordination Centre (NCCC) under the NSDC, and the legal foundation is laid by the Law of Ukraine "On the Basic Principles of Ensuring Cybersecurity of Ukraine", adopted back in 2017. The strategy takes into account modern challenges — from cloud and quantum computing and 5G networks to the Internet of Things and artificial intelligence — and explicitly sets a course for cooperation with the EU, the US, and NATO member states.
A separate Strategy Implementation Plan, approved by decree in February 2022, translated the strategic goals into concrete measures. A characteristic feature of the Ukrainian model is the principle of broad engagement: to address cybersecurity tasks, in addition to the main state entities, the state plans to involve businesses, civil society organizations, and individual citizens, recognizing that cyberspace resilience is impossible without the participation of business and society. For Ukraine, which has lived under constant hybrid aggression and cyberattacks on state institutions and critical infrastructure since 2014, this document is not a formality but a practical defense framework. That is why the topic of national cyber resilience regularly comes up at specialized venues such as the Kyiv Cyber Resilience Forum and collective exercises like NATO Cyber Coalition.
Common elements of a successful national action plan
Despite different names and contexts, all successful national cybersecurity action plans share a common architecture. The first element is centralized leadership with clear accountability: a federal CISO in the US, the Government Cyber Unit in Britain, the NCCC in Ukraine. Without a single responsible party, coordination disintegrates into scattered initiatives of individual agencies.
The second is dedicated funding with a return-on-investment mechanism. The American ITMF showed that a revolving fund is more effective than one-off grants: it forces agencies to choose projects with the highest return and sustains itself. The British plan, with a budget of £210 million, works on a similar prioritization logic.
The third is the talent component. No plan works without specialists, which is why all documents contain educational programs, university grants, and the development of the cyber profession. This directly overlaps with the topic we covered in our piece on learning cybersecurity from scratch.
The fourth is critical infrastructure resilience and response protocols. Both Britain and the EU directly tie their plans to real incidents, which defines their practical orientation. Finally, the fifth element is measurable outcomes and accountability: a plan without performance indicators quickly turns into a declaration.
What this means for business and professionals
National action plans affect the private sector directly. They set standards that gradually become mandatory for state suppliers: the British Cyber Security and Resilience Bill directly imposes requirements on firms that provide services to the government — from energy and water to healthcare and data centers. If your company works with the public or critical sector, the requirements of a national plan are your future compliance minimum.
For professionals, these documents signal growing demand for qualified talent and a clear list of directions in which states are investing: IT modernization, threat detection, incident response, training. And for the ordinary user, a national plan means that the question "have my data been leaked" becomes a state priority — and that it is worth checking basic hygiene yourself, for example through the data breach check tool.
A national cybersecurity action plan is at once a political document and an engineering roadmap. The US laid down the template in 2016, Britain in 2026 showed how to rebuild government cybersecurity around a central coordinator, the EU showed how to apply the same approach to a single sector, and Ukraine is adapting these mechanisms to wartime conditions. For every organization operating in cyberspace, this logic scales downward as well: clear accountability, a dedicated budget, prioritized measures, and measurable results — this is a recipe for resilience not only for a state but for an individual company.
Ultimately, a national action plan is not abstract bureaucracy but a response to very real incidents and a concrete mechanism that turns money and responsibility into measurable resilience. That is why it is worth tracking updates to such documents: they set standards that will tomorrow become mandatory for government contractors and critical industries.