
What is Facility Security Clearance and how do you get it?
New to defence supply? What Facility Security Clearance (formerly List X) is, when you need it, how sponsorship works, and what to do before you apply.
Expert analysis, research, and industry insights from the security sector. Some content is exclusive to HASC members.

New to defence supply? What Facility Security Clearance (formerly List X) is, when you need it, how sponsorship works, and what to do before you apply.

Insider risk is the risk that individuals with authorised access, whether deliberately or inadvertently, cause harm to an organisation’s data, systems, reputation, or assets. In recent years, the defence sector has been increasingly subject to insider incidents. Espionage, ranging from individually motivated to coordinated schemes, puts operational integrity and trust at risk. Infiltration, whether to access classified information or to disrupt systems, puts sensitive data and personnel safety at risk and directly harms the effectiveness of operations. As custodians of security, defence organisations have an inherent responsibility to safeguard their critical assets. As such, more than in many other sectors, the cost of insider incidents goes beyond financial losses, impacting operational integrity, international security, and regulatory standing.

Critical National Infrastructure (CNI) resilience measures are expanding globally through mandatory frameworks, including the EU CER Directive, German KRITIS Act, and US CISA expanded authorities, but implementation remains inconsistent across organizations. Regulatory frameworks are converging on common requirements, including risk assessments, incident reporting within 24-48 hours, and cybersecurity standards compliance, although organizations struggle with funding constraints, aging infrastructure vulnerabilities, and public-private coordination challenges. Private sector resilience capabilities vary significantly across regions and sectors, with developed economies showing higher maturity in some industries but gaps remaining in supply chain resilience and cross-sector coordination. Major incidents in 2025 demonstrate that organizations with proactive resilience measures, including redundancy, backup operational processes, and trained personnel, showed better recovery outcomes, while those relying on single points of failure faced extended disruptions with cascading impacts.

Risks of disruptions to critical national infrastructure (CNI) are proliferating due to the increasing integration of different CNI sectors, largely through automation and digitalization of supply chains and the expanding use of artificial intelligence (AI). CNI remains a priority target for threat actors and poses continuous risks to businesses, governments, and local populations. Vulnerabilities to CNI in developing countries typically include out-of-date infrastructure, which threat actors exploit by using advanced tactics, techniques, and procedures (TTPs), particularly in the cyber domain, where advancements are rapid and can lead to security update requirements. Conversely, in developed nations, advances in CNI through digitalization and the use of AI to coordinate systems have changed the typical threat profile by broadening the potential impact of CNI disruption, potentially leading to outages in several CNI sectors in the same attack. Risks to CNI have also been exacerbated by global developments, such as geopolitical tensions, climate change, and the expanded use of AI, prompting organizations to adapt and develop more robust crisis management strategies to mitigate the associated risks.

Practical Guidance for Innovators Seeking Success in the Evolving UK National Security and Defence Ecosystem. An expert insight from a member of the HASC Advisory Board.

A wide spectrum of threat actors, including state-aligned groups, cyber threat actors, activists, terrorists, and organized criminal groups, are actively targeting CNI to pursue strategic, financial, or political objectives. CNI is increasingly becoming a target for threat actors due to the extensive impacts its disruption can have on the public, businesses, and state functions. There is increasing overlap and convergence between threat actor groups. Hostile states are increasingly leveraging cyber threat actors and criminal proxies to conduct deniable operations against CNI, impeding attribution and response while hindering effective countermeasures.

CNI is increasingly becoming a target for threat actors due to the extensive impacts its disruption can have on the public, businesses, and state functions. Flashpoints, such as domestic and foreign policy changes, conflicts, and global tensions, are key indicators of CNI targeting and disruption. While threat actors are unlikely to target CNI with the specific intent to disrupt business operations, the increasing integration of private organizations with CNI renders it more likely that businesses will be impacted. Whether CNI disruption is caused by malicious intent or by accident, it is probable that businesses will be disrupted by secondary and tertiary effects.

Today’s most capable threat actors target the UK’s critical sectors through interconnected cyber, physical, and human vulnerabilities. Organisations need security professionals who combine technical expertise with strategic, business‑aligned skills. The High Assurance Security Centre exists to raise these standards and build true resilience across sectors vital to national prosperity.

The intelligence cycle offers organisations a structured means of managing intelligence relevant to their requirements. It is applicable across military, law enforcement, industry and other sectors. The structure changes from one model to another, but the logic remains consistent.

Organisations across the private sector, military, police and intelligence agencies should all employ the intelligence cycle if they are to maximise their collection of and benefit from intelligence products. While the process logic is consistent across domains, implementation differs in ways that reflect different operational environments, legal constraints, and organizational cultures: if you’re building or running an intelligence function, the details of your environment will shape how you apply each step.
Request access to start using the platform. Membership is vetted.
No obligation.See how practitioners use the platform day to day across high-assurance sectors.
Book a demo →Questions about membership or where to start? We would love to talk it through.
Contact us →